Managed Honeypots for Early-warning Threat Intelligence 🍯 Sign up today for a 14-day trial: console.defusedcyber.com/sig…

Pinned Tweet
🚨 New Fortinet vulnerability being exploited as an 0-day CVE-2026-35616 - FortiClient EMS pre-authentication API access bypass - CVSS 9.1 Critical After observing in-the-wild exploitation of this vulnerability earlier this week, Defused reported it to Fortinet under responsible disclosure. Fortinet has released an emergency hotfix - plus a scheduled patch - for FortiClient EMS 7.4.5 and 7.4.6. The vulnerability allows an unauthenticated attacker to bypass API authentication and authorization entirely, unauthorized code or commands via crafted requests. This discovery was made through our upcoming Radar feature launching next week 😇 Advisory: fortiguard.com/psirt/FG-IR-2… Track exploitation of this and other Fortinet vulns in real time and get updates on the new Defused Radar 👉 console.defusedcyber.com/sig… Credit also to @heckintosh_ for independently discovering this vulnerability 💪
11
112
361
82,241
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
7
13
85
11,893
Defused retweeted
On August 30, @DefusedCyber honeypots detected valid exploitation attempts against the vulnerability. The observed attacker used command execution, followed by additional enumeration and exfiltration activity.
1
2
5
301
In May, we deployed Switchvox honeypots in coordination with @Horizon3Attack, anticipating that their newly reported vulnerabilities would eventually be exploited. On August 30, they were. Our sensors caught the first known in-the-wild exploitation attempts against CVE-2026-9586 (unauthenticated SQLi → RCE, patched in 8.4.0.2) - the same actor hitting multiple honeypots in quick succession, which suggests broad targeting of the ~4,000 internet-exposed instances. Check out the Horizon3 blog post for the full technical analysis 👇
Today we are disclosing the technical details of CVE-2026-9586, a SQLi-to-RCE in #Sangoma #Switchvox which we reported in April 2026. On 30 Aug 2026, we received honeypot alerts of valid exploitation attempts across multiple internet sensors deployed in coordination with @DefusedCyber. Check out the details and IoCs in our latest blog: horizon3.ai/attack-research/…
1
6
16
1,963
🚨 We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th) An actor is abusing the auth bypass to hijack PaperCut's external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft - dumping DB tables via Derby ⚠️We haven't yet verified whether the exfil route is a working one Track emerging Papercut MF exploit activity 👉 console.defusedcyber.com/sig…
2
12
65
7,526
🚨 We're seeing CVE-2026-32566 (Wordpress ACPT Pro, CVSS 9.8) exploited in our honeypots - a day after disclosure The unauth WordPress admin-creation vulnerability was exploited using two different routes (via REST and admin-ajax) by a single actor. The rogue admin's password was set to "solevisible" which links to ALFA-Shell, a WordPress webshell that's circulated for years. Full details on Defused Radar 👉 console.defusedcyber.com/rad…
1
16
61
7,849
🚨 We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520. No code execution observed yet Chain writeup published yesterday by @VulnCheckAI Full details on Defused Radar 👉 console.defusedcyber.com/rad…
9
47
5,642
Defused retweeted
A critical SAP Commerce Cloud flaw was exploited just three days after patching, according to @DefusedCyber, highlighting how quickly attackers are moving against enterprise vulnerabilities. #cybersecurity #CISO #infosec bit.ly/4wGFmaD
1
1
5
1,134
🚨 Exploit activity continues high over the weekend, with new recon activity on the horizon 1. A FortiSandbox endpoint (a VM-provisioning / VNC-start route that appears in none of the 2026 FortiSandbox advisories) saw attempted exploitation on our decoys - added to Defused Radar 2. First in-the-wild exploitation of the Citrix NetScaler pre-auth RCE from @watchtowrcyber (CVE-2026-8452) hit Defused EX customer sensors Sunday morning. Public writeup was released on Friday 3. A multi-vendor edge-VPN enumeration sweep hit across our honeypot fleet - FortiGate, GlobalProtect, SonicWall, Citrix, Ivanti, Cisco - spraying product-specific login probes at every sensor. Activity originates from known malicious ASNs Stay on top of acute exploit activity 👉console.defusedcyber.com/sig…
1
7
30
6,973
محاولات استغلال ثغرة حرجة في منصة @SAP Commerce Cloud، وذلك عقب ثلاثة أيام من إصدار التحديث الأمني لشهر أغسطس، وفق تقرير @DefusedCyber . تستهدف الثغرة ملحق Data Hub Adapter وتتيح للمهاجمين تجاوز آليات المصادقة والتحقق، وإرسال مدخلات خبيثة للوصول إلى مكونات داخلية حساسة.
1
1
10
1,219
🚨 First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots - 3 days after patch day. This vulnerability has no public PoC and is not known to be exploited. View the full payload 👉console.defusedcyber.com/sig…
1
17
71
11,328
Defused retweeted
You can set up tripwires in @DefusedCyber which alert you when certain paths get exploited 🍯
You're back in the room, trapped with us - and a Citrix NetScaler Pre-Auth RCE (CVE-2026-8452) Enjoy... labs.watchtowr.com/youre-bac…
1
10
979
Defused retweeted
Sharepoint baddies in the honeypots at @DefusedCyber coming in from: 205.147.17.6 abusing the vulnerability from CVE-2026-55040

ALT Happy New Year Honey GIF

5
33
3,594
Defused retweeted
A lot to do with your honeypot: collect POC/exploit, IoC, follow campaigns and more..it has a very high value ...because this is where things happens for real! Thanks to @DefusedCyber @SimoKohonen for the amazing job there, too underrated I gess, from both Offensive and Defensive guys
🚨 Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots The vulnerability is a Microsoft SharePoint JWT auth bypass for which Rapid7 published a technical writeup and proof-of-concept code yesterday. Track it live 👉 console.defusedcyber.com/sig…
1
4
15
2,648
🚨 Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots The vulnerability is a Microsoft SharePoint JWT auth bypass for which Rapid7 published a technical writeup and proof-of-concept code yesterday. Track it live 👉 console.defusedcyber.com/sig…
12
53
8,443
⚠️We are observing a spike in scanning against VMware vCenter Our honeypots are logging increased fingerprinting - such as version probes via POST /sdk/ (RetrieveServiceContent) and walks of the /websso SAML SSO flow - coinciding with Broadcom's VMSA-2026-0006 (CVE-2026-59309, unauth auth-bypass in vmdir, CVSS 9.8). Track VMWare vCenter activity now -> console.defusedcyber.com/sig…
2
20
65
7,106
❗️New: all verified users can now start a 14-day full-access trial of Defused - no strings attached. Existing freemium users included. Sign up today 👉 console.defusedcyber.com/sig…
1
11
3,745
Defused retweeted
Updates next week 🙌
The past 6 months have been a crazy time for @DefusedCyber . That said, I've been running the platform with a "beta" mindset - very quickly implementing somewhat half-baked ideas, which have yielded good results but also left the platform slightly disjointed in places. However, the vision where to take the platform is quite clear now, and the remainder of June will both accelerate that vision and also mark the closing of the beta stage, hopefully removing all of the ridiculous UI and UX snafus still lingering in the platform. Got some really wild expanses coming, plus a completely renewed free offering. Stay tuned and LFG!
1
6
828