OffSeq is a cybersecurity company enhancing organizational digital resilience through comprehensive protection against evolving cyber threats. We offer specialized services for businesses of all sizes, with particular expertise in Baltic, Scandinavian, Belgian markets and EU regulatory compliance.
OffSequence
@offseq@infosec.exchange
infosec.exchange
CVE-2026-16723: CRITICAL RCE in Alibaba Fastjson 1.2.68. Exploitable under default config — no patch yet. Avoid 1.2.68 & monitor vendor updates for mitigation. CVSS 9.0. https://radar.offseq.com/threat/cve-2026-16723-cwe-20-improper-input-validation-in-alibaba-fastjson-939ed165aac7ce81 #OffSeq #infosec #CVE202616723 #remotecodeexecution
Security Crawler Carl
@security_crawler_carl@infosec.exchange
READ CYBERSECURITY NEWS. DON'T DIE.
infosec.exchange
Replying to
@security_crawler_carl@infosec.exchange
Searchlight Cyber published exploitation details; the wolves read it too. ServiceNow has acknowledged the activity. Hosted instances were updated automatically — on-prem adventurers, you're on your own, as always.
Patch your ServiceNow AI platform instances against CVE-2026-6875 immediately if you haven't already.
Reward: A Tattered Scroll of Good Intentions, untranslated, slightly on fire.
#ServiceNow #CVE202668875 #RemoteCodeExecution #ZeroDay #CyberSecurity #PatchedOrPerish (2/2)
Security Crawler Carl
@security_crawler_carl@infosec.exchange
READ CYBERSECURITY NEWS. DON'T DIE.
infosec.exchange
Replying to
@security_crawler_carl@infosec.exchange
Reward: You've received a Cracked Heap Fragment — a common drop. Very common, apparently.
#NGINX #CyberSecurity #CriticalVulnerability #RemoteCodeExecution #CVE202642533 #PatchedOrPerish (3/3)
thecybersecguru
@thecybersecguru@infosec.exchange
infosec.exchange
🚨 CRITICAL: WordPress Core "wp2shell" RCE
A single anonymous HTTP request can lead to Remote Code Execution on vulnerable WordPress Core installations.
⚠️ No plugins.
⚠️ No themes.
⚠️ No authentication required.
Tracked as:
🔴 CVE-2026-63030 (REST API Batch Route Confusion → RCE)
🔴 CVE-2026-60137 (Facilitated SQL Injection)
Affected versions
• WordPress 6.9.0–6.9.4
• WordPress 7.0.0–7.0.1
✅ Update immediately to WordPress 6.9.5 or 7.0.2. Due to the severity, WordPress has enabled forced automatic security updates for affected installations.
🔗 Full technical analysis:
https://thecybersecguru.com/news/wordpress-core-rce-wp2shell/
#WordPress #WordPressSecurity #wp2shell #CVE202663030 #CVE202660137 #RCE #RemoteCodeExecution #SQLInjection #RESTAPI #CyberSecurity #InfoSec #WebSecurity #WebsiteSecurity #PatchNow #ThreatIntelligence #BlueTeam #SOC #Linux #PHP #ZeroDay #SecurityResearch #SysAdmin #DevSecOps
thecybersecguru
@thecybersecguru@infosec.exchange
infosec.exchange
🚨 Millions of 7-Zip users should update immediately.
A newly disclosed vulnerability, CVE-2026-14266, could allow Remote Code Execution (RCE) when a victim opens a specially crafted XZ archive.
🔍 Key details:
• Heap-based buffer overflow
• User interaction required
• Exploitable through phishing emails, malicious downloads, and weaponized archive files
• Fixed in 7-Zip 26.02
If you use 7-Zip, update now and avoid opening compressed files from untrusted sources.
Read the full technical breakdown 👇
https://thecybersecguru.com/news/7-zip-vulnerability-cve-2026-14266/
#CyberSecurity #InfoSec #CyberThreat #Vulnerability #CVE #CVE202614266 #7Zip #RemoteCodeExecution #RCE #ThreatIntel #CyberAttack #Malware #Phishing #SecurityUpdate #PatchNow #WindowsSecurity #BlueTeam #SOC #ThreatHunting #CyberDefense
Daily CyberSecurity
@DailyCyberSecurity@infosec.exchange
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
infosec.exchange
CVE-2026-6875 (CVSS 9.5) is a ServiceNow sandbox escape in the AI Platform that allows unauthenticated remote code execution. Patch now.
#ServiceNow #CVE20266875 #RemoteCodeExecution #SandboxEscape #CyberSecurity
https://securityonline.info/servicenow-sandbox-escape-cve-2026-6875/?utm_source=mastodon&utm_medium=jetpack_social
OffSequence
@offseq@infosec.exchange
OffSeq is a cybersecurity company enhancing organizational digital resilience through comprehensive protection against evolving cyber threats. We offer specialized services for businesses of all sizes, with particular expertise in Baltic, Scandinavian, Belgian markets and EU regulatory compliance.
infosec.exchange
tinyparrot npm v0.4.1 flagged as CRITICAL: Malicious postinstall script executes attacker-supplied shell commands via obfuscated HTTPS POST. Remove & avoid use! No patch available. https://radar.offseq.com/threat/mal-2026-10190-malicious-code-in-tinyparrot-npm-8e0728bab742b27e #OffSeq #npm #remotecodeexecution #malware
You've seen all posts