Sign in

Modat

@modat-io.bsky.social
42 followers 9 following 70 posts

European Internet Intelligence Company. Understand the intent behind internet infrastructure before it is weaponised. Check it out on modat.io

PostsRepliesMedia
Modat @modat-io.bsky.social · 28/09/2026
CVE-2026-88771 & CVE-2026-88772 (CVSS 9.5, CISA KEV): two Citrix NetScaler RCE zero-days exploited before a patch existed. 88771 hits default configs unauthenticated. Upgrade to 14.1-73.37 / 13.1-64.23. Query: (product~"Citrix NetScaler") and last_seen>-7D
000
Modat @modat-io.bsky.social · 18/09/2026
New in Modat Magnify: 1. Free text search: one term, 11 fields at once 2. Richer host detail view: ASN, netblock and location for any IP 3. Facets you can add, remove and reorder Fewer steps from indicator to infrastructure. magnify.modat.io/docs
000
Modat @modat-io.bsky.social · 25/08/2026
CVE-2026-21962 (CVSS 10.0, CISA KEV): unauth attackers gain complete data access via Oracle HTTP Server & WebLogic Proxy Plug-Ins. Apply Oracl’s January Patch. 3-day CISA deadline. Query: magnify.modat.io/search?query...
000
Modat @modat-io.bsky.social · 24/08/2026
CVE-2026-66915 (CVSS 10.0): unauth RCE in Fabrik for Joomla via the calc element. Affects 1.0.0-4.6.8; 4.6.7 & 4.6.8 did NOT fix it. Update to 4.7.2. Query: (fingerprints.technologies.name="Joomla" or web.html~"Joomla! - Open Source Content Management") and fingerprints.tags!="Honeypot"
010
Modat @modat-io.bsky.social · 20/08/2026
A joint US advisory this week warned of AI-generated exploits targeting Siemens S7 PLCs. We checked how many are actually exposed. 7,435 S7 services online, 77 countries, all on the port the advisory names. Six are fail-safe safety controllers. modat.io/blog/siemens...
000
Modat @modat-io.bsky.social · 05/08/2026
CVE-2026-58048 (CVSS 9.4): cPanel & WHM DB privilege-escalation flaw lets an authenticated MySQL user run SQL as database root, risking OS-level compromise. Affects all versions + WP Squared. Patch now. Query: technology="cPanel" or web.title~"WP Squared Login" or web.headers~"whostmgrrelogin"
010
Modat @modat-io.bsky.social · 30/07/2026
CVE-2026-20316 (CISA KEV): static credentials for a low-priv account in Cisco Secure FMC let an unauthenticated attacker log in & read sensitive data. Exploited as a zero-day, chainable with CVE-2026-20079 (CVSS 10.0) for root access. Patch now. Query: product="Cisco FDM"
000
Modat @modat-io.bsky.social · 20/07/2026
⚠️ CVE-2026-6875 (Critical): pre-auth sandbox-escape RCE in ServiceNow AI Platform lets unauthenticated attackers run code. Patched July 13; reports of in-the-wild exploitation. Update now, prioritise self-hosted. Query: technology="ServiceNow"
000
Modat @modat-io.bsky.social · 18/07/2026
⚠️ wp2shell (CVE-2026-63030, CVSS 9.8): pre-auth RCE in WordPress core via the REST batch API (batch/v1), on by default & reachable unauthenticated. Works on a stock install, no plugins. Affects 6.9.0–6.9.4 & 7.0.0–7.0.1. Update to 6.9.5/7.0.2 now. Query: technology="WordPress"
000
Modat @modat-io.bsky.social · 16/07/2026
⚠️ F5 patched 3 memory-safety flaws in NGINX incl. CVE-2026-42533 (CVSS 9.2) is a heap overflow via the map directive that crafted HTTP requests can trigger, with possible code exec if ASLR is off; plus an SSI use-after-free & a slice memory leak. Upgrade now to 1.31.3. Query: technology="Nginx"
