#cisakev — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cisakev, aggregated by home.social.
-
Our weekly CVE report: 1,571 new flaws and 6 actively exploited vulnerabilities hit CISA KEV, including ColdFusion and Joomla RCE.
-
Our weekly CVE report: 1,571 new flaws and 6 actively exploited vulnerabilities hit CISA KEV, including ColdFusion and Joomla RCE.
-
Our weekly CVE report: 1,571 new flaws and 6 actively exploited vulnerabilities hit CISA KEV, including ColdFusion and Joomla RCE.
-
CISA aggiunge Langflow e Joomla al catalogo KEV: una IDOR ruba le chiavi degli agenti AI, uno zero-day PHP infetta i siti in un solo POST
Quattro CVE critiche entrano nel catalogo Known Exploited Vulnerabilities di CISA: un IDOR cross-tenant in Langflow usato per rubare chiavi LLM e AWS, e due zero-day di file upload non autenticato in estensioni Joomla che regalano l'accesso Super User con una singola richiesta. -
CISA aggiunge Langflow e Joomla al catalogo KEV: una IDOR ruba le chiavi degli agenti AI, uno zero-day PHP infetta i siti in un solo POST
Quattro CVE critiche entrano nel catalogo Known Exploited Vulnerabilities di CISA: un IDOR cross-tenant in Langflow usato per rubare chiavi LLM e AWS, e due zero-day di file upload non autenticato in estensioni Joomla che regalano l'accesso Super User con una singola richiesta. -
CISA aggiunge Langflow e Joomla al catalogo KEV: una IDOR ruba le chiavi degli agenti AI, uno zero-day PHP infetta i siti in un solo POST
Quattro CVE critiche entrano nel catalogo Known Exploited Vulnerabilities di CISA: un IDOR cross-tenant in Langflow usato per rubare chiavi LLM e AWS, e due zero-day di file upload non autenticato in estensioni Joomla che regalano l'accesso Super User con una singola richiesta. -
CISA aggiunge Langflow e Joomla al catalogo KEV: una IDOR ruba le chiavi degli agenti AI, uno zero-day PHP infetta i siti in un solo POST
Quattro CVE critiche entrano nel catalogo Known Exploited Vulnerabilities di CISA: un IDOR cross-tenant in Langflow usato per rubare chiavi LLM e AWS, e due zero-day di file upload non autenticato in estensioni Joomla che regalano l'accesso Super User con una singola richiesta. -
CISA aggiunge Langflow e Joomla al catalogo KEV: una IDOR ruba le chiavi degli agenti AI, uno zero-day PHP infetta i siti in un solo POST
Quattro CVE critiche entrano nel catalogo Known Exploited Vulnerabilities di CISA: un IDOR cross-tenant in Langflow usato per rubare chiavi LLM e AWS, e due zero-day di file upload non autenticato in estensioni Joomla che regalano l'accesso Super User con una singola richiesta. -
CISA flags an actively exploited SharePoint vulnerability (CVE-2026-45659) enabling remote code execution. Patch SharePoint Server 2016 now.
#SharePoint #Microsoft #CVE202645659 #CISAKEV #RCE #ExploitedInTheWild #Vulnerability
-
CISA flags an actively exploited SharePoint vulnerability (CVE-2026-45659) enabling remote code execution. Patch SharePoint Server 2016 now.
#SharePoint #Microsoft #CVE202645659 #CISAKEV #RCE #ExploitedInTheWild #Vulnerability
-
CISA flags an actively exploited SharePoint vulnerability (CVE-2026-45659) enabling remote code execution. Patch SharePoint Server 2016 now.
#SharePoint #Microsoft #CVE202645659 #CISAKEV #RCE #ExploitedInTheWild #Vulnerability
-
https://www.europesays.com/ch-fr/187905/ Anatomie de la CVE-2026-42271 : la passerelle IA LiteLLM exécutait du code via le protocole MCP #CISAKEV #Cve202642271 #ExécutionDeCodeàDistance #litellm #MCP #PasserelleIa #Science #ScienceAndTechnology #Sciences #SciencesEtTechnologies #SécuritéDesApi #starlette #Suisse #Technologies #Technology
-
This week's top 5: 2yr Oracle patch exploited, FSB USB worm, Android KEV zero-day, WordPress CVSS 9.8 admin takeover, RaaS at 90% affiliate share.
