#securityops — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #securityops, aggregated by home.social.
-
🔵 THREAT INTELLIGENCE
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
Vulnerability | CRITICAL
CVEs: CVE-2026-63077A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the...
Full analysis:
https://www.yazoul.net/news/article/cisa-flags-teamcity-cve-2026-63077-rce-flaw-under-active-exploitation-in-the-wilby Yazoul AI
-
🔵 THREAT INTELLIGENCE
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
Vulnerability | CRITICAL
CVEs: CVE-2026-20316Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was...
Full analysis:
https://www.yazoul.net/news/article/cisco-fmc-zero-day-actively-exploited-static-credentials-could-expose-sensitive- -
🔵 THREAT INTELLIGENCE
Critical wp2shell WordPress flaws exploited to install webshells
Vulnerability | CRITICAL
CVEs: CVE-2026-60137, CVE-2026-63030Hackers are exploiting the 'wp2shell' critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent...
Full analysis:
https://www.yazoul.net/news/article/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells -
CRITICAL: Integrate app security scanner data with exposure management to counter rising risk from AI-driven code deployments 🚀 Siloed data slows remediation. No specific CVE or product. Boost visibility & risk context. https://radar.offseq.com/threat/5-reasons-to-bring-application-security-data-into--d632db8ee16c6296 #OffSeq #AppSec #SecurityOps
-
🔵 THREAT INTELLIGENCE
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
Vulnerability | CRITICAL
CVEs: CVE-2026-48939The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity security flaws impacting iCagenda and Balbooa...
Full analysis:
https://www.yazoul.net/news/article/icagenda-and-balbooa-forms-joomla-flaws-reportedly-exploited-as-zero-days -
🔵 THREAT INTELLIGENCE
Weekly Threat Roundup: 2026-06-29 to 2026-07-05
Roundup | CRITICAL
CVEs: CVE-2026-58138Cybersecurity roundup for 2026-06-29 to 2026-07-05. 1 CVE advisories, 1 breach reports, 3 threat news stories.
Full analysis:
https://www.yazoul.net/news/article/2026-w27-weekly-threat-roundup -
🔵 THREAT INTELLIGENCE
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
Vulnerability | CRITICAL
CVEs: CVE-2026-45659CISA warned on Wednesday that attackers have begun exploiting a high-severity Microsoft SharePoint remote code execution vulnerability patched in...
Full analysis:
https://www.yazoul.net/news/article/sharepoint-rce-cve-2026-45659-added-to-cisa-kev-after-active-exploitation -
🔵 THREAT INTELLIGENCE
Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw
Vulnerability | CRITICAL
CVEs: CVE-2026-20262Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in...
Full analysis:
https://www.yazoul.net/news/article/cisco-releases-security-updates-for-actively-exploited-sd-wan-manager-flaw -
🔵 THREAT INTELLIGENCE
CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog Amid Active Exploitation
Vulnerability | CRITICAL
CVEs: CVE-2026-20245The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added three new vulnerabilities to its Known Exploited Vulnerabilities...
Full analysis:
https://www.yazoul.net/news/article/cisa-adds-cisco-chrome-and-arista-flaws-to-kev-catalog-amid-active-exploitation -
🔹 THREAT INTELLIGENCE
Weekly Threat Roundup: 2026-06-01 to 2026-06-07
Roundup | HIGH
CVEs: CVE-2025-48595, CVE-2026-28318Cybersecurity roundup for 2026-06-01 to 2026-06-07. 2 CVE advisories, 4 breach reports, 4 threat news stories.
Full analysis:
https://www.yazoul.net/news/article/2026-w23-weekly-threat-roundup -
🔵 THREAT INTELLIGENCE
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
Vulnerability | CRITICAL
CVEs: CVE-2026-45247The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular...
Full analysis:
https://www.yazoul.net/news/article/cisa-adds-exploited-magento-rce-flaw-cve-2026-45247-to-kev-catalog -
🚨 THREAT INTELLIGENCE
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
Vulnerability | CRITICAL
CVEs: CVE-2026-0257Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active...
