Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
Noch ein Cisco Zero-Day (perfekte 10) unter Angriff
Ja, Cisco-Evangelisten müssen dieser Tage ganz stark sein. Kurz nach dem Desaster mit dem "sicheren" E-Mail-Gateway ist die nächste "Sicherheitslücke" aufgefallen, weil sie bereits angegriffen wird. CVE-2026-76460 hat eine perfekte 10 (von 10) als Risiko-Einstufung erhalten. Die "Sicherheitslücke" steckt in der Cisco Identity Services Engine (ISE). Wie der Name nahelegt, ist die Aufgabe dieser Funktion, Benutzer/innen zu identifizieren und dann für bestimmte Tätigkeiten zu autorisieren. Die Schwachstelle entsteht durch, ich zitiere: "... insufficient authentication control ... Weiterlesen:
#0day #backdoor #closedsource #exploits #hersteller #identität #sicherheit #UnplugTrump #zeroday #cisco
Cisco ISE zero-day CVE-2026-76460 is being actively exploited.
The CVSS 10.0 flaw allows remote, unauthenticated attackers to bypass authentication and potentially execute commands with root privileges.
Cisco says there is no complete workaround and recommends upgrading immediately.
Read more here:
https://forum.hashpwn.net/post/16740
📰 Cisco ISE Zero-Day (CVSS 10.0) Under Active Attack, Bypasses Auth
Cisco warns of a critical (CVSS 10.0) zero-day in Identity Services Engine (ISE) actively exploited in the wild. The flaw, CVE-2026-76460, allows full authentication bypass. CISA added to KEV catalog. Patch immediately! #Cisco #ZeroDay #CyberSecurity
Overview
- checkpoint
- Quantum Security Management
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
Check Point Security Mgmt & Log Server face CRITICAL stack buffer overflow (CVE-2026-91843). Remote, unauthenticated RCE as root possible. Patch now or restrict access, monitor for 'Username too long' login failures. https://radar.offseq.com/threat/new-check-point-flaw-lets-hackers-execute-code-with-root-privileges-00056aa571ef0004 #OffSeq #CheckPoint #Vuln #RCE
📰 Check Point Patches Critical RCE Flaw in Management Servers
Check Point patches critical RCE flaw (CVE-2026-91843, CVSS 9.8) in Security Management Servers. Unauthenticated attackers can gain root access via a long username. LivePatch is available. Restrict trusted client access now! #CyberSecurity #CheckPoin...
Bluesky
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
- HCL Software
- HCL BigFix Service Management
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-67100: HCL BigFix Service Management v23 faces CRITICAL SQL injection & cross-tenant data exposure (CVSS 9.8). Authenticated attackers can access PII across orgs. No patch yet — restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-67100-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-dc5bf090924b31aa #OffSeq #Vuln #SQLi #Infosec
HCL Software patched critical HCL BigFix vulnerabilities, including CVE-2026-67100 and CVE-2026-18963. Patch now to prevent total account takeovers.
#HCLBigFix #Cybersecurity #CVE202667100 #Vulnerability #InfoSec
Overview
- GNU
- inetutils
Description
Statistics
- 1 Post
- 7 Interactions
Overview
- conductor-oss
- conductor
Description
Statistics
- 1 Post
- 1 Interaction
Overview
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
CISA warned of exploited Linux kernel vulnerabilities in the KEV catalog. Patch these Linux kernel vulnerabilities to block privilege escalation.
#LinuxKernel #CISA #CVE202539964 #CVE202653266 #Cybersecurity
Overview
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
CISA warned of exploited Linux kernel vulnerabilities in the KEV catalog. Patch these Linux kernel vulnerabilities to block privilege escalation.
#LinuxKernel #CISA #CVE202539964 #CVE202653266 #Cybersecurity
Overview
- ModelTC
- LightLLM
- LightLLM
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
Go hack more LLM shit.
https://nvd.nist.gov/vuln/detail/cve-2026-93839
sev:CRIT 9.3 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. Attackers can disclose full user prompts routed to their socket, trigger denial of service by replacing legitimate nodes, or make the PD Master issue requests to internal network addresses.