<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CloudKey Blog</title><description>Field notes from the CloudKey security team. CVEs, zero-days, product walkthroughs and honest comparisons.</description><link>https://www.cloudkey-tech.com/</link><language>en-US</language><item><title>Adobe ColdFusion leads seven CVEs now confirmed exploited</title><link>https://www.cloudkey-tech.com/blog/cve-digest-2026-07-13/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/cve-digest-2026-07-13/</guid><description>Seven flaws are now confirmed exploited: an Adobe ColdFusion path traversal and a wave of Joomla file-upload RCEs, all on CISA KEV this week. Patch by exposure first.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate><category>cve</category><category>kev</category><category>epss</category><category>cve-digest</category><category>coldfusion</category><category>joomla</category><category>langflow</category></item><item><title>SharePoint and SimpleHelp: two CVEs now confirmed exploited</title><link>https://www.cloudkey-tech.com/blog/cve-digest-2026-07-06/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/cve-digest-2026-07-06/</guid><description>Two flaws are now confirmed exploited: a Microsoft SharePoint code-execution bug and a SimpleHelp auth bypass, both on CISA KEV this week. Patch them before your CVSS queue.</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate><category>cve</category><category>kev</category><category>epss</category><category>cve-digest</category><category>sharepoint</category><category>simplehelp</category></item><item><title>How to check if your company credentials leaked</title><link>https://www.cloudkey-tech.com/blog/check-company-credentials-leaked/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/check-company-credentials-leaked/</guid><description>A practical guide to check if your company credentials leaked: where stolen logins come from, how to search breach and infostealer data safely, and what to do about a hit.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><category>product</category><category>credential-leak</category><category>dark-web</category><category>infostealer</category><category>password-security</category><category>mfa</category><category>dark-web-monitoring</category></item><item><title>Patch Now: SharePoint Server Is Exploited, Federal Deadline July 4</title><link>https://www.cloudkey-tech.com/blog/microsoft-sharepoint-cve-2026-45659-exploited/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/microsoft-sharepoint-cve-2026-45659-exploited/</guid><description>CVE-2026-45659 is an actively exploited deserialization flaw in Microsoft SharePoint Server. CISA added it to KEV on July 1 with a federal deadline of July 4, 2026.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><category>zero-day</category><category>rapid-response</category><category>kev</category><category>microsoft</category><category>sharepoint</category><category>deserialization</category><category>cwe-502</category></item><item><title>Attackers Are Exploiting SimpleHelp: CVSS 10 Auth Bypass in the Wild</title><link>https://www.cloudkey-tech.com/blog/simplehelp-cve-2026-48558-auth-bypass-exploited/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/simplehelp-cve-2026-48558-auth-bypass-exploited/</guid><description>CVE-2026-48558, a CVSS 10 authentication bypass in SimpleHelp, is actively exploited and added to CISA KEV with a July 2 federal patch deadline.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>zero-day</category><category>rapid-response</category><category>kev</category><category>epss</category><category>simplehelp</category><category>authentication-bypass</category><category>oidc</category></item><item><title>CVE digest: Cisco, Ubiquiti, PTC and Lantronix exploited in the wild</title><link>https://www.cloudkey-tech.com/blog/cve-digest-2026-06-29/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/cve-digest-2026-06-29/</guid><description>Four flaws now confirmed exploited, added to CISA&apos;s KEV the week of June 29, 2026: Cisco Unified CM, Ubiquiti UniFi OS, PTC Windchill and Lantronix. What to patch first.</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>cve</category><category>kev</category><category>epss</category><category>cve-digest</category><category>cisco</category><category>ubiquiti</category><category>ptc</category></item><item><title>Cisco Unified CM SSRF Exploited, Patch by June 28</title><link>https://www.cloudkey-tech.com/blog/cisco-unified-cm-cve-2026-20230-exploited/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/cisco-unified-cm-cve-2026-20230-exploited/</guid><description>CVE-2026-20230 is a server-side request forgery flaw in Cisco Unified CM and Unified CM SME added to CISA KEV on June 25. Federal deadline is June 28.</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate><category>zero-day</category><category>rapid-response</category><category>kev</category><category>cisco</category><category>unified-cm</category><category>ssrf</category><category>cwe-918</category></item><item><title>Is penetration testing required for SOC 2?</title><link>https://www.cloudkey-tech.com/blog/penetration-testing-for-soc2/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/penetration-testing-for-soc2/</guid><description>Is penetration testing required for SOC 2? Not by name in the Trust Services Criteria, but auditors expect one to satisfy CC7.1. What to test, and how often.