Overview
Description
Statistics
- 8 Posts
- 4 Interactions
Fediverse
Geopolitical tensions persist between the U.S. and Iran regarding actions in the Strait of Hormuz (Sept 1, 2026). On the cybersecurity front, critical infrastructure, including Midwest water utilities, faces new ransomware attacks. Additionally, a severe authentication bypass flaw (CVE-2026-82329) in JFrog Artifactory is actively being exploited. OpenAI has issued a stark warning regarding the escalating threat of AI-enabled cyberattacks.
#JFrog #Artifactory: Attackers are already exploiting critical auth bypass CVE-2026-82329 (CVSS 9.8) to mint admin tokens. Compromising your organisation's artifact repository could poison builds and trigger #SoftwareSupplyChain attacks - patch now!
👇
https://www.csoonline.com/article/4217534/exploited-jfrog-artifactory-bug-puts-software-supply-chain-on-alert.html
Angreifer nutzen derzeit eine kritische Schwachstelle in JFrog Artifactory (CVE-2026-82329) aktiv aus. Die Sicherheitslücke erlaubt das Umgehen der Authentifizierung, wodurch unberechtigte administrative Token erstellt werden können. Betroffene Betreiber müssen umgehend die bereitgestellten Software-Aktualisierungen einspielen und bestehende Tokens prüfen.
Bluesky
Overview
- Microsoft
- Microsoft Exchange Server 2016 Cumulative Update 23
Description
Statistics
- 5 Posts
- 6 Interactions
Fediverse
Exchange Server : près de 22 000 serveurs exposés sont vulnérables à la CVE-2026-62911 https://www.it-connect.fr/microsoft-exchange-cve-2026-62911/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #Exchange
Más de 21,000 servidores Microsoft Exchange siguen expuestos al CVE-2026-62911
https://blog.elhacker.net/2026/09/mas-de-21000-servidores-microsoft.html
Bluesky
Overview
Description
Statistics
- 11 Posts
- 10 Interactions
Fediverse
SonicWall weist aktuell auf 2 Schwachstellen in seiner SMA1000-Serie hin.
Während die nach CVSS mit 10 von 10 bewertete CVE-2026-83548 für sich alleine bereits ein erhebliches Bedrohungspotenzial für Betreiber mitbringt, ist auch eine Kombination mit der zweiten Sicherheitslücke - CVE-2026-83549 (7.8) - denkbar.
Der Hersteller berichtet von beobachteten Angriffen. IT-Sicherheitsverantwortliche sollten daher schnellstmöglich handeln: https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/2026-288433-1032.pdf
⚠️Alerte CERT-FR⚠️
Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.
Tiens, encore du #SonicWall SMA1000 ...
Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.
La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.
Sont concernés les SMA1000 6210, 7210 et 8200v.
Pas de workaround : hotfix à appliquer au plus vite. ☹️
Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.
À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.
Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃
Advisory 🩹
👇
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
Warning about two #vulnerabilities (CVE-2026-83548, CVE-2026-83549) in the #SMA1000 series from #SonicWall. These are already being exploited in attacks, so apply the patches.
📰 SonicWall Warns of Two Actively Exploited Zero-Days in SMA1000
🚨 BREAKING: SonicWall warns of two actively exploited zero-days (CVE-2026-83548, CVE-2026-83549) in SMA 1000 appliances. Attackers chain the flaws for unauthenticated RCE. Patches are available and must be applied immediately. #ZeroDay #SonicWall #C...
Bluesky
Overview
Description
Statistics
- 5 Posts
- 1 Interaction
Fediverse
Angreifer nutzen aktiv eine kritische SQL-Injection-Schwachstelle (CVE-2026-9586) in der VoIP-Plattform Sangoma Switchvox aus. Die Lücke ermöglicht unauthentifizierten Akteuren die Remotecodeausführung sowie das Einrichten von Reverse Shells auf den Zielsystemen. Verantwortliche Administratoren müssen umgehend die bereitgestellten Sicherheitsupdates einspielen, um Kompromittierungen zu verhindern.
Bluesky
Overview
Description
Statistics
- 10 Posts
- 10 Interactions
Fediverse
SonicWall weist aktuell auf 2 Schwachstellen in seiner SMA1000-Serie hin.
Während die nach CVSS mit 10 von 10 bewertete CVE-2026-83548 für sich alleine bereits ein erhebliches Bedrohungspotenzial für Betreiber mitbringt, ist auch eine Kombination mit der zweiten Sicherheitslücke - CVE-2026-83549 (7.8) - denkbar.
