Výsledky hledání

téma: identita× v celém archivu zrušit filtry

221 karet z 233 položek · strana 1 z 4 CZ · EN/orig

6

New Android malware uses AI to steal bank logins and PINs

Researchers at Zimperium’s zLabs have analyzed an Android Trojan that uses an automated, multi-stage infection process. What’s new is that RatHat gives a live AI assistant the keys to the accessibility tree of the infected device and uses it to determine where to tap or scroll, rather than following a hardcoded script. The variable attack path makes it harder for signature- and rule-based mobile security tools to detect this Trojan. It also abuses Android Debug Bridge (ADB), a legitimate tool…

Google finance US

tg: rozbor tg: propagace tp: malware tp: podvod tp: AI tp: identita

· Malwarebytes Labs · New Android malware uses AI to steal bank logins and PINs

Secure enterprise sharing with access reviews for Microsoft 365

Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. [...]

Microsoft US

tg: návod tg: propagace tp: identita

· BleepingComputer · Secure enterprise sharing with access reviews for Microsoft 365

A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.

US

tg: rozbor tg: návod tp: AI tp: identita

· Palo Alto Unit 42 · A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

Risolte vulnerabilità in pgAdmin

Rilasciato aggiornamento che risolve 2 vulnerabilità di sicurezza, con gravità “critica”, in pgAdmin, nota piattaforma di amministrazione e sviluppo open source per PostgreSQL. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato di eludere i meccanismi di autenticazione e di scrivere file arbitrari sul filesystem dei sistemi interessati

EPSS 0.00 CVE-2026-86863 CVE-2026-86864 pgAdmin IT

tg: zranitelnost tp: identita

· CSIRT Itálie (ACN) · Risolte vulnerabilità in pgAdmin

SPOJENO PŘES CVE ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.

EPSS 0.00 CVSS 4.9 CVE-2026-20235 Cisco US

tg: zranitelnost tp: identita

· Zero Day Initiative · ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability · Cisco PSIRT · Cisco Identity Services Engine Information Disclosure Vulnerability

The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era 

Key Takeaways Periodic audits provide a point-in-time assessment, but they cannot demonstrate whether controls remain effective between audit cycles. Qualys platform data shows 10.5 billion configuration findings across customer environments but only 1.6% represent meaningful exposure and under 1% are prioritized, business-critical findings. Verizon’s 2026 DBIR found the median time to resolve weak passwords and misconfigured permissions is about 8 months. Across 1 billion misconfiguration…

US

tg: rozbor tg: návod tg: propagace tp: ransomware tp: AI tp: identita

· Qualys · The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era 

13

AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460

Number: AL26-021Date: September 17, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian…

KEV ✓ EPSS 0.01 CVE-2026-20192 CVE-2026-76423 CVE-2026-76460 Cisco CA

tg: zneužíváno tg: zranitelnost tp: identita

· Cyber Centre Kanada · AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460

From guidance to action: Security fundamentals that materially reduce risk 

AI has already made fundamental changes to the operating environment for cybersecurity. Cyberattackers are testing more paths, adapting their techniques, and moving across digital environments with greater speed and persistence. The weaknesses they exploit remain familiar: excessive permissions, unprotected authentication flows, unpatched systems, exposed execution paths, and gaps between controls. What has changed is how quickly these weaknesses can combine into attack paths that cross…

Microsoft US

tg: rozbor tg: návod tg: propagace tp: malware tp: phishing tp: AI tp: identita

· Microsoft Security Blog · From guidance to action: Security fundamentals that materially reduce risk 

SPOJENO PŘES CVE Cisco security advisory (AV26-932)

Serial number: AV26-932Date: September 17, 2026 As of September 16, 2026, Cisco is affected by vulnerabilities in the following products: Cisco Secure Firewall Threat Defense (FTD) Software Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0 Cisco Secure Firewall Management Center (FMC) Software Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0 Cisco Identity Services Engine (ISE) Software Prior to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4…

