Ransomware Actors Weaponize Palo Alto GlobalProtect Authentication Bypass for Stealthy VPN Access Palo Alto GlobalProtect CVE-2026-0257 is being exploited by Qilin and Settra ransomware actors. Check affected PAN-OS… https://thecybersecguru.com/news/cve-2026-0257-globalprotect-vpn-ransomware/
CVE Firehose
by @cyfar.ca
The vulnerability firehose for Bluesky. CVEs as they drop, KEV additions, PoCs, patch Tuesday chaos, and zero-day disclosures — all in one chronological feed. Curated by @pigondrugs.
PoC released for Zammad Session Leak Flaw enabling Remote Code Execution: cybersecuritynews.com/poc-released...
Pentest-Windows — Collection of Windows internals research and exploitation techniques covering privilege escalation, token abuse, and post-exploitation tricks for red teamers and pentesters. https://ktp.sh/YFjwyKxMau
ReliaQuest says Qilin and Settra are using a Palo Alto Networks authentication bypass to access corporate networks.… https://en.hacks.gr/reliaquest-qilin-kai-settra-ferontai-na-mpainoyn-se-etairika-diktya-meso-globalprotect-choris-stoicheia-syndesis/ #PaloAltoNetworks #GlobalProtect #PrismaAccess
🔴 CVE-2026-104803 - Critical (9.8) The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up t... https://www.thehackerwire.com/vulnerability/CVE-2026-104803/ #infosec #cybersecurity #CVE #vulnerability #security #patchstack
NetScaler admins get more patch homework 😬 Citrix reports a new critical vulnerability, CVE-2026-107406, with a CVSS v4.0 score of 9.5, affecting NetScaler ADC and Gateway via SAML.
Unquoted Windows service paths can enable privilege escalation to SYSTEM. Windows may try `C:\Program.exe` before the intended executable. An unquoted path alone isn't a vulnerability. Check whether users can write to an earlier path location. The path is the lead. Write access is the finding.
🟠 CVE-2026-91136 - High (7.5) The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and in... https://www.thehackerwire.com/vulnerability/CVE-2026-91136/ #infosec #cybersecurity #CVE #vulnerability #security #patchstack