NINJA SIGNAL
DEFCON··GUARDED

TODAY

Ancient Apache and FTP flaws freshly KEV-listed — patch now.

THE THREE

  1. #1 · CVE-2016-3081

    Apache

    KEV

    What: If your organization runs Apache Struts with Dynamic Method Invocation enabled — common in older Java web apps — attackers can remotely execute code on your server with a 93% exploit probability, and this was KEV-listed just 1 day ago. This is the same class of flaw that enabled the Equifax breach.

    Why it moved: Actively exploited · KEV-listed this week · Everyone runs this · 93% exploit odds · New this week

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Disable Dynamic Method Invocation in Struts or upgrade to a patched version immediately.

  2. #2 · CVE-2026-85706

    Gitlab

    KEV

    What: Any organization running GitLab (self-hosted CE or EE) is exposed to an unauthenticated attacker reading arbitrary files from your repositories — source code, secrets, credentials — no login required. CVSS 10.0 with 93% exploit odds makes this a near-certain target.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 93% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply GitLab's patch for CVE-2026-85706 or restrict repository API access at the network perimeter.

  3. #3 · CVE-2026-20079

    Cisco

    KEV

    What: Attackers can completely bypass authentication on Cisco Secure Firewall Management Center and Security Cloud Control, potentially taking over your firewall policy — meaning they could open your network wide open without your knowledge.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply Cisco's patch immediately and restrict FMC/SCC management interfaces to trusted IPs only.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
12M
Relationships
67M
Threat actors
242
Indicators
969k
Feeds live
20
Sources total
24
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.