NINJA SIGNAL
DEFCON··LOW

TODAY

GitLab and Cisco firewall auth bypasses under active attack — patch now.

THE THREE

  1. #1 · CVE-2026-85706

    Gitlab

    KEV

    What: Any unauthenticated attacker on the internet can read arbitrary files from your GitLab server — including source code, secrets, and credentials — without logging in. With a 93% exploit probability and active exploitation confirmed, this is a high-priority target for data theft and supply chain attacks.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 93% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Update GitLab CE/EE to the latest patched version immediately.

  2. #2 · CVE-2026-20079

    Cisco

    KEV

    What: Attackers can completely bypass authentication on Cisco Firewall Management Center and Security Cloud Control, meaning your firewall policy and network defenses could be read or altered by anyone on the internet. This is a full perimeter compromise risk.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply Cisco's patch for FMC/SCC and restrict management interface access to trusted IPs.

  3. #3 · CVE-2026-81578

    Papercut

    KEV

    What: PaperCut NG/MF print management servers — common in schools, hospitals, and offices — can be reconfigured by unauthenticated remote attackers, and this flaw chains with a second vulnerability for deeper compromise. Ransomware groups have historically targeted PaperCut heavily.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 85% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Patch PaperCut NG/MF to the latest version and block external access to the admin port.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
12M
Relationships
67M
Threat actors
242
Indicators
961k
Feeds live
20
Sources total
24
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.