Clone Systems

Clone Systems Clone Systems has been securing businesses since 1998 and delivering PCI compliance as an ASV for 18 years.

We’re here to make security and compliance simple for your team.

08/24/2026

Vulnerability Alert: Cisco Patches Multiple Critical Flaws

Cisco has released security updates addressing nine vulnerabilities affecting Cisco Crosswork platforms and Cisco Secure Workload, including four vulnerabilities with a maximum CVSS score of 10.0.

The critical flaws include SQL injection, missing authentication, improper access controls, authentication bypasses, and external control of file system vulnerabilities. Successful exploitation could expose affected enterprise environments to serious security risks.

Affected products include:
• Cisco Crosswork Data Gateway
• Cisco Crosswork Network Controller
• Cisco Crosswork Planning
• Cisco Secure Workload

Cisco has released fixes in:
• Crosswork 7.2.1-SP
• Secure Workload 3.10.9.1
• Secure Workload 4.0.4.16

Cisco states that these vulnerabilities were discovered during internal testing and are not currently known to be actively exploited.

Organizations using affected Cisco products should review their deployed versions and prioritize the appropriate security updates.

08/19/2026

Oracle has released 943 security patches in its August 2026 Critical Patch Update, addressing vulnerabilities across Oracle Database, Fusion Middleware, E Business Suite, Java SE, MySQL, Enterprise Manager, PeopleSoft, Communications products, and other enterprise platforms.

The most urgent risks include multiple critical Oracle WebLogic Server vulnerabilities that could allow unauthenticated remote attackers to take control of affected servers. Several flaws impact WebLogic Server Core through T3, IIOP, and RMI protocols, with severity scores as high as 9.9.

For organizations running Oracle environments, this is not a routine patch cycle to casually place in the backlog. WebLogic, Fusion Middleware, and other business critical systems often support sensitive applications, internal workflows, customer data, and operational processes.

Security teams should identify affected Oracle products, prioritize internet facing WebLogic servers, test and deploy the applicable patches quickly, and restrict exposed protocols where immediate patching is not possible.

When a single patch update contains hundreds of fixes and multiple critical takeover risks, prioritization matters. Start with the systems attackers can reach first.

08/18/2026

GitLab has released patches for CVE-2026-19478, a critical GraphQL API vulnerability affecting self managed GitLab CE and EE installations.

The flaw could allow an unauthenticated remote attacker to delete or modify public projects and associated user data through a malicious GraphQL directive. That creates serious risk for data loss, project integrity, and software supply chain disruption.

This affects self managed GitLab CE and EE versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. GitLab.com and GitLab Dedicated are not affected.

Organizations running self managed GitLab should upgrade immediately to the patched versions, monitor for unexpected project changes or deletions, and review public project exposure.

When your source code platform is the target, the risk is not just downtime. It is trust, integrity, and control of the development pipeline.

08/17/2026

A newly identified Linux botnet called Evooo1Bot is exploiting known vulnerabilities in internet facing routers, firewalls, cameras, and other edge devices to turn them into SOCKS5 proxy nodes.

Built from Mirai based functionality, the malware adds encrypted command and control, SSH brute forcing, credential sniffing, proxy relay capabilities, exploit modules, and DDoS functions.

The concern is not only device compromise. Once infected, these systems can be used to disguise malicious traffic, support follow on attacks, bypass detection, or create distributed proxy infrastructure for attackers.

Organizations should patch exposed edge devices, remove unnecessary internet exposure, replace default or weak credentials, monitor for unexpected proxy traffic, and investigate unusual outbound connections from network appliances.

Old vulnerabilities do not stay old when botnets keep giving them new life.

08/04/2026

Nable N Central is facing active exploitation involving CVE-2026-18556 and CVE-2026-18577, with attackers reportedly bypassing an incomplete patch to compromise vulnerable servers.

The risk is especially serious because N Central is widely used by MSPs and IT teams to manage customer environments, endpoints, patching, monitoring, and remote administration. When a management platform is compromised, attackers may gain a powerful path into multiple downstream systems.

This is not a wait and see issue. Organizations using affected N Central deployments should apply the latest hotfix immediately, confirm they are running the corrected version, restrict external access, rotate credentials, and review systems for signs of compromise.

Security tools are only helpful when the tool itself is secure. Patch fast, validate the fix, and investigate before attackers turn management access into wider damage.

