tenfold CE: Our complimentary Identity Governance tool has received 2 new features

tenfold CE: Our complimentary Identity Governance tool has received 2 new features

tenfold’s Community Edition provides organizations with fewer than 150 users complete access to our Identity Governance and Administration (IGA) solution. Recent enhancements have introduced additional free features for CE users, including access reviews for shared content and centralized event auditing. As IT environments grow increasingly fragmented and intricate, ensuring that your workforce has access to…

Read More
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

A vacant field. An open repository. A single response to an email. An unprotected box. None of these scenarios seem particularly alarming, which is part of the issue. This week’s threats continue to exploit minor details that are often easily missed. There are vulnerabilities currently being exploited, more streamlined intrusion methods, advanced automation, and a…

Read More
Microsoft Exchange Vulnerability Allows Authenticated Users to Access Other Users' Mailboxes

Microsoft Exchange Vulnerability Allows Authenticated Users to Access Other Users’ Mailboxes

Microsoft has issued out-of-band security updates to fix a critical vulnerability in Microsoft Exchange Server that may enable an attacker to escalate their privileges under specific circumstances. This vulnerability, identified as CVE-2026-96940, has a CVSS score of 8.8. According to an advisory published on October 2, 2026, Microsoft stated, “Weak authorization in Microsoft Exchange Server…

Read More
Apple Fixes CoreGraphics Vulnerability Potentially Used in Targeted Attacks

Apple Fixes CoreGraphics Vulnerability Potentially Used in Targeted Attacks

Apple has issued security updates to rectify a flaw in older versions of iOS, iPadOS, and macOS, which it indicated might have been utilized in targeted attacks. The flaw, identified as CVE-2026-86950, pertains to an out-of-bounds write affecting the CoreGraphics component, potentially allowing arbitrary code execution when handling a maliciously crafted file. The company stated…

Read More
Keio Corporation in Japan Acknowledges Ransomware Attack Disrupting Operations

Keio Corporation in Japan Acknowledges Ransomware Attack Disrupting Operations

Keio Corporation, a prominent private railway operator in Japan, reported that its network experienced a ransomware attack over the weekend, leading to disruptions in several of its business systems. After a system failure occurred early Saturday morning, the company confirmed the attack and took measures to shut down its network to mitigate further damage. Keio…

Read More
Counterfeit LastPass Authenticator Installer Exploits Microsoft-Signed Driver to Disable Antivirus and EDR

Counterfeit LastPass Authenticator Installer Exploits Microsoft-Signed Driver to Disable Antivirus and EDR

A counterfeit LastPass Authenticator installer available on GitHub installs a Windows kernel driver that disables antivirus and other security applications before a password theft program executes, according to researchers from LastPass and Delphos Labs on September 17. The driver is signed by Microsoft’s hardware compatibility program, received zero detections on VirusTotal during an August check…

Read More
CISA warns of ongoing exploitation of three Linux kernel vulnerabilities

CISA warns of ongoing exploitation of three Linux kernel vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the exploitation of three vulnerabilities in the Linux kernel, one of which is classified as critical. These three security flaws were individually reported last week and have severity ratings that range from medium to critical. Notably, one of them, identified as CVE-2025-39964,…

Read More
BigBear Microsoft 365 Phishing Service Circumvents MFA at 258 Organizations

BigBear Microsoft 365 Phishing Service Circumvents MFA at 258 Organizations

A phishing-as-a-service platform known as BigBear 2.0 has successfully circumvented multi-factor authentication (MFA) for 258 organizations, resulting in the theft of over 5,000 Microsoft 365 credentials. Researchers from the cybersecurity firm CloudSEK gained administrative access to the control panel and discovered that the service operated 42 VPS nodes, all specifically configured to target Microsoft 365…

Read More
Executives Targeted by Phony IT Calls in Microsoft 365 Data Theft and Extortion Schemes

Executives Targeted by Phony IT Calls in Microsoft 365 Data Theft and Extortion Schemes

Threat hunters have revealed information about a large-scale data theft and extortion threat group that is focusing on Microsoft 365 and other software-as-a-service (SaaS) platforms through IT help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. This activity primarily targets directors, vice presidents, and other high-ranking officials, and is being monitored by Arctic Wolf…

Read More
Back To Top