<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CipherWatch — Security Assessment &amp; Testing</title><description>Security intelligence covering Security Assessment &amp; Testing: Vulnerability assessment, penetration testing, audit strategies, and security metrics.</description><link>https://cipherwatch.io/</link><language>en-gb</language><item><title>Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8): ShinyHunters Exploit Zero-Day to Breach University Student Records at Scale</title><link>https://cipherwatch.io/articles/2026-06-15-oracle-peoplesoft-cve-2026-35273-shinyhunters-universities/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-15-oracle-peoplesoft-cve-2026-35273-shinyhunters-universities/</guid><description>A critical zero-day vulnerability in Oracle PeopleSoft Campus Solutions — CVE-2026-35273, CVSS 9.8 — has been exploited by the ShinyHunters threat group to breach student record systems at multiple universities across the US, UK, and Australia. The flaw allows unauthenticated attackers to bypass authentication in the PeopleSoft web application layer, granting direct access to student enrolment, financial aid, and academic records.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>oracle</category><category>peoplesoft</category><category>cve-2026-35273</category><category>zero-day</category><category>shinyhunters</category><category>higher-education</category><category>student-data</category><category>ferpa</category><category>gdpr</category></item><item><title>SAP Landscape Security Assessment: Managing NetWeaver Vulnerabilities Across Enterprise ERP Environments</title><link>https://cipherwatch.io/articles/2026-06-12-sap-landscape-security-assessment-netweaver/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-12-sap-landscape-security-assessment-netweaver/</guid><description>CVE-2026-44748 (CVSS 9.9) in SAP NetWeaver ABAP is the second critical SAP vulnerability of 2026 affecting SAML authentication. Enterprise organisations running complex SAP landscapes with multiple NetWeaver instances face challenges in identifying which systems are affected, prioritising patching across landscape tiers, and assessing whether compromise indicators are present.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>sap</category><category>netweaver</category><category>abap</category><category>cve-2026-44748</category><category>saml</category><category>security-assessment</category><category>erp-security</category><category>vulnerability-assessment</category><category>enterprise-applications</category></item><item><title>CVE-2026-23111 Detection and Hardening Guide: Protecting Linux Environments from the nf_tables Exploit</title><link>https://cipherwatch.io/articles/2026-06-11-linux-cve-2026-23111-nftables-detection-hardening/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-11-linux-cve-2026-23111-nftables-detection-hardening/</guid><description>With public proof-of-concept code available for CVE-2026-23111, security teams running Linux across production, containerised, and cloud environments need specific detection and hardening guidance. This guide covers kernel patch availability by distribution, interim mitigations, eBPF-based detection, and Kubernetes-specific containment measures.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>linux-kernel</category><category>nftables</category><category>cve-2026-23111</category><category>detection</category><category>hardening</category><category>kubernetes</category><category>containers</category><category>privilege-escalation</category><category>ebpf</category><category>security-assessment</category></item><item><title>CISA Adds Chrome V8 Zero-Day, Cisco SD-WAN, and Arista EOS to Known Exploited Vulnerabilities Catalogue</title><link>https://cipherwatch.io/articles/2026-06-09-cisa-kev-june-9-chrome-cisco-arista/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-09-cisa-kev-june-9-chrome-cisco-arista/</guid><description>CISA added three vulnerabilities to the KEV catalogue on 9 June: Google Chrome CVE-2026-11645 (V8 out-of-bounds write, actively exploited), Cisco SD-WAN CVE-2026-20245 (authentication bypass), and Arista EOS CVE-2026-7473 (privilege escalation command injection). Federal agencies face a 30 June remediation deadline across all three.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>cisa-kev</category><category>chrome</category><category>cve-2026-11645</category><category>cisco</category><category>sd-wan</category><category>arista</category><category>eos</category><category>vulnerability-management</category><category>remediation-deadline</category><category>2026</category></item><item><title>Assessing Network Perimeter Device Security: A Methodology for Firewalls, VPN Gateways, and Load Balancers</title><link>https://cipherwatch.io/articles/2026-06-07-perimeter-device-security-assessment-methodology/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-07-perimeter-device-security-assessment-methodology/</guid><description>Network perimeter devices — firewalls, VPN gateways, and load balancers — are the most frequently exploited initial access category in enterprise breaches. Despite this, they are often excluded from regular security assessments. This methodology covers how to assess the security posture of perimeter network devices without disrupting production operations.