US federal agencies have until Sunday to patch a maximum‑severity authentication bypass in Cisco Catalyst SD‑WAN controllers that attackers are already exploiting. The flaw allows unauthenticated remote takeover with admin privileges; it has been added to CISA’s Known Exploited Vulnerabilities list. Organizations should patch immediately, audit admin accounts and logs for signs of compromise, and limit management-plane exposure.
Source: RecordedFuture
Microsoft Exchange zero‑day (CVE‑2026‑42897) exploited in the wild; OWA impacted
Microsoft warned that attackers are actively exploiting an Exchange Server cross‑site scripting flaw (CVSS 8.1) affecting Outlook Web Access. Temporary mitigations are available while a permanent patch is prepared; admins should apply mitigations, increase monitoring for anomalous OWA activity, and review egress for data theft. Given recent offensive research, prioritize isolation of internet‑exposed Exchange services.
Source: SecurityWeek
PoC released for critical NGINX rewrite module bug; patch now to avert RCE
Exploit proof‑of‑concept code is now public for a long‑standing critical vulnerability in NGINX’s HTTP rewrite module, which was patched this week in both open‑source and NGINX Plus. The flaw, present since 2008, could enable denial of service and potentially remote code execution via crafted requests. Update NGINX immediately and consider compensating controls (e.g., WAF virtual patches) where rapid maintenance isn’t feasible.
Source: SecurityWeek
OpenAI caught in TanStack npm supply‑chain incident; employee devices, repo creds hit
OpenAI confirmed two employee devices were compromised via the TanStack supply‑chain attack, leading to theft of credential material from internal code repositories. The company says no user data, production systems, or IP were impacted. The case underscores persistent risks in developer ecosystems—security teams should lock down developer endpoints, rotate secrets, enforce least‑privilege repo access, and continuously scan dependencies.
Source: SecurityWeek
‘Fragnesia’ Linux privilege‑escalation disclosed with PoC; fourth such flaw in weeks
A new Linux kernel privilege‑escalation vulnerability dubbed “Fragnesia” has been disclosed, and a proof‑of‑concept is publicly available. It’s at least the fourth Linux privesc in recent weeks, raising the urgency for rapid kernel updates across servers and endpoints. Monitor distribution advisories, patch quickly, and use eBPF/LKM tamper controls and syscall monitoring to detect exploitation attempts.
Source: SCMagazine
JDownloader site compromise swapped installer links with malware for days
Attackers breached the JDownloader website and replaced official installer download links with malware for several days. Users who downloaded during the window may have executed trojanized binaries. Verify hashes/signatures, re‑install from clean sources, and hunt for post‑execution indicators; software publishers should harden CI/CD and release channels to reduce supply‑chain exposure.
Source: MalwareBytes Blog
GTIG exposes ‘BlackFile’ vishing + AiTM extortion playbook targeting M365/Okta
Google Threat Intelligence detailed UNC6671 (“BlackFile”), which uses voice phishing and adversary‑in‑the‑middle techniques to capture credentials, bypass MFA, register attacker devices, and programmatically exfiltrate data from Microsoft 365 and Okta‑connected apps. The group favors stealthy API/scripted downloads and escalates extortion with aggressive multi‑channel harassment. Move to phishing‑resistant MFA (FIDO2/passkeys), enable credential guarding, and treat anomalous FileAccessed events with scripted user‑agents as high priority.
Source: GoogleCloud TI
You May Also Be Interested In...
Chrome 148 Update Patches Critical Vulnerabilities
ESET details new Ghostwriter activity targeting Ukrainian government