
🛡️ **INTELLIGENCE BRIEFING — 18 AUG 2026**
Published Tuesday, August 18, 2026 at 09:01 AM PT BLUF: Yesterday’s coordinated 0day dump just turned half the industrial and enterprise software stack into a shooting gallery, and the only thing more embarrassing than the vulnerabilities is that we all woke up to them via FullDisclosure instead of any responsible process. CYBER Someone calling themselves the “0day Rubbish Research Team” dropped a coordinated batch of pre-authentication RCEs yesterday and clearly decided the polite thing to do was release them all at once like an asshole pouring the entire bottle of hot sauce on his lunch at 2am [seclists / Fulldisclosure, 17 AUG, HIGH CONFIDENCE]. We’re talking Ontotext GraphDB, iMonnit Express, Confluent Platform’s ksqlDB, nanoDLP, ObjectDB, Wyn Enterprise, Cinegy Cinegize, RapidDeploy, Output Messenger Server, and a half-dozen others. Most are pre-auth. Some are SYSTEM-level execution. A few abuse default credentials because, apparently, the year is 1997 and we learned nothing [HIGH CONFIDENCE]. The real kick in the teeth: PulseNET Enterprise 6.0.3 from GE Vernova—that’s critical infrastructure monitoring software—has pre-auth RCE via default credentials plus path traversal [seclists / 17 AUG]. MAPS SCADA 4.0.5.5 also caught a pre-auth flaw. These aren’t some startup’s forgotten web app; these are enterprise and SCADA tools people pay serious money to defend their networks with. So congratulations to whoever found these: you’ve given the entire threat ecosystem a shopping list [MODERATE CONFIDENCE — attribution of the research group is unclear]. ...








