AWS reports threat actors are leaning on generative AI to rapidly identify exposed management ports and weak credentials, taking over hundreds of FortiGate devices across multiple countries. The operation shows how commercial AI tooling is accelerating recon and exploitation at scale. Security teams should remove public access to management interfaces, enforce MFA, rotate credentials, and ensure devices run the latest firmware.
Source: SecurityWeek
RoundCube XSS Bug Actively Exploited Months After Patch Release
A recently disclosed RoundCube webmail flaw is being exploited in the wild to trigger XSS via animate tags embedded in SVG files. Although patches were released in December 2025, attackers continue to target unpatched instances. Admins should update immediately, consider disabling SVG rendering, and monitor for suspicious webmail activity.
Source: SecurityWeek
PayPal Breach Led to Fraudulent Transactions After 6-Month Exposure
PayPal said an application error exposed customer data for nearly half a year, resulting in some fraudulent charges. The company has reset passwords and is notifying affected users. Customers should enable two-factor authentication, review recent account activity, and be alert for phishing that leverages leaked personal data.
Source: SecurityWeek
Ransomware Forces University of Mississippi Medical Center to Shut Clinics
A ransomware attack forced UMMC to close roughly three dozen clinics across Mississippi and cancel elective procedures, disrupting patient care statewide. The incident highlights the fragility of healthcare operations and the need for segmented networks, secure remote access, offline backups, and well-rehearsed downtime procedures.
Source: SecurityWeek
Ukraine: Grid Intrusions Now Feeding Targeting Data for Missile Strikes
Ukrainian officials say Russian cyber operations against the energy sector increasingly focus on intelligence collection to guide kinetic missile attacks, rather than immediate service disruption. The shift underscores the value of OT-IT monitoring, detection of lateral movement and data exfiltration, and rapid intel sharing across critical infrastructure operators.
Source: The Record by Recorded Future
Active npm Supply-Chain Worm Steals Crypto Keys, CI Secrets, and API Tokens
Researchers uncovered a “Shai-Hulud-like” campaign using at least 19 malicious npm packages to exfiltrate cryptocurrency keys, CI/CD secrets, and other tokens. The worm-like behavior spreads through dependency chains, posing risk to developer environments and build systems. Teams should audit recent package installs, pin and verify dependencies, rotate exposed secrets, and harden developer workstations.
Source: The Hacker News
Enterprises Scramble to Rein In Agentic AI With Access to Core Systems
According to Cisco’s State of AI Security 2026, organizations are wiring AI agents into ticketing tools, code repos, chat platforms, and cloud consoles—often with authority to open PRs, query databases, and trigger workflows. This powerful access raises new risks around identity, change control, and supply chain integrity. Security leaders are responding with least-privilege scopes, human-in-the-loop approvals, robust audit trails, and continuous monitoring of agent actions.
Source: Help Net Security
You May Also Be Interested In...
Ransomware gangs advancing Moscow’s geopolitical aims, Romanian cyber chief warns
MuddyWater targets MENA organizations with GhostFetch, CHAR, and HTTP_VIP
Claude Code scans, verifies, and patches code vulnerabilities