Citrix confirms two NetScaler RCE zero-days exploited before any patch existed: CVE-2026-88771 and CVE-2026-88772 (CVSS 9.5). One hits default configs. Patching won't evict an attacker already inside. Hunt for compromise, rotate secrets, then update. #ZeroDay#InfoSec#Citrix
CISA patch deadline hits today: CVE-2026-5430 (WSO2, CVSS 9.8, path traversal to unauth RCE) and CVE-2026-71362 (Adobe Commerce, session takeover). watchTowr logged in-the-wild exploitation since Sept 13. Federal mandate or not, this one is on the clock. #InfoSec#CISA#KEV
Cisco ISE zero-day CVE-2026-76460 is a CVSS 10.0 auth bypass giving root via an unauthenticated API call. Exploited in the wild, no workaround, and CISA federal patch deadline is Sept 19. If ISE brokers your network access, patch tonight. #ZeroDay#InfoSec#Cisco
CISA added CVE-2026-87902 to KEV on Sept 25: unauthenticated remote file inclusion in WordPress Core, leading to RCE, exploited in the wild. Federal deadline Sept 28, forensic triage required. This is core, not a plugin. Patch now. #InfoSec#WordPress#CISA
Cisco ISE zero-day CVE-2026-76460 is a CVSS 10.0 auth bypass giving root via an unauthenticated API call. Exploited in the wild, no workaround, and CISA federal patch deadline is Sept 19. If ISE brokers your network access, patch tonight. #ZeroDay#InfoSec#Cisco
Proofpoint: UNK_CondorFiltration sprayed 5,700+ accounts across 28 Microsoft 365 tenants from 1,487 AWS EC2 IPs. Only 7 fell, and every one was a forgotten service account with a default password and no MFA. Non-human identities are the soft edge. #InfoSec#IAM#M365
Cisco ISE zero-day CVE-2026-76460 is a CVSS 10.0 auth bypass giving root via an unauthenticated API call. Exploited in the wild, no workaround, and CISA federal patch deadline is Sept 19. If ISE brokers your network access, patch tonight. #ZeroDay#InfoSec#Cisco
Cisco ISE zero-day CVE-2026-76460 is a CVSS 10.0 auth bypass giving root via an unauthenticated API call. Exploited in the wild, no workaround, and CISA federal patch deadline is Sept 19. If ISE brokers your network access, patch tonight. #ZeroDay#InfoSec#Cisco
Gyazo: 23.62M user records plus 490M image metadata entries stolen via an image-upload server flaw. Exposed data includes password hashes and X integration tokens, so the blast radius extends past Gyazo. Rotate every OAuth token you granted it. #Cybersecurity#DataBreach
Cisco ISE zero-day CVE-2026-76460 is a CVSS 10.0 auth bypass giving root via an unauthenticated API call. Exploited in the wild, no workaround, and CISA federal patch deadline is Sept 19. If ISE brokers your network access, patch tonight. #ZeroDay#InfoSec#Cisco
BragJack: one unvetted browser extension hijacked the built-in AI agents in Chrome, Edge, Opera Neon, Comet and Claude in Chrome. No prompt injection needed, it crossed straight into the agent's privileged channel. CVE-2026-0628 and CVE-2026-55945 patched. #InfoSec#AISecurity
Cisco ISE zero-day CVE-2026-76460 is a CVSS 10.0 auth bypass giving root via an unauthenticated API call. Exploited in the wild, no workaround, and CISA federal patch deadline is Sept 19. If ISE brokers your network access, patch tonight. #ZeroDay#InfoSec#Cisco
Cisco ISE zero-day CVE-2026-76460 is a CVSS 10.0 auth bypass giving root via an unauthenticated API call. Exploited in the wild, no workaround, and CISA federal patch deadline is Sept 19. If ISE brokers your network access, patch tonight. #ZeroDay#InfoSec#Cisco
F5 Labs logged ~32,000 scans against internet-exposed Vite dev servers in August, 19x the prior three months combined. CVE-2026-39364 lets unauthenticated attackers pull .env files, AWS keys and terraform.tfstate. Patch to 7.3.2 or 8.0.5, then rotate. #Cybersecurity#DevSecOps
CVE-2026-76461: one crafted email gets an attacker root on Cisco Secure Email Gateway. CVSS 9.8, exploited in the wild, no workaround. CISA set a Sept 17 federal patch deadline. Cisco warns attackers can scrub the IoCs, so audit logs off-box. #InfoSec#ZeroDay#Cisco
Wiz: attackers chained CVE-2026-42018 + CVE-2026-42016 to mint admin tokens on self-hosted JFrog Artifactory, then planted a Rust backdoor via malicious Groovy plugins. Exploited Aug 15 to Sep 8. Patches already existed. Now in CISA KEV. #SupplyChain#DevSecOps#InfoSec
CVE-2026-20079: CVSS 10.0 auth bypass in Cisco Secure FMC. Talos confirms a Sandworm-linked actor and Qilin ransomware operators both exploiting it for root. CISA's federal patch deadline passed Sept 12. Internet-facing FMC? Assume compromise. #InfoSec#Ransomware#CISAKEV
CVE-2026-20079: CVSS 10.0 auth bypass in Cisco Secure FMC. Talos confirms a Sandworm-linked actor and Qilin ransomware operators both exploiting it for root. CISA's federal patch deadline passed Sept 12. Internet-facing FMC? Assume compromise. #InfoSec#Ransomware#CISAKEV
CISA federal patch deadline for CVE-2026-20079 (Cisco Secure FMC, CVSS 10.0) is today. Talos confirms 3 exploitation clusters, state-sponsored and ransomware, dropping web shells for root. Citrix NetScaler and FortiOS flaws share the same deadline. #InfoSec#KEV#Cybersecurity
CISA federal patch deadline for CVE-2026-20079 (Cisco Secure FMC, CVSS 10.0) is today. Talos confirms 3 exploitation clusters, state-sponsored and ransomware, dropping web shells for root. Citrix NetScaler and FortiOS flaws share the same deadline. #InfoSec#KEV#Cybersecurity