NATHANIELPETTUSCYBER INTELLIGENCE
NEW POST DAILY
DAILY CYBER BLOG · FACTS + OPINION

Know what happened.
Know where I stand.

I explain cybersecurity news, active attacks, privacy, surveillance technology, vulnerabilities, and OSINT in plain English, then give my independent analysis.

GLOBAL THREAT ACTIVITYPREVIEW
World map preview with representative activity markersNorth AmericaEuropeMiddle EastEast AsiaOceania
Representative preview—not live observations. Open the Live Threat Center for sourced data and map limitations.
LIVE THREAT FEED

Actively exploited vulnerabilities

Current entries from CISA’s official Known Exploited Vulnerabilities catalog. These are confirmed weaknesses attackers have used, not simulated attack-map traffic.

REFRESHES EVERY 15 MINUTES
ACTIVE EXPLOITATION

CVE-2026-5430: WSO2 Multiple Products

WSO2 Multiple Products Path Traversal Vulnerability

WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.
ACTIVE EXPLOITATION

CVE-2026-71362: Adobe Commerce and Magento

Adobe Commerce and Magento Incorrect Authorization Vulnerability

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
ACTIVE EXPLOITATION

CVE-2026-93952: Arista VeloCloud Orchestrator

Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
ACTIVE EXPLOITATION

CVE-2026-94127: F5 BIG-IP APM

F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
ACTIVE EXPLOITATION

CVE-2026-93616: Check Point Multiple Products

Check Point Multiple Products Path Traversal Vulnerability

Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.
ACTIVE EXPLOITATION

CVE-2026-85102: Check Point Multiple Products

Check Point Multiple Products Improper Certificate Validation Vulnerability

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
VIEW THE OFFICIAL CISA CATALOG

“Live” means the feed updates from current public reporting. It does not identify every attack or prove the physical location of an attacker.

CHOOSE WHAT YOU NEED

You do not need a cybersecurity background.

Each section answers a different question. Start with the one that sounds most useful to you.

LATEST BLOG POST

The newest story, explained and analyzed.

IMPORTANT UPDATE

474 leaked GitHub App private keys still worked, exposing supply-chain risk

GitGuardian found that 474 publicly leaked GitHub App private keys still authenticated, including keys with repository-write and organization-admin permissions. A CDC-linked key was revoked after disclosure, and no malicious use has been publicly confirmed.

READ THE FULL POST & OPINION
HOW POSTS ARE ORGANIZED

Every post separates reporting from opinion.

  1. 1What happened?A clear summary of confirmed facts.
  2. 2How does it work?Technical context without unnecessary jargon.
  3. 3My analysisA direct opinion, clearly labeled.
  4. 4What should happen next?Practical action and accountability.