#Cymulate
Today I learned that SSM Agent auto-update isn't enabled by default.

Initially, I was focused on addressing a security vulnerability (path traversal) on customer SSM Agents identified by Cymulate. More details below. ↓

Never mind, this Terraform resource will do the trick.
April 18, 2025 at 3:30 PM
🚨📢 Insomni'hack 2025

We are happy to announce Cymulate as our Silver Sponsor.

🤝 Special thanks to the local team!

👉 Register here: insomnihack.ch/register/?ut...

#INSO25 #Insomnihack #cybersecurity #cymulate
March 6, 2025 at 4:19 PM
In this clip from our latest #podcast, David Kellerman the Field #CTO at Cymulate explains how the company's attack simulation feature works - helping organizations test the effectiveness of security products in real life attack scenarios. Check out the full interview here: lnkd.in/efyEiJRe
January 17, 2025 at 1:23 PM
CVE-2025-64669: Uncovering Local Privilege Escalation Vulnerability in Windows Admin Center
CVE-2025-64669: Uncovering Local Privilege Escalation Vulnerability in Windows Admin Center 
Cymulate Research Labs discovered CVE-2025-64669, a local privilege escalation flaw in Windows Admin Center enabling SYSTEM-level compromise.
cymulate.com
December 15, 2025 at 5:28 PM
Exposure validation emerges as critical cyber defense component - Help Net Security www.helpnetsecurity.com/2025/04/25/e...
Exposure validation emerges as critical cyber defense component - Help Net Security
Organizations that run exposure validation processes monthly see a 20% drop in breaches, according to Cymulate.
www.helpnetsecurity.com
April 27, 2025 at 10:16 AM
The Pipe That Trusted Everyone: How a Single Misconfigured Named Pipe Let Any User Hijack OpenAI Codex CLI and Steal Developer Credentials + Video

Introduction: The race to embed artificial intelligence into every developer workflow has created a dangerous blind spot: AI agents are being shipped…
The Pipe That Trusted Everyone: How a Single Misconfigured Named Pipe Let Any User Hijack OpenAI Codex CLI and Steal Developer Credentials + Video
Introduction: The race to embed artificial intelligence into every developer workflow has created a dangerous blind spot: AI agents are being shipped with security models that lag years behind their capabilities. Cymulate Research Labs recently uncovered a critical vulnerability in OpenAI Codex CLI’s Windows sandbox—a classic trust-boundary mistake that allowed any unprivileged user on a shared machine to spoof AI output, inject malicious instructions, and exfiltrate persistent cloud credentials.
undercodetesting.com
July 2, 2026 at 2:45 AM
Azure Identity Token Vulnerability Enables Tenant-Wide Compromise in Windows Admin Center
Azure Identity Token Vulnerability Enables Tenant-Wide Compromise in Windows Admin Center
A high-severity vulnerability in Windows Admin Center’s Azure Single Sign-On implementation has exposed Azure virtual machines and Arc-connected systems to unauthorized access across entire tenants. Cymulate Research Labs discovered the flaw, now tracked as CVE-2026-20965 , which demonstrates how improper token validation can collapse security boundaries between individual machines and complete Azure environments. Microsoft patched the issue via Windows Admin Center Azure Extension v0.70.00 on January 13, 2026, following Cymulate’s August 2025 disclosure. All unpatched deployments below this version remain exposed. CVE ID Description Severity CVSS Score Affected Versions Patch CVE-2026-20965 Improper token validation in WAC Azure SSO allows mixing stolen WAC.CheckAccess token with forged PoP token for lateral movement. High Not yet published < 0.70.00 v0.70.00 Exploitation requires local admin on a WAC-enabled Azure VM or Arc machine, plus a privileged user connecting via Azure Portal. No wild exploitation reported, but retrospective detection advised, Cymulate added . Windows Admin Center uses two tokens: WAC.CheckAccess (verifies role-based access via UPN) and PoP-bound token (browser-generated key pair prevents replay). Flaws include no UPN matching between tokens, acceptance of cross-tenant PoP tokens, non-gateway URLs in PoP (e.g., direct IP via port 6516), reused nonces, and unscoped WAC.CheckAccess granting tenant-wide access. JIT access exposes port 6516 to all IPs, not just gateway DNS, enabling direct forgery without DNS discovery. This collapses VM isolation, allowing impersonation of admins across resource groups. Attack Chain Dump WAC cert, stop service, run rogue server. Capture admin’s WAC.CheckAccess token during portal connection. Enumerate targets via metadata/subnet. Forge PoP using attacker tenant: generate keys, bind via refresh token, insert target resource ID/IP. Send InvokeCommand with mixed tokens for RCE on any accessible WAC machine. Repeat for chaining. Enables lateral movement, privilege escalation, credential theft, cross-subscription compromise, and evasion via fake UPNs. Detection Guidance Monitor for WAC virtual accounts like WAC_user@externaltenant.onmicrosoft.com, indicating abuse. KQL Query for Suspicious Logons: text DeviceLogonEvents | where Timestamp > ago(30d) | where AccountName has "@" | where not(AccountName has "<your-tenant>") | project Timestamp, DeviceName, AccountName, ActionType, LogonType | order by Timestamp desc Flag anomalous WAC activity: new identities on targets, InvokeCommand spikes in trusted contexts. IOCs: Port 6516 open via JIT NSG (all sources). Rogue WAC processes/services. Mixed-tenant UPN logons. Unscoped PoP token reuse. Update to v0.70.00 immediately. Enhance NSG/JIT to gateway-only. Monitor WAC logs for anomalies. This flaw underscores Azure SSO risks: subtle validation gaps enable local-to-cloud pivots, bypassing segmentation. Prioritize patching and simulation testing. Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories. The post Azure Identity Token Vulnerability Enables Tenant-Wide Compromise in Windows Admin Center appeared first on Cyber Security News .
cybersecuritynews.com
January 15, 2026 at 5:02 PM
Cymulate Joins Anthropic’s Cyber Verification Program: The AI Security Shift That Changes Everything + Video

