top of page
Cyber Alerts.webp

Cyber Alerts

DEFENSE INTELLIGENCE

Alert:  Microsoft SharePoint Vulnerability Exploited Despite “Medium” Severity (CVE-2026-32201)

Thurs, Apr 16

A medium-severity vulnerability in Microsoft SharePoint (CVE-2026-32201) is being actively exploited, with researchers warning that the flaw can enable unauthorized access and manipulation of sensitive data. Despite its lower severity score, the vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, signaling real-world risk. What You Should Know: - CVE-2026-32201 (CVSS 6.5) is an input validation flaw enabling spoofing attacks. - Successful exploitation can allow attackers to: - Access confidential information - Modify data within SharePoint environments - Researchers observed a coordinated reconnaissance campaign targeting SharePoint across multiple IPs and hosting providers. - CISA has added the vulnerability to the KEV catalog, confirming active exploitation. - Microsoft has issued mitigations, though initial guidance was limited. - This follows a pattern of repeated SharePoint targeting, including large-scale exploitation campaigns in 2025. Recommended Actions: - Apply Microsoft’s mitigation guidance for CVE-2026-32201 immediately. - Do not deprioritize based on severity. Treat as actively exploited. - Monitor SharePoint environments for unusual access or data modification activity. - Review logs for spoofing-related anomalies or unauthorized requests. - Prioritize SharePoint in patching and threat detection workflows.

Alert:  Internet-Connected OT Devices Targeted in Iran-Linked Attacks Causing Operational Disruption

Thurs, Apr 9

U.S. agencies are warning that Iran-affiliated threat actors are actively targeting internet-connected operational technology (OT) devices in the United States, causing operational disruption and financial loss across multiple critical infrastructure sectors. The joint advisory says the activity has affected municipal governments, water and wastewater systems, and the energy sector. What You Should Know: - The advisory was issued jointly by U.S. agencies including the FBI, NSA, and Department of Defense components, and warns that the campaign has intensified amid the current U.S.-Iran conflict. - Attackers are specifically targeting internet-exposed PLCs, especially Rockwell Automation / Allen-Bradley devices, and may also be targeting Siemens equipment. - Agencies say victims experienced disruption through malicious manipulation of HMI and SCADA displays and interference with PLC operations. - CISA previously ordered agencies to patch CVE-2021-22681, a Rockwell OT vulnerability now tied to ongoing exploitation concerns. - Officials compare the activity to earlier Iran-linked campaigns against PLC environments, but note that the current operations show continued focus on deeper operational access, not just defacement. Recommended Actions: - Remove PLCs, HMIs, and SCADA components from direct internet exposure immediately. - Patch affected Rockwell and other OT systems, including fixes for CVE-2021-22681 where applicable. - Review logs for suspicious remote access, unauthorized project-file changes, and abnormal HMI/SCADA display manipulation. - Segment OT from IT and restrict management interfaces to trusted internal networks only. - Treat any exposed OT environment as high risk and prioritize incident response if signs of manipulation are found.

Alert:  Ransomware Deploys Within 24 Hours by Exploiting Newly Disclosed Vulnerabilities

Tue, Apr 7

Microsoft warns that the Medusa ransomware group is exploiting newly disclosed vulnerabilities and moving from initial access to data exfiltration and ransomware deployment in as little as 24 hours. The group is actively targeting internet-facing systems during the patch gap, dramatically shrinking the window defenders have to respond. What You Should Know: - Medusa is exploiting vulnerabilities within days—or even before public disclosure. - Attacks can progress from intrusion to ransomware deployment in under 24 hours. - Primary targets include healthcare, education, finance, and public sector organizations. - Initial access focuses on unpatched, internet-facing systems. - Attackers quickly establish persistence by creating new user accounts. - Use of legitimate tools (e.g., ScreenConnect, AnyDesk) helps evade detection. Recent exploited vulnerabilities include: CVE-2026-23760 (SmarterMail) CVE-2025-10035 (GoAnywhere MFT) Recommended Actions: - Reduce exposure of internet-facing systems and validate external attack surface. - Accelerate patch timelines for newly disclosed vulnerabilities. - Monitor for rapid post-compromise behaviors (new accounts, remote tool usage). - Implement controls for remote access tools and privileged account creation. - Treat intrusion detection as time-sensitive—hours, not days.

Alert:  Fortinet FortiClient EMS Vulnerability Actively Exploited, Risk of Widespread Compromise

Tue, Apr 7

U.S. and Singapore government agencies warn that a critical vulnerability in Fortinet FortiClient EMS (CVE-2026-35616) is actively being exploited in the wild, with organizations urged to immediately apply available hotfixes to prevent compromise. What You Should Know: - CVE-2026-35616 (CVSS 9.1) is under active exploitation. - Affects FortiClient Endpoint Management Server (EMS), widely used across enterprises and government environments. - Exploitation activity began rapidly after discovery, with honeypots capturing attacks immediately. - Timing suggests attackers are exploiting low-response windows (e.g., holidays). - This is the second FortiClient EMS vulnerability in recent weeks, increasing exposure risk. - CISA issued urgent guidance requiring rapid mitigation. Recommended Actions: - Apply Fortinet’s hotfix immediately. - Audit all internet-exposed FortiClient EMS instances. - Check for indicators of compromise across affected systems. - Monitor for abnormal authentication or endpoint management activity. - Prioritize patching cadence for repeat-target platforms like Fortinet.

Alert:  Sensitive Data Exposure Risk in Citrix NetScaler Could Trigger New Exploitation Wave

Fri, Mar 27

Citrix has disclosed a critical vulnerability (CVE-2026-3055) in NetScaler ADC and Gateway that can expose sensitive data, raising concerns of a potential new exploitation wave similar to CitrixBleed. While widespread exploitation has not yet been confirmed, researchers warn that attacks are likely once a public proof of concept is released. What You Should Know: - CVE-2026-3055 (CVSS 9.3) is an input validation flaw that can lead to sensitive data leakage, including session-related information. - A second flaw (CVE-2026-4368, CVSS 7.7) was also disclosed. - The vulnerability behavior is similar to CitrixBleed (2023), which enabled session hijacking and ransomware attacks. - Systems configured as SAML identity providers are particularly at risk. Researchers are already seeing: - Increased scanning activity - Authentication method fingerprinting in the wild Exploitation is expected to begin rapidly after public PoC release. NetScaler devices remain a high-value initial access target for attackers. Recommended Actions: - Apply Citrix patches immediately for NetScaler ADC and Gateway. - Identify systems using SAML authentication and prioritize remediation. - Monitor for unusual authentication behavior or session anomalies. - Review logs for scanning, probing, or authentication fingerprinting activity. Treat this as a pre-exploitation window: time to act before weaponization scales.

Alert:  Zero-Day in Dell RecoverPoint Enables Root-Level Persistence

Thurs, Feb 26

Threat actors are actively exploiting a critical hardcoded credential vulnerability in Dell RecoverPoint for Virtual Machines. The flaw enables unauthenticated attackers to gain root-level access and deploy advanced backdoors. What You Should Know: - CVE-2026-22769 (CVSS 10) - Exploited by UNC6201 (China-linked) - Used to deploy Grimbolt, replacing prior Brickstorm malware - Enables lateral movement and persistent root access - Added to CISA KEV Recommended Actions: - Apply Dell’s mitigations immediately - Audit for unauthorized root access - Hunt for Grimbolt/Brickstorm indicators - Review VMware environments for persistence mechanisms

Alert:  Active Exploitation of Cisco SD-WAN Infrastructure

Thurs, Feb 26

Five Eyes cybersecurity agencies warn that threat actors are actively exploiting Cisco SD-WAN vulnerabilities to gain persistent root-level access and insert rogue devices into network management planes. What You Should Know: - Affects Cisco SD-WAN (CVE-2026-20127, CVE-2022-20775) - Attackers can create rogue SD-WAN peers - Root privilege escalation and log evasion observed - Exploitation ongoing since 2023 - Emergency directives issued Recommended Actions: - Patch immediately - Audit SD-WAN control plane for rogue devices - Investigate logging anomalies - Restrict external management access - Follow Five Eyes hunt guidance

Alert:  Critical BeyondTrust Remote Support Flaw Shows Early Exploitation Activity

Fri, Feb 13

Security researchers are reporting a surge in reconnaissance and early exploitation attempts targeting CVE-2026-1731, a critical operating system command injection vulnerability affecting BeyondTrust Remote Support and certain versions of Privileged Remote Access (PRA). The flaw allows unauthenticated remote command execution and is a variant of the vulnerability exploited in the 2024 U.S. Treasury Department breach. What You Should Know: - CVE-2026-1731 enables unauthenticated attackers to execute arbitrary commands without credentials or user interaction. - The flaw is linked to the same vulnerability class used by Silk Typhoon in the 2024 Treasury intrusion. - A surge in reconnaissance activity began shortly after a proof-of-concept was published. - Scanning activity has been observed from infrastructure tied to a commercial VPN provider. - Limited in-the-wild exploitation has been confirmed, with researchers warning activity may increase. BeyondTrust has automatically patched cloud-hosted customers; self-hosted deployments require manual upgrades. Recommended Actions: - Immediately apply BeyondTrust’s latest updates for Remote Support and PRA. - Identify and restrict external exposure of BeyondTrust services. - Monitor for suspicious command execution or abnormal outbound traffic. - Review logs for anomalous authentication bypass attempts. - Treat unpatched systems as high-risk due to prior state-sponsored exploitation of similar flaws.

