Overview
Description
Statistics
- 13 Posts
- 3 Interactions
Fediverse
Recent reports confirm a critical GitLab zero-day (CVE-2026-85706) exploited within 24 hours, alongside new EU Cyber Resilience Act mandates for 24-hour vulnerability reporting. Operational technology (OT) sectors face emerging ransomware threats. Meanwhile, leading AI developers advocate for a slowdown in development due to safety concerns, prompting market shifts. Geopolitically, the BRICS summit addressed rising global tensions and the "weaponization of technology."
CRITICAL CISA KEV ALERT: CVE-2026-85706 targets GitLab CE/EE via path traversal in the repository commits API. Active exploitation verified. Access our TSUITE brief for SIEM detection queries and compensating controls to protect your CI/CD pipeline and isolate your secrets.
CVE-2026-85706 GitLab CE/EE: unauthenticated arbitrary file read via commits API, CVSS 10. Affects 18.7 up to 19.1.8, 19.2.6, 19.3.2. No patch confirmed yet, restrict access now. https://www.valtersit.com/cve/CVE-2026-85706/ #CVE #GitLab #infosec
⚠️GitLab : CVE-2026-85706 est activement exploitée.
Une faille critique de traversée de répertoires permet à un attaquant non authentifié de lire des fichiers arbitraires sur le serveur.
Encore une vulnérabilité qui prend des chemins de traverse…
../../../../etc/ :dumpster_fire_gif: 👀
-->GitLab auto-hébergé exposé sur Internet : mise à jour rapide recommandée.
Correctifs : 19.1.8, 19.2.6 et 19.3.2.
La faille a déjà rejoint le catalogue KEV de la CISA, et ça commence clairement à renifler autour : watchTowr et plusieurs honeypots ont déjà vu passer des tentatives de probing.
Onyphe recense une bonne centaine d’instances vulnérables en CH aujourd'hui...
「パッチ適用後数日で、GitLabの完璧なバグが攻撃を受ける
/CISAは、WatchTowerがインターネットに接続されたサーバーを攻撃する悪意のある人物を発見したことから、攻撃が活発に行われていることを確認した。 」: #TheRegister
「CISAによると、攻撃者はGitLabの深刻な脆弱性を悪用しており、認証されていない悪意のある人物が脆弱なサーバーから任意のファイルを読み取ることができるようになっている。これは、GitLabが9月10日に修正プログラムをリリースした後も続いている。
米国サイバーセキュリティ・インフラストラクチャセキュリティ庁は、 既知の悪用された脆弱性カタログにCVE-2026-85706を追加しました 。
この脆弱性は、リポジトリのコミットAPIにおけるパストラバーサル攻撃のバグであり、GitLab Community EditionとEnterprise Editionの両方に影響します。」
Bluesky
Overview
Description
Statistics
- 8 Posts
- 6 Interactions
Fediverse
ayy lmao Cisco CVE-2026-76461
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.
CRITICAL CISA KEV ALERT: CVE-2026-76461 targets Cisco Secure Email Gateway via SQL injection, granting root-level RCE. Active exploitation verified. Access our TSUITE brief for SIEM queries and hardening steps to secure your email perimeter.
No one else seems to have noticed the Cisco exploited zero-day:
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability
CVE-2026-76461 (CVSS 9.8) is a Cisco Secure Email Gateway vulnerability exploited in the wild. SQL injection grants root command execution. Patch now.
#Cisco #EmailSecurity #CVE202676461 #SQLInjection #RCE #ExploitedInTheWild #AsyncOS #InfoSec #PatchNow #RootAccess
CRITICAL (CVSS 9.8): CVE-2026-76461 in Cisco AsyncOS for Secure Email Gateway lets unauthenticated attackers execute commands as root via crafted emails. Patch status unknown — monitor Cisco’s updates. https://radar.offseq.com/threat/a-vulnerability-in-the-email-parsing-of-cisco-asyncos-software-for-cisco-secure-email-gateway-could-a5a1b3247d786df4 #OffSeq #Cisco #Vulnerability #EmailSecurity
Bluesky
Overview
- Microsoft
- Windows 10 Version 1607
Description
Statistics
- 1 Post
- 64 Interactions
Fediverse
Microsoft today released an out of band update that includes a security update to a vulnerability they first patched in August. I guess the first patch didn't work broadly enough or introduced more flaws (or both). According to MS, though, there aren't any signs this vulnerability is actively being exploited. MS just says "The CVE was updated with links to security updates for Windows 11, version 26H1, 25H2, and 24H2 to address a missed fix."
https://msrc.microsoft.com/update-guide/advisory/CVE-2026-62721
Overview
Description
Statistics
- 3 Posts
Fediverse
ConnectWise ScreenConnect CRITICAL vuln (CVE-2026-84869) exploited in worm-like attacks — unauthorized file transfer & execution via remote sessions in versions <26.6.5. Patch to 26.6.5 now or disable TransferFiles. https://radar.offseq.com/threat/connectwise-patches-screenconnect-vulnerability-exploited-in-worm-like-attacks-c3e27ae69aeeacb1 #OffSeq #Cybersecurity #Vuln #CISA
CRITICAL CISA KEV ALERT: CVE-2026-84869 targets ConnectWise ScreenConnect with unauthorized file transfer and RCE. Active exploitation verified. Access our TSUITE brief for Splunk, Sentinel, QRadar queries, and endpoint hardening steps to protect your environment. https://thecybermind.co/g5ob
Overview
Description
Statistics
- 2 Posts
Fediverse
The Vite development server vulnerability CVE-2026-39364 is exploited in mass scanning for credential harvesting. F5 Labs logged 32,000 events. Patch now.
#Vite #CVE202639364 #CloudSecurity #CredentialHarvesting #F5Labs #DevSecOps #FileDisclosure #InfoSec #AWS #MassScanning
「ハッカーがViteの開発サーバーを標的にAWSとAzureの機密情報を盗み出す 」: #BLEEPINGCOMPUTER
「インターネットに公開されているVite開発サーバーを標的とした大規模なスキャンキャンペーンが、AWSおよびAzure環境からクラウド認証情報と設定を盗み出そうとしている。
この攻撃は、Vite バージョン 7.1.0 から 7.3.2、および 8.x ブランチの 8.0.5 より前のバージョンにおいて、ファイルの読み取り/アクセス制御を回避できる深刻な脆弱性である CVE-2026-39364 を悪用するものです。
この脆弱性は4月7日に公表され、認証されていない攻撃者がHTTP GETリクエストのクエリパラメータを操作することで、セキュリティ制限を回避し、通常はアクセスできないはずの場所から平文のファイルを取得できるというものである。」
Overview
- stellarwp
- The Events Calendar
Description
Statistics
- 2 Posts
Fediverse
A critical The Events Calendar vulnerability is exploited in the wild. Patch The Events Calendar vulnerability now to stop remote code execution.
#TheEventsCalendar #WordPress #CVE202678006 #Cybersecurity #InfoSec
Bluesky
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
- checkpoint
- Quantum Security Gateway
Description
Statistics
- 3 Posts
Bluesky
Overview
- checkpoint
- Quantum Security Gateway
Description
Statistics
- 3 Posts
Bluesky
Overview
- crawlab-team
- crawlab
Description
Statistics
- 1 Post
- 11 Interactions
Fediverse
Go fuck with some crawlers.
https://nvd.nist.gov/vuln/detail/cve-2026-90945
Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.