George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.
Arista VeloCloud CVE-2026-93952: On-Prem Orchestrator CVSS 10 — KEV Due September 25

Arista VeloCloud CVE-2026-93952: On-Prem Orchestrator CVSS 10 — KEV Due September 25

Actively exploited CVSS 10 on on-prem VCO. Hosted patched; on-prem needs fixed builds and an IoC hunt....

Check Point CVE-2026-85102 / 93616: VPN Gateway RCE + Management Zero-Day — KEV Due September 25

Check Point CVE-2026-85102 / 93616: VPN Gateway RCE + Management Zero-Day — KEV Due September 25

CISA added two Check Point CVSS 9.8s to KEV yesterday. Federal due September 25 — patch gateways and management Jumbo…

Zyxel GS1900 CVE-2026-7273: Unauth LAN Stack Overflow to OS Commands — KEV Due September 24

Zyxel GS1900 CVE-2026-7273: Unauth LAN Stack Overflow to OS Commands — KEV Due September 24

CISA added the GS1900 CGI stack overflow to KEV yesterday. Federal due September 24 — patch, lock management VLANs, triage....

Ivanti Neurons for ITSM: Unauth Deserialization RCE Pair (CVE-2026-12744 / 12745)

Ivanti Neurons for ITSM: Unauth Deserialization RCE Pair (CVE-2026-12744 / 12745)

Two CVSS 9.8 unauth deserialization bugs on the ITSM brain. On-prem needs September updates or 2026.2+....

The 5-Minute Cyber Brief: September 22, 2026

The 5-Minute Cyber Brief: September 22, 2026

Zyxel GS1900 KEV due Thursday, Ivanti Neurons unauth RCE, Linux LPE quartet, Windows Update Stack due today....

Windows Update Stack CVE-2026-81963: Federal KEV Due Today (September 22)

Windows Update Stack CVE-2026-81963: Federal KEV Due Today (September 22)

Link-following Update Stack EoP to SYSTEM — federal due today. Verify September cumulatives actually landed....

Linux LPE Quartet: DirtyAH6, TUNderflow, PPPoEject, DiagSpill — Patch Beyond Monday’s KEV

Linux LPE Quartet: DirtyAH6, TUNderflow, PPPoEject, DiagSpill — Patch Beyond Monday’s KEV

Four more local-root bugs disclosed September 18 — different from Monday’s KEV trio. Confirm your kernel covers all four....

CrowdSec: Departed Employee’s Live GitHub Access → ~170 Private Repos Cloned

CrowdSec: Departed Employee’s Live GitHub Access → ~170 Private Repos Cloned

TanStack credential theft plus retained ex-employee GitHub access cloned ~170 private repos....

Orkes Conductor CVE-2026-58138: Pre-Auth RCE via Unsandboxed Workflow Scripts

Orkes Conductor CVE-2026-58138: Pre-Auth RCE via Unsandboxed Workflow Scripts

Pre-auth INLINE scripts escape GraalVM. Fortinet is blocking thousands of attempts — upgrade to 3.30.2+....

Linux Kernel KEV Trio: kTLS, ebtables, AF_ALG — Federal Due September 21

Linux Kernel KEV Trio: kTLS, ebtables, AF_ALG — Federal Due September 21

CISA's three exploited Linux kernel bugs are due today. Patch, reboot, then triage....

SolarWinds Access Rights Manager CVE-2026-28326: Hard-Coded Key to Unauth RCE

SolarWinds Access Rights Manager CVE-2026-28326: Hard-Coded Key to Unauth RCE

Hard-coded static key yields unauthenticated RCE on ARM ≤2026.2. Ship 2026.2.1....

The 5-Minute Cyber Brief: September 21, 2026

The 5-Minute Cyber Brief: September 21, 2026

Monday reboot-and-revoke brief: Linux kernel KEV trio due today, Orkes Conductor RCE, SolarWinds ARM, CrowdSec offboarding....

The 5-Minute Cyber Brief: September 18, 2026

The 5-Minute Cyber Brief: September 18, 2026

Friday clock stories: Cisco ISE root bypass due Saturday, Acronis hosting LPE, MikroTik MikroTrick, Check Point management root....