The attack surface is what you don't control.
-
CVE-2026-0257: Palo Alto GlobalProtect sotto attacco — cookies bypassano l’autenticazione VPN
Rapid7 MDR ha documentato due ondate di sfruttamento attivo di CVE-2026-0257, un bypass dell'autenticazione GlobalProtect di Palo Alto Networks. Gli attaccanti forgiano cookie validi usando la chiave pubblica TLS dell'appliance, ottenendo accesso VPN senza credenziali. Un PoC pubblico è già disponibile e la vulnerabilità è nella CISA KEV. -
CVE-2026-0257: Palo Alto GlobalProtect sotto attacco — cookies bypassano l’autenticazione VPN
Rapid7 MDR ha documentato due ondate di sfruttamento attivo di CVE-2026-0257, un bypass dell'autenticazione GlobalProtect di Palo Alto Networks. Gli attaccanti forgiano cookie validi usando la chiave pubblica TLS dell'appliance, ottenendo accesso VPN senza credenziali. Un PoC pubblico è già disponibile e la vulnerabilità è nella CISA KEV. -
CVE-2026-0257: Palo Alto GlobalProtect sotto attacco — cookies bypassano l’autenticazione VPN
Rapid7 MDR ha documentato due ondate di sfruttamento attivo di CVE-2026-0257, un bypass dell'autenticazione GlobalProtect di Palo Alto Networks. Gli attaccanti forgiano cookie validi usando la chiave pubblica TLS dell'appliance, ottenendo accesso VPN senza credenziali. Un PoC pubblico è già disponibile e la vulnerabilità è nella CISA KEV. -
CVE-2026-0257: Palo Alto GlobalProtect sotto attacco — cookies bypassano l’autenticazione VPN
Rapid7 MDR ha documentato due ondate di sfruttamento attivo di CVE-2026-0257, un bypass dell'autenticazione GlobalProtect di Palo Alto Networks. Gli attaccanti forgiano cookie validi usando la chiave pubblica TLS dell'appliance, ottenendo accesso VPN senza credenziali. Un PoC pubblico è già disponibile e la vulnerabilità è nella CISA KEV. -
CVE-2026-0257: Palo Alto GlobalProtect sotto attacco — cookies bypassano l’autenticazione VPN
Rapid7 MDR ha documentato due ondate di sfruttamento attivo di CVE-2026-0257, un bypass dell'autenticazione GlobalProtect di Palo Alto Networks. Gli attaccanti forgiano cookie validi usando la chiave pubblica TLS dell'appliance, ottenendo accesso VPN senza credenziali. Un PoC pubblico è già disponibile e la vulnerabilità è nella CISA KEV. -
https://www.europesays.com/ch-fr/131467/ Noyau Linux : la chaîne d’exploitation « dirty frag » ouvre un accès root sur les serveurs non patchés #CERTFR #CISAKEV #Cve202631431 #Cve202643284 #Cve202643500 #DirtyFrag #ElévationDePrivilèges #LinuxKernel #NIS2 #Science #ScienceAndTechnology #Sciences #SciencesEtTechnologies #Suisse #Technologies #Technology #vulnérabilité
-
Third-party ecosystems are structurally exposed.
Black Kite’s 2026 report reframes supply chain cyber risk from “weakest link” theory to concentration dynamics.Key systemic indicators:
• 5.28 downstream victims per breach (2025 average)
• 10-day median detection vs. 73-day median disclosure
• 53%+ organizations with at least one critical vulnerability
• 23%+ with corporate credentials exposedTop 50 shared vendors:
– 70% KEV exposure
– 84% CVSS ≥ 8
– 62% stealer-log credential presence
– 52% breach historyShared infrastructure nodes are now strategic attack surfaces.
Security teams must shift toward:
Dependency mapping
Concentration analytics
Active intelligence monitoring
Exposure propagation modeling
Is your organization modeling systemic fragility — or auditing in isolation?Engage below.
