Suriq - Always on Watch

@suriq.io

Managed security for the servers you run, built on Wazuh. We catch what is being exploited and tell you exactly what to do. suriq.io

🚨 BREAKING A stranger with no login can upload a PHP file and run it on your WooCommerce store. Request a Quote for WooCommerce (through 2.9.2) has a critical file-upload flaw, and there is no patch yet. Disable the popup quote form now. (CVE-2026-18143)

Request a Quote WooCommerce CVE-2026-18143: Unauth RCE, No Patch

CVE-2026-18143 is a critical unauthenticated file-upload flaw in Request a Quote for WooCommerce (through 2.9.2), with no patch yet. Act now.

suriq.io

🔴 EXPLOITED Check Point is patching two flaws in its firewalls and management servers, both 9.8 and both exploited now. One ran silent as a zero-day for two months. Patch, then hunt: the fix won't tell you if you were already hit. (CVE-2026-93616 / CVE-2026-85102)

Check Point CVE-2026-93616 & 85102: 9.8 Pre-Auth RCEs Exploited

Check Point CVE-2026-93616 and CVE-2026-85102 are two 9.8 pre-auth flaws exploited in the wild and on CISA's KEV list. Patch, then hunt for compromise.

suriq.io

Cisco ISE and Kong Gateway had the week's marquee flaws, and both were auth bypasses in the identity appliances themselves (two Cisco bugs CVSS 10.0, one in CISA KEV). A bypass yields a valid session, so the auth log looks normal. Where to hunt:

The gatekeeper was the target: identity appliances got bypassed

This week's exploited flaws were in the access-control layer itself: Cisco ISE (two CVSS 10.0, in CISA KEV) and Kong Gateway's SAML bypass.

suriq.io

Brevo, the email platform once called Sendinblue, was abused to inject malware into up to 100,000 sites. The script swap happened at Brevo's CDN, so site files never changed and integrity checks stayed quiet. Embed its code? Audit your third-party scripts.

Brevo Hack Injected Malware at the CDN Edge, Evading Site Checks

Attackers abused Brevo (formerly Sendinblue) to inject malware into up to 100,000 sites at the CDN edge, so origin files never changed and checks missed it.

suriq.io

🔴 EXPLOITED Cisco Identity Services Engine has a second CVSS 10 zero-day under active attack: CVE-2026-76460, an unauthenticated API auth bypass. Same admin interface as last week's exploited flaw. Affects ISE 3.1-3.5. Patch now.

Cisco ISE CVE-2026-76460: Exploited Auth-Bypass Zero-Day, Patch

CVE-2026-76460 is an unauthenticated API auth bypass in Cisco ISE, CVSS 10.0, actively exploited and in CISA KEV. Patch ISE 3.1-3.5 to the fixed build now.

suriq.io