Cisco Talos reports active exploitation of an authentication bypass in Cisco Catalyst SD‑WAN Controller/Manager that lets remote, unauthenticated attackers obtain administrative privileges. Adversaries add rogue peers and can chain post-exploitation steps for root access; CISA has issued an emergency directive urging immediate patching and review of peering events in logs. Organizations should upgrade to fixed releases without delay and validate unexpected control-plane connections.
Source: Cisco Talos
Google and partners disrupt PRC‑linked “UNC2814” espionage using Google Sheets as C2 (GRIDTIDE)
Google Threat Intelligence, Mandiant, and partners dismantled a long‑running campaign that breached 53 organizations across 42 countries, primarily in telecoms and government. The actor abused legitimate Google Sheets API calls as command‑and‑control for the GRIDTIDE backdoor to blend into normal SaaS traffic; Google terminated attacker projects/accounts and released IOCs and hunting guidance. Defenders should monitor non‑browser use of Sheets API endpoints and investigate suspicious service accounts.
Source: Google Threat Intelligence
Critical Claude Code flaws enabled RCE and API key theft via malicious repo configs
Check Point researchers disclosed CVE‑2025‑59536 and CVE‑2026‑21852 in Anthropic’s Claude Code that allowed remote code execution and exfiltration of API keys by abusing repository‑level configurations. The attack could trigger simply by cloning and opening an untrusted project, leveraging Hooks, MCP integrations, and environment variables to bypass trust controls and redirect authenticated traffic. Findings underscore a growing AI supply‑chain risk where dev tooling becomes an execution vector.
Source: Check Point Blog
CISA adds actively exploited FileZen command injection bug to KEV (CVE-2026-25108)
CISA placed an OS command injection flaw in Soliton Systems’ FileZen secure file transfer solution on its Known Exploited Vulnerabilities catalog after the vendor confirmed in‑the‑wild attacks and multiple damage reports. Given speculation around recent ransomware activity in Japan, organizations should patch immediately, remove public exposure, and review FileZen logs for suspicious command execution.
Source: Help Net Security
SolarWinds Serv‑U patches four critical RCE‑level bugs; update ASAP
SolarWinds fixed four critical vulnerabilities in Serv‑U that could allow attackers to create system admin users and/or execute code with elevated privileges. Serv‑U is widely deployed on Windows and Linux for FTP/SFTP/HTTP(S) transfers, making timely patching essential—especially on internet‑exposed instances. Restricting admin access and monitoring for anomalous account creation are recommended until updates are applied.
Source: Help Net Security
US sanctions Russian exploit broker Operation Zero amid crackdown on zero‑day trade
The US sanctioned Operation Zero, a Russian exploit broker that acquired eight zero‑days from a former US defense contractor executive now jailed for his role. The action signals increased pressure on the commercial exploit market and raises compliance exposure for entities interacting—directly or indirectly—with sanctioned brokers. Security teams should assess vendor/supplier ties and update sanctions screening.
Source: SecurityWeek
Ex‑L3Harris (Trenchant) executive gets 87 months for selling cyber‑exploit trade secrets to Russia
Peter Williams was sentenced to more than seven years in prison after pleading guilty to stealing and selling sensitive cyber‑exploit trade secrets to a Russian broker, causing an estimated $35 million in losses. The court also ordered three years of supervised release and forfeitures, including a $1.3 million money judgment and crypto. The case highlights insider risk and the need for strict controls around exploit research and IP access.
Source: Help Net Security
You May Also Be Interested In...
Wireshark 4.6.4 resolves dissector flaws, plugin compatibility issue
Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware
Your MRI is Online: The Hidden Risks of Exposed DICOM Servers in UK Healthcare