Follow TechNadu for advanced infosec, vendor risk, and threat intelligence coverage.#Infosec #ThirdPartyRisk #VendorSecurity #ThreatIntelligence #CISAKEV #CyberExposure #Ransomware #SupplyChainSecurity #SecurityEngineering #CyberResilience #RiskAnalytics
-
Third-party ecosystems are structurally exposed.
Black Kite’s 2026 report reframes supply chain cyber risk from “weakest link” theory to concentration dynamics.Key systemic indicators:
• 5.28 downstream victims per breach (2025 average)
• 10-day median detection vs. 73-day median disclosure
• 53%+ organizations with at least one critical vulnerability
• 23%+ with corporate credentials exposedTop 50 shared vendors:
– 70% KEV exposure
– 84% CVSS ≥ 8
– 62% stealer-log credential presence
– 52% breach historyShared infrastructure nodes are now strategic attack surfaces.
Security teams must shift toward:
Dependency mapping
Concentration analytics
Active intelligence monitoring
Exposure propagation modeling
Is your organization modeling systemic fragility — or auditing in isolation?Engage below.
Follow TechNadu for advanced infosec, vendor risk, and threat intelligence coverage.#Infosec #ThirdPartyRisk #VendorSecurity #ThreatIntelligence #CISAKEV #CyberExposure #Ransomware #SupplyChainSecurity #SecurityEngineering #CyberResilience #RiskAnalytics
-
Third-party ecosystems are structurally exposed.
Black Kite’s 2026 report reframes supply chain cyber risk from “weakest link” theory to concentration dynamics.Key systemic indicators:
• 5.28 downstream victims per breach (2025 average)
• 10-day median detection vs. 73-day median disclosure
• 53%+ organizations with at least one critical vulnerability
• 23%+ with corporate credentials exposedTop 50 shared vendors:
– 70% KEV exposure
– 84% CVSS ≥ 8
– 62% stealer-log credential presence
– 52% breach historyShared infrastructure nodes are now strategic attack surfaces.
Security teams must shift toward:
Dependency mapping
Concentration analytics
Active intelligence monitoring
Exposure propagation modeling
Is your organization modeling systemic fragility — or auditing in isolation?Engage below.
Follow TechNadu for advanced infosec, vendor risk, and threat intelligence coverage.#Infosec #ThirdPartyRisk #VendorSecurity #ThreatIntelligence #CISAKEV #CyberExposure #Ransomware #SupplyChainSecurity #SecurityEngineering #CyberResilience #RiskAnalytics
-
Third-party ecosystems are structurally exposed.
Black Kite’s 2026 report reframes supply chain cyber risk from “weakest link” theory to concentration dynamics.Key systemic indicators:
• 5.28 downstream victims per breach (2025 average)
• 10-day median detection vs. 73-day median disclosure
• 53%+ organizations with at least one critical vulnerability
• 23%+ with corporate credentials exposedTop 50 shared vendors:
– 70% KEV exposure
– 84% CVSS ≥ 8
– 62% stealer-log credential presence
– 52% breach historyShared infrastructure nodes are now strategic attack surfaces.
Security teams must shift toward:
Dependency mapping
Concentration analytics
Active intelligence monitoring
Exposure propagation modeling
Is your organization modeling systemic fragility — or auditing in isolation?Engage below.