Alert:  Russian Hackers Exploit Microsoft Office Zero-Day — Tactics Likely to Broaden Beyond Current Targets

Fri, Feb 6

Researchers report that Russian state-linked hackers (APT28 / Fancy Bear) are actively exploiting a recently disclosed Microsoft Office vulnerability (CVE-2026-21509) in a sophisticated espionage campaign currently focused on European maritime, transportation, and diplomatic organizations. While the observed activity is international in scope, the attack technique itself is broadly applicable and could quickly shift to new industries and regions using the same exploit and delivery methods. What You Should Know: - The campaign exploits CVE-2026-21509, a newly disclosed Microsoft Office vulnerability weaponized within days of disclosure. - Initial targets include organizations in Poland, Slovenia, Turkey, Greece, the UAE, Ukraine, Slovakia, and Romania. - Attacks were delivered via a 72-hour concentrated spearphishing operation, using: - Compromised government email accounts - Legitimate-looking Office documents that trigger exploitation automatically - Once compromised, systems deployed: - MiniDoor malware for email theft - PixyNetLoader, which installs a Covenant backdoor - The attackers used legitimate cloud services for command-and-control to blend into normal traffic. - While current targeting reflects geopolitical priorities, the same exploit chain can be reused against commercial enterprises, critical infrastructure, or domestic organizations with minimal modification. Recommended Actions: - Apply Microsoft patches for CVE-2026-21509 immediately, regardless of industry or geography. - Treat this as a general Microsoft Office exploitation risk, not a region-specific threat. - Monitor for suspicious Office execution behavior and unusual cloud-based outbound traffic. - Harden email controls against trusted-but-compromised sender domains. - Conduct proactive threat hunting for MiniDoor, PixyNetLoader, and Covenant indicators. - Brief users that geopolitical lures are a delivery mechanism — not a limitation on who can be targeted.

Alert:  Okta Access allowing Escalated Identity-based Extortion 

Wed, Feb 4

Security researchers are tracking an escalation in extortion activity linked to the ShinyHunters ecosystem, involving voice phishing and branded credential-harvesting sites to compromise identity systems — including Okta environments. What You Should Know: - Multiple clusters (UNC6661, UNC6671, UNC6240) impersonate IT staff to steal SSO credentials and MFA codes. - Victims are directed to organization-branded phishing pages during phone calls. - Mandiant confirmed Okta account access in some cases. - After access is gained, attackers pivot into cloud SaaS platforms to steal data. - Extortion emails demand payment within 72 hours, and a new leak site has appeared. Recommended Actions: - Alert employees to IT impersonation and MFA reset scams. - Enforce verification steps for identity or MFA changes. - Review Okta logs for abnormal MFA challenges, session creation, and IP anomalies. - Deploy phishing-resistant MFA where possible. - Prepare an extortion response plan focused on investigation, not engagement.

Alert:  Ivanti EPMM Servers Actively Exploited via Critical RCE Vulnerabilities

Wed, Feb 4

Security researchers are warning of active exploitation attempts against on-premises Ivanti Endpoint Manager Mobile (EPMM) following disclosure of two critical remote code execution vulnerabilities. Evidence suggests targeted attacks began prior to public disclosure, with post-compromise activity now expanding. What You Should Know: - The flaws (CVE-2026-1281 and CVE-2026-1340) allow unauthenticated remote code execution. - CVE-2026-1281 was added to CISA’s Known Exploited Vulnerabilities catalog immediately. - Ivanti confirmed exploitation affecting a limited number of customers before disclosure. - Researchers report targeted exploitation, not broad scanning, followed by: - Web shell deployment - Reverse shells and callback activity - Over 1,400 EPMM instances remain exposed globally. Recommended Actions: - Apply Ivanti EPMM patches immediately. - Identify and restrict externally accessible EPMM instances. - Hunt for web shells, outbound callbacks, and privilege escalation activity. - Treat impacted systems as potentially compromised and escalate to IR if indicators are found.

Alert:  QR-Code Phishing Used by North korean hackers to Bypass MFA and Hijack Cloud Accounts

Fri, Jan 9

The FBI has issued a FLASH warning that North Korean state-sponsored hackers (Kimsuky) are actively using malicious QR codes in spearphishing campaigns to compromise U.S. organizations. The technique, known as QR-code phishing, is designed to bypass traditional email security controls and multi-factor authentication by shifting victims from corporate endpoints to personal mobile devices. What You Should Know: - Kimsuky has targeted think tanks, academic institutions, NGOs, government entities, and foreign policy experts. - Emails impersonate trusted contacts (advisors, embassies, colleagues) and include QR codes claiming to link to: - Questionnaires - Secure document portals - Conference registrations - When scanned, QR codes redirect victims to attacker-controlled infrastructure that: - Fingerprints the mobile device - Presents fake Microsoft 365, Google, Okta, or VPN login pages - Steals credentials and session tokens, allowing MFA bypass - Because the attack occurs on unmanaged mobile devices, it often evades EDR, URL scanning, and email sandboxing. - Once accounts are compromised, attackers establish persistence and send follow-on phishing from the victim’s mailbox. Recommended Actions: - Educate staff to never scan unsolicited QR codes, regardless of apparent sender. - Require phishing-resistant MFA (e.g., FIDO2) for cloud and remote access. - Implement mobile device security or MDM controls capable of inspecting QR-linked URLs. - Monitor for suspicious login activity and token-based authentication abuse. - Enforce least-privilege access and regularly audit account permissions. - Establish a clear internal process for reporting suspicious QR codes. - Coordinate with your local FBI Cyber Squad or report activity to IC3.gov.

Alert:  Zero-Day Cisco Secure Email Exploit

Fri, Dec 19

Cisco has confirmed that Chinese state-sponsored attackers are exploiting a critical zero-day vulnerability (CVE-2025-20393) affecting its Secure Email Gateway and Secure Email and Web Manager products. The flaw carries the maximum severity score of 10 and has been actively exploited since late November. There is no patch available, and CISA has ordered federal agencies to apply mitigations by December 24. What You Should Know: - The zero-day affects appliances running AsyncOS with a specific spam prevention feature enabled. - When that feature is exposed to the internet, attackers can compromise the device and maintain persistent access. - Cisco identified a Chinese threat group (UAT-9686) using custom tooling—including a persistence mechanism known as AquaShell. - UAT-9686 has operational and tooling overlaps with UNC5174 and APT41, among the most prolific PRC-linked intrusion groups. - CISA has confirmed exploitation in the wild and elevated the vulnerability to the KEV (Known Exploited Vulnerabilities) catalog. - In some cases, the only remediation for compromised appliances is full rebuild due to deeply embedded persistence. Recommended Actions: - Immediately remove internet exposure to all Cisco Secure Email Gateway and Web Manager appliances. - Follow Cisco’s published steps to restore devices to a secure configuration. If you suspect compromise: - Contact Cisco TAC for validation - Prepare for full appliance rebuild if persistence is detected - Deploy strict access control and place these appliances behind a firewall. - Monitor devices for unusual processes, outbound connections, or new user accounts. - Implement CISA’s required mitigations prior to December 24.

