❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayIT Security

TP-Link Zero-Touch Provisioning Flaws Could Expose Enterprise Networks, Warns Forescout

5 August 2026 at 05:13

Forescout Vedere Labs research has uncovered 15 previously unknown vulnerabilities affecting TP-Link’s Omada Zero-Touch Provisioning (ZTP) ecosystem, warning that weaknesses in automated device deployment could allow attackers to compromise not just individual devices, but the management infrastructure responsible for entire networks.

The research highlights an emerging security challenge as organisations increasingly rely on Zero-Touch Provisioning to simplify the deployment and management of routers, switches, gateways and wireless access points across distributed environments. While ZTP reduces operational overhead, Forescout argues that it also creates highly trusted relationships between devices, controllers and cloud services that, if exploited, could significantly increase the scale of an attack.

Rather than exploiting a single network device, Vedere Labs researchers demonstrated how multiple vulnerabilities can be chained together to move from device onboarding to compromising controllers, cloud services and managed infrastructure. The vulnerabilities span client-side code execution, credential disclosure, device spoofing and weaknesses in cryptographic trust.

Daniel dos Santos, VP of Research at Forescout, said: β€œAs organisations adopt Zero-Touch Provisioning to automate deployment and management, weaknesses in those systems can create entirely new attack scenarios. Our findings underscore the importance of visibility not only into connected devices, but also into the management systems and trust relationships that control them.”

What it means for organisations

The findings emphasise the need for a mindset change when it comes to infrastructure security. Traditionally, security teams have focused on protecting endpoints and individual network devices. However, as provisioning and lifecycle management become increasingly automated, the management platforms themselves are becoming attractive targets.

A successful compromise of a provisioning system could allow attackers to deploy malicious configurations, steal credentials or gain access to multiple devices simultaneously, amplifying the impact of a single breach. This is particularly relevant for organisations managing large estates of network infrastructure across branch offices, warehouses, retail locations or industrial environments where ZTP has become commonplace.

The research also highlights that the risk extends beyond TP-Link Omada, with some vulnerabilities affecting related TP-Link ecosystems including Festa, VIGI, Tapo and Kasa, demonstrating how weaknesses in shared provisioning technologies can have wider implications.

Reducing the risk

Forescout is urging organisations using affected products to install available updates for devices, controllers and associated applications as soon as possible. Beyond patching, the company recommends reviewing provisioning processes to ensure default credentials are replaced with strong, unique passwords, enabling multi-factor authentication for TP-Link accounts, rotating exposed credentials, segmenting provisioning infrastructure from the wider network, and continuously monitoring communications between devices, controllers and cloud services. Applying Zero Trust principles to device management workflows can also help limit the impact if a provisioning platform is compromised.

The research serves as a reminder that as organisations embrace automation to improve operational efficiency, they must apply the same level of scrutiny to the systems managing infrastructure as they do to the infrastructure itself. Protecting the chain of trust underpinning automated deployment is becoming just as important as securing the devices being deployed.

The full research is available here: Zero Day Provisioning: Chaining TP-Link ZTP Vulnerabilities to Infiltrate Networks

The post TP-Link Zero-Touch Provisioning Flaws Could Expose Enterprise Networks, Warns Forescout appeared first on IT Security Guru.

Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave

28 July 2026 at 20:00
Between January and June 2026, TrendAIβ„’ tracked more than 35,000 fake sites exploiting the 2026 FIFA World Cup, spanning counterfeit merchandise shops, cloned ticket pages, and bogus free-streaming sites, which together drew roughly 1.48 million visits from Japan.

13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan

22 July 2026 at 20:00
We analyzed a sustained tech support scam campaign that sent more than 13 million emails to Japanese addresses, with workplace-themed lures suggesting a possible expansion toward enterprise targets.

Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It

OpenAI’s own models broke out of a test sandbox and into Hugging Face’s servers to solve an evaluation, with no human attacker involved. The incident showed how keeping agentic AI safe now depends on how it’s contained, not just on how it’s trained.

Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass

Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.

Forescout Report Reveals Surge in AI-Driven Cyber Threats

21 July 2026 at 09:17

The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day.

The report, published by Forescout Research – Vedere Labs, analysed more than 37,000 vulnerabilities, over 1,000 tracked threat actors and thousands of cyberattacks observed between January and June 2026. Researchers found that rapid advances in AI, alongside growing geopolitical tensions, are increasing the pressure on security teams already struggling to prioritise risk.

Among the reportβ€˜s key findings, researchers discovered that nearly half of all additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue related to vulnerabilities published before 2026, reinforcing the continued risk posed by older, unpatched flaws. The number of active ransomware groups also increased to 103, while China, Russia and Iran collectively accounted for almost a third of tracked threat actors with significant activity during the reporting period.

The research also highlights the growing use of AI by threat actors to accelerate attacks, alongside increasingly sophisticated software supply chain compromises. At the same time, attackers continue to focus on network infrastructure, operational technology, IoT and IoMT devices, many of which receive less security oversight than traditional endpoints.

β€œAI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.

β€œIn observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.”

He added that organisations need a better understanding of the assets connected to their networks so they can prioritise risk and contain threats before attackers can move laterally into critical systems.

The report also examines the evolution of Iranian cyber operations, noting that the distinction between state-sponsored actors, hacktivist groups and cybercriminal organisations is becoming increasingly blurred. Researchers found these groups are using a mix of espionage campaigns, ransomware and attacks targeting critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, said organisations must extend their focus beyond traditional endpoints to address unmanaged assets and connected devices.

β€œAs attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” he said.

β€œMany organisations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps.”

The report recommends that organisations should continuously identify vulnerable assets, strengthen network segmentation, prioritise the highest-risk systems and accelerate response capabilities to reduce exposure across increasingly complex environments.

The post Forescout Report Reveals Surge in AI-Driven Cyber Threats appeared first on IT Security Guru.

Americans are ignoring scam calls, but phishing emails still fool many

15 July 2026 at 02:28
Americans are becoming more effective at avoiding spam calls and texts, but new research suggests that the strategy comes with an unexpected cost. A new survey of 1,000 Americans from privacy company Cloaked, revealed that two-thirds of respondents have missed an important phone call because they ignored an unknown number. One in three have missed [...]

Filigran report: Organisations can see their threats but can’t act fast enough

Fragmented tools and manual processes are widening the gap between threat awareness and effective CTEM. Only 41% of organisations have a fully consolidated view of cyber risk exposure, and security teams spend 42% of their time investigating risks that turn out to be low priority or non-exploitable At the same time, AI-driven CTEM processes expected [...]

TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry

By: Yuya Sato
28 June 2026 at 20:00
In this blog entry, TrendAIβ„’ Research examines a wave of phishing emails observed in May 2026 that targeted Japanese accommodation facilities using Booking.com, detailing the victims, attack techniques used, and characteristics of the malware involved.

❌
❌