Daily Brief

Ransomware crews now target TeamCity — patch your build server

Ransomware crews now target TeamCity — patch your build server

CISA says ransomware crews now exploit TeamCity CVE-2026-63077. Upgrade to 2025.11.7 or 2026.1.3, take the server off the Internet, and check for compromise.

Old Roundcube webmail bug now exploited — update this week

Old Roundcube webmail bug now exploited — update this week

A pre-auth SQL injection in Roundcube's virtuser_query plugin is now exploited. Update to 1.6.16 or 1.7.1 or disable the plugin. Here's what to check today.

One cPanel account can own the whole server — patch today

One cPanel account can own the whole server — patch today

A cPanel CalDAV/CardDAV flaw lets any hosting account run code as root. Update to 11.134.0.57, 11.136.0.41 or 11.138.0.8, plus WP Toolkit 6.11.3, today.

Your GitLab issue-email address can push code — rotate it today

Your GitLab issue-email address can push code — rotate it today

GitLab's issue-by-email address carries an account-wide token that can push code and run CI jobs past IP allowlists. How to rotate it and check for misuse.

Friday’s brief: TeamCity ransomware, then Roundcube, cPanel, GitLab

Friday’s brief: TeamCity ransomware, then Roundcube, cPanel, GitLab

Friday's 5-minute cyber brief: ransomware on TeamCity build servers, exploited Roundcube webmail, cPanel root for any account, and a risky GitLab email token.

WordPress under active attack — patch Core before Friday

WordPress under active attack — patch Core before Friday

Attackers went from probing to writing PHP in under a day. Verify you’re on a fixed release....

Tomcat WebSocket lock can be walked around — check yours this week

Tomcat WebSocket lock can be walked around — check yours this week

If auth sits in a Tomcat security constraint, an alternate endpoint name can skip it....

Palo Alto says HIGHEST urgency — root risk on PA-Series firewalls

Palo Alto says HIGHEST urgency — root risk on PA-Series firewalls

No known exploit yet — that’s the window, not a reason to wait....

SAP’s CVSS 10 kernel bug now has public PoCs — patch Internet-facing first

SAP’s CVSS 10 kernel bug now has public PoCs — patch Internet-facing first

Shared kernel, pre-auth, PoCs out. Role checks won’t save you....

Thursday’s brief: WordPress under fire, then Tomcat, Palo Alto, SAP

Thursday’s brief: WordPress under fire, then Tomcat, Palo Alto, SAP

WordPress under active exploitation, Tomcat WebSocket bypass, Palo Alto HIGHEST urgency, SAP OVERPASS with public PoCs....

Arista VeloCloud CVE-2026-93952: On-Prem Orchestrator CVSS 10 — KEV Due September 25

Arista VeloCloud CVE-2026-93952: On-Prem Orchestrator CVSS 10 — KEV Due September 25

Actively exploited CVSS 10 on on-prem VCO. Hosted patched; on-prem needs fixed builds and an IoC hunt....

Chromium V8 CVE-2026-87491: Out-of-Bounds Write Exploited — KEV Due Today (September 23)

Chromium V8 CVE-2026-87491: Out-of-Bounds Write Exploited — KEV Due Today (September 23)

In-the-wild V8 write; Chrome 153.0.8010.36/.37 fixes it. Federal KEV due is today — verify Edge and other Chromium browsers too....

The 5-Minute Cyber Brief: September 23, 2026

The 5-Minute Cyber Brief: September 23, 2026

Check Point VPN+mgmt KEV due Friday, F5 APM OAuth RCE, Arista VeloCloud CVSS 10, Chromium V8 due today....