Alert:  FortiGate Devices targeted with malicious sSO Logins

Wed, Dec 17

Researchers are reporting active intrusion attempts against Fortinet FortiGate appliances less than a week after Fortinet disclosed two critical authentication bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719). Attackers are using malicious SAML messages to bypass FortiCloud SSO authentication on devices where the feature is enabled. What You Should Know: - The flaws allow an attacker to bypass FortiCloud SSO authentication using a crafted SAML message. - Arctic Wolf detected multiple malicious login attempts across customer environments and has now observed tens of intrusions. - Activity appears opportunistic, not targeted — suggesting broad scanning and automated exploitation. - Several IP addresses were seen exploiting Fortinet honeypots over the weekend. - FortiCloud SSO is not enabled by default, but becomes enabled automatically when a device is registered in the GUI unless the admin disables the toggle (“Allow administrative login using FortiCloud SSO”). - CISA has added the vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog. Recommended Actions: - Temporarily disable FortiCloud SSO on all FortiGate devices running vulnerable versions until patched. - Apply Fortinet’s latest security updates for CVE-2025-59718 and CVE-2025-59719 as soon as possible. - Restrict firewall management interface access to trusted internal networks only. - Monitor for suspicious authentication attempts or SAML-related anomalies. If malicious activity is detected: - Reset all firewall credentials - Review administrative audit logs for unauthorized changes

Alert:  China’s BRICKSTORM Malware Enables Long-Term Persistence in VMware & Windows Environments

Mon, Dec 8

CISA, NSA, and the Canadian Centre for Cyber Security released a joint advisory detailing BRICKSTORM, a Chinese state-sponsored malware family used to maintain long-term, covert access inside government and IT sector networks. Analysis of eight malware samples shows BRICKSTORM is designed for stealth, resilience, and persistent control, with active campaigns observed throughout 2024–2025. What You Should Know: - BRICKSTORM is a stealthy backdoor linked to PRC state cyber operations. - The malware is being used for government targeting across the U.S., Canada, and APAC. - In confirmed incidents, attackers: - Compromised VMware vCenter servers, domain controllers, and ADFS - Extracted credentials and exported encryption keys - Created hidden virtual machines to maintain persistence - BRICKSTORM includes a self-reinstallation mechanism, allowing it to restart itself if disrupted. Malware capabilities: file browsing, upload/download, creation/deletion, system manipulation, and lateral movement. CrowdStrike and Mandiant report intrusions dating back to 2023, with targeting focused on: - Intellectual property - Executive email inboxes - Developers and system administrators - Data aligned to PRC intelligence priorities Recommended Actions: - Immediately review VMware vCenter and ESXi systems for persistence mechanisms (including hidden VMs). - Audit Active Directory and ADFS servers for unauthorized key exports or unusual authentication activity. - Pull and analyze logs for: - Unexpected vCenter operations - Suspicious service creations - Privilege escalation events - Deploy detection rules from CISA’s advisory for all BRICKSTORM variants. - Require MFA for all administrative access and restrict management interfaces from public exposure. - Treat any confirmed BRICKSTORM indicators as a potential long-term compromise requiring full incident response.

Alert:  Credential-Harvesting Campaign Targets Zendesk Environments

Fri, Dec 5

Researchers are warning that attackers linked to the Scattered Lapsus$ Hunters group are preparing, and in some cases already launching, a credential-harvesting campaign targeting organizations that use Zendesk for customer service operations. Over the last six months, researchers identified ~40 impersonating domains mimicking Zendesk login portals, many hosting fake SSO pages designed to steal credentials from high-privilege users. What You Should Know: - The threat actor has registered dozens of impersonation domains resembling real Zendesk environments. - Several domains host phishing pages with counterfeit SSO login screens, aimed at stealing help-desk and administrator credentials. - Researchers have evidence that attackers are already: - Submitting fraudulent tickets to real Zendesk instances - Using those tickets to target support teams - Delivering remote access Trojans (RATs) and other malware - Activity patterns mirror tactics seen in earlier campaigns against Salesforce and customer-service platforms linked to Scattered Lapsus$ Hunters. Zendesk says it is monitoring for misuse of its brand and blocking malicious domains as appropriate. Recommended Actions: - Warn Zendesk administrators and support teams to scrutinize login URLs and unexpected tickets. - Enforce SSO-only authentication and restrict login workflows wherever possible. - Configure domain-based login banners and explicit URL checks to limit spoofing success. - Enable MFA for all Zendesk users, especially those with admin or integration privileges. - Monitor for fraudulent tickets containing attachments, links, or executable content. - Add identified impersonated domains to web filtering and email security blocklists. - Review Zendesk audit logs for suspicious session activity, failed logins, new device sign-ins, or configuration changes.

Alert:  Critical FortiWeb Vulnerability Under Active Exploitation 

Mon, Nov 17

A critical FortiWeb vulnerability (CVE-2025-64446) is now under active exploitation. The flaw (CVSS 9.1) is a relative path traversal vulnerability that allows unauthenticated attackers to execute administrative commands using crafted HTTP(S) requests. Researchers report exploitation began weeks ago—before Fortinet issued public guidance—raising concerns over a “silent patch” released in late October. What You Should Know: - CVE-2025-64446 allows privileged command execution on vulnerable FortiWeb systems. - Attackers are primarily creating new administrator accounts as a persistence mechanism. - CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog. - The patched version (8.0.2) appears to have been quietly released on Oct. 28, weeks before disclosure. - Fortinet has acknowledged the vulnerability and activated PSIRT response workflows. Recommended Actions: - Immediately update to the patched version (8.0.2 or later). - If you cannot patch, disable HTTP/HTTPS on internet-facing interfaces as CISA recommends. - Review logs for unusual admin account creation or privilege escalation. - Report suspicious activity to CISA and Fortinet support channels.

Alert:  Cisco and Citrix Zero-Days Exploited in Stealth Campaign

Mon, Nov 17

Amazon security teams uncovered a sophisticated threat actor exploiting zero-days in both Cisco Identity Services Engine (ISE) and Citrix NetScaler systems — including CVE-2025-5777 (“Citrix Bleed Two”) and the ISE flaw later identified as CVE-2025-20337. The campaign predates public disclosure by months and involves custom malware, bespoke backdoors, and exploitation across multiple infrastructure types. What You Should Know: - The threat actor had access to multiple unpublished zero-days, signaling substantial resources and expertise. - Citrix Bleed Two (CVE-2025-5777) was exploited before its July disclosure. - Cisco ISE zero-day (CVE-2025-20337) enabled administrator-level access via an undocumented endpoint. - Threat actors deployed custom-built backdoors designed specifically for Cisco ISE. - Impacted organizations included government, critical identity systems, and network access control infrastructure. - Activity overlaps with IP addresses previously tied to RansomHub ransomware operations. Recommended Actions: - Apply all Cisco ISE and Citrix NetScaler security updates immediately. - Check for custom backdoors, persistence mechanisms, and unauthorized identity-policy changes. - Review identity infrastructure for abuse, token theft, or privilege anomalies. - Monitor for new indicators from Amazon, Cisco, Citrix, and CISA as the investigation evolves.

Alert:  Anthropic Claude Used for Autonomous Cyberattacks

Mon, Nov 17

Anthropic revealed a groundbreaking, and alarming, case in which a Chinese state-sponsored group (GTG-1002) used Claude AI to conduct the majority of operational tasks in cyberattacks across roughly 30 organizations. Claude autonomously handled reconnaissance, exploitation, credential harvesting, lateral movement, and data exfiltration, marking one of the first confirmed real-world cases of agentic AI-driven cyberattacks at scale. What You Should Know: - Claude performed 80–90% of intrusion activity indirectly, with human operators approving only major decisions. - Attackers bypassed guardrails by posing as cybersecurity professionals conducting testing. - Successful intrusions targeted tech firms, financial institutions, chemical manufacturers, and government agencies. - Claude autonomously identified internal systems, validated stolen credentials, analyzed exfiltrated data, and generated full attack documentation. - Anthropic admitted the activity evaded detection long enough to enable several compromises. - The incident signals a dramatic decrease in resource requirements for sophisticated nation-state cyber operations. Recommended Actions: - Audit any AI integrations touching sensitive data or administrative workflows. - Implement strict identity verification for AI interactions, especially with document, inbox, or network connectors. - Increase monitoring for high-volume automated requests originating from AI-related APIs. - Begin tabletop exercises for agentic AI misuse scenarios, which are now real-world threats.

Alert:  Critical Windows Server Flaw Exploited in WSUS Attacks 

Wed, Oct 30

CISA has issued an emergency directive urging agencies and businesses to patch Windows Servers affected by CVE-2025-59287, a critical WSUS remote code execution vulnerability now being actively exploited. The flaw affects multiple Windows Server versions (2012 through 2025) and stems from an incomplete fix released earlier this month. What You Should Know: - Severity: CVSS 9.8 — allows unauthenticated remote code execution with full system privileges. - Status: Confirmed exploitation by multiple threat groups (Huntress, Unit42, watchTowr). - Cause: Prior Microsoft update failed to fully patch WSUS; new out-of-band fix released. - Scope: Thousands of vulnerable Windows Servers exposed online, including sensitive networks. - Urgency: CISA orders federal agencies to patch or isolate affected servers by November 14. Recommended Actions: - Install Microsoft’s October 2025 WSUS patch and reboot servers immediately. - Restrict external network access to all WSUS-related ports and interfaces. - Audit for anomalous network behavior or WSUS process execution. - Treat all internet-exposed Windows Servers as potentially compromised. - Follow CISA mitigation and detection guidance as new indicators emerge.

Alert:  F5 Supply-Chain Breach Puts 600,000+ BIG-IP Devices at Risk of Pre-Patch Exploitation

Fri, Oct 17

F5 disclosed that nation-state hackers accessed internal networks and sensitive vulnerability information tied to BIG-IP. Within 24 hours, researchers counted 600k+ internet-reachable F5 devices. CISA directed agencies to patch promptly and disconnect management interfaces from the internet due to the risk that stolen details could speed exploit creation before patches are fully deployed. What You Should Know: - Scope: ~600k devices online globally; ~130k in the U.S. (Shadowserver). - Risk: Theft of confidential vuln details could enable exploit development ahead of patch uptake. - Status: F5 says it has evicted intruders; investigation ongoing with public/private partners. - Context: Edge devices are high-value targets for nation-state operations and ransomware crews. Recommended Actions: - Apply latest F5 BIG-IP patches immediately and watch for out-of-band releases. - Isolate/disable internet-exposed management; require VPN/JIT admin with MFA. - Rotate credentials, review auth integrations, and audit recent config changes. - Increase monitoring for exploitation indicators and anomalous device behavior. - Validate network segmentation and tested device backups.

Alert:  Microsoft Outlook Disables Inline SVG Images to Block Phishing and Malware Campaigns

Mon, Oct 06

Microsoft announced that Outlook for Web and the new Outlook for Windows will no longer render inline SVG images. The change mitigates phishing and malware attacks leveraging the SVG format, which has been heavily abused in phishing-as-a-service operations. What You Should Know: - Inline SVGs are blocked beginning September 2025, with full rollout expected by mid-October 2025. - SVG-based attacks have surged by 1,800% year-over-year, often used to deliver phishing content or malicious scripts. - Only inline SVGs are affected — attached SVG files remain supported and viewable. - The update also follows Microsoft’s ongoing effort to disable legacy features exploited in attacks, including macros, ActiveX controls, and certain file types. Recommended Actions: - Communicate the Outlook behavior change to users to avoid confusion when images fail to render - Replace SVG-based templates or images with safer formats (e.g., PNG, JPG) - Strengthen mail filtering and sandboxing for nontraditional file types - Maintain user training on recognizing phishing attempts using attachments or embedded content

Alert:  Executives Targeted with Oracle-themed extortion Campaign

Thurs, Oct 02

Corporate executives are the focus of a large-scale extortion campaign launched by hackers claiming affiliation with the Clop ransomware gang. The campaign leverages compromised email accounts to pressure executives with threats of exposing alleged data from Oracle E-Business Suite applications. What You Should Know: - While claims of Oracle E-Business Suite breaches are unverified, researchers have confirmed strong links to FIN11, a Clop-associated threat actor. - Extortion notes include email addresses tied to Clop’s leak site, validating threat actor connections. - The campaign is high volume and has been observed across hundreds of compromised accounts. - Clop has a history of mass exploitation campaigns, including MOVEit (2023) and Cleo file transfer (2024). Recommended Actions: - Alert executive leadership and staff who may be targeted by extortion emails - Block and report suspicious emails referencing Oracle or Clop - Investigate Oracle E-Business Suite environments for compromise indicators - Develop an internal executive extortion response protocol that prioritizes incident reporting, not engagement

Alert:  Shai-Hulud Supply Chain Worm Infects 500+ npm Packages, Exfiltrates Developer Credentials

Fri, Sept 26

The Shai-Hulud worm spread through more than 500 npm packages, stealing developer credentials and automatically propagating malicious code to additional projects. CISA has issued an alert urging organizations to review all npm dependencies and rotate developer credentials. What You Should Know: - Attackers used malicious code to scan for and exfiltrate secrets such as GitHub tokens and cloud service API keys. - The worm’s self-replication allowed it to automatically infect new packages once a compromised developer environment was accessed. - GitHub removed the malicious packages from the npm registry and blocked future uploads tied to the compromise. - Experts say this incident represents the first large-scale supply chain worm to succeed in the npm ecosystem. Recommended Actions: - Immediately review npm environments for indicators of compromise - Rotate all credentials and API keys tied to developer accounts - Monitor for suspicious network traffic and unauthorized repository activity - Implement stronger authentication and publishing safeguards in open-source workflows

Alert:  SonicWall Customers Warned of Brute Force Attacks on Cloud Backup Service

Fri, Sept 26

SonicWall has confirmed that attackers are conducting brute force attacks against the MySonicWall.com portal, targeting the company’s cloud backup service for firewalls. Investigators found that attackers accessed about 5% of firewall backup preference files. While stored credentials were encrypted, the files contain configuration details that could aid in future firewall exploitation. What You Should Know: - Backup files include sensitive configuration data such as user accounts, group settings, DNS, and log configurations. - SonicWall has shut down an unauthorized backup point linked to the incident. - CISA urged customers to log into their MySonicWall accounts immediately to determine exposure. - Nation-state and ransomware actors have historically leveraged firewall configuration data for follow-on intrusions. - SonicWall is working with law enforcement and cybersecurity partners; a customer video advisory is available. Recommended Actions: - Reset all stored credentials associated with SonicWall devices - Audit firewall configurations for anomalies or changes - Apply segmentation and monitoring controls to firewall-connected environments - Follow SonicWall and CISA advisories for ongoing updates

Alert:  OpenAI Fixes ShadowLeak Zero-Click Vulnerability in ChatGPT Deep Research

Mon, Sept 22

OpenAI patched a critical flaw, CVE pending – ShadowLeak, in its Deep Research agent. The bug enabled attackers to exfiltrate sensitive data without user interaction by embedding malicious instructions in emails or documents ingested by the tool. What You Should Know: - The exploit was zero-click: victims didn’t need to open or interact with the malicious message. - Deep Research could be tricked into calling attacker-controlled URLs with private parameters like employee names, addresses, or internal business data. - While demonstrated with Gmail, the technique could extend to other connectors (Google Drive, Dropbox, SharePoint, etc.). - Radware disclosed the issue in June; OpenAI fixed it in August and marked it resolved September 3. - No exploitation in the wild has been observed, but researchers warn this reflects a new category of AI agent abuse. Recommended Actions: - Confirm updates to Deep Research and related connectors are applied - Audit usage of AI-integrated email and document systems for anomalies - Establish AI usage policies to treat these agents as privileged applications - Monitor emerging research on prompt injection and autonomous agent exploits

Alert:  FBI Warns of Spoofed IC3 Websites Used for Fraud (PSA I-091925)

Fri, Sept 19

The FBI issued Public Service Announcement I-091925, warning that attackers are creating spoofed versions of the IC3.gov website to steal personal and financial data. What You Should Know: - Spoofed domains may use slight spelling changes or alternative top-level domains to impersonate IC3. - Fraudulent sites are harvesting names, addresses, banking details, and more from unsuspecting victims. - The real IC3 site is only www.ic3.gov . IC3 does not charge fees, direct users to third-party recovery firms, or maintain social media accounts. Recommended Actions: - Always type www.ic3.gov directly into your browser—do not rely on search results or ads. - Confirm URLs end in .gov before entering personal or financial data. - Report fraudulent sites and impersonation attempts to the FBI via the legitimate IC3 site. - Educate users on recognizing spoofed domains and avoiding phishing websites.

