Description
Statistics
- 20 Posts
- 13 Interactions
Fediverse
Google and CISA warned that an actively exploited zero-day vulnerability (CVE-2026-58704) affecting Pixel cellular modems.
This allows attackers to silently bypass permission checks and escalate privileges with no user interaction!
It was quickly added to CISA's Known Exploited Vulnerabilities (KEV) catalog [1.2.1, 1.5.1].
Would be an excellent idea for Pixel owners to ownload and apply the September Android OS patches ASAP!
@skyblitz CVE-2026-58704 is a modem firmware vulnerability with a patch released today and it will be included in our upcoming release.
If you've got a Google Pixel cell phone, do a system patch immediately. There is an active vulnerability that allows the hacker to take control of your device with no user interaction. It is being actively used in the wild.
(CISA TS-MAN) The Cyber Mind TSUITE Brief: CVE-2026-58704 – Google Pixel Improper Authorization Vulnerability
Actionable threat intelligence and end-to-end hardening strategies for CVE-2026-58704, addressing improper authorization flaws in Google Pixel cellular modems....
Google confirmed a Pixel modem zero-day (CVE-2026-58704) exploited in a zero-click spyware attack to escape the modem sandbox. Update now.
#Pixel #ZeroDay #CVE202658704 #Google #Spyware #ZeroClick #CyberSecurity
https://securityexpress.info/pixel-modem-zero-day/?utm_source=mastodon&utm_medium=jetpack_social
「Google、限定的な標的型攻撃の兆候が見られる中、Pixelモデムの脆弱性を修正 」: #TheHackerNews
「Googleは、 明らかにした。 同社のPixel Cellular Modemに存在する深刻なセキュリティ上の欠陥が、実際に悪用されていることを
(CVSSスコア:8.0)として追跡されているこの脆弱性は CVE-2026-58704 、権限昇格の欠陥です。
によると、「セルラーモデムには、コードの論理エラーにより権限がバイパスされる可能性がある」とのことです NIST(米国国立標準技術研究所)の国家脆弱性データベース(NVD)に掲載されているバグの説明 。「これにより、追加の実行権限を必要とせずに、リモート(近接/隣接)での権限昇格が可能になる可能性がある。悪用にはユーザーの操作は不要である。」 」
https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html
「Google Pixel端末がゼロクリック攻撃でハッキングされる
/CISAは連邦政府機関に対し、パッチ適用にわずか3日間しか猶予を与えていない。 」: #TheRegister
「Googleと米国政府は、Pixelスマートフォンの携帯モデムに存在するゼロデイ脆弱性を悪用した攻撃者が、権限チェックを回避し、ユーザーの操作なしに権限を昇格できると警告した。この脆弱性は、アップデートを行うことで既に修正されている。
Googleは 火曜日に、 CVE-2026-58704 として追跡されているこの重大な脆弱性 を公表し 、その際、このセキュリティホールが「限定的かつ標的を絞った悪用を受けている可能性がある」と警告した。つまり、Googleが問題を修正する前に、悪意のある人物がこのバグを発見し、悪用していたということだ。」
@GrapheneOS funny to see google fixing : CVE-2025-48595 that was fixed looooooong ago in your.
i don't see CVE-2026-58704, is it already fixed ?
Bluesky
Overview
Description
Statistics
- 8 Posts
- 17 Interactions
Fediverse
Patch your Cisco ISE. CVE-2026-76460 a perfect 10 and is EITW. 🥳
The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.
CRITICAL auth bypass (CVE-2026-76460) in Cisco ISE & ISE-PIC is being actively exploited. Remote attackers gain root on management interface via crafted API calls. Patch ASAP — no workarounds except ACLs. Details: https://radar.offseq.com/threat/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day-d5bd452a61e0a8f8 #OffSeq #Cisco #ZeroDay
An exploited Cisco ISE vulnerability (CVE-2026-76460) allows remote root access. Patch this critical Cisco ISE vulnerability to secure networks.
「Ciscoは、ISEのゼロデイ脆弱性が攻撃に悪用され、深刻な被害を受ける可能性があると警告している。 」: #BLEEPINGCOMPUTER
「シスコは、攻撃者が実際に悪用している、深刻度が最大レベルのアイデンティティサービスエンジンの脆弱性に対処するためのセキュリティアップデートをリリースしました。
Cisco ISEは、IT管理者がエンドポイント、ユーザー、およびデバイスのネットワークリソースへのアクセスを管理するために使用する集中型ポリシープラットフォームであり、多くの場合、ゼロトラストセキュリティモデルを適用しながら使用されます。
このセキュリティ上の欠陥( CVE-2026-76460 として追跡)により、リモートの攻撃者は、Cisco Identity Services Engine(ISE)およびCisco ISE Passive Identity Connector(ISE-PIC)のAPIの脆弱性を悪用することで、設定に関係なく認証を回避できます。 」
Bluesky
Overview
Description
Statistics
- 9 Posts
- 1 Interaction
Fediverse
Global cybersecurity agencies, including CISA & NSA, issued guidance to mitigate 17 Active Directory compromise techniques (Sept 16). Cisco patched an actively exploited email gateway zero-day (CVE-2026-76461). Geopolitically, the US confirmed deploying space weapons, drawing warnings from China about an arms race (Sept 15). AI is now the leading driver for new cybersecurity spending.
Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution https://www.esecurityplanet.com/threats/news-cisco-secure-email-gateway-cve-2026-76461/
Recent developments include Cisco patching a critical zero-day (CVE-2026-76461) in its Secure Email Gateway, which was actively exploited for root command execution. Geopolitically, China warned against weaponizing space after the US confirmed orbital weapon deployments. In technology, debates continue on AI safety versus national competitive advantage, with US Speaker Johnson rejecting development pauses.
Bluesky
Overview
- checkpoint
- Quantum Security Management
Description
Statistics
- 5 Posts
- 13 Interactions
Fediverse
🚨New Censys Advisory: CVE-2026-91843
A critical (CVSS 9.8) unauthenticated RCE affects Check Point Quantum Security Management and Log Servers.
Censys observes 3,836 hosts globally exposing the management/log server role. This is total product presence, not a confirmed-vulnerable count.
No public PoC or confirmed exploitation has been reported as of publication. Check Point has released patches for supported versions via LivePatch.
Read the analysis and remediation details: https://censys.com/advisory/cve-2026-91843/
🚨 Please read this important update from Check Point:
CVE-2026-91843 - Stack overflow in login process to the Security Management and Log Servers
https://support.checkpoint.com/results/sk/sk1000155
#CheckPoint #CheckPointsoftwareTechnologies #CVE #CVE202691843
Check Point fixed a critical Check Point login flaw (CVE-2026-91843). Patch this Check Point login flaw now to block unauthenticated remote root takeovers.
#CheckPoint #Cybersecurity #CVE202691843 #InfoSec #Vulnerability
Bluesky
Overview
- Issabel Foundation
- Issabel Framework
Description
Statistics
- 4 Posts
- 3 Interactions
Fediverse
‼️ Attackers are exploiting a critical Issabel Framework flaw.
CVE-2026-89026 uses a hard-coded JWT signing key, letting unauthenticated remote attackers forge tokens and execute OS commands as the Asterisk user. A fix is available.
How the flaw works: https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
An Issabel PBX vulnerability exploited in active attacks allows remote code execution. Patch this Issabel PBX vulnerability to secure systems.
Bluesky
Overview
Description
Statistics
- 3 Posts
Fediverse
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-84869 – ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
C-Suite threat intelligence and mitigation protocols for CVE-2026-84869, addressing active exploitation vectors within enterprise ConnectWise environments....
Bluesky
Description
Statistics
- 4 Posts
- 1 Interaction
Bluesky
Overview
- NLnet Labs
- Unbound
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
CVE-2026-81642: CRITICAL heap buffer overflow in NLnet Labs Unbound ≤1.26.0. Exploitable via DNSKEY with owner compression pointer — possible DoS & RCE. Patch ASAP. https://radar.offseq.com/threat/cve-2026-81642-cwe-122-heap-based-buffer-overflow-in-nlnet-labs-unbound-2ab04cc5a0313c65 #OffSeq #DNS #Unbound #Vuln #RCE
NLnet Labs patched critical Unbound DNS vulnerabilities. Upgrade now to fix Unbound DNS vulnerabilities and block remote code execution attacks.
Overview
- WSO2
- WSO2 Universal Gateway
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
📰 Critical WSO2 API Flaw Under Active Attack, Exposes Enterprise Data
Critical auth bypass (CVE-2026-5430, CVSS 10.0) in WSO2 API Manager is now actively exploited. Attackers can take over admin accounts. Patched in April 2026, ensure your systems are updated! #WSO2 #APISecurity #CyberAttack
Overview
- WNC
- T-Mobile 5G Box IDU
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
Vulnerabilities in a 5g router from T-Mobile, the company known for its security?! I'm shocked. Shocked! Well, not that shocked.
Patch the critical T-Mobile 5G Box vulnerabilities today. Learn how WNC router flaws allow auth bypass and command injection, and secure your network.
#TMobile5G #RouterSecurity #CVE202640854 #Cybersecurity #Vulnerability