Der Hersteller berichtet von beobachteten Angriffen. IT-Sicherheitsverantwortliche sollten daher schnellstmöglich handeln: https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/2026-288433-1032.pdf
⚠️Alerte CERT-FR⚠️
Les vulnérabilités CVE-2026-83548 et CVE-2026-83549 affectent les SMA 1000 et permettent une SSRF ainsi que l'exécution de code arbitraire à distance.
Elles sont activement exploitées.
Tiens, encore du #SonicWall SMA1000 ...
Deux nouvelles vulnérabilités 0-day, CVE-2026-83548 (CVSS 10) et CVE-2026-83549, activement exploitées.
La première permet une SSRF sans authentification, la seconde une injection de commandes/RCE. Les deux peuvent être chaînées pour arriver à une RCE sans authentification sur l'appliance.
Sont concernés les SMA1000 6210, 7210 et 8200v.
Pas de workaround : hotfix à appliquer au plus vite. ☹️
Et SonicWall dans la doc dédiée ne s’arrête pas au patch : recherche d’IoC recommandée et, si compromission détectée, re-image/redeploy de l’appliance + reset des mots de passe admin/utilisateurs et des tokens TOTP.
À noter : les SSL-VPN des firewalls SonicWall et la gamme SMA100 ne sont pas concernés.
Bref, si vous avez du SMA1000 exposé, ça mérite clairement un petit détour dans l’inventaire ce matin. 🙃
Advisory 🩹
👇
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
Warning about two #vulnerabilities (CVE-2026-83548, CVE-2026-83549) in the #SMA1000 series from #SonicWall. These are already being exploited in attacks, so apply the patches.
📰 SonicWall Warns of Two Actively Exploited Zero-Days in SMA1000
🚨 BREAKING: SonicWall warns of two actively exploited zero-days (CVE-2026-83548, CVE-2026-83549) in SMA 1000 appliances. Attackers chain the flaws for unauthenticated RCE. Patches are available and must be applied immediately. #ZeroDay #SonicWall #C...
Bluesky
Overview
- servmask
- All-in-One WP Migration and Backup
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
#WordPress Plugin All-in-One WP Migration and Backup mit #Sicherheitslücke CVE-2026-19949
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
- fast-uri
- fast-uri
Description
Statistics
- 3 Posts
Fediverse
🚨 High-severity security fix in fast-uri (4.1.4, 3.1.7, 2.4.6) just released!
Patches CVE-2026-84292: fast-uri vulnerable to authority injection via an unvalidated port in serialize
https://github.com/fastify/fast-uri/security/advisories/GHSA-qw65-cvwx-89v3
Overview
- Langflow
- Langflow
Description
Statistics
- 3 Posts
Fediverse
Langflow RCE now under active exploitation
Attackers are actively exploiting CVE-2026-0768, a critical unauthenticated RCE flaw in Langflow's code validator, running credential-harvesting operations that pull OpenAI API keys and AWS access straight out of compromised agentic AI infrastructure, with exploitation clocked within roughly 20 hours of disclosure....
https://itnerd.blog/2026/09/02/langflow-rce-now-under-active-exploitation/
Overview
- F5
- NGINX JavaScript
Description
Statistics
- 1 Post
- 7 Interactions
Fediverse
I am fortunate enough to not know anything about NGINX JavaScript ( hashtag blessed ) but if you do, this might be of interest.
https://nvd.nist.gov/vuln/detail/cve-2026-78689
Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list causes an out-of-bounds write past the end of a heap allocation. With the njs engine, which is the engine used when the js_engine directive is absent, this corrupts adjacent objects and crashes the NGINX worker. With the QuickJS engine, the same call additionally leaks the prefix list on every invocation, causing worker memory to grow across requests. The official nginxinc/nginx-saml reference implementation is affected during SAML signature verification. It reads InclusiveNamespaces/@PrefixList from an untrusted SAML message and passes it to xml.exclusiveC14n() before the signature has been verified, so a valid SAML signature is not required. A crafted SAML Response, Assertion, LogoutRequest, or LogoutResponse is sufficient. Code execution has not been demonstrated and cannot be ruled out for all platforms, as the effect of the out-of-bounds write depends on conditions beyond the attacker's control. Impact This vulnerability allows remote attackers to cause a denial of service on the NGINX system, either through repeatable worker restarts or through worker memory growth or possibly trigger code execution. There is no control plane exposure; this is a data plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.