> Field Notes_

Organic writeups, analysis, and research straight from the lab. My own words, my own work.

Inside Two Separate Device-Code Phishing Operations and the Operator Who Told On Himself

Two live phishing kits crossed my desk. I set out to document how they steal Microsoft 365 sessions. I ended up reading one operator's admin panel, walking the other's victim database an integer at a time, and pulling the first kit's operator straight out of Telegram. Both of them made the same mistake: they protected everything except the thing that gave them away.

read more →

Building an Autonomous Malware Triage Stack

I ended my Kinsing post with an uncomfortable admission about an agent doing in two hours what took us a week. This is what happened when I stopped just thinking about it.

read more →

Agent Analysis: asgardprotector — IExpress SFX Dropper Repackaging AutoIt

Picked up by the deep tier overnight — six minutes of agent time to produce a full report with footnoted evidence. Worth publishing because the technique is dead simple to reproduce and the detection story isn't great.

read more →

Agent Analysis: acrstealer — Signed Go 1.26 with Randomized Module Path

A signed Go PE32 with the trimpath + randomized module name + obfuscated main combo. The C2 came from the OpenCTI label, not the binary — consistent with runtime-decoded configuration.

read more →

Agent Analysis: chacha8 — Tiny ChaCha20 File Encryptor With No C2

A 53 KB binary masquerading as svchost.exe that encrypts files in-place with ChaCha20 and leaves no ransom note, no C2, no kill switch. Completely offline. The agent flagged the cipher from the key-expansion constant in strings.

read more →

Was My Honeypot Part of a Loader-as-a-Service Operation?

When RondoDox hit our honeypot and Kinsing followed six hours later from a different C2, I had a theory. Turns out the research backs it up.

read more →

Dissecting a Mirai Variant: From Honeynet Capture to Ghidra

Walkthrough of capturing a RondoDox/Mirai IoT botnet variant in our honeynet deployment, extracting the binary, and performing static analysis in Ghidra to map C2 infrastructure.

read more →

Kinsing Crypto Miner: Catching a Live One

The first indicator wasn't one thing. It was a cascade of alerts, invisible files, and a file manager that contradicted everything the terminal was telling me.

read more →

Home Lab v3: Network Segmentation with pfSense

Latest iteration of the home lab network architecture. VLANs, firewall rules, and isolated zones for safe malware detonation and ongoing research.

read more →

> Threat Watch_

Current events in cybersecurity, summarized and posted as they happen. Threat intel, malware campaigns, supply chain attacks, new CVEs, AI security, anything worth paying attention to. Updated every two to five days via automated Cowork pipeline.

CISA Adds GitLab Path Traversal CVE-2026-85706 to KEV Catalog

CISA added CVE-2026-85706, a GitLab CE and EE path traversal flaw, to its Known Exploited Vulnerabilities catalog. If you are running self-hosted GitLab on the public internet, patch and audit exposure now.

read more →

CISA Adds Artifactory and ScreenConnect Flaws to KEV Under Risk-Based Directive

CISA added three actively exploited vulnerabilities to its KEV catalog, including two JFrog Artifactory auth bugs and one ConnectWise ScreenConnect privilege flaw. The announcement also serves as the first real exercise of the new BOD 26-04 risk-based patching directive.

read more →

CISA Adds Two MikroTik RouterOS Flaws to KEV Catalog Under Active Exploitation

CISA added CVE-2026-67277 and CVE-2026-86060 to its Known Exploited Vulnerabilities catalog this week. Both affect MikroTik RouterOS and carry the kind of low-complexity, high-impact profile that makes edge routers a persistent target.

read more →

CISA KEV Batch Targets Auth Bypasses on NetScaler, Cisco FMC, Fortinet, Chrome

CISA added four vulnerabilities to its KEV catalog this week, including authentication bypasses in Citrix NetScaler and Cisco FMC. The batch highlights how attackers are still focusing on exposed network edge infrastructure.

read more →

CISA Adds Four KEVs: N-able RMM and Adobe Commerce Zero-Day Under Active Exploitation

CISA added four actively exploited flaws to its KEV catalog this week, including a max-severity Adobe Commerce backdoor and an N-able N-central RMM vulnerability that the vendor cannot seem to patch cleanly.

read more →

SonicWall SMA1000 Zero-Days Chained for RCE in Active Attacks

SonicWall says threat actors are actively chaining two zero-days in the SMA1000 secure access appliance to achieve remote code execution. If you are running this at the edge, treat it as a likely compromise until patched.

