Overview
Description
Statistics
- 17 Posts
- 1 Interaction
Fediverse
Cisco ISE Zero-Day: CVE-2026-76460 Bypasses Authentication With a Perfect CVSS 10.0
Cisco ISE CVE-2026-76460 is a critical CVSS 10 authentication bypass. Learn how the flaw enables admin and root access, IOCs, hunting and fixeshttps://thecybersecguru.com/news/cisco-ise-cve-2026-76460-authentication-bypass/
CVE-2026-76460: CRITICAL auth bypass in Cisco ISE & ISE-PIC is actively exploited. Remote attackers can gain admin access via crafted API requests. Patch ISE 3.1 – 3.5 now — no workarounds. More: https://radar.offseq.com/threat/cisco-warns-of-max-severity-ise-zero-day-exploited-in-attacks-7c00b7de95d29289 #OffSeq #Cisco #ZeroDay #Vuln #Cybersecurity
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-76460 – Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
A strategic executive briefing detailing privileged API mitigation, network segmentation, and zero-trust verification frameworks for CVE-2026-76460 in Cisco ISE....
📰 Cisco ISE Zero-Day (CVSS 10.0) Under Active Attack, Bypasses Auth
Cisco warns of a critical (CVSS 10.0) zero-day in Identity Services Engine (ISE) actively exploited in the wild. The flaw, CVE-2026-76460, allows full authentication bypass. CISA added to KEV catalog. Patch immediately! #Cisco #ZeroDay #CyberSecurity
⚠️ CRITICAL: Cisco alerts customers to second actively exploited zero-day in as many days
Cisco ISE zero-day CVE-2026-76460 is actively exploited in the wild. Remote attackers can bypass authentication, take full device control, modify network policies, and steal credentials. If you run ISE, this is a direct threat to your network perimeter and access controls.
🤖 AI generated summary
「Cisco、ISE認証バイパスの新たなゼロデイ脆弱性(CVSS 10.0)が現在進行中の攻撃で悪用されていると警告 」: #TheHackerNews
「Ciscoは、Identity Services Engine(ISE)に影響を与える新たな最高レベルのセキュリティ脆弱性が発見され、現在悪用されていると警告した。
CVE-2026-76460 (CVSSスコア:10.0)として追跡されているこの脆弱性により 、認証されていないリモート攻撃者が認証を回避できる可能性がある。
「この脆弱性は、APIエンドポイントにおける認証制御の不備に起因するものです」とシスコは述べています。「攻撃者は、細工されたリクエストを影響を受けるAPIエンドポイントに送信することで、この脆弱性を悪用する可能性があります。攻撃が成功すると、攻撃者はWebベースの管理インターフェースを迂回して、影響を受けるデバイスへの不正アクセスを取得できる可能性があります。」 」
https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html
Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.
Bluesky
Description
Statistics
- 3 Posts
- 30 Interactions
Fediverse
Google sieht Hinweise auf eine begrenzte, gezielte Ausnutzung von
CVE-2026-58704 auf Pixel-Geräten. Die Schwachstelle steckt im Modem
und ermöglicht eine Rechteausweitung. Der September-Patchlevel
2026-09-05 behebt die Lücke.
https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
🚨 Google confirms Pixel phones targeted in zero-click zero-day attacks
Google has patched CVE-2026-58704, a high-severity vulnerability in Pixel phones' cellular modem that the company says was already under "limited, targeted exploitation."
⠀
The flaw is caused by a logic error that can allow an attacker to bypass permission checks and escalate privileges beyond the modem's isolated environment.
⠀
Most importantly, exploitation requires no interaction from the victim.
No malicious link needs to be clicked and no file needs to be opened, making it a zero-click attack.
⠀
Google has not disclosed:
• Who carried out the attacks
• How many Pixel owners were targeted
• How the victims were selected
• What tools or spyware may have been deployed
⠀
CISA has added CVE-2026-58704 to its Known Exploited Vulnerabilities catalog and set a September 19 remediation deadline for affected federal systems.
⠀
Google says Pixel devices with the September 5, 2026 security patch level or later are protected.
Pixel owners should update their devices immediately.
Hey @GrapheneOS do you happen to know when CVE-2026-58704 will be patched?
(to clarify, tone is not meant to be passive aggressive, genuinely just curious)
Overview
- Docker
- Docker Sandboxes
Description
Statistics
- 5 Posts
- 2 Interactions
Fediverse
‼️ ALERT - Critical Docker Sandboxes flaw lets malicious guest code escape the shared workspace and read or modify files across a macOS host.
CVE-2026-77179 crosses the virtio-fs boundary with the host account’s rights.
Read how the escape works → https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
「Dockerサンドボックスの重大な脆弱性により、悪意のあるゲストコードがmacOSホストファイルを読み取り、変更することが可能になる。 」: #TheHackerNews
「Dockerは9月15日のセキュリティ発表 で、macOS上のDocker Sandboxes 仮想マシン内で実行されている悪意のあるコードが、 共有されているプロジェクトディレクトリから脱出し、ホスト上の他の場所にあるファイルを読み取ったり変更したりする可能性があると警告した 。
このエスケープ処理は、仮想マシンを実行するホストアカウントの権限で実行されます。この脆弱性( CVE-2026-77179 )は、深刻度が「重大」と評価されており、macOS 版のバージョン 0.28.0 から 0.42.0 まで(0.42.0 は含まない)に影響があり、 9 月 7 日にリリースされたバージョン 0.42.0 で修正されました。 」
https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
Critical Docker Sandboxes Flaws Let AI Agents Escape MicroVMs to Hijack Hosts (CVE-2026-77179 & CVE-2026-79994)
Critical Docker Sandboxes flaws CVE-2026-77179 and CVE-2026-79994 can let malicious AI agents escape microVM isolation and access the host systemhttps://thecybersecguru.com/news/docker-sandboxes-cve-2026-77179-cve-2026-79994/
Bluesky
Overview
- checkpoint
- Quantum Security Management
Description
Statistics
- 3 Posts
Fediverse
Check Point Security Mgmt & Log Server hit by CRITICAL RCE (CVE-2026-91843) via unauthenticated login. No active exploitation yet. Patch ASAP. Tanium (SQLi, RCE) & Kaspersky (Redis) also patched. https://radar.offseq.com/threat/check-point-kaspersky-tanium-patch-product-vulnerabilities-ae8c3757ea9b181a #OffSeq #Vulnerability #RCE #PatchNow
Critical cybersecurity alerts issued as Check Point (CVE-2026-91843) and Cisco (CVE-2026-76460) disclose severe vulnerabilities, with Cisco's already exploited. Geopolitically, USCG/FBI investigate suspected foreign cyberattacks on two oil tankers; Iran reportedly targeted another in the Strait of Hormuz. Tech advances with OpenAI's 'Astra for Law' for legal AI workflows.
Overview
Description
Statistics
- 3 Posts
Fediverse
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2026-87886 – Acronis Backup Incorrect Default Permissions Vulnerability
A strategic executive briefing detailing permission hardening, risk deliberation, and incident response frameworks for CVE-2026-87886 in Acronis Backup environments....
Overview
- Mitsubishi Electric Corporation
- GX Works3
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-15688 | Mitsubishi Electric GX Works3 (CVSS 9.2, CRITICAL): Local attackers can bypass authentication by modifying memory, risking control program compromise. No fix yet — restrict local access. #OffSeq #ICS #CVE202615688 https://radar.offseq.com/threat/cve-2026-15688-cwe-303-incorrect-implementation-of-authentication-algorithm-in-mitsubishi-electric-b35e18a6ba962469
Overview
Description
Statistics
- 2 Posts
Fediverse
Cisco Zero-Day wird aktiv angegriffen
Mal was neues - ach nein, Hintertüren bei Cisco sind ja gar nicht neu, sondern schon fast Gewohnheit. Am Montag hat die Firma ihre Kunden informiert, dass im Secure Email Gateway (SEG) eine Sicherheitslücke steckt, die bereits aktiv angegriffen wird. Dabei ist gleichgültig, ob das SEG auf eigener Hardware (Appliance) läuft oder als virtuelle Maschine oder Cloud-Dienst. Auch die Konfiguration des SEG macht keinen Unterschied. Das muss man sich mal auf der Zunge zergehen lassen: Das SEG, das vor schädlichen E-Mails schützen soll, kann durch genau solche angegriffen werden! Die Sicherheitslücke CVE-2026-76461 ... Weiterlesen:
https://www.pc-fluesterer.info/wordpress/2026/09/17/cisco-zero-day-wird-aktiv-angegriffen/
#0day #backdoor #closedsource #email #exploits #hersteller #sicherheit #UnplugTrump #zeroday #cisco
Overview
- Docker
- Docker Sandboxes
Description
Statistics
- 3 Posts
Fediverse
Critical Docker Sandboxes Flaws Let AI Agents Escape MicroVMs to Hijack Hosts (CVE-2026-77179 & CVE-2026-79994)
Critical Docker Sandboxes flaws CVE-2026-77179 and CVE-2026-79994 can let malicious AI agents escape microVM isolation and access the host systemhttps://thecybersecguru.com/news/docker-sandboxes-cve-2026-77179-cve-2026-79994/
Bluesky
Overview
- HP Inc.
- HP Linux Imaging and Printing Software (HPLIP)
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
HP patched critical HPLIP vulnerabilities. Update your print drivers to fix HPLIP vulnerabilities and prevent remote code execution.
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-81005 Linux kernel NULL pointer dereference in ipmi_si after failed SMI registration. CVSS N/A. Unpatched. A BMC that fails Get Device ID can crash the kernel. Patch now. https://www.valtersit.com/cve/CVE-2026-81005/ #CVE #Linux #infosec