Full analysis:
https://www.yazoul.net/news/article/pan-os-globalprotect-authentication-bypass-cve-2026-0257-under-active-exploitati -
🟡 THREAT INTELLIGENCE
CISA Announces Revised Town Hall Schedule to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure
Vulnerability | MEDIUM
Full analysis:
https://www.yazoul.net/news/article/cisa-announces-revised-town-hall-schedule-to-engage-with-stakeholders-on-cyber-i -
🔵 THREAT INTELLIGENCE
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV
Vulnerability | CRITICAL
CVEs: CVE-2026-9082Drupal is warning that hackers are attempting to exploit a 'highly critical' SQL injection vulnerability announced earlier this week. [...]
Full analysis:
https://www.yazoul.net/news/article/drupal-core-sql-injection-bug-actively-exploited-added-to-cisa-kev -
🔵 THREAT INTELLIGENCE
Cisco Catalyst SD-WAN Controller Auth Bypass Actively Exploited to Gain Admin Access
Vulnerability | CRITICAL
CVEs: CVE-2026-20182Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day...
Full analysis:
https://www.yazoul.net/news/article/cisco-catalyst-sd-wan-controller-auth-bypass-actively-exploited-to-gain-admin-ac -
In January 2026, a malicious actor accessed France's national bank account registry using a stolen civil servant credential.
1.2 million accounts. 3 weeks of undetected access ^ no vulnerability exploited.
Everything was permitted. Every control saw what it expected.
The anomaly was the behavior - query volume and scope inconsistent with any normal workflow.
Authentication monitoring couldn't catch it. Only behavioral monitoring could.
gethumming.io
#ITDR #IVIP #IdentitySecurity #SecurityOps -
🔵 THREAT INTELLIGENCE
Weekly Threat Roundup: 2026-05-04 to 2026-05-10
Roundup | CRITICAL
CVEs: CVE-2026-0300, CVE-2026-33587, CVE-2026-40281Cybersecurity roundup for 2026-05-04 to 2026-05-10. 10 CVE advisories, 5 breach reports, 4 threat news stories.
Full analysis:
https://www.yazoul.net/news/article/2026-w19-weekly-threat-roundup -
Your SOC is drowning in alerts. Your team is 15 people. They're spread across six continents and responding from satellites.
They aren't failing because they stopped using LLMs for threat modeling.
Energy-Based Models responds as energy landscapes—not the next text string. Governed by TAME principles: Tested, Auditable, Measurable, Explainable. Court-admissible evidence in 47 seconds.
Watch it live: https://securesql.info/2026/05/01/infosecblueprints/
#SecurityOps #IncidentResponse #CyberSecurityAI #SentinelMesh
-
⚡ THREAT INTELLIGENCE
Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution
Vulnerability | MEDIUM
Palo Alto Networks warned customers today that a critical-severity unpatched vulnerability in the PAN-OS User-ID Authentication Portal is being...
Full analysis:
https://www.yazoul.net/news/article/palo-alto-pan-os-flaw-under-active-exploitation-enables-remote-code-execution -
Enterprise Strategy Group says the average enterprise spends 11 person-hours investigating a single critical identity alert.
Not 11 minutes. 11 hours.
Attackers move laterally in minutes. and the gap between those two speeds is where system damage accumulates.
Auth Sentry's AI Analysis performs every investigation automatically & delivers real, actionable results.
Average time: under 2 minutes.Try it free for 7 days:
gethumming.io/how-it-works
#ITDR #IVIP #IdentitySecurity #SecurityOps -
🔵 THREAT INTELLIGENCE
CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
Vulnerability | CRITICAL
CVEs: CVE-2026-31431The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a recently disclosed security flaw impacting various Linux...
Full analysis:
https://www.yazoul.net/news/article/cisa-adds-actively-exploited-linux-root-access-bug-cve-2026-31431-to-kev -
Formation Hackfest 2026: Formation Cloud Pragmatique & Security Ops
C'est un bootcamp opérationnel où chaque minute compte.