000
Modat @modat-io.bsky.social · 15/07/2026
CVE-2026-56164 (CISA KEV): unauthenticated privilege escalation in on-prem Microsoft SharePoint, chained in the wild to RCE, IIS key theft & persistence. Exploited a zero-day in Microsoft's record July Patch Tuesday. Patch now & enable AMSI Full Mode. Query: technology="Microsoft SharePoint"
000
Modat @modat-io.bsky.social · 15/07/2026
CVE-2026-44747 (CVSS 9.9): out-of-bounds write in SAP NetWeaver AS ABAP allows an authenticated attacker to trigger memory corruption, risking data access, modification, or DoS. Patched in SAP's July 2026 Security Patch Day. Install the fixed ABAP Kernel now. Query: product="SAP NetWeaver"
000
Modat @modat-io.bsky.social · 08/07/2026
⚠️ Ubiquiti Security Advisory Bulletin 066: 25 vulnerabilities across the UniFi ecosystem (OS, Network, Protect, Access, Talk, Connect). Several critical, up to CVSS 10.0 (CVE-2026-50746, UniFi Connect). Update per advisory. Query: web.title~"UniFi OS"
000
Modat @modat-io.bsky.social · 02/07/2026
⚠️ CVE-2026-45659 (CVSS 8.8, CISA KEV): deserialization flaw in Microsoft SharePoint letting an authenticated attacker with Site Member permissions run code remotely, no user interaction. Actively exploited. Affects SharePoint 2016, 2019 & Sub Edition. Query: technology="Microsoft SharePoint"
000
Modat @modat-io.bsky.social · 24/06/2026
⚠️ Squidbleed (CVE-2026-47729, CVSS 6.5): a flaw in Squid's FTP parser that can leak another user's cleartext HTTP request, including credentials, to someone already using the same proxy. Upgrade and verify the patch, or disable FTP. Query: technology="Squid Proxy"
000
Modat @modat-io.bsky.social · 23/06/2026
⚠️ DifyTap: 4 Dify vulnerabilities that could expose AI conversations and files across tenants under certain conditions. Two require no auth. Highest-rated is CVE-2026-41948 (CVSS 9.4). Fixed in 1.14.2, except CVE-2026-41948 (next release). Query: product=dify
000
Modat @modat-io.bsky.social · 17/06/2026
𝐒𝐭𝐚𝐝𝐢𝐮𝐦 𝐨𝐟 𝐒𝐡𝐚𝐝𝐨𝐰𝐬: 𝐈𝐧𝐬𝐢𝐝𝐞 𝐭𝐡𝐞 𝐈𝐏𝐓𝐕 𝐏𝐢𝐫𝐚𝐜𝐲 𝐖𝐨𝐫𝐥𝐝 The FIFA World Cup is the largest demand event illegal IPTV has ever faced. In the days around kickoff, our research team set out to map the infrastructure behind it. Full field report on the Modat research blog: www.modat.io/post/stadium...
000
Modat @modat-io.bsky.social · 11/06/2026
CVE-2026-35273: Unauthenticated RCE in Oracle PeopleSoft PeopleTools (8.61, 8.62) via the Environment Management component. Remotely exploitable with no credentials, can lead to full system compromise. Patch immediately. Query: web.html~"Please click here to PeopleSoft logon page"
000
Modat @modat-io.bsky.social · 09/06/2026
⚠️ CISA added CVE-2026-42271 to KEV: Command injection in LiteLLM gateway (1.74.2–1.83.7). MCP preview endpoints spawn attacker commands on the proxy host, gated only by an API key, so any authenticated user gets command execution. Patch to 1.83.7+. Query: product="LiteLLM API" OR product="LiteLLM"
000
Modat @modat-io.bsky.social · 09/06/2026
We mapped 973,819 internet-exposed video services. 8,074 were streaming live with no password: thermal sensors on high-voltage equipment, server rooms, feeds in conflict zones. Not just a camera problem. Full research: www.modat.io/post/exposed...