read more →

IXON VPN Client CRLF Flaw Allows Root Remote Code Execution

CISA published an advisory for CVE-2026-75925, a 9.6 CVSS CRLF injection in IXON VPN Client before 1.4.7. Unauthenticated attackers can abuse the configuration interface to execute commands as root or SYSTEM.

read more →

CISA Adds Chrome V8 Zero-Day to KEV Under Active Exploitation

CISA added CVE-2026-85046, a Google Chrome V8 type confusion flaw, to its Known Exploited Vulnerabilities catalog on Friday. Federal agencies must prioritize patching under BOD 26-04, and everyone else should treat browser RCE as a Tier 1 risk.

read more →

CISA KEV Update: Seven Actively Exploited Bugs in VPN, AI, and DevOps Tools

CISA added seven new vulnerabilities to its Known Exploited Vulnerabilities Catalog, including pre-auth flaws in SonicWall SMA1000 and bugs in AI and devops tools now under active exploitation.

read more →

Claude Ported a Pre-Auth RCE Exploit Across WAGO PLC Models

Forescout Vedere Labs used Anthropic's Claude to port a working pre-auth RCE for CVE-2021-31886 from one WAGO PLC model to another, running ARM shellcode on live hardware with minimal manual reverse engineering.

read more →

CISA Adds Two Actively Exploited PaperCut Flaws to KEV Catalog

CISA added two actively exploited PaperCut NG/MF flaws to its KEV catalog. CVE-2026-81578 and CVE-2026-82078 should be patched this week, with compromise checks before remediation.

read more →

CISA Red Team Compromises Two Orgs and Exposes the Cost of Untuned Detection

CISA ran simultaneous red-team assessments at two critical infrastructure organizations using identical TTPs. One SOC detected and contained the intrusion; the other never saw it, highlighting how untuned alerts and organizational silos decide outcomes.

read more →

Active Exploitation of Critical Gitea RCE Drops Miner Payloads

CISA is warning that CVE-2026-60004, a critical Gitea RCE scoring 9.8, is under active exploitation. Attackers with ordinary repository write access can execute shell commands and are dropping miner-like payloads in the wild.

read more →

Oracle WebLogic CVSS 10.0 Flaw Added to CISA KEV Under Active Exploitation

CISA has added CVE-2026-21962, a maximum-severity Oracle WebLogic and HTTP Server flaw, to its Known Exploited Vulnerabilities catalog amid active exploitation. Unauthenticated attackers can access critical data over HTTP.

read more →

CISA KEV Update Targets ownCloud, JFrog Artifactory, and Linux Kernel Under BOD 26-04

CISA added three actively exploited vulnerabilities to its KEV catalog this week, covering ownCloud, the Linux kernel, and JFrog Artifactory. The update reinforces BOD 26-04 guidance that federal agencies must prioritize patching exposed assets granting total control post-exploitation.

read more →

CISA KEV Update: 2015 Red Hat Bugs and a 2026 Citrix NetScaler Flaw Actively Exploited

CISA added six actively exploited bugs to the KEV catalog, including decade-old Red Hat privilege escalations and a new Citrix NetScaler memory buffer flaw. If your vulnerability program skips legacy Linux or edge appliances, this week is the time to fix that.

read more →

CISA Adds Actively Exploited Gitea Code Injection to KEV Catalog

CISA added CVE-2026-60004, a Gitea code injection flaw, to its Known Exploited Vulnerabilities catalog this week. If you are running self-hosted Gitea, this is your signal to patch and audit.

read more →

CISA Adds Oracle Weblogic Proxy Flaw to KEV Under New BOD 26-04 Rules

CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog. The Oracle HTTP Server and Weblogic proxy plug-in flaw is now subject to new BOD 26-04 rapid-remediation rules for federal agencies.

read more →

Microsoft Confirms Entra ID CVSS 10 Flaw Actively Exploited

Microsoft disclosed a maximum-severity RCE vulnerability in Entra ID, CVE-2026-69836, that is being exploited in the wild. Despite the CVSS 10.0 rating, the company says no customer action is required.

read more →

macOS Improper Authentication Flaw CVE-2026-65400 Added to CISA KEV

CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog this week, led by a CVSS 9.8 improper authentication bug in Apple macOS that is already under active exploitation.

