• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
      • Vulnerability Management
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
      • Vulnerability Management
  • German
  • English
  • Italian
  • Dutch
Joseph Lee

About Joseph Lee

Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.

He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.

Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.

LinkedIn

Entries by Joseph Lee

Blog

September 2026 Threat Report: Unchecked Accumulation of Security Debt in Enterprise IT

Widespread, unchecked accumulation of security debt in enterprise IT is emerging at an accelerated pace. While the numbers are staggering, defenders need to realize that regular scanning, orderly prioritization, and timely patching are still the most fundamental way to prevent attackers from exploiting software flaws for impact. For prudent defenders applying well-orchestrated security programs, vulnerability […]

5. October 2026/by Joseph Lee
Blog

CVE-2026-5430: Full Account Takeover in WSO2 API Management Products Now Actively Exploited

CVE-2026-5430 (CVSS 10), published August 6th, 2026, is a critical authentication bypass in WSO2 JSON Web Token (JWT) authentication affecting multiple WSO2 API management products. The flaw allows a token signed with an unsupported algorithm to bypass JWT authentication. Exploitation allows unauthorized access, compromise of administrative accounts, and full account takeover. Although the CVE was […]

30. September 2026/by Joseph Lee
Blog

CVE-2026-7273: Zyxel GS1900 Switches Actively Exploited Globally

CVE-2026-7273 (CVSS 8.8, EPSS 1.286% (69th)), published in mid-June 2026, is a stack-based buffer overflow that allows unauthenticated remote code execution (RCE) on Zyxel GS1900 series switches. The flaw is in the device’s firmware CGI program and can be triggered via crafted HTTP request. As of September 21st, 2026, CVE-2026-7273 is considered actively exploited and […]

28. September 2026/by Joseph Lee
Blog

CVE-2026-48842: Unauthenticated SQL Injection Flaw in Roundcube Webmail Now Targeted

Overview of CVE-2026-48842, the unauthenticated SQL injection flaw in Roundcube Webmail, shown with its CVSS severity band and EPSS exploitation-probability score CVE-2026-48842 CVSS 8.1 · High EPSS 0.8% (54th) CVE-2026-48842 (CVSS 8.1, EPSS ≥ 54th pctl), published in May 2026, is an unauthenticated SQL injection flaw in Roundcube Webmail. Vulnerable instances warrant prompt attention due […]

24. September 2026/by Joseph Lee
Blog

Patch Now! Heightened Risk Across Cisco Products in September 2026

So far, Cisco has published 97 new CVE IDs affecting its products this month. Although cyber security experts have noted that raw CVE count is not a direct measure of risk, the total makes September Cisco’s largest-ever month for coordinated CVE disclosures. Also, 32 of the CVEs are “umbrella CVEs”—clusters of multiple underlying vulnerabilities grouped […]

22. September 2026/by Joseph Lee
Blog

CVE-2026-85706: CVSS 10 GitLab CE/EE API Flaw Actively Exploited

CVE-2026-85706 (CVSS 10, EPSS 96th pctl), published on September 12th, 2026, is a critical path traversal flaw in the GitLab CE/EE repository Commits API and Repository Files API. Exploitation can allow an unauthenticated attacker to read arbitrary files from the GitLab server on affected self-managed instances. However, the unauthenticated exploit path requires at least one […]

17. September 2026/by Joseph Lee
Blog

Three New JFrog Artifactory CVEs Actively Exploited in the Wild

CVE-2026-82329, CVE-2026-42018, and CVE-2026-42016, all affecting JFrog Artifactory, were added to CISA’s Known Actively Exploited (KEV) in September 2026 [1][2][3]. Artifactory acts as a central repository for software build artifacts, binaries, packages, containers, files, releases, and increasingly AI/ML artifacts. A compromise of Artifactory could allow an attacker to steal sensitive artifacts and credentials, tamper with […]

15. September 2026/by Joseph Lee
Blog

“MikroTrick” Exploit Chain Targets SSH-Exposed MikroTik RouterOS Devices

According to CERT Polska, active exploitation of MikroTik RouterOS has been underway since at least September 2nd, 2026. The chain leverages CVE-2026-67276 (CVSS 9.2) and CVE-2026-86060 (CVSS 9.2) against devices whose SSH service is reachable from public networks. A successful breach yields full control of the targeted system. MikroTik has published fixes for the flaws […]

14. September 2026/by Joseph Lee
Blog

August 2026 Threat Report: The Vulnpocalypse Hits Full Force

The so-called Vulnpocalypse is now in full force. This August 2026 threat report only scratches the surface of new high-risk vulnerabilities that emerged in August 2026. To see how Greenbone’s industry leading vulnerability detection can benefit your IT security operations, visit our SecInfo portal and view our complete coverage portfolio. August reinforced a now too […]

7. September 2026/by Joseph Lee
Blog

CVE-2026-64849: SSRF Flaw in MLflow Actively Exploited

CVE-2026-64849 (CVSS 9.3, EPSS ≥ 95th pctl) is a critical-severity unauthenticated full-read server-side request forgery (SSRF) flaw [CWE-918] in MLflow webhook delivery. The CVE affects all versions prior to 3.15.0. The root cause is flawed redirect handling and DNS rebinding. The flaw is exploited by bypassing the _validate_webhook_url protections in the default MLflow Tracking Server […]

26. August 2026/by Joseph Lee
Page 1 of 9123›»

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn