Overview
Description
Statistics
- 12 Posts
- 1 Interaction
Fediverse
Recent reports confirm a critical GitLab zero-day (CVE-2026-85706) exploited within 24 hours, alongside new EU Cyber Resilience Act mandates for 24-hour vulnerability reporting. Operational technology (OT) sectors face emerging ransomware threats. Meanwhile, leading AI developers advocate for a slowdown in development due to safety concerns, prompting market shifts. Geopolitically, the BRICS summit addressed rising global tensions and the "weaponization of technology."
CVE-2026-85706 GitLab CE/EE: unauthenticated arbitrary file read via commits API, CVSS 10. Affects 18.7 up to 19.1.8, 19.2.6, 19.3.2. No patch confirmed yet, restrict access now. https://www.valtersit.com/cve/CVE-2026-85706/ #CVE #GitLab #infosec
⚠️GitLab : CVE-2026-85706 est activement exploitée.
Une faille critique de traversée de répertoires permet à un attaquant non authentifié de lire des fichiers arbitraires sur le serveur.
Encore une vulnérabilité qui prend des chemins de traverse…
../../../../etc/ :dumpster_fire_gif: 👀
-->GitLab auto-hébergé exposé sur Internet : mise à jour rapide recommandée.
Correctifs : 19.1.8, 19.2.6 et 19.3.2.
La faille a déjà rejoint le catalogue KEV de la CISA, et ça commence clairement à renifler autour : watchTowr et plusieurs honeypots ont déjà vu passer des tentatives de probing.
Onyphe recense une bonne centaine d’instances vulnérables en CH aujourd'hui...
Bluesky
Overview
Description
Statistics
- 4 Posts
Fediverse
ConnectWise ScreenConnect CRITICAL vuln (CVE-2026-84869) exploited in worm-like attacks — unauthorized file transfer & execution via remote sessions in versions <26.6.5. Patch to 26.6.5 now or disable TransferFiles. https://radar.offseq.com/threat/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks-c3e27ae69aeeacb1 #OffSeq #Cybersecurity #Vuln #CISA
CRITICAL CISA KEV ALERT: CVE-2026-84869 targets ConnectWise ScreenConnect with unauthorized file transfer and RCE. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to protect your environment. https://thecybermind.co/g5ob
Bluesky
Overview
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
⚠️🐰 Tencent flaw deploys GrayRabbit
CVE-2026-51990 enables RCE through Sogou Input Method; fixed in version 16.3.
Defend against the CVE-2026-51990 Sogou exploit. Discover how hackers use this one-click flaw to drop backdoors and how to secure your systems today.
#CVE202651990 #SogouInputMethod #CyberSecurity #UNC3569 #InfoSec #EndpointSecurity #ThreatIntel
Overview
Description
Statistics
- 2 Posts
Fediverse
Discover how the PivotC2 FortiGate RAT uses CVE-2025-25249 exploitation to harvest credentials and tunnel traffic across corporate network environments.
#PivotC2 #FortiGate #Malware #Cybercrime #CVE202525249
http://securityonline.info/pivotc2-fortigate-rat/?utm_source=mastodon&utm_medium=jetpack_social
Overview
- irontec
- sngrep
Description
Statistics
- 3 Posts
Bluesky
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 1 Post
- 12 Interactions
Fediverse
🔎 NEXUS8 WEEKLY DIGEST · 💥 EXPLOIT
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The vulnerability…
Also tracked this week: Hackers exploit Sangoma Switchvox flaw to deploy reverse… · Microsoft Plugs Nearly 1,000…
Overview
Description
Statistics
- 2 Posts
Fediverse
Overview
- Cisco
- Cisco Secure Email
Description
Statistics
- 1 Post
- 6 Interactions
Fediverse
ayy lmao Cisco CVE-2026-76461
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.