The US FCC has barred the import and sale of all new consumer routers manufactured overseas unless vendors obtain an exemption, calling the products an “unacceptable risk” to national security. The sweeping move could reshape the home networking market, trigger supply chain shifts, and force buyers to scrutinize provenance and firmware security more closely.
Source: The Record
Citrix NetScaler critical flaw (CVE-2026-3055) poised for exploitation—patch now
Citrix fixed an out‑of‑bounds read in NetScaler ADC and Gateway that can be exploited remotely without authentication to read sensitive data from memory, potentially including session tokens. Researchers warn exploitation is likely imminent; organizations should patch urgently and invalidate active sessions to blunt token theft.
Source: SecurityWeek
DarkSword leak threatens to “democratize” iPhone exploitation
A GitHub leak of the DarkSword exploit kit could turn elite iOS hacking into a commodity tool, potentially putting hundreds of millions of iOS 18 devices at risk if attackers weaponize the code. Researchers warn the exposure lowers the barrier to entry and could accelerate opportunistic targeting while patch adoption lags.
Source: CyberScoop
Supply chain hit: LiteLLM Python package backdoored via polluted CI/CD
Attackers compromised two LiteLLM releases on PyPI with credential‑stealing code, likely stemming from the same TeamPCP campaign behind the Trivy incident. The tampered versions were yanked, but the episode underscores how CI/CD compromises can cascade into widely used developer components.
Source: The Register
FBI, CISA warn of account hijacks on Signal and WhatsApp
US and European agencies flagged a broad, easily scalable social engineering campaign hijacking encrypted messaging accounts. The guidance urges enabling PINs/registration locks, securing voicemail, and watching for SIM‑swap precursors as adversaries pivot to identity‑based takeovers.
Source: Malwarebytes
Report: 32% of top‑exploited vulns are more than a decade old
Cisco Talos’ 2025 Year in Review shows newly disclosed flaws are being weaponized almost immediately while a long tail of ancient weaknesses remains hot in the wild. The findings reinforce the need to pair rapid patching for fresh bugs with sustained remediation of legacy exposures across identity, infrastructure, and user workflows.
Source: Help Net Security
US prisons Russian initial access broker tied to ransomware operations
Aleksei Volkov was sentenced to 81 months for selling network access that enabled ransomware attacks causing over $9 million in losses and $24 million in intended damages. The case highlights law enforcement’s focus on the access-broker ecosystem that fuels rapid intrusion-to-extortion timelines.
Source: SecurityWeek
You May Also Be Interested In...
GitHub‑hosted malware campaign uses split payload to evade detection
Dutch Finance Ministry probing cyber breach affecting internal systems
Microsoft details AI prompt abuse techniques targeting AI assistants