Install
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
The Chain That Opened the Crisis: How SonicWall SMA1000’s First Zero-Day Turned VPN Appliances Into MFA Harvesting Machines
19+ min ago (129+ words) CVE-2026-15409 chained SSRF and code injection to achieve root on SMA1000 appliances, stealing TOTP MFA seeds and turning the VPN gateway into a persistent surveillance platform. CISA flagged it for ransomware exploitation. We covered the second chain but never the first…...
Cybersecurity briefly – 20260911 – MICROWIRE.news APAC
1+ hour, 41+ min ago (366+ words) Here are some weekly APAC cybersecurity snippets that you might find interesting. As an aviator, this news struck me. On September 10, Vietnam suffered a data breach when cybersecurity researchers found over 220 million flight records of passengers and crew available on…...
Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited
2+ hour, 19+ min ago (1419+ words) Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zero trust AI agents demand a different kind of security In this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust principles…...
Code Hidden In 'White-Labeled' Routers Gives Chinese Servers Full Control - BGR
11+ hour, 3+ min ago (501+ words) Code Hidden In 'White-Labeled' Routers Gives Chinese Servers Full Control bgr.com Code Hidden In 'White-Labeled' Routers Gives Chinese Servers Full Control The last few years have seen Western legislators repeatedly push back against Chinese apps and devices, citing national…...
CyberDefenders Write-up: Oski Category: Threat Intel | Tools: VirusTotal, ANY.RUN
19+ min ago (28+ words) Scenario The accountant at the company received an email titled “Urgent New Order” from a client late in the …...
Check Point VPN CVE-2026-85102 and CVE-2026-85103: Early Warning for Pre-Authentication RCE
7+ hour, 42+ min ago (1541+ words) 1. Basic Information Original Title: Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent Source: BleepingComputer, Dutch NCSC, Check Point Published Date: 2026-09-12 Severity: High Basis for Severity: Both CVSS 9.8 vulnerabilities allow unauthenticated remote code execution. Although the reference materials do…...
Portal Drop — TryHackMe Write Up
5+ hour ago (786+ words) A spoiler free SOC investigation using web access logs EDR telemetry and MITRE ATTACK By Emir Kılıçer A WAF alert reports a scan against a public CRM portal …...
Dissecting the “Mammoth” PhaaS Framework: From SaaS Hijacking to Real-Time Socket C2 and Financial…
7+ hour, 59+ min ago (23+ words) Dissecting the “Mammoth” PhaaS Framework: From SaaS Hijacking to Real-Time Socket C2 and Financial Profiling Threat actors targeting European peer-to-peer e-commerce platforms (specifically …...
Dutch NCSC says Check Point VPN flaw exploitation is imminent – 4sysops
15+ hour, 52+ min ago (25+ words) The Dutch NCSC now expects attackers to target two critical Check Point VPN flaws soon, despite no public proof-of-concept exploit. The warning raises the urgen...
Why “Claimable” Doesn’t Always Mean “Exploitable”: A Subdomain Takeover That Wasn’t
13+ hour, 22+ min ago (150+ words) A dangling CNAME, a claimable Mailgun domain, and a rejection that taught me more than an acceptance would have. Subdomain takeover checklists all say some version of the same thing: find a CNAME pointing to a service, confirm the target…...