KEV ✓ EPSS 0.01 CVE-2026-76460 Cisco CA SE HU IT FR US

tg: zneužíváno tg: zranitelnost tp: identita

· Cyber Centre Kanada · Cisco security advisory (AV26-932) · CERT-SE · Cisco publicerar säkerhetsuppdateringar för flera sårbarheter · NKI Maďarsko · Riasztás Cisco szoftvereket érintő sérülékenységekről · CSIRT Itálie (ACN) · Risolte vulnerabilità in prodotti Cisco · CERT-FR – avis · Multiples vulnérabilités dans les produits Cisco (17 septembre 2026) · Cisco PSIRT · Cisco Identity Services Engine Authentication Bypass Vulnerability · CISA KEV · Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (CVE-2026-76460)

SPOJENO PŘES CVE LiteLLM: rilevato sfruttamento in rete della CVE-2026-59822

Rilevato lo sfruttamento in rete di una vulnerabilità, identificata tramite la CVE-2026-59822, in LiteLLM di BerriAI, server proxy impiegato come gateway per l'accesso a modelli linguistici di grandi dimensioni (LLM). La vulnerabilità consente a un attaccante remoto non autenticato di eludere i meccanismi di autenticazione e accedere agli strumenti MCP senza disporre di credenziali valide.

KEV ✓ EPSS 0.01 CVE-2026-59822 BerriAI IT US

tg: zneužíváno tg: zranitelnost tp: AI tp: identita

· CSIRT Itálie (ACN) · LiteLLM: rilevato sfruttamento in rete della CVE-2026-59822 · CISA KEV · BerriAI LiteLLM Improper Authentication Vulnerability (CVE-2026-59822)

Mecanismo deficiente de recuperación de contraseñas olvidadas en MobiAPParc

Weak password recovery mechanism for forgotten password in MobiAPParc Thu, 09/17/2026 - 14:21 Aviso Affected Resources IOS MobiAPParc v0 – v2.28;Android MobiAPParc v0 – v2.42. Description INCIBE has coordinated the disclosure of a high-severity vulnerability affecting SMAP’s MobiAPParc, an app that enables users to pay for parking in regulated parking zones and in municipal car parks managed by Palma City Council. The vulnerability was discovered by Llorenç Romá.This vulnerability has been…

EPSS 0.00 CVSS 8.1 CVE-2026-14850 SMAP doprava ES

tg: zranitelnost tp: identita

· INCIBE-CERT · Mecanismo deficiente de recuperación de contraseñas olvidadas en MobiAPParc

Schneider Electric PowerChute Serial Shutdown

View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data. The following versions of Schneider Electric…

EPSS 0.00 CVSS 5.3 CVE-2026-13348 Schneider Electric energetika výroba a průmysl US

tg: zranitelnost tp: identita tp: průmyslové systémy

· CISA Advisories · Schneider Electric PowerChute Serial Shutdown

NCSC-2026-0382 [1.00] [H/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE)

Cisco heeft 21 kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE) en Cisco ISE Passive Identity Connector (ISE-PIC). De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Cisco ISE en ISE-PIC, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van middel tot kritiek. Van de in totaal 21 kwetsbaarheden zijn 13 als kritiek…

KEV ✓ EPSS 0.01 CVE-2026-20130 CVE-2026-20192 CVE-2026-76423 CVE-2026-76460 Cisco NL

tg: zneužíváno tg: zranitelnost tp: identita

· NCSC-NL · NCSC-2026-0382 [1.00] [H/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE)

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]

KEV ✓ EPSS 0.68 CVE-2025-20337 CVE-2026-20176 CVE-2026-20211 CVE-2026-20284 CVE-2026-20307 CVE-2026-76423 CVE-2026-76460 Cisco US

tg: zneužíváno tg: zranitelnost tp: identita

· BleepingComputer · Cisco warns of max severity ISE zero-day exploited in attacks

Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv4.0: 9.3, CVEs: CVE-2026-89026, Summary: The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System…

EPSS 0.01 CVSS 9.3 CVE-2026-89026 Issabel FI

tg: zneužíváno tg: zranitelnost tp: identita

· NCSC-FI · Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate

11

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these…

EPSS 0.00 CVE-2026-76439 CVE-2026-76444 CVE-2026-76446 CVE-2026-76447 Cisco US

tg: zranitelnost tp: identita

· Cisco PSIRT · Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Cisco Secure Firewall Management Center Software Vulnerabilities

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access and perform session forgery or session impersonation. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com…

EPSS 0.00 CVE-2026-76412 CVE-2026-76413 CVE-2026-76420 Cisco US

tg: zranitelnost tp: identita

· Cisco PSIRT · Cisco Secure Firewall Management Center Software Vulnerabilities

Cisco Identity Services Engine Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco…

EPSS 0.00 CVE-2026-20130 CVE-2026-20192 CVE-2026-20194 CVE-2026-20234 CVE-2026-20237 CVE-2026-20287 Cisco US

tg: zneužíváno tg: zranitelnost tg: novinka v produktu tp: identita

· Cisco PSIRT · Cisco Identity Services Engine Hardening Release: September 2026

Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an unauthenticated, local attacker to either conduct an authentication bypass or disclose sensitive information. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com…

EPSS 0.00 CVE-2026-20071 CVE-2026-20072 Cisco US

tg: zranitelnost tp: identita

· Cisco PSIRT · Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities

Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilities

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated attacker to perform an sftunnel authentication bypass or sftunnel denial of service (DoS) attack. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This…

EPSS 0.01 CVE-2026-20295 CVE-2026-20323 Cisco US

tg: zranitelnost tp: DDoS tp: identita

· Cisco PSIRT · Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilities

Using Cyber Decoys to Strengthen Detection and Response

CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to…

US

tg: návod tp: identita

· CISA Advisories · Using Cyber Decoys to Strengthen Detection and Response

Risolte vulnerabilità nei prodotti Atlassian

Aggiornamenti di sicurezza Atlassian sanano alcune vulnerabilità, di cui una con gravità "alta", che interessano il prodotto Crowd Data Center. Tale vulnerabilità, qualora sfruttata, potrebbe consentire, a un utente malintenzionato non autenticato, di eludere i meccanismi di autenticazione e ottenere accesso a funzionalità o risorse riservate sui sistemi interessati.

EPSS 0.00 CVE-2026-21582 Atlassian IT

tg: zranitelnost tp: identita

· CSIRT Itálie (ACN) · Risolte vulnerabilità nei prodotti Atlassian

Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

Executive Summary OpenAI disclosed that agents used exposed Hugging Face credentials to write a file and deploy proxy Spaces during an unrelated May 2026 research workload, but it did not identify the accounts. SentinelLABS identified two accounts likely used in associated activity, 0Time and Nyx9. Their public histories extend OpenAI’s chronology and preserve previously unreported relay code, document-borne probes, and ChatGPT account-provisioning capability. The public records provide precise…

OpenAI Hugging Face US

tg: incident tg: rozbor tp: AI tp: identita

· SentinelLabs · Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face

9

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.Key takeawaysThe Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI.The Essential…

veřejná správa US

tg: regulace tg: návod tp: AI tp: identita tp: průmyslové systémy

· Tenable Research · Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

CareCam CM2507

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access live video and sensitive device information, enable unauthorized services, execute arbitrary code, modify device operation, and recover stored credentials. The following versions of CareCam CM2507 are affected: HMT.CM2507 Firmware v251211.1507 (CVE-2026-88259, CVE-2026-84398, CVE-2026-84400, CVE-2026-81305, CVE-2026-85478, CVE-2026-85497, CVE-2026-81321) CVSS Vendor Equipment Vulnerabilities v3…

