Výsledky hledání

téma: identita× v celém archivu zrušit filtry

221 karet z 233 položek · strana 2 z 4 CZ · EN/orig

2

What Is ISPM? How It Differs from IAM, PAM, IGA, and IDaaS

Key Takeaways Identity Security Posture Management (ISPM) is the continuous risk and posture layer of the identity stack not a replacement for Identity and Access Management (IAM), Privileged Access Management (PAM), Identity Governance and Administration (IGA), or Identity-as-a-Service (IDaaS), but the layer that continuously assesses the exposure those systems create. IAM authenticates and authorizes, PAM secures privileged access, IGA governs the identity lifecycle, and IDaaS delivers…

US

tg: návod tg: propagace tp: identita

· Qualys · What Is ISPM? How It Differs from IAM, PAM, IGA, and IDaaS

12

SPOJENO PŘES CVE Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]

KEV ✓ EPSS 0.76 CVE-2026-20079 Cisco veřejná správa US

tg: zneužíváno tg: zranitelnost tp: identita

· BleepingComputer · Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks · CISA KEV · Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2026-20079) · Cisco PSIRT · Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

Scans for Proxmox Servers, (Wed, Sep 9th)

About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now. But it appears that the vulnerability may have caught the attention of some attackers and researchers. We do see a bump in scans for port 8006, and also some additional brute force traffic. For example, brute force requests like: POST /api2/json/access…

Proxmox US

tg: varování tg: rozbor tp: identita

· SANS Internet Storm Ctr. · Scans for Proxmox Servers, (Wed, Sep 9th)

Passkey-themed social engineering leads to identity and cloud compromise

In this article Attack chain overviewAttributionMitigation and protection guidanceLearn more Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs. Microsoft Security Research assesses that this sequence is consistent with automated collection from…

Microsoft US

tg: varování tg: rozbor tp: phishing tp: únik dat tp: identita

· Microsoft Security Blog · Passkey-themed social engineering leads to identity and cloud compromise

Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it

If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them.Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating policy, depends on the answer being right. The traditional answer comes from the outside: the scan engine sends traffic to a range of ports and infers each port's state from how the host responds. That…

US

tg: novinka v produktu tg: návod tp: identita

· Rapid7 · Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it

The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords

The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April. Claude Mythos Preview identified thousands of previously unknown flaws across every major operating system and browser, including a 27-year-old denial-of-service condition in OpenBSD, and within a month Anthropic and its Project Glasswing partners had logged more than 10,000 high and critical severity findings, among them a certificate forgery flaw in wolfSSL, a…

OpenAI Anthropic Hugging Face US

tg: incident tg: rozbor tp: AI tp: identita

· Qualys · The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords

MFA's Weakest Link: Account Recovery Is the New Attack Path

MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]

US

tg: návod tg: propagace tp: phishing tp: identita

· BleepingComputer · MFA's Weakest Link: Account Recovery Is the New Attack Path

SPOJENO PŘES CVE Kritisk sårbarhet i Citrix NetScaler ADC och NetScaler Gateway

Citrix har publicerat information om en kritisk sårbarhet som påverkar Citrix NetScaler ADC och NetScaler Gateway. Sårbarheten, CVE-2026-19490, har fått CVSS v.4-klassning på 9.3. [1, 2]

KEV ✓ EPSS 0.06 CVSS 9.3 CVE-2026-19490 Citrix SE US

tg: zneužíváno tg: zranitelnost tp: identita

· CERT-SE · Kritisk sårbarhet i Citrix NetScaler ADC och NetScaler Gateway · CISA KEV · Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2026-19490) · BleepingComputer · Critical Citrix NetScaler auth bypass now leveraged in attacks · Rapid7 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway

NCSC-2026-0357 [1.00] [M/H] Kwetsbaarheid verholpen in Ivanti Sentry

Ivanti heeft een kwetsbaarheid verholpen in Sentry versies voorafgaand aan R10.8.2, R10.7.3 en R10.6.4. De kwetsbaarheid betreft een authenticatie-bypass die het mogelijk maakt voor externe aanvallers zonder authenticatie om administratieve toegang tot het systeem te verkrijgen. Deze kwetsbaarheid treft meerdere releases van het Sentry-platform en kan leiden tot ongeautoriseerde controle over administratieve functies.

Ivanti NL

tg: zranitelnost tp: identita

· NCSC-NL · NCSC-2026-0357 [1.00] [M/H] Kwetsbaarheid verholpen in Ivanti Sentry

NCSC-2026-0356 [1.00] [M/H] Kwetsbaarheden verholpen in diverse SAP-producten

SAP heeft kwetsbaarheden verholpen in SAP Extended Passport Protocol (EPP) processing library, SAP NetWeaver Message Server, @sap/cds-mtxs NPM library, SAP GUI for Java, SAP ABAP Development Tools voor SAP NetWeaver AS ABAP, SAP Integration Suite, SAP NetWeaver Business Client, SAP Web Dispatcher, Internet Communication Manager, SAP Content Server, SAP S/4HANA Intercompany Matching and Reconciliation module, en SAP Manufacturing Integration and Intelligence. De kwetsbaarheid met kenmerk CVE…

EPSS 0.00 CVE-2026-44756 CVE-2026-58240 CVE-2026-66768 CVE-2026-76969 SAP NL

tg: zranitelnost tp: identita

· NCSC-NL · NCSC-2026-0356 [1.00] [M/H] Kwetsbaarheden verholpen in diverse SAP-producten

ZDI-26-629: Microsoft Azure Entra ID OAuth Device Code Grant Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.8.

