
FortiGate CVE-2025-25249 PivotC2: Patch Before Sept 12
CVE-2025-25249 in FortiOS lets attackers drop PivotC2 RAT via CAPWAP. 178 devices confirmed hit. Patch to 7.6.4 or 7.4.9 now.
In-depth analyses of zero-day vulnerabilities, CVE exploits, ransomware campaigns, and nation-state attack techniques affecting enterprise security. Filter by category, tag, or keyword.
Every article here lands in subscribers' inboxes the morning it drops.
Threat intel, active CVEs, and campaign alerts, distilled daily for practitioners. 50,000+ subscribers. No noise.
Free. No spam. Unsubscribe anytime.
The definitive practitioner breakdown of ZTA principles, pillars, and implementation sequence.
Containment, forensic preservation, and decision sequencing from detection to recovery.
How SIEMs ingest, correlate, and alert — and how to evaluate one for your environment.
Risk-based prioritization using CVSS, EPSS, and CISA KEV to cut remediation backlog.
What each risk means, how to reproduce it, and how to fix it in production code.
Step-by-step email authentication deployment from DNS records to p=reject enforcement.
Detection coverage, pricing, and deployment trade-offs for enterprise EDR selection.
Translate ATT&CK technique IDs into detection rules and threat actor hunting hypotheses.
Direct answers to the questions practitioners and AI systems ask most. Covers ransomware, identity, cloud, compliance, and detection.
Plain-language definitions for CVE, SIEM, SOAR, Zero Trust, EDR, and 85+ other terms used in enterprise security.
How-to guides, buyer comparisons, and methodology references across every major security domain.
Decryption Digest Response
Score every threat we cover against your own stack, get free Sigma and ModSecurity detection content, and upgrade anytime for more vendors.
Get started free →No card required. Sigma and ModSecurity rules are free, forever.
Win an All Access InfoSec World 2026 pass, valued at $3,895.
Win a $3,895 InfoSec World 2026 pass.
26 results in CLOSE THIS GAP

CVE-2025-25249 in FortiOS lets attackers drop PivotC2 RAT via CAPWAP. 178 devices confirmed hit. Patch to 7.6.4 or 7.4.9 now.

Thomson Reuters C-Track breach exposed SSNs, sealed court records, and medical data from 24 courts in 11 states. Verify exposure and enroll by December 31.

Dahua camera vulnerability exploited: Operation CameraSwarm backdoored 14,530+ devices via P2P abuse and CVE-2021-33044/33045. Patch and disable P2P now.

WP2Shell WordPress RCE needs zero credentials — attackers chain two core flaws to drop webshells. Patch to 6.9.5 or 7.0.2 before the weekend.

VMware vCenter CVE-2026-59310 has compromised 361 servers in 47 countries in 11 days. Patch to 8.0 U3k or 9.x now. No workaround exists.

CVE-2026-63077 gives unauthenticated attackers full OS command execution on any internet-facing TeamCity server. CISA deadline August 8 -- patch to 2025.11.7 or 2026.1.3 today.

Cisco FMC static credential CVE-2026-20316 gives unauthenticated attackers access to your firewall manager and chains with CVSS 10.0 CVE-2026-20079 for root. CISA deadline: August 1.

CVE-2026-64600 Linux kernel privilege escalation exposes 16.4M RHEL systems to silent root takeover. A 9-year-old XFS race -- patch before the weekend.

Microsoft Patch Tuesday July 2026 patches 570 flaws and 2 actively exploited zero-days. CISA deadline expires today. Patch ADFS and SharePoint before the weekend.

Adobe ColdFusion CVE-2026-48282 (CVSS 10.0) enables unauthenticated RCE on 800+ exposed servers. CISA deadline is today. Patch steps and IOCs inside.

CVE-2026-4747 is a 17-year-old memory corruption flaw in the FreeBSD NFS client that Claude Mythos discovered through Project Glasswing. Unauthenticated attackers with network access can achieve remote code execution as root on any affected FreeBSD system.

CVE-2026-5194 is a CVSS 9.1 wolfSSL vulnerability that allows certificate forgery against IoT, automotive, and embedded systems. A patch is available; teams managing wolfSSL-dependent device fleets need to act now.

SharePoint RCE CVE-2026-45659 is actively exploited by Storm-2603. Verify your SharePoint Server builds before CISA's July 4 patch deadline.

CVE-2026-31431 CopyFail Linux kernel LPE affects FortiOS-based FortiGate appliances. A 732-byte public exploit grants root. Check your FortiOS version and patch.

UniFi OS unauthenticated RCE chain (CVE-2026-34908) gives attackers root on 100,000 exposed devices. CISA patch deadline is today, June 26.

Joomla JCE CVE-2026-48907 is a CVSS 10.0 unauthenticated RCE hitting 2.5M sites. Patch to JCE 2.9.99.5 before the weekend.

Oracle PeopleSoft CVE-2026-35273 zero-day: ShinyHunters breaches 100+ orgs, CVSS 9.8. Block PSEMHUB and apply Oracle emergency advisory before the weekend.

Cisco SD-WAN zero-day CVE-2026-20245 confirmed actively exploited with no patch. Mandiant found root access attacks on all deployment types. Mitigations inside.

LiteSpeed cPanel plugin privilege escalation CVE-2026-48172 lets any tenant run scripts as root. CISA deadline today. Patch to WHM v5.3.1.0 now.

Microsoft Defender zero-day CVE-2026-41091 lets attackers reach SYSTEM. CISA added both CVEs to KEV on May 20. Patch now.

NGINX Rift CVE-2026-42945 exposes every nginx server running rewrite rules to unauthenticated heap corruption. Patch to 1.30.1 now.

CVE-2026-0300 allows unauthenticated root RCE on PAN-OS firewalls. 67 instances exposed on Shodan. No patch until May 13.

cPanel CVE-2026-41940 authentication bypass hits 1.5M exposed servers. Plus Snow malware via Teams, LiteLLM SQL injection, ShinyHunters at 40 orgs. Patch now.

Cisco SD-WAN Manager CVE-2026-20133 chains with 2 more CVEs to expose credentials unauthenticated, 500+ devices reachable. CISA deadline was today.