Meta has remediated a critical security vulnerability that exposed sensitive customer support information due to weaknesses in authorization controls across its shared backend infrastructure. The flaw involved broken access control and insecure direct object references, allowing unauthorized users to access support-related resources without the required permissions. The issue affected multiple Meta support services and highlighted the risks of inconsistent authorization mechanisms within interconnected systems. Researchers discovered that certain GraphQL queries returned customer support data even when the requesting user lacked appropriate access rights. As a result, attackers could view sensitive information such as customer support emails, support case records, live chat conversations, internal notes, attachments, and case metadata. The vulnerability also allowed unauthorized users to perform actions including creating support tickets for other organizations, modifying case statuses, and adding unauthorized participants to support threads, increasing the risk of data exposure, social engineering, and operational disruption. The issue was initially identified during security testing of Meta Horizon Managed Solutions and was later traced to shared support infrastructure that relied on insufficient authorization checks and predictable support case identifiers. Researchers found that these weaknesses allowed attackers to enumerate support records across multiple services. Although Salesforce components were integrated into the environment, the vulnerability resulted from Meta's implementation rather than the Salesforce platform itself. Meta has since resolved the issue, reinforcing the importance of consistent authorization controls and secure access validation across shared applications and enterprise support environments.
Researchers H0j3n and Aniq Fakhrul disclosed a proof-of-concept exploit named Certighost for CVE-2026-54121, an Active Directory Certificate Services (AD CS) vulnerability patched ...
At the core of an advanced malvertising attack scheme known as FakeAgent, SectopRAT was utilized by the cybercriminals in exploiting Anthropic’s Claude platform for the distribut...
Researchers at Group-IB have uncovered a previously undocumented cyber espionage campaign, tracked as JadeProx, targeting government, healthcare, and education organizations across...