</description><pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate><category>network-appliances</category><category>security-assessment</category><category>firewall</category><category>vpn</category><category>perimeter-security</category><category>vulnerability-management</category><category>configuration-audit</category><category>check-point</category></item><item><title>CISA KEV June 2026 Tracker: Vulnerability Additions, BOD 22-01 Deadlines, and Remediation Priorities</title><link>https://cipherwatch.io/articles/2026-06-05-cisa-kev-june-2026-tracker-remediation-guidance/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-05-cisa-kev-june-2026-tracker-remediation-guidance/</guid><description>The CISA Known Exploited Vulnerabilities catalogue added three entries in the first week of June 2026, including the Oracle WebLogic deserialization vulnerability (CVE-2024-21182) and the Mirasvit Magento RCE (CVE-2026-45247). This tracker consolidates the June additions with their remediation deadlines and documents the patch availability status for each.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>cisa-kev</category><category>vulnerability-management</category><category>bod-22-01</category><category>remediation</category><category>patch-management</category><category>june-2026</category><category>compliance</category></item><item><title>CVE-2026-46243: Identifying Affected Systems and Detecting Exploitation Attempts</title><link>https://cipherwatch.io/articles/2026-06-03-linux-cifs-cve-2026-46243-detection-affected-systems/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-03-linux-cifs-cve-2026-46243-detection-affected-systems/</guid><description>With a public proof-of-concept available and patched kernels in distribution repositories, security teams need a systematic approach to identify which Linux systems in their environment are exposed to CVE-2026-46243 and whether any exploitation activity has occurred. This guide covers detection queries, affected system identification, and temporary mitigation steps for environments that cannot patch immediately.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>linux</category><category>cve-2026-46243</category><category>cifs</category><category>detection</category><category>vulnerability-assessment</category><category>lpe</category><category>audit</category><category>kernel-patch</category></item><item><title>ServiceNow Security Assessment: Auditing API Exposure and Access Control Configuration</title><link>https://cipherwatch.io/articles/2026-06-02-servicenow-security-assessment-api-exposure-audit/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-02-servicenow-security-assessment-api-exposure-audit/</guid><description>Following the ServiceNow API breach, organisations should conduct a targeted security assessment of their ServiceNow instance, focusing on API endpoint exposure, unauthenticated access paths, ACL configuration, and service account privilege scope. This assessment guide covers the key checks and how to perform them without specialist ServiceNow security tooling.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>servicenow</category><category>security-assessment</category><category>api-audit</category><category>access-control</category><category>itsm</category><category>saas-security</category><category>acl</category><category>vulnerability-assessment</category></item><item><title>Oracle WebLogic Security Assessment Guide: Discovering Exposure Before the Next T3 Exploit</title><link>https://cipherwatch.io/articles/2026-06-01-oracle-weblogic-security-assessment-enterprise/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-01-oracle-weblogic-security-assessment-enterprise/</guid><description>Enterprise Java middleware is often the least-assessed component of the application security programme. Oracle WebLogic installations are frequently discovered during incident response rather than proactive inventory. This guide covers the discovery, assessment, and continuous monitoring steps for WebLogic security.