❌

Vue lecture

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.

Azure outage eases, but five regions still show gateway issues

Azure outage eases, but five regions still show gateway issues
Microsoft says most regions affected by an Azure network outage are recovering, but five still show impact as the company investigates a disruption tied to infrastructure servicing. The September 30 incident affected ExpressRoute and VPN gateways, Azure VMware Solution, and other network services across 18 regions.

Source

CISA flags critical MikroTik RouterOS flaw that can hand over root access

CISA flags critical MikroTik RouterOS flaw that can hand over root access
CISA has warned that a pre-authentication flaw in MikroTik RouterOS can let an unauthenticated attacker run code as root or knock a device offline with one crafted HTTP request. The alert lands days after CISA first put MikroTik RouterOS on its exploited-vulnerabilities list, but this new advisory spells out the bug as an integer underflow in the web-management service and says there is no evidence of active exploitation yet.

Source

NetScaler attackers turn zero-day access into WHIPSHOT and SLAPSHOT foothold

NetScaler attackers turn zero-day access into WHIPSHOT and SLAPSHOT foothold
Unknown attackers are moving beyond initial NetScaler compromise and using root access to plant two new payloads, WHIPSHOT and SLAPSHOT, on Citrix ADC and Gateway appliances. The campaign builds on the same ongoing NetScaler exploitation that has already hit organizations across North America and Europe, but now shows how intruders are modifying appliance configs to keep control and pivot deeper into internal networks.

Source

Citrix NetScaler zero-day attacks add web shells, root access and tunneling malware

Citrix NetScaler zero-day attacks add web shells, root access and tunneling malware
Citrix NetScaler zero-day exploitation is escalating from patch alerts to full post-compromise tradecraft: attackers are using CVE-2026-88772 and the separately exploited CVE-2026-88771 to plant web shells, gain root access, steal credentials and move into internal networks. The campaign, already flagged in earlier 4sysops coverage of the NetScaler RCE flaws, now appears to have been active since at least early September across government, finance, education, legal and professional-services targets.

Source

Citrix patches two NetScaler RCE zero-days after attacks began

Citrix patches two NetScaler RCE zero-days after attacks began
Citrix has patched two critical NetScaler ADC and NetScaler Gateway vulnerabilities that attackers were already exploiting before fixes became available. CVE-2026-88771 enables unauthenticated command execution across affected deployments, while CVE-2026-88772 can provide remote code execution or cause denial of service when DTLS is enabled.

Source

InfraTrust finds attackers targeting the consoles behind enterprise networks

InfraTrust finds attackers targeting the consoles behind enterprise networks
Eclypsium’s latest InfraTrust report warns that attackers are increasingly targeting management consoles rather than the firewalls, switches, and routers they control. The September report tracked 158 advisories across 17 vendors, including 71 remotely exploitable flaws requiring no authentication—an escalation from the initial InfraTrust risk database launched in July.

Source

VMware pulls SmartNIC firewall as customer demand stalls

VMware pulls SmartNIC firewall as customer demand stalls
VMware has stopped selling its SmartNIC-based distributed firewall after customers showed interest but failed to buy, marking a retreat from the company’s push to bring hyperscaler-style hardware acceleration to private clouds. The Distributed Services Engine remains supported in Cloud Foundation, so existing SmartNIC integrations are not being abandoned outright.

Source

Check Point rushes LivePatch for critical Security Management flaw

Check Point rushes LivePatch for critical Security Management flaw
Check Point is urging immediate patching for CVE-2026-91843, a critical flaw in Security Management and Log Servers that can let attackers execute code as root through an oversized login username. The vulnerability affects R82.20, standalone deployments, Log Servers, and Multi-Domain systems; Check Point says there is no evidence of exploitation, but R82.20 has no protective Jumbo Hotfix yet.

Source

BIND 9.20.29 fixes 14 flaws, including a one-request DoH crash

BIND 9.20.29 fixes 14 flaws, including a one-request DoH crash
BIND 9.20.29 and 9.21.26 fix 14 security vulnerabilities, including a high-severity flaw that lets an unauthenticated attacker crash the `named` DNS process through a single malicious DNS-over-HTTPS request. ISC says it has seen no active exploitation, but administrators should upgrade because the release also addresses resolver crashes, resource exhaustion, DNSSEC validation errors, and unauthorized zone data.

Source

Microsoft Entra Private Access offers a phased path beyond VPNs

Microsoft Entra Private Access offers a phased path beyond VPNs
Microsoft is outlining a practical route for replacing traditional VPN access with Microsoft Entra Private Access, using identity, device health, and application-level policies instead of broad network tunnels. The phased approach starts with discovering VPN-dependent resources and ends with incremental decommissioning, helping administrators modernize remote access without disrupting critical applications.

Source

❌