Cisco confirmed active exploitation of a high-severity privilege escalation flaw in Catalyst SD‑WAN Manager that currently has no patch. Attackers need netadmin-level access, which Cisco says may be obtained by chaining with CVE‑2026‑20182 or CVE‑2026‑20127; the company has observed limited in-the-wild abuse. Organizations should lock down admin credentials, restrict management-plane exposure, audit recent file uploads/config changes, and monitor for anomalous admin activity.
Source: The Hacker News
Supply-chain alert: Miasma worm compromises 73 Microsoft GitHub repos
A self-replicating supply-chain campaign dubbed “Miasma” hit 73 Microsoft repositories across Azure, MicrosoftDocs, and other orgs, prompting GitHub to disable access to impacted repos. The ongoing operation has also been linked in separate reports to poisoned npm packages, underscoring the risk to developer environments and CI/CD secrets. Teams should freeze and verify dependencies, rotate exposed tokens, and audit build pipelines for tainted artifacts.
Source: The Hacker News
Researchers demo autonomous AI worm that reasons, adapts, and self-hosts its LLM
University of Toronto researchers built a proof-of-concept agentic AI worm that autonomously selects and exploits known vulnerabilities, then hijacks compute on infected hosts to run its own LLMs—driving the marginal cost of new infections to near zero. In a simulated mixed Windows/Linux/IoT environment, it compromised 73.8% of the network within seven days. While a lab demo, it signals a shift toward more adaptive attacks; defenders should double down on fundamentals: asset inventory, segmentation, rapid patching, and anomaly detection.
Source: TechTarget SearchSecurity
Silent Ransom Group adds in‑person impersonation to vishing playbook, Google/Mandiant warns
Mandiant (Google Cloud) details a fast-moving UNC3753/Silent Ransom Group campaign that uses voice phishing to convince employees to run screen‑sharing and RMM tools, then exfiltrates legal and financial data for extortion—often in under a day. In some cases aligned with an FBI alert, actors allegedly sent impostor “IT technicians” on-site to steal data via USB. Recommended controls include strict conditional access for VDI/VPN, blocking unauthorized RMM/screen control, out‑of‑band verification for IT requests, USB lockdown, and high‑fidelity monitoring for bulk file access and exfiltration.
Source: Google Cloud Threat Intelligence
Chrome 149 ships record 429 security fixes—patch immediately
Google’s latest Chrome release addresses 429 vulnerabilities, with more than 100 rated critical or high, including numerous use‑after‑free and input validation issues. Enterprise admins should expedite updates across Windows, macOS, Linux, Android, and iOS channels, and validate EDR/patch compliance given the unusually large fix set.
Source: SecurityWeek
Dashlane: Threat actor copied encrypted vaults from some user accounts
Dashlane disclosed that a brute‑force campaign enabled access to a subset of customer accounts and the copying of encrypted password vaults; there’s no evidence of an internal systems breach. While vaults remain encrypted, risk rises for users with weak master passwords or reused credentials. Dashlane users should enable 2FA, ensure a strong, unique master password, review device activity, and rotate any credentials that may be at risk.
Source: Help Net Security
CISA adds actively exploited SolarWinds Serv‑U DoS flaw (CVE‑2026‑28318) to KEV
CISA placed a high‑severity denial‑of‑service bug in SolarWinds Serv‑U on its Known Exploited Vulnerabilities catalog after reports of attackers crashing servers. Federal agencies—and any org running Serv‑U—should prioritize vendor updates and mitigate exposure of file‑transfer services, while monitoring for repeated crash cycles and service restarts indicative of exploitation.
Source: The Hacker News
You May Also Be Interested In...
Let’s Encrypt plans post‑quantum web authentication via Merkle Tree CertificatesFive Eyes: Chinese spies pose as recruiters targeting government and military staff
Meta’s AI support agent enabled account takeovers—why your SOC missed it