CVSS 5.8 Microsoft US

tg: zranitelnost tp: identita

· Zero Day Initiative · ZDI-26-629: Microsoft Azure Entra ID OAuth Device Code Grant Information Disclosure Vulnerability

Security Advisory Ivanti Sentry (CVE-2026-83527)

Classification: Severe, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.0: 8.1, CVEs: CVE-2026-83527, Summary: Ivanti has released updates for Ivanti Sentry that address one high severity vulnerability. This vulnerability impacts deployments managed by EPMM and Ivanti Neurons for MDM. We are not aware of any customers being exploited by this vulnerability at the time of disclosure. CVE-2026-83527 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS:3.0 8.1 An Authentication Bypass…

EPSS 0.01 CVSS 8.1 CVE-2026-83527 Ivanti FI

tg: zranitelnost tg: novinka v produktu tp: identita

· NCSC-FI · Security Advisory Ivanti Sentry (CVE-2026-83527)

FortiMonitorOnSight JWT used for authentication in web GUI signed with static key

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.6, CVEs: CVE-2026-84390, Summary: An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT

EPSS 0.01 CVSS 9.6 CVE-2026-84390 Fortinet FI

tg: zranitelnost tp: identita

· NCSC-FI · FortiMonitorOnSight JWT used for authentication in web GUI signed with static key

38

NCSC-2026-0349 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Exchange server

Microsoft heeft 9 kwetsbaarheden verholpen in Exchange Server. Een kwaadwillende kan de kwetsbaarheden misbruiken om een Denial-of-Service uit te voeren, zich voor te doen als andere gebruiker, zich verhoogde rechten toe te kennen, willekeurige code uit te voeren en/of toegang te krijgen tot gevoelige gegevens. De ernstigste kwetsbaarheid met kenmerk CVE-2026-69380 heeft een CVSS-score van 9,9 en betreft een autorisatiekwetsbaarheid. Een geauthenticeerde kwaadwillende met beperkte rechten en…

EPSS 0.01 CVE-2026-55007 CVE-2026-69355 CVE-2026-69356 CVE-2026-69361 CVE-2026-69375 CVE-2026-69378 CVE-2026-69380 CVE-2026-69382 CVE-2026-69641 Microsoft NL

tg: zranitelnost tp: identita

· NCSC-NL · NCSC-2026-0349 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Exchange server

NCSC-2026-0347 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Azure

Microsoft heeft 4 kwetsbaarheden verholpen in diverse Azure componenten. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade, zoals genoemd in onderstaande tabel. De kwetsbaarheid met kenmerk CVE-2026-69854 heeft een CVSS-score van 9,0. Een kwaadwillende die al over een geldige sessie beschikt, kan de kwetsbaarheid onder specifieke voorwaarden, zoals bepaalde protocolinstellingen of configuraties, misbruiken om zijn rechten…

EPSS 0.01 CVE-2026-62895 CVE-2026-69854 CVE-2026-77909 CVE-2026-81961 Microsoft NL

tg: zranitelnost tp: identita

· NCSC-NL · NCSC-2026-0347 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Azure

Commvault security advisory (AV26-895)

Serial Number: AV26-895Date: September 8, 2026 As of September 8, 2026, Commvault is affected by vulnerabilities in the following product: Commvault Cloud 11.36.0 Prior to 11.36.123 11.40.0 Prior to 11.40.72 11.44.0 Prior to 11.44.20 11.46.0 Prior to 11.46.20 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CV_2026_07_1: Command Center API Authentication Bypass Commvault Cloud Security Advisories

Commvault CA

tg: zranitelnost tp: identita

· Cyber Centre Kanada · Commvault security advisory (AV26-895)

Webinar: The forgotten Google Workspace access that can lead to a breach

Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure. [...]