000
Modat @modat-io.bsky.social · 04/06/2026
⚠️CVE-2024-21182: Oracle WebLogic Server unauthenticated access via T3/IIOP now actively exploited & added to CISA KEV. Affects 12.2.1.4.0 & 14.1.1.0.0. Patch immediately or block port 7001. Query: web.headers~"WebLogic Server"  magnify.modat.io
000
Modat @modat-io.bsky.social · 20/05/2026
⚠️ Drupal announced an upcoming highly critical core security release (PSA-2026-05-18) affecting supported Drupal 10 & 11 branches. Details remain undisclosed, but exploits may emerge within hours of release. Reserve emergency patching time for May 20. Query: technology="Drupal"
000
Modat @modat-io.bsky.social · 19/05/2026
⚠️ CVE-2026-42945 (CVSS 9.2): NGINX heap overflow in ngx_http_rewrite_module (≤1.30.0) is actively being exploited in the wild. Crafted HTTP requests via rewrite/if/set PCRE “?” can crash workers and may lead to RCE (ASLR off). Patch now to Nginx 1.31.0 or 1.30.1. Query: technology="Nginx"
000
Modat @modat-io.bsky.social · 14/05/2026
⚠️ CVE-2026-44578: SSRF in self-hosted Next.js via the WebSocket upgrade handler allows unauthenticated access to internal services & cloud metadata endpoints using crafted absolute-form HTTP requests. Affected: 13.4.13+ to <15.5.16 / <16.2.5. Query: technology="Next.js"  Platform: magnify.modat.io
000
Modat @modat-io.bsky.social · 12/05/2026
️⚠ CVE-2026-7482: Critical heap out-of-bounds read in Ollama via crafted GGUF uploads to /api/create may leak API keys, prompts, credentials & conversation data from process memory. Affected: <0.17.1. Patch now. Query: product="Ollama"  The platform:  magnify.modat.io
100
Modat @modat-io.bsky.social · 06/05/2026
⚠️ CVE-2026-23918: Double free in Apache HTTP Server 2.4.66 HTTP/2 may allow unauth RCE via crafted requests, risking full server compromise. Update to 2.4.67 or disable HTTP/2/restrict access. Query: web.headers="Server: Apache/2.4.66"  The platform: magnify.modat.io
000
Modat @modat-io.bsky.social · 04/05/2026
⚠️CVE-2025-71284 Synway SMG RCE via en/9-2radius.php(CVSS 9.8). Sed injection via radius_address+POST params enables unauth RCE. No patch. Query: (web.title="IPPBX" or web.html~"synwayjs") OR (web.html~"text ml10 mr20" and (web.title="网关管理软件" or web.title~"Gateway Management")) and tag!="Honeypot"
000
Modat @modat-io.bsky.social · 30/04/2026
‼️CVE-2026-41940: cPanel & WHM Authentication Bypass (CVSS 9.8 Critical)  A critical authentication bypass has been discovered in cPanel & WHM. Modat Magnify Query:  (technology="cPanel" or web.html~"/cPanel_magic_revision_" or web.headers~"whostmgrrelogin") and tag!=honeypot
001
Modat @modat-io.bsky.social · 30/04/2026
New Modat research: Belastingdienst-themed phishing hitting Dutch taxpayers, mostly aimed at crypto wallets.  Notable shift: attackers ditching backends for direct Telegram bot exfil. Full research: www.modat.io/post/phishin...
000
Modat @modat-io.bsky.social · 15/04/2026
Focusing on Iran's "blackout" misses the bigger picture.  New research across 8 countries. Three strategies: mediation, deception, stabilisation. None of them silence.  Read full research: www.modat.io/post/beyond-...
