Pinned Tweet
Easter holidays and a Fortinet 0-day - a match made in heaven 🐰 (also my first credited CVE 😇)
🚨 New Fortinet vulnerability being exploited as an 0-day CVE-2026-35616 - FortiClient EMS pre-authentication API access bypass - CVSS 9.1 Critical After observing in-the-wild exploitation of this vulnerability earlier this week, Defused reported it to Fortinet under responsible disclosure. Fortinet has released an emergency hotfix - plus a scheduled patch - for FortiClient EMS 7.4.5 and 7.4.6. The vulnerability allows an unauthenticated attacker to bypass API authentication and authorization entirely, unauthorized code or commands via crafted requests. This discovery was made through our upcoming Radar feature launching next week 😇 Advisory: fortiguard.com/psirt/FG-IR-2… Track exploitation of this and other Fortinet vulns in real time and get updates on the new Defused Radar 👉 console.defusedcyber.com/sig… Credit also to @heckintosh_ for independently discovering this vulnerability 💪
5
15
113
38,775
Google / Mandiant linked this activity to ShinyHunters! cloud.google.com/blog/topics…
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
2
8
28
2,583
Simo retweeted
timely. I wonder what news about Oracle PeopleSoft made some threat actors hone in on this vuln's capabilities???
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
2
9
36
3,511
🍯🍯🍯
🚨 We are seeing elevated Oracle PeopleSoft (CVE-2026-35273 / PSEMHUB RCE) activity in our honeypots since Sep 22 UTC, including simple WAF bypass attempts against the standard path-block mitigation. Source IPs and the full indicators are available on Defused Radar. console.defusedcyber.com/sig…
5
13
2,175
Super cool joint effort between @DefusedCyber and @Horizon3Attack in implementing pre-emptive honeypots for yet to be publicized vulns 👇 Many thanks to @hacks_zach 🙏
Today we are disclosing the technical details of CVE-2026-9586, a SQLi-to-RCE in #Sangoma #Switchvox which we reported in April 2026. On 30 Aug 2026, we received honeypot alerts of valid exploitation attempts across multiple internet sensors deployed in coordination with @DefusedCyber. Check out the details and IoCs in our latest blog: horizon3.ai/attack-research/…
5
14
1,840
🚨 We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29th) An actor is abusing the auth bypass to hijack PaperCut's external user-lookup. Unlike the RCE path in public writeups, the actor goes for data theft - dumping DB tables via Derby ⚠️We haven't yet verified whether the exfil route is a working one Track emerging Papercut MF exploit activity 👉 console.defusedcyber.com/sig…
29
1,839
Papercut stuff starting to happen 👀
2
17
1,223
70% of the interesting stuff happens on the weekend these days 😮‍💨😮‍💨
🚨 We're seeing CVE-2026-32566 (Wordpress ACPT Pro, CVSS 9.8) exploited in our honeypots - a day after disclosure The unauth WordPress admin-creation vulnerability was exploited using two different routes (via REST and admin-ajax) by a single actor. The rogue admin's password was set to "solevisible" which links to ALFA-Shell, a WordPress webshell that's circulated for years. Full details on Defused Radar 👉 console.defusedcyber.com/rad…
1
3
25
2,827
hunny hunny 🍯
🚨 We're seeing the SharePoint CVE-2026-55040 + CVE-2026-63520 RCE chain probed in our honeypots The JWT bypass (55040) was exercised, followed by heavy admin enumeration and probing of the Business Data Catalog sink behind CVE-2026-63520. No code execution observed yet Chain writeup published yesterday by @VulnCheckAI Full details on Defused Radar 👉 console.defusedcyber.com/rad…
1
4
22
2,914
😮‍💨 the fun never ends
🚨 Exploit activity continues high over the weekend, with new recon activity on the horizon 1. A FortiSandbox endpoint (a VM-provisioning / VNC-start route that appears in none of the 2026 FortiSandbox advisories) saw attempted exploitation on our decoys - added to Defused Radar 2. First in-the-wild exploitation of the Citrix NetScaler pre-auth RCE from @watchtowrcyber (CVE-2026-8452) hit Defused EX customer sensors Sunday morning. Public writeup was released on Friday 3. A multi-vendor edge-VPN enumeration sweep hit across our honeypot fleet - FortiGate, GlobalProtect, SonicWall, Citrix, Ivanti, Cisco - spraying product-specific login probes at every sensor. Activity originates from known malicious ASNs Stay on top of acute exploit activity 👉console.defusedcyber.com/sig…
2
2
12
2,210
Featuring @DefusedCyber 🍯
Max severity SAP Commerce Cloud flaw now targeted in attacks bleepingcomputer.com/news/se… bleepingcomputer.com/news/se…
1
1
12
1,523
Simo retweeted
🚨 First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots - 3 days after patch day. This vulnerability has no public PoC and is not known to be exploited. View the full payload 👉console.defusedcyber.com/sig…
1
17
71
11,338
You can set up tripwires in @DefusedCyber which alert you when certain paths get exploited 🍯
You're back in the room, trapped with us - and a Citrix NetScaler Pre-Auth RCE (CVE-2026-8452) Enjoy... labs.watchtowr.com/youre-bac…
1
10
984
Featuring @DefusedCyber 👁️👅👁️
Hackers leverage new Microsoft SharePoint exploit in attacks bleepingcomputer.com/news/mi… bleepingcomputer.com/news/mi…
1
1
8
962
Simo retweeted
A lot to do with your honeypot: collect POC/exploit, IoC, follow campaigns and more..it has a very high value ...because this is where things happens for real! Thanks to @DefusedCyber @SimoKohonen for the amazing job there, too underrated I gess, from both Offensive and Defensive guys
