Overview
- Microsoft
- Microsoft Entra
Description
Statistics
- 3 Posts
Fediverse
「マイクロソフトが警鐘を鳴らす、Entra IDの完全な欠陥が攻撃を受けている
/マイクロソフトはクラウドIDのバグは既に修正済みだと述べているが、誰がどの程度悪用したのかは明らかにしていない。 」: #TheRegister
「マイクロソフトは、攻撃者が既に悪用していたEntra IDの深刻度が最大レベルの脆弱性を修正した。
CVE-2026-69836として追跡されているこの脆弱性は、CVSSスコアが最高値の10.0であり、認証されていない攻撃者がMicrosoftのクラウドIDサービス上でリモートからコードを実行できる可能性がある。Microsoft は木曜日にこの脆弱性を公表し 、既に悪用が確認されているという残念なニュースも同時に発表した。
Entra ID(旧称Azure Active Directory)は、マイクロソフトのお客様向けIDおよびアクセス管理の中核を担い、クラウドアプリケーションやその他の企業リソースへの認証とアクセスを管理します。」
Bluesky
Overview
Description
Statistics
- 2 Posts
- 4 Interactions
Fediverse
Attackers are exploiting a critical MLflow bug to reach internal systems and cloud metadata, putting cloud secrets at risk. CISA has added CVE-2026-64849 to its KEV catalog.
Listen/Read: https://hackread.com/attackers-exploit-critical-mlflow-ai-platform-flaw/
Overview
- Grafana
- Grafana OSS
Description
Statistics
- 3 Posts
Bluesky
Overview
- NetScaler
- ADC
Description
Statistics
- 2 Posts
Fediverse
Citrix NetScaler (CVE-2026-19490) : cette faille critique permet de contourner l’authentification https://www.it-connect.fr/citrix-netscaler-cve-2026-19490-contournement-authentification/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
Overview
- TRENDnet
- TEW-821DAP
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-77946: Stack-based buffer overflow in TRENDnet TEW-821DAP v2.2.01b05 (CRITICAL, CVSS 10). Remote code execution possible via NTP config. No patch — limit exposure & monitor traffic. https://radar.offseq.com/threat/cve-2026-77946-stack-based-buffer-overflow-in-trendnet-tew-821dap-679ce40e9d7aa62a #OffSeq #CVE202677946 #infosec #vulnerability
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Bluesky
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Geopolitical tensions rise as the US escalates economic pressure on Iran, which labels new sanctions as a "declaration of war". Ukraine faces critical missile shortages amid intensified Russian strikes. In technology, major investments continue in AI infrastructure, with Google backing Marvell's custom AI chips. Cybersecurity sees CISA adding a critical Zimbra vulnerability (CVE-2026-73570) to its KEV catalog and new banking Trojans actively exploited globally.
Overview
- Cisco
- Cisco Secure Workload
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
Fuck it, CVE dumpster diving.
CVE-2026-20231 - this is one of a batch of Cisco CVEs that stood out to me because they have multiple descriptions: One by the CNA, one by an ADP, "CVE" itself. The ADP one is just "please please please dont do this (bundling multiple vulns into a single cve) :neobot_angel_pleading: ". Cisco dont care, they put out 9 of those over the last 7 days.
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🚨🇫🇷 iMapper allegedly breached through critical Metabase vulnerability, account data and database access leaked on a cybercrime forum
⠀
A forum actor claims to have compromised iMapper, a French web-connected 2D laser measurement platform for building professionals, using a vulnerability identified in the listing as CVE-2026-72898 with a claimed CVSS score of 10.0.
⠀
The exposed account dataset reportedly contains 2,463 records and includes:
⠀
• User IDs and usernames
• Password hashes
• Account roles
• Email addresses
• Phone numbers
• Professions
• MFA status and related metadata
• Language preferences
• Stripe customer IDs
• Stripe tax-related identifiers
• Measurement and display configuration fields
⠀
The data is being distributed in XLSX format. The listing also claims the compromised environment contains additional database tables and offers credentials that could provide access to those systems.
⠀
The claims, exploitation method and authenticity, availability and scope of the allegedly exposed data and database access have not been independently verified.
⠀
💥 No delays. No guessing. No redactions. Get the intel threat actors see, the moment they post it. darkwebinformer.com/pricing
Overview
Description
Statistics
- 1 Post
- 1 Interaction