NINJA SIGNAL
DEFCON··LOW

TODAY

GitLab and Cisco Firewall auth bypasses under active attack — patch now.

THE THREE

  1. #1 · CVE-2026-85706

    Gitlab

    KEV

    What: Any organization running GitLab (self-hosted) is at risk — an attacker with no credentials can read any file on your GitLab server through the repository API, potentially exposing source code, secrets, and credentials. With a 93% exploit probability and CVSS 10.0, this is as dangerous as it gets.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 93% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Patch GitLab CE/EE to the latest fixed version immediately.

  2. #2 · CVE-2026-20079

    Cisco

    KEV

    What: If your organization uses Cisco Firewall Management Center or Cisco Security Cloud Control, an attacker on the internet can bypass login entirely and take control of your firewall management plane — effectively owning your network perimeter. This is actively exploited with an 88% exploit probability.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply Cisco's security patch for FMC/SCC and restrict management access to trusted IPs.

  3. #3 · CVE-2026-81578

    Papercut

    KEV

    What: PaperCut NG/MF print management software — common in schools, universities, and offices — can be remotely reconfigured by anyone without logging in, and chaining this with a second flaw (CVE-2026-82078) can lead to full system compromise. Ransomware groups have historically targeted PaperCut heavily.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 85% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Update PaperCut NG/MF to the latest patched version right now.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
12M
Relationships
67M
Threat actors
242
Indicators
964k
Feeds live
20
Sources total
24
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.