NINJA SIGNAL
DEFCON··LOW

TODAY

GitLab and Cisco Firewall auth bypasses actively exploited — patch now.

THE THREE

  1. #1 · CVE-2026-85706

    Gitlab

    KEV

    What: Any organization running GitLab (self-hosted CE or EE) is exposed — an unauthenticated attacker can read arbitrary files from your repositories via the API, meaning source code, secrets, and credentials are at risk without any login required. With a 93% exploit probability and active exploitation confirmed, this is being hit right now.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 93% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply GitLab's patch or block unauthenticated access to the commits API immediately.

  2. #2 · CVE-2026-20079

    Cisco

    KEV

    What: If your organization uses Cisco Firewall Management Center or Cisco Security Cloud Control to manage your firewalls, an attacker on the internet can bypass authentication entirely and take control — effectively owning your firewall policy without a password. This is a perfect target for ransomware operators seeking network-wide access.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply Cisco's patch or restrict FMC/SCC management access to trusted IPs only.

  3. #3 · CVE-2026-81578

    Papercut

    KEV

    What: Organizations using PaperCut NG or MF for print management face an unauthenticated attacker being able to change system configurations remotely, and this flaw chains directly with CVE-2026-82078 below for full remote code execution. PaperCut has been a ransomware favorite before — this is a high-priority fix.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 85% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Patch PaperCut NG/MF to the latest version and restrict server access to internal networks.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
12M
Relationships
67M
Threat actors
240
Indicators
936k
Feeds live
19
Sources total
21

Ingest paused — figures are the last-good snapshot, not live.

ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.