Overview
Description
Statistics
- 10 Posts
- 2 Interactions
Fediverse
🚨 Kritischer Security Alert (CVSS 10.0)
CISA warnt vor Angriffen auf Oracle HTTP Server & WebLogic Proxy Plug-in (CVE-2026-21962).
Risiko: Path Traversal & Remote Code Execution ohne Authentifizierung (Vollständige Übernahme).
Status: Exploits/PoC öffentlich auf GitHub.
⚡Updates aus dem Oracle Critical Patch Update (Januar!!!) umgehend einspielen!
#ITSecurity #CyberSecurity #Oracle #WebLogic #CISA #SysAdmin #PatchManagement
https://www.heise.de/news/Attacken-auf-Oracle-Weblogic-und-HTTP-Server-beobachtet-11424527.html
Geopolitical tensions escalate as the US launches "Operation Economic Outcast" against Iran, imposing new sanctions amidst Strait of Hormuz disputes (Aug 25). Canada is set to announce retaliatory tariffs against the US (Aug 25). The UK and Ukraine formalized an AI defense partnership (Aug 24).
In technology, Nvidia's AI chips remain a focal point, with Taiwan indicting nine individuals for illegal AI server exports to China (Aug 24). Hybrid bonding is advancing as a foundational technology for enhanced semiconductor performance (Aug 25).
Cybersecurity: CISA issued a warning regarding the active exploitation of an Oracle WebLogic vulnerability (CVE-2026-21962), urging immediate patching (Aug 25). ReliaQuest also confirmed an employee fell victim to a social engineering attack (Aug 25).
🚨 Critical Threat Intel: CVE-2026-21962 impacts Oracle HTTP Server & Weblogic Proxy Plug-in via access control bypass. Review exploitation patterns, web access detection queries, and active endpoint hardening actions.
https://thecybermind.co/jily
Bluesky
Overview
Description
Statistics
- 4 Posts
- 1 Interaction
Fediverse
Here's a concise overview of recent geopolitical, technology, and cybersecurity developments:
Geopolitical: The US has declared an "economic D-Day" against Iran, which is now threatening Strait of Hormuz disruption. China completed its largest South China Sea naval base at Antelope Reef.
Cybersecurity: Norway's public services were hit by a major DDoS attack on August 25. Iran-linked cyberattacks are increasingly targeting critical infrastructure in the UK and US. Over 270 Zimbra servers have been compromised via a high-severity RCE flaw (CVE-2026-73570).
Technology: Apple unveiled its M6 and M5 Ultra chips on August 25, significantly boosting AI performance in new Macs.
Bluesky
Overview
- Microsoft
- Microsoft SharePoint Enterprise Server 2016
Description
Statistics
- 5 Posts
- 10 Interactions
Fediverse
If you've missed any super dope research from @lobsterjerusalem recently, pleez don't miss it anymore:
Oh no the internet is awash with AI slop PoCs, send poor Jonathan tiny cupcakes and quick: https://www.vulncheck.com/blog/death-by-20k-pocs
SharePoint RCE:
https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce
En las últimas 24 horas, una masiva filtración expone datos de 70,000 agentes marroquíes, mientras una vulnerabilidad crítica en Microsoft SharePoint pone en riesgo sistemas corporativos; simultáneamente, el botnet Kimwolf v7 avanza en ataques a dispositivos IoT y la emblemática lista Bugtraq reanuda actividades para fortalecer la defensa cibernética. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:
🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 25/08/26 📆 |====
🔓 JABAROOT ELEVÁ LA GUERRA DE LOS ESPÍAS: FILTRA DATOS DE 70,000 AGENTES MARROQUÍES
El grupo de hackers Jabaroot ha expuesto una base de datos que contiene las identidades de más de 70,000 miembros de los servicios de inteligencia y seguridad de Marruecos. Esta filtración representa un serio riesgo para la seguridad nacional y coloca en alerta a organismos de todo el mundo, dada la sensibilidad de la información comprometida. La publicación de los archivos continuará en las próximas horas, lo que podría ampliar aún más el impacto de esta brecha. Mantente informado sobre esta amenaza creciente. Descubre todos los detalles y el análisis de esta filtración aquí 👉 https://djar.co/ozZgH
🛡️ ANÁLISIS TÉCNICO DE LA VULNERABILIDAD REMOTA CVE-2026-63520 EN MICROSOFT SHAREPOINT
Se ha identificado una vulnerabilidad crítica de ejecución remota de código en Microsoft SharePoint, catalogada como CVE-2026-63520. Esta falla se debe a una instanciación no restringida de tipos .NET, lo que permite a atacantes ejecutar código malicioso a distancia si no se aplica un parche oportuno. Esta vulnerabilidad puede comprometer la integridad de sistemas corporativos y exponer datos sensibles. Se recomienda a los administradores revisar el análisis técnico y aplicar las actualizaciones de seguridad cuanto antes. Consulta el informe completo con recomendaciones de mitigación aquí 👉 https://djar.co/SzG0s
🤖 KIMWOLF V7: EVOLUCIÓN DEL BOTNET ORIENTADO A DISPOSITIVOS ANDROID IOT
