• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
      • Vulnerability Management
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
      • Vulnerability Management
  • German
  • English
  • Italian
  • Dutch
Joseph Lee

About Joseph Lee

Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.

He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.

Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.

LinkedIn

Entries by Joseph Lee

Blog

CVE-2026-85706: CVSS 10 GitLab CE/EE API Flaw Actively Exploited

CVE-2026-85706 (CVSS 10, EPSS 96th pctl), published on September 12th, 2026, is a critical path traversal flaw in the GitLab CE/EE repository Commits API and Repository Files API. Exploitation can allow an unauthenticated attacker to read arbitrary files from the GitLab server on affected self-managed instances. However, the unauthenticated exploit path requires at least one […]

17. September 2026/by Joseph Lee
Blog

Three New JFrog Artifactory CVEs Actively Exploited in the Wild

CVE-2026-82329, CVE-2026-42018, and CVE-2026-42016, all affecting JFrog Artifactory, were added to CISA’s Known Actively Exploited (KEV) in September 2026 [1][2][3]. Artifactory acts as a central repository for software build artifacts, binaries, packages, containers, files, releases, and increasingly AI/ML artifacts. A compromise of Artifactory could allow an attacker to steal sensitive artifacts and credentials, tamper with […]

15. September 2026/by Joseph Lee
Blog

“MikroTrick” Exploit Chain Targets SSH-Exposed MikroTik RouterOS Devices

According to CERT Polska, active exploitation of MikroTik RouterOS has been underway since at least September 2nd, 2026. The chain leverages CVE-2026-67276 (CVSS 9.2) and CVE-2026-86060 (CVSS 9.2) against devices whose SSH service is reachable from public networks. A successful breach yields full control of the targeted system. MikroTik has published fixes for the flaws […]

14. September 2026/by Joseph Lee
Blog

August 2026 Threat Report: The Vulnpocalypse Hits Full Force

The so-called Vulnpocalypse is now in full force. This August 2026 threat report only scratches the surface of new high-risk vulnerabilities that emerged in August 2026. To see how Greenbone’s industry leading vulnerability detection can benefit your IT security operations, visit our SecInfo portal and view our complete coverage portfolio. August reinforced a now too […]

7. September 2026/by Joseph Lee
Blog

CVE-2026-64849: SSRF Flaw in MLflow Actively Exploited

CVE-2026-64849 (CVSS 9.3, EPSS ≥ 95th pctl) is a critical-severity unauthenticated full-read server-side request forgery (SSRF) flaw [CWE-918] in MLflow webhook delivery. The CVE affects all versions prior to 3.15.0. The root cause is flawed redirect handling and DNS rebinding. The flaw is exploited by bypassing the _validate_webhook_url protections in the default MLflow Tracking Server […]

26. August 2026/by Joseph Lee
Blog

CVE-2026-19478: GitLab CE/EE GraphQL Unauthenticated Flaw Actively Exploited

GitLab has released fixes for CVE-2026-19478 (CVSS 9.4, EPSS 0.7% (51st percentile)), a critical-severity code injection flaw [CWE-94]. The vulnerability affects the GraphQL directive in GitLab Community Edition (CE) and Enterprise Edition (EE). According to GitLab, the flaw can allow an unauthenticated attacker to remotely modify or delete public projects and user data under certain […]

24. August 2026/by Joseph Lee
Blog

CVE-2026-8037 Now Actively Exploited! Unauthenticated RCE in Progress Kemp LoadMaster and ECS Connection Manager

CVE-2026-8037 (CVSS 9.8, EPSS >= 100th pctl) is a critical, unauthenticated remote code execution (RCE) vulnerability in Progress Kemp LoadMaster and Progress ECS Connection Manager. eSentire reported that exploitation attempts began on June 29th, 2026, and the flaw has now been added to CISA’s Known Exploited Vulnerabilities (KEV) list. watchTowr Labs published a separate technical […]

20. August 2026/by Joseph Lee
Blog

Patch Now! Two Actively Exploited CVEs Affecting VMware vCenter Server and More

Update CVE-2026-59310 has now been added to CISA’s KEV catalog. Public proof-of-concept exploit code is also available, further increasing the risk of ongoing attacks. Broadcom published VMSA-2026-0006 on July 29th, 2026, to address five vulnerabilities affecting VMware ESX, VMware vCenter Server, VMware Workstation, and VMware Fusion. The highest-risk issues are CVE-2026-59309 (CVSS 9.8) and CVE-2026-59310 […]

19. August 2026/by Joseph Lee
Blog

Lazarus Combines Social Engineering and CVE-2026-68820 Windows Privilege-Escalation Flaw for Espionage

Operation Dream Job is a long-running cyber attack campaign operated by the Lazarus Group [1][2], a prolific North Korean APT threat actor. The group is known for targeting defense, aerospace, and aviation organizations across Europe, Asia, and South America since at least 2016, potentially as far back as 2009 or earlier. Public reporting has often […]

17. August 2026/by Joseph Lee
Blog

Threat Report July 2026: Vulnpocalypse – Just Scratching the Surface?

Plenty of new risks to enterprise IT defenders emerged in July 2026. Earlier this month, our blog covered emerging issues such as active exploitation of WordPress Core [2], Adobe ColdFusion [3] and Check Point SmartConsole [4]; new critical-severity flaws in Cisco products [5], BeyondTrust RS and PRA [6], and Citrix NetScaler ADC and Gateway [7]; […]

12. August 2026/by Joseph Lee
Page 1 of 9123›»

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn