Here we post vulnerability research, honeypot field reports and open-source tools. Open to collaboration.
offseq.com/en/
#InfoSec #PenTest #RedTeam
Here we post vulnerability research, honeypot field reports and open-source tools. Open to collaboration.
offseq.com/en/
#InfoSec #PenTest #RedTeam
deployments should patch immediately while reviewing logs for indicators of compromise.
Source: [OffSeq](https://radar.offseq.com/threat/arista)
## 5. Meta Muse Mac Zero-Day: Token Hijacking Risk
deployments should patch immediately while reviewing logs for indicators of compromise.
Source: [OffSeq](https://radar.offseq.com/threat/arista)
## 5. Meta Muse Mac Zero-Day: Token Hijacking Risk
be patched immediately. Active exploitation has been confirmed in the wild.
Source: [OffSeq](https://radar.offseq.com/threat/cisco-warns)
## 4. Arista VeloCloud Orchestrator Zero-Day Under Active Exploitation
be patched immediately. Active exploitation has been confirmed in the wild.
Source: [OffSeq](https://radar.offseq.com/threat/cisco-warns)
## 4. Arista VeloCloud Orchestrator Zero-Day Under Active Exploitation
affected Android devices.
- https://infosec.exchange/@offseq/117279544153085501
affected Android devices.
- https://infosec.exchange/@offseq/117279544153085501
https://infosec.exchange/@offseq/117285914298082330
- https://infosec.exchange/@offseq/117285207237888691
## 3. Cisco Secure Email Gateway Zero-Day Vulnerability (Critical)
Cisco Secure Email Gateway is affected by a critical zero-day vulnerability that is
https://infosec.exchange/@offseq/117285914298082330
- https://infosec.exchange/@offseq/117285207237888691
## 3. Cisco Secure Email Gateway Zero-Day Vulnerability (Critical)
Cisco Secure Email Gateway is affected by a critical zero-day vulnerability that is
SIGABRT events.
Source: [HackRead](https://hackread.com/f5-breach-so), [OffSeq](https://radar.offseq.com/threat/critical-f5-big-ip-apm-rce-zero-day)
## 3. Cisco ISE Authentication Bypass — Actively Exploited Zero-Day (CVE-2026-76460)
SIGABRT events.
Source: [HackRead](https://hackread.com/f5-breach-so), [OffSeq](https://radar.offseq.com/threat/critical-f5-big-ip-apm-rce-zero-day)
## 3. Cisco ISE Authentication Bypass — Actively Exploited Zero-Day (CVE-2026-76460)
same network segment. ViewSonic has not yet released a patch; users are advised to segment and monitor affected systems.
Source: [OffSeq](https://radar.offseq.com/threat/082989)
## 7. Revolut Customers Hit by Second Data Breach in September
same network segment. ViewSonic has not yet released a patch; users are advised to segment and monitor affected systems.
Source: [OffSeq](https://radar.offseq.com/threat/082989)
## 7. Revolut Customers Hit by Second Data Breach in September
5.2.3.16 and 6.4.2.8) allows attackers to access privileged functions without credentials. Immediate patching is essential, and administrators should review system logs for any signs of compromise.
https://infosec.exchange/@offseq/117319534208953341
## 7. Meta
5.2.3.16 and 6.4.2.8) allows attackers to access privileged functions without credentials. Immediate patching is essential, and administrators should review system logs for any signs of compromise.
https://infosec.exchange/@offseq/117319534208953341
## 7. Meta
`copy_msg_element` function in the Device Discovery Service. No patch exists; users are advised to restrict access immediately. An offseq post confirms public exploit code.
`copy_msg_element` function in the Device Discovery Service. No patch exists; users are advised to restrict access immediately. An offseq post confirms public exploit code.
immediate risk to organizations managing network access control.
Sources: [OffSeq](https://radar.offseq.com/threat/cisco-warns-actively-exploited-ise-auth-bypass/), [Bluesky @offseq.bsky.social](https://infosec.exchange/@offseq/117285914298082330)
4. **CISA
immediate risk to organizations managing network access control.
Sources: [OffSeq](https://radar.offseq.com/threat/cisco-warns-actively-exploited-ise-auth-bypass/), [Bluesky @offseq.bsky.social](https://infosec.exchange/@offseq/117285914298082330)
4. **CISA
CVSS 9.4. Both have public exploits and no patches are available. Restricting network access to these devices is the only mitigation for now.
Sources: [OffSeq #1](https://radar.offseq.com/threat/cve-2026-94100-buffer-overflow-in-), [OffSeq
CVSS 9.4. Both have public exploits and no patches are available. Restricting network access to these devices is the only mitigation for now.
Sources: [OffSeq #1](https://radar.offseq.com/threat/cve-2026-94100-buffer-overflow-in-), [OffSeq