#OffSeq
OffSeq is an European offensive security company. Pentesting, red teaming, OT/ICS security and NIS2/DORA work across the EU.

Here we post vulnerability research, honeypot field reports and open-source tools. Open to collaboration.

offseq.com/en/

#InfoSec #PenTest #RedTeam
Offensive Security for Cyber Resilience – OffSeq
European offensive-security company providing red team operations, threat intelligence, security audits, continuous monitoring and NIS2 compliance support.
offseq.com
September 26, 2026 at 6:56 AM
Daily IT Security Digest — 2026-09-25
deployments should patch immediately while reviewing logs for indicators of compromise.

Source: [OffSeq](https://radar.offseq.com/threat/arista)

## 5. Meta Muse Mac Zero-Day: Token Hijacking Risk
September 25, 2026 at 5:02 AM
Daily IT Security Digest — 2026-09-25
be patched immediately. Active exploitation has been confirmed in the wild.

Source: [OffSeq](https://radar.offseq.com/threat/cisco-warns)

## 4. Arista VeloCloud Orchestrator Zero-Day Under Active Exploitation
September 25, 2026 at 5:02 AM
Daily IT Security Digest — 2026-09-22
affected Android devices.
- https://infosec.exchange/@offseq/117279544153085501
September 22, 2026 at 5:01 AM
Daily IT Security Digest — 2026-09-22
https://infosec.exchange/@offseq/117285914298082330
- https://infosec.exchange/@offseq/117285207237888691

## 3. Cisco Secure Email Gateway Zero-Day Vulnerability (Critical)
Cisco Secure Email Gateway is affected by a critical zero-day vulnerability that is
September 22, 2026 at 5:01 AM
Daily IT Security Digest — 2026-09-25
SIGABRT events.

Source: [HackRead](https://hackread.com/f5-breach-so), [OffSeq](https://radar.offseq.com/threat/critical-f5-big-ip-apm-rce-zero-day)

## 3. Cisco ISE Authentication Bypass — Actively Exploited Zero-Day (CVE-2026-76460)
September 25, 2026 at 5:02 AM
OpenClaw Slack (<2026.8.1) faces HIGH severity (CVSS 8.7) auth bypass in multi-person DMs — unauthorized users can trigger Slack agents. Upgrade to 2026.8.1+ to secure your data. https://radar.offseq.com/threat/cve-2026-100575-missing-authorization-in-openclaw-slack-2a3447a3c9192e9f #OffSeq #Vuln...
CVE-2026-100575: Missing Authorization in openclaw slack
CVE-2026-100575 is a missing authorization vulnerability in OpenClaw Slack affecting versions prior to 2026.8.1. The issue arises from improper enforcement of sender allowlists in multi-person direct messages, enabling unauthorized particip
radar.offseq.com
September 26, 2026 at 4:30 AM
Daily IT Security Digest — 2026-09-25
same network segment. ViewSonic has not yet released a patch; users are advised to segment and monitor affected systems.

Source: [OffSeq](https://radar.offseq.com/threat/082989)

## 7. Revolut Customers Hit by Second Data Breach in September
September 25, 2026 at 5:02 AM
Daily IT Security Digest — 2026-09-24
5.2.3.16 and 6.4.2.8) allows attackers to access privileged functions without credentials. Immediate patching is essential, and administrators should review system logs for any signs of compromise.
https://infosec.exchange/@offseq/117319534208953341

## 7. Meta
September 24, 2026 at 5:02 AM
Daily IT Security Digest — 2026-09-23
`copy_msg_element` function in the Device Discovery Service. No patch exists; users are advised to restrict access immediately. An offseq post confirms public exploit code.
September 23, 2026 at 5:02 AM
Daily IT Security Digest — 2026-09-21
immediate risk to organizations managing network access control.
Sources: [OffSeq](https://radar.offseq.com/threat/cisco-warns-actively-exploited-ise-auth-bypass/), [Bluesky @offseq.bsky.social](https://infosec.exchange/@offseq/117285914298082330)

