NINJA SIGNAL
DEFCON··ELEVATED

TODAY

Ancient Apache and FTP bugs resurface — patch or get owned now.

THE THREE

  1. #1 · CVE-2016-3081

    Apache

    KEV

    What: If your organization runs Apache Struts with Dynamic Method Invocation enabled, attackers can execute any code they want on your server — this 10-year-old bug was just added to CISA's must-patch list 2 days ago with a 95% exploit probability, meaning active attacks are near-certain. Web apps built on older Struts versions are the primary target, and compromise typically leads to full server takeover or ransomware deployment.

    Why it moved: Actively exploited · KEV-listed this week · Everyone runs this · 95% exploit odds · New this week

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Disable Dynamic Method Invocation in Struts or upgrade past 2.3.28 immediately.

  2. #2 · CVE-2026-85706

    Gitlab

    KEV

    What: Any unauthenticated person on the internet can read arbitrary files from your GitLab server — source code, secrets, credentials — without logging in at all. This is a CVSS 10.0 actively exploited vulnerability that puts your entire codebase and any secrets stored in repos at risk of theft.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 93% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply GitLab's patch for CVE-2026-85706 and restrict repository API access externally.

  3. #3 · CVE-2026-20079

    Cisco

    KEV

    What: Attackers can bypass authentication entirely on Cisco Firewall Management Center and Security Cloud Control, meaning your firewall management plane — the thing controlling your network defenses — can be accessed and modified by anyone without a password. A compromised FMC lets attackers silently rewrite firewall rules across your entire environment.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply Cisco's patch for CVE-2026-20079 and isolate FMC management interfaces from the internet.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
12M
Relationships
67M
Threat actors
242
Indicators
972k
Feeds live
20
Sources total
24
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.