Researchers say an Iran-linked group has been inside multiple US organizations since early February, including an airport, a bank, and a software company. The activity suggests pre-positioning ahead of potential broader operations as regional tensions rise, underscoring the need to hunt for lateral movement, unusual admin tool use, and new persistence. Prioritize credential hygiene and network segmentation to reduce blast radius if footholds already exist.
Source: SecurityWeek
Active exploitation: Cisco Catalyst SD-WAN Manager flaws under attack
Cisco confirmed that attackers are exploiting two vulnerabilities (CVE-2026-20122 and CVE-2026-20128) in Catalyst SD-WAN Manager/vManage, enabling file overwrites and privilege escalation. Organizations should patch immediately, restrict management interfaces from the internet, and monitor for anomalous admin actions and configuration changes in SD-WAN controllers.
Source: The Register
CISA adds iOS Coruna exploit kit chain to Known Exploited Vulnerabilities list
Three iOS vulnerabilities tied to a nation-state–grade exploit kit affecting versions 13 through 17.2.1 were added to CISA’s KEV catalog, signaling confirmed in-the-wild abuse. Federal agencies face patch deadlines, and enterprises should expedite updates to the latest iOS, enforce MDM controls, and block untrusted configuration profiles to limit mobile attack surface.
Source: SecurityWeek
Rockwell ICS vulnerability exploited in real-world attacks
A long-known Rockwell Automation Logix flaw disclosed in 2021 has been observed in active attacks, highlighting persistent risk to industrial control environments. Asset owners should re-apply vendor mitigations, audit controller change logs, and ensure strict IT/OT network segmentation and allow-listing of programming workstations.
Source: SecurityWeek
FBI probes ‘suspicious’ cyber activity on system with sensitive surveillance data
The FBI is investigating suspicious activity affecting a system that holds sensitive surveillance information and is working to determine scope and impact. The incident is a reminder to harden high-value law enforcement and intelligence systems with strict access controls, continuous monitoring, and rapid isolation runbooks.
Source: SecurityWeek
Hacking security cameras becomes part of modern warfare playbook
New research documents hundreds of attempts by apparent Iranian state actors to hijack consumer-grade security cameras, often timed to missile and drone strikes for intelligence and battle damage assessment. Organizations should treat cameras as high-risk IoT: change defaults, patch firmware, disable remote access, and isolate devices on dedicated, no-internet VLANs.
Source: Wired
‘ClickFix’ twist: Windows Terminal lured into launching Lumma infostealer
A new campaign persuades users to open Windows Terminal and paste attacker-supplied commands themselves, installing the Lumma credential stealer and raiding browser password vaults. Because the execution is user-initiated, traditional email defenses can miss it—educate users, restrict script execution where possible, and monitor for suspicious Terminal and PowerShell activity.
Source: The Register
You May Also Be Interested In... Fake CleanMyMac site installs SHub Stealer and backdoors crypto wallets (Malwarebytes)
Transport for London says 2024 breach affected 7M customers, not 5,000 (The Register)
Cisco patches 48 firewall bugs including two CVSS 10 flaws (HackRead)