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>oracle</category><category>weblogic</category><category>security-assessment</category><category>middleware</category><category>enterprise-java</category><category>vulnerability-assessment</category><category>asset-discovery</category></item><item><title>Windows Domain Controller Security Monitoring: Building an Event Log Detection Baseline</title><link>https://cipherwatch.io/articles/2026-05-31-windows-dc-security-monitoring-event-log-baseline/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-31-windows-dc-security-monitoring-event-log-baseline/</guid><description>Effective detection of domain controller attacks requires more than collecting logs — it requires specific audit policy configuration, a curated set of detection rules, and a SIEM pipeline with alert response SLAs. This guide covers the complete baseline configuration for DC security monitoring after CVE-2026-41089 highlighted the importance of pre-compromise visibility.</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>windows</category><category>domain-controller</category><category>security-monitoring</category><category>event-logs</category><category>siem</category><category>active-directory</category><category>audit-policy</category><category>detection-engineering</category></item><item><title>Zero-Day Response Maturity: Assessing Your Organisation&apos;s Capability Against May 2026&apos;s Vulnerability Cluster</title><link>https://cipherwatch.io/articles/2026-05-30-zero-day-response-maturity-assessment-framework/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-30-zero-day-response-maturity-assessment-framework/</guid><description>May 2026 produced multiple simultaneous zero-days and CVSS 9.0+ vulnerabilities with active exploitation. The month serves as an inadvertent assessment of enterprise vulnerability response capability. This framework evaluates response maturity across five dimensions using the month&apos;s events as test cases.</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><category>zero-day</category><category>vulnerability-management</category><category>maturity-assessment</category><category>security-assessment</category><category>response-capability</category><category>enterprise-security</category></item><item><title>Hardware Vulnerability Assessment: Methodology for CPU Microarchitecture and Firmware Security Evaluation</title><link>https://cipherwatch.io/articles/2026-05-28-hardware-vulnerability-assessment-cpu-firmware-methodology/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-28-hardware-vulnerability-assessment-cpu-firmware-methodology/</guid><description>AMD CVE-2026-46174 and the broader class of CPU microarchitecture vulnerabilities require assessment methodology distinct from software vulnerability scanning. This guide covers the scoping, testing, and remediation verification steps for enterprise hardware security assessments covering processor vulnerabilities.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><category>hardware-security</category><category>cpu-vulnerability</category><category>firmware</category><category>vulnerability-assessment</category><category>microarchitecture</category><category>assessment-methodology</category></item><item><title>Auditing VS Code Extensions for Supply-Chain Risk: A Practical Assessment Guide</title><link>https://cipherwatch.io/articles/2026-05-27-vs-marketplace-extension-supply-chain-audit-guide/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-27-vs-marketplace-extension-supply-chain-audit-guide/</guid><description>The Nx Console supply-chain compromise in TeamPCP&apos;s May 2026 campaign targeted an extension with millions of downloads. With over 60,000 extensions in the VS Marketplace, most organisations have no inventory of which extensions their developers run. This guide covers extension auditing, publisher verification, and policy controls.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>vs-code</category><category>extensions</category><category>supply-chain</category><category>developer-security</category><category>security-assessment</category><category>ide-security</category><category>enterprise-controls</category></item><item><title>Apple&apos;s Retroactive CVE Disclosure Practice Creates Systematic Gaps in Enterprise Patch Management</title><link>https://cipherwatch.io/articles/2026-05-26-apple-cve-disclosure-enterprise-patch-management-challenge/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-26-apple-cve-disclosure-enterprise-patch-management-challenge/</guid><description>Apple&apos;s habit of retroactively adding CVE details to previously published security advisories creates operational complexity for enterprise vulnerability management programmes: vulnerabilities appear as &apos;new&apos; in CVE feeds after they have already been patched in deployed OS versions, generating false-positive remediation workflows and obscuring the true patch state of Apple endpoints.