Overview
Description
Statistics
- 17 Posts
- 2 Interactions
Fediverse
This the one I been waiting for..
shout out to Xi and da boiz
https://watchtowr.com/intelligence/cisco-catalyst-sd-wan-manager-cve-2026-76504-faq/
U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog
Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)
Threat Advisory: CVE-2026-76504 Affected Vendor/Product: Cisco - Catalyst SD-WAN Manager Vulnerability Type (CWE): N/A Operational Threat Level:...
https://thecybermind.co/2026/10/01/cve-2026-76504-catalyst-sd-wan-manager/
Critical Threat Advisory: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)
CISA’s active exploitation verification of CVE-2026-76504 demands an immediate, high-priority posture adjustment across all Cisco Catalyst SD-WAN Manager…...
https://thecybermind.co/2026/10/01/cve-2026-76504-catalyst-sd-wan-manager-3/
📰 Cisco Patches Actively Exploited SD-WAN Auth Bypass Zero-Day
Cisco patches critical auth bypass zero-day (CVE-2026-76504) in Catalyst SD-WAN Manager. CVSS 9.8 flaw actively exploited. Unauthenticated attackers can gain admin access. CISA added to KEV. Patch immediately! #Cisco #ZeroDay #SDWAN #CVE202676504
Bluesky
Overview
Description
Statistics
- 8 Posts
- 37 Interactions
Fediverse
Great IOCs on the follow up spray and pray activity on #PitScaler so far.
For context this activity definitely is not related to the inital threat actor activity in early September. This is new stuff.
oh wow that grep|sed|awk pipeline...
I keep saying this:
Parsing strings all over the place is a funny idea that #Unix had, but inherently prone to error and, frankly, horribly insecure.
Attackers exploit Citrix NetScaler zero-day CVE-2026-88772 for root access, then hide WHIPSHOT web shells and a SLAPSHOT tunneler. Patch now.
#CitrixNetScaler #ZeroDay #CVE202688772 #CVE202688771 #WHIPSHOT #SLAPSHOT #Mandiant #CyberSecurity
https://securityonline.info/citrix-netscaler-zero-day/?utm_source=mastodon&utm_medium=jetpack_social
📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack
Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE
Bluesky
Overview
Description
Statistics
- 8 Posts
- 5 Interactions
Fediverse
Un domaine eu\.org cité par Microsoft sur l'attaque Zimbra. Domaine suspendu. Sauf erreur de ma part, Microsoft n'a jamais contacté eu\.org. Je n'en ai eu connaissance que ce matin par @dascritch qui m'a envoyé le lien @NextInpact
🚨 Attackers exploited a Zimbra flaw to plant web shells and harvest authentication secrets.
CVE-2026-73570 can be triggered by a crafted SMTP request when SNMP notifications are enabled and zimbra-snmp is installed.
Read: https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
#infosec #Zimbra
https://www.microsoft.com/en-us/security/blog/2026/09/30/unauthenticated-command-injection-on-internet-facing-mail-servers-tracking-cve-2026-73570/
Bluesky
Overview
Description
Statistics
- 6 Posts
- 5 Interactions
Fediverse
Geopolitical: Iran warned UAE following Netanyahu's visit (Sept 30) amidst regional tensions, while Russia conducted a drone strike on Ukraine's National Academy of Sciences (Sept 29).
Technology: OpenAI launched "dots" agents and GPT-6.1 Sol (Sept 29), despite shelving a prior AI model (Astra) due to safety concerns. SpaceX's Starship successfully completed its first orbital flight (Sept 28-29).
Cybersecurity: Urgent advisories were issued for actively exploited Citrix NetScaler zero-days (Sept 30), mandating federal agency patching. Apple also patched a CoreGraphics zero-day (CVE-2026-86950) used in targeted attacks (Sept 29).
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
#Apple released a #security update for #iOS 26, #iPadOS 26, and #macOS 26 to fix a #vulnerability in the #graphicsengine that could be exploited for sophisticated attacks. The bug, CVE-2026-86950, was discovered by Meta and could potentially allow hackers to steal personal data. A separate zero-click bug, CVE-2026-86869, was also fixed, preventing silent data theft via malicious iMessages. https://techcrunch.com/2026/09/29/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this-urgent-security-fix/
Bluesky
Overview
Description
Statistics
- 8 Posts
Fediverse
CVE-2026-88772, a Citrix NetScaler DTLS memory overflow, is exploited in the wild. A watchTowr PoC and full details are now public. Patch NetScaler now.
