Mandiant found root-level implants on exploited NetScaler appliances and says upgrading alone will not evict them. Six KEV additions, one hacked tanker.
GitLab's CVSS 10.0 path-traversal flaw and a ConnectWise ScreenConnect KEV addition landed the same week — one hits source code, the other hits every client an MSP touches.
N-able N-central exploited through an incomplete patch, signed ScreenConnect agents abused with no CVE, and six KEV additions on three-day clocks.
SharePoint, PTC Windchill and edge devices join CISA KEV where CUI lives, while TeamPCP credential theft feeds Vect ransomware. What DIB teams must check.