read more →

CISA KEVs Zimbra Command Injection and Tells Agencies to Hunt Before Patching

CISA added CVE-2026-73570, a Zimbra Collaboration Suite OS command injection flaw, to the KEV catalog. The accompanying BOD 26-04 directive requires federal agencies to hunt for compromise before patching internet-exposed assets.

read more →

CISA Adds Two Actively Exploited TrueConf Server Vulnerabilities to KEV

CISA added CVE-2026-72529 and CVE-2026-72530 for TrueConf Server to its KEV catalog. The announcement highlights new BOD 26-04 requirements that agencies check for compromise before patching internet-facing assets.

read more →

CISA Adds MLflow SSRF to KEV Catalog Under Active Exploitation

CISA added CVE-2026-64849 to its KEV catalog this week, flagging active exploitation of an MLflow SSRF flaw. The advisory highlights BOD 26-04's new requirement to check for pre-patch compromise.

read more →

CISA Adds Four KEVs Covering SharePoint, vCenter, IKE, and macOS

CISA added four actively exploited vulnerabilities to the KEV catalog spanning Microsoft SharePoint, VMware vCenter, IKE, and Apple macOS. If you run any of these, your patching timeline just collapsed.

read more →

CISA Adds Ray Project Code Injection Flaw to KEV Catalog

CISA added CVE-2025-62593 to its KEV catalog this week. A code injection flaw in the Ray distributed computing framework is now confirmed under active exploitation, with serious implications for AI and MLOps infrastructure.

read more →

Unauthenticated DoS in Cisco ASA and FTD Firewalls Actively Exploited

Cisco confirmed that CVE-2026-20349, an unauthenticated remote denial-of-service flaw in ASA and FTD Software, is being exploited in the wild. The vulnerability carries a CVSS score of 8.6.

read more →

CISA KEV Update: Cisco Firewall, Windows Kernel, and Metabase Under Active Exploitation

CISA added three actively exploited vulnerabilities to the KEV catalog, spanning Cisco firewalls, the Windows kernel, and Metabase analytics. Federal agencies now face binding remediation deadlines under BOD 26-04.

read more →

CISA Warns Gunra RaaS Is Hitting Critical Infrastructure Through Known VPN and RDP Flaws

CISA's new advisory on Gunra ransomware confirms the RaaS is actively targeting government and critical infrastructure by exploiting known, unpatched vulnerabilities in internet-facing VPN and RDP gateways.

read more →

Metabase Unauthenticated SQL Injection Zero-Day Exploited in the Wild

Metabase disclosed a CVSS 10.0 zero-day with no CVE identifier that allows unauthenticated remote attackers to inject SQL and gain admin access. Exploitation is already happening in the wild.

read more →

CISA Adds Progress Kemp LoadMaster Command Injection to KEV After Hundreds of Attacks

CISA cataloged CVE-2026-8037 in its Known Exploited Vulnerabilities list after detecting 792 exploit attempts against Progress Kemp LoadMaster gateways. If you are running LoadMaster, your management plane is already being scanned.

read more →

Progress LoadMaster Command Injection Lands on CISA KEV Catalog

CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog this week, confirming active exploitation of a command injection flaw in Progress LoadMaster. Federal agencies must prioritize remediation under BOD 26-04, but every organization running this edge infrastructure should treat it with the same urgency.

read more →

CISA Adds Langflow, Tomcat, and N-central Flaws to KEV Under Active Exploitation

CISA added three actively exploited flaws to its KEV catalog on August 5, including CVE-2026-9198, an unauthenticated remote code execution vulnerability in the Langflow AI framework scoring 9.8.

read more →

CISA Adds Actively Exploited TeamCity Deserialization Flaw to KEV Catalog

CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog on August 5. The JetBrains TeamCity deserialization bug grants total control of build servers and triggers rapid remediation requirements under BOD 26-04.

read more →

CISA KEV Update: N-able Auth Bypass, Langflow Code Injection, Tomcat Encryption Flaw

CISA added three vulnerabilities to its KEV catalog on August 4, including an N-able N-central authentication bypass, an IBM Langflow code-injection flaw, and an Apache Tomcat missing-encryption bug. All three are under active exploitation and now carry binding remediation deadlines for federal agencies under BOD 26-04.

read more →

CISA Flags Actively Exploited N-able N-central Authentication Bypass

CISA added CVE-2026-18577 to its KEV catalog this week. The N-able N-central authentication bypass is being actively exploited and poses a supply-chain risk to every downstream endpoint the platform manages.

