❌

Vue normale

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.
Hier — 6 octobre 2026IT

DNS root key rollover: check your resolver before October 11

Par : IT News
6 octobre 2026 à 20:29
DNS root key rollover: check your resolver before October 11
The DNS root’s signing key is scheduled to change on October 11, 2026, and a resolver that has not trusted the replacement could make otherwise healthy websites unreachable. The new key, KSK-2024 (key tag 38696), has been published since January 2025; now operators can test whether their resolver recognizes it. Most website operators do not need to act, but DNSSEC resolver operators should verify readiness.

Source

IBM expands IBM Z networking with 100GbE and on-chip I/O

Par : IT News
5 octobre 2026 à 21:29
IBM expands IBM Z networking with 100GbE and on-chip I/O
IBM is pushing IBM Z further into hybrid data centers with two-port 100GbE connectivity and networking options that combine standard Ethernet with high-speed RDMA. The changes aim to move more data with less latency while reducing the adapters and I/O hardware customers need. That also helps keep sensitive transactional data close to AI workloads running on or alongside the mainframe.

Source

À partir d’avant-hierIT

Microsoft Titan exposed 17 trillion rows as NetScaler zero-days spread

Par : IT News
5 octobre 2026 à 12:21
Microsoft Titan exposed 17 trillion rows as NetScaler zero-days spread
A flaw in Microsoft’s Titan analytics service potentially exposed employee records and Bing search data across a system holding roughly 17 trillion rows. Meanwhile, attackers exploited two Citrix NetScaler zero-days to install web shells, with Mandiant linking early attacks on one flaw to suspected state-backed actors.

Source

Citrix NetScaler DoS flaw is under active attack—SAML setups need another patch

Par : IT News
5 octobre 2026 à 12:21
Citrix NetScaler DoS flaw is under active attack—SAML setups need another patch
Attackers are exploiting CVE-2026-88779 to knock vulnerable NetScaler ADC and Gateway appliances offline. The warning comes days after emergency fixes for other NetScaler zero-days; this flaw affects customer-managed appliances using SAML and requires a separate update.

Source

Azure outage eases, but five regions still show gateway issues

Par : IT News
1 octobre 2026 à 16:54
Azure outage eases, but five regions still show gateway issues
Microsoft says most regions affected by an Azure network outage are recovering, but five still show impact as the company investigates a disruption tied to infrastructure servicing. The September 30 incident affected ExpressRoute and VPN gateways, Azure VMware Solution, and other network services across 18 regions.

Source

CISA flags critical MikroTik RouterOS flaw that can hand over root access

Par : IT News
30 septembre 2026 à 21:29
CISA flags critical MikroTik RouterOS flaw that can hand over root access
CISA has warned that a pre-authentication flaw in MikroTik RouterOS can let an unauthenticated attacker run code as root or knock a device offline with one crafted HTTP request. The alert lands days after CISA first put MikroTik RouterOS on its exploited-vulnerabilities list, but this new advisory spells out the bug as an integer underflow in the web-management service and says there is no evidence of active exploitation yet.

Source

NetScaler attackers turn zero-day access into WHIPSHOT and SLAPSHOT foothold

Par : IT News
30 septembre 2026 à 15:20
NetScaler attackers turn zero-day access into WHIPSHOT and SLAPSHOT foothold
Unknown attackers are moving beyond initial NetScaler compromise and using root access to plant two new payloads, WHIPSHOT and SLAPSHOT, on Citrix ADC and Gateway appliances. The campaign builds on the same ongoing NetScaler exploitation that has already hit organizations across North America and Europe, but now shows how intruders are modifying appliance configs to keep control and pivot deeper into internal networks.

Source

Citrix NetScaler zero-day attacks add web shells, root access and tunneling malware

Par : IT News
29 septembre 2026 à 22:38
Citrix NetScaler zero-day attacks add web shells, root access and tunneling malware
Citrix NetScaler zero-day exploitation is escalating from patch alerts to full post-compromise tradecraft: attackers are using CVE-2026-88772 and the separately exploited CVE-2026-88771 to plant web shells, gain root access, steal credentials and move into internal networks. The campaign, already flagged in earlier 4sysops coverage of the NetScaler RCE flaws, now appears to have been active since at least early September across government, finance, education, legal and professional-services targets.

Source

CISA confirms global attacks on eight Citrix NetScaler flaws

Par : IT News
28 septembre 2026 à 16:16
CISA confirms global attacks on eight Citrix NetScaler flaws
CISA says attackers are exploiting globally the two NetScaler RCE zero-days Citrix disclosed this weekend. The urgent alert expands the risk to eight vulnerabilities, including a third critical flaw that can bypass front-end security controls through HTTP request smuggling.