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>apple</category><category>cve-management</category><category>patch-management</category><category>vulnerability-scanning</category><category>enterprise-security</category><category>macos</category><category>ios</category></item><item><title>CVE-2026-46333 Detection and Mitigation: Security Assessment Guide for Linux Environments</title><link>https://cipherwatch.io/articles/2026-05-25-cve-2026-46333-ptrace-linux-detection-mitigation/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-25-cve-2026-46333-ptrace-linux-detection-mitigation/</guid><description>CVE-2026-46333, the Linux kernel ptrace race condition with four known exploit chains, requires both patching and verification that compromise has not already occurred. This guide covers the detection queries, audit configuration, and post-patch verification steps security teams need to assess exposure and confirm remediation.</description><pubDate>Mon, 25 May 2026 00:00:00 GMT</pubDate><category>linux</category><category>cve-2026-46333</category><category>ptrace</category><category>vulnerability-assessment</category><category>detection</category><category>audit</category><category>kernel-security</category><category>ssh-keys</category></item><item><title>Enterprise Wi-Fi Security Assessment: Evaluating Ubiquiti UniFi Against Enterprise-Grade Alternatives After Bulletin 064</title><link>https://cipherwatch.io/articles/2026-05-22-enterprise-wifi-security-assessment-unifi-infrastructure/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-22-enterprise-wifi-security-assessment-unifi-infrastructure/</guid><description>The three CVSS 10.0 vulnerabilities in Ubiquiti UniFi OS Bulletin 064 prompt a broader question: how does UniFi&apos;s security posture, vendor support, and enterprise control plane architecture compare to traditional enterprise Wi-Fi vendors? A structured assessment framework helps organisations evaluate whether UniFi is appropriate for their specific threat model.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>ubiquiti</category><category>unifi</category><category>enterprise-wifi</category><category>wireless-security</category><category>security-assessment</category><category>cisco</category><category>aruba</category><category>meraki</category><category>network-infrastructure</category></item><item><title>End-of-Life VPN Appliances: A Security Assessment Framework for Identifying Unsupportable Network Equipment</title><link>https://cipherwatch.io/articles/2026-05-19-eolife-vpn-security-assessment-framework/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-19-eolife-vpn-security-assessment-framework/</guid><description>The SonicWall Generation 6 end-of-life situation is the latest instance of a recurring enterprise security problem: internet-facing network equipment that reaches vendor end-of-life while still actively exploited. A structured assessment approach helps security teams identify, prioritise, and communicate the risk of EoL perimeter equipment.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>end-of-life</category><category>vpn</category><category>network-security</category><category>vulnerability-management</category><category>asset-management</category><category>security-assessment</category></item><item><title>Pwn2Own Berlin 2026 Closes: DEVCORE Wins Master of Pwn with $505K and 50.5 Points — $1.3M Total Across 47 Zero-Days</title><link>https://cipherwatch.io/articles/2026-05-17-pwn2own-berlin-2026-day3-devcore-master-of-pwn/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-17-pwn2own-berlin-2026-day3-devcore-master-of-pwn/</guid><description>Pwn2Own Berlin 2026 concluded with DEVCORE Research Team winning the Master of Pwn title with $505,000 in earnings and 50.5 points, driven by Orange Tsai&apos;s Exchange SYSTEM RCE chain and consistent results across multiple targets. The three-day competition produced 47 unique zero-day vulnerabilities across enterprise products, cloud infrastructure, and AI tools, with $1,298,250 in total prize money awarded.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>pwn2own</category><category>devcore</category><category>master-of-pwn</category><category>zero-day</category><category>vulnerability-research</category><category>berlin-2026</category></item><item><title>Pwn2Own Berlin 2026 Day 2: DEVCORE Chains Three Bugs for Exchange SYSTEM RCE — 15 Zero-Days and $385K Awarded</title><link>https://cipherwatch.io/articles/2026-05-16-pwn2own-berlin-day2-exchange-system-rce-rhel-lpe/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-16-pwn2own-berlin-day2-exchange-system-rce-rhel-lpe/</guid><description>The second day of Pwn2Own Berlin saw DEVCORE&apos;s Orange Tsai chain three previously unknown vulnerabilities to achieve SYSTEM-level remote code execution on fully patched Microsoft Exchange Server, earning $200,000. Day 2 also featured Red Hat Enterprise Linux LPE, additional Windows 11 privilege escalation, and LM Studio AI exploitation across 15 unique zero-days.