read more →

Siemens Desigo CC OpenSSL Flaw Leaves Building Automation Open to RCE

CISA warns that a CVSS 9.8 OpenSSL buffer overflow in Siemens Desigo CC could allow remote code execution in building automation systems. Patches are available only for V9, leaving V7 and V8 operators relying on countermeasures.

read more →

Rapid7 Publishes PoC for Actively Exploited Check Point SmartConsole Auth Bypass

CVE-2026-16232, a CVSS 9.3 authentication bypass in Check Point SmartConsole, is under active exploitation and now has public proof-of-concept code from Rapid7. If your Security Management Server is exposed, this is a drop-everything patch.

read more →

CISA Flags 40 Linux CVEs in Siemens S7-1500 MFP Controllers

CISA advisory ICSA-26-209-04 discloses over 40 upstream Linux CVEs in the GNU/Linux subsystem of Siemens SIMATIC S7-1500 CPU 1518 MFP firmware V3.1.6. Siemens is preparing fixes, but defenders should segment these edge-capable PLCs now.

read more →

Cisco FMC Zero-Day Uses Static Credentials to Breach Management Plane

CISA added CVE-2026-20316 to its Known Exploited Vulnerabilities catalog after attackers used static credentials to access Cisco Secure Firewall Management Center. A CVSS 5.3 score understates the risk of handing unauthenticated remote actors the keys to your firewall policy.

read more →

Cisco Secure Firewall Management Center Hard-Coded Password Added to CISA KEV

CISA added CVE-2026-20316 to its KEV catalog this week. A hard-coded password in Cisco Secure Firewall Management Center is under active exploitation, and federal agencies now face a binding remediation deadline.

read more →

Arista Patches Actively Exploited VeloCloud Orchestrator Command Injection Zero-Day

Arista patched a maximum-severity command injection zero-day in on-premises VeloCloud Orchestrator. Active exploitation means the SD-WAN control plane is already a target.

read more →

CISA Adds Actively Exploited Fortinet and Arista Flaws to KEV

CISA added two new actively exploited vulnerabilities to its KEV catalog: a Fortinet FortiOS information exposure bug and an Arista VeloCloud Orchestrator OS command injection. Both fall under the new BOD 26-04 prioritization rules for federal agencies.

read more →

Siemens Opcenter X JWT Algorithm Confusion Allows Full Admin Takeover

Siemens patched a CVSS 10 authentication bypass in Opcenter X. CVE-2026-56451 lets unauthenticated attackers forge JWT tokens by manipulating the algorithm header, granting full admin access to manufacturing execution systems.

read more →

Cl0p Affiliates Chain Pre-Auth Flaws in PTC Windchill and FlexPLM for RCE

Cl0p affiliates are chaining pre-authentication flaws in PTC Windchill and FlexPLM to gain unauthenticated remote code execution and extort manufacturing victims. If your PLM stack faces the internet, this is your Monday morning priority.

read more →

Check Point Patches Actively Exploited SmartConsole Authentication Bypass

Check Point patched an actively exploited zero-day in SmartConsole that allows unauthenticated attackers to gain full administrative access to Security Management and MDSM servers. CVE-2026-16232 scores 9.3 and demands immediate attention.

read more →

LAUNDRY BEAR Escalates to Zero-Day Exploitation Against Zimbra Email Servers

CISA warns that Russian state-supported LAUNDRY BEAR is now targeting Zimbra Collaboration Suite with a zero-day exploit to steal email from Western government and commercial targets.

read more →

CISA Adds Check Point SmartConsole and SharePoint Flaws to KEV Catalog

CISA confirmed active exploitation of two vulnerabilities this week: an improper authentication bug in Check Point SmartConsole and a deserialization flaw in Microsoft SharePoint. Federal agencies must now patch and hunt for pre-patch compromise under BOD 26-04.

read more →

CISA Adds WordPress Core, Langflow, and DD-WRT to KEV Catalog

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog, including two 2026 WordPress Core bugs, a Langflow flaw, and a four-year-old DD-WRT buffer overflow. Federal agencies now face tiered remediation deadlines under BOD 26-04.

read more →

CISA Adds Actively Exploited SharePoint RCE Zero-Day to KEV Catalog

CISA added CVE-2026-58644, a critical deserialization flaw in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog with a patch deadline of July 19 for federal agencies. If you still have on-prem SharePoint anywhere in your environment, that is your weekend priority.

