RWP Ventures // Cyber intelligence
Intelligence for the threats that matter.
Daily and weekly analysis of enterprise cybersecurity, identity, cloud, AI, vulnerabilities, ransomware, nation-state activity, and operational technology.
Today's top intelligence · Daily Top
2026-09-12 · DevOps / Vulnerability
Unauthenticated path traversal in the repository commits API. CISA KEV due 14 September with forensic triage. GitLab.com is patched; self-managed is not.
CONFIRMED GitLab shipped 19.3.2 / 19.2.6 / 19.1.8 on 10 September 2026 for a path traversal in the repository commits API. CVE-2026-85706 is CVSS 3.1 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). An unauthenticated caller can, under the conditions GitLab published, read arbitrary f
Read assessment →
Latest intelligence
Recent Daily Top
Daily Top
GreyNoise measured 395 organizations in 48 countries. PaperCut’s QA’d maintenance releases replace the emergency patches. CISA KEV due 14 September.
2026-09-11
Read →
Daily Top
Talos published three post-compromise clusters on CVE-2026-20079 the same day CISA KEV’d it. Federal due date is 12 September. Patching without forensic triage is not remediation.
2026-09-10
Read →
Daily Top
Microsoft confirmed exploitation of CVE-2026-81963 in the Update Stack and CVE-2026-85880 in ALPC. CISA listed both on 8 September. Patch those first; the haystack is a separate problem.
2026-09-09
Read →
Daily Top
APSB26-146 assigns CVE-2026-75650 to StyleSmuggler, confirms in-the-wild exploitation, and tells merchants to apply VULN-39341 and rotate every credential the encryption key protected.
2026-09-08
Read →
Daily Top
Sansec reports an unauthenticated StyleSmuggler chain on current Magento 2.4.x, including stores that already applied July and August 2026 patches. Adobe has not published a CVE or fix as of 7 September.
2026-09-07
Read →
Daily Top
Microsoft saw Unicode tag characters split words like "funding" so filters missed them — a hunting signature jumped from ~21k hits on 8 February 2026 to 1.3 million the next day.
2026-09-07
Read →
Weekly products
Weekly intelligence
IT threat intelligence
- Enterprise
- Identity
- Cloud
- Vulnerabilities
- Ransomware
- Nation-state activity
Latest
The IT week was RMM, session theft, and a sixth Chrome 0-day — not a quiet Labor Day
31 August–7 September 2026. N-central took four hotfixes in five weeks and a CVSS 10 pre-auth RCE. BigBear 2.0 and Knight Office kept eating Microsoft 365 sessions. Chrome CVE-2026-85046 is in the wild. Magento StyleSmuggler is the storefront story, not the enterprise one.
View IT intelligence →
OT / ICS threat intelligence
- ICS / SCADA
- Industrial control
- Critical infrastructure
- CPS
- Industrial ransomware
Latest
ICS Patch Tuesday hit M580 Safety and Reyrolle. The exploited device this week is a MikroTik, not a PLC.
4–11 September 2026. Schneider CVE-2026-3869 on Modicon M580 and M580 Safety — firmware and application level both required. Siemens SSA-142885 Reyrolle 7SR5 session-ID exposure (CVE-2026-62645, CVSS 9.8) and Industrial Edge Management account takeover (CVE-2026-18963, 9.1). CISA KEV’d two MikroTik RouterOS bugs on 10 September; CERT.PL says the chain has been live since 2 September. No new Stage 2 ICS malware in public reporting this week.
View OT intelligence →
Intelligence domains
Browse by domain
RWP Ventures
Intelligence informs execution.
RWP Intelligence publishes defensive analysis. RWP Ventures helps organizations assess, architect, implement, and operate cybersecurity and technology programs — principal-led, threat-informed, documented against the frameworks boards and auditors expect.
OT Atlas
Open OT knowledge
Open, vendor-neutral defensive knowledge for operational technology and cyber-physical systems, supporting the OT practice at RWP Ventures.
Explore OT Atlas ↗