Browsing Tag
Enterprise Security
29 posts
Security issues affecting enterprise software, IT systems, identity, observability, and business infrastructure.
EU Cyber Resilience Act Puts Product Security Teams on a 24-Hour Clock
The EU Cyber Resilience Act’s vulnerability-reporting duties start September 11, forcing makers of connected devices and commercial software to report actively exploited flaws quickly. Product teams should treat the deadline as an operational change, not a paperwork exercise.
Adobe Commerce Zero-Day Turns Online Stores Into Backdoor Targets
Adobe has issued an emergency hotfix for CVE-2026-75650, a critical Adobe Commerce and Magento Open Source flaw already exploited in the wild. Merchants should patch, confirm the hotfix, inspect for backdoors, and rotate more than the Magento encryption key.
Ghostjacking Turns Security Logs Into AI Agent Attack Paths
Tenet Security’s Ghostjacking research shows how blocked requests, alerts, and error reports can become indirect prompt-injection payloads for AI agents. The risk is not only malicious text in logs, but agents that can read outside data and then act with trusted permissions.
N-able N-central Hotfix Turns RMM Servers Into an Incident Response Drill
N-able has released a second required hotfix for an actively exploited N-central authentication-bypass flaw. For MSPs and enterprise IT teams, the work is not only upgrading to 2026.3.1.10, but also checking Take Control sessions, Cloudflare Tunnel persistence, and downstream endpoints before treating the RMM platform as trusted again.
Rails Active Storage Flaw Turns Image Uploads Into a Secret-Rotation Drill
Rails maintainers patched CVE-2026-66066, a critical Active Storage flaw that can let attackers turn image uploads into arbitrary file reads and possible remote code execution. For affected teams, the job is not only upgrading Rails and libvips, but checking exposure windows and rotating secrets that may have been readable by the Rails process.
Microsoft Project Perception Puts AI Agents on the Security Patch Path
Microsoft’s Project Perception enters public preview August 3 with MAI-Cyber-1-Flash inside MDASH, promising lower-cost vulnerability discovery and agentic security workflows. The important question is how much action enterprises should let AI security agents take.
Check Point SmartConsole Zero-Day Puts Firewall Management on Patch Deadline
Check Point has patched CVE-2026-16232, an actively exploited SmartConsole authentication bypass that can give attackers full administrator access to exposed Security Management servers. The urgent work is not only installing the Jumbo Hotfix, but also restricting Trusted Clients and checking management logs for signs of compromise.
ACR Stealer Turns ClickFix Lures Into Browser-Token Theft
Microsoft says ACR Stealer activity rose across customer environments from late April to mid-June, with campaigns using ClickFix lures, WebDAV, MSHTA, obfuscated PowerShell, and even JPEG-hidden payloads. Security teams should treat infections as token and document-exposure events, not just password resets.
Zoom’s Windows Account-Takeover Bug Makes Client Updates an Admin Priority
Zoom has patched CVE-2026-53412, a critical Windows client flaw that could let an unauthenticated attacker take over accounts over the network. The practical response is to verify Zoom Workplace and VDI client versions, not just assume auto-update has reached every endpoint.
SharePoint’s New Exploited RCE Turns Patching Into Key Rotation Triage
CISA added Microsoft SharePoint Server CVE-2026-58644 to its exploited-vulnerabilities catalog on July 16, two days after Microsoft patched it. Admins should patch, verify AMSI, hunt for machine-key theft, and reduce internet exposure before treating the farm as clean.