NINJA SIGNAL
DEFCON··LOW

TODAY

GitLab and Cisco Firewall auth bypasses under active attack — patch now.

THE THREE

  1. #1 · CVE-2026-85706

    Gitlab

    KEV

    What: Any unauthenticated person on the internet can read arbitrary files from your GitLab server — including source code, secrets, and credentials — with no login required. With a 91% exploit probability and a perfect CVSS 10, this is as dangerous as it gets for dev teams.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 91% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Patch GitLab CE/EE to the latest fixed version immediately.

  2. #2 · CVE-2026-20079

    Cisco

    KEV

    What: Attackers can completely bypass authentication on Cisco Firewall Management Center and Security Cloud Control, potentially taking over your firewall policy and opening your network to anything they want. This is a remote, no-credentials-needed attack on the device meant to protect everything else.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply Cisco's patch for FMC/SCC and restrict management access to trusted IPs.

  3. #3 · CVE-2026-8037

    Progress

    KEV

    What: Progress LoadMaster load balancers can be fully compromised by an unauthenticated attacker who can run any command on the appliance — putting all traffic it handles at risk of interception or manipulation. This has been actively exploited for nearly two months.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 77% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Update Progress LoadMaster firmware to the vendor-patched version now.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
12M
Relationships
67M
Threat actors
239
Indicators
922k
Feeds live
19
Sources total
21
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.