FortiBleed harvests 110M credentials; Cisco SSRF actively exploited; GitHub patches CI/CD attacks
FortiBleed credential-harvesting campaign collected 110 million credentials from 430
Read the full briefing →AI-generated daily briefings and vulnerability analysis for security teams who need signal, not noise.
FortiBleed credential-harvesting campaign collected 110 million credentials from 430
Read the full briefing →| CVE | Product | CVSS | Exploited | Patch |
|---|---|---|---|---|
| CVE-2026-10520 | Ivanti Sentry | 10 | KEV | — |
| CVE-2026-20253 | Splunk Enterprise | 9.8 | KEV | advisory |
| CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools | 9.8 | KEV | — |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer | 9.8 | KEV | — |
| CVE-2026-48172 | LiteSpeed CPanel Plugin | 9.8 | KEV | advisory |
KEV = listed in CISA catalog · IN WILD = active exploitation reported · PoC = public exploit code
FortiBleed credential-harvesting campaign collected 110 million credentials from 430
ShapedPlugin WordPress Pro plugins backdoored via build-pipeline compromise, Dify AI platform has four cross-tenant data-exposure flaws, immediate deployment required.
Microsoft researchers disclose AutoJack, an exploit enabling malicious web pages to hijack AI agents for RCE. Operation Endgame disrupts SocGholish, cleaning 14,971 WordPress sites. Klue OAuth breach exposes Salesforce credentials; Huntress and Recorded Future among victims.
North Korean-linked BlueNoroff compromised 140+ npm packages via Mastra AI. Gravity SMTP WordPress plugin (100k sites) actively exploited for API key theft. AutoJack attack chain targets Windows AI browsing agents.
59 security tools indexed · free + paid + open source · updated regularly
No tools match your search. Try a different keyword.
Pick up to 4 tools to compare pricing, deployment, and capabilities
Once a day at 04:00 UTC, the pipeline pulls ten authoritative security feeds – including CISA advisories – and extracts the day’s most important stories and the CVEs they cite.
Every CVE is checked against NVD for canonical CVSS and cross-referenced with the CISA KEV catalog. Inline citations link each story to its sources, and a skeptical second AI pass flags – or blocks – claims it can’t substantiate.
Severity is scored from CVSS and confirmed exploitation – not editorial tone – so Critical is rare by design. Structured briefings tell your team exactly what to patch, investigate, or escalate.
Join security professionals who start their morning with defend.network intelligence. Free forever.