Simo
5K posts

Simo
@SimoKohonen
chief honeypot @defusedcyber

🚨 Two updates from the Defused honeypot lab 1️⃣ New FortiClient EMS decoy deployed CVE-2026-21643 (pre-auth SQLi, CVSS 9.1) - Bishop Fox just dropped a full exploitation writeup for FortiClient EMS 7.4.4. No public exploitation observed yet but with a detailed writeup now out, it's a matter of time. We've added a FortiClient EMS honeypot stream to catch early exploitation attempts 🍯 2️⃣ SharePoint CVE-2026-20963 added to CISA KEV Microsoft SharePoint deserialization flaw - actively exploited in the wild. RCE via crafted network requests, no auth required. Track exploitation attempts against our SharePoint decoys on the platform. 👉 console.defusedcyber.com/signup



grok generated a teaser for you







In 6 minutes, Gili Raanan (@giliraanan), the foremost expert on cybersecurity, explains why we're all f*cked.


⚠️ We are observing an active exploitation campaign targeting Citrix NetScaler instances We have observed 500+ exploit attempts of both CitrixBleeds (CVE-2025-5777 and CVE-2023-4966) against our NetScaler decoys across multiple regions: 193.24.211.86 AS215929 🇧🇬 Data Campus Limited 173.164.73.25 AS7922 🇺🇸 Comcast Cable Communications 91.92.243.126 AS202412 🇳🇱 Omegatech LTD 194.31.223.238 AS215439 🇩🇪 PLAY2GO INTERNATIONAL LIMITED Highly elevated exploit activity against older vulnerabilities can often precede a zero-day vulnerability Monitor exploitation of edge devices like Citrix NetScaler in real time 👉 console.defusedcyber.com/signup




@UK_Daniel_Card Have you tried this?











