Overview
Description
Statistics
- 11 Posts
- 14 Interactions
Fediverse
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/
Cisco Talos warns of Cisco FMC vulnerabilities actively exploited in the wild. Attackers chain CVE-2026-20079 and CVE-2026-20316 to deploy ransomware.
Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by threat actors deploying malware, web shells, and ransomware. Customers are strongly urged to apply security patches immediately to prevent unauthorized access and potential compromise.
https://blog.talosintelligence.com/fmc-ongoing-exploitation/
Bluesky
Description
Statistics
- 12 Posts
- 9 Interactions
Fediverse
Google Chrome #zeroday
Google is aware that an exploit for CVE-2026-87491 exists in the wild.
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
Google Chrome 153 (153.0.8010.36/.37) korrigiert 230 Sicherheitslücken – CVE-2026-87491 in der freien Wildbahn
The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html
⚠️ CRITICAL: Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google patched CVE-2026-87491, a zero-day out-of-bounds write in Chrome's V8 engine actively exploited in the wild. Attackers can execute arbitrary code within the browser sandbox via crafted HTML, potentially compromising any user visiting a malicious page. This is the seventh exploited Chrome zer…
🤖 AI generated summary
Earlier this month, @volexity detected multiple Chinese threat actors launching attacks against its customers using chained 0-day exploits in Google Chrome (CVE-2026-85046 & CVE-2026-87491) and Microsoft Windows (CVE-2026-85880). Volexity observed threat actors it tracks as UTA0560 and JungleBamboo using variations of the same exploits to deliver different malware implants. These implants ranged from a JScript backdoor (GRIMWEDGE) to a fake Google Gemini Chrome extension (LONGTALE).
Read the full analysis of the exploit chain and post-exploitation tradecraft here: https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/
#DFIR #threatintel
Bluesky
Overview
- WebPros
- cPanel
Description
Statistics
- 6 Posts
- 4 Interactions
Fediverse
I can't imagine trying to manage cPanel on the public Internet in 2026, especially on shared systems.
https://nvd.nist.gov/vuln/detail/cve-2026-67401
sev:CRIT 9.9 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
Critical cPanel Vulnerability (CVE-2026-67401): How an EmailTrack SQL Injection Grants Root Access
A critical cPanel EmailTrack SQL injection vulnerability, CVE-2026-67401, can allow authenticated attackers to escalate to root and take over an entire hosting serverhttps://thecybersecguru.com/news/cve-2026-67401-cpanel-emailtrack/
Bluesky
Overview
- Microsoft
- Microsoft Malware Protection Engine
Description
Statistics
- 4 Posts
- 3 Interactions
Fediverse
CRITICAL: ShieldCrash zero-day (CVE-2026-69414) exploits Microsoft Defender on patched Windows (Sept 2026), enabling privilege escalation to System and SAM dumping. No patch yet. Monitor for Defender anomalies. https://radar.offseq.com/threat/new-shieldcrash-zero-day-exploit-targets-microsoft-defender-c4e918e12bdbcf86 #OffSeq #ZeroDay #MicrosoftDefender #Infosec
Bluesky
Overview
Description
Statistics
- 4 Posts
- 2 Interactions
Fediverse
Magento : la faille zero-day StyleSmuggler est corrigée, mais des boutiques sont déjà piratées https://www.it-connect.fr/magento-adobe-commerce-faille-zero-day-stylesmuggler-cve-2026-75650/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Adobe
CVE-2026-75650 Adobe Commerce Zero-Day: Patch Isn’t Enough https://www.esecurityplanet.com/threats/news-adobe-commerce-cve-2026-75650-stylesmuggler/
Overview
- checkpoint
- Quantum Security Gateway
Description
Statistics
- 4 Posts
- 18 Interactions
Fediverse
It has been :zero_percent: days since an ASN.1 decoding vuln.
It has been :zero_percent: days since an overflow vuln in a corp VPN.
It has been :zero_percent: days since a vuln with "Quantum" in the system name.
They are all the same vuln.
https://nvd.nist.gov/vuln/detail/cve-2026-85103
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
CRITICAL CVE-2026-85103 in Check Point Quantum Security Gateway: Heap-based buffer overflow in VPN certificate ASN.1 decoding allows unauthenticated RCE. Patch pending — monitor vendor. https://radar.offseq.com/threat/cve-2026-85103-cwe-122-heap-based-buffer-overflow-in-checkpoint-quantum-security-gateway-769c0bcac8d0fa47 #OffSeq #CheckPoint #infosec #Vuln
Check Point fixed critical Check Point VPN vulnerabilities. Update gateways to prevent remote code execution under CVE-2026-85102 and CVE-2026-85103.
[Action Required] - Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510
Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation.
#CheckPoint #CheckPointSoftwareTechnologies #VPN #vulnerability
Overview
- SAP_SE
- SAP Extended Passport (EPP) Processing
Description
Statistics
- 5 Posts
- 1 Interaction
Fediverse
The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP security company Onapsis, it has been codenamed OVERPASS. https://thehackernews.com/2026/09/sap-patches-cvss-100-kernel-flaw.html
SAP OVERPASS CVE-2026-44756: CVSS 10.0 Kernel RCE Explained
SAP OVERPASS CVE-2026-44756 is a CVSS 10.0 kernel flaw enabling unauthenticated RCE. Learn the attack path, S4GET risks and patching stepshttps://thecybersecguru.com/news/sap-overpass-cve-2026-44756/
Bluesky
Overview
- Palo Alto Networks
- Cloud NGFW
Description
Statistics
- 4 Posts
- 25 Interactions
Fediverse
RE: https://infosec.exchange/@cR0w/117241961119105876
Seriously, maybe take a good look at CVE-2026-0310.
CVSS-BT: 7.2 / **CVSS-B: 9.2** (CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:U/AU:N/R:U/V:D/RE:M/U:Red)
A new PAN-OS buffer overflow flaw, tracked as CVE-2026-0310, exposes firewalls to remote code execution. Patch your network devices immediately.
#PANOS #BufferOverflow #CVE20260310 #Cybersecurity #PaloAltoNetworks
Overview
Description
Statistics
- 4 Posts
- 1 Interaction
Bluesky
Overview
Description
Statistics
- 3 Posts