Overview
Description
Statistics
- 17 Posts
- 8 Interactions
Fediverse
In einem aktuellen Sicherheitshinweis warnt Cisco vor der Ausnutzung einer Zero-Day-Schwachstelle in seiner Secure Email Gateway-Lösung. Angreifer nutzen diese, um aus der Ferne SQL-Befehle auf verwundbaren Systemen auszuführen und mit Root-Rechten zu operieren. Auch weil keine Authentifizierung erforderlich ist, wird CVE-2026-76461 mit 9.8 von 10 bewertet.
Betreiber sollten daher unverzüglich aktiv werden:
https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/2026-288868-1032_bits.pdf
「Ciscoのセキュアメールゲートウェイの脆弱性が実際に悪用され、ルート権限でのコマンド実行が可能になる 」: #TheHackerNews
「スコは、Cisco Secure Email Gateway向けAsyncOSソフトウェアに影響を与える新たな重大な脆弱性が、実際に悪用されていると警告した。
CVE-2026-76461 として追跡されているこの脆弱性は 、CVSSスコアが10.0点満点中9.8点です。これは、メール解析ロジックにおける検証の不備が原因で、認証されていないリモート攻撃者が、基盤となるオペレーティングシステム上でroot権限で任意のコマンドを実行できる可能性があるとされています。
シスコは月曜日の勧告で、「攻撃者は、悪意のあるSQL文を含む細工された電子メールメッセージを影響を受けるデバイスに送信することで、この脆弱性を悪用する可能性がある」 と述べた 。」
https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html
Actionable C-Suite threat intelligence and mitigation strategies for CVE-2026-76461, addressing active SQL injection exploitation vectors within enterprise Cisco Secure Email Gateway infrastructures. https://thecybermind.co/r5ry
Geopolitical tensions: A Russian drone struck a Kyiv-Warsaw train near the Polish border (Sept 13), and Houthi forces secured Yemen's Red Sea coast (Sept 11), affecting maritime routes. Tech news: Apple's Siri AI, powered by Apple Intelligence, began its beta rollout (Sept 14). Cybersecurity: Cisco warned of active exploitation of a critical Secure Email Gateway flaw (CVE-2026-76461) (Sept 15), and Anthropic reported Russia-linked spies used its AI Claude for hacking campaigns.
📰 Cisco Patches Actively Exploited Zero-Day in Secure Email Gateways
Cisco patches critical, actively exploited zero-day (CVE-2026-76461) in Secure Email Gateways. Unauthenticated attackers can compromise devices via a crafted email. CISA has added it to the KEV catalog. #CyberSecurity #ZeroDay #Infosec #Cisco
⚠️ CRITICAL: Cisco warns customers of actively exploited zero-day in email gateways
Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabili…
🤖 AI generated summary
A critical Cisco Secure Email Gateway vulnerability allows unauthenticated attackers to gain root access via a single email. Learn about CVE-2026-76461.
Bluesky
Overview
Description
Statistics
- 8 Posts
- 86 Interactions
Fediverse
Aktuell sind uns in Deutschland rund 3.150 offen aus dem Internet erreichbare GitLab-Instanzen bekannt, die noch für die kritische Schwachstelle CVE-2026-85706 verwundbar sind. Diese werden ab heute an die zuständigen Netzbetreiber gemeldet.
1.640 GitLab-Instanzen sind noch für die ältere kritische Schwachstelle CVE-2026-19478 verwundbar. Diese melden wir bereits seit dem 31.08. an die zuständigen Netzbetreiber.
Beide Schwachstellen werden bereits aktiv ausgenutzt.
🚨 Patch NOW! 🚨
Comment la faille de GitLab peut mettre à nu vos serveurs https://goodtech.info/gitlab-faille-critique-cve-2026-85706-cisa-cert-fr/ #Développement #Revuedepresse #Sécurité
Learn why CISA added GitLab CVE-2026-85706 to the Known Exploited Vulnerabilities catalog. Discover how this CVSS 10 flaw allows remote secret extraction.
Actionable C-Suite threat intelligence for CVE-2026-85706, covering active path traversal exploitation vectors, endpoint hardening, and patch automation across GitLab environments. https://thecybermind.co/uzke
Bluesky
Overview
Description
Statistics
- 4 Posts
Fediverse
「大規模スキャンキャンペーンがViteの脆弱性を悪用し、公開された開発サーバーからクラウド認証情報を抽出 」: #TheHackerNews
「サイバーセキュリティ研究者らは、Viteの導入事例を標的とした大規模なスキャンキャンペーンの詳細を明らかにし、機密データの窃盗を企てていたことを明らかにした。
F5 Labs によると、1つ目はインターネットに公開されているVite開発サーバーを標的とした自動化された攻撃で、クラウド認証情報、Amazon Web Services(AWS)およびMicrosoft Azureインスタンスからの構成情報、インフラストラクチャの状態ファイルを盗むように設計されている 。
2026年8月に観測された認証情報収集活動は、Viteの深刻なセキュリティ脆弱性であるCVE-2026-39364(CVSSスコア:8.2)の脆弱性を悪用していることが判明しました。」
https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html
Overview
- Rymera Web Co Pty Ltd.
- Woocommerce Wholesale Lead Capture
- woocommerce-wholesale-lead-capture
Description
Statistics
- 3 Posts
Bluesky
Overview
- GitLab
- GitLab
Description
Statistics
- 1 Post
- 78 Interactions
Fediverse
Aktuell sind uns in Deutschland rund 3.150 offen aus dem Internet erreichbare GitLab-Instanzen bekannt, die noch für die kritische Schwachstelle CVE-2026-85706 verwundbar sind. Diese werden ab heute an die zuständigen Netzbetreiber gemeldet.
1.640 GitLab-Instanzen sind noch für die ältere kritische Schwachstelle CVE-2026-19478 verwundbar. Diese melden wir bereits seit dem 31.08. an die zuständigen Netzbetreiber.
Beide Schwachstellen werden bereits aktiv ausgenutzt.
🚨 Patch NOW! 🚨
Overview
- mySCADA Technologies
- mySCADA myPRO
Description
Statistics
- 3 Posts
Fediverse
CVE-2026-73807 | CRITICAL: mySCADA myPRO (v0 – 2.1) API flaw allows unauthenticated access to privileged functions. No patch yet — restrict API network access & monitor logs. https://radar.offseq.com/threat/cve-2026-73807-cwe-862-in-myscada-technologies-myscada-mypro-e06debb83925d7aa #OffSeq #ICS #SCADA #Vulnerability
Discover the latest mySCADA myPRO Manager vulnerabilities, including CVE-2026-73807, and learn how to patch your systems to prevent remote attacks.
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
- Logitech
- Logi Options+
Description
Statistics
- 2 Posts
Fediverse
Logitech Options+ : une faille donne les privilèges SYSTEM à n’importe quel utilisateur Windows https://www.it-connect.fr/logitech-options-plus-faille-system-cve-2026-12518/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
Bluesky
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 2 Posts