Vous ne repartez pas avec des concepts abstraits — mais avec une infrastructure qui tourne, une sécurité qui protège, et la capacité d'intervenir comme une SWAT team sur n'importe quel incident Azure. -
Formation Hackfest 2026: Formation Cloud Pragmatique & Security Ops
C'est un bootcamp opérationnel où chaque minute compte.
Vous ne repartez pas avec des concepts abstraits — mais avec une infrastructure qui tourne, une sécurité qui protège, et la capacité d'intervenir comme une SWAT team sur n'importe quel incident Azure. -
Detection gaps aren’t about visibility. They’re about judgment.
"Machines also cannot infer intentionality."
If attackers operate within normal behavior, most detections won’t trigger.https://www.technadu.com/when-detection-fails-quietly-what-are-teams-really-chasing/627185/
-
⚡ THREAT INTELLIGENCE
Chinese Silk Typhoon Hacker Extradited to U.S. Over COVID Research Cyberattacks
Vulnerability | MEDIUM
A Chinese national accused of carrying out cyberespionage operations for China's intelligence services has been extradited from Italy to the United...
Full analysis:
https://www.yazoul.net/news/article/chinese-silk-typhoon-hacker-extradited-to-u-s-over-covid-research-cyberattacks -
🔵 THREAT INTELLIGENCE
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline
Vulnerability | CRITICAL
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities impacting SimpleHelp, Samsung MagicINFO 9...
Full analysis:
https://www.yazoul.net/news/article/cisa-adds-4-exploited-flaws-to-kev-sets-may-2026-federal-deadline -
⚡ THREAT INTELLIGENCE
CISA, National Cyber Security Centre (NCSC) UK, and Global Partners Issue Advisory on Chinese Government-Linked Covert Cyber Networks
Vulnerability | MEDIUM
Full analysis:
https://www.yazoul.net/news/article/cisa-national-cyber-security-centre-ncsc-uk-and-global-partners-issue-advisory-o -
AI agents are executing actions - not just responding.
“The real exposure is at the agent layer.”
• Prompt injection = social engineering for AI
• Zero-click attacks can trigger system actions
• No visibility into downstream executionFull interview:
https://www.technadu.com/ai-observability-what-defenders-need-when-systems-execute-what-they-read-and-act-without-input/626769/ -
AI agents are executing actions - not just responding.
“The real exposure is at the agent layer.”
• Prompt injection = social engineering for AI
• Zero-click attacks can trigger system actions
• No visibility into downstream executionFull interview:
https://www.technadu.com/ai-observability-what-defenders-need-when-systems-execute-what-they-read-and-act-without-input/626769/ -
How many identities does your organization actually have?
Not your IdP headcount - identities across every provider, OAuth grants, every account that can authenticate somewhere.3 problem layers:
Multi-provider sprawl: no single IdP shows the full picture
OAuth grant accumulation: persistent, often forgotten, often broad
Unconnected apps: legacy systems with no IdP connection at allAuth Sentry Monitor covers layers 1 & 2 free.
gethumming.io/monitor
#ITDR #IdentitySecurity #IVIP #SecurityOps -
🔵 THREAT INTELLIGENCE
CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
Vulnerability | CRITICAL
CVEs: CVE-2023-27351The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known Exploited Vulnerabilities...
Full analysis:
https://www.yazoul.net/news/news/cisa-adds-8-exploited-flaws-to-kev-sets-april-may-2026-federal-deadlines -
One system says 10:02.
Another says 9:58.
The firewall says 10:05.Welcome to incident response if your clocks aren’t synchronized.
New article: The Silent Risk of Inconsistent Time Synchronization
https://jimguckin.com/2026/03/04/the-silent-risk-of-inconsistent-time-synchronization/
-
A breach is not only a security issue. It is an operations issue. #IBM puts the average at $4.4M. The practical lesson for 2026 is to automate the basics: identity hygiene, alert triage, and response runbooks so teams contain faster and spend less.
