Overview
Description
Statistics
- 5 Posts
Fediverse
Critical cybersecurity alert: North Korea's UNC2970 is weaponizing Google Gemini for reconnaissance. A CVSS 9.9 BeyondTrust vulnerability (CVE-2026-1731) is also under active exploitation, enabling remote code execution. Meanwhile, the Munich Security Conference highlighted deepening transatlantic tensions.
Bluesky
Overview
- Ivanti
- Endpoint Manager
Description
Statistics
- 1 Post
- 17 Interactions
Fediverse
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
#cybersecurity #ivanti #vulnerabilitymanagement #vulnerability
Thanks @reverseics for the infographics and Ivanti for the continuous source of discoveries.
Overview
Description
Statistics
- 4 Posts
- 3 Interactions
Fediverse
This build has a fix for CVE-2026-2441 (Use after free in CSS), which has a known exploit in the wild.
@secbox @vivaldiversiontracker
It might seem strange but this build has a fix for CVE-2026-2441 (Use after free in CSS), which has a known exploit in the wild. 🤷
Thursday: New Chrome release! It reverts one commit, a "trivial" performance optimization suspected of causing crashes.
https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_12.html
Friday: New Chrome release! A zero day! "CVE-2026-2441: Use after free in CSS."
https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html
Overview
- Hitachi Energy
- RTU500 series CMU firmware
Description
Statistics
- 2 Posts
Fediverse
'... each of the targeted facilities had Fortinet FortiGate devices exposed to the internet, using default credentials and lacking [MFA] ... the initial attack vector.
'... included [Hitachi Energy] RTU560 [RTUs] .... which threat actors accessed using default credentials ... a security feature meant to prevent malicious firmware updates had not been enabled, but even if it had been enabled the devices were affected by CVE-2024-2617, a known flaw allowing unsigned firmware updates.
'... Hitachi Relion protection and control relays ... failure to disable a default FTP account (the vendor recommends disabling this account) and the use of default credentials.
'... RTUs and human-machine interfaces (HMIs) made by Mikronika ...protected with default credentials ...
'... wipers on Windows machines hosting the HMI software, which, on devices protected by default local admin credentials, caused damage.
'Moxa NPort serial device servers ... exposed web interfaces and default credentials to access the systems and then reset them to factory settings, changed their login password, and assigned IP addresses that prevented legitimate users from accessing them'.
Basics not getting implemented means your CNI is basically not in a good place.
https://www.securityweek.com/default-ics-credentials-exploited-in-destructive-attack-on-polish-energy-facilities/
Overview
- dani-garcia
- vaultwarden
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- milvus-io
- milvus
Description
Statistics
- 1 Post
Fediverse
🔴 CVE-2026-26190: CRITICAL auth bypass in Milvus (<2.5.27, 2.6.0-2.6.9). REST API & /expr debug endpoint exposed via port 9091, enabling unauth access to data & creds. Patch to 2.5.27/2.6.10 ASAP! Details: https://radar.offseq.com/threat/cve-2026-26190-cwe-306-missing-authentication-for--6b5551d3 #OffSeq #infosec #AIsecurity
Overview
Description
Statistics
- 1 Post
Fediverse
🔴 CRITICAL: CVE-2026-26273 in Known <1.6.3 leaks password reset tokens in HTML — full account takeover possible without email access. Upgrade to 1.6.3+ & audit reset flows. https://radar.offseq.com/threat/cve-2026-26273-cwe-200-exposure-of-sensitive-infor-d59f1dbb #OffSeq #CVE202626273 #Vuln #Security
Overview
- OpenClaw
- OpenClaw
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Bluesky
Overview
Description
Statistics
- 1 Post