Overview
Description
Statistics
- 6 Posts
- 1 Interaction
Fediverse
Akute Sicherheitslücke im JCE-Editor!
Mit einem Volltreffer auf der CVE-Skala (10/10) ist ein Update des JCE-Editor im Joomla kein Task für morgen, sondern für "nach meinem Wissen jetzt ... sofort".
Weitere Infos:
🚨 New critical improper access control vulnerability tagged CVE-2026-48907, affecting Widget Factory Joomla Content Editor is seeing active exploitation in the wild as reported by CISA.
Vulnerability detection script available below:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-48907.yaml
Patches and mitigations are available:
https://www.sentinelone.com/vulnerability-database/cve-2026-48907/
⚠️ Vous administrez un site Joomla ?
Petit point sécurité : la faille CVE-2026-48907 touche l’extension **JCE / Joomla Content Editor **et elle est déjà exploitée automatiquement sur Internet.
👇 🩹
https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites
En clair : un site vulnérable peut être compromis même sans compte public ni inscription ouverte.
À faire dès que possible:
• mettre JCE à jour en 2.9.99.6 ou plus récent
• vérifier les profils/comptes suspects
• changer les mots de passe admin, base de données et hébergement
• lancer un scan serveur
(La mise à jour ferme la porte, mais ne nettoie pas forcément ce qui aurait déjà été déposé.)
URGENT: CVE-2026-48907 is seeing active exploitation in Joomla! JCE extensions. This critical RCE flaw allows unauthenticated attackers to take full control. Read our executive remediation brief to harden your environment now.
https://thecybermind.co/ic6z
#CyberSecurity #Joomla #Infosec #KEV
Bluesky
Overview
- Microsoft
- Microsoft Malware Protection Engine
Description
Statistics
- 3 Posts
- 5 Interactions
Fediverse
Nightmare Eclipses RoguePlanet now has a CVE 🎉: https://nvd.nist.gov/vuln/detail/cve-2026-50656
Not any new detail in there & no fix yet (has only been a week, give them some time...).
Much less relevant but annoying me personally: It taking them a week to ... sorry, shit this out. Broken description in the CVE form & even in the MSRC page it's pretty obvious no one even proofread the non-description. Also empty Acknoledgement section despite link to the Github (not the first time btw)... at least they didn't have it taken down this time? 🙃
Bluesky
Overview
- RocketGenius
- Gravity SMTP
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
Solid breakdown by @honeylabs of the opportunistic activity against CVE-2026-4020
~560 IPs rotating through ~3,300 UAs
Rly important to heed the info further down in the article re: "attacking the CVE" vs "added yet-another-cred path to existing scans".
https://honeylabs.net/blog/the-cloud-fleet-behind-cve-2026-4020
Overview
Description
Statistics
- 4 Posts
Fediverse
📰 Actively Exploited Cisco SD-WAN Flaw Added to CISA KEV Catalog
⚠️ Cisco Catalyst SD-WAN Manager flaw CVE-2026-20262 is actively exploited! The bug allows root privilege escalation. CISA has added it to the KEV catalog, mandating a patch by June 29. Update now! #Cisco #CVE #CyberSecurity #KEV
🌐 cyber[.]netsecops[.]io
🚨 CVE-2026-20262: Cisco SD-WAN Manager flaw allows web shell uploads, leading to orchestrator RCE and complete network fabric compromise.
https://denizhalil.com/2026/06/17/cve-2026-20262-cisco-sd-wan-manager-vulnerability/
Overview
Description
Statistics
- 2 Posts
- 14 Interactions
Fediverse
Europarat gehackt – dank Oracle.
Die Besetzungsliste: ShinyHunters, Oracle, der Europarat. Die Handlung: Vor mehr als zwanzig Jahren hat Oracle* nach einer wahren Übernahmeschlacht die Firma PeopleSoft geschluckt. Deren Software wird vor allem in den USA eingesetzt, aber eben auch im Europarat. Die Software enthielt eine Zero-Day Sicherheitslücke CVE-2026-35273, die von ShinyHunters ausgenutzt wurde. Die Hackergruppe will darüber mehr als 100 Institutionen gehackt haben, darunter den Europarat. Dabei seien fast 300 GByte an Daten in die Hände der Erpresser gefallen, darunter Personalakten, Gehaltsabrechnungen, Einkäufe; Lebensläufe, Gehälter,
https://www.pc-fluesterer.info/wordpress/2026/06/16/europarat-gehackt-dank-oracle/
#0day #closedsource #cybercrime #datenleck #datenschutz #exploits #sicherheit #UnplugOracle #UnplugTrump #zeroday
Overview
Description
Statistics
- 3 Posts
Fediverse
📰 CISA KEV Catalog Adds Exploited LiteSpeed cPanel Plugin Flaw
📢 CISA KEV ALERT: A LiteSpeed cPanel plugin flaw, CVE-2026-54420, is being actively exploited for root privilege escalation on shared servers. Federal agencies must patch by June 18. Hosting providers, check your systems! #CVE #KEV #CISA #CyberSecurity
🌐 cyber[.]netsecops[.]io
Bluesky
Overview
- Microsoft
- Microsoft 365 Copilot
Description
Statistics
- 2 Posts
- 9 Interactions
Fediverse
https://winbuzzer.com/2026/06/16/microsoft-patches-copilot-searchleak-data-theft-flaw-xcxwbn/
Microsoft has patched a Copilot flaw after researchers showed a one-click chain that could expose two-factor codes and enterprise data via search.
#AI #SearchLeak #Microsoft365Copilot #Microsoft #Microsoft365 #MicrosoftCopilot #Varonis #CVE202642824 #Cybersecurity
Overview
- Fortinet
- FortiSandbox
Description
Statistics
- 3 Posts
Fediverse
⚠️ CRITICAL: Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
Fortinet FortiSandbox is under active exploitation for three critical unauthenticated RCE vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089). All three bypass authentication and allow arbitrary command execution via HTTP requests. Organizations running FortiSandbox are at immediate ri…
Bluesky
Overview
- Splunk
- Splunk Enterprise
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
🔒 CRITICAL: CVE-2026-12441 in Chrome <149.0.7827.155 on Linux — use-after-free in File Input. Remote attacker can trigger heap corruption via crafted HTML. Update Chrome ASAP! https://radar.offseq.com/threat/cve-2026-12441-use-after-free-in-google-chrome-643def61 #OffSeq #Chrome #Linux #Vuln