CYBERSECURITY INTEL FREE'Dself-hosted CTI

HIGH PRIORITY // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 48 matching records.
AUTO-POLL // 2026-08-16 03:50 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-07-15 13:14 UTC
Vendor Research
TIER 2

CVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild

Tenable Cyber Exposure Alerts · Scott Caveza · indexed 2026-08-16 02:02 UTC

SonicWall patched two recently exploited zero-day vulnerabilities in its SMA 1000 Series secure remote access appliances which may have been chained for unauthenticated remote code execution.Key takeawaysCVE-2026-15409 and CVE-2026-15410 are a pair of exploited vulnerabilities that may have been chained together to allow for code execution on SonicWall SMA1000 series appliances. Zero-day exploitation of these vulnerabilities has been observed and confirmed by SonicWall. Patches and indicators of compromise are available and urgent patching is recommended.BackgroundSonicWall's Secure Mobile Ac…

Cloud SecurityNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-15409CVE-2026-15410
P100
2026-08-11 21:10 UTC
Vendor Research
TIER 2

Patch Tuesday - August 2026

Rapid7 · Adam Barnett · indexed 2026-08-16 02:02 UTC

Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday, including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are no…

Cloud SecurityCredential ExposureLinuxMicrosoftSecurity ResearchVulnerabilities CVE-2026-50656CVE-2026-55040CVE-2026-62832CVE-2026-63520CVE-2026-6726CVE-2026-6727CVE-2026-68820CVE-2026-72971
P95
2026-07-16 12:00 UTC
Vendor Research
TIER 2

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.Key TakeawaysCISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-202…

Cloud SecurityMalwareMicrosoftRansomwareThreat ActorsVulnerabilities CVE-2026-32201CVE-2026-45659CVE-2026-55040CVE-2026-56164CVE-2026-58644
P95
2026-06-09 14:19 UTC
Vendor Research
TIER 2

Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

32Critical166Important0Moderate0LowMicrosoft addresses 198 CVEs in the largest Patch Tuesday release, including three zero-days.Microsoft patched 198 CVEs in its June 2026 Patch Tuesday release, with 32 rated critical and 166 rated as important. Our counts omitted 6 CVEs that were already addressed by Microsoft via servicing and do not require additional customer action to resolve as well as 2 CVEs that were disclosed by other CNAs (CVE-2025-10263 and CVE-2026-8863). This Patch Tuesday release is the largest release since the Patch Tuesday program began, smashing the previous record of 167 CV…

Cloud SecurityLinuxMicrosoftMobile SecurityVulnerabilities CVE-2025-10263CVE-2026-33825CVE-2026-41091CVE-2026-42909CVE-2026-42913CVE-2026-42985CVE-2026-42992CVE-2026-42993CVE-2026-44799CVE-2026-44801CVE-2026-47289CVE-2026-47653CVE-2026-47654CVE-2026-48563CVE-2026-49160CVE-2026-50507CVE-2026-8863
P95
2026-08-11 17:54 UTC
Community
TIER 2

Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)

SANS Internet Storm Center · indexed 2026-08-16 02:20 UTC

This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs. 

MicrosoftVulnerabilities
P70
2026-08-07 14:32 UTC
Vendor Research
TIER 2

Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)

Rapid7 · Stephen Fewer · indexed 2026-08-16 02:02 UTC

OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unsafe deserialization vulnerability affecting JetBrains TeamCity. An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without credentials and execute operating system commands with the privileges of the TeamCity server process.JetBrains reported no known active exploitation when it disclosed the vulnerability. However, on August 5, 2026, CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities (KEV) catalog, confirming exploitation in the …

MicrosoftVulnerabilities CVE-2026-63077
P70
2026-07-20 09:36 UTC
Vendor Research
TIER 2

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-08-16 02:02 UTC

An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.Key takeaways:Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations. Multiple security firms have confirmed in-the-w…

Cloud SecurityDFIRMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-60137CVE-2026-601377CVE-2026-63030
P70
2026-08-11 14:04 UTC
Vendor Research
TIER 2

Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)

Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC

42Critical355Important1Moderate0LowMicrosoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.This month’s update includes patches for:.NET.NET Core.NET FrameworkAMD ZenActive Directory Certificate Services (AD CS)Application Information ServicesAzure Active DirectoryAzure CycleCloudAzure Monitor Agent…

Cloud SecurityLinuxMicrosoftMobile SecurityNetwork SecurityVulnerabilities CVE-2022-21919CVE-2022-26904CVE-2024-38193CVE-2025-21418CVE-2025-32709CVE-2026-61348CVE-2026-62714CVE-2026-62715CVE-2026-62716CVE-2026-62718CVE-2026-62720CVE-2026-62742CVE-2026-62745CVE-2026-62761CVE-2026-62776CVE-2026-62803CVE-2026-62807CVE-2026-62812CVE-2026-62814CVE-2026-6726CVE-2026-6727CVE-2026-68820CVE-2026-70307
P65
2026-08-04 11:11 UTC
Vendor Research
TIER 2

CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

Rapid7 · Rapid7 · indexed 2026-08-16 02:02 UTC

OverviewOn August 2, 2026, N-able published a security advisory for CVE-2026-18577, an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments.N-able N-central is a widely deployed Remote Monitoring and Management (RMM) platform used by managed service providers (MSPs) and enterpri…

DFIRMicrosoftThreat IntelligenceVulnerabilities CVE-2026-18556CVE-2026-18577
P65
2026-07-14 14:23 UTC
Vendor Research
TIER 2

Microsoft’s July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

56Critical510Important3Moderate0LowMicrosoft addresses 569 CVEs in the largest Patch Tuesday release yet. This month’s release includes three zero-days, two of which were exploited in the wild.Microsoft patched 569 CVEs in its July 2026 Patch Tuesday release, with 56 rated critical, 510 rated as important, and 3 rated as moderate. This marks the largest Patch Tuesday release ever, crushing the previous record of 198 CVEs in June. Last week, Microsoft announced that its multi-model agentic scanning harness (MDASH) is being used to identify vulnerabilities faster and noted that “customers will …

AppleCloud SecurityLinuxMalwareMicrosoftMobile SecurityNetwork SecurityVulnerabilities CVE-2026-56155CVE-2026-56164
P65
2026-06-18 05:23 UTC
Vendor Research
TIER 2

Oracle June 2026 Critical Security Patch Update Addresses 243 CVEs (CVE-2026-35273)

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-16 02:02 UTC

Oracle addresses 243 CVEs in its June 2026 Critical Security Patch Update with 245 patches, including 122 critical updates.Key TakeawaysThe June 2026 Critical Security Patch Update (CSPU) contains fixes for 243 unique CVEs in 245 security updates122 issues (49.8% of all patches) were assigned a critical severity ratingOracle Fusion Middleware received the highest number of patches at 106, accounting for 43.3% of all patchesBackgroundOn June 16, Oracle released its Critical Security Patch Update (CSPU) for June 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle tha…

Threat IntelligenceVulnerabilities CVE-2026-35273
P65
2026-07-28 18:32 UTC
Vendor Research
TIER 2

Rapid7 Analysis: Check Point SmartConsole Authentication Bypass (CVE-2026-16232)

Rapid7 · Stephen Fewer · indexed 2026-08-16 02:02 UTC

OverviewOn July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GU…

MicrosoftVulnerabilities CVE-2026-16232
P60
2026-05-11 14:00 UTC
Vendor Research
TIER 2

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-16 02:02 UTC

Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows. This report, based on insights derived from Mandiant incident response engagements, Gemini, and GTIG’s proactive research, highlights the dual nature of the current threat environment where AI serves as both a sophisticated engine for adversary operations and a high-value target for attacks. We explore the foll…

AI SecurityAppleAPT / Nation-StateCloud SecurityDFIRInitial AccessMalwareMicrosoftNetwork SecurityRansomwareSecurity ResearchThreat ActorsThreat IntelligenceVulnerabilities
P60
2026-04-16 14:00 UTC
Vendor Research
TIER 2

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

Google Threat Intelligence / Mandiant · Francis deSouza · indexed 2026-08-16 02:02 UTC

Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulnerabilities. Faced with this scenario, defenders have two critical tasks: hardening the software we u…

AI SecurityAPT / Nation-StateCloud SecurityDFIRMicrosoftRansomwareThreat Actor ChatterThreat ActorsUnderground IntelligenceVulnerabilities
P60
2026-08-11 13:00 UTC
Vendor Research
TIER 2

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Rapid7 · Stephen Fewer · indexed 2026-08-16 02:02 UTC

OverviewRapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month.Our full disclosure timeline for the exploit chain can be seen below in Figure 1.Figure 1: The road to disc…

AI SecurityMicrosoftSecurity ResearchVulnerabilities CVE-2026-55040CVE-2026-63520
P55
2026-08-08 06:52 UTC
Security Journalism
TIER 3

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary

Vulnerabilities CVE-2026-8037
P55
2026-05-25 14:00 UTC
Vendor Research
TIER 2

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). An unknown threat actor leveraged this access to inject malicious code into the LMS platform, with the goal of infecting users visiting the site. This vulnerability stems from the use of identi…

AppleDFIRMalwareMicrosoftThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-5426
P55
2026-03-25 07:51 UTC
Government
TIER 1

2026-004: Critical Vulnerability in SharePoint Exploited

CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC

On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026. Additionally, three further RCE flaws affecting Microsoft SharePoint were addressed in the March 2026 release. CERT-EU strongly recommends updating SharePoint servers as soon a…