La nueva versión del botnet Kimwolf, etiquetada como v7, ha mejorado sus capacidades para atacar dispositivos Android IoT mediante técnicas avanzadas de fingerprinting DDoS utilizando el protocolo HTTP/2. Además, incorpora resolución C2 con Ethereum ENS y enrutamiento de respaldo a través de la red Tor para aumentar su resiliencia. Esta evolución representa una amenaza mayor para la infraestructura IoT y los usuarios, evidenciando la creciente sofisticación de las ciberamenazas. Entiende cómo funciona y cómo proteger tus dispositivos. Profundiza en su análisis técnico aquí 👉 https://djar.co/dXQj4
📢 LA LISTA DE DIFUSIÓN ORIGINAL DE BUGTRAQ VUELVE A ESTAR ACTIVA
Bugtraq, la lista de difusión más emblemática para la divulgación responsable y discusión sobre vulnerabilidades y exploits, ha reactivado su servicio tras un tiempo de inactividad. Esta plataforma sigue siendo un recurso fundamental para profesionales de la seguridad informática, ofreciendo información detallada y análisis actualizados que permiten anticiparse a amenazas emergentes. Si buscas estar a la vanguardia en seguridad cibernética, no puedes perderte esta herramienta clave en el sector. Accede a la lista y su comunidad aquí 👉 https://djar.co/hS0rf
🤖 ¿EXISTE UN MEJOR MODELO DE IA PARA HACKING? | XBOW
Con la rápida evolución de los modelos de inteligencia artificial, el debate sobre cuál es el "mejor" para hacking se intensifica. Sin embargo, expertos señalan que más importante que elegir un modelo único es enfocarse en la orquestación y la integración con sistemas de seguridad robustos que amplifiquen su eficiencia. Este enfoque integral permite una defensa más adaptativa y precisa frente a las ciberamenazas dinámicas de hoy. Explora esta perspectiva innovadora para transformar tu estrategia de ciberseguridad. Lee el análisis completo aquí 👉 https://djar.co/VuoH
🎙️ ENTREVISTA EXCLUSIVA CON MARIANO M DEL RÍO, FUNDADOR DE SECURETECH
En esta entrevista, Mariano M del Río comparte su visión sobre las tendencias actuales en seguridad informática, los desafíos que enfrentan las organizaciones y cómo la innovación tecnológica está redefiniendo la protección digital. Su experiencia y liderazgo en SECURETECH aportan insights valiosos para profesionales que buscan fortalecer sus defensas y anticipar amenazas. No te pierdas esta conversación llena de estrategias y consejos prácticos para mantenerse seguro en el entorno digital actual. Accede a la entrevista completa aquí 👉 https://djar.co/iBym
A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.
#SharePoint #CVE202663520 #CVE202655040 #CyberSecurity #Exploit
Bluesky
Overview
- Red Hat
- Red Hat build of Keycloak 26.4
- rhbk/keycloak-operator-bundle
Description
Statistics
- 2 Posts
- 14 Interactions
Fediverse
CVE-2026-18963: #Keycloak arbitrary account takeover via session confusion using simple HTTP requests. 😱
Nice find and (allegedly) not even AI-powered at its core.
A working exploit is publicly available. Given Keycloak's widespread use in critical auth systems, this appears to be flying a bit under the radar so far.
If you run Keycloak, it needs your attention *now*.
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
https://thehackernews.com/2026/08/critical-keycloak-password-reset-flaw.html
> Keycloak CVE-2026-18963 could let unauthenticated attackers skip the emailed action token and reset any user's password.
Overview
- WatchGuard
- WatchGuard Agent
Description
Statistics
- 2 Posts
- 12 Interactions
Fediverse
sev:CRIT ../ in WatchGuard Agent. Once again, INFOSEC increasing that attack surface instead of decreasing it.
Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.
Overview
- WatchGuard
- WatchGuard Agent
Description
Statistics
- 2 Posts
- 4 Interactions
Fediverse
Two critical WatchGuard Agent flaws (CVE-2026-57909, CVE-2026-57910) allow unauthenticated remote code execution. Update to 1.25.13.0000 now.
Overview
Description
Statistics
- 3 Posts
- 3 Interactions
Fediverse
A public SharePoint RCE vulnerability PoC is actively probed in the wild. Patch CVE-2026-63520 and CVE-2026-55040 now to protect your servers.
#SharePoint #CVE202663520 #CVE202655040 #CyberSecurity #Exploit
Bluesky
Overview
- Weidmueller Interface
- IE-SR-2TX-WL
Description
Statistics
- 2 Posts
Fediverse
A critical Weidmueller router flaw, CVE-2026-63586 (CVSS 9.8), lets attackers execute arbitrary commands with root privileges. Patch devices immediately.
🔒 New CSAF advisory published
VDE-2026-083
Weidmueller: Security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by multiple vulnerabilities
CVE-2026-63586, CVE-2026-63587
Weidmueller security routers IE-SR-2TX-WL and IE-SR-2TX-WL-4G are affected by an unauthenticated remote code execu…
HTML: https://certvde.com/en/advisories/VDE-2026-083/
CSAF JSON: https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-083.json
Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
The August 2026 OpenSSL security update fixes 9 flaws, including a QUIC double free (CVE-2026-18798) and a CMS heap overflow. Patch now.
Bluesky
Overview
Description
Statistics
- 1 Post
- 6 Interactions