EU Cybersecurity Incident Response Gaps Exposed

EU Cybersecurity Incident Response Gaps Exposed

A new European Court of Auditors report finds serious EU cybersecurity incident response gaps at the very top of the escalation ladder: no EU member state has ever formally classified a cyber incident as “large-scale,” the tier that triggers cross-border EU crisis coordination, since that classification system existed from 2016. Not WannaCry. Not NotPetya. Not…

Read More

F5 BIG-IP APM RCE Vulnerability Exploited

F5 BIG-IP APM RCE vulnerability

F5 has confirmed active, unauthenticated exploitation of a critical F5 BIG-IP APM RCE vulnerability, tracked as CVE-2026-94127 (CVSS 9.8), affecting Access Policy Manager instances configured as OAuth Authorization Servers. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day F5 disclosed it, September 22, and gave federal agencies until Friday, September 25…

Read More

WatchGuard Firebox Ransomware Exploitation

WatchGuard Firebox ransomware exploitation is now confirmed by CISA. A December patch still leaves ~125,000 devices exposed. Patch and rotate now.

WatchGuard Firebox ransomware exploitation is now officially confirmed. CISA updated its Known Exploited Vulnerabilities catalog entry for CVE-2025-14733 on September 10, 2026, to reflect that ransomware gangs, not just opportunistic access brokers, are actively weaponizing a firewall flaw that has had a public patch available since December 2025. What Happened CVE-2025-14733 is an out-of-bounds write…

Read More

Cisco ISE Authentication Bypass Vulnerability Hits Root

A Cisco ISE authentication bypass vulnerability (CVSS 10.0) lets attackers reach root with no credentials. Active exploitation confirmed. Patch now.

A Cisco ISE authentication bypass vulnerability tracked as CVE-2026-76460 carries a perfect CVSS score of 10.0 and is already under active exploitation. An unauthenticated attacker can bypass Cisco Identity Services Engine’s web-based management interface entirely and, per Cisco’s own advisory, reach command execution as root. That is the one system in your network built to…

Read More

GitLab Path Traversal Vulnerability: Patch Now

A critical GitLab path traversal vulnerability lets attackers read any file from self-managed servers with no login. Active exploitation confirmed.

A critical GitLab path traversal vulnerability, CVE-2026-85706 (CVSS 10.0), lets an unauthenticated attacker read any file off a self-managed GitLab server, including credentials, deploy keys, and CI/CD configuration. GitLab shipped a patch on September 10; CISA added the flaw to its Known Exploited Vulnerabilities catalog the next day, and BSI issued its own warning on…

Read More