Sunday 26 July 2026 11:04:10 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#broken access control


Meta Support Flaw Turned Private Cases Into a Cross-Account Risk

Published: 22 July 2026 16:42Category: Breaches & Data LeaksGeo: North America / USAAuthor: BYTEHERMIT

A critical IDOR-style access control bug in Meta’s support infrastructure reportedly let one account reach another user’s case data, showing how a single authorization miss can put both privacy and workflow integrity on the line.

When One Missing Permission Check Opens the Support Desk

Published: 22 July 2026 16:33Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A reported critical access-control flaw in Meta’s support systems highlights how IDOR-style mistakes can turn routine case management into a cross-account privacy risk.

When a File Transfer Server Starts Looking Like a Root Shell

Published: 22 July 2026 12:50Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

SolarWinds’ Serv-U patch cycle shows how broken authorization in admin workflows can turn a managed file transfer platform into a high-risk target, especially on Linux.

Machine-Written Code, Human-Scale Risk: The Vulnerability Count That Should тревить Every Dev Team

Published: 22 July 2026 02:09Category: AI Security & Agentic SystemsGeo: Oceania / AustraliaAuthor: KERNELWATCHER

A new benchmark claim puts a hard number on a familiar fear: when AI writes code, the problem is often not speed, but the steady return of old weaknesses at industrial scale.

Meta’s Support Back Door: The $78,000 Bug That Exposed the Cost of Broken Permissions

Published: 21 July 2026 14:41Category: Breaches & Data LeaksGeo: North America / USAAuthor: BYTEHERMIT

A researcher found a broken access control flaw in Meta’s support infrastructure that exposed customer support data, prompting a $78,000 bounty and a reminder that authorization bugs can matter more than flashy exploits.

When the Vault Trusts the Wrong User: Bitwarden Server and the Hidden Cost of Broken Access Control

Published: 09 July 2026 19:15Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A public proof of concept for CVE-2026-60104 puts the spotlight on a familiar but dangerous failure mode: backend trust, not encryption, can become the weak link in a password manager.

When a Management Plane Breaks Open, the Host Is the Prize

Published: 08 June 2026 10:27Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A critical flaw chain in UniFi OS Server shows how broken access control, path handling, and command injection can collapse a trusted admin surface into root-level risk.

RCI Breach Puts Access Control Under the Microscope

Published: 05 June 2026 10:12Category: Breaches & Data LeaksGeo: North America / USAAuthor: SECURERECLAIMER

A March intrusion that affected about 40,000 people now looks less like a simple break-in and more like a reminder that one weak authorization path can turn a web app into a data-loss channel.

Leak-Site Listings Turn Ecommerce Into a Ransomware Pressure Point

Published: 02 June 2026 02:05Category: Ransomware & ExtortionGeo: North America / USAAuthor: NEBULASCOUT

A victim post naming Power & Tel highlights how extortion crews use public leak sites to turn uncertainty into pressure, even when the underlying compromise is not yet verified.

A Small Plugin, a Big Shortcut: How a WordPress Map Tool Could Turn Visitors into Administrators

Published: 01 June 2026 02:07Category: Vulnerabilities & Patch ManagementAuthor: SECURESPECTER

A flaw in WP Maps Pro shows how one exposed AJAX path and weak server-side authorization can collapse the boundary between a normal user and a site owner.

PraisonAI’s Fast-Moving Flaw Shows How Quiet Defaults Become Loud Breakouts

Published: 15 May 2026 14:06Category: Vulnerabilities & Patch ManagementAuthor: DEEPAUDIT

A high-severity authentication bypass in PraisonAI’s legacy API server highlights a familiar failure mode in AI tooling: if a workflow runner is reachable and not properly locked down, the attack surface can appear long before defenders notice it.

One Portal Flaw, One Big Privacy Problem: How a Car Brand’s Shop Became a Data Target

Published: 11 May 2026 22:14Category: Breaches & Data LeaksGeo: Europe / Czech RepublicAuthor: BYTESHIELD

A customer-facing shopping portal can turn into a serious security boundary when access controls fail, putting personal data in the crosshairs even without payment details.