Palo Alto Networks confirmed active exploitation of CVE-2026-0300, a buffer overflow in the Captive Portal service of PAN-OS on PA and VM series firewalls that enables unauthenticated remote code execution. Organizations should immediately restrict exposure of the User-ID/Authentication Portal to untrusted networks and apply vendor updates or mitigations as released.
Source: SecurityWeek
DAEMON Tools supply-chain attack delivers selective backdoor via signed installers
Kaspersky and others report that official, digitally signed DAEMON Tools installers were trojanized and distributed from the legitimate site, leading to thousands of infection attempts. While the trojanized installers were widespread, a sophisticated backdoor was dropped on only a small set of systems, including government and scientific entities—hallmarks of a highly targeted operation.
Source: SecurityWeek
Google patches critical zero‑click Android RCE (CVE‑2026‑0073)—update now
Google fixed a critical vulnerability in Android’s System component that allows remote code execution without any user interaction. The flaw lets attackers execute code as the shell user; admins should expedite deployment of the latest Android security updates across managed fleets.
Source: SecurityWeek
China‑nexus APT UAT‑8302 hits governments across South America and Europe
Cisco Talos exposed UAT‑8302, a sophisticated China-linked group that has targeted South American government entities since at least late 2024 and agencies in southeastern Europe in 2025. The campaigns feature post‑exploitation with custom malware and shared tooling across regions, underscoring sustained, geopolitical collection priorities.
Source: Cisco Talos
CloudZ RAT adds ‘Pheno’ plugin to steal one‑time passwords via Windows Phone Link
Cisco Talos detailed an intrusion active since January 2026 in which attackers deployed the CloudZ RAT and a previously undocumented “Pheno” plugin designed to capture credentials and potentially intercept OTPs. The technique abuses Windows Phone Link integrations, highlighting the need to harden device‑pairing workflows and favor phishing‑resistant MFA.
Source: Cisco Talos
MOVEit Automation flaws enable auth bypass and privilege escalation
Progress Software disclosed and patched two serious MOVEit Automation issues: CVE‑2026‑4670 (authentication bypass) and CVE‑2026‑5174 (privilege escalation). Given the platform’s critical role in file transfer workflows, organizations should patch immediately, review access logs, and validate automation credentials and roles.
Source: SOCRadar
CISA launches ‘CI Fortify’ to protect critical infrastructure during conflicts
CISA unveiled CI Fortify, a program aimed at helping U.S. critical infrastructure operators harden and sustain operations amid geopolitical conflict scenarios. The initiative follows years of warnings about foreign penetration of non‑military infrastructure and focuses on readiness, resilience, and rapid support.
Source: Nextgov
You May Also Be Interested In...
Rowhammer attacks on NVIDIA GPUs can lead to full system compromise
CISA reportedly weighing a 3‑day patch deadline for KEV vulnerabilities
Google expands Binary Transparency to Android apps to curb supply‑chain risk