Managed Honeypots for Early-warning Threat Intelligence 🍯 Sign up today for a 14-day trial: console.defusedcyber.com/sig…

Pinned Tweet
🚨 New Fortinet vulnerability being exploited as an 0-day CVE-2026-35616 - FortiClient EMS pre-authentication API access bypass - CVSS 9.1 Critical After observing in-the-wild exploitation of this vulnerability earlier this week, Defused reported it to Fortinet under responsible disclosure. Fortinet has released an emergency hotfix - plus a scheduled patch - for FortiClient EMS 7.4.5 and 7.4.6. The vulnerability allows an unauthenticated attacker to bypass API authentication and authorization entirely, unauthorized code or commands via crafted requests. This discovery was made through our upcoming Radar feature launching next week 😇 Advisory: fortiguard.com/psirt/FG-IR-2… Track exploitation of this and other Fortinet vulns in real time and get updates on the new Defused Radar 👉 console.defusedcyber.com/sig… Credit also to @heckintosh_ for independently discovering this vulnerability 💪
11
112
362
83,598
🚨 In addition to the IPs on circulating on social media, some additional IPs we are observing interacting with .ctxs.receiver webshells (Citrix Netscaler) on our decoys: 194[.]127.166.19 194[.]127.166.32 194[.]127.166.36 194[.]127.166.70 194[.]127.166.126 103[.]214.20.54 81[.]94.239.8 We're also seeing multiple actors sending the crafted Pitboss log entry in-request (pre-exploit). This is possibly a variation on CVE-2026-88771 exploitation, but we have not confirmed it works. Track Citrix Netscaler activity live 👉 console.defusedcyber.com/sig…
4
26
105
11,641
🚨 We are seeing in-the-wild exploitation of Cisco Catalyst SD-WAN Manager (CVE-2026-76504 / API auth bypass) in our honeypots since Sep 30 UTC, about seven hours after Cisco's advisory. Attackers are hex-encode the login path (/%6a_security_check) to slip past the auth rule and reach the admin API. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
11
31
3,718
🚨Per @watchtowr research, CVE-2026-88771 (Citrix NetScaler) is exploitable across multiple paths (any logged field works) We have observed hundreds of hits on our decoys in the last 24h across: • /nf/auth/doAuthentication.do • /cgi/login • /p/u/doLogon.do • /logon/LogonPoint/tmindex.html • / (payload in the User-Agent header) Post-exploit intent we're seeing includes: → whoami/id to prove root → marker files (nx_verify.html) to tag vuln boxes for a target list → curl/wget/fetch pulling stage-2 → blind DNS callbacks Full IOCS are available on Defused Radar
6
19
72
5,648
Defused retweeted
🧵If cyber deception is not part of your defensive security strategy, you’re missing out. If you work in IT or security and don’t know where to start, do this…
6
29
186
23,201
Defused retweeted
Citrix Netscaler CVE-2026-88771 now being mass exploited 🍯
8
61
267
32,671
Defused retweeted
Google / Mandiant linked this activity to ShinyHunters! cloud.google.com/blog/topics…
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
2
11
57
6,646
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
7
14
92
19,744
Defused retweeted
On August 30, @DefusedCyber honeypots detected valid exploitation attempts against the vulnerability. The observed attacker used command execution, followed by additional enumeration and exfiltration activity.
1
2
5
313
In May, we deployed Switchvox honeypots in coordination with @Horizon3Attack, anticipating that their newly reported vulnerabilities would eventually be exploited. On August 30, they were. Our sensors caught the first known in-the-wild exploitation attempts against CVE-2026-9586 (unauthenticated SQLi → RCE, patched in 8.4.0.2) - the same actor hitting multiple honeypots in quick succession, which suggests broad targeting of the ~4,000 internet-exposed instances. Check out the Horizon3 blog post for the full technical analysis 👇
Today we are disclosing the technical details of CVE-2026-9586, a SQLi-to-RCE in #Sangoma #Switchvox which we reported in April 2026. On 30 Aug 2026, we received honeypot alerts of valid exploitation attempts across multiple internet sensors deployed in coordination with @DefusedCyber. Check out the details and IoCs in our latest blog: horizon3.ai/attack-research/…
1
5
16
2,414
🚨 We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th) An actor is abusing the auth bypass to hijack PaperCut's external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft - dumping DB tables via Derby ⚠️We haven't yet verified whether the exfil route is a working one Track emerging Papercut MF exploit activity 👉 console.defusedcyber.com/sig…
2
12
65
7,870
🚨 We're seeing CVE-2026-32566 (Wordpress ACPT Pro, CVSS 9.8) exploited in our honeypots - a day after disclosure The unauth WordPress admin-creation vulnerability was exploited using two different routes (via REST and admin-ajax) by a single actor. The rogue admin's password was set to "solevisible" which links to ALFA-Shell, a WordPress webshell that's circulated for years. Full details on Defused Radar 👉 console.defusedcyber.com/rad…
1
16
62
8,053
🚨 We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520. No code execution observed yet Chain writeup published yesterday by @VulnCheckAI Full details on Defused Radar 👉 console.defusedcyber.com/rad…
9
48
5,763
Defused retweeted
A critical SAP Commerce Cloud flaw was exploited just three days after patching, according to @DefusedCyber, highlighting how quickly attackers are moving against enterprise vulnerabilities. #cybersecurity #CISO #infosec bit.ly/4wGFmaD
1
1
5
1,142
🚨 Exploit activity continues high over the weekend, with new recon activity on the horizon 1. A FortiSandbox endpoint (a VM-provisioning / VNC-start route that appears in none of the 2026 FortiSandbox advisories) saw attempted exploitation on our decoys - added to Defused Radar 2. First in-the-wild exploitation of the Citrix NetScaler pre-auth RCE from @watchtowrcyber (CVE-2026-8452) hit Defused EX customer sensors Sunday morning. Public writeup was released on Friday 3. A multi-vendor edge-VPN enumeration sweep hit across our honeypot fleet - FortiGate, GlobalProtect, SonicWall, Citrix, Ivanti, Cisco - spraying product-specific login probes at every sensor. Activity originates from known malicious ASNs Stay on top of acute exploit activity 👉console.defusedcyber.com/sig…
1
7
30
7,090
محاولات استغلال ثغرة حرجة في منصة @SAP Commerce Cloud، وذلك عقب ثلاثة أيام من إصدار التحديث الأمني لشهر أغسطس، وفق تقرير @DefusedCyber . تستهدف الثغرة ملحق Data Hub Adapter وتتيح للمهاجمين تجاوز آليات المصادقة والتحقق، وإرسال مدخلات خبيثة للوصول إلى مكونات داخلية حساسة.
1
1
10
1,223
🚨 First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots - 3 days after patch day. This vulnerability has no public PoC and is not known to be exploited. View the full payload 👉console.defusedcyber.com/sig…
1
17
72
11,382
Defused retweeted
You can set up tripwires in @DefusedCyber which alert you when certain paths get exploited 🍯
You're back in the room, trapped with us - and a Citrix NetScaler Pre-Auth RCE (CVE-2026-8452) Enjoy... labs.watchtowr.com/youre-bac…
1
11
997
Defused retweeted
Sharepoint baddies in the honeypots at @DefusedCyber coming in from: 205.147.17.6 abusing the vulnerability from CVE-2026-55040

ALT Happy New Year Honey GIF

5
33
3,597