Overview
Description
Statistics
- 11 Posts
- 1 Interaction
Fediverse
Your firewall management plane has a CVSS 10.0 root vulnerability, and the attackers have been inside for six weeks.
Cisco confirmed active exploitation of CVE-2026-20079 in Secure Firewall Management Center this week. Unauthenticated. No credentials. Root on the box. No workaround. The web interface is the entry point. The compromised system is the one that pushes policy to every firewall you own.
Patch Tuesday gave you 974 CVEs this week. CISA just told you which three come first.
The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/
The EU Cyber Resilience Act (CRA) takes effect today, September 11, mandating 24-hour vulnerability reporting from manufacturers of connected hardware and software. Simultaneously, state-backed threat actors are increasingly targeting EU officials via encrypted messaging apps for phishing attacks, and a critical Cisco Secure Firewall Management Center flaw (CVE-2026-20079) requires urgent patching. Geopolitically, tensions escalated in the Strait of Hormuz following Iranian claims of ship attacks after US actions, and conflicts continue in the Middle East. In technology, Google Threat Intelligence reported on an AI system capable of harvesting thousands of credentials autonomously.
Three threat clusters, including state-sponsored actors and Qilin ransomware affiliates, have exploited two critical Cisco FMC vulnerabilities to deploy web shells, Cyclops Blink malware, and steal sensitive credentials. Cisco has confirmed the exploitation of CVE-2026-20079 and CVE-2026-20316 and urges all customers to install the released hotfixes immediately.
https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
Bluesky
Overview
- DeepSeek
- DeepSeek Harness
Description
Statistics
- 3 Posts
- 12 Interactions
Fediverse
CVE-2026-82533: la falla in DeepSeek Harness che lasciava agli agenti AI le chiavi della propria sandbox
#tech
https://spcnet.it/cve-2026-82533-la-falla-in-deepseek-harness-che-lasciava-agli-agenti-ai-le-chiavi-della-propria-sandbox/
@informatica
CVE-2026-82533: la falla in DeepSeek Harness che lasciava agli agenti AI le chiavi della propria sandbox
Un'interfaccia locale priva di autenticazione e vulnerabile a host header spoofing permetteva agli agenti di DeepSeek Harness di disattivare la propria sandbox con un solo comando. Analisi tecnica di CVE-2026-82533 (CVSS 9.4) e consigli pratici per proteggere gli ambienti dove girano coding agent AI.Overview
- SAP_SE
- SAP Extended Passport (EPP) Processing
Description
Statistics
- 3 Posts
Fediverse
The SAP OVERPASS vulnerability (CVE-2026-44756) scores a perfect CVSS 10.0, letting attackers seize SAP servers before login. Patch Note 3747649 now.
#SAP #OVERPASS #CVE202644756 #CyberSecurity #RCE #Onapsis #InfoSec
#SAP toppt mit #Schwachstellen (CVSS Base Score 10.0) zum Sept. 2026 Patchday mal wieder alles - das BSI warnt, patchen, patchen, patchen.
https://borncity.com/blog/2026/09/10/sap-schwachstellen-cve-2026-44756-cvss-10-0-im-sept-2026/
Overview
Description
Statistics
- 5 Posts
- 1 Interaction
Fediverse
Three threat clusters, including state-sponsored actors and Qilin ransomware affiliates, have exploited two critical Cisco FMC vulnerabilities to deploy web shells, Cyclops Blink malware, and steal sensitive credentials. Cisco has confirmed the exploitation of CVE-2026-20079 and CVE-2026-20316 and urges all customers to install the released hotfixes immediately.
https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
Bluesky
Overview
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
If you want to learn more about the latest zero-day #Magento exploit (StyleSmuggler), this a great read: https://www.graycore.io/case-studies/CVE-2026-75650-style-smuggler
Overview
Description
Statistics
- 2 Posts
- 3 Interactions
Fediverse
Discover the severe N-central CVE-2026-86218 vulnerability allowing unauthenticated RCE. Learn about N-able HF4 patches, CISA mandates, and threat actors.
#Ncentral #CVE202686218 #CyberSecurity #ZeroDay #Vulnerability
Overview
Description
Statistics
- 2 Posts
Fediverse
CVE-2025-14733: CRITICAL RCE in WatchGuard Firebox (Fireware OS 11.x+, 12.x+, 2025.1 – 2025.1.3) exploited by ransomware. Patch ASAP! Review VPN configs, monitor for IOCs. Details: https://radar.offseq.com/threat/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks-43ee9be28a996ee8 #OffSeq #WatchGuard #Ransomware #Infosec
Overview
Description
Statistics
- 3 Posts
Fediverse
An active SonicWall SMA 1000 campaign breached a UK council. Learn how the SonicWall SMA 1000 campaign exposed Active Directory records worldwide.
#SonicWall #Cybersecurity #ActiveDirectory #CVE202615409 #InfoSec
Overview
- Forgejo
- Forgejo
Description
Statistics
- 1 Post
- 11 Interactions
Fediverse
RE: https://infosec.exchange/@cR0w/117247864965166656
CVE for this one:
https://nvd.nist.gov/vuln/detail/cve-2026-89094
sev:CRIT 9.9 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 3 Posts
Fediverse
#Microsoft patched a Critical #Windows DNS Server Remote Code Execution (#RCE) #vulnerability in September Patch Tuesday:
🔴 CVE-2026-69730
⚠️ CVSS: 9.8
🌐 Unauthenticated remote attack (use-after-free)
Patch your DNS servers!
👇
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69730