Introduction: The cybersecurity industry has long grappled with a fundamental paradox: the same AI capabilities that empower defenders can also be weaponized by attackers. As organizations…
Cymulate Joins Anthropic’s Cyber Verification Program: The AI Security Shift That Changes Everything + Video
Introduction: The cybersecurity industry has long grappled with a fundamental paradox: the same AI capabilities that empower defenders can also be weaponized by attackers. As organizations race to adopt generative AI for security operations, they face the chilling reality that frontier AI models block legitimate defensive work—exploitation analysis, adversarial simulation, and threat modeling—by default, treating these activities as prohibited dual-use behavior.
undercodetesting.com
July 11, 2026 at 10:00 AM
🎙️ In this clip from our latest podcast, host @paulroberts.bsky.social asks David Kellerman, Field #CTO at #Cymulate about security tool overload and whether enterprises might already have all they need to protect themselves from major cyber risks. #podcast #sponsored
January 16, 2025 at 2:31 AM
Is your business secure or just feeling lucky? 😅

Ingram Micro and Cymulate teamed up to make sure it’s not just a guess.

Find out how to really protect your company:

mastermaverick.com.br/2025/05/cibe...
Cibersegurança Empresarial: Ingram Micro e Cymulate Revolucionam Mercado Brasileiro
Descubra como a parceria entre Ingram Micro Brasil e Cymulate está transformando a cibersegurança empresarial com soluções avançadas de validação de exposição a ameaças.
mastermaverick.com.br
May 14, 2025 at 2:51 AM
Verborgene Gefahr in der Cloud: Schwachstelle in AWS-Organisationen ermöglicht umfassende Kontrolle durch Angreifer
www.all-about-security.de/verborgene-g...
Verborgene Gefahr in der Cloud: Schwachstelle in AWS-Organisationen ermöglicht umfassende Kontrolle durch Angreifer
Sicherheitsforscher der Firma Cymulate haben eine kritische Schwachstelle in der Struktur von AWS-Organisationen aufgedeckt. Im Rahmen ihrer Analyse zu Kontowechsel- und Kompromittierungsszenarien sti...
www.all-about-security.de
July 12, 2025 at 2:53 PM
Security Researcher @ Cymulate Make Your Mark Cymulate’s Continuous Security Validation enables companies to challenge, assess and optimize their cyber-security posture against the evolving cyber...