000
Modat @modat-io.bsky.social · 14/04/2026
⚠️CVE-2026-34486: Fail-open regression in Tomcat Tribes may lead to unauth RCE. If TCP/4000 is reachable & gadget classes exist on the classpath, unencrypted packets can trigger code execution via bypassed encryption. Affected: 11.0.20, 10.1.53, 9.0.116. Update now! Query: technology="Apache Tomcat"
000
Modat @modat-io.bsky.social · 10/04/2026
New research by Modat & Recorded Future reveals how attackers automate defense evasion in a modular cryptomining campaign. Explore the findings: www.modat.io/post/neutral...
000
Modat @modat-io.bsky.social · 08/04/2026
⚠️ CVE-2026-33032 (CVSS 9.8) in Nginx UI ≤2.3.5 allows unauthenticated takeover via exposed /mcp_message endpoint (missing auth + fail-open IP whitelist). Attackers can control configs & service. No patch, restrict access now. Query: web.title~"nginx ui"
000
Modat @modat-io.bsky.social · 24/03/2026
Citrix fixed CVE-2026-3055 (9.3) & CVE-2026-4368 (7.7) in NetScaler ADC/Gateway. A memory overread may leak data and a race condition can cause session mix-up. Check - (SAML IdP / Gateway / AAA). Query: product="Citrix Gateway" OR product="Citrix ADC" OR web.title~"NetScaler Gateway" tag!=honeypot
000
Modat @modat-io.bsky.social · 19/03/2026
⚠️ CISA added CVE-2025-66376 to KEV after active exploitation of Zimbra Collaboration Suite. A stored XSS in the Classic UI allows script injection via HTML emails; opening them can trigger in-session execution and enable mailbox access or session hijacking. Query: product="Zimbra Collaboration"
010
Modat @modat-io.bsky.social · 12/03/2026
⚠️️ CISA added CVE-2025-68613 (CVSS 10.0) to KEV. Together with CVE-2026-27577 & CVE-2026-27493, n8n workflow expression flaws allow remote code execution and credential theft, potentially leading to full instance compromise. Patch now.  Query: web.title~"n8n.io - Workflow Automation" tag!=honeypot
000
Modat @modat-io.bsky.social · 06/03/2026
CISA added CVE-2026-22719 to KEV after active exploitation of VMware Aria Operations (incl. Cloud Foundation & vSphere Foundation). Patch immediately. Query: web.html~"com.vmware.vsphere.client" OR web.title~"VMware Cloud Director Availability" OR web.title~"VMware Aria Operations"
010
Modat @modat-io.bsky.social · 26/02/2026
⚠️ CISA added CVE-2026-20127 to its KEV catalog and issued ED 26-03 after active exploitation of Cisco Catalyst SD-WAN. An auth bypass lets unauthenticated attackers gain admin access and manipulate SD-WAN configs. Patch now. Modat Magnify Query: web.html~"Cisco SD-WAN" OR web.html~"Cisco Catalyst"
000
Modat @modat-io.bsky.social · 24/02/2026
CISA added CVE-2025-49113 & CVE-2025-68461 to its KEV catalog after active exploitation of Roundcube Webmail. A 9.9 deserialization flaw enables authenticated RCE, while an SVG animate XSS allows script injection. Patch 1.6.12 / 1.5.12+. Modat Magnify Query: web.title~"Roundcube Webmail"
000
Modat @modat-io.bsky.social · 09/02/2026
⚠️ Active exploit. of SolarWinds Web Help Desk. Internet‑exposed WHD hit via unauth RCE. Attackers use Zoho RMM for persistence, Velociraptor for C2/recon/exfil, Cloudflare for access, then disable Defender/firewall. WHD <12.8.7 HF1 is vulnerable. Patch 2026.1+ Magnify Query: web.html.mmh3=1424519104
000
Modat @modat-io.bsky.social · 03/02/2026
⚠️CVE-2026-25253: 1-click RCE in OpenClaw. A crafted link leaks gateway tokens via WebSocket, enabling host command execution even on localhost. Fixed v2026.1.29 patch & rotate tokens. Query: web.title~"Clawdbot Control" OR web.title~"OpenClaw Control" OR web.title~"Moltbot Control"  magnify.modat.io
magnify.modat.io
Modat Magnify
000
Modat @modat-io.bsky.social · 30/01/2026
Latest research: Moldbot exposed across 53 countries.  
