NINJA SIGNAL
DEFCON··ELEVATED

TODAY

Ancient Apache and FTP bugs resurface with near-certain exploit odds.

THE THREE

  1. #1 · CVE-2016-3081

    Apache

    KEV

    What: If your organization runs Apache Struts with Dynamic Method Invocation enabled, attackers can remotely execute any code they want — this is the same class of flaw behind major breaches. With a 96% exploit probability and added to CISA's Known-Exploited list just three days ago, active attacks are essentially guaranteed.

    Why it moved: Actively exploited · KEV-listed this week · Everyone runs this · 96% exploit odds · New this week

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Disable Dynamic Method Invocation in Apache Struts or upgrade immediately.

  2. #2 · CVE-2026-85706

    Gitlab

    KEV

    What: Any unauthenticated person on the internet can read arbitrary files from your GitLab instance — including source code, secrets, and credentials — without logging in. This is a perfect score (CVSS 10.0) actively exploited vulnerability affecting both Community and Enterprise editions.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 93% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply GitLab's patch now and restrict repository API access externally.

  3. #3 · CVE-2026-20079

    Cisco

    KEV

    What: Attackers can completely bypass authentication on Cisco Firewall Management Center and Security Cloud Control, meaning your firewall rules and network security posture can be read or altered by anyone with network access. This is a CVSS 10.0 flaw being actively exploited.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 88% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Patch Cisco FMC and SCC immediately; restrict management interfaces to trusted IPs.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
12M
Relationships
67M
Threat actors
242
Indicators
974k
Feeds live
20
Sources total
24
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.