Origin | Interest | Match
aijobs.net will become foo🦍 - visit foorilla.com!
aijobs.net will become foo🦍 - visit foorilla.com!
aijobs.net
July 3, 2025 at 10:52 AM
One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands
One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands
Windows Admin Center is a locally deployed, browser-based management tool used by IT administrators to manage Windows servers, clients, and clusters from a centralized graphical interface. This newly discovered critical flaw, identified by Cymulate Research Labs, allows attackers to achieve unauthenticated, one-click remote code execution (RCE) on both Azure-integrated and on-premises WAC deployments. By simply coercing a victim into visiting a tampered URL, adversaries can secretly execute arbitrary commands and take over target networks. The vulnerabilities were responsibly disclosed to Microsoft on August 22, 2025. Following the report, Microsoft successfully applied server-side patches to secure all Azure-managed instances. Because this fix was implemented on the service side, cloud customers are protected automatically without requiring any manual action. However, organizations using on-premises WAC deployments must proactively update their systems to the latest release to close the vulnerability and prevent exploitation. The waconazure app runs in the Azure portal via an iframe (source: Cymulate) Core Vulnerabilities Driving the Exploit According to the technical report published by Cymulate Research Labs, the exploit chain relies on three underlying architectural weaknesses that attackers combine for maximum impact: Response-based cross-site scripting (XSS) allows attackers to inject arbitrary JavaScript into both Azure portal flows and on-premises error handling mechanisms. Insecure redirect handling causes WAC to accept externally controlled gateway URLs without proper validation, enabling threat actors to hijack legitimate application flows for spoofing and phishing attacks . Insecure credential storage in on-premises setups leaves sensitive Azure access and refresh tokens directly in the browser’s local storage, exposing them to immediate theft via the XSS flaw. The research highlights distinct attack paths and consequences depending on how the Windows Admin Center environment is deployed . Unsanitized error messages enable HTML injection (source: Cymulate) Azure-managed environments allow attackers to craft authentic-looking URLs containing malicious payloads that prompt fake basic or NTLM authentication, silently harvesting user credentials from a trusted Microsoft origin. On-premises deployments carry a significantly higher security impact because threat actors can force the gateway to execute arbitrary PowerShell commands on managed servers. Connected l ocal gateways expose stored Azure tokens , facilitating lateral movement that grants attackers the victim’s full cloud privileges and tenant control. The Exploit Chain in Action Cymulate researchers demonstrated that the complete attack chain requires minimal user interaction. An attacker-hosted payload can automatically steal client credentials (Source: Cymulate) An adversary needs to register a valid domain name, secure a trusted web certificate, and forge a WAC gateway URL. This malicious link can then be delivered through phishing emails, masked links, or automated web redirection . Once the unsuspecting victim clicks the link, the WAC application automatically redirects traffic to the attacker-controlled server. The rogue server then responds with a crafted error message containing hidden scripts. Because the application fails to sanitize the incoming response properly, the malicious code executes directly within the highly privileged WAC browser environment. This exploit clearly proves that developers must rigorously validate both client input and server responses to prevent complex attacks. While Azure-hosted WAC customers are already protected, the security risk remains critical for internal networks. Cymulate Research Labs strongly advises all security teams managing on-premises Windows Admin Center deployments to upgrade to the latest, patched Microsoft release immediately. Administrators must verify that no outdated instances remain active on their network to prevent complete infrastructure compromise. Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories. The post One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands appeared first on Cyber Security News .
cybersecuritynews.com
April 17, 2026 at 8:47 AM
New Kerberos Relay Attack Uses DNS CNAME to Bypass Mitigations – PoC Released
New Kerberos Relay Attack Uses DNS CNAME to Bypass Mitigations – PoC Released