4. **CISA
September 21, 2026 at 5:02 AM
Daily IT Security Digest — 2026-09-21
CVSS 9.4. Both have public exploits and no patches are available. Restricting network access to these devices is the only mitigation for now.
Sources: [OffSeq #1](https://radar.offseq.com/threat/cve-2026-94100-buffer-overflow-in-), [OffSeq
September 21, 2026 at 5:02 AM
IBM Concert (v1.0.0 – 3.0.0) is affected by a CRITICAL use-after-free vulnerability (CVSS 9.8). Remote exploitation possible — patch status unconfirmed. Monitor IBM advisories: https://radar.offseq.com/threat/cve-2026-6928-cwe-416-use-after-free-in-ibm-concert-2eb5c8a4bd6982d7 #OffSeq #IBM #CVE20...
CVE-2026-6928: CWE-416 Use After Free in IBM Concert
IBM Concert versions 1.0.0 through 3.0.0 contain a use-after-free vulnerability (CWE-416) where the software references or accesses memory after it has been freed. This memory corruption issue can be exploited by an attacker able to influen
radar.offseq.com
September 24, 2026 at 1:30 AM
React Native CRITICAL flaw exposes dev systems to remote attack. No patch yet — restrict access & monitor for updates. High risk for EU orgs. More: https://radar.offseq.com/threat/severe-react-native-flaw-exposes-developer-systems-39d58deb #OffSeq #ReactNative #DevSecOps
November 6, 2025 at 1:31 AM
Deltaww DIAEnergie (pre-1.11.00.022) hit by CRITICAL Improper Authentication flaw — auth bypass possible. Patch ASAP when available. https://radar.offseq.com/threat/cve-2026-78308-cwe-287-improper-authentication-in-deltaww-diaenergie-6cc9f25ab57e2374 #OffSeq #ICS #Vulnerability
CVE-2026-78308: CWE-287: Improper Authentication in Deltaww DIAEnergie
Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.
radar.offseq.com
September 24, 2026 at 9:00 AM
donutautosellsrc PyPI package (v0.3.7 – 0.3.9) is CRITICAL: contains obfuscated infostealer using blockchain C2. Uninstall affected versions now and monitor for data loss. https://radar.offseq.com/threat/malicious-code-in-donutautosellsrc-pypi-adf2fee072c2c5b1 #OffSeq #PyPISecurity #Malware
Malicious code in donutautosellsrc (PyPI)
During installation, the donutautosellsrc package fetches code hidden within an image containing a Python application with a native extension module. This native module is obfuscated and functions as an infostealer, collecting sensitive inf
radar.offseq.com
September 27, 2026 at 12:00 PM
CRITICAL: requests-cache-utils v1.0.0 (PyPI) contains install-time malware, exfiltrating browser data. Remove and avoid use. Full details: https://radar.offseq.com/threat/malicious-code-in-requests-cache-utils-pypi-e8c3f4806b2131ca #OffSeq #Malware #PyPISecurity
Malicious code in requests-cache-utils (PyPI)
The requests-cache-utils PyPI package version 1.0.0 is a malicious package that overrides the setup.py install command to execute code during installation. This code downloads and executes a remote infostealer malware that targets browser d
radar.offseq.com
September 27, 2026 at 1:30 PM
chromatitle npm v1.0.0 carries CRITICAL malicious code: obfuscated loader fetches & runs remote payloads on import. Remove & audit dependencies ASAP. No patch available. #OffSeq #npm #Security https://radar.offseq.com/threat/malicious-code-in-chromatitle-npm-1cefd95c647d92b5
Malicious code in chromatitle (npm)
The 'chromatitle' npm package (version 1.0.0) advertises itself as a terminal color/title formatter but contains a malicious payload. Its main entry point immediately executes a bootstrap function that loads an obfuscated ~51KB JavaScript a
radar.offseq.com
September 25, 2026 at 1:30 PM
