[CVE] CVE SPOTLIGHT

CVE-2026-93952 CVSS 9.0 Patch Now Arista VeloCloud Orchestrator
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
CISA KEV
CVE-2026-94127 CVSS 9.0 Patch Now F5 BIG-IP APM
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
CISA KEV
CVE-2026-93616 CVSS 9.0 Patch Now Check Point Multiple Products
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.
CISA KEV
CVE-2026-85102 CVSS 9.0 Patch Now Check Point Multiple Products
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
CISA KEV
CVE-2026-7273 CVSS 9.0 Patch Now Zyxel GS1900 Series Switches
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
CISA KEV

[0x01] ⚠️ CRITICAL VULNERABILITIES & EXPLOITATION TRENDS

Critical CVE-2026-77521 https://www.gbhackers.com/feed/
MaxKB AI Platform Flaw Enables OS Command Execution via Prompt Injection
A critical vulnerability in MaxKB AI knowledge-base platforms allows attackers to execute operating system commands through prompt injection. This flaw can run commands on the underlying host in certain configurations, bypassing application-level controls. Administrators must implement strict input validation and containerize AI platforms to mitigate host access.

[0x02] 🦠 THREAT ACTOR ACTIVITY & MALWARE ANALYSIS

[0x03] 🌐 SUPPLY CHAIN & LARGE-SCALE BREACHES

[0x04] 🛠️ AI/PRODUCT-SPECIFIC RISKS & ADVISORIES

[0x05] CYBERSECURITY VIDEOS

🎯 CTF Solve
TryHackMe Windows Basics Lab | Full Workthrough Complete guide 2026 #TryHackMe #windowsbasics
Cyber Mahour
🎯 CTF Solve
TeamPCP OSINT Investigation
John Hammond
🎯 CTF Solve
Axiom Systems CTF Walkthrough | Full Lab Solution | SQL Injection & Enumeration | ThunderCipher
ThunderCipher
📰 News
How Hackers Find Leaked Website Information and Abuse It
OWL
🐛 Bug Walkthrough
Anthropic Caught Hackers Doing This So I Rebuilt It in a Few Hours
NahamSec
🔬 Exploit POC
Windows 11 Update Flaw Lets Local Users Seize Control (CVE-2026-81963)
AISLabs AI

[0x07] BUG BOUNTY HIGHLIGHTS

[0x08] EXPLOIT-DB FRESH DROPS

[0x09] UPCOMING CTFs

Jeopardy Weight: 0.0
BreachPoint 2026
Sep 25, 04:00 UTC 1 days
CTFTime ↗ Register ↗
Jeopardy Weight: 0.0
Null Origin CTF 2026: Grand finale
Sep 25, 04:30 UTC 12 hours
CTFTime ↗ Register ↗
Jeopardy Weight: 0.0
NileCTF
Sep 25, 12:00 UTC 2 days
CTFTime ↗ Register ↗
Jeopardy Weight: 0.0
FlightPath2026
Sep 25, 13:30 UTC 2 days
CTFTime ↗ Register ↗
Jeopardy Weight: 0.0
BCS CTF 2026
Sep 25, 14:00 UTC 2 days
CTFTime ↗ Register ↗

[0x0a] SECURITY PODCASTS

Darknet Diaries
LOW - Now Available
03:39
Listen ↗
Risky Business
Risky Business #853 -- We're all gonna die, apparently
3548
Listen ↗
Security Now
SN 1097: Mega Patch Tuesday Fallout - When AI Outsmarts Its Makers
2:50:02
Listen ↗
SANS Internet Storm Center
SANS Stormcast Wednesday, September 23rd, 2026: GET with Body; Checkpoint, VeloCloud, BigIP and Microsoft Defender 0-days
4:52
Listen ↗

[0xff] ARCHIVE

Keyboard Shortcuts

Focus search/
Next articlej
Previous articlek
Open article linkEnter
Toggle TL;DR modet
Toggle themed
Listen to briefinga
Close overlayEsc
Show shortcuts?