Aggregator
Google lets Workspace admins apply one policy across all SAML apps
Google has updated Context-Aware Access (CAA) in Google Workspace to introduce a default policy assignment for SAML applications. SAML applications are third-party or internal applications that use the Security Assertion Markup Language (SAML) protocol to enable single sign-on (SSO) with Google Workspace credentials. Google says this update introduces a default assignment that serves as a universal security baseline, automatically protecting any SAML-based application that does not have a specific policy already assigned. By establishing this … More →
The post Google lets Workspace admins apply one policy across all SAML apps appeared first on Help Net Security.
Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182)
Cisco has patched yet another Catalyst SD-WAN Controller authentication bypass vulnerability (CVE-2026-20182) that has been exploited as a zero-day by “a highly sophisticated cyber threat actor”. About CVE-2026-20182 CVE-2026-20182 – affecting both Cisco Catalyst SD-WAN Controller (the “brain” of the Cisco Catalyst SD-WAN solution) and Cisco Catalyst SD-WAN Manager (the management plane for the entire SD-WAN fabric) – stems from a flawed peering authentication mechanism. It affects both on-prem and cloud deployments. CVE-2026-20182 was reported … More →
The post Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182) appeared first on Help Net Security.
CVE-2017-3274 | Oracle Email Center up to 12.2.6 User Interface access control (Nessus ID 96608 / BID-95591)
CVE-2017-3275 | Oracle Email Center up to 12.2.6 User Interface 7pk security (Nessus ID 96608 / BID-95593)
CVE-2017-3279 | Oracle Leads Management 12.1.1/12.1.2/12.1.3 User Interface access control (Nessus ID 96608 / BID-95614)
CVE-2017-3278 | Oracle One-to-One Fulfillment 12.1.3 Request Confirmatoin access control (Nessus ID 96608 / BID-95600)
CVE-2017-3277 | Oracle Applications Manager up to 12.2.6 OAM Client information disclosure (Nessus ID 96608 / BID-95617)
CVE-2017-3280 | Oracle Partner Management up to 12.2.6 User Interface input validation (Nessus ID 96608 / BID-95577)
CVE-2017-3281 | Oracle Partner Management up to 12.2.6 User Interface access control (Nessus ID 96608 / BID-95582)
CVE-2017-3282 | Oracle Partner Management up to 12.2.6 User Interface access control (Nessus ID 96608 / BID-95586)
CVE-2017-3283 | Oracle Partner Management up to 12.2.6 User Interface input validation (Nessus ID 96608 / BID-95587)
CVE-2017-3276 | Oracle Solaris 11.3 Kernel Zones virtualized block driver access control (Nessus ID 96601 / ID 296008)
Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange Servers
Microsoft to automatically roll back faulty Windows drivers
Microsoft Warns of Attackers Using Trusted HPE Operations Agent for Malware-Free Intrusions
A recent intrusion uncovered by security researchers revealed a calculated attack campaign that used a legitimate enterprise management tool as a weapon. The threat actor gained access through a compromised third-party IT services provider, then quietly moved through the victim’s environment using tools that were already approved and running. No obvious malware was dropped, and […]
The post Microsoft Warns of Attackers Using Trusted HPE Operations Agent for Malware-Free Intrusions appeared first on Cyber Security News.