vulnerability 'Certighost' Flaw Haunts Microsoft Active Directory Certificates A critical vulnerability, dubbed ‘Certighost,’ has been patched by Microsoft that allowed a low-privileged domain user to impersonate a domain controller and compromise an Active Directory environment. The flaw stemmed from a broken trust boundary within the certificate enrollment process, enabling attackers to trick t… Dark Reading · Jul 28, 2026 Critical CVE-2026-54121UNcertificateactive directorypkis
vulnerability Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide A researcher discovered a critical vulnerability in Shark robot vacuums due to a flawed certificate policy on Amazon's AWS cloud platform. Attackers can exploit this to gain remote control of vacuums across an entire AWS… The Hacker News · Jul 16, 2026 Critical awsiotcertificate
vulnerability H.VIEW HV-500S6 IP Camera This CISA advisory details a critical vulnerability in H.VIEW HV-500S6 IP cameras, specifically version IPCAM_V4.06.88.251229. The vulnerability allows authenticated users to upload malicious files and execute arbitrary… CISA Advisories · Jun 25, 2026 Critical CVE-2026-55975CVE-2026-56414CHcertificateinput validationcommand injection
vulnerability Siemens WinCC Certificate Manager A vulnerability has been identified in Siemens WinCC Certificate Manager, specifically versions V16 through V21, that allows an attacker to potentially extract sensitive information due to insufficient protection of key… CISA Advisories · Jun 23, 2026 High CVE-2026-24349GEcertificatekey managementindustrial control systems
vulnerability Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups Check Point has identified and warned of a critical vulnerability (CVE-2026-50751) in its Remote Access VPN and Mobile Access products, allowing unauthenticated attackers to bypass password authentication when using the… The Hacker News · Jun 8, 2026 Critical CVE-2026-50751CVE-2026-50752GLikev1vpncertificate
vulnerability Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit A vulnerability in Palo Alto Networks' PAN-OS GlobalProtect VPN technology, tracked as CVE-2026-0257, is currently being actively exploited. Attackers are leveraging a configuration flaw to bypass authentication and gain… Dark Reading · Jun 1, 2026 Critical CVE-2026-0257CVE-2025-0108USvpnauthenticationcookie
threat-intel Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks Microsoft disrupted a malware-signing-as-a-service (MSaaS) operation, dubbed OpFauxSign, led by the threat actor Fox Tempest, which was using its Artifact Signing system to distribute malware and ransomware. The operatio… The Hacker News · May 20, 2026 High USFRINmsaascode-signingmalware