Blog
CVE-2026-76461 (CVSS 9.8): Cisco Secure Email Gateway Root RCE — Just Send a Crafted Email to Compromise the Appliance
A pre-auth SQL injection in Cisco Secure Email Gateway lets attackers execute OS commands as root simply by sending a crafted email. CVSS 9.8, actively exploited, CISA deadline September 17.…
Read More →MikroTrick: The Three-CVE Chain That Silently Hands Attackers Admin Access to Your MikroTik Router
The MikroTrick exploit chain (CVE-2026-67276 + CVE-2026-86060, CVSS 9.2) bypasses SSH authentication and escalates to full admin on MikroTik RouterOS. Over 122,500 devices exposed. CISA KEV added September 10. Patch…
Read More →CVE-2026-85706 (CVSS 10.0): GitLab Path Traversal Leaks SSH Keys and CI/CD Secrets — Actively Exploited, Patch Now
GitLab CVE-2026-85706 (CVSS 10.0): unauthenticated path traversal lets attackers read any server file. Patch to 19.3.2, 19.2.6, or 19.1.8 now.
Read More →CVE-2026-85102 & CVE-2026-85103 (CVSS 9.8): Dutch NCSC Warns Check Point VPN Firewalls Face Imminent Pre-Auth RCE — Patch Now
Two CVSS 9.8 Check Point VPN flaws (CVE-2026-85102, CVE-2026-85103) enable pre-auth RCE. Dutch NCSC warns exploitation is imminent — patch to Jumbo HFA R82.10 Take 44 immediately.
Read More →Sandworm, Mustang Panda & Lazarus Now Target Energy Grids in 66% of APT Campaigns — Trellix SecondSight September 2026
Trellix SecondSight's September 2026 threat report reveals energy & utilities appear in 66% of APT campaigns — with Sandworm, Mustang Panda, and Lazarus active across 18 countries. India's critical infrastructure…
Read More →BlueMoon Exploit Kit: Four China-Linked Spy Groups Used the Same Chrome + Windows Zero-Day Chain Within a Week
BlueMoon exploit kit chains CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880 — four China-linked APT groups including APT31 deployed it within a week. Patch Chrome and Windows now.
Read More →CVE-2026-85046 (CVSS 8.8): Google Chrome V8 Zero-Day Actively Exploited — Update to 152.0.7977.82 Now
CVE-2026-85046 is a CVSS 8.8 type confusion zero-day in Chrome’s V8 engine actively exploited in the wild. Update Chrome to 152.0.7977.82 immediately. CISA KEV deadline: September 18, 2026.
Read More →AI Agents Breached an Enterprise Network in Under 10 Hours — Unit 42’s Wake-Up Call for Every CISO
Unit 42 documented a real AI-assisted intrusion that compressed two weeks of attack tradecraft into under 10 hours using 50+ MITRE ATT&CK techniques. Here is the defence blueprint.
Read More →CVE-2026-83548 (CVSS 10.0): SonicWall SMA 1000 Zero-Day Chain Weaponised by INC Ransomware — Patch Now
SonicWall SMA 1000 series appliances are under active exploitation via a chained SSRF-to-RCE zero-day (CVE-2026-83548, CVSS 10.0 + CVE-2026-83549). INC ransomware and UTA0533 are confirmed actors. Patch to 12.4.3-03526 or…
Read More →CVE-2025-25249 (CVSS 9.8): PivotC2 RAT Is Actively Backdooring FortiGate Firewalls — Patch FortiOS Now
Attackers exploit CVE-2025-25249, a heap overflow in FortiOS cw_acd, to deploy PivotC2 — a Node.js RAT that steals FortiGate credentials and tunnels into your network.
Read More →