Pinned Tweet
Easter holidays and a Fortinet 0-day - a match made in heaven 🐰 (also my first credited CVE 😇)
🚨 New Fortinet vulnerability being exploited as an 0-day CVE-2026-35616 - FortiClient EMS pre-authentication API access bypass - CVSS 9.1 Critical After observing in-the-wild exploitation of this vulnerability earlier this week, Defused reported it to Fortinet under responsible disclosure. Fortinet has released an emergency hotfix - plus a scheduled patch - for FortiClient EMS 7.4.5 and 7.4.6. The vulnerability allows an unauthenticated attacker to bypass API authentication and authorization entirely, unauthorized code or commands via crafted requests. This discovery was made through our upcoming Radar feature launching next week 😇 Advisory: fortiguard.com/psirt/FG-IR-2… Track exploitation of this and other Fortinet vulns in real time and get updates on the new Defused Radar 👉 console.defusedcyber.com/sig… Credit also to @heckintosh_ for independently discovering this vulnerability 💪
5
15
112
39,265
We have entered the era of stealth exploits (encoding a single character to bypass security controls)🍯🍯🍯
🚨 We are seeing in-the-wild exploitation of Cisco Catalyst SD-WAN Manager (CVE-2026-76504 / API auth bypass) in our honeypots since Sep 30 UTC, about seven hours after Cisco's advisory. Attackers are hex-encode the login path (/%6a_security_check) to slip past the auth rule and reach the admin API. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
7
23
1,648
Simo retweeted
🚨Per @watchtowr research, CVE-2026-88771 (Citrix NetScaler) is exploitable across multiple paths (any logged field works) We have observed hundreds of hits on our decoys in the last 24h across: • /nf/auth/doAuthentication.do • /cgi/login • /p/u/doLogon.do • /logon/LogonPoint/tmindex.html • / (payload in the User-Agent header) Post-exploit intent we're seeing includes: → whoami/id to prove root → marker files (nx_verify.html) to tag vuln boxes for a target list → curl/wget/fetch pulling stage-2 → blind DNS callbacks Full IOCS are available on Defused Radar
6
18
71
5,575
Citrix Netscaler CVE-2026-88771 now being mass exploited 🍯
8
61
267
32,483
Google / Mandiant linked this activity to ShinyHunters! cloud.google.com/blog/topics…
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
2
11
57
6,645
Simo retweeted
timely. I wonder what news about Oracle PeopleSoft made some threat actors hone in on this vuln's capabilities???
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
2
9
36
3,566
🍯🍯🍯
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
5
14
2,332
Super cool joint effort between @DefusedCyber and @Horizon3Attack in implementing pre-emptive honeypots for yet to be publicized vulns 👇 Many thanks to @hacks_zach 🙏
Today we are disclosing the technical details of CVE-2026-9586, a SQLi-to-RCE in #Sangoma #Switchvox which we reported in April 2026. On 30 Aug 2026, we received honeypot alerts of valid exploitation attempts across multiple internet sensors deployed in coordination with @DefusedCyber. Check out the details and IoCs in our latest blog: horizon3.ai/attack-research/…
6
17
2,052
🚨 We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th) An actor is abusing the auth bypass to hijack PaperCut's external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft - dumping DB tables via Derby ⚠️We haven't yet verified whether the exfil route is a working one Track emerging Papercut MF exploit activity 👉 console.defusedcyber.com/sig…
29
1,930
Papercut stuff starting to happen 👀
2
17
1,270
70% of the interesting stuff happens on the weekend these days 😮‍💨😮‍💨
🚨 We're seeing CVE-2026-32566 (Wordpress ACPT Pro, CVSS 9.8) exploited in our honeypots - a day after disclosure The unauth WordPress admin-creation vulnerability was exploited using two different routes (via REST and admin-ajax) by a single actor. The rogue admin's password was set to "solevisible" which links to ALFA-Shell, a WordPress webshell that's circulated for years. Full details on Defused Radar 👉 console.defusedcyber.com/rad…
1
3
25
2,882
hunny hunny 🍯
🚨 We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520. No code execution observed yet Chain writeup published yesterday by @VulnCheckAI Full details on Defused Radar 👉 console.defusedcyber.com/rad…
1
4
21
2,946
😮‍💨 the fun never ends
🚨 Exploit activity continues high over the weekend, with new recon activity on the horizon 1. A FortiSandbox endpoint (a VM-provisioning / VNC-start route that appears in none of the 2026 FortiSandbox advisories) saw attempted exploitation on our decoys - added to Defused Radar 2. First in-the-wild exploitation of the Citrix NetScaler pre-auth RCE from @watchtowrcyber (CVE-2026-8452) hit Defused EX customer sensors Sunday morning. Public writeup was released on Friday 3. A multi-vendor edge-VPN enumeration sweep hit across our honeypot fleet - FortiGate, GlobalProtect, SonicWall, Citrix, Ivanti, Cisco - spraying product-specific login probes at every sensor. Activity originates from known malicious ASNs Stay on top of acute exploit activity 👉console.defusedcyber.com/sig…
2
2
11
2,238
Featuring @DefusedCyber 🍯
Max severity SAP Commerce Cloud flaw now targeted in attacks bleepingcomputer.com/news/se… bleepingcomputer.com/news/se…
1
1
11
1,536
Simo retweeted
🚨 First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots - 3 days after patch day. This vulnerability has no public PoC and is not known to be exploited. View the full payload 👉console.defusedcyber.com/sig…
1
17
72
11,378
You can set up tripwires in @DefusedCyber which alert you when certain paths get exploited 🍯
You're back in the room, trapped with us - and a Citrix NetScaler Pre-Auth RCE (CVE-2026-8452) Enjoy... labs.watchtowr.com/youre-bac…
1
11
996
Featuring @DefusedCyber 👁️👅👁️
Hackers leverage new Microsoft SharePoint exploit in attacks bleepingcomputer.com/news/mi… bleepingcomputer.com/news/mi…
1
1
8
969
Simo retweeted
A lot to do with your honeypot: collect POC/exploit, IoC, follow campaigns and more..it has a very high value ...because this is where things happens for real! Thanks to @DefusedCyber @SimoKohonen for the amazing job there, too underrated I gess, from both Offensive and Defensive guys
🚨 Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots The vulnerability is a Microsoft SharePoint JWT auth bypass for which Rapid7 published a technical writeup and proof-of-concept code yesterday. Track it live 👉 console.defusedcyber.com/sig…
1
4
15
2,654
🍯🍯🍯🍯
🚨 Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots The vulnerability is a Microsoft SharePoint JWT auth bypass for which Rapid7 published a technical writeup and proof-of-concept code yesterday. Track it live 👉 console.defusedcyber.com/sig…
1
7
842
Simo retweeted
⚠️We are observing a spike in scanning against VMware vCenter Our honeypots are logging increased fingerprinting - such as version probes via POST /sdk/ (RetrieveServiceContent) and walks of the /websso SAML SSO flow - coinciding with Broadcom's VMSA-2026-0006 (CVE-2026-59309, unauth auth-bypass in vmdir, CVSS 9.8). Track VMWare vCenter activity now -> console.defusedcyber.com/sig…
2
20
66
7,145
Defused Freemium has been absolutely useless for months now, finally got around to fixing that 😅
❗️New: all verified users can now start a 14-day full-access trial of Defused - no strings attached. Existing freemium users included. Sign up today 👉 console.defusedcyber.com/sig…
2
3
8
1,941