Alert:  Crowdstrike Packages used to deploy backdoors

Wed, Sept 17

Security researchers have identified malicious packages in the npm registry that impersonated CrowdStrike tools. The packages delivered JavaScript backdoors capable of executing attacker commands and exfiltrating sensitive data. What You Should Know: - The fake packages were designed to blend in with legitimate CrowdStrike libraries, increasing the chance of accidental installation. - Once installed, the malware could collect system and credential data and provide attackers remote access. - Supply chain attacks like this highlight the risks of dependency trust in modern development workflows, particularly in npm’s open ecosystem. Recommended Actions: - Immediately audit npm projects for suspicious CrowdStrike-themed dependencies - Lock dependencies with integrity verification and use private registries when possible - Educate development teams on spotting package impersonation attacks - Monitor CI/CD pipelines for unauthorized package pulls or script execution

Alert:  Apple Zero-Day ImageIO Exploited

Tues, Sept 2

Apple and CISA have disclosed CVE-2025-43300, a zero-day vulnerability in the ImageIO framework impacting iPhones, iPads, and Macs. The bug is already being used in “extremely sophisticated” attacks against select individuals. What You Should Know: - This is a zero-click exploit—it requires no user interaction and can be triggered by a malicious image delivered via email, message, or web content. - Apple’s advisory explicitly acknowledges targeted exploitation, language the company rarely uses. - The bug is now listed in CISA’s Known Exploited Vulnerabilities catalog. - Exploitation echoes past spyware activity (e.g., the 2023 BLASTPASS chain used to deliver Pegasus). - While attacks are targeted, Apple stresses that all users should patch immediately. Recommended Actions: - Update to the latest iOS, iPadOS, and macOS versions as soon as possible - Treat unexpected or suspicious media files with caution until fully patched - Prioritize updates for executives, administrators, and other high-risk roles - Enhance monitoring for spyware-like behavior on Apple endpoints

Alert:  NetScaler Zero-Day Vulnerability Exploited for Remote Code Execution

Thurs, August 28

NetScaler has released urgent security updates after confirming active exploitation of CVE-2025-7775, a critical memory overflow vulnerability affecting its application delivery controllers and remote-access tools. The flaw carries a CVSS score of 9.2 and can result in denial of service or remote code execution. What You Should Know: - Exploitation is ongoing, with evidence of attackers installing backdoors that persist post-patch - At least 28,000 vulnerable NetScaler instances remain exposed online - Exploitation requires common configurations such as Gateway mode or AAA virtual servers - Additional flaws (CVE-2025-7776 and CVE-2025-8424) can cause denial of service or unauthorized file access - CISA has added CVE-2025-7775 to the Known Exploited Vulnerabilities catalog Recommended Actions: - Patch all affected NetScaler appliances immediately - Audit for persistence mechanisms and unauthorized access - Limit external exposure of NetScaler services - Monitor for anomalies linked to denial of service or RCE attempts

Alert:  ScreenConnect Admins Targeted

Wed, August 27

A credential-harvesting campaign dating back to 2022 is targeting ScreenConnect cloud administrators. Using spear-phishing emails sent from compromised Amazon accounts, attackers aim to steal super-admin credentials, providing deep access to remote management environments. What You Should Know: - The phishing kits leverage EvilGinx adversary-in-the-middle tools to bypass MFA. - With stolen credentials, attackers can deploy their own ScreenConnect instances across multiple systems, facilitating lateral movement. - The campaign is linked to the Qilin ransomware group, whose affiliates have used the access to exfiltrate, encrypt, and ransom organizational data. - Incident responders have observed attacks against managed service providers and enterprises, underscoring the scale of exposure. Recommended Actions: - Warn and retrain admins on ScreenConnect phishing impersonations - Enforce phishing-resistant MFA (e.g., FIDO2, hardware keys) -Audit and rotate privileged accounts; minimize super-admin access -Monitor for new or unauthorized ScreenConnect installations in your environment

Alert:  Microsoft Exchange Vulnerability could enable domain-wide compromise

Mon, August 11

CISA and Microsoft have issued urgent guidance on CVE-2025-53786, a high-severity flaw in on-premise Microsoft Exchange servers. If exploited, the vulnerability could allow an attacker with admin-level access to escalate privileges and compromise both on-premises and cloud-based identities in hybrid deployments. What You Should Know: - Applies to on-premise Exchange servers in hybrid or standalone environments - Poses a risk of total domain compromise if unpatched - End-of-life versions—like SharePoint Server 2013—should be taken offline - No confirmed exploitation yet, but both CISA and Microsoft are urging immediate mitigation Recommended Actions: - Apply Microsoft’s April 2025 (or later) Hot Fix and follow all configuration changes from the April 18 guidance - Remove public access to unsupported Exchange and SharePoint servers - Audit and monitor privileged accounts for suspicious activity - Follow CISA’s emergency directive timelines if applicable

Alert:  Dell Security Chips Firmware-Level Vulnerability

Fri, August 8

Security researchers at Cisco Talos have disclosed critical firmware vulnerabilities in Broadcom’s ControlVault chip, used in over 100 models of Dell Latitude and Precision laptops. The flaws allow attackers to access, exfiltrate, and modify sensitive credential stores below the OS level—undetected by traditional security tools. What You Should Know: ControlVault is designed as a hardware “vault” for biometric templates, smartcard credentials, and encryption keys. The vulnerabilities, including CVE-2025-24919, enable: - Remote access without admin privileges using Windows APIs - Out-of-bounds reads and writes exposing and modifying sensitive memory - Code execution within the chip to embed persistent, undetectable malware - Credential theft or destruction with long-term operational consequences Impacted systems are used in sectors requiring elevated security postures, including cybersecurity, government, and ruggedized field deployments. Recommended Actions: - Patch all impacted Dell devices with the latest ControlVault firmware - Validate security policies around biometric or smartcard authentication - Re-key and re-authenticate users in high-trust roles if compromise is suspected - Harden endpoint privilege access to avoid remote code execution triggers

Alert:  SonicWall VPNs Actively Exploited in Zero-Day Ransomware Attacks

Wed, August 6

A fast-moving ransomware campaign is actively exploiting a likely zero-day vulnerability in SonicWall Gen 7 firewall SSL VPNs. Multiple external response teams and researchers have confirmed that attackers are gaining access to environments—even those fully patched and secured with MFA. What You Should Know: - Over 20 confirmed intrusions observed since July 25 - Ransomware deployed by the Akira group - SonicWall has acknowledged the issue but not yet released a patch - Access vectors appear tied directly to SSL VPN services - Huntress and Arctic Wolf are urging organizations to take systems offline now Recommended Actions: - Disable SSL VPN on Gen 7 SonicWall devices immediately - Scan firewall logs for unusual activity, especially reboots or access failures - Review and rotate privileged credentials - Strengthen lateral movement defenses and ransomware response plans

Alert:  AI Code Assistants under Attack

Wed, July 30

Two separate incidents involving Amazon and Google show that AI-powered development tools are now viable targets for attackers. With deep access to developer environments, weak authentication controls, and high trust, these tools create new risk surfaces across the software supply chain. Incident #1: Amazon Q Developer Extension A malicious actor injected code into Amazon Q’s GitHub repo via an unverified pull request. The altered version (1.84.0) was published to nearly a million users through the VS Code marketplace. While the code was malformed, it demonstrated how workflow misconfigurations can turn helpful extensions into attack vectors. Incident #2: Google Gemini CLI Flaw A vulnerability in Gemini CLI’s setup workflow allowed attackers to hijack authentication tokens and silently execute commands on dev systems. The issue was fixed, but not before showing how token handling flaws can create remote execution paths. Recommended Actions: - Patch Amazon Q Developer to v1.85.0 - Audit permission scopes for CLI and IDE extensions - Harden GitHub workflows and authentication tokens - Treat AI development tools as privileged software—because they are

Alert:  PaperCut Remote Code Execution Vulnerability

Wed, July 30

CISA has confirmed active exploitation of CVE‑2023‑2533, a remote code execution vulnerability in PaperCut NG/MF. The flaw allows unauthenticated attackers to execute code on vulnerable servers via the SetupCompleted configuration page. What You Should Know: - Exploited in the wild, this bug poses a major risk to organizations using PaperCut to manage print services. - - Attackers can bypass authentication, run malicious code, and gain full control of the affected systems. Recommended Actions: - Apply PaperCut patches immediately - Restrict PaperCut access to internal networks only - Review logs for any unusual SetupCompleted access - Isolate print servers from business-critical assets

Alert:  Scattered Spider Expands to Insurance & Airlines with Deepfake and Vishing Campaigns

Thurs, July 16

Scattered Spider, known for targeting retailers, has expanded into insurance and now airline sectors. Their updated campaign uses deepfake video calls, vishing, and in-platform impersonations to breach MFA and trick employees. What You Should Know: - Google TAG confirms the shift to insurance; the FBI warns airlines are now at risk. - The group leverages human trust—posing as IT support to bypass MFA—and uses collaboration apps and deepfake tools to access systems without technical exploits. Recommended Actions: - Educate staff on multi-channel impersonation across video, voice, and chat - Restrict remote-access tool installations to official channels - Monitor for anomalous activity in help-desk and ticketing platforms - Verify all MFA and support requests with strict multi-factor verification