CVSS 7.5 CVE-2026-81305 CVE-2026-81321 CVE-2026-84398 CVE-2026-84400 CVE-2026-85478 CVE-2026-85497 CVE-2026-88259 CareCam US

tg: zranitelnost tp: identita

· CISA Advisories · CareCam CM2507

Wärtsilä FOS-Onboard

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client. The following versions of Wärtsilä FOS-Onboard are affected: FOS-Onboard 5.07.0923.01 (CVE-2026-78225, CVE-2026-81855) CVSS Vendor Equipment Vulnerabilities v3 9.1 Wärtsilä Wärtsilä FOS-Onboard Use of Hard-coded Cryptographic Key Background Critical Infrastructure Sectors:…

EPSS 0.00 CVSS 9.1 CVE-2026-78225 CVE-2026-81855 Wärtsilä doprava US

tg: zranitelnost tp: identita tp: průmyslové systémy

· CISA Advisories · Wärtsilä FOS-Onboard

SPOJENO PŘES CVE Siemens Mendix SAML

View CSAF Summary Mendix SAML module contains a vulnerability that could allow unauthenticated remote attackers to hijack an account in specific SSO configurations. Mendix has provided fix releases for the Mendix SAML module and recommends to update to the latest version. The following versions of Siemens Mendix SAML are affected: Mendix SAML (Mendix 10 compatible) vers:intdot/<4.2.3 (CVE-2026-80465) Mendix SAML (Mendix 11 compatible) vers:intdot/<4.2.3 (CVE-2026-80465) Mendix SAML (Mendix 9.24…

EPSS 0.00 CVSS 8.7 CVE-2026-80465 Siemens výroba a průmysl US IT

tg: zranitelnost tp: identita

· CISA Advisories · Siemens Mendix SAML · CSIRT Itálie (ACN) · Siemens: risolta vulnerabilità in Mendix SAML

Schneider Electric SCADAPack x70 Products

View CSAF Summary Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communication capabilities for remote monitoring and control. Failure to apply the mitigations provided below may increase the risk of unauthorized access to RTU configuration through the Secure Lock functionality, potentially resulting in a loss of confidentiality. The…

EPSS 0.00 CVSS 6.5 CVE-2026-81861 Schneider Electric výroba a průmysl energetika US

tg: zranitelnost tp: identita tp: průmyslové systémy

· CISA Advisories · Schneider Electric SCADAPack x70 Products

Digital Watchdog VMAX DVR and NVR Product Lineups

View CSAF Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point. The following versions of Digital Watchdog VMAX DVR and NVR Product Lineups are affected: VMAX A1 G4 DVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VMAX IP G4 NVRs vers:all/* …

EPSS 0.00 CVSS 9.6 CVE-2026-66372 CVE-2026-66887 CVE-2026-66890 CVE-2026-68070 CVE-2026-68950 CVE-2026-68953 Digital Watchdog veřejná správa zdravotnictví doprava US

tg: zranitelnost tp: identita

· CISA Advisories · Digital Watchdog VMAX DVR and NVR Product Lineups

Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers

Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. As agencies adopt hybrid and multi-cloud environments, single sign-on, federation, and application programming interface (API)-based access increasingly depend on signed tokens and…

veřejná správa US

tg: návod tp: identita

· CISA Advisories · Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers

HBO Max’s verified Reddit account hijacked to spread malware

Researchers at Hudson Rock found that cybercriminals hijacked HBO Max’s verified Reddit account and used it to run 108 malicious ads over roughly 48 hours. The ads used HBO Max’s trusted corporate account to promote fake AI tools, developer software, and macOS utilities, lowering potential victims’ guards. Some ads directed users to convincing HBO lookalike sites that claimed to offer a native HBO Max app for macOS or a promotional download. But instead of providing an installer, the sites…

Reddit HBO média US

tg: incident tg: varování tp: malware tp: phishing tp: identita

· Malwarebytes Labs · HBO Max’s verified Reddit account hijacked to spread malware

Rilevate vulnerabilità nel tema WordPress “Design Scuole Italia”