Follow TechNadu for advanced infosec, vendor risk, and threat intelligence coverage.#Infosec #ThirdPartyRisk #VendorSecurity #ThreatIntelligence #CISAKEV #CyberExposure #Ransomware #SupplyChainSecurity #SecurityEngineering #CyberResilience #RiskAnalytics
-
CISA Silently Updates Vulnerabilities Exploited by Ransomware Groups https://thecyberexpress.com/vulnerabilities-exploited-by-ransomware-groups/ #FortinetVulnerability #Ivantivulnerability #TheCyberExpressNews #ThreatIntelligence #paloaltonetworks #ransomwareattack #TheCyberExpress #Vulnerabilities #FirewallDaily #cybersecurity #CyberThreats #cyberattacks #Ransomware #CyberNews #Microsoft #CISAKEV #CISA
-
CISA Silently Updates Vulnerabilities Exploited by Ransomware Groups https://thecyberexpress.com/vulnerabilities-exploited-by-ransomware-groups/ #FortinetVulnerability #Ivantivulnerability #TheCyberExpressNews #ThreatIntelligence #paloaltonetworks #ransomwareattack #TheCyberExpress #Vulnerabilities #FirewallDaily #cybersecurity #CyberThreats #cyberattacks #Ransomware #CyberNews #Microsoft #CISAKEV #CISA
-
CISA Silently Updates Vulnerabilities Exploited by Ransomware Groups https://thecyberexpress.com/vulnerabilities-exploited-by-ransomware-groups/ #FortinetVulnerability #Ivantivulnerability #TheCyberExpressNews #ThreatIntelligence #paloaltonetworks #ransomwareattack #TheCyberExpress #Vulnerabilities #FirewallDaily #cybersecurity #CyberThreats #cyberattacks #Ransomware #CyberNews #Microsoft #CISAKEV #CISA
-
CISA Silently Updates Vulnerabilities Exploited by Ransomware Groups https://thecyberexpress.com/vulnerabilities-exploited-by-ransomware-groups/ #FortinetVulnerability #Ivantivulnerability #TheCyberExpressNews #ThreatIntelligence #paloaltonetworks #ransomwareattack #TheCyberExpress #Vulnerabilities #FirewallDaily #cybersecurity #CyberThreats #cyberattacks #Ransomware #CyberNews #Microsoft #CISAKEV #CISA
-
🚨 Microsoft’s January 2026 Patch Tuesday dropped 114 fixes—including a CISA KEV-listed Windows zero-day.
Full Weekly Cybersecurity Brief available here.
#PatchTuesday #Cybersecurity #WindowsVulnerability #CISAKEV #CVE
-
CISA Closes 10 Emergency Directives as Vulnerability Catalog Takes Over https://www.securityweek.com/cisa-closes-10-emergency-directives-as-vulnerability-catalog-takes-over/ #Vulnerabilities #vulnerability #Featured #CISAKEV #CISA
-
CISA Closes 10 Emergency Directives as Vulnerability Catalog Takes Over https://www.securityweek.com/cisa-closes-10-emergency-directives-as-vulnerability-catalog-takes-over/ #Vulnerabilities #vulnerability #Featured #CISAKEV #CISA
-
CISA Closes 10 Emergency Directives as Vulnerability Catalog Takes Over https://www.securityweek.com/cisa-closes-10-emergency-directives-as-vulnerability-catalog-takes-over/ #Vulnerabilities #vulnerability #Featured #CISAKEV #CISA
-
CISA Closes 10 Emergency Directives as Vulnerability Catalog Takes Over https://www.securityweek.com/cisa-closes-10-emergency-directives-as-vulnerability-catalog-takes-over/ #Vulnerabilities #vulnerability #Featured #CISAKEV #CISA
-
Critical HPE OneView Vulnerability Exploited in Attacks https://www.securityweek.com/critical-hpe-oneview-vulnerability-exploited-in-attacks/ #Vulnerabilities #vulnerability #HPEOneView #exploited #Featured #CISAKEV #HPE
-
Critical HPE OneView Vulnerability Exploited in Attacks https://www.securityweek.com/critical-hpe-oneview-vulnerability-exploited-in-attacks/ #Vulnerabilities #vulnerability #HPEOneView #exploited #Featured #CISAKEV #HPE
-
Critical HPE OneView Vulnerability Exploited in Attacks https://www.securityweek.com/critical-hpe-oneview-vulnerability-exploited-in-attacks/ #Vulnerabilities #vulnerability #HPEOneView #exploited #Featured #CISAKEV #HPE