read more →

CISA: AutomationDirect Productivity Suite Flaws Enable Local Privilege Escalation

CISA issued ICSA-26-197-04 for six vulnerabilities in AutomationDirect Productivity Suite 4.6.2.2 and earlier. Local attackers can exploit kernel memory corruption flaws to escalate privileges on engineering workstations bridging IT and OT.

read more →

Joomla iCagenda and Balbooa Forms Flaws Exploited as CVSS-10 Zero-Days

CISA added two maximum-severity flaws in Joomla extensions iCagenda and Balbooa Forms to its KEV catalog after observing active zero-day exploitation. Arbitrary file upload vulnerabilities allow remote code execution on affected sites.

read more →

FSB Center 16 Targets Critical Infrastructure Through Edge Router Exploitation

CISA, NSA, and international partners warn that Russian FSB Center 16 actors continue to compromise critical infrastructure networks by exploiting poorly configured edge routers and networking devices. Audit your perimeter this week.

read more →

CISA Adds FortiSandbox and SharePoint Vulnerabilities to KEV Catalog

CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog this week, including two OS command injection flaws in FortiSandbox and a deserialization bug in SharePoint. All three are confirmed under active exploitation.

read more →

CISA Adds Actively Exploited KNX Protocol and Oracle EBS Flaws to KEV Catalog

CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog this week, including a building automation protocol flaw and an Oracle E-Business Suite privilege bug. Both are under active exploitation and now carry BOD 26-04 remediation obligations for federal agencies.

read more →

CISA Adds SonicWall and SharePoint Flaws to Known Exploited Vulnerabilities Catalog

CISA added four new vulnerabilities to its KEV catalog, including SSRF and code injection flaws in SonicWall SMA1000 appliances and authentication bypass issues in Microsoft SharePoint and ADFS. All four are confirmed as actively exploited and grant total control of affected assets.

read more →

CISA Flags 18-Year-Old Cisco IOS CSRF Under Active Exploitation

CISA added an 18-year-old Cisco IOS CSRF vulnerability to its KEV catalog. If you still have public-facing web admin on edge routers, this is your Monday morning priority.

read more →

Hydro-Québec EV Charging Backend Hit by 9.8 CVSS Websocket Auth Bypass

CISA advisory ICSA-26-188-01 details CVE-2026-20744 in Hydro-Québec's Le Circuit Electrique charging station backend, where an unauthenticated websocket endpoint allows privilege escalation. Versions prior to June 2026 are affected, and Hydro-Québec has updated the majority of its fleet.

read more →

Microsoft Details GigaWiper Backdoor Combining Wiper and Fake Ransomware

Microsoft analyzed GigaWiper, a destructive Windows backdoor that combines disk wiping, spyware, and fake ransomware into a single operator-controlled platform. The malware lets attackers choose their destruction method from a menu of previously separate tools.

read more →

CISA Adds Joomla iCagenda and Balbooa Forms Upload Flaws to KEV Catalog

CISA has added two unrestricted file upload vulnerabilities in the Joomla extensions iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities catalog. If you are running either plugin, patch this week.

read more →

CISA Adds Adobe ColdFusion Path Traversal to KEV Under New BOD Rules

CISA added CVE-2026-48282, an actively exploited Adobe ColdFusion path traversal, to the KEV catalog. The entry comes as BOD 26-04 mandates rapid, risk-based remediation for federal agencies.

read more →

CISA Adds Three KEVs Targeting Joomla Page Builders and Langflow

CISA added three new KEVs on Tuesday, including two Joomla page builder plugins and a Langflow authorization bypass. All three grant total control of the asset and demand immediate patching.

read more →

Siemens SINEC OS Flaws Hit RUGGEDCOM Industrial Switches with CVSS 9.8 Severity

Siemens patched SINEC OS for the RUGGEDCOM RST2428P after CISA disclosed a CVSS 9.8 cluster of memory safety and access control flaws. The advisory reads like a catalog of fundamental security failures in industrial network gear.

read more →

Progress Kemp LoadMaster Pre-Auth RCE Under Active Exploitation

eSentire's TRU says attackers are already exploiting CVE-2026-8037, a pre-authentication OS command injection in Progress Kemp LoadMaster rated CVSS 9.6. If you are running LoadMaster on the edge, this is a patch-now event.