</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate><category>product</category><category>penetration-testing</category><category>soc-2</category><category>compliance</category><category>security-testing</category><category>trust-services-criteria</category></item><item><title>Attackers Can Reach Root on UniFi OS and Lantronix Edge Servers</title><link>https://www.cloudkey-tech.com/blog/cisa-kev-unifi-os-lantronix-copy-fail-2026-06-23-exploited/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/cisa-kev-unifi-os-lantronix-copy-fail-2026-06-23-exploited/</guid><description>Ubiquiti UniFi OS and Lantronix EDS5000 reached CISA KEV on June 23 with unauthenticated root flaws, and Copy Fail (CVE-2026-31431) now hits B&amp;R OT gear. Patch fast.</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>zero-day</category><category>rapid-response</category><category>kev</category><category>ubiquiti</category><category>unifi-os</category><category>lantronix</category><category>linux-kernel</category><category>zero-day</category></item><item><title>CVE digest: Splunk, Joomla JCE and LiteSpeed exploited in the wild</title><link>https://www.cloudkey-tech.com/blog/cve-digest-2026-06-22/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/cve-digest-2026-06-22/</guid><description>Three flaws now confirmed exploited, added to CISA&apos;s KEV the week of June 22, 2026: Splunk Enterprise, the Joomla JCE editor and a LiteSpeed cPanel plugin. What to patch first.</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>cve</category><category>kev</category><category>epss</category><category>cve-digest</category><category>splunk</category><category>joomla</category><category>litespeed</category></item><item><title>FortiBleed: 73,000 Fortinet VPN Credentials Exposed, What To Do</title><link>https://www.cloudkey-tech.com/blog/fortibleed-fortinet-vpn-credentials-exposed/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/fortibleed-fortinet-vpn-credentials-exposed/</guid><description>A leaked dataset exposed plaintext VPN credentials for 73,932 FortiGate firewalls in 194 countries. What FortiBleed is, whether your gateway is affected, and what to do now.</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate><category>news</category><category>fortinet</category><category>fortigate</category><category>vpn</category><category>credential-leak</category><category>ssl-vpn</category><category>dark-web</category><category>incident-response</category></item><item><title>Splunk Enterprise CVE-2026-20253 Exploited: Patch Before June 21</title><link>https://www.cloudkey-tech.com/blog/splunk-enterprise-cve-2026-20253-exploited/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/splunk-enterprise-cve-2026-20253-exploited/</guid><description>CISA added Splunk Enterprise CVE-2026-20253 to KEV on June 18, 2026. Unauthenticated file write via PostgreSQL sidecar, federal due date June 21. Who is affected and what to do.</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate><category>zero-day</category><category>rapid-response</category><category>kev</category><category>splunk</category><category>enterprise</category><category>file-write</category><category>authentication-bypass</category></item><item><title>Vulnerability scanning vs penetration testing: which one?</title><link>https://www.cloudkey-tech.com/blog/vulnerability-scanning-vs-penetration-testing/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/vulnerability-scanning-vs-penetration-testing/</guid><description>Vulnerability scanning vs penetration testing: one finds known flaws at scale, the other proves what an attacker can exploit. Which you need, and why both.</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate><category>comparison</category><category>vulnerability-scanning</category><category>penetration-testing</category><category>security-testing</category><category>pci-dss</category><category>vulnerability-management</category></item><item><title>Attackers Are Exploiting JCE Editor to Plant PHP Webshells on Joomla Sites</title><link>https://www.cloudkey-tech.com/blog/widget-factory-jce-cve-2026-48907-exploited/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/widget-factory-jce-cve-2026-48907-exploited/</guid><description>CVE-2026-48907 in Joomla Content Editor lets unauthenticated attackers upload PHP webshells. CISA added it to KEV on June 16; patch to JCE 2.9.99.6 now.</description><pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate><category>zero-day</category><category>rapid-response</category><category>kev</category><category>joomla</category><category>jce</category><category>webshell</category><category>cms</category></item><item><title>Attackers Are Exploiting Cisco SD-WAN Manager and LiteSpeed cPanel Plugin</title><link>https://www.cloudkey-tech.com/blog/cisa-kev-cisco-sd-wan-litespeed-2026-06-15-exploited/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/cisa-kev-cisco-sd-wan-litespeed-2026-06-15-exploited/</guid><description>Attackers are exploiting Cisco Catalyst SD-WAN Manager (CVE-2026-20262) and the LiteSpeed cPanel plugin (CVE-2026-54420), both added to CISA KEV on June 15, 2026. Patch now.