-
Critical HPE OneView Vulnerability Exploited in Attacks https://www.securityweek.com/critical-hpe-oneview-vulnerability-exploited-in-attacks/ #Vulnerabilities #vulnerability #HPEOneView #exploited #Featured #CISAKEV #HPE
-
CISA Known Exploited Vulnerabilities Soared 20% in 2025 https://thecyberexpress.com/cisa-known-exploited-vulnerabilities-kev-2025/ #KnownexploitedvulnerabilitiesCISA #TheCyberExpressNews #ransomwareattack #Vulnerabilities #TheCyberExpress #FirewallDaily #cybersecurity #Vulnerability #CyberThreats #Ransomware #CyberNews #CISAKEV #cyble #CISA
-
CISA Known Exploited Vulnerabilities Soared 20% in 2025 https://thecyberexpress.com/cisa-known-exploited-vulnerabilities-kev-2025/ #KnownexploitedvulnerabilitiesCISA #TheCyberExpressNews #ransomwareattack #Vulnerabilities #TheCyberExpress #FirewallDaily #cybersecurity #Vulnerability #CyberThreats #Ransomware #CyberNews #CISAKEV #cyble #CISA
-
CISA Known Exploited Vulnerabilities Soared 20% in 2025 https://thecyberexpress.com/cisa-known-exploited-vulnerabilities-kev-2025/ #KnownexploitedvulnerabilitiesCISA #TheCyberExpressNews #ransomwareattack #Vulnerabilities #TheCyberExpress #FirewallDaily #cybersecurity #Vulnerability #CyberThreats #Ransomware #CyberNews #CISAKEV #cyble #CISA
-
CISA Known Exploited Vulnerabilities Soared 20% in 2025 https://thecyberexpress.com/cisa-known-exploited-vulnerabilities-kev-2025/ #KnownexploitedvulnerabilitiesCISA #TheCyberExpressNews #ransomwareattack #Vulnerabilities #TheCyberExpress #FirewallDaily #cybersecurity #Vulnerability #CyberThreats #Ransomware #CyberNews #CISAKEV #cyble #CISA
-
CISA KEV Catalog Expanded 20% in 2025, Topping 1,480 Entries https://www.securityweek.com/cisa-kev-catalog-expanded-20-in-2025-topping-1480-entries/ #Vulnerabilities #vulnerability #CISAKEV #CISA
-
CISA KEV Catalog Expanded 20% in 2025, Topping 1,480 Entries https://www.securityweek.com/cisa-kev-catalog-expanded-20-in-2025-topping-1480-entries/ #Vulnerabilities #vulnerability #CISAKEV #CISA
-
CISA KEV Catalog Expanded 20% in 2025, Topping 1,480 Entries https://www.securityweek.com/cisa-kev-catalog-expanded-20-in-2025-topping-1480-entries/ #Vulnerabilities #vulnerability #CISAKEV #CISA
-
CISA KEV Catalog Expanded 20% in 2025, Topping 1,480 Entries https://www.securityweek.com/cisa-kev-catalog-expanded-20-in-2025-topping-1480-entries/ #Vulnerabilities #vulnerability #CISAKEV #CISA
-
CISA Warns of Exploited Flaw in Asus Update Tool https://www.securityweek.com/cisa-warns-of-exploited-flaw-in-asus-update-tool/ #Vulnerabilities #vulnerability #exploited #CISAKEV #Asus
-
CISA Warns of Exploited Flaw in Asus Update Tool https://www.securityweek.com/cisa-warns-of-exploited-flaw-in-asus-update-tool/ #Vulnerabilities #vulnerability #exploited #CISAKEV #Asus
-
CISA Warns of Exploited Flaw in Asus Update Tool https://www.securityweek.com/cisa-warns-of-exploited-flaw-in-asus-update-tool/ #Vulnerabilities #vulnerability #exploited #CISAKEV #Asus
-
CISA Warns of Exploited Flaw in Asus Update Tool https://www.securityweek.com/cisa-warns-of-exploited-flaw-in-asus-update-tool/ #Vulnerabilities #vulnerability #exploited #CISAKEV #Asus
-
CISA Warns of ScadaBR Vulnerability After Hacktivist ICS Attack https://www.securityweek.com/cisa-warns-of-scadabr-vulnerability-after-hacktivist-ics-attack/ #Vulnerabilities #vulnerability #exploited #Featured #CISAKEV #OpenPLC #ScadaBR #ICS/OT #HMI #ICS #OT
-
CISA Warns of ScadaBR Vulnerability After Hacktivist ICS Attack https://www.securityweek.com/cisa-warns-of-scadabr-vulnerability-after-hacktivist-ics-attack/ #Vulnerabilities #vulnerability #exploited #Featured #CISAKEV #OpenPLC #ScadaBR #ICS/OT #HMI #ICS #OT