A critical authentication bypass in Cisco Catalyst SD‑WAN Controller/Manager (CVE-2026-20127, CVSS 10.0) has been actively exploited since 2023 to gain unauthenticated administrative access. Organizations should patch immediately and lock down management interfaces, as successful exploitation enables policy push at scale and rapid lateral impact across sites.
Source: Security Affairs
Google disrupts China‑linked cyberespionage hitting 53 orgs across 42 countries
Google detailed and disrupted a long‑running cyberespionage campaign targeting at least 53 government and telecom organizations in 42 countries. The takedown underscores sustained, globally distributed targeting of critical public‑sector networks and telecom infrastructure by China‑nexus operators.
Source: Recorded Future News (The Record)
New “Dohdoor” backdoor targets U.S. education and healthcare
Cisco Talos tracked threat cluster UAT‑10027 deploying a previously unseen backdoor dubbed “Dohdoor” against U.S. education and healthcare orgs since at least December 2025. Initial access likely begins with phishing that launches PowerShell, with the stealthy implant designed for persistent remote control.
Source: Security Affairs
Anthropic patches Claude Code flaws that enabled silent RCE and API key theft
Anthropic fixed vulnerabilities in Claude Code that researchers showed could be triggered via malicious configuration files to achieve remote code execution and exfiltrate developer API credentials. Teams should update promptly, review developer environments for tampering, and rotate potentially exposed tokens and keys.
Source: SecurityWeek
OpenAI: Fraudsters fold ChatGPT into global romance scams and influence ops
OpenAI’s latest abuse report shows ChatGPT and related APIs integrated into worldwide fraud and influence campaigns, including romance scams, fake legal services, coordinated propaganda, and a state‑linked harassment effort. The findings highlight how off‑the‑shelf AI accelerates social engineering at scale, raising the urgency for content‑driven detection and user education.
Source: Help Net Security
Industrial networks still exposed: OT services leaking onto the public internet
New research from Palo Alto Networks, Siemens, and Idaho National Lab found ongoing growth in publicly reachable OT assets, including remote access portals and building automation servers, with over 110 million observations of exposed OT devices in 2024. Operators should urgently inventory external exposure, enforce segmentation, and eliminate unauthenticated remote access to industrial systems.
Source: Help Net Security
NATO greenlights iPhone and iPad for handling restricted‑level classified data
Apple confirmed iPhone and iPad are now approved for use with restricted‑level classified information in NATO environments and added to the NIAPC, without requiring specialized software or settings. The move expands COTS device usage in sensitive government contexts and raises the bar for enterprise‑grade mobile security baselines.
Source: SecurityWeek
You May Also Be Interested In...
Juniper Networks PTX Routers Affected by Critical Vulnerability