NINJA SIGNAL
DEFCON··GUARDED

TODAY

GitLab and Cisco firewall auth bypasses under active attack — patch now.

THE THREE

  1. #1 · CVE-2026-85706

    Gitlab

    KEV

    What: Any unauthenticated attacker can read arbitrary files from your GitLab server — including source code, secrets, and credentials — without logging in at all. With a 93% exploit probability and active exploitation confirmed, exposed GitLab instances are being hit right now.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 93% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply GitLab's latest security patch or block unauthenticated access to the repository commits API immediately.

  2. #2 · CVE-2026-20079

    Cisco

    KEV

    What: Attackers can completely bypass authentication on Cisco Firewall Management Center and Security Cloud Control, meaning your firewall policies and network controls could be altered or read by anyone on the internet. This is a perfect entry point for ransomware or espionage.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Patch Cisco FMC and SCC to the vendor-fixed version or restrict management interface access to trusted IPs only.

  3. #3 · CVE-2026-81578

    Papercut

    KEV

    What: An unauthenticated attacker can change system configurations on your PaperCut print management server, and when chained with CVE-2026-82078 (also listed today), this leads to full remote code execution. PaperCut is common in schools, offices, and healthcare.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 85% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Update PaperCut NG/MF to the patched version and restrict server access to internal networks only.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
12M
Relationships
67M
Threat actors
242
Indicators
944k
Feeds live
19
Sources total
21
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.