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>zero-day</category><category>rapid-response</category><category>kev</category><category>cisco</category><category>sd-wan</category><category>litespeed</category><category>cpanel</category><category>zero-day</category></item><item><title>CVE digest: six KEV additions hit Oracle, Ivanti, Cisco and Chrome</title><link>https://www.cloudkey-tech.com/blog/cve-digest-2026-06-15/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/cve-digest-2026-06-15/</guid><description>CISA added six CVEs to KEV in the week of June 15, 2026: Oracle PeopleSoft, Ivanti Sentry, Cisco SD-WAN, Arista, Chrome and LiteLLM. Scores and what to patch first.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>cve</category><category>kev</category><category>epss</category><category>cve-digest</category><category>ivanti</category><category>oracle</category><category>cisco</category><category>chrome</category></item><item><title>Oracle PeopleSoft CVE-2026-35273 Is Exploited: Patch PeopleTools 8.61 and 8.62</title><link>https://www.cloudkey-tech.com/blog/oracle-peoplesoft-cve-2026-35273-exploited/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/oracle-peoplesoft-cve-2026-35273-exploited/</guid><description>Oracle PeopleSoft PeopleTools CVE-2026-35273: active exploitation, known ransomware use, unauthenticated takeover, CVSS 9.8, on CISA KEV. Who is affected and what to do.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate><category>zero-day</category><category>rapid-response</category><category>kev</category><category>epss</category><category>oracle</category><category>peoplesoft</category><category>ssrf</category><category>rce</category></item><item><title>Ivanti Sentry CVE-2026-10520 Is Exploited: Patch to R10.7.1 Now</title><link>https://www.cloudkey-tech.com/blog/ivanti-sentry-cve-2026-10520-exploited/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/ivanti-sentry-cve-2026-10520-exploited/</guid><description>CISA added Ivanti Sentry CVE-2026-10520 to KEV on June 11, 2026. Unauthenticated root RCE, CVSS 10.0, federal due date June 14. Here is who is affected and what to do.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>zero-day</category><category>rapid-response</category><category>kev</category><category>epss</category><category>ivanti</category><category>sentry</category><category>rce</category></item><item><title>What is a CVE? Definition, ID format, and what to do about them</title><link>https://www.cloudkey-tech.com/blog/what-is-a-cve/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/what-is-a-cve/</guid><description>What a CVE is, who assigns the IDs, how the numbering works, and how to act on the 40,000+ published each year. A plain-language guide for IT and security teams.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>cve</category><category>cve</category><category>nvd</category><category>vulnerability-management</category><category>vulnmonitor</category></item><item><title>Weekly CVE Digest 2026-06-09: Linux, Android, Magento, SolarWinds</title><link>https://www.cloudkey-tech.com/blog/cve-digest-2026-06-09/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/cve-digest-2026-06-09/</guid><description>Four CVEs hit CISA KEV this week: Linux, Android, Magento RCE, and SolarWinds DoS. See which patch cuts the most risk against confirmed exploitation.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>cve</category><category>kev</category><category>epss</category><category>cve-digest</category><category>linux</category><category>android</category><category>magento</category><category>solarwinds</category></item><item><title>CVSS vs EPSS vs KEV: how to prioritize CVEs that matter</title><link>https://www.cloudkey-tech.com/blog/cvss-vs-epss-vs-kev/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/cvss-vs-epss-vs-kev/</guid><description>CVSS vs EPSS vs KEV: three signals that rank vulnerabilities differently. Why CloudKey patches KEV-listed CVEs first, EPSS-elevated next, CVSS last.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>cve</category><category>kev</category><category>cvss</category><category>epss</category><category>vulnerability-prioritization</category><category>vulnmonitor</category></item><item><title>What a useful dark web monitoring report contains</title><link>https://www.cloudkey-tech.com/blog/dark-web-monitoring-report/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/dark-web-monitoring-report/</guid><description>A CloudKey dark web monitoring report, walked section by section: the open-finding ledger, re-test attestations, and the parts auditors ask for first.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>product</category><category>dark-web-monitoring</category><category>exposure-report</category><category>leaked-credentials</category><category>external-attack-surface</category></item><item><title>SBOM asset inventory reconciliation in practice</title><link>https://www.cloudkey-tech.com/blog/sbom-asset-inventory-reconciliation/</link><guid isPermaLink="true">https://www.cloudkey-tech.com/blog/sbom-asset-inventory-reconciliation/</guid><description>SBOM asset inventory reconciliation maps each signed manifest to the host actually running it, so the CVE queue ranks risk on real systems, not the manifests.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><category>product</category><category>sbom</category><category>asset-inventory</category><category>vulnmonitor</category><category>supply-chain</category></item></channel></rss>