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><category>pwn2own</category><category>exchange</category><category>rce</category><category>zero-day</category><category>vulnerability-research</category><category>devcore</category></item><item><title>Pwn2Own Berlin 2026 Day 1: Windows 11 Hacked Three Times, Edge Sandbox Escaped for $175K — 24 Zero-Days Demonstrated</title><link>https://cipherwatch.io/articles/2026-05-14-pwn2own-berlin-2026-day1-windows-edge-24-exploits/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-14-pwn2own-berlin-2026-day1-windows-edge-24-exploits/</guid><description>The first day of Pwn2Own Berlin 2026 saw researchers demonstrate 24 previously unknown vulnerabilities across Windows 11, Microsoft Edge, VMware Workstation, and Oracle VirtualBox. Windows 11 was compromised three separate times by different teams, and a full Microsoft Edge sandbox escape earned a $175,000 award. No CVE IDs have been assigned yet as vendors begin the 90-day remediation process.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>pwn2own</category><category>zero-day</category><category>windows</category><category>edge</category><category>vulnerability-research</category><category>sandbox-escape</category></item><item><title>SharePoint Server RCE and Office Preview Pane Vulnerabilities Fixed in May Patch Tuesday — Enterprise Document Attack Surface Elevated</title><link>https://cipherwatch.io/articles/2026-05-12-sharepoint-office-rce-preview-pane-patch-tuesday/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-12-sharepoint-office-rce-preview-pane-patch-tuesday/</guid><description>May&apos;s Patch Tuesday patches an authenticated RCE in SharePoint Server (CVE-2026-40365) and multiple Office vulnerabilities exploitable via the Windows Explorer and Outlook preview pane without opening files. Together they represent a significant enterprise document attack surface. Assess SharePoint exposure and validate Office update deployment this week.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>sharepoint</category><category>microsoft-office</category><category>rce</category><category>patch-tuesday</category><category>enterprise-risk</category></item><item><title>cPanel/WHM Patches Three New Vulnerabilities Including CVSS 8.8 Code Execution and Privilege Escalation</title><link>https://cipherwatch.io/articles/2026-05-06-cpanel-whm-new-cves-29201-29202-29203-code-exec/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-06-cpanel-whm-new-cves-29201-29202-29203-code-exec/</guid><description>cPanel has released security updates addressing three new vulnerabilities distinct from the previously covered CVE-2026-41940 zero-day: CVE-2026-29202 (CVSS 8.8, Perl code execution), CVE-2026-29203 (CVSS 8.8, symlink-based privilege escalation), and CVE-2026-29201 (CVSS 4.3, arbitrary file read). Web hosting providers running cPanel/WHM should apply the updates urgently given the platform&apos;s current elevated threat posture following mass exploitation in May 2026.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>cpanel</category><category>whm</category><category>cve</category><category>code-execution</category><category>privilege-escalation</category><category>web-hosting</category><category>patch</category><category>vulnerability-management</category></item><item><title>CISA ICS Advisory: GRASSMARLIN OT Network Visualisation Tool Vulnerability CVE-2026-6807</title><link>https://cipherwatch.io/articles/2026-05-05-grassmarlin-cve-2026-6807-cisa-ics-advisory/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-05-grassmarlin-cve-2026-6807-cisa-ics-advisory/</guid><description>CISA has issued ICS advisory ICSA-26-118-01 for CVE-2026-6807, a vulnerability in GRASSMARLIN — the NSA-developed open-source network visualisation tool widely used by industrial control system operators and OT security teams to map and analyse operational technology networks. The vulnerability affects teams using GRASSMARLIN for defensive ICS visibility, creating a risk of compromise of the analyst workstations conducting that analysis.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><category>ics</category><category>ot-security</category><category>cisa</category><category>grassmarlin</category><category>nsa</category><category>cve</category><category>advisory</category><category>pcap-analysis</category><category>security-tooling</category></item><item><title>Wireshark CVE-2026-5656 — Remote Code Execution via Malicious PCAP File, Update to 4.4.6</title><link>https://cipherwatch.io/articles/2026-05-04-wireshark-cve-2026-5656-rce-pcap/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-04-wireshark-cve-2026-5656-rce-pcap/</guid><description>A code execution vulnerability in Wireshark&apos;s PCAP/PCAPNG file parser allows a malicious capture file to trigger arbitrary code execution when opened by an analyst. CVE-2026-5656 affects all Wireshark versions prior to 4.4.6 across Windows, macOS, and Linux. The attack vector is especially concerning for security teams that open externally-sourced capture files during incident response or threat hunting — update Wireshark to 4.4.6 immediately.