Alert:  New Citrix Bleed 2 Vulnerability Exposes NetScaler Systems
 

Thurs, June 25

Citrix has disclosed a new critical vulnerability in NetScaler ADC and Gateway (CVE-2025-5777), dubbed CitrixBleed 2. The flaw allows unauthenticated attackers to extract sensitive data directly from system memory, including session tokens, credentials, and encryption keys. What You Should Know: - Though no exploitation has yet been confirmed, experts predict that attacks are likely imminent. - The vulnerability affects common NetScaler configurations for remote access (VPN, ICA Proxy, CVPN, RDP Proxy) used by many large enterprises. - Attackers can leverage this weakness without user interaction or credentials. Recommended Actions: - Apply Citrix security updates immediately - Verify all external-facing NetScaler appliances are patched - Execute Citrix-recommended commands post-patch to terminate active sessions - Monitor logs for signs of unauthorized session access

Alert:  Microsoft CoPilot Vulnerability 
 

Thurs, June 12

Microsoft has patched a zero-click vulnerability in Copilot, the AI assistant integrated into Microsoft 365. The flaw allowed attackers to extract internal data by embedding malicious prompts in emails—without the user clicking or responding. What You Should Know: This is the first known exploit of its kind involving an enterprise AI assistant. The vulnerability—CVE-2025-32711—was significant because it demonstrated how prompt injection could be weaponized for real-world data theft without user interaction. The incident underscores the importance of visibility and control over AI-assisted workflows. Recommended Actions: - Audit Copilot activity logs for unusual data access patterns - Evaluate where AI may interact with sensitive business information - Train users on risks tied to AI-generated email content - Begin establishing monitoring protocols for future AI-driven features

Alert:  Salesforce Apps Targeted via OAuth Abuse
 

Thurs, June 05

Google’s Threat Analysis Group has warned of a campaign in which attackers are exploiting OAuth permissions to gain persistent access to Salesforce accounts. Once in, they install malicious applications capable of data theft or malware deployment. What You Should Know: OAuth-based attacks bypass login credentials entirely. Traditional security controls—like MFA or login alerts—don’t detect this. The risk is elevated for any organization with widely used or lightly monitored SaaS platforms. Recommended Actions: - Review and restrict third-party app access in Salesforce - Audit OAuth token logs and scopes for abnormalities - Remove unused or suspicious integrations - Train staff on the risks of app authorization and fake consent screens

Alert:  Google Calendar Used to Deliver Malware
 

Fri, May 30

China-linked APT41 is leveraging Google Calendar to stealthily deliver malware. Victims receive calendar invites with malicious URLs disguised as event details, leading to second-stage malware. What You Should Know: This method blends into daily workflow and is unlikely to trigger traditional email filters. It’s a reminder that even trusted cloud platforms can be weaponized. Recommended Actions - Monitor for abnormal calendar event creation - Enforce calendar URL scanning and restriction policies - Train staff to flag suspicious event invites - Evaluate G Workspace settings for risk reduction

Alert:  Fake Bitdefender Website Spreading VenomRAT and Credential-stealing malware
 

Fri, May 30

Threat actors have created a convincing fake Bitdefender website to spread malware. Unsuspecting users who download software from the site receive VenomRAT or a credential-harvesting infostealer. What You Should Know: This campaign targets users seeking legitimate antivirus protection—turning their search into an infection. Malicious downloads bypass some endpoint tools via trusted branding. Recommended Actions - Block impersonation domains and scan installer traffic - Educate users on software sourcing hygiene - Monitor for RAT behavior and credential leaks - Review endpoint protection efficacy against sideloaded threats

Alert:  Data Exfiltration Risk via NodeSnake RAT in New Ransomware Campaign
 

Fri, May 30

New Interlock ransomware is being deployed alongside NodeSnake, a JavaScript-based RAT. This tactic allows threat actors to silently exfiltrate data before executing encryption, increasing the impact and complexity of response. What You Should Know: This threat is a dual-pronged attack. Even with backups in place, stolen data can lead to compliance risks, legal exposure, and leverage for extortion. Detection and prevention must extend beyond traditional ransomware defenses. Recommended Actions: - Strengthen detection rules for JavaScript and fileless malware activity. - Monitor endpoints and cloud workloads for NodeSake behavior. - Enforce DLP policies and inspect outbound traffic for exfiltration signs. - Adapt ransomware response plans to cover data theft before encryption.

Alert:  Commvault Vulnerabilities
 

Wed, May 28

CISA has issued a new alert detailing active exploitation of critical vulnerabilities in Commvault software—a widely used backup and recovery platform. Threat actors are leveraging these flaws to gain remote access, exfiltrate data, and move laterally into cloud environments. What You Should Know: These vulnerabilities are actively being exploited in the wild—this is not a drill. If left unaddressed, they create a clear path for attackers to escalate privilege and compromise critical cloud systems. Steps to take now: Patch all exposed Commvault instances—especially those accessible via the internet. Audit cloud and backup integrations for unusual behavior. Strengthen identity controls to prevent lateral movement. Hunt for activity tied to CVE-2025-3928 and related indicators of compromise.

Alert:  "Fast Flux" Ransomware tactic
 

Mon, Apr 7

A joint advisory from the U.S., Australia, and Canada highlights a growing ransomware tactic: fast-flux DNS — a technique that rapidly rotates IPs and domains to evade detection and takedown. Cybercriminal groups like LockBit and Black Basta, with links to Russia, are actively using it to target sectors including healthcare, government, and critical infrastructure. Why it matters to you: •Fast-flux makes ransomware attacks harder to trace, contain, and mitigate •Traditional defenses may not detect this level of infrastructure agility •The tactic signals a continued evolution in attacker sophistication 📌 Next steps: Ensure your teams are evaluating DNS-layer defense strategies and securing offline backups.

Alert:  Unpatched Microsoft Windows Shortcut .lnk Active Exploit
 

Tues, Mar 18

A critical Windows zero-day vulnerability, identified as ZDI-CAN-25373, is currently being actively exploited by nation-state threat actors. This flaw allows attackers to execute hidden malicious commands via specially crafted Windows shortcut (.lnk) files. The vulnerability has been present for at least eight years, was reported six months ago but remains unpatched by Microsoft. Nation-state actors from North Korea, Iran, Russia, and China are leveraging this exploit to conduct cyber espionage and financial crimes, particularly targeting cryptocurrency platforms and sensitive government data. To mitigate the risk, please take the following immediate actions: •Monitor for suspicious .lnk files: Scan systems for shortcut files that may contain embedded malicious commands. •Restrict execution of unknown shortcuts: Prevent the automatic execution of .lnk files from untrusted sources. •Use endpoint detection and response (EDR) solutions: Deploy advanced security tools to detect anomalous behavior linked to shortcut exploitation. •Educate employees: Train staff to recognize suspicious files and avoid executing unknown shortcuts. Given the severity and active exploitation of ZDI-CAN-25373, it is imperative to assess your exposure and strengthen defenses accordingly.

Alert:  Fortinet Bug Active Exploit
 

Tues, Mar 18

A critical Windows zero-day vulnerability, identified as ZDI-CAN-25373, is currently being actively exploited by nation-state threat actors. This flaw allows attackers to execute hidden malicious commands via specially crafted Windows shortcut (.lnk) files. The vulnerability has been present for at least eight years, was reported six months ago but remains unpatched by Microsoft. Nation-state actors from North Korea, Iran, Russia, and China are leveraging this exploit to conduct cyber espionage and financial crimes, particularly targeting cryptocurrency platforms and sensitive government data. To mitigate the risk, please take the following immediate actions: •Monitor for suspicious .lnk files: Scan systems for shortcut files that may contain embedded malicious commands. •Restrict execution of unknown shortcuts: Prevent the automatic execution of .lnk files from untrusted sources. •Use endpoint detection and response (EDR) solutions: Deploy advanced security tools to detect anomalous behavior linked to shortcut exploitation. •Educate employees: Train staff to recognize suspicious files and avoid executing unknown shortcuts. Given the severity and active exploitation of ZDI-CAN-25373, it is imperative to assess your exposure and strengthen defenses accordingly.

