{"total":5,"items":[{"id":359,"title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)","original_title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)","source_rating":null,"summary":"Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days…","ai":false,"actions":[],"url":"https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/","type":"research","language":"en","published_at":"2026-09-30T20:00:04+00:00","severity":"middel","priority":37,"vendors":["Citrix"],"cves":[{"id":"CVE-2026-88772","cvss":9.5,"epss":0.01301,"epss_percentile":0.69447,"in_kev":true,"kev_ransomware":false},{"id":"CVE-2026-88771","cvss":9.5,"epss":0.01063,"epss_percentile":0.63433,"in_kev":true,"kev_ransomware":false}],"cve_count":2,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.5,"epss_max":0.01301,"source_count":3,"ncsc":null,"source":{"slug":"unit42","name":"Palo Alto Unit 42","category":"onderzoek","country":null,"license":"© Palo Alto Networks","reuse":"excerpt"},"bundle":null},{"id":350,"title":"Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use","original_title":"Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use","source_rating":null,"summary":"Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to…","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/","type":"research","language":"en","published_at":"2026-09-17T10:00:43+00:00","severity":"middel","priority":42,"vendors":["Cisco"],"cves":[{"id":"CVE-2020-1472","cvss":5.5,"epss":0.99389,"epss_percentile":0.9994,"in_kev":true,"kev_ransomware":true},{"id":"CVE-2025-24799","cvss":9.8,"epss":0.86692,"epss_percentile":0.99738,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2025-2479","cvss":6.1,"epss":0.00335,"epss_percentile":0.24583,"in_kev":false,"kev_ransomware":false}],"cve_count":3,"in_kev":true,"exploited_by":["CISA KEV"],"kev_ransomware":true,"cvss_max":9.8,"epss_max":0.99389,"source_count":1,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":352,"title":"We've got one word for it, and it's usually the wrong one","original_title":"We've got one word for it, and it's usually the wrong one","source_rating":null,"summary":"In this week's Threat Source newsletter, Joe explores why the word \"burnout\" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address…","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/weve-got-one-word-for-it-and-its-usually-the-wrong-one/","type":"research","language":"en","published_at":"2026-09-10T18:00:15+00:00","severity":"hoog","priority":52,"vendors":[],"cves":[{"id":"CVE-2026-20079","cvss":10.0,"epss":0.8818,"epss_percentile":0.99765,"in_kev":true,"kev_ransomware":false},{"id":"CVE-2026-20316","cvss":5.3,"epss":0.35096,"epss_percentile":0.98397,"in_kev":true,"kev_ransomware":true}],"cve_count":2,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":true,"cvss_max":10.0,"epss_max":0.8818,"source_count":3,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":353,"title":"Active exploitation of Cisco Secure Firewall Management Center vulnerabilities","original_title":"Active exploitation of Cisco Secure Firewall Management Center vulnerabilities","source_rating":null,"summary":"Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/fmc-ongoing-exploitation/","type":"research","language":"en","published_at":"2026-09-09T16:08:59+00:00","severity":"hoog","priority":52,"vendors":["Cisco"],"cves":[{"id":"CVE-2026-20079","cvss":10.0,"epss":0.8818,"epss_percentile":0.99765,"in_kev":true,"kev_ransomware":false},{"id":"CVE-2026-20316","cvss":5.3,"epss":0.35096,"epss_percentile":0.98397,"in_kev":true,"kev_ransomware":true}],"cve_count":2,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":true,"cvss_max":10.0,"epss_max":0.8818,"source_count":3,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null},{"id":354,"title":"Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities","original_title":"Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities","source_rating":null,"summary":"Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as \"critical.\"","ai":false,"actions":[],"url":"https://blog.talosintelligence.com/microsoft-patch-tuesday-for-september-2026/","type":"research","language":"en","published_at":"2026-09-08T22:16:35+00:00","severity":"middel","priority":27,"vendors":["Microsoft"],"cves":[{"id":"CVE-2026-85880","cvss":7.8,"epss":0.03616,"epss_percentile":0.89147,"in_kev":true,"kev_ransomware":false},{"id":"CVE-2026-65772","cvss":8.8,"epss":0.01693,"epss_percentile":0.76299,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-69845","cvss":9.8,"epss":0.01022,"epss_percentile":0.62209,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-72982","cvss":9.8,"epss":0.00974,"epss_percentile":0.60735,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-69525","cvss":9.8,"epss":0.00974,"epss_percentile":0.60738,"in_kev":false,"kev_ransomware":false},{"id":"CVE-2026-70296","cvss":9.8,"epss":0.00974,"epss_percentile":0.60732,"in_kev":false,"kev_ransomware":false}],"cve_count":165,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":10.0,"epss_max":0.03616,"source_count":2,"ncsc":null,"source":{"slug":"talos","name":"Cisco Talos Intelligence","category":"onderzoek","country":null,"license":"© Cisco Talos","reuse":"excerpt"},"bundle":null}]}