Overview
Description
Statistics
- 18 Posts
- 5 Interactions
Fediverse
Cisco SD-WAN CVE-2026-76504 analysis and exploit walk-through available c/o Landon Rice on the @vulncheck team ㊙️
https://www.vulncheck.com/blog/revenge-of-the-sd-wan-cve-2026-76504
Recent geopolitical news indicates Russia initiated a winter strike campaign targeting Ukraine's energy infrastructure on September 30. In cybersecurity, CISA added a critical Cisco Catalyst SD-WAN Manager authentication bypass flaw (CVE-2026-76504) to its Known Exploited Vulnerabilities catalog on September 30. On the technology front, Chinese hackers were reported to be impersonating AI experts to target US policy minds on October 1. Additionally, the NSA announced new post-quantum cryptography measures to safeguard national security systems on October 1.
U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog
Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)
Threat Advisory: CVE-2026-76504 Affected Vendor/Product: Cisco - Catalyst SD-WAN Manager Vulnerability Type (CWE): N/A Operational Threat Level:...
https://thecybermind.co/2026/10/01/cve-2026-76504-catalyst-sd-wan-manager/
Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)
CISA’s active exploitation verification of CVE-2026-76504 demands an immediate, high-priority posture adjustment across all Cisco Catalyst SD-WAN Manager…...
https://thecybermind.co/2026/10/01/cve-2026-76504-catalyst-sd-wan-manager-3/
📰 Cisco Patches Actively Exploited SD-WAN Auth Bypass Zero-Day
Cisco patches critical auth bypass zero-day (CVE-2026-76504) in Catalyst SD-WAN Manager. CVSS 9.8 flaw actively exploited. Unauthenticated attackers can gain admin access. CISA added to KEV. Patch immediately! #Cisco #ZeroDay #SDWAN #CVE202676504
Bluesky
Overview
Description
Statistics
- 8 Posts
- 37 Interactions
Fediverse
Great IOCs on the follow up spray and pray activity on #PitScaler so far.
For context this activity definitely is not related to the inital threat actor activity in early September. This is new stuff.
oh wow that grep|sed|awk pipeline...
I keep saying this:
Parsing strings all over the place is a funny idea that #Unix had, but inherently prone to error and, frankly, horribly insecure.
Attackers exploit Citrix NetScaler zero-day CVE-2026-88772 for root access, then hide WHIPSHOT web shells and a SLAPSHOT tunneler. Patch now.
#CitrixNetScaler #ZeroDay #CVE202688772 #CVE202688771 #WHIPSHOT #SLAPSHOT #Mandiant #CyberSecurity
https://securityonline.info/citrix-netscaler-zero-day/?utm_source=mastodon&utm_medium=jetpack_social
📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack
Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE
Bluesky
Overview
Description
Statistics
- 8 Posts
- 5 Interactions
Fediverse
Un domaine eu\.org cité par Microsoft sur l'attaque Zimbra. Domaine suspendu. Sauf erreur de ma part, Microsoft n'a jamais contacté eu\.org. Je n'en ai eu connaissance que ce matin par @dascritch qui m'a envoyé le lien @NextInpact
🚨 Attackers exploited a Zimbra flaw to plant web shells and harvest authentication secrets.
CVE-2026-73570 can be triggered by a crafted SMTP request when SNMP notifications are enabled and zimbra-snmp is installed.
Read: https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
#infosec #Zimbra
https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/
Bluesky
Overview
Description
Statistics
- 8 Posts
Fediverse
CVE-2026-88772, a Citrix NetScaler DTLS memory overflow, is exploited in the wild. A watchTowr PoC and full details are now public. Patch NetScaler now.
#Citrix #NetScaler #CVE202688772 #DTLS #watchTowr #KEV #ZeroDay #RCE
Attackers exploit Citrix NetScaler zero-day CVE-2026-88772 for root access, then hide WHIPSHOT web shells and a SLAPSHOT tunneler. Patch now.
#CitrixNetScaler #ZeroDay #CVE202688772 #CVE202688771 #WHIPSHOT #SLAPSHOT #Mandiant #CyberSecurity
https://securityonline.info/citrix-netscaler-zero-day/?utm_source=mastodon&utm_medium=jetpack_social
📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack
Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE
Bluesky
Overview
- Sharp Corporation
- Multiple Multifunction Printers
Description
Statistics
- 1 Post
- 48 Interactions
Fediverse
Fuck this bullshit. This 2024 CVE was just published today. Which, fine, whatever. It happens. Except it specifically says it was observed EITW in July 2024.
https://www.cve.org/CVERecord?id=CVE-2024-58388
Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.
Witholding a CVE for something known to be EITW for over two years is fucking bullshit. Especially when the PoC was published in June 2024:
https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html#pre-auth-lfi
But at least there's a Nuclei template:
Overview
Description
Statistics
- 3 Posts
- 3 Interactions
Fediverse
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
Bluesky
Overview
Description
Statistics
- 2 Posts
- 4 Interactions
Fediverse
Happy #zeroday FortiMail customers
CVE-2026-104286: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
This has been reported to be exploited in the wild
Attackers exploit CVE-2026-104286, a 9.8 FortiMail vulnerability allowing unauthenticated file writes. CISA adds it to KEV. Apply the workaround.
#Fortinet #FortiMail #CVE2026104286 #PathTraversal #CISAKEV #ActivelyExploited #ZeroDay
Overview
Description
Statistics
- 2 Posts
Fediverse
Learn how to patch critical ASUS security vulnerabilities like CVE-2026-13313 to protect your routers and motherboards from severe network exploits.
CVE-2026-13313 (HIGH, CVSS 8.9) in ASUS routers: Authenticated attackers can enable Telnet via debug code, gaining root command execution. Restrict management access & monitor Telnet until patch info is released. https://radar.offseq.com/threat/cve-2026-13313-cwe-489-active-debug-code-in-asus-router-57f2c007e7c82b59 #OffSeq #ASUS #Infosec #Vuln
Overview
Description
Statistics
- 2 Posts
Fediverse
From Check Point Research: Exploitation of CVE-2026-85102 and CVE-2026-93616
Check Point has observed active exploitation of two critical pre-authentication vulnerabilities with CVSS scores of 9.8 - CVE-2026-85102 and CVE-2026-93616. The flaws affect Security Gateway and Security Management products and can enable remote code execution. Fixes for both vulnerabilities are available.
#CheckPoint #CheckPointSoftwareTechnologies #CVE #CVE202685102 #CVE202693616
Overview
- WatchGuard
- Fireware OS
Description
Statistics
- 2 Posts