@fieldeffectsoft

Field Effect delivers intelligence-grade managed detection and response for the AI era. See for yourself: https://nitter.cf/t.co/Z63hh2Jw8U

Ottawa, Ontario
Joined April 2016
A recently disclosed Apache Tomcat vulnerability, CVE-2026-34486, exposes clustered deployments to remote code execution under specific conditions.
1
3
234
Public proof-of-concept exploit code demonstrates practical exploitation through the Tomcat Tribes communication channel, increasing risk where clustering is enabled and network exposure exists.
1
220
More than 80% of incidents our team investigated last year stemmed from cloud identity compromise, highlighting a growing shift in how adversaries are gaining access to corporate environments. Get more cybersecurity data, trends, and analysis here: get.fieldeffect.com/2026-cyb…
92
Escalating conflict following coordinated U.S. and Israeli strikes on Iranian military and nuclear sites has raised concerns about potential cyber spillover.
1
2
119
Researchers have observed a rise in opportunistic hacktivist activity and unverified claims of DDoS attacks, defacements, and data leaks targeting Iran’s adversaries.
1
1
91
🚨 AWS reports groups are actively exploiting the #React2Shell RCE in the wild. Attackers are using exposed RSC endpoints for unauthenticated RCE → webshells → cloud pivoting. Patch React/Next.js immediately. No Field Effect systems are affected. More: fieldeffect.com/blog/react-s…
177
From our security experts 👇 A high-severity RCE vulnerability (CVE-2025-62518) impacts Rust-based archive libraries like async-tar, used across cloud-native & containerized systems. Multiple patches avail, check our writeup for full mitigation details: fieldeffect.com/blog/tarmage…
141
An exec-targeted extortion campaign is claiming theft of Oracle EBS data. Since then, a critical flaw in Oracle EBS (CVE-2025-61882) has been confirmed.
1
165
If you run #Oracle #EBS (v12.2.3-12.2.14) or have internet-exposed modules: - Patch immediately - Lock down/reset access paths - Hunt for IoCs (reverse shells, HTTP anomalies, unusual outbound activity) Full breakdown: fieldeffect.com/blog/oracle-…
118
What started as a potentially unwanted application (PUA) flagged as malicious by Microsoft Defender led our analysts to uncover a broader malware campaign using trojanized apps, signed binaries, and deceptive 7-Zip packaging. Read the full breakdown: fieldeffect.com/blog/potenti…
1
2
117
🚨 New patch alert: SolarWinds has released a hotfix for CVE-2025-26399, a critical Web Help Desk flaw enabling RCE. The company urged customers yesterday to upgrade to Web Help Desk version 12.8.7 Hotfix 1 to mitigate the issue. Details: fieldeffect.com/blog/patch-s…
116
Field Effect is actively monitoring a supply chain attack involving hijacked npm packages. Researchers say hackers planted malicious code in open source software packages with 2B+ weekly updates. None of Field Effect's services are affected and our internal review confirms...
1
1
85
...no exposure to the compromised components. Field Effect's onboarding process for 3rd-party libraries includes validation steps that would've identified affected packages & updates are performed only after a review of their current security posture.
1
56
Ongoing attacks against Sangoma #FreePBX systems (since Aug 21) exploit publicly exposed Admin Control Panels. 🔹 Affected: v16 & v17 w/ Endpoint Manager installed 🔹 Fix: EDGE module update (temp fix) 🔹 + Restrict ACP to trusted IPs or VPN Details: fieldeffect.com/blog/sangoma…
1
317