read more →

CISA Adds SharePoint Deserialization RCE CVE-2026-45659 to KEV Under Active Exploitation

CISA confirmed active exploitation of CVE-2026-45659, a CVSS 8.8 deserialization flaw in Microsoft SharePoint Server patched in May. If your farm is still unpatched, this is your Monday morning priority.

read more →

Ransomware Gangs Exploiting Windows Defender BlueHammer Privilege Escalation

CISA confirmed this week that ransomware gangs are actively exploiting the BlueHammer local privilege escalation flaw in Windows Defender, shifting a previously abused zero-day into broad commodity operations.

read more →

Anubis Ransomware Exploits Citrix Bleed 2 via RMM and Credentials

Threat actors linked to Anubis are actively exploiting CVE-2025-5777 to breach networks, then using legitimate RMM tools and stolen credentials for hands-on-keyboard lateral movement and payload deployment.

read more →

Oracle E-Business Suite Payments Bug CVE-2026-46817 Actively Exploited

A critical authentication and privilege flaw in Oracle E-Business Suite Payments is being actively exploited to take over instances. Defused Cyber reports in-the-wild attacks against CVE-2026-46817, rated CVSS 9.8.

read more →

CISA KEVs SharePoint Deserialization Bug Under Active Exploitation

CISA added CVE-2026-45659 to the KEV catalog. A Microsoft SharePoint deserialization flaw is actively exploited, and BOD 26-04 means federal agencies must now hunt for pre-patch compromise.

read more →

CISA Adds SimpleHelp Authentication Bypass to KEV Catalog Under Active Exploitation

CISA added CVE-2026-48558, a SimpleHelp authentication bypass, to the KEV catalog. If you run this remote support tool, assume active exploitation and patch now while checking for pre-patch compromise.

read more →

DirtyClone Linux Kernel Bug Gives Local Attackers Root via Cloned Packets

JFrog Security Research published a working exploit for DirtyClone (CVE-2026-43503), a Linux kernel privilege escalation that lets local users gain root by corrupting file-backed memory through cloned network packets. In containerized environments, local is all an attacker needs.

read more →

Delta Electronics DTM Soft Flaw Allows Arbitrary Code Execution via Project Files

CISA issued an advisory for CVE-2026-12578, a deserialization flaw in Delta Electronics DTM Soft affecting all versions. With no patch available yet, critical manufacturing sectors worldwide are left relying on file-handling workarounds to prevent arbitrary code execution.

read more →

Unauthenticated WebSocket APIs in EVoke Charging System Score CVSS 9.4

CISA issued an advisory for EVoke Systems CSMS, citing a CVSS 9.4 bug and multiple authentication failures that let attackers impersonate charging stations and gain admin control.

read more →

CISA Adds PTC Windchill RCE to KEV Amid Ongoing Web Shell Campaign

CISA confirmed an actively exploited RCE in PTC Windchill PDMLink and FlexPLM, adding it to the KEV catalog as web shell attacks against enterprise PLM systems continue. Manufacturing and critical infrastructure defenders should treat this as an acute, patch-now threat.

read more →

CISA Adds PTC Windchill and Cisco CUCM to KEV Under Active Exploitation

CISA added two enterprise software vulnerabilities to the KEV catalog this week, including a PTC Windchill input validation flaw and a Cisco Unified Communications Manager SSRF. Both are actively exploited and fall under BOD 26-04's new rapid-remediation rules for federal agencies.

read more →

ABB Freelance Security Lock Exposes Underlying OS During Active Operations

CISA warns that ABB Freelance Security Lock allows access to underlying OS functions even when Operations mode is active, affecting all versions across Freelance 2013 through 2024.

read more →

CISA Adds Three Ubiquiti UniFi OS Flaws and Lantronix Bug to KEV Catalog

CISA added four actively exploited vulnerabilities to its KEV catalog, including three Ubiquiti UniFi OS bugs and a Lantronix EDS5000 code injection flaw. Edge network and serial gateway infrastructure continue to be prime targets.

read more →

ShapedPlugin Pro Plugins Backdoored Through Official Update Pipeline

Attackers compromised ShapedPlugin's build pipeline and pushed backdoored code to Pro plugins through official licensed update channels. Paying customers received the malware as part of routine, trusted updates.

read more →

AzeoTech DAQFactory CVE-2026-12390 Allows Code Execution via Malicious .ctl Files