Google US

tg: návod tg: propagace tp: identita

· BleepingComputer · Webinar: The forgotten Google Workspace access that can lead to a breach

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan,…

PyPI npm Docker GitHub zdravotnictví veřejná správa média US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: AI tp: identita

· Mandiant / Google TI · GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

CareCam Pro IP Cameras

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083) CVSS Vendor Equipment Vulnerabilities v3 6.8 CareCam CareCam Pro IP Cameras Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Commercial Facilities Countries…

EPSS 0.00 CVSS 6.8 CVE-2026-85083 CareCam US

tg: zranitelnost tp: identita

· CISA Advisories · CareCam Pro IP Cameras

CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

OverviewWhile conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.CVE IDDescriptionCWECVSSv4CVE-2026-86206Semicolon/Forwarded access-control bypassCWE…

KEV ✓ EPSS 0.54 CVE-2026-18577 CVE-2026-86206 CVE-2026-86207 N-able US

tg: zranitelnost tg: rozbor tp: identita

· Rapid7 · CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

SPOJENO PŘES CVE MikroTik router flaws allow takeover without a password

CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet. Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet. Attackers are exploiting two…

KEV ✓ EPSS 0.01 CVSS 9.2 CVE-2026-67276 CVE-2026-86060 MikroTik US HR IT

tg: zneužíváno tg: zranitelnost tg: návod tp: identita

· Malwarebytes Labs · MikroTik router flaws allow takeover without a password · CERT.hr · Upozorenj: kritična ranjivosti u MikroTik RouterOS-u. Preporučuje se hitna nadogradnja. · CSIRT Itálie (ACN) · MikroTik: rilevato sfruttamento in rete di nuove vulnerabilità

NCSC-2026-0345 [1.00] [M/H] Kwetsbaarheden verholpen in MikroTik RouterOS

MikroTik heeft meerdere kwetsbaarheden verholpen in RouterOS. De eerste kwetsbaarheid betreft een fout in de SSH-authenticatiemechanisme waarbij de exponent van RSA-sleutels niet werd geverifieerd. Hierdoor kunnen aanvallers RSA-handtekeningen vervalsen en ongeautoriseerde SSH-toegang verkrijgen. De tweede kwetsbaarheid betreft een probleem met gebruikersnamen die beginnen met een verboden teken, waardoor de trusted policy mask kan worden gemanipuleerd en privilege escalation mogelijk is binnen…

MikroTik NL

tg: zneužíváno tg: zranitelnost tp: identita

· NCSC-NL · NCSC-2026-0345 [1.00] [M/H] Kwetsbaarheden verholpen in MikroTik RouterOS

AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance

Active Directory Rights Management Services still ships in Windows Server 2025, years after Microsoft began steering customers to the cloud, and it remains fully supported on-premises. Part 1 maps the AD RMS trust model (the Server Licensor Certificate, the license flow, the SOAP surface) and shows how to discover an RMS deployment, fingerprint an AD RMS-protected file, and trace the path to that certificate's private key.

Microsoft US

tg: rozbor tp: identita

· Huntress · AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance

4

Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

This week on the Lock and Code podcast… Crooks are taking a holiday. They’re counting on you to fund it. For decades, cybercriminals have stolen roughly the same types of data. Biographical and personal details—like Social Security numbers, birthdates, addresses, and phone numbers—can be stolen to commit identity fraud. Credit card numbers, expiration dates, and CVC codes can be stolen to make fraudulent purchases. Usernames and passwords can, in the wrong hands, let a cybercriminal impersonate…

US

tg: rozbor tg: propagace tg: přehled tp: podvod tp: identita

· Malwarebytes Labs · Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

Upozorenje: WhatsApp prijevara “Glasajte za moje dijete”

Nacionalni CERT zaprimio je prijave o phishing (smishing) prijevari putem preuzetog WhatsApp računa te je prijavio prijevare izvorima incidenta i nadležnim CERT timovima. Primjer WhatsApp poruke: Sadržaj lažnih WhatsApp poruka je: “Glasajte za … dijete na natjecanju”Možete primiti poruku od poznate osobe s poveznicom za glasovanje na natjecanju. Nakon klika traži se unos broja mobitela te kôda – time prevarantu nesvjesno dajete pristup svom WhatsApp računu i omogućavate širenje lažnih poruka…

WhatsApp HR

tg: varování tp: phishing tp: podvod tp: identita

· CERT.hr · Upozorenje: WhatsApp prijevara “Glasajte za moje dijete”

1

Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed. The patch will attempt to detect compromise and set the "Flagged" status. Details: https://mikrotik.com/supportsec/september-2026-vulnerability -- Johannes B. Ullrich, Ph.D. , Dean of…

MikroTik US

tg: zneužíváno tg: zranitelnost tp: identita

· SANS Internet Storm Ctr. · Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

3

SPOJENO PŘES CVE AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

Number: AL26-019Date: September 4, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre…

KEV ✓ EPSS 0.06 CVSS 9.3 CVE-2026-19489 CVE-2026-19490 Citrix CA IT NL FI FR

tg: zranitelnost tp: identita

· Cyber Centre Kanada · AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489 · CSIRT Itálie (ACN) · Vulnerabilità in prodotti Citrix · NCSC-NL · NCSC-2026-0318 [1.00] [M/M] Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gateway · NCSC-FI · Citrix Netscaler ADC ja Gateway -tuotteissa kriittisiä haavoittuvuuksia · CERT-FR – avis · Multiples vulnérabilités dans les produits Citrix (20 août 2026)