Overview
- N-able
- N-central
Description
Statistics
- 5 Posts
- 17 Interactions
Fediverse
Some time ago I discovered a meddler in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse:
https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7.
#Nable #Ncentral #CVE202618577 #AccountTakeover #RMM #CyberSecurity
Bluesky
Overview
Description
Statistics
- 4 Posts
Fediverse
📰 Ruby on Rails Patches Critical RCE Flaw (CVE-2026-66066)
Ruby on Rails patches critical RCE vulnerability CVE-2026-66066 (CVSS 9.5). The flaw in Active Storage allows arbitrary file read via crafted image uploads, leading to potential RCE. Update immediately. #RubyOnRails #CVE #CyberSecurity
Bluesky
Overview
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati
@informatica
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per installare OWAReaper, una backdoor che sopravvive a reset password e reimaging. Colpiti enti
📰 Russian Group Midnight Blizzard Exploits Outlook XSS Flaw (CVE-2026-42897)
Russian actor Midnight Blizzard (Storm-2945) exploits Outlook XSS flaw CVE-2026-42897 to access mailboxes. Also hijacks hotel Wi-Fi in 'CaptiveCrunch' campaign to steal M365 tokens with CornFlake & ChocoShell malware. #ThreatIntel #APT
Overview
- TP-Link Systems Inc.
- TL-WR940N v6
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
A TP-Link TL-WR940N flaw, CVE-2026-12935, allows unauthenticated remote code execution via an RTSP stack buffer overflow. Update the router firmware now.
#TPLink #TLWR940N #CVE202612935 #RCE #RouterSecurity #InfoSec
Overview
- checkpoint
- Security Management Server
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
CRITICAL auth bypass (CVE-2026-18574, CVSS 9.3) affects Check Point Security Management Server & MDS. Remote attackers can execute commands w/o auth. No patch yet — restrict management access. https://radar.offseq.com/threat/cve-2026-18574-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-checkpoint-security-b30ba167a9a0b365 #OffSeq #CVE202618574 #CheckPoint #Infosec 🔒
CVE-2026-18574 is a Check Point authentication bypass rated CVSS 9.3, letting attackers run commands as admin. Patch via the latest Jumbo Hotfix.
#CheckPoint #CVE202618574 #AuthenticationBypass #SecurityManagement #CyberSecurity #Firewall
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 2 Posts
Fediverse
Certighost: cuando un usuario de dominio puede acabar obteniendo un certificado de un Domain Controller (CVE-2026-54121)
Si durante los últimos años ha habido una tecnología de Active Directory que ha pasado de ser la gran olvidada a convertirse en uno de los objetivos favoritos de Red Teams y atacantes reales, esa es Active Directory Certificate Services (AD CS). Desde la publicación de Certified Pre-Owned...
https://www.hackplayers.com/2026/07/certighost-cuando-un-usuario-de-dominio.html
Bluesky
Overview
- Adobe
- Adobe Campaign Classic
Description
Statistics
- 2 Posts
Fediverse
Nutzt wer Adobe Campaign Classic (ACC) und hat noch nicht gepatcht? Zwei fette Sicherheitslücken (CVSS 3.x von 10.0 bei einer).
Adobe fixes a CVSS 10 RCE in Campaign Classic (CVE-2026-48449) and eight critical flaws in Bridge. Update to build 9398 and Bridge 15.1.7 or 16.0.6 now.
#AdobeCampaign #CVE202648449 #AdobeBridge #CriticalPatch #RCE
Overview
Description
Statistics
- 2 Posts
Fediverse
📰 CISA Warns of Actively Exploited Cisco Firewall Management Flaw
📢 CISA WARNING: A static credential flaw in Cisco Secure Firewall Management Center (CVE-2026-20316) is actively exploited. The flaw allows unauthorized access. CISA adds it to KEV catalog, mandating federal action. #CVE202620316 #Cisco #KEV
Overview
- ArcadeData
- arcadedb
Description
Statistics
- 1 Post
- 3 Interactions
Overview
- Ubiquiti Inc
- UniFi Protect Floodlight
Description
Statistics
- 1 Post
- 2 Interactions