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate><category>wireshark</category><category>cve</category><category>code-execution</category><category>pcap</category><category>network-analysis</category><category>analyst-tools</category><category>patch</category></item><item><title>Three Critical Buffer Overflow Vulnerabilities Disclosed in Hashcat — Penetration Testing Toolchain at Risk</title><link>https://cipherwatch.io/articles/2026-05-03-hashcat-buffer-overflow-cves-pentest-tool/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-03-hashcat-buffer-overflow-cves-pentest-tool/</guid><description>Security researchers have disclosed three buffer overflow vulnerabilities (CVE-2026-42482, CVE-2026-42483, CVE-2026-42484) in Hashcat, the widely-used open-source password recovery and penetration testing tool. The flaws can be triggered via maliciously crafted hash files or wordlists and may allow code execution in environments where Hashcat processes untrusted input — including shared red team infrastructure and automated password auditing pipelines.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate><category>hashcat</category><category>buffer-overflow</category><category>penetration-testing</category><category>toolchain-security</category><category>cve</category><category>password-auditing</category></item><item><title>PhantomRPC — Unpatched Windows Privilege Escalation Technique Abuses COM Server Activation</title><link>https://cipherwatch.io/articles/2026-05-01-phantomrpc-windows-lpe-no-patch/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-01-phantomrpc-windows-lpe-no-patch/</guid><description>Security researchers have disclosed PhantomRPC, an unpatched local privilege escalation technique in Windows that abuses the COM server activation mechanism to elevate from standard user to SYSTEM without triggering standard EDR alerts. Microsoft has acknowledged the report but not committed to a patch timeline. Defenders should implement mitigation controls; red teams should incorporate this technique into assessments.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>windows</category><category>com</category><category>privilege-escalation</category><category>lpe</category><category>unpatched</category><category>red-team</category><category>edr-evasion</category><category>post-exploitation</category></item><item><title>cPanel and WHM CVE-2026-41940 — CVSS 9.8 Authentication Bypass Exploited as Zero-Day Before Patch</title><link>https://cipherwatch.io/articles/2026-04-30-cpanel-whm-cve-2026-41940-auth-bypass-zero-day/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-30-cpanel-whm-cve-2026-41940-auth-bypass-zero-day/</guid><description>CVE-2026-41940, a CVSS 9.8 authentication bypass in cPanel and WHM web hosting control panel software, was exploited in the wild before the vendor issued a patch. All versions from 11.40 onwards are affected. Proof-of-concept code is now public. Web hosting providers, managed service providers, and any organisation running cPanel/WHM for server management should apply the emergency patch immediately.</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate><category>cpanel</category><category>whm</category><category>cve-2026-41940</category><category>auth-bypass</category><category>zero-day</category><category>web-hosting</category><category>actively-exploited</category></item><item><title>AI Agents Can Autonomously Compromise Cloud Infrastructure With Minimal Human Oversight, Research Finds</title><link>https://cipherwatch.io/articles/2026-04-28-ai-autonomous-cloud-attack-research/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-28-ai-autonomous-cloud-attack-research/</guid><description>New academic research demonstrates that AI agents equipped with common cloud security tools can autonomously identify, chain, and exploit misconfigurations in production-like cloud environments — achieving lateral movement, privilege escalation, and data exfiltration in multi-step attack sequences without human guidance. The findings have direct implications for red team methodologies, cloud security posture management, and the adversarial use of AI-assisted attack tooling.