CISA issued an ICS advisory for AzeoTech DAQFactory versions 21.1 and prior. A type-confusion flaw in CVE-2026-12390 lets attackers achieve arbitrary code execution by tricking users into loading malicious .ctl files.

read more →

Rockwell FactoryTalk Historian SE Auth Bypass and Race Condition Disclosed by CISA

CISA disclosed three vulnerabilities in Rockwell FactoryTalk Historian Site Edition, including an authentication bypass that yields valid tokens after repeated login requests. Critical manufacturing sites should isolate and patch these systems immediately.

read more →

Cisco Patches Actively Exploited SD-WAN Manager Flaw

Cisco fixed CVE-2026-20262 in Catalyst SD-WAN Manager after seeing active exploitation. The authenticated web UI bug scores 6.5, but any live fire against your WAN brain is worth treating as critical.

read more →

CISA Adds Splunk Enterprise Missing Auth Bug to KEV as BOD 26-04 Reshapes Patching

CISA added CVE-2026-20253 to its KEV catalog: a missing-authentication flaw in Splunk Enterprise confirmed under active exploitation. The timing underscores how BOD 26-04 is forcing sharper prioritization of publicly exposed assets that grant total control.

read more →

CISA Adds Maximum Severity Joomla JCE Flaw to KEV Catalog

CISA has added CVE-2026-48907, a maximum-severity improper access control flaw in the Widget Factory Joomla Content Editor, to its KEV catalog. Federal agencies face a rapid patching deadline under BOD 26-04.

read more →

Oracle PeopleSoft Zero-Day Actively Exploited by ShinyHunter for Data Theft

Oracle is warning of a critical unauthenticated RCE zero-day in PeopleSoft Suite tracked as CVE-2026-35273. ShinyHunter is actively exploiting the flaw to steal enterprise HR and financial data.

read more →

CISA Adds Cisco SD-WAN and LiteSpeed Flaws to KEV Catalog

CISA added two actively exploited flaws to its KEV catalog alongside BOD 26-04, which directs federal agencies to prioritize patches for publicly exposed assets that grant total control post-exploitation.

read more →

Unpatched Langflow RCE Flaw CVE-2026-5027 Under Active Exploitation

VulnCheck reports active exploitation of CVE-2026-5027, an unpatched path-traversal flaw in the Langflow AI platform that grants unauthenticated attackers arbitrary file write and subsequent remote code execution.

read more →

ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Extort Universities

Mandiant and Google report that UNC6240, known as ShinyHunters, actively exploited CVE-2026-35273 in Oracle PeopleSoft as a zero-day. The campaign primarily hit higher education institutions, with most victim organizations notified in the United States.

read more →

Ivanti Sentry Command Injection Lands in KEV as BOD 26-04 Takes Effect

CISA added CVE-2026-10520 to its Known Exploited Vulnerabilities catalog alongside a new federal directive that changes how agencies prioritize patches and prove compromise before remediation.

read more →

CISA Adds Chrome V8, Arista EOS, and Cisco SD-WAN to KEV Catalog Under Active Exploitation

CISA added three actively exploited vulnerabilities to the KEV catalog, spanning Chrome's V8 engine, Arista EOS, and Cisco Catalyst SD-WAN Manager. Federal agencies face binding remediation deadlines, but every organization should treat these as patch-this-week priorities.

read more →

CISA KEVs: LiteLLM Command Injection and Check Point Gateway Auth Bypass Under Active Exploit

CISA added two vulnerabilities to the KEV catalog Monday: command injection in BerriAI LiteLLM and an authentication flaw in Check Point Security Gateways. Both are being actively exploited.

read more →

Unpatched Cisco SD-WAN Manager Zero-Day Actively Exploited for Root Access

Cisco confirmed active exploitation of CVE-2026-20245, a high-severity zero-day in Catalyst SD-WAN Manager that enables root privilege escalation. No patch is available yet, and the flaw affects on-prem, cloud, and FedRAMP deployments.

read more →

CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog

CISA added CVE-2026-28318, a high-severity SolarWinds Serv-U denial-of-service bug, to its Known Exploited Vulnerabilities catalog this week after spotting active exploitation in the wild.

read more →

Eight Federal Agencies Warn on Internet-Exposed Tank Gauges

A joint advisory from eight federal agencies warns that internet-exposed automatic tank gauge systems are under active malicious targeting across energy, chemical, and transportation sectors. The recommended fixes are basic but urgent: remove them from the public internet and enforce strong authentication.

