FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators gro...
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators gro...
Overview While conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulner...
Best value overall: Microsoft Defender for Endpoint — if you hold Microsoft 365 E5, you already own competitive enterprise endpoint protection and the margin...
Best value overall: Fortinet. Delivered directly and through the largest partner network in security, at price points the premium providers can’t approach pr...
Best value overall: Opinnate. It targets the gap the enterprise vendors leave open policy automation at a price mid-market organizations can actually approve...
DNS security delivers more blocked attacks per dollar than any other network control when you buy the right shape at the right tier.
Firewall-as-a-service moved from experiment to default: inspection, IPS, and policy delivered from the cloud, priced per user or per site instead of per appl...
CloudSEK has uncovered BigBear 2.
Security researchers have demonstrated how vulnerabilities in AI-powered customer service agents can be exploited to bypass identity checks, expose sensitive...
A malicious dataset exploits code-execution paths in a remote-code dataset loader and a dataset configuration before compromising access credentials to move ...
Enterprises increasingly give AI agents the credentials, tools, and network access of privileged employees, but security experts warn that existing security ...
Coder has reported a significant software supply chain incident in which an unidentified threat actor redirected part of its official module registry traffic...
Every engineering team has spent years trying to keep credentials out of source code. Then AI agents moved the problem.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploi...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerabil...
Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams.
A large-scale phishing operation is abusing trusted Google services as a multi-stage redirect network to bypass email security controls, deliver highly perso...
Another trove of data from Berlin's government has appeared online, authorities said. Germany's information security agency separately warned about the Rhysi...
The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. The post Modified ScreenConnect Clients U...
Best value overall: Ubiquiti. Published hardware pricing, no mandatory licensing, and WPA3 with VLAN segmentation included for organizations whose compliance...