Skip to main content

Share story

Security

Attackers probe SharePoint authentication-bypass and RCE chain

Attackers probe SharePoint authentication-bypass and RCE chain Image: Primary
Threat actors are probing a chain of two Microsoft SharePoint vulnerabilities in Defused honeypots, BleepingComputer reported. CVE-2026-55040 is an authentication-bypass flaw in JWT token validation; attackers can chain it with CVE-2026-63520 in Business Connectivity Services for remote code execution on an unpatched server. Public proof-of-concept code for the two flaws was released August 11 and August 24. Defused said it saw the bypass followed by administrative enumeration and BCS probing, but no code execution in those observations.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Products
Security Products

Bitwarden plans commercial builds for app stores starting next release

Bitwarden says its apps distributed through stores will use commercially licensed builds starting with the next release. Current features will remain available in both the commercial and GPLv3 open-source versions, and users will ...

Security
Security

Pays accounts used "123456" during Danish civil registry breach

At least three accounts at Danish IT company Pays used the password "123456" when hackers accessed Denmark's central civil registration database, Politiken reported, including an administrator account. The breach exposed informati...

Security
Security

Huntress finds exploited AhsayCBS flaws persist in latest release

Huntress said Friday that AhsayCBS 10.3.4, the latest version of the backup management platform, remains vulnerable to two flaws attackers are exploiting. Both had been reported as fixed in version 10.3.2. Attacks observed on Octo...

Security
Security

FBI arrests suspected ShinyHunters member linked to agency breach

The FBI arrested another suspected ShinyHunters member believed to be involved in the FBIJobs breach, Director Kash Patel announced Friday. The New York Times identified the suspect as a Canadian citizen arrested in Pennsylvania a...