#Cybersecurity #SecurityOps #Automation #RiskManagement #MSP
-
🚨 NEW BLOG POST 🚨
"The Breaking Point: Why Cybersecurity and SOC Professionals Are Burning Out—And What Actually Works"
Nearly half of cybersecurity professionals experience moderate to severe burnout. 65% of SOC analysts have seriously considered leaving. But here's the thing: it's not a resilience problem. It's a design problem.
I've written a comprehensive breakdown of:
✓ Why the 10,000+ daily alerts trap is unsustainable
✓ How 24/7 shifts destroy sleep and performance
✓ Why compensation alone won't fix retention
✓ Practical solutions: fatigue management, alert rationalization, career paths, and organizational cultureThis isn't about yoga classes and "self-care." It's about fixing the structural issues that burn through talent faster than the industry can train replacements.
Read the full post with research-backed strategies for both individuals and organizational leaders:
#Cybersecurity #SOC #Burnout #MentalHealth #InfoSec #SecurityOps #CareerDevelopment #Workforce
-
👾 Digital Threats Don’t Knock — They Breach.
Most companies patch holes.
Hacktivate Labs builds digital shields before the attack even happens.🧠 Your firewall isn’t your defense.
Your people are. Train them like operators — not employees.The next workforce won’t just use AI…
They’ll secure it, fortify it, and harden every endpoint in the network.⚠️ If your team isn’t security-trained —
your infrastructure is already exposed.This is your warning shot.
Welcome to the era of cyber intelligence.#HacktivateLabs #SecurityOps #NetworkSecurity #AIIntegrity #CyberWorkforce #KillTheBreach
-
AI is becoming central to security operations. Let's talk about why. 👇
AI-assisted workflows are on the rise. ⬆️ And, when an algorithm highlights a critical #security event, analysts need to understand why that happened. Without true visibility, this #AI assistance risks creating new blind spots and hiding important context, rather than leading to a solution. 😓
To make sense of the constant overflow of alerts, you need AI capabilities that are built into workflows that you already use, like:
☑️ Behavioral detection
☑️ Risk-based prioritization
☑️ Investigation summaries
☑️ Smarter dashboards and searchLearn how you can leverage these important AI capabilities and stay in control while using tools that accelerate detection, streamline investigations, and strengthen your reporting: https://graylog.org/post/how-graylog-uses-explainable-ai-to-help-security-teams/ #cybersecurity #securityops #security #securityanalyst
-
A comprehensive look at EDR systems' inner workings and the real-world tactics employed to circumvent them. Essential information for professionals involved in security operations and threat analysis.
Grounded in tested techniques—not speculation—and focused on practical tradecraft.
-
Drowning in CISA advisories? Tines has a free workflow automating monitoring, enrichment (CrowdStrike), & ticketing (ServiceNow) via Slack approvals. Cut manual tasks by 60% & keep analysts focused.
#SecurityOps #Automation #InfoSec -
⚡️ Turkish-trained Gorgor Commando forces in Somalia carry out planned operations in Mudug region, targeting Al-Shabaab bases. The militants fled as troops conducted a cleanup operation, with ongoing pursuit of fleeing militants. The mission aims to eliminate Al-Shabaab presence in Galmudug. #SecurityOps #Counterterrorism https://www.riskmap.com/incidents/1937676/articles/195645551/?utm_source=dlvr.it&utm_medium=mastodon
-
⚡️ Troops of Nigerian Army arrest 10 suspects involved in kidnapping and cultism during operations in Edo and Bayelsa. Raid on a cultists' camp in Ogbia LGA, Bayelsa leads to the arrest of 8 members, recovery of weapons & drugs. In Edo, troops rescue a kidnap victim, arrest 2 suspects with firearms and fetish items. Suspects undergoing interrogation, victim reunited with family. #SecurityOps #AntiKidnapping #Cultism https://www.riskmap.com/incidents/1935932/articles/195400969/?utm_source=dlvr.it&utm_medium=mastodon