NINJA SIGNAL
DEFCON··ELEVATED

TODAY

GitLab and Cisco Firewall auth bypasses under active attack — patch now.

THE THREE

  1. #1 · CVE-2026-85706

    Gitlab

    KEV

    What: Any organization running GitLab (self-hosted or cloud-managed) is at risk — an unauthenticated attacker can read any file on your server through the repository API, meaning source code, credentials, and secrets can be stolen without logging in. With a 91% probability of exploitation, this is being actively targeted right now.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 91% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Upgrade GitLab to the latest patched release immediately.

  2. #2 · CVE-2026-20079

    Cisco

    KEV

    What: If your organization uses Cisco Firewall Management Center or Cisco Security Cloud Control to manage your firewalls, an attacker on the internet can completely bypass login and take control — effectively owning your entire firewall policy and network perimeter. This is as bad as it gets for network security.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply Cisco's patch for FMC and SCC now; isolate management interfaces in the meantime.

  3. #3 · CVE-2026-8037

    Progress

    KEV

    What: Progress LoadMaster is a widely used load balancer appliance, and this flaw lets an unauthenticated attacker run any command on the device — meaning full appliance takeover and potential access to all traffic flowing through it. It has been exploited in the wild for nearly two months.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 77% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Patch Progress LoadMaster to the latest version and restrict management interface access.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
12M
Relationships
67M
Threat actors
238
Indicators
912k
Feeds live
19
Sources total
21
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.