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>ai-security</category><category>red-team</category><category>cloud-security</category><category>autonomous-attack</category><category>llm</category><category>penetration-testing</category></item><item><title>Critical Flaw in CrowdStrike Falcon LogScale and High-Severity Nessus Bug Patched — Security Tooling Vulnerabilities Demand Rapid Response</title><link>https://cipherwatch.io/articles/2026-04-25-crowdstrike-logscale-tenable-nessus-vulnerabilities/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-25-crowdstrike-logscale-tenable-nessus-vulnerabilities/</guid><description>CrowdStrike has patched a critical SSRF vulnerability in Falcon LogScale, its SIEM and log management platform, while Tenable has addressed a privilege escalation flaw in Nessus. Security tooling vulnerabilities are among the most consequential: a compromised SIEM or vulnerability scanner has privileged visibility across the entire environment it monitors.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate><category>crowdstrike</category><category>tenable</category><category>siem</category><category>vulnerability-scanner</category><category>ssrf</category><category>privilege-escalation</category></item><item><title>CISA Adds Quest KACE (CVSS 10.0), Kentico Xperience, and Zimbra ZCS to Known Exploited Vulnerabilities — Federal Deadline May 4</title><link>https://cipherwatch.io/articles/2026-04-24-cisa-kev-quest-kace-kentico-zimbra-april-2026/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-24-cisa-kev-quest-kace-kentico-zimbra-april-2026/</guid><description>CISA&apos;s April 2026 KEV additions include a CVSS 10.0 unauthenticated SQL injection in Quest KACE Systems Management Appliance, active exploitation of Kentico Xperience CMS, and Zimbra Collaboration Suite vulnerabilities. Federal agencies have a May 4 remediation deadline; enterprise organisations should treat confirmed KEV additions as indicators of active attacker tooling and prioritise these systems immediately.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>cisa-kev</category><category>quest-kace</category><category>zimbra</category><category>kentico</category><category>vulnerability-management</category><category>actively-exploited</category><category>patch-management</category></item><item><title>Seized Gentlemen Ransomware C2 Server Exposes 1,570 Victims — GPO Deployment Reveals Full Domain Compromise</title><link>https://cipherwatch.io/articles/2026-04-23-gentlemen-ransomware-systembc-c2-seized-gpo-deployment/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-23-gentlemen-ransomware-systembc-c2-seized-gpo-deployment/</guid><description>Check Point Research&apos;s analysis of a seized SystemBC command-and-control server linked to The Gentlemen ransomware operation exposed 1,570+ victim IP addresses and documented the group&apos;s use of Group Policy Objects to deploy ransomware domain-wide. GPO-based distribution is a forensic marker that attackers achieved Domain Admin access days before encryption — defenders should treat it as an indicator of extended dwell time, not a starting point.</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate><category>ransomware</category><category>threat-intelligence</category><category>systembc</category><category>c2-infrastructure</category><category>gpo-abuse</category><category>detection</category><category>threat-hunting</category></item><item><title>CISA Adds Eight CVEs to KEV: PaperCut, JetBrains TeamCity, and Cisco SD-WAN Actively Exploited</title><link>https://cipherwatch.io/articles/2026-04-21-cisa-kev-april-20-papercut-teamcity-cisco-sdwan/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-21-cisa-kev-april-20-papercut-teamcity-cisco-sdwan/</guid><description>CISA&apos;s April 20 Known Exploited Vulnerabilities addition is the largest single-day batch this month, confirming active exploitation across enterprise print management, CI/CD pipelines, content management, and Cisco SD-WAN infrastructure. The batch spans CVE publication years from 2023 to 2026, demonstrating that unpatched legacy vulnerabilities continue to be weaponised alongside newly disclosed flaws. Federal agencies face a BOD 22-01 remediation deadline, and private sector organisations should treat these as immediate prioritisation signals.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><category>cisa-kev</category><category>papercut</category><category>teamcity</category><category>cisco-sdwan</category><category>vulnerability-management</category><category>actively-exploited</category><category>patch-prioritisation</category><category>quest-kace</category><category>kentico</category></item><item><title>NIST Ends Full NVD Enrichment — What It Means for Your Vulnerability Management Programme</title><link>https://cipherwatch.io/articles/2026-04-17-nist-nvd-enrichment-overhaul-vulnerability-assessment/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-17-nist-nvd-enrichment-overhaul-vulnerability-assessment/</guid><description>NIST has announced it will no longer enrich every CVE record in the National Vulnerability Database, shifting to a risk-based model that prioritises only the most critical submissions. With CVE volumes up 263% since 2020 and the NVD backlog now officially unresolvable, security teams that rely on NVD CVSS scores and CPE data for vulnerability prioritisation must urgently adapt their tooling and workflows.