Hermes Threat Observatory
π¨ Critical Signals & Immediate Operational Decisions
Sorted by HTS SeverityCisco ISE β Token-Replay Authentication Bypass & Super-Admin Takeover →
Added to CISA KEV catalog following active in-the-wild exploitation targeting Cisco ISE Guest Portal.
Unauthenticated remote attackers forge provisioning requests to grant themselves Super-Admin rights, compromising enterprise Zero Trust policy planes.
All enterprises running Cisco ISE 3.1 through 3.4 with exposed guest or administration portals.
Oracle WebLogic Server β Unauthenticated T3/IIOP Deserialization RCE →
Emergency release in Oracle September 2026 Critical Patch Update with maximum CVSS 10.0 rating.
Complete bypass of JEP 290 deserialization filters via T3/IIOP network protocols, granting SYSTEM-level code execution without credentials.
WebLogic Server 12.2.1.4.0 and 14.1.1.0.0 exposing ports 7001/7002 to internal networks or the internet.
Acronis Cyber Protect cPanel/Plesk β Symlink Race Condition to Root LPE →
CISA KEV addition confirming attackers leverage shared cPanel accounts to overwrite root system binaries.
Allows attackers with compromised low-privilege WordPress sites to immediately escape and seize root on dedicated hosting servers.
Web hosting providers and enterprises managing cPanel/Plesk servers with Acronis backup agents.
LangBot AI Orchestrator β Password Reset Entropy Collapse & Agent Tool Hijacking →
Public exploit demonstrated brute-forcing 24-bit reset tokens due to async rate-limiting bypass.
Full admin takeover enabling attackers to weaponize agent tool connections, execute unauthorized shell commands, and poison vector memories.
Teams orchestrating autonomous AI agents with LangBot versions <= 3.2.1.
1. The Signal Reduction Funnel Methodology
Section titled β1. The Signal Reduction Funnel MethodologyβIn a typical 24-hour cycle, global vulnerability databases, social feeds, and research trackers publish thousands of raw advisories. Security teams attempting to review everything experience operational paralysis:
- Tier 1 (Raw Signals): Automated ingestion filters out duplicate advisories, documentation updates, and minor library bumps.
- Tier 2 (Significant Changes): Evaluates if new material evidence (code diff, advisory addendum) alters the attack surface.
- Tier 3 (High-Interest): Assesses attack vector, required privileges, and asset deployment footprint.
- Tier 4 (Actionable Decisions): Synthesizes telemetry into one of 6 decisive actions:
PATCH,MITIGATE,ISOLATE,REPLACE,ACCEPT, orMONITOR.