New data from BeyondTrust's 2026 report reveals a concerning trend: critical Microsoft vulnerabilities doubled last year, with a significant shift towards Elevation of Privilege and Information Disclosure flaws. Attackers are now forging tokens (like the Entra ID flaw CVE-2025-55241) and operating undetected, making traditional log-based detection obsolete. This demands a strategic…

https://www.tpp.blog/u1zt1dq

#cybersecurity #beyondtrust #microsoft

🤖 This post was AI-generated.

Microsoft Vulnerabilities Spike in Critical Areas

A single critical flaw, like CVE-2025-55241, can give attackers unrestricted access to any tenant, highlighting the alarming rise in critical Microsoft vulnerabilities, which doubled in 2025 despite a stable overall number of vulnerabilities. This sharp increase in high-impact weaknesses demands attention and action.

https://osintsights.com/microsoft-vulnerabilities-spike-in-critical-areas?utm_source=mastodon&utm_medium=social

#MicrosoftVulnerabilities #EntraId #Cve202555241 #IdentityWeakness #Beyondtrust

Microsoft Vulnerabilities Spike in Critical Areas

Discover how Microsoft vulnerabilities spiked in critical areas, learn the risks and take action to protect your systems now with expert insights and recommendations.

OSINTSights
Une #vulnérabilité critique activement exploitée dans #BeyondTrust RS. Plusieurs sociétés de #sécurité ont lancé des alertes après l’exploitation rapide d’une #faille critique (...)
https://www.lemondeinformatique.fr/actualites/lire-une-vulnerabilite-critique-activement-exploitee-dans-beyondtrust-rs-99399.html
Une vulnérabilité critique activement exploitée dans BeyondTrust RS - Le Monde Informatique

Ces attaques, détectées par des chercheurs, ont compromis des appliances de support à distance de Bomgar dont beaucoup ont atteint leur fin de vie....

LeMondeInformatique
📢 Faille critique CVE-2026-1731 dans BeyondTrust exploitée pour prendre le contrôle d’Active Directory
📝 GBHackers Security rapporte qu’une campagne d’attaque exploite la vulnérabilité critique **CVE-2026-1...
📖 cyberveille : https://cyberveille.ch/posts/2026-02-16-faille-critique-cve-2026-1731-dans-beyondtrust-exploitee-pour-prendre-le-controle-dactive-directory/
🌐 source : https://gbhackers.com/attackers-exploit-critical-beyondtrust-flaw/
#BeyondTrust #CISA_KEV #Cyberveille
Faille critique CVE-2026-1731 dans BeyondTrust exploitée pour prendre le contrôle d’Active Directory

GBHackers Security rapporte qu’une campagne d’attaque exploite la vulnérabilité critique CVE-2026-1731 affectant des déploiements auto-hébergés de BeyondTrust Remote Support et Privileged Remote Access. La faille autorise des attaquants non authentifiés à réaliser une injection de commandes système, conduisant à une exécution de code à distance (RCE). Les produits concernés sont explicitement les instances auto-hébergées de BeyondTrust Remote Support et de Privileged Remote Access. ⚠️ L’impact mis en avant est majeur, les attaquants pouvant prendre un contrôle complet d’Active Directory, ce qui élargit drastiquement leur surface d’action au sein des environnements ciblés.

CyberVeille
U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. CISA adds a vulnerability in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog.

Security Affairs
Attackers exploit BeyondTrust CVE-2026-1731 within hours of PoC release

Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code execution.

Security Affairs
BeyondTrust fixes critical pre-auth bug allowing remote code execution

BeyondTrust patched a critical pre-auth flaw in Remote Support and PRA that could let attackers execute code remotely.

Security Affairs
When Your VPN Opens Your Private Network to the Public

How AI-assisted reverse engineering of stripped PAN-OS binaries led to finding a JWT algorithm confusion vulnerability in GlobalProtect's Cloud Authentication Service, enabling full VPN auth bypass with just a username.

Hacktron AI
🚨 CVE-2026-1731: CRITICAL RCE in BeyondTrust RS & PRA. Unauthenticated attackers can execute OS commands pre-auth. Restrict access, monitor logs, and prep for patching. CVSS 9.9 — act now! https://radar.offseq.com/threat/cve-2026-1731-cwe-78-improper-neutralization-of-sp-066ed5de #OffSeq #BeyondTrust #Vuln #InfoSec

Our latest interview with Morey J. Haber (Chief Security Advisor, BeyondTrust) explores identity technical debt, Zero Trust gaps, and why least privilege continues to fall short without continuous discovery.

Haber breaks down:
• Why overprivileged accounts remain the biggest lateral-movement risk
• How AI ecosystems expand attack paths
• Why Zero Trust often becomes piecemeal
• Why identity - not endpoints - is the new perimeter
• Essential control layers CISOs must revisit now

Full interview:
https://www.technadu.com/why-organizations-need-better-understanding-and-rethink-access-least-privilege-and-zero-trust-with-ai-in-the-ecosystem/613877/

Follow for more detailed expert interviews.

#CyberSecurity #IdentitySecurity #ZeroTrust #AccessControl #BeyondTrust #MoreyHaber