Cybersecurity

Fortinet FortiOS CVE-2025-25249: CAPWAP Heap Overflow to PivotC2 RAT

Fortinet FortiOS CVE-2025-25249: CAPWAP Heap Overflow to PivotC2 RAT

Unauthenticated CAPWAP overflow abused to deploy PivotC2 on FortiGate. Upgrade FortiOS and rotate harvested secrets....

Cisco Secure FMC CVE-2026-20079: Auth Bypass to Root — Patch ≠ Clean

Cisco Secure FMC CVE-2026-20079: Auth Bypass to Root — Patch ≠ Clean

CVSS 10 FMC authentication bypass confirmed exploited by nation-state and ransomware clusters. Hotfix now; TAC if IoCs hit....

The 5-Minute Cyber Brief: September 16, 2026

The 5-Minute Cyber Brief: September 16, 2026

Wednesday brief: vCenter ransomware, Magento StyleSmuggler, FortiGate PivotC2, and Cisco FMC root bypass....

The 5-Minute Cyber Brief: September 15, 2026

The 5-Minute Cyber Brief: September 15, 2026

Cisco email gateway root RCE due Wednesday, Sogou one-click to GRAYRABBIT, Windows ALPC SYSTEM zero-day, and F5 PoisonedRefresh fileless webshell....

F5 BIG-IP APM PoisonedRefresh: Fileless PHP Web Shell After CVE-2025-53521 — Patch ≠ Clean

F5 BIG-IP APM PoisonedRefresh: Fileless PHP Web Shell After CVE-2025-53521 — Patch ≠ Clean

PoisonedRefresh injects a PHP webshell into BIG-IP APM memory after CVE-2025-53521. Patching alone does not remove the implant....

Windows ALPC Heap Overflow CVE-2026-85880: AppContainer to SYSTEM Zero-Day (Not the Update Stack Bug)

Windows ALPC Heap Overflow CVE-2026-85880: AppContainer to SYSTEM Zero-Day (Not the Update Stack Bug)

CVE-2026-85880 is an exploited Windows ALPC heap overflow to SYSTEM — separate from Update Stack CVE-2026-81963. KEV due September 22....

UNC3569 / Sogou Input Method CVE-2026-51990: One-Click RCE to GRAYRABBIT

UNC3569 / Sogou Input Method CVE-2026-51990: One-Click RCE to GRAYRABBIT

Gen Digital observed UNC3569 exploiting CVE-2026-51990 in Sogou Input Method to deploy GRAYRABBIT. Fix ≥ 16.3.0.3498....

Cisco Secure Email Gateway CVE-2026-76461: Unauth SQL Injection to Root — KEV Due Wednesday

Cisco Secure Email Gateway CVE-2026-76461: Unauth SQL Injection to Root — KEV Due Wednesday

CVE-2026-76461: unauthenticated SQL injection in Cisco AsyncOS email parsing escalates to root. CISA KEV due September 17, 2026. Fixed AsyncOS…

GitLab CVE-2026-85706: One Request, No Login, Your Secrets on Disk — Patch Deadline Is Today

GitLab CVE-2026-85706: One Request, No Login, Your Secrets on Disk — Patch Deadline Is Today

Self-hosted GitLab: one unauthenticated commits-API request can read secrets on disk. Federal due date is today....

ConnectWise ScreenConnect CVE-2026-84869: Guest Session, Host Compromise — KEV Due Today

ConnectWise ScreenConnect CVE-2026-84869: Guest Session, Host Compromise — KEV Due Today

A ScreenConnect client bug can transfer and run files on the host without confirmation. Due today....

Chrome CVE-2026-87491: Google’s Seventh Exploited Zero-Day of 2026 — Update to 153

Chrome CVE-2026-87491: Google’s Seventh Exploited Zero-Day of 2026 — Update to 153

Google patched a V8 bug already exploited in the wild. Chrome 153 is the floor....

WatchGuard Firebox CVE-2025-14733: CISA Flags Ransomware Use on a Stubborn Edge RCE

WatchGuard Firebox CVE-2025-14733: CISA Flags Ransomware Use on a Stubborn Edge RCE

CISA marked the WatchGuard Firebox RCE as known ransomware campaign use. Patch the edge....

The 5-Minute Cyber Brief: September 14, 2026

The 5-Minute Cyber Brief: September 14, 2026

Monday due dates: GitLab file-read, ScreenConnect client, Chrome’s seventh 2026 zero-day, WatchGuard ransomware flag....