Asutorufaのブログ

こんにちは

Threat Intelligence

Threat Intelligence

Daily security intelligence collected from public sources.

Latest

Threat Intelligence Daily · 2026-09-14

The most urgent new threat on September 14 was Cisco Secure Email Gateway CVE-2026-76461: an unauthenticated remote attacker can trigger root-level command execution through a crafted email. Cisco confirmed active exploitation and CISA added it to KEV the same day. Other notable items include the Mathspace breach via Metabase CVE-2026-72898, follow-up on the IDScan.net identity-data incident, and new JVN disclosures affecting FLEXLAN, YAMAP and ExLlamaV3.

Critical1High3Medium2Low0Exploited26 threats

Threat Intelligence Daily · 2026-09-14

The most urgent new threat on September 14 was Cisco Secure Email Gateway CVE-2026-76461: an unauthenticated remote attacker can trigger root-level command execution through a crafted email. Cisco confirmed active exploitation and CISA added it to KEV the same day. Other notable items include the Mathspace breach via Metabase CVE-2026-72898, follow-up on the IDScan.net identity-data incident, and new JVN disclosures affecting FLEXLAN, YAMAP and ExLlamaV3.

Critical1High3Medium2Low0Exploited26 threats

Threat Intelligence Daily · 2026-09-13

As of 2026-09-13, the most urgent threats center on actively exploited DevOps, remote-management and edge-device vulnerabilities, plus the BlueMoon browser/Windows zero-day chain rapidly adopted by multiple state-aligned clusters. CISA added five KEVs, PaperCut and GitLab saw real-world attack activity, while Check Point disclosed two critical VPN RCEs and the Brevo incident enabled targeted phishing against Trezor users.

Critical7High1Medium0Low0Exploited78 threats
©2026Asutorufa