NINJA SIGNAL
DEFCON··GUARDED

TODAY

GitLab and Cisco firewall auth bypasses under active attack — patch now.

THE THREE

  1. #1 · CVE-2026-85706

    Gitlab

    KEV

    What: Any unauthenticated person on the internet can read arbitrary files from your GitLab server — including source code, secrets, and credentials — with no login required. This is a CVSS 10 with a 93% chance of exploit and is actively being abused.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 93% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply GitLab's patch immediately; block unauthenticated access to the repository commits API at the perimeter if patching is delayed.

  2. #2 · CVE-2026-20079

    Cisco

    KEV

    What: Attackers can completely bypass authentication on Cisco Firewall Management Center and Security Cloud Control, meaning they can reconfigure or disable your firewall without any credentials. A compromised firewall manager puts your entire network perimeter at risk.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Patch Cisco FMC and SCC to the fixed version immediately, or restrict management interface access to trusted IPs only.

  3. #3 · CVE-2026-81578

    Papercut

    KEV

    What: PaperCut NG/MF print servers can be reconfigured by anyone on the network without logging in, and this flaw chains directly with CVE-2026-82078 for full remote code execution. PaperCut is common in schools, hospitals, and offices — high-value ransomware targets.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 85% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Patch PaperCut NG/MF now and block external access to the admin interface at the firewall.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
12M
Relationships
67M
Threat actors
240
Indicators
933k
Feeds live
19
Sources total
21
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.