#Citrix #NetScaler #CVE202688772 #DTLS #watchTowr #KEV #ZeroDay #RCE
Attackers exploit Citrix NetScaler zero-day CVE-2026-88772 for root access, then hide WHIPSHOT web shells and a SLAPSHOT tunneler. Patch now.
#CitrixNetScaler #ZeroDay #CVE202688772 #CVE202688771 #WHIPSHOT #SLAPSHOT #Mandiant #CyberSecurity
https://securityonline.info/citrix-netscaler-zero-day/?utm_source=mastodon&utm_medium=jetpack_social
📰 Citrix Patches Two Critical NetScaler Zero-Days Under Active Attack
Critical Alert: Two Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772) are under active global attack. Flaws allow unauthenticated RCE. CISA KEV listed. Patch and hunt for compromise now! #Citrix #NetScaler #CyberSecurity #CVE
Bluesky
Overview
- Sharp Corporation
- Multiple Multifunction Printers
Description
Statistics
- 1 Post
- 46 Interactions
Fediverse
Fuck this bullshit. This 2024 CVE was just published today. Which, fine, whatever. It happens. Except it specifically says it was observed EITW in July 2024.
https://www.cve.org/CVERecord?id=CVE-2024-58388
Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30.
Witholding a CVE for something known to be EITW for over two years is fucking bullshit. Especially when the PoC was published in June 2024:
https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html#pre-auth-lfi
But at least there's a Nuclei template:
Overview
Description
Statistics
- 2 Posts
Fediverse
Learn how to patch critical ASUS security vulnerabilities like CVE-2026-13313 to protect your routers and motherboards from severe network exploits.
CVE-2026-13313 (HIGH, CVSS 8.9) in ASUS routers: Authenticated attackers can enable Telnet via debug code, gaining root command execution. Restrict management access & monitor Telnet until patch info is released. https://radar.offseq.com/threat/cve-2026-13313-cwe-489-active-debug-code-in-asus-router-57f2c007e7c82b59 #OffSeq #ASUS #Infosec #Vuln
Overview
- WatchGuard
- Fireware OS
Description
Statistics
- 2 Posts
Bluesky
Overview
- Kiteworks
- Email Protection Gateway
Description
Statistics
- 2 Posts
Fediverse
Kiteworks Email Protection Gateway <9.5.1 has a CRITICAL vuln (CVE-2026-102149, CVSS 9.4): attackers can assign certificates to other user accounts, risking encrypted email exposure & unauthorized access. Await patch, consider disabling cert login. https://radar.offseq.com/threat/cve-2026-102149-cwe-306-missing-authentication-for-critical-function-in-kiteworks-email-protection-4008bd0cefe1b69f #OffSeq #CVE2026102149 #infosec
Kiteworks vulnerabilities fixed in 9.5.1 include CVE-2026-102115, a 9.8 password reset flaw that enables admin account takeover. Patch now.
#Kiteworks #KiteworksVulnerabilities #CVE2026102115 #CVE2026102149 #CVE2026102147 #EmailSecurity #SSRF #PatchNow
https://securityonline.info/kiteworks-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
Overview
- Kiteworks
- Core
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-102147: Stored XSS in Kiteworks Core (<9.5.1) rated CRITICAL (CVSS 9.3). Unauth attacker can hijack admin sessions via injected JS — admin takeover risk. No patch yet; restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-102147-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-de1db64f96a0fee0 #OffSeq #CVE2026102147 #AppSec ⚡️
Kiteworks vulnerabilities fixed in 9.5.1 include CVE-2026-102115, a 9.8 password reset flaw that enables admin account takeover. Patch now.
#Kiteworks #KiteworksVulnerabilities #CVE2026102115 #CVE2026102149 #CVE2026102147 #EmailSecurity #SSRF #PatchNow
https://securityonline.info/kiteworks-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social