read more →

SolarWinds Serv-U CVE-2026-28318 Added to CISA KEV Under Active Exploitation

CISA added SolarWinds Serv-U CVE-2026-28318 to the KEV catalog this week. The uncontrolled resource consumption flaw is under active exploitation, and file-transfer edge systems remain a reliable target for attackers.

read more →

Magento Cache Warmer Deserialization Flaw CVE-2026-45247 Added to CISA KEV

CISA added CVE-2026-45247 to its KEV catalog. The deserialization flaw in Mirasvit's Magento Full Page Cache Warmer is actively exploited and carries a CVSS score of 9.8.

read more →

CISA Adds 2022 Linux Kernel Bug and Android Zero-Day to KEV

CISA added two vulnerabilities to its KEV catalog this week: a four-year-old Linux kernel bug and an actively exploited Android Framework zero-day. Both are under active attack and should be prioritized immediately.

read more →

CISA Adds Oracle WebLogic CVE-2024-21182 to KEV Catalog

CISA added CVE-2024-21182 to the KEV catalog. The two-year-old Oracle WebLogic flaw allows unauthenticated server takeover and is still being actively exploited in the wild.

read more →

CISA KEVs Palo Alto GlobalProtect Auth Bypass Under Active Exploitation

CISA added CVE-2026-0257 to the KEV catalog this week. An authentication bypass in Palo Alto PAN-OS GlobalProtect is being actively exploited to establish unauthorized VPN tunnels into enterprise networks.

read more →

North Korean Actor UNC1069 Backdoors Axios NPM Package in Supply Chain Attack

UNC1069 compromised the widely used axios NPM package to distribute the WAVESHAPER.V2 backdoor. If your builds pulled versions 1.14.1 or 0.30.4 on March 31, you need to hunt your dependency trees this week.

read more →

Google Tracks AI Distillation and Accelerated Adversarial Attack Tooling

Google Threat Intelligence Group reports threat actors are increasingly using AI to speed up reconnaissance, social engineering, and malware development, while also mounting model extraction distillation attacks against AI services.

read more →

Poisoned Nx Console VS Code Extension Used to Breach GitHub Employee and Repositories

CISA warns that a compromised Nx Console VS Code extension auto-updated to poisoned version 18.95.0, granting threat actors access to a GitHub employee device and internal repositories. Developer tooling is now a primary supply chain attack vector.

read more →

Mandiant Refreshes Destructive Attack Guidance as Geopolitical Tensions Rise

Mandiant released updated hardening guidance for destructive attacks, adding endpoint and MDM platform abuse to the watch list as global instability drives more wiper and ransomware activity.

read more →

DarkSword iOS Zero-Day Chain Spreads Across Surveillance and State Actors

GTIG's DarkSword report details six iOS zero-days already spreading across commercial surveillance vendors and suspected state-sponsored actors. The same exploit proliferation pipeline we watched with Coruna is repeating on modern iPhones.

read more →

Mandiant: Ransomware Profits Drop as Actor TTPs Shift Under Pressure

Mandiant's latest analysis shows ransomware profitability is declining due to better defenses and faster recovery. The real risk is how financially motivated actors adapt their tactics when margins shrink.

read more →

Iran's Back in U.S. OT, and They Didn't Need a Zero-Day

CISA's AA26-097A warns that Iran-linked APTs, likely CyberAv3ngers, are abusing internet-exposed Rockwell/Allen-Bradley PLCs to disrupt U.S. water, energy, and local government. No zero-day required, just bad exposure.

read more →

CVE-2024-3400: PAN-OS Command Injection, Patch Now

Critical command injection vulnerability in Palo Alto Networks PAN-OS GlobalProtect gateway. Active exploitation confirmed. CVSS 10.0.

read more →

APT29 Targets Energy Sector with Spear-Phishing Campaign

CISA advisory warns of renewed APT29 activity targeting U.S. energy infrastructure with sophisticated spear-phishing lures impersonating regulatory bodies.

read more →

Ivanti Connect Secure Auth Bypass Under Active Exploitation

CVE-2024-21887 authentication bypass in Ivanti Connect Secure being actively exploited in the wild. Chained with SSRF for remote code execution.

read more →

New Kinsing Campaign Targets Misconfigured Docker Hosts

Updated Kinsing variant scanning for exposed Docker API endpoints. Deploys XMRig miner and establishes persistence via cron jobs and rootkit modules.

read more →