Follow the cybersecurity developments that matter, explained in about five minutes each weekday.
Attackers went from probing to writing PHP in under a day. Verify you’re on a fixed release....
If auth sits in a Tomcat security constraint, an alternate endpoint name can skip it....
No known exploit yet — that’s the window, not a reason to wait....
Shared kernel, pre-auth, PoCs out. Role checks won’t save you....
WordPress under active exploitation, Tomcat WebSocket bypass, Palo Alto HIGHEST urgency, SAP OVERPASS with public PoCs....
CISA added two Check Point CVSS 9.8s to KEV yesterday. Federal due September 25 — patch gateways and management Jumbo…
Unauth data-plane RCE when a VIP has both APM and an OAuth profile. Hotfixes and interim iRule out; federal due…
Actively exploited CVSS 10 on on-prem VCO. Hosted patched; on-prem needs fixed builds and an IoC hunt....
In-the-wild V8 write; Chrome 153.0.8010.36/.37 fixes it. Federal KEV due is today — verify Edge and other Chromium browsers too....
Check Point VPN+mgmt KEV due Friday, F5 APM OAuth RCE, Arista VeloCloud CVSS 10, Chromium V8 due today....
CISA added the GS1900 CGI stack overflow to KEV yesterday. Federal due September 24 — patch, lock management VLANs, triage....
Two CVSS 9.8 unauth deserialization bugs on the ITSM brain. On-prem needs September updates or 2026.2+....
Four more local-root bugs disclosed September 18 — different from Monday’s KEV trio. Confirm your kernel covers all four....