Sabitlenmiş Tweet
Drew
31.4K posts

Drew
@DopeDrew
Retired Vet | Cybersecurity | CISSP SecurityX PenTest+ CySA+ SSCP Sec+ Net+ A+ CC ITIL AZ900 SC900 | #BlackTechTwitter #CyberProfessional #BlacksInCyber
Cleveland, OH Katılım Haziran 2009
2.8K Takip Edilen1.9K Takipçiler

Critical: CVE-2026-0300 lets attackers take over exposed PAN-OS firewalls without logging in. This puts the network edge at risk. Patch now, disable or restrict Captive Portal exposure, and hunt for signs of compromise.
#CyberSecurity #CyberThreat #ThreatIntel #C3Security
🔗 security.paloaltonetworks.com/CVE-2026-0300
English

Critical PAN-OS flaw CVE-2026-0300 is being exploited via the User-ID Authentication Portal. If it is internet-facing on affected 10.2, 11.1, 11.2, or 12.1 releases, patch now.
#CyberSecurity #CyberThreat #ThreatIntel #C3Security
🔗 security.paloaltonetworks.com
English

GitHub disclosed critical RCE CVE-2026-3854 in git push handling. GitHub cloud was patched, but GitHub Enterprise Server admins should upgrade immediately.
#CyberSecurity #CyberThreat #ThreatIntel #C3Security
🔗 github.blog/security/secur…
English

CVE-2026-34197 is hitting Apache ActiveMQ Classic now. If your brokers are internet-exposed and on 5.19.4 or earlier, or 6.2.3 or earlier, patch immediately.
#CyberSecurity #CyberThreat #ThreatIntel #C3Security
🔗 bleepingcomputer.com/news/security/…
English

Check out the latest article in my newsletter: Adobe’s Acrobat Zero-Day Is a Reminder That “Routine” Software Still Creates Frontline Risk linkedin.com/pulse/adobes-a… via @LinkedIn
English

Axios npm was backdoored. 50M weekly downloads, now shipping a RAT for Windows/macOS/Linux. North Korean UNC1069. Audit your lock files, rotate tokens, rebuild from clean. CI/CD pipelines are at risk.
#CyberSecurity #CyberThreat #ThreatIntel #C3Security
🔗 thehackernews.com/2026/04/google…
English

CISA KEV: CVE-2025-31277 — buffer overflow in Apple Safari, iOS & macOS lets malicious web content corrupt memory. All Apple devices at risk. Patch: Settings → General → Software Update.
#CyberSecurity #CyberThreat #ThreatIntel #C3Security
🔗 cisa.gov/known-exploite…
English

🍎 Apple just silently patched a WebKit flaw (CVE-2026-20643) that broke the same-origin policy — the wall that stops malicious sites from reading your bank tabs & email.
No malware needed. Just visiting a page.
Check Settings → Privacy & Security → enable Background Security Improvements.
#CyberSecurity #CyberThreat #ThreatIntel #C3Security
🔗 thehackernews.com/2026/03/apple-…
English

The cybersecurity takeaway nobody wants to hear: if a random cybercriminal stumbled into these files through a misconfiguration, what do you think nation-state actors with actual resources have already accessed?
Basic security hygiene isn't optional — even for the FBI. #cybersecurity #infosec
English

🚨 CVE-2026-1603: Ivanti EPM has a critical auth bypass letting unauthenticated attackers steal stored credentials remotely. CISA added it to KEV on March 9th — patch by March 23rd or disconnect immediately.
#CyberSecurity #CyberThreat #ThreatIntel #C3Security
🔗 cisa.gov/known-exploite…
English


