OFFSEC
Offensive Security
Adversarial testing, red teaming and exploit research: finding the gaps before adversaries do.
18 articles
Latest
- The F5 hotfix closes the overflow. It does not revoke the tokens CVE-2026-94127 gives an unauthenticated attacker code execution on BIG-IP APM where it is configured as an OAuth authorization server. F5 confirms exploitation before disclosure. Remediation is… 6 min 14 sources
- The exploited Cisco ISE flaw is a trust problem, not a patching problem CVE-2026-76460 carries a CVSS of 10.0 and a scope-change metric. Root on an Identity Services Engine node means the credentials, certificates and access policy it holds… 6 min 17 sources
- The vault is not the boundary: agent runtimes hold credentials in clear Unit 42 showed that an agent's own tooling can reach the credential the platform decrypted for it. The vendor closed the report as documented behaviour. That… 5 min 11 sources
- MikroTrick: 122,500 exposed routers, and a patch that does not evict the intruder CERT Polska disclosed a two-flaw chain giving unauthenticated administrative control of MikroTik RouterOS over SSH. Exploitation was confirmed the day before the fix shipped, and Indonesia… 5 min 12 sources
- Oracle went monthly and shipped 673 patches. The flaw being exploited was fixed in January. The September update carries six maximum-severity flaws, none yet exploited. Meanwhile CVE-2026-21962, patched eight months ago, drew more than 140,000 recorded attacks and was catalogued as… 5 min 10 sources
- Three security appliances, one three-day deadline: reading the September KEV batch Cisco Secure FMC, Citrix NetScaler and Fortinet FortiOS entered the CISA catalogue within a day of each other, all under active exploitation. For at least two… 6 min 16 sources
- StyleSmuggler’s source data is the finding, not its CVSS score CVE-2026-75650 is a maximum-severity Magento flaw exploited three days before Adobe shipped a fix. The more useful material is in the source telemetry: most observed addresses… 5 min 12 sources
- Three edge appliances, one pattern: the window is now days Cisco Secure FMC, Citrix NetScaler and FortiOS all reached CISA's exploited list inside a fortnight. Read together, the three timelines say something uncomfortable about how long… 5 min 13 sources