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><category>nvd</category><category>nist</category><category>cvss</category><category>vulnerability-management</category><category>cve</category><category>patch-prioritisation</category></item><item><title>CISA Adds Seven CVEs to KEV Including Decade-Old Microsoft Bugs Exploited by Storm-1175</title><link>https://cipherwatch.io/articles/2026-04-13-cisa-kev-legacy-microsoft-cves-storm-1175-exploitation/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-13-cisa-kev-legacy-microsoft-cves-storm-1175-exploitation/</guid><description>CISA has added seven vulnerabilities to the Known Exploited Vulnerabilities catalogue, including four Microsoft flaws spanning from 2012 to 2025 being actively leveraged by the Storm-1175 ransomware group. The additions highlight a persistent patching blind spot: vulnerabilities patched years ago that never made it into legacy system maintenance cycles, now routinely weaponised for initial access and privilege escalation.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><category>cisa-kev</category><category>patch-management</category><category>storm-1175</category><category>medusa</category><category>microsoft</category><category>exchange</category><category>fortinet</category><category>adobe</category><category>legacy-vulnerabilities</category><category>vulnerability-management</category></item><item><title>CISA Supplemental Direction ED 26-03: How to Hunt for Compromise in Cisco Catalyst SD-WAN</title><link>https://cipherwatch.io/articles/2026-04-10-cisa-cisco-sdwan-hunt-hardening-guidance/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-10-cisa-cisco-sdwan-hunt-hardening-guidance/</guid><description>CISA has issued supplemental hunt-and-hardening guidance for Cisco Catalyst SD-WAN systems under Emergency Directive 26-03, providing defenders with specific indicators to look for in environments exposed to CVE-2026-20127 — a CVSS 10.0 authentication bypass exploited since 2023. Organisations running Cisco SD-WAN infrastructure should treat this guidance as a mandatory compromise assessment checklist.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>cisco</category><category>sd-wan</category><category>cisa</category><category>emergency-directive</category><category>compromise-assessment</category><category>threat-hunting</category><category>cvss-10</category><category>authentication-bypass</category></item><item><title>March 2026 Brought 83 Patch Tuesday CVEs and Three CISA KEV Additions — How to Prioritise</title><link>https://cipherwatch.io/articles/2026-04-02-march-vulnerability-prioritisation-enterprise-patch-guidance/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-02-march-vulnerability-prioritisation-enterprise-patch-guidance/</guid><description>March 2026&apos;s Patch Tuesday addressed 83 vulnerabilities including three critical Office RCEs, an Active Directory privilege escalation now in CISA&apos;s KEV catalogue, and a Kerberos security feature bypass. Add three separate CISA KEV additions throughout the month — F5 BIG-IP, Citrix NetScaler, and Active Directory — and security teams are managing a substantial patching backlog entering April. This analysis cuts through the volume to identify where to focus.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate><category>vulnerability-management</category><category>patch-tuesday</category><category>cisa-kev</category><category>prioritisation</category><category>microsoft</category><category>enterprise</category></item><item><title>NIST Updates DNS Security Guidance SP 800-81-3 — What Changed and Why It Matters Now</title><link>https://cipherwatch.io/articles/2026-03-29-nist-sp800-81-3-dns-security-guidance/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-03-29-nist-sp800-81-3-dns-security-guidance/</guid><description>NIST released an updated edition of Special Publication 800-81, its foundational guidance on securing the Domain Name System, as DNS-based attacks and abuse techniques have evolved significantly since the previous version. The new SP 800-81-3 expands coverage of DNS-over-HTTPS, DNSSEC deployment best practices, DNS-based threat detection, and resilience against cache poisoning variants. Security teams should use this revision to audit current DNS architecture against current recommendations.</description><pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate><category>nist</category><category>dns</category><category>dnssec</category><category>sp800-81</category><category>dns-over-https</category><category>doh</category><category>security-assessment</category><category>architecture-review</category><category>dns-poisoning</category></item></channel></rss>