A critical flaw in Windows Kerberos authentication that significantly expands the attack surface for credential relay attacks in Active Directory environments. By abusing how Windows clients handle DNS CNAME responses during Kerberos service ticket requests, attackers can coerce systems into requesting tickets for attacker-controlled services, bypassing traditional protections. Abuse flow chart (Source: Cymulate) The Attack Vector The vulnerability centers on a fundamental behavior: when a Windows client receives a DNS CNAME record , it follows the alias. It constructs the Ticket Granting Service (TGS) request using the CNAME hostname as the Service Principal Name (SPN). An attacker positioned on-path to intercept DNS traffic can exploit this to force victims into requesting service tickets for attacker-chosen targets. The technique requires an attacker to establish DNS man-in-the-middle capabilities through ARP poisoning, DHCPv6 poisoning (MITM6), or similar methods. The victim is redirected to the attacker’s server, which responds with 401 to force Kerberos authentication. (Source: Cymulate) When a victim attempts to access a legitimate domain asset, the malicious DNS server responds with a CNAME record pointing to an attacker-controlled hostname, along with an A record resolving to the attacker’s IP address. This causes the victim to authenticate against the attacker’s infrastructure using a ticket intended for the attacker’s target service. Attack Capabilities and Impact : Impact Area Description RCE Remote code execution via ADCS Web Enrollment (ESC8) Relay Attacks Cross-protocol relays (HTTP→SMB, HTTP→LDAP) Lateral Movement Unauthorized access and network spread Impersonation User impersonation without passwords Testing confirmed exploitation works on default configurations across Windows 10, Windows 11 , Windows Server 2022, and Windows Server 2025. The attack succeeds against unprotected services, including SMB, HTTP, and LDAP, when signing or Channel Binding Tokens (CBT) are not enforced. The vulnerability was responsibly disclosed to Microsoft in October 2025. DNS poisoning redirects the victim to a malicious target, forcing a Kerberos TGS request. (Source: Cymulate) In response, Microsoft implemented CBT support for HTTP.sys. It released patches across supported Windows Server versions in January 2026 security updates, tracked as CVE-2026-20929 . However, this mitigation only addresses HTTP relay scenarios. The underlying DNS CNAME coercion primitive remains unchanged, leaving other protocols vulnerable. Proof of Concept Researchers released a modified version of the MITM6 tool on GitHub with CNAME poisoning capabilities. The tool supports targeted CNAME poisoning against specific domains or all DNS queries. Includes DNS-only mode for ARP poisoning integration, and enables passthrough for critical infrastructure connectivity. Exploitation requires Python 3.x and a Linux operating system. A record for adcs-server.mycorp.local pointing to the attacker’s IP  (Source: Cymulate) Cymulate Research Labs advises organizations to implement layered defenses: Security Layer Recommended Control Purpose SMB Security Enforce SMB signing on all servers beyond domain controllers Prevents SMB relay and man-in-the-middle attacks Directory Services Require LDAP signing and enforce LDAPS Channel Binding Tokens (CBT) where supported Protects against LDAP relay and credential interception Web Services Mandate HTTPS with CBT for all internal HTTP services Mitigates NTLM relay attacks over HTTP DNS Infrastructure Harden DNS servers and consider DNS over HTTPS (DoH) Reduces DNS spoofing and traffic manipulation risks Kerberos Monitoring Monitor anomalous TGS requests targeting unusual SPNs Detects potential Kerberos abuse or lateral movement Threat Detection Alert on cross-protocol authentication patterns Identifies NTLM/Kerberos relay and protocol abuse attempts The research underscores a critical security reality: Kerberos itself does not inherently prevent relay attacks.  Enforcement of protection lies at the service level. After DNS poisoning, the victim connects to the attacker’s rogue HTTP or SMB server.(Source: Cymulate) Disabling NTLM alone is insufficient; organizations must explicitly enforce anti-relay protections across every Kerberos-enabled service to eliminate relay risk effectively. Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories. The post New Kerberos Relay Attack Uses DNS CNAME to Bypass Mitigations – PoC Released appeared first on Cyber Security News .
cybersecuritynews.com
January 19, 2026 at 7:44 AM
Anthropic MCP Server Flaws: Path Traversal & Symlink Attacks Allow RCE
Anthropic MCP Server Flaws: Path Traversal & Symlink Attacks Allow RCE
Cymulate reveals two flaws (CVE-2025-53110, CVE-2025-53109) in Anthropic's Filesystem MCP Server, allowing path traversal, symlink attacks, and RCE, exposing AI developer machines.
securityonline.info
July 4, 2025 at 2:36 AM
Organizations are increasingly taking to the offensive to foil threats before they become attacks, according to a report released Wednesday. #cybersecurity * #infosec #zerottrust #datasecurity #Cymulate #SANSInstitute #XMCyber #CriticalStart #BforeAi #Drata
jpmellojr.blogspot.com/2024/03/whit...
March 6, 2024 at 4:36 PM
Cymulate’s new platform turns threat validation into smarter defense

Cymulate announced the new Cymulate Exposure Management Platform, which validates, prioritizes and optimizes the entire security ecosystem – continuously. The new Cymulate platform unifies exposure data and int…

#hackernews #news
Cymulate’s new platform turns threat validation into smarter defense
Cymulate announced the new Cymulate Exposure Management Platform, which validates, prioritizes and optimizes the entire security ecosystem – continuously. The new Cymulate platform unifies exposure data and integrates threat validation results to accelerate existing SecOps, detection engineering and exposure management workflows. The new Cymulate Exposure Management Platform prioritizes remediation action by correlating data from multiple vulnerability scanners and exposure discovery tools with proof of exploitability from threat validation and compensating security controls. To prioritize threats, …
www.helpnetsecurity.com
August 6, 2025 at 11:47 AM