Every story tagged Endpoint Security, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
140 stories · open in the command center
AI-powered PCs, Intel AMT, and managed services are changing endpoint management from a reactive support function into a strategic capability that can improve security, resilience, and employee productivity. For CIOs, the business impact is lower downtime and faster issue resolution, while the strategic implication is a more standardized and remotely manageable device estate that better supports hybrid work. IT organizations will need to align hardware, remote management, and service partners around a proactive endpoint strategy rather than treating laptops and desktops as isolated assets.
A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary code on the affected endpoint with the elevated privileges of the agent.
A missing integrity verification vulnerability in the Windows client software for ClearPass Policy Manager could allow malicious users on a local instance to elevate their user privileges. A successful exploit could allow these users to execute attacker-supplied code with elevated privileges on the local system.
Researchers demonstrated a proof-of-concept technique, "BigDiskBuster," that can stop Microsoft Defender from receiving security intelligence updates while the Defender service continues to run normally. For CIOs and technology leaders, the business risk is a silent protection gap: endpoints may appear healthy and compliant while actually missing the latest detections, extending the window for malware persistence and increasing exposure across the fleet. IT organizations should treat security update integrity as an operational control, not just an application status check, and add monitoring for failed Defender updates, disk-usage anomalies, and related I/O behaviors.
Microsoft is tightening Outlook and Outlook on the Web by blocking .msix and .msixbundle attachments by default, reducing the risk that users will accidentally install malicious Windows application packages. For CIOs and IT leaders, this is another example of Microsoft shifting more email security controls into the platform, which lowers endpoint risk but may require policy exceptions for legitimate software distribution workflows. Organizations should review whether these package types are used internally and update mail policies before the November rollout to avoid business disruption.
Attackers are increasingly abusing legitimate RMM platforms, using phishing-delivered files and trusted signed installers to gain persistence and remote control while blending into normal administrative traffic. For CIOs and IT leaders, this raises the risk that sanctioned management tools can become an entry point for ransomware or hands-on-keyboard activity, making identity controls, egress monitoring, and vendor-account governance as important as traditional malware defenses.
The NXP GAU ADC driver (drivers/adc/adc_mcux_gau_adc.c) validated the caller-supplied sequence->buffer_size, which is expressed in bytes, against the number of active channels, which is a sample count. It then stored that byte count directly in data->results_length and used it in mcux_gau_adc_read_samples() as the number of uint16_t slots available. Because each conversion result occupies sizeof(uint16_t) bytes, a buffer that was accepted as "large enough" could be written with up to twice its size in bytes, so every sample past the buffer's midpoint was written out of bounds. adc_read() and adc_read_async() are Zephyr system calls. The syscall verifier in drivers/adc/adc_handlers.c only confirms that the caller owns buffer_size writable bytes (K_SYSCALL_MEMORY_WRITE); deciding whether that size is sufficient for the requested channels and extra_samplings is delegated entirely to the driver. On a build with CONFIG_USERSPACE=y, a user-mode thread that has been granted the ADC device...
The system-call verifier for i3c_do_ccc() in drivers/i3c/i3c_handlers.c validated the outer struct i3c_ccc_payload, the broadcast ccc.data buffer and the targets.payloads[] array, but did not validate the per-target data buffers those array elements point at. Each struct i3c_ccc_target_payload carries its own data pointer and data_len, and neither was passed through K_SYSCALL_MEMORY() before the payload was handed to z_impl_i3c_do_ccc() and on to the controller driver. The verifier also operated on the caller's live structure rather than a snapshot, so validated fields could be changed by a second user thread between the check and the driver's use — unlike the sibling z_vrfy_i3c_transfer(), which has always copied its message array first. The defect is only present in CONFIG_USERSPACE builds, where drivers/i3c/i3c_handlers.c is compiled. An unprivileged user-mode thread that has been granted access to the I3C controller device object — the ordinary way an application lets a user th...
This article highlights the diversity and creativity of user-agent strings seen in honeypot traffic, showing how scanners often advertise their intent, include contact details, reuse public lists, or even attempt parser exploits like Shellshock. For CIOs and technology leaders, the business impact is that simple web telemetry can reveal active reconnaissance, attacker tooling, and weak hygiene in external-facing environments—making user-agent analysis a low-cost source of threat intelligence that can improve detection, prioritization, and exposure management. IT organizations should treat these strings as an operational signal to strengthen logging, enrich SIEM detections, and monitor for repeated or unusual scanning patterns that may precede exploitation.
Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.
Researchers have uncovered Linux backdoors that closely mimic legitimate Korean and Taiwanese mail security appliances, making them exceptionally difficult to detect and increasing the risk of long-term stealth compromise in enterprises, telecoms, and public-sector environments. For CIOs and technology leaders, this is a reminder that edge appliances and Linux-based security controls are now high-value attack surfaces, and IT organizations need stronger integrity monitoring, behavioral baselining, and threat hunting beyond signature-based defenses.
colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local user on a monitored host to inject escape sequences into the terminal of an operator running colmux, via a crafted process name (argv[0]).
Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can authenticate as iOS/iPadOS hosts to read device data and trigger device-scoped actions including software installation and MDM migration.