Source

Citrix patches two NetScaler RCE zero-days after attacks began

Par : IT News
27 septembre 2026 à 21:25
Citrix patches two NetScaler RCE zero-days after attacks began
Citrix has patched two critical NetScaler ADC and NetScaler Gateway vulnerabilities that attackers were already exploiting before fixes became available. CVE-2026-88771 enables unauthenticated command execution across affected deployments, while CVE-2026-88772 can provide remote code execution or cause denial of service when DTLS is enabled.

Source

Huawei’s UnifiedBus targets the networking bottleneck in agentic AI

Par : IT News
24 septembre 2026 à 14:02
Huawei’s UnifiedBus targets the networking bottleneck in agentic AI
Huawei is shifting its AI infrastructure pitch from faster accelerators to faster connections between them. At Huawei Connect 2026, the company introduced UnifiedBus alongside the Atlas 960E SuperPoD, claiming the architecture can reduce latency, increase bandwidth tenfold, and scale systems for massive agentic-AI workloads.

Source

Microsoft confirms September Windows updates can break Always On VPN

Par : IT News
23 septembre 2026 à 19:36
Microsoft confirms September Windows updates can break Always On VPN
Microsoft has confirmed that the September 2026 Windows 11 updates can disrupt Always On VPN, expanding the certificate-authentication failures reported after KB5124008 was deployed. The company is investigating the newly acknowledged connection problem, which can leave enterprise devices unable to establish their automatic VPN tunnel.

Source

80% of network professionals are ready to give AI autonomy

Par : IT News
23 septembre 2026 à 17:27
80% of network professionals are ready to give AI autonomy
Cisco’s survey of 1,000 IT and network leaders found that 80% are comfortable giving AI a high or fully autonomous role in network operations. While 56% still require human approval, 24% would allow agents to act without oversight, and 84% expect an AI-led operating model within a year.

Source

InfraTrust finds attackers targeting the consoles behind enterprise networks

Par : IT News
23 septembre 2026 à 17:27
InfraTrust finds attackers targeting the consoles behind enterprise networks
Eclypsium’s latest InfraTrust report warns that attackers are increasingly targeting management consoles rather than the firewalls, switches, and routers they control. The September report tracked 158 advisories across 17 vendors, including 71 remotely exploitable flaws requiring no authentication—an escalation from the initial InfraTrust risk database launched in July.

Source

VMware pulls SmartNIC firewall as customer demand stalls

Par : IT News
21 septembre 2026 à 11:49
VMware pulls SmartNIC firewall as customer demand stalls
VMware has stopped selling its SmartNIC-based distributed firewall after customers showed interest but failed to buy, marking a retreat from the company’s push to bring hyperscaler-style hardware acceleration to private clouds. The Distributed Services Engine remains supported in Cloud Foundation, so existing SmartNIC integrations are not being abandoned outright.

Source

Check Point rushes LivePatch for critical Security Management flaw

Par : IT News
18 septembre 2026 à 10:56
Check Point rushes LivePatch for critical Security Management flaw
Check Point is urging immediate patching for CVE-2026-91843, a critical flaw in Security Management and Log Servers that can let attackers execute code as root through an oversized login username. The vulnerability affects R82.20, standalone deployments, Log Servers, and Multi-Domain systems; Check Point says there is no evidence of exploitation, but R82.20 has no protective Jumbo Hotfix yet.

Source

Cisco rushes patches for actively exploited CVSS 10 ISE zero-day

Par : IT News
18 septembre 2026 à 10:56
Cisco rushes patches for actively exploited CVSS 10 ISE zero-day
Cisco has released emergency fixes for CVE-2026-76460 after confirming that the Cisco ISE zero-day is under active attack. The maximum-severity flaw lets unauthenticated remote attackers bypass web management authentication and potentially obtain root access, making immediate patching a priority.

Source

BIND 9.20.29 fixes 14 flaws, including a one-request DoH crash

Par : IT News
17 septembre 2026 à 18:43
BIND 9.20.29 fixes 14 flaws, including a one-request DoH crash
BIND 9.20.29 and 9.21.26 fix 14 security vulnerabilities, including a high-severity flaw that lets an unauthenticated attacker crash the `named` DNS process through a single malicious DNS-over-HTTPS request. ISC says it has seen no active exploitation, but administrators should upgrade because the release also addresses resolver crashes, resource exhaustion, DNSSEC validation errors, and unauthorized zone data.

Source

❌
❌