NINJA SIGNAL
DEFCON··ELEVATED

TODAY

GitLab and Cisco firewall auth bypasses actively exploited — patch now.

THE THREE

  1. #1 · CVE-2026-85706

    Gitlab

    KEV

    What: Any organization running GitLab — even self-hosted — is exposed: an unauthenticated attacker can read any file on your GitLab server via the repository API, meaning source code, secrets, and credentials are at immediate risk. With a 91% exploit probability and CVSS 10.0, this is being hit in the wild right now.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 91% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply GitLab's latest security patch immediately and block unauthenticated external access to the API.

  2. #2 · CVE-2026-20079

    Cisco

    KEV

    What: If your organization uses Cisco Secure Firewall Management Center or Cisco Security Cloud Control, an attacker on the internet can bypass authentication entirely and take control of your firewall management plane — effectively owning your network perimeter without a single credential. CVSS 10.0 and actively exploited.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply Cisco's security advisory patch for FMC/SCC and restrict management interface access to trusted IPs only.

  3. #3 · CVE-2026-8037

    Progress

    KEV

    What: Progress LoadMaster is a widely used load balancer, and this unauthenticated command injection flaw lets attackers run arbitrary OS commands on the appliance — a fast path to network pivoting or ransomware staging. It has been actively exploited for over seven weeks.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 77% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Update Progress LoadMaster to the patched version and disable public-facing management interfaces immediately.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
12M
Relationships
67M
Threat actors
238
Indicators
914k
Feeds live
19
Sources total
21
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.