08/03/2026

Adobe has released an urgent security update for Adobe Campaign Classic after a critical flaw was found that could allow arbitrary code ex*****on without user interaction.

Tracked as CVE-2026-48449, the vulnerability carries a maximum severity score and affects Adobe Campaign Classic v7 7.4.3 build 9397 and earlier. Adobe also patched CVE-2026-48448, a SQL injection flaw that could allow attackers to read arbitrary files from the system.

For organizations using Adobe Campaign Classic, this is a high priority patching issue. Marketing automation platforms often connect to customer data, campaign workflows, email systems, and internal business processes, which makes compromise especially risky.

Affected users should update to Adobe Campaign Classic v7 7.4.3 build 9398 or later immediately, review access controls, and monitor systems for suspicious activity.

When a marketing platform can become a code ex*****on risk, patching is not just an IT task. It is customer data protection.

The recent OpenAI security incident wasn’t just a story about one company. It was a reminder that AI systems are becomin...
07/29/2026

The recent OpenAI security incident wasn’t just a story about one company. It was a reminder that AI systems are becoming part of every organization’s attack surface.

As AI assistants, agents, and integrations gain access to business systems, traditional security testing alone may not identify risks such as:

* Prompt injection
* Tool and API abuse
* Retrieval-Augmented Generation (RAG) poisoning
* Excessive AI permissions
* Agentic behavior across connected systems

Organizations deploying AI should be asking a different question: Are we testing AI systems the way they can actually fail?

In our latest blog, we break down what happened, why it matters, and the practical steps security teams can take to better secure AI-enabled environments.

Read the full article: https://www.clone-systems.com/what-the-openai-security-incident-teaches-about-ai-security/

07/29/2026

Vulnerability Alert: CVE-2026-53921

A critical vulnerability affecting OpenWrt’s DHCPv6 service could allow an unauthenticated attacker to execute arbitrary code as root on vulnerable devices.

Tracked as CVE-2026-53921 (CVSS 9.8), the flaw exists in odhcpd, OpenWrt’s default DHCPv6 server. Successful exploitation could give an attacker complete control of an affected router.

At this time, there are no reports of active exploitation in the wild, but public proof-of-concept code has been released, increasing the urgency to patch.

Key Details:
• CVE-2026-53921 (CVSS 9.8 – Critical)
• Unauthenticated remote code ex*****on as root
• Affects vulnerable OpenWrt DHCPv6 services
• Public proof-of-concept available

Recommended Actions:
• Upgrade to OpenWrt 24.10.8 or 25.12.5
• Update separately installed packages
• Review optional LuCI applications and permissions
• Remove unnecessary services to reduce exposure

Organizations using OpenWrt should prioritize applying the latest security updates to reduce the risk of compromise.

Is your online store PCI compliant?Quarterly PCI ASV scanning helps identify external vulnerabilities before attackers d...
07/27/2026

Is your online store PCI compliant?

Quarterly PCI ASV scanning helps identify external vulnerabilities before attackers do and is a key requirement for many businesses under PCI DSS.

At Clone Systems, we make compliance simple with trusted PCI ASV scanning, actionable reporting, and expert support to help you stay secure year-round.

Scan smarter. Stay secure.

https://buff.ly/iknhDS3

07/27/2026

Vulnerability Alert: CVE-2026-16723

Attackers are actively targeting a critical remote code ex*****on (RCE) vulnerability affecting Alibaba Fastjson 1.x.

The vulnerability impacts Fastjson versions 1.2.68–1.2.83 running in vulnerable Spring Boot fat-JAR applications and can allow unauthenticated remote code ex*****on. There is currently no official patch available for Fastjson 1.x.

Key Details:
• CVE-2026-16723 (CVSS 9.0 – Critical)
• Active exploitation observed in the wild
• Fastjson 1.2.68–1.2.83 affected
• No authentication required for exploitation under vulnerable conditions

Recommended Actions:
• Enable Fastjson SafeMode (-Dfastjson.parser.safeMode=true)
• Inventory direct and transitive Fastjson dependencies
• Monitor for indicators of compromise, including suspicious values and unexpected outbound connections
• Plan migration to Fastjson2, which is not affected

Organizations using Java and Spring Boot applications should assess their exposure and implement mitigations as soon as possible.

Address

Philadelphia, PA

Alerts

Be the first to know and let us send you an email when Clone Systems posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share