openclaw msteams <2026.8.1 has a HIGH severity bug (CVE-2026-100582) allowing unauthorized channel reads. Upgrade to 2026.8.1+ to block data exposure. https://radar.offseq.com/threat/cve-2026-100582-missing-authorization-in-openclaw-msteams-98e504ab6e11afa6 #OffSeq #Vulnerability #Cybersecurity
CVE-2026-100582: Missing Authorization in openclaw msteams
OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) prior to 2026.8.1 do not enforce the configured channel read allowlist for caller-supplied explicit read targets. This missing author
radar.offseq.com
September 26, 2026 at 3:00 AM
LOW severity: US proposes AI incident alert system with China. No current technical threat, but signals future policy changes for AI risk reporting. Monitor developments. https://radar.offseq.com/threat/us-proposes-ai-incident-alert-system-in-talks-with-china-bessent-says-0ae21c941fe0207e #OffSeq...
US Proposes AI Incident Alert System in Talks With China, Bessent Says
The U.S. Treasury Secretary announced a proposal for an AI incident notification mechanism to improve transparency and communication between the U.S. and China about AI incidents with potential national security implications. This system is
radar.offseq.com
September 22, 2026 at 3:00 AM
CRITICAL: tobychui zoraxy 3.2.3 – 3.3.4 has auth bypass (CVE-2026-100390) via IPv6 X-Forwarded-For spoofing. Restrict IPv6 or avoid IP-based controls until patched. https://radar.offseq.com/threat/cve-2026-100390-authentication-bypass-by-spoofing-in-tobychui-zoraxy-92a9e1620a0f6d01 #OffSeq #CVE20...
CVE-2026-100390: Authentication Bypass by Spoofing in tobychui zoraxy
The vulnerability in tobychui's Zoraxy product affects versions 3.2.3 through 3.3.4. The software fails to correctly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers, specifically the X-Forwarded-For header. This
radar.offseq.com
September 26, 2026 at 1:30 AM
Joomla Content Editor (JCE) CRITICAL vuln lets unauth users upload & run PHP (v1.0.0 – 2.9.99.4). No patch yet — restrict or disable JCE + monitor activity. Stay updated: https://radar.offseq.com/threat/cve-2026-48907-cwe-284-improper-access-control-in--ff15bdc3 #OffSeq #Joomla #SecurityAlert
CVE-2026-48907: CWE-284 Improper Access Control in joomlacontenteditor.net Jooml
The Joomla Content Editor (JCE) extension for Joomla contains an improper access control vulnerability (CWE-284) that permits unauthenticated attackers to create new editor profiles. This flaw enables attackers to upload and execute arbitra
radar.offseq.com
June 5, 2026 at 9:00 AM
CRITICAL: Bitget hit by $351.6M theft from hot/warm wallets — multiple blockchains affected. Withdrawals paused, User Protection Fund covers losses. Monitor for updates. https://radar.offseq.com/threat/hackers-steal-3516-million-in-bitget-crypto-exchange-hack-95a2b6dc1669868f #OffSeq #cryptosec #...
Hackers steal $351.6 million in Bitget crypto exchange hack
Suspected North Korean hackers compromised a critical backend wallet-service system at Bitget, enabling them to spoof transaction data and trigger authorization to transfer approximately $351.6 million from hot and warm wallets. The attack
radar.offseq.com
September 25, 2026 at 9:00 AM
Malicious npm package 'pino-testkit@10.4.5' (CRITICAL) enables arbitrary code execution. Remove immediately, check for typosquatting, and verify dependencies. https://radar.offseq.com/threat/malicious-code-in-pino-testkit-npm-da4f2d1960e5a45d #OffSeq #npm #SupplyChain
Malicious code in pino-testkit (npm)
The pino-testkit@10.4.5 package is a typosquatting malicious npm package that mimics the legitimate pino logger by copying its package.json metadata and README content. It includes an additional obfuscated file (lib/contract.js) that recons
radar.offseq.com
September 24, 2026 at 7:30 AM