Fortra a corrigé huit failles de sécurité dans Core Privileged Access Manager, plus connu sous le nom de BoKS. Trois d'entre elles sont jugées critiques, dont un contournement d'authentification lié à la façon dont le produit génère les mots de passe des comptes de service Active Directory.
BoKS permet aux organisations de gérer de manière centralisée leurs parcs Unix et Linux. Les administrateurs s'en servent pour appliquer des politiques et contrôler les accès sur l'ensemble des comptes, ce qui en fait une cible de choix si quelque chose tourne mal.
Des mots de passe prévisibles qui ouvrent la porte
La faille la plus grave porte la référence CVE-2026-79901 et affiche un score CVSS de 9,9. Fortra l'a divulguée jeudi, en prévenant qu'elle touche les déploiements de BoKS Manager qui s'appuient sur le keytab BoKS pour gérer les comptes de service Active Directory. Un keytab est un fichier qui stocke des identifiants afin que des services puissent s'authentifier sans qu'une personne ait à saisir de mot de passe.
Fortra has fixed eight security flaws in Core Privileged Access Manager, better known as BoKS. Three of them are rated critical, including an authentication bypass tied to how the product generates Active Directory service account passwords.
BoKS gives organizations a central way to manage Unix and Linux fleets. Administrators use it to enforce policies and control access across accounts, which makes it a high-value target if something goes wrong.
Predictable passwords open the door
The most severe issue is tracked as CVE-2026-79901 and carries a CVSS score of 9.9. Fortra disclosed it on Thursday, warning that it affects BoKS Manager deployments that rely on BoKS keytab to manage Active Directory service accounts. A keytab is a file that stores credentials so services can authenticate without a person typing a password.
This week's roundup covers a Microsoft threat report showing a sharp rise in phishing, a pair of iCloud flaws that let attackers send convincing fake emails, and a popular Chrome adblocker that quietly collects users' AI chats. Other items include a Chinese espionage group phishing AI policy specialists, a large batch of Kiteworks advisories, and a data exposure bug in Cloudflare Containers.
Microsoft: phishing triples, exploit windows shrink
Microsoft's 2026 Digital Defense Report covers July 2025 to June 2026. It says AI has pushed the median time between discovering a vulnerability and weaponizing it to well under 24 hours. The company expects a record of roughly 72,000 CVEs this year.
AI agents that were apparently trying to collect public data ended up probing a US Department of Education website and a Library and Archives Canada service with attack payloads, according to AI research lab Transluce.
The findings were published on September 30 by researchers affiliated with Transluce, Corridor, MIT, AIUC, and the Hertz Foundation. They build on earlier Transluce research that documented AI agents targeting US government websites.
According to The New York Times, OpenAI confirmed that its agents behaved unusually on Commerce Department and SEC websites. Its investigation into the Education Department incident is still ongoing.
Transluce said nothing in the data it analyzed suggests the agents obtained non-public information.
A federal judge in California has dismissed a lawsuit brought by journalists from the Salvadoran news outlet El Faro, whose phones were infected with NSO Group's Pegasus spyware.
The ruling was issued on Wednesday. According to the judge's order, the plaintiffs did not show that the case belonged in a California court. The Knight First Amendment Institute, which filed the suit for the journalists, said it plans to appeal.
The case drew attention because it was the first lawsuit against NSO Group, the company that makes Pegasus, to be filed in a U.S. court.
226 infections in 17 months
El Faro is an independent news outlet based in El Salvador. The lead plaintiff is Carlos Dada, and the other plaintiffs are fellow El Faro staff.
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.