Defused

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) 2026-07-22 at 14:47 By Zeljka Zorz Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, […]

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) Read More »

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) 2026-07-20 at 17:32 By Zeljka Zorz Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) Read More »

Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)

Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) 2026-06-30 at 16:58 By Zeljka Zorz Exploitation attempts targeting a critical vulnerability (CVE-2026-46817) in Oracle Payments, the payment-processing module within Oracle’s E-Business Suite (EBS), have been spotted over the weekend, threat intelligence company Defused warned on Monday. The detected exploitation attempts (Source: Defused) “On 27 June 2026

Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) Read More »

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) 2026-06-24 at 14:36 By Zeljka Zorz CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. “Our honeypots are seeing automated sweeps dropping webshells, all

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) Read More »

Attackers are exploiting FortiSandbox vulnerabilities

Attackers are exploiting FortiSandbox vulnerabilities 2026-06-16 at 18:27 By Zeljka Zorz Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from threat intelligence company Defused, which said

Attackers are exploiting FortiSandbox vulnerabilities Read More »

A suspected Fortinet FortiWeb zero-day is actively exploited, researchers warn

A suspected Fortinet FortiWeb zero-day is actively exploited, researchers warn 2025-11-14 at 14:10 By Zeljka Zorz A suspected (but currently unidentified) zero-day vulnerability in Fortinet FortiWeb is being exploited by unauthenticated attackers to create new admin accounts on vulnerable, internet-facing devices. Whether intentionally or accidentally, the vulnerability (or this specific path for triggering it) has

A suspected Fortinet FortiWeb zero-day is actively exploited, researchers warn Read More »

Scroll to Top