Magnet Forensics reportedly found a way to preserve an iPhone’s After First Unlock state even if the device reboots, reducing the effectiveness of Apple’s Inactivity Reboot protection and weakening one of the safeguards that helps keep seized or stolen devices from remaining accessible. For CIOs and IT leaders, this underscores that endpoint security controls on mobile devices are not absolute: forensic vendors may be able to bypass protections, which has implications for investigations, legal holds, chain-of-custody, and expectations around data-at-rest risk on corporate iPhones.
A new Mac malware campaign is disguising a fake Zoom installer to trick users into manually bypassing Apple’s Gatekeeper protections, then deploying an infostealer that can exfiltrate sensitive data within seconds. For CIOs and technology leaders, this underscores that endpoint risk is increasingly driven by user deception and trust abuse, making secure software sourcing, admin privilege controls, and rapid threat detection essential parts of the IT security strategy.
Attackers are using a signed, legitimate ScreenConnect client delivered through phishing to establish remote access, illustrating how trusted remote management tools can bypass traditional security controls and appear benign to browsers and endpoint defenses. For CIOs, this raises the strategic risk that commodity, vendor-signed software can become an attacker-controlled access path, increasing the need for stronger application control, email/web filtering, and behavioral detection rather than relying only on signature-based defenses.
OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get over the node WebSocket to silently capture screenshots, photograph users through webcams, and obtain device geolocation without user interaction.
OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load attacker-controlled code and achieve arbitrary code execution.
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system.
`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes. Every consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls. **Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever — `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`), `_nx_icmpv6_process_na` (`:147, :156`) and `_nx_icmpv6_process_redirect` (`:247, :350`). The walk runs in the IP thread, which is the highest-priority thread and does not yield inside the loop, so...
IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.
Buffer overflow vulnerabilities exist in the affected interface of HPE Networking Instant ON APS that could allow an unauthenticated adjacent attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
In Anjvision YSSD-RTMP-H5 firmware version 3.3.2.4, an empty-body POST to /setUserConfig, dispatched through the web server's SOAP-RPC handler, silently downgrades the administrator password to the default value and corrupts the in-memory authentication state until the device reloads. The handler does not verify the session's privilege level, so any authenticated user can trigger it.
The article highlights Orchard, a tool designed to continuously enforce macOS updates, application updates, and security settings so Apple fleets stay compliant and audit-ready. For CIOs and IT leaders, the business value is reduced patching risk, less manual operational overhead, and stronger endpoint governance across a growing Apple environment, making patch automation a strategic capability rather than a routine admin task.
Mac-targeted attacks are becoming more user-driven and harder to detect: the dominant delivery method is now ClickFix-style social engineering, where employees are tricked into pasting malicious commands into Terminal, bypassing many native Mac protections. The business impact for CIOs is a shift from commodity stealers to persistent implants and backdoors that can exfiltrate credentials and enable repeat access, increasing risk to identity, data, and operational continuity across Mac fleets. IT and security teams need to move beyond file-based scanning and invest in behavior-based detection, tighter endpoint controls, and stronger user education because attackers are increasingly disguising malware as trusted Apple services.
Attackers are impersonating HR and payroll software with fake desktop apps that install legitimate remote-management software, creating a stealthy, persistent foothold on employee endpoints and putting highly sensitive personnel and payroll data at risk. For CIOs, the key implication is that traditional malware defenses may miss abuse of trusted tools and infrastructure, so IT organizations need stronger vendor verification, endpoint control, and detection for unauthorized RMM deployments and silent installers. This campaign is a reminder that social engineering aimed at business functions can become an enterprise access problem, not just a fraud issue.
This BOFH satire underscores a real IT governance lesson: when support teams replace disciplined troubleshooting with trendy, unvalidated methods, they risk prolonging outages, increasing collateral damage, and eroding user trust. For CIOs and technology leaders, the strategic implication is that IT organizations should balance empathy and customer experience with clear diagnostic playbooks, change control, and operational rigor so service quality improves without sacrificing reliability.
SectopRAT’s return highlights how attackers can bypass traditional trust signals by embedding a remote access Trojan inside a legitimate-looking application, increasing the risk of undetected compromise across endpoints. For CIOs and technology leaders, the key implication is that application identity alone is no longer sufficient; IT teams need stronger behavior-based monitoring, detection engineering, and rapid response capabilities to limit business disruption, data exposure, and lateral movement.
This campaign shows how attackers are abusing legitimate websites and a ClickFix-style social engineering flow to target macOS users, turning trusted browsing into a malware delivery channel. For CIOs and IT leaders, the business risk is broader endpoint compromise and credential theft across Mac fleets, with the added challenge that the initial lure looks like routine bot protection rather than a traditional malicious download.
A new process parameter-poisoning technique can bypass EDR monitoring by injecting code into a process’s initialization structures rather than using the Windows APIs that many tools watch, which increases the risk of stealthy malware execution and reduces confidence in endpoint-only detection. For CIOs and technology leaders, this reinforces that modern adversaries are targeting gaps in telemetry and that IT security teams must strengthen layered defenses, behavioral analytics, and threat hunting beyond standard API-based controls.