Rilevate quattro vulnerabilità, di cui due con gravità “alta”, in Design Scuole Italia, noto tema WordPress destinato alla realizzazione dei siti istituzionali delle scuole italiane. Tali vulnerabilità, qualora sfruttate, potrebbero consentire ad un utente malintenzionato di leggere file arbitrari sul filesystem, eludere i meccanismi di autenticazione ed accedere a informazioni sensibili sui sistemi interessati

EPSS 0.00 CVE-2026-87791 CVE-2026-87792 CVE-2026-87793 CVE-2026-89307 WordPress Design Scuole Italia školství IT

tg: zranitelnost tp: identita

· CSIRT Itálie (ACN) · Rilevate vulnerabilità nel tema WordPress “Design Scuole Italia”

8

Upozornění na Device Code Phishing

Upozorňujeme na phishingovou kampaň zneužívající autentizační mechanismus Device Code Flow. Útočník pod záminkou připojení ke schůzce nebo videohovoru přes legitimní nástroje přiměje uživatele k autorizaci a přes kontrolovanou relaci dochází ke krádeži přístupového tokenu a následné kompromitaci uživatele.Device Code FlowDevice Code Flow je autentizační mechanismus navržený pro případy, kdy se uživatel přihlašuje na zařízení s omezenými možnostmi zadávání přihlašovacích údajů, například na…

Microsoft CZ

tg: varování tg: návod tp: phishing tp: identita

· NÚKIB · Upozornění na Device Code Phishing

Webinar: How malicious OAuth apps can lead to Google Workspace breaches

Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. [...]

Google US

tg: návod tg: propagace tp: phishing tp: identita

· BleepingComputer · Webinar: How malicious OAuth apps can lead to Google Workspace breaches

Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit

A deep technical analysis of the Smishing Triad’s JWR phishing kit and Outsider operator cluster, revealing its real-time victim control, encrypted WebSocket communications, multi-stage credential theft, AES-256-CTR implementation, infrastructure, and actionable indicators for defenders.

SG

tg: rozbor tp: phishing tp: podvod tp: identita

· Group-IB · Smish. Click. Drained: Inside the Smishing Triad’s Phishing Cockpit

6

The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)

I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of their own. What I captured was not simply credential theft, but an inference supply chain — an agent harvesting, validating, and consolidating LLM access into infrastructure that serves it again through…

US

tg: varování tg: rozbor tp: AI tp: identita

· SANS Internet Storm Ctr. · The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)

The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

IntroductionThe surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal…

US

tg: rozbor tp: podvod tp: identita

· Rapid7 · The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

7

Detect and disrupt AI-themed attacks with Microsoft Defender

Every wave of technology excitement creates a new opportunity for cyberattackers, and AI is no exception. Microsoft Threat Intelligence has published research showing a growing set of campaigns that impersonate popular AI platforms and tools, including ChatGPT, Microsoft Copilot, DeepSeek, and Claude.1 The goal is to make phishing, search-driven malware campaigns, and malvertising—which is malicious advertising that uses online ads to lure users to harmful sites, downloads, or redirect…

Microsoft US

tg: varování tg: rozbor tg: propagace tp: malware tp: phishing tp: podvod tp: identita

· Microsoft Security Blog · Detect and disrupt AI-themed attacks with Microsoft Defender

ST Engineering iDirect iQ-Series Terminals (Update A)

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected: Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058) 3315‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058) 9‑Series terminals <=4…

EPSS 0.01 CVSS 8.8 CVE-2026-38056 CVE-2026-38057 CVE-2026-38058 CVE-2026-38059 ST Engineering iDirect telekomunikace obrana energetika veřejná správa US

tg: zranitelnost tp: identita

· CISA Advisories · ST Engineering iDirect iQ-Series Terminals (Update A)

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42.

SPIFFE SPIRE US

tg: rozbor tp: identita

· Palo Alto Unit 42 · The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE