Overview
- JetBrains
- TeamCity
Description
Statistics
- 7 Posts
- 1 Interaction
Fediverse
CRITICAL: JetBrains TeamCity On-Premises (all versions) vulnerable to CVE-2026-63077 — auth bypass enables remote code execution via HTTPS. Patch to 2025.11.7/2026.1.3 or apply plugin for 2017.1+. TeamCity Cloud unaffected. https://radar.offseq.com/threat/jetbrains-warns-of-critical-teamcity-remote-code-execution-flaw-b5d2b338dff8d1eb
#OffSeq #Vuln #TeamCity #CVE202663077
Bluesky
Overview
Description
Statistics
- 6 Posts
- 18 Interactions
Fediverse
RE: https://ruby.social/@flavorjones/117003927959522056
The Rails security team published attack details and -- more importantly -- tools and agent skills to run a forensic investigation to help you determine if you were exploited. Be careful out there.
Bluesky
Overview
Description
Statistics
- 6 Posts
- 1 Interaction
Fediverse
Nutzt wer das Cisco Secure Firewall Management Center (FMC)? Da ist eine Backdoor mit festen Zugangsdaten durch Cyberkriminelle, die das ausnutzen, aufgeflogen. Patchen ist angesagt - und die FMC sollte nicht per Internet erreichbar sein.
https://borncity.com/blog/2026/07/30/backdoor-cve-2026-20316-in-cisco-firewall-wird-ausgenutzt/
Critical advisory: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to hard-coded credential abuse. Review active threat vectors, network access lockdowns, and system hardening playbooks to protect your perimeter. https://thecybermind.co/bkur
Executive alert: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to active exploitation via hard-coded credentials. Review enterprise exposure metrics, zero-trust segmentation, and board-level risk mitigation strategies today. https://thecybermind.co/jily
Bluesky
Overview
Description
Statistics
- 3 Posts
- 3 Interactions
Fediverse
⚠️ CRITICAL: Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Russian state-sponsored group Laundry Bear is actively exploiting a zero-day XSS vulnerability (CVE-2026-42897) in Exchange OWA to deploy OWAReaper backdoor. Targets include U.S. and European government entities and private sector organizations. Successful exploitation grants persistent mailbox acc…
Bluesky
Overview
- codeigniter4
- CodeIgniter4
Description
Statistics
- 3 Posts
Fediverse
CVE-2026-63223 - Critical arbitrary file upload in CodeIgniter. Bypass of is_image/mime_in validation can lead to RCE. CVSS 9.8. Update to 4.7.4 immediately. #CVE #CodeIgniter #infosec
So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.
Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)
Did people still use CodeIgniter?
Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.
Overview
- ruvnet
- ruflo
Description
Statistics
- 2 Posts
Fediverse
⚠️ CRITICAL: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
CVE-2026-59726 in Ruflo AI orchestration platform allows unauthenticated remote code execution via an exposed Model Context Protocol bridge. Attackers can steal API keys, access user conversations, and corrupt AI memory without any credentials. Any organization running Ruflo is immediately exploita…
Overview
- Adobe
- Adobe Campaign Classic
Description
Statistics
- 2 Posts
Fediverse
Adobe Campaign Classic flaw CVE-2026-48449 scores a perfect CVSS 10.0 and allows arbitrary code execution. Update to build 9398 now.
Overview
- PHP Group
- PHP
- ext-pgsql
Description
Statistics
- 2 Posts
Fediverse
A PHP SQL injection flaw, CVE-2026-17543, was patched alongside two memory bugs. Update to PHP 8.2.33, 8.3.33, 8.4.24, or 8.5.9 now.
#PHP #SQLInjection #CVE202617543 #PostgreSQL #Vulnerability #InfoSec
Overview
- Microsoft
- Azure Cosmos DB
Description
Statistics
- 2 Posts
Fediverse
Azure Cosmos DB suffers a CRITICAL improper access control vulnerability (CVE-2026-66803) allowing unauthorized remote code execution. No patch yet — restrict network access & monitor Microsoft advisories. https://radar.offseq.com/threat/improper-access-control-in-azure-cosmos-db-allows-an-unauthorized-attacker-to-execute-code-over-a-db3b78e9f6a886eb #OffSeq #Azure #Vuln #CyberSecurity
Overview
Description
Statistics
- 3 Posts
- 11 Interactions
Fediverse
ICYMI, GhostLock (CVE-2026-43499) is now patched in AlmaLinux production repos for 8, 9, and 10.
Update your kernel and reboot to protect against this unprivileged local root/container escape vulnerability! https://almalinux.org/blog/2026-07-09-ghostlock/
Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.
Some interesting attacks exploiting CVE-2026-10702 are shoring up:
https://thehackernews.com/2026/07/researchers-show-single-malicious.html?m=1
Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).
(Unclear if/how Firefox-ESR is affected)