Cloud SecurityMicrosoftVulnerabilities
P55
2026-07-30 16:11 UTC
Vendor Research
TIER 2

KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

Rapid7 · Rapid7 Labs · indexed 2026-08-16 02:02 UTC

OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability has a CVSSv4 score of 9.5 and is classified as Initialization of a Resource with an Insecure Default (CWE-1188). An unauthenticated attacker may be able to leverage CVE-2026-66066 and read files accessible to the Rails application process, potentially exposing secrets that could enable remote code execution (RCE) or access to connected system…

Vulnerabilities CVE-2026-66066
P50
2026-07-30 10:35 UTC
Vendor Research
TIER 2

Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)

Rapid7 · Rapid7 · indexed 2026-08-16 02:02 UTC

OverviewOn July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.CVECVSSv3.1Description SummaryCVE-2026-593099.8 (Critical)An authentication bypass vulnerability in the VMware Directory Service of vCenter that could all…

MicrosoftVulnerabilities CVE-2026-59309CVE-2026-59310CVE-2026-593109
P50
2026-07-29 16:16 UTC
Vendor Research
TIER 2

CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity

Rapid7 · Rapid7 · indexed 2026-08-16 02:02 UTC

OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8. An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process.In the blog post that JetBrains shared in tandem with CVE publication, they stated that …

Vulnerabilities CVE-2026-63077
P50
2026-08-08 06:58 UTC
Security Journalism
TIER 3

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-16 02:02 UTC

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain

Vulnerabilities
P45
2026-07-29 13:00 UTC
Vendor Research
TIER 2

How AI is Rewriting the Zero-Day Playbook for Preemptive Security

Rapid7 · Joel Alcon · indexed 2026-08-16 02:02 UTC

The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most difficult, question: "Are we exposed?”Answering questions like these when zero-days drop tends to trigger a frantic, high-stress fire drill. Analysts scramble to cross-reference outdated Configuration Management Databases (CMDBs), query disparate endpoint detection tools, and ping IT administrators. The…

DFIRVulnerabilities
P45
2026-07-28 23:19 UTC
Vendor Research
TIER 2

Coordinated "cyberattack" on U.S. water utilities: What you need to know

Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC

A coordinated cyber attack disrupted water and wastewater systems in at least 12 U.S. states, including more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how to protect exposed infrastructure.Change logUpdate August 10: Added Columbus Water Works as a second confirmed Georgia victim. Added a table summarizing publicly confirmed affected entities to date.This is an active situation. Tenable's Research Special Operations team is monitoring developments and will update t…

DFIRICS / OTLaw EnforcementMalwareMicrosoftThreat IntelligenceVulnerabilities CVE-2021-22681
P45
2026-07-23 07:13 UTC
Government
TIER 1

2026-009: Critical Vulnerabilities in Microsoft SharePoint

CERT-EU Security Advisories · indexed 2026-08-16 02:02 UTC

[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that…

Cloud SecurityCredential ExposureMicrosoftVulnerabilities CVE-2026-32201CVE-2026-45659CVE-2026-50522CVE-2026-56164CVE-2026-58644
P45
2026-06-11 14:00 UTC
Vendor Research
TIER 2

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8) in the Environment Management component. The exploitation of this vulnerability directly aligns with the observed targeting of Environment Management Hub (PSEMHUB) endpoints. Because this activity p…

AppleCloud SecurityData BreachesLinuxMicrosoftThreat ActorsThreat IntelligenceVulnerabilities CVE-2026-35273
P45
2026-08-14 07:01 UTC
Security Journalism
TIER 3

Hackers Exploiting Unpatched GeoServer Zero-Day

SecurityWeek · Ionut Arghire · indexed 2026-08-16 02:02 UTC

The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek.

Vulnerabilities
P40
2026-06-24 11:00 UTC
Vendor Research
TIER 2

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-08-16 02:02 UTC

Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access. The vulnerability stems from the device’s file upload feature lacking the ability to properly filter malicious data. Throughout the intrusion, to maintain operational security and avoid det…

Initial AccessMicrosoftNetwork SecurityThreat ActorsVulnerabilities CVE-2026-20127CVE-2026-20182CVE-2026-20245
P40
2026-07-17 10:00 UTC
Vendor Research
TIER 2

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

Palo Alto Networks Unit 42 · Emmanuel Zhou, Adam Robbie, Rick Wyble and Miguel Pereira · indexed 2026-08-16 02:02 UTC

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.

Network SecurityVulnerabilities
P35
2026-08-14 21:36 UTC
Vendor Research
TIER 2

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

Tenable Blog · Research Special Operations · indexed 2026-08-16 02:02 UTC

Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts, and exfiltrated more than 2,564 personnel records in approximately four days.The Taiwan campaign is…

AI SecurityAPT / Nation-StateCloud SecurityInitial AccessNetwork SecurityThreat ActorsVulnerabilities CVE-2025-3248
P30
12