1,487 hosts leaking data via mDNS, 635 public control panels, and credential artifacts tied to Signal, Telegram & WhatsApp. 
Full research👉 www.modat.io/post/moldbot...
modat.io
Moldbot Unmasked: A Global Deployment Analysis
mDNS Broadcasts Leak: Our findings indicate that Moltbot instances are routinely exposing far more information via mDNS than expected, posing a significant configuration risk for global infrastructure...
000
Modat @modat-io.bsky.social · 29/01/2026
⚠️ CISA added CVE-2026-24858 to its KEV catalog after active exploitation of Fortinet FortiOS via FortiCloud SSO. An auth bypass lets attackers with a FortiCloud account access other tenants’ devices, enabling admin access and config abuse. Patch now. Modat Magnify Query: os="FortiOS" product~"Forti"
000
Modat @modat-io.bsky.social · 26/01/2026
⚠️ CISA added CVE‑2024‑37079 to its KEV catalogue after confirmed in‑the‑wild exploitation of VMware vCenter Server. An out‑of‑bounds write in the DCE/RPC protocol allows unauthenticated network‑based RCE via crafted packets. Patch immediately. Modat Magnify Query: product="VMware vCenter"
000
Modat @modat-io.bsky.social · 22/01/2026
⚠️ CVE-2026-21962 (CVSS 10.0) impacts Oracle Fusion Middleware, including Oracle HTTP Server and WebLogic Proxy Plug-Ins. Unauthenticated attackers can gain full system control and pivot across environments. Apply Oracle’s January 2026 Critical Patch Update immediately.
000
Modat @modat-io.bsky.social · 13/01/2026
⚠️ CISA has added CVE-2025-8110 to its KEV catalog after active exploitation of public-facing Gogs instances. The flaw bypasses a prior RCE fix via improper symlink handling, allowing authenticated attackers to overwrite files and achieve remote code execution. Modat Magnify Query: technology="Gogs"
000
Modat @modat-io.bsky.social · 01/12/2025
Cyber Monday Deal 
Get 6 months of Modat Magnify Pro for just €5 total (save €355).  Use code: MODAT2025CYBERMONDAY   
Try the platform. Run advanced queries. Find what others miss. 
 magnify.modat.io 
#CyberMonday #Cybersecurity #OSINT
011
Modat @modat-io.bsky.social · 07/08/2025
New Research – Global Impact: Over 1.2 million internet-connected healthcare devices and systems with exposure that endanger patient data.   Findings across 70+ different types of medical devices & systems: MRI, CT, X-rays, hospital management systems, others 
 
👉 Read the full blog:
bit.ly/4fqfKrv
bit.ly
Exposed to the Bare Bone: When Private Medical Scans Surface on the Internet
Globally Impactful Research: 1.2 Million Healthcare Devices and Systems Available on the Open Internet. European cybersecurity company Modat reveals that exposed internet-connected devices are resul...
000
Modat @modat-io.bsky.social · 03/07/2025
🚨 Cisco fixed CVE-2025-20309 — a root-level backdoor in Unified CM. Affected users must update to 15 SU3 or patch now. Try this query: one_service(product="Cisco UCS Manager") and one_service(port=22 service=ssh) The platform: magnify.modat.io #Modat #CVE202520309 #ModatMagnify #Cisco
magnify.modat.io
Modat Magnify
011
Modat @modat-io.bsky.social · 24/06/2025
🚨 Citrix fixes critical NetScaler bug CVE-2025-5777—patch ASAP. Out-of-bounds flaw similar to CitrixBleed may expose session token. Affects gateway-configured devices. Upgrade + kill active sessions. #citrix #CVE-2025-5777 #modat #modatmagnify Try this query: magnify.modat.io/search?query=p…
magnify.modat.io
Modat Magnify
010