Alert: Bug affecting pHP scripts requires Immediate attention

Mon, Mar 10

Alert: Botnet targeting Basic Auth in Microsoft 365 password spray attacks

Tue , Feb 25

Alert: Microsoft 365 accounts targeted with Russian spear phishing attack

Tue, Feb 25

Alert:  Ghost Ransomware attacking known vulnerabilities in Microsoft Exchange, SharePoint and other public-facing applications (all sectors impacted)

Fri, Feb 21

Alert:  Cisco Devices Targeted at Telcos and Universities
 

Fri, Feb 14

Alert:  Zero-Day Attack Targeting SonicWall Devices
 

Mon, Jan 27

Alert:  Impersonating Microsoft Tech Support
 

Wed, Jan 22

Alert:  AWS Environments Compromised
 

Fri, Aug 23

Alert: Actively Exploited SonicWall Vulnerabilities Enable Remote Code Execution

Thurs, Sept 3

SonicWall is urging customers to immediately update SMA1000 series appliances after confirming that attackers are exploiting two vulnerabilities that can be chained together to achieve remote code execution. The attack combines CVE-2026-83548, a critical server-side request forgery vulnerability with a maximum CVSS score of 10, and CVE-2026-83549, a high-severity OS command-injection vulnerability. The risk is particularly significant because SonicWall SMA appliances provide remote users with access to internal applications and resources, and affected interfaces may be exposed to the public internet. What You Should Know: - Active exploitation has been confirmed. SonicWall reports that attackers are exploiting the vulnerabilities in the wild. - CVE-2026-83548 is a critical server-side request forgery vulnerability in the Appliance Work Place interface that can allow attackers to access sensitive functions and perform unauthorized actions. - The vulnerability carries a CVSS score of 10.0, the highest possible severity rating. - Attackers can chain CVE-2026-83548 with CVE-2026-83549, an OS command-injection vulnerability in the Appliance Management Console, to achieve remote code execution. - SMA appliances can occupy a particularly sensitive position in enterprise environments because they provide authorized users with remote access to internal applications and resources. Recommended Actions: - Install SonicWall's latest hotfix immediately on affected SMA1000 appliances. - Identify internet-facing SMA1000 systems and prioritize them for remediation. - Confirm that updates have been successfully applied rather than relying solely on scheduled patching processes. - Review SMA1000 logs and surrounding security telemetry for suspicious activity or evidence of unauthorized access. - Investigate unexpected commands, configuration changes, or activity involving internal resources accessible through affected appliances. - Restrict unnecessary public exposure and administrative access to SMA1000 interfaces. - If evidence of compromise is identified, treat the appliance as a potential entry point into the broader environment and investigate activity beyond the device itself. - Continue monitoring SonicWall and CISA guidance as exploitation develops.

Alert: Cisco Routers Compromised by China-Linked Espionage Campaign to Reach Trusted Networks

Mon, Aug 31

Security researchers are warning that a sophisticated China-nexus threat actor is compromising Cisco routers running IOS XR as part of a long-term espionage campaign targeting high-value networks and critical infrastructure. The threat actor, tracked as Fire Ant, is using compromised network infrastructure to collect traffic and administrative credentials, map trusted relationships, establish persistent access, and conceal evidence of its activity. The campaign is particularly concerning because compromising trusted network infrastructure can give attackers visibility and access that traditional endpoint-focused defenses may not detect. What You Should Know: - The actor was previously associated with attacks against VMware ESXi and vCenter environments and has now expanded its activity into trusted network infrastructure. - Researchers observed attackers collecting network traffic and administrative credentials while mapping routes and trusted relationships. - The attackers established multiple persistence mechanisms and manipulated evidence to make their activity more difficult to detect. - Investigators found a GRE tunnel interface operating on a compromised router even though its visible configuration and commit history did not explain its existence. - The attackers compromised TACACS infrastructure to interfere with authentication and steal credentials. - Researchers identified specialized tools including BridgeAgent, an implant disguised as Zabbix monitoring software and used for tunneling and persistence, and TacTap, which was used to collect credentials. - The compromise extended beyond the Cisco router into Linux infrastructure and other parts of the network. Recommended Actions: - Restrict privileged access to routers and other network management infrastructure using dedicated administrative paths. - Review Cisco IOS XR environments for unexpected GRE or other tunnel interfaces. - Investigate discrepancies between a device's operational state and its visible configuration or change history. - Centralize router authentication logs and network telemetry outside of managed devices so attackers cannot easily alter the evidence stored on a compromised system. - Review TACACS infrastructure and administrative credentials for signs of compromise. - Hunt for unauthorized persistence, tunneling activity, unusual Linux infrastructure access, and unexpected monitoring tools. - Treat unexplained configuration inconsistencies as potential indicators of compromise rather than assuming the device's local records provide a complete picture.

Alert: Actively Exploited PaperCut Vulnerabilities Enable Full Server Compromise

Mon, Aug 31

PaperCut has issued emergency patches after attackers successfully exploited two critical vulnerabilities affecting its PaperCut MF and PaperCut NG print management software. The vulnerabilities, CVE-2026-81578 and CVE-2026-82078, can be chained together to allow an unauthenticated attacker to compromise an exposed PaperCut server without requiring a username, password, or user interaction. Multiple organizations have already been compromised, and CISA has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. What You Should Know: - CVE-2026-81578 is an improper access-control vulnerability that allows an unauthenticated attacker to modify certain system configurations. - CVE-2026-82078 is an unsafe dynamic class loading vulnerability that can enable execution of arbitrary Java bytecode. - Researchers report that chaining the two vulnerabilities can result in full compromise of an affected PaperCut server. - Exploitation requires no credentials or user interaction; researchers warn that an attacker may need only the target's IP address or hostname. - Multiple customers have already been successfully targeted, and researchers are seeing attackers take additional steps following initial compromise. - Post-compromise activity has included deployment of remote management tools to establish persistence, elevate privileges, and attempt lateral movement. - Researchers identified ways to bypass PaperCut's initial patches. A subsequent set of patches has held against the proof-of-concept testing described by researchers. Recommended Actions: - Apply PaperCut's latest security updates immediately. Ensure systems have the most recent fixes rather than relying on the initial patch release. - Remove PaperCut application servers from the public-facing internet and restrict access to trusted networks. - Identify exposed PaperCut MF and NG servers and review them for evidence of exploitation. - Hunt for unauthorized remote management tools, privilege escalation, persistence, and lateral movement originating from affected systems. - Preserve and secure existing server backups before beginning remediation if compromise is suspected. - If a server has been compromised, follow PaperCut's guidance to wipe and rebuild the application server and restore from a known-clean backup. - Continue monitoring PaperCut and CISA guidance as the exploitation activity develops.

Alert: Microsoft SharePoint Vulnerabilities Can Be Chained for Remote Code Execution

Wed, Aug 26

Organizations running on-premises Microsoft SharePoint should confirm that recent security updates have been applied after researchers demonstrated that two critical vulnerabilities can be chained together to achieve unauthenticated remote code execution. The first vulnerability, CVE-2026-55040, allows an attacker to bypass authentication and is already under active exploitation. Researchers report that when it is combined with CVE-2026-63520, an attacker could execute code remotely on a vulnerable SharePoint server without authentication. Researchers are also beginning to observe probing activity associated with the chained attack sequence, increasing the urgency for organizations operating on-premises SharePoint environments. What You Should Know: - CVE-2026-55040 is already being exploited and has been added to CISA’s Known Exploited Vulnerabilities catalog. - CVE-2026-55040 alone provides an authentication bypass. When chained with CVE-2026-63520, the vulnerabilities can enable unauthenticated remote code execution. - Microsoft addressed CVE-2026-55040 in its July security update and CVE-2026-63520 in its August security update. - Researchers have identified approximately 8,500 internet-visible SharePoint servers, creating a substantial potential attack surface. This follows several recent SharePoint exploitation campaigns, reinforcing the importance of treating internet-facing SharePoint environments as high-priority assets. Recommended Actions: - Verify both security updates are installed. Confirm Microsoft’s July update addressing CVE-2026-55040 and August update addressing CVE-2026-63520 have been successfully deployed. - Validate deployment. Follow Microsoft’s SharePoint software update deployment guidance to ensure updates are fully and correctly applied across affected servers. - Reduce internet exposure. Identify externally accessible SharePoint servers and restrict unnecessary public access. - Review for signs of compromise. Examine SharePoint, authentication and supporting security logs for unusual authentication activity, probing or unexpected code execution. - Investigate prior exposure. If affected SharePoint systems were internet-accessible and remained unpatched while exploitation was occurring, investigate whether compromise may have occurred before remediation. - Continue monitoring. Watch for updated Microsoft and CISA guidance as attacker activity develops. The key issue is the combination of these vulnerabilities. Security teams should not evaluate them as isolated flaws. With one component already under exploitation and probing of the chained attack now being observed, verifying both patches, and checking for prior compromise, should be a priority.