🚨 Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots The vulnerability is a Microsoft SharePoint JWT auth bypass for which Rapid7 published a technical writeup and proof-of-concept code yesterday. Track it live 👉 console.defusedcyber.com/sig…
1
4
15
2,648
🍯🍯🍯🍯
🚨 Attackers are now using the @rapid7 POC for CVE-2026-55040 against our SharePoint honeypots The vulnerability is a Microsoft SharePoint JWT auth bypass for which Rapid7 published a technical writeup and proof-of-concept code yesterday. Track it live 👉 console.defusedcyber.com/sig…
1
7
836
Simo retweeted
⚠️We are observing a spike in scanning against VMware vCenter Our honeypots are logging increased fingerprinting - such as version probes via POST /sdk/ (RetrieveServiceContent) and walks of the /websso SAML SSO flow - coinciding with Broadcom's VMSA-2026-0006 (CVE-2026-59309, unauth auth-bypass in vmdir, CVSS 9.8). Track VMWare vCenter activity now -> console.defusedcyber.com/sig…
2
20
65
7,110
Defused Freemium has been absolutely useless for months now, finally got around to fixing that 😅
❗️New: all verified users can now start a 14-day full-access trial of Defused - no strings attached. Existing freemium users included. Sign up today 👉 console.defusedcyber.com/sig…
2
3
8
1,935
Updates next week 🙌
The past 6 months have been a crazy time for @DefusedCyber . That said, I've been running the platform with a "beta" mindset - very quickly implementing somewhat half-baked ideas, which have yielded good results but also left the platform slightly disjointed in places. However, the vision where to take the platform is quite clear now, and the remainder of June will both accelerate that vision and also mark the closing of the beta stage, hopefully removing all of the ridiculous UI and UX snafus still lingering in the platform. Got some really wild expanses coming, plus a completely renewed free offering. Stay tuned and LFG!
1
6
828
“End-to-end autonomous” is utter bullshit unless Hugging Face has the attacker-side traces. Victim telemetry can show that an attack was highly automated. It cannot prove that no human was steering, restarting, redirecting or selecting successful runs behind the scenes. Did the attackers hand over their prompts and execution logs? Did they explain the setup over coffee? Probably not. So provide the proof, or shut the fuck up and stop pushing an AI marketing narrative as established fact. @XciD_ @OpenAI
One thing about this OpenAI / Hugging Face incident really bothers me. Hugging Face says the intrusion was driven “end to end” by an autonomous AI agent system. But how do they actually know that? Victim-side telemetry can show automation, speed, thousands of actions, short-lived sandboxes, changing infrastructure etc. It cannot show what happened upstream. It cannot tell us whether humans changed prompts, restarted runs, selected successful paths, provided more context, redirected agents or manually helped at certain points. We also don’t know what was actually decided by a model and what was simply automated by the surrounding agent framework. Maybe OpenAI has all those traces. Fine. Then publish them. Show the prompts, tool calls, failed runs, model handoffs, restarts and human interventions. Without that, “end-to-end autonomous” is a claim, not a proven technical finding. The forensic-refusal dataset Hugging Face published proves something much smaller: huggingface.co/datasets/hugg… It shows that Claude refused to analyze one small Python backdoor while GLM 5.2 completed the analysis. That is a valid example of hosted-model guardrails getting in the way of incident response. But this is not evidence that the intrusion itself was carried out end to end by an autonomous agent. And this claim matters because it pushes a very specific idea into people’s heads: AI agents can now independently find zero-days, escape sandboxes, move laterally, steal credentials and compromise companies. Then comes the second part of the story: Hugging Face used local AI models to investigate the AI attacker “at machine speed”. So the message basically becomes: - AI attacked us - AI helped save us - Therefore, everyone needs more AI Come on 🙄 Weak isolation, excessive privileges, poor credential boundaries, insufficient segmentation and far too much blast radius. You don’t need an AI defender to fix those things. Even fairly basic controls like rate limits and temporary blocks across source IPs, accounts, tokens and job volume could have throttled at least parts of this activity and created a very obvious signal for an analyst to review. Add proper egress restrictions, isolated workers and credentials that do not open the door to production clusters .. none of this requires an LLM Using a local model to analyze 17,000 events may have helped during the investigation. Good - I’m not questioning that. But that happened after the compromise. What I really hate is that something which would have been an embarrassment ten years ago is now repackaged as a capability demo, a heroic AI-vs-AI story and a marketing pitch. Maybe the attack really was fully autonomous. Then show the evidence. Until then, I don’t think this claim should be repeated as if it had already been proven. Sources nitter.net/OpenAI/status/20796589… nitter.net/XciD_/status/207967807… huggingface.co/datasets/hugg…
12
26
192
15,410