Digital Plumber Plumbing the information age
RSS

Topics

Network Security

Security for network teams: firewall, VPN and SASE vulnerabilities and advisories, zero trust networking and SOC automation.

133stories in the archive
12 up from 7last 7 days · 7 the 7 before
37last 30 days
Jun 11first covered · 2026

Recent activity

Stories per week

Latest stories

10 most recent
  1. The Register · Oct 2, 2026 · Industry news

    Fortinet FortiMail zero-day exploited with federal fix deadline

    Fortinet warned customers to lock down FortiMail after attackers started exploiting a critical CVSS 9.8 bug allowing unauthenticated file writes via crafted HTTP/HTTPS requests. CISA added it to KEV on October 1 with federal mitigation deadline of October 4, 2026.

    Why it matters Email gateway compromise enables mail scanning bypass, communication exfiltration, persistent backdoors, and lateral network pivot—critical for organizations managing perimeter security and incident response.

    Oct 5, 2026 edition

  2. Security Boulevard · Sep 28, 2026 · Industry news

    Two Citrix NetScaler zero-days exploited in default configurations

    CISA added two Citrix NetScaler zero-days (both CVSS 9.5) to KEV after confirming active global exploitation: CVE-2026-88771 is an unauthenticated RCE in default configurations affecting ADC and Gateway, and CVE-2026-88772 is a DTLS VPN memory buffer overflow enabling RCE or denial of service.

    Why it matters Unauthenticated RCE on remote-access edge appliances in default configuration creates immediate perimeter compromise; federal agencies must mitigate by September 30 despite potential downtime from patching.

    Oct 5, 2026 edition

  3. IPSIP Vietnam · Oct 4, 2026 · Industry news

    Cisco SD-WAN Manager authentication bypass exploited in the wild

    Cisco released a fix September 30, 2026 for CVE-2026-76504, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager allowing unauthenticated remote attackers to gain administrator-level access via crafted HTTP requests. Active exploitation confirmed during September 2026.

    Why it matters SD-WAN Manager compromise on the management plane enables attackers to alter network policies, configurations, and device settings across distributed WAN infrastructure in a single attack vector.

    Oct 5, 2026 edition

  4. CISO Platform · Sep 30, 2026 · Analysis

    Cisco SD-WAN Manager zero-day grants unauthenticated admin access

    Cisco published an emergency advisory for CVE-2026-76504 (CVSS 9.8), an unauthenticated authentication bypass in Catalyst SD-WAN Manager API caused by improper URI encoding. Attackers can craft HTTP requests to obtain administrative access to network fabric management without credentials.

    Why it matters SD-WAN Manager compromise equals network-wide routing policy control; this zero-auth, zero-workaround flaw requires immediate inventory and network segmentation until patching completes.

    Oct 4, 2026 edition

  5. SDxCentral · Oct 3, 2026 · Analysis

    Netskope tops Gartner SASE ranking as Palo Alto slips

    Gartner's 2026 Magic Quadrant for SASE Platforms ranks Netskope as leader on execution, with Cato Networks moving to second place and Palo Alto Networks downgraded from top position to third. Evaluations emphasize agentic threat suppression, post-quantum cryptography, and AI-driven operational simplicity.

    Why it matters SASE vendor shifts signal architectural preferences for zero-trust consolidation; operators evaluating platform transitions should prioritize agentic AI and sovereignty controls alongside traditional security capabilities.

    Oct 4, 2026 edition

  6. Cisco Security · Sep 30, 2026 · Primary source

    Cisco warns of October advisories for NX-OS, APIC and Meraki

    Cisco PSIRT will publish security advisories on October 7, 2026 for multiple products including NX-OS, Application Policy Infrastructure Controller, and Meraki, with security hardening releases. Vulnerabilities were discovered using frontier AI models during internal testing.

    Why it matters Advance notice enables network teams to prepare patches for Cisco infrastructure before disclosure; AI-assisted vulnerability discovery signals accelerating attack surface exposure.

    Oct 2, 2026 edition

  7. Unit 42 (Palo Alto Networks) · Sep 30, 2026 · Primary source

    Citrix NetScaler zero-days exploited with 50,000 instances exposed

    On September 27, 2026, Citrix disclosed eight vulnerabilities affecting NetScaler ADC and Gateway, including two critical RCE flaws actively exploited globally. Palo Alto Networks identified 50,277 exposed instances vulnerable to these CVEs as of September 27.

    Why it matters Pre-disclosure attackers exploited these zero-days for 17 days; enterprises must assume compromise on exposed NetScaler appliances and implement forensic response for potential persistence.

    Oct 1, 2026 edition

  8. eSecurity Planet · Sep 30, 2026 · Industry news

    WatchGuard flaw lets rogue VPN servers root Firebox appliances

    WatchGuard disclosed CVE-2026-86131, a critical Fireware vulnerability (CVSS 9.2) allowing attacker-controlled VPN servers to obtain root access to connected Firebox appliances via improper BOVPN over TLS certificate validation.

    Why it matters VPN appliances trusting upstream VPN concentrators as security boundaries become an attack surface; validates defense-in-depth principle for remote access infrastructure.

    Oct 1, 2026 edition

  9. Seceon Inc · Sep 30, 2026 · Vendor release

    Seceon claims unified NDR automates 70% of L1 response

    Seceon OTM delivers unified NDR with agentless DPI, encrypted traffic analysis, and automated response via aiSOAR playbooks, automating ~70% of L1 response actions for network threat detection and SOC automation.

    Why it matters Reduces MTTR and automates firewall blocks, host isolation, and credential blocking for network-based threats—addressing the alert fatigue and manual response bottleneck in SOCs.

    Sep 30, 2026 edition

  10. Security Boulevard · Sep 23, 2026 · Industry news

    Mid-market security teams face 4,000 alerts a day

    Enterprise threat detection increasingly relies on AI, ML, behavioral analytics, and SOAR to process network, endpoint, and identity telemetry—addressing alert volumes exceeding 4,000 alerts per day at mid-market enterprises.

    Why it matters Network security teams must integrate SOC automation and AI-driven detection to process firewall/VPN alerts at scale; manual triage is no longer operationally viable.

    Sep 30, 2026 edition

Coverage history

123 earlier stories

September 2026 34

August 2026 29

July 2026 26

June 2026 34