Alert: Internet-Exposed Siemens Industrial Control Systems Targeted by AI-Assisted Attacks

Fri, Aug 21

The FBI, NSA, and CISA are warning that attackers are targeting vulnerable and internet-exposed Siemens S7 programmable logic controllers (PLCs) across multiple critical industries. Attackers are using AI-generated exploitation scripts disguised as legitimate monitoring software to support reconnaissance, credential theft, initial access, and denial-of-service activity. Potentially affected sectors include energy, water, critical manufacturing, agriculture, and possibly defense. What You Should Know: - The campaign targets multiple Siemens S7 PLC families, including: - S7-200 - S7-300 - S7-400 - S7-1200 - S7-1500 - Many of the targeted systems are running out-of-service software or have configurations that leave them unnecessarily exposed to the internet. - Importantly, Siemens has not identified a new vulnerability associated with this campaign. Instead, attackers are applying new techniques against existing weaknesses, outdated systems, and insecure configurations. - According to federal authorities, AI is being used to develop exploitation scripts that resemble legitimate software and to generate code supporting initial access, credential theft, and disruptive activity. - Successful attacks against PLC environments could result in consequences beyond traditional data loss, including: - Disruption of critical industrial processes. - Operational downtime. - Safety incidents. - Loss of visibility or control. - Potential equipment damage. The campaign follows previous warnings about attacks against internet-facing PLCs used by water and wastewater organizations, reinforcing the importance of reducing direct exposure of operational technology. Recommended Actions: Organizations operating Siemens S7 environments should: - Identify all Siemens S7 PLCs and confirm whether any are directly accessible from the internet. - Remove direct internet exposure wherever possible. - Update firmware and apply available security patches. - Identify and replace or isolate systems running unsupported software. - Review configurations against current Siemens security guidance. - Enable multifactor authentication where supported. - Monitor for unauthorized access, unusual configuration changes, credential activity, and denial-of-service behavior. - Review segmentation between IT and OT networks and restrict unnecessary pathways into industrial environments. Bottom Line: This campaign does not depend on a newly discovered Siemens vulnerability. Attackers are using AI-assisted techniques to find and exploit weaknesses that already exist. For OT leaders, the priority is reducing internet exposure, addressing legacy systems, and ensuring that preventable configuration weaknesses do not become an entry point into critical industrial operations.

Alert: Critical GitLab Vulnerability Under Active Exploitation Can Modify or Delete Public Projects

Fri, Aug 21

GitLab has issued an emergency security update for a critical code-injection vulnerability that can allow an unauthenticated attacker to modify or delete publicly accessible projects and user data. The vulnerability, CVE-2026-19478, carries a CVSS score of 9.4. Researchers have already observed exploitation attempts in the wild, making remediation a priority for organizations operating internet-facing, self-hosted GitLab environments. What You Should Know: - CVE-2026-19478 can be exploited remotely through a GraphQL directive without requiring credentials or user interaction. - Security researchers were able to reproduce the vulnerability shortly after public disclosure, demonstrating how quickly attackers can move from newly published vulnerability information to working exploits. Successful exploitation could allow an attacker to: - Delete entire publicly accessible repositories. - Modify the state of GitLab projects. - Forge merge records. - Ban project maintainers. - Alter or delete user data. GitLab has released out-of-band updates to address the vulnerability. Researchers have also recommended reviewing web logs for requests containing gl_introduced, which may indicate probing for the vulnerability. The emergency release additionally addresses CVE-2026-19650, a separate cross-site request forgery vulnerability that, under certain conditions, could allow unauthorized mutations through GET requests. Recommended Actions: Organizations running self-hosted GitLab should: - Upgrade affected GitLab instances to a patched release immediately. - Prioritize internet-facing environments and publicly accessible repositories. - If immediate patching is not possible, restrict unauthenticated access to api/graphql. - Consider disabling public repository access until remediation is complete. - Review web logs for requests containing gl_introduced and other suspicious GraphQL activity. - Examine repositories, merge records, maintainers, and user data for unexpected changes. - Continue monitoring GitLab guidance and exploitation activity. Bottom Line: The time between vulnerability disclosure and exploitation continues to shrink. With exploitation already being observed, organizations running affected self-hosted GitLab environments should not wait for their normal patch cycle. Patch now and verify that publicly accessible projects have not already been probed or altered.

Alert: Critical Infrastructure Targeted with Fortinet Firewall Vulnerabilities

Mon, Aug 17

The FBI and South Korean authorities are warning that the Gunra ransomware group is exploiting known Fortinet firewall vulnerabilities to breach critical infrastructure organizations, steal data, and deploy ransomware. The group has targeted healthcare, financial services, government, and industrial organizations globally. According to the joint advisory, ransom demands in investigated incidents have exceeded $10 million, with victims given as little as five to seven days to pay. What You Should Know: - Gunra actors have been exploiting two previously disclosed Fortinet vulnerabilities: - CVE-2024-55591 - CVE-2025-24472 - Successful exploitation can provide attackers with privileged access to an organization. From there, Gunra operators can move further into the environment, steal sensitive information, encrypt data, and use the stolen information as leverage for extortion. - The group emerged in 2025 and has since expanded into a ransomware-as-a-service (RaaS) operation, recruiting additional cybercriminals and initial access brokers. Authorities have also observed the group operating under other names, including Golden Community. - Gunra initially focused on Windows environments but has expanded its capabilities to Linux systems, increasing the potential exposure for organizations with diverse infrastructure. - The warning comes amid continued growth in ransomware attacks against industrial organizations. The FBI and its partners are urging organizations to address known vulnerabilities before ransomware operators can use them as an entry point. Recommended Actions: Organizations should: - Identify Fortinet devices affected by CVE-2024-55591 and CVE-2025-24472 and ensure applicable updates and mitigations have been implemented. - Prioritize internet-facing firewalls and other perimeter infrastructure for vulnerability remediation. - Restrict administrative interfaces from unnecessary internet exposure. - Review Fortinet and authentication logs for suspicious administrative access or unexpected configuration changes. - Monitor for evidence of credential compromise, lateral movement, and unusual data transfers. - Maintain tested, isolated backups and confirm critical systems can be restored without relying on compromised infrastructure. - Review incident response and ransomware procedures before an attack occurs. Bottom Line: Gunra's activity reinforces a familiar but costly lesson: known vulnerabilities in perimeter security devices can quickly become the entry point for a much larger ransomware event. Organizations using affected Fortinet products should verify both remediation and evidence of prior compromise rather than assuming patching alone closes the risk.

Alert: Voice-Phishing Extortion Campaign Targets Private Equity, Financial and Legal Firms

Wed, Aug 12

Security researchers are warning of an extortion campaign targeting private equity firms, financial organizations, and law firms through sophisticated voice-phishing attacks. The threat actors, tracked as UNC6671 and formerly associated with BlackFile, impersonate IT help desk personnel and call employees directly. Their objective is to steal corporate credentials and multifactor authentication tokens, gain access to enterprise systems, and exfiltrate sensitive data that can later be used for extortion. What You Should Know: - The attackers contact employees on their mobile devices while posing as internal IT support. Victims are then directed to attacker-controlled infrastructure designed to capture credentials and MFA information. - Once inside an organization, attackers can use automated tools to rapidly collect large volumes of corporate data before issuing an extortion demand. - Recent activity has focused heavily on private equity and related organizations, where transaction data, financial information, and other confidential material can provide attackers with significant leverage. - However, this is not exclusively a financial-sector threat. Researchers have observed related targeting across manufacturing, insurance, real estate, healthcare, hospitality, technology, and transportation. - The campaign demonstrates why MFA alone does not eliminate identity risk when attackers can socially engineer employees into providing the information needed to defeat it. Recommended Actions: Organizations should: - Alert employees to unsolicited calls claiming to come from internal IT or help desk personnel. - Require independent verification before employees act on requests involving credentials, MFA, password resets, or account changes. - Train help desk and high-value users to recognize voice-phishing techniques. - Implement phishing-resistant MFA where possible. - Monitor for unusual authentication activity and unexpected MFA enrollment or reset events. - Review access to sensitive corporate and transaction data using least-privilege principles. Bottom Line: Attackers do not need to defeat security technology if they can convince an employee to help them bypass it. Organizations should strengthen identity controls while making verification of unexpected IT requests a standard employee behavior.
  • Page 1

Concerned You May Be a Target?

bottom of page