CVE-2022-20775, CVE-2025-59536, CVE-2026-20127, CVE-2026-21852
IP Addresses:
20.9.8.2, 20.12.6.1, 20.15.4.2, 20.18.2.1
Get tomorrow's brief in your inbox
February 26, 2026
Today: Cisco issued emergency patches for two SD-WAN zero-days exploited since 2023 by sophisticated threat actors, CISA deadline February 27. Scattered LAPSUS$ Hunters now recruiting women for vishing attacks offering $500-1,000 per call. Claude Code vulnerabilities allow remote code execution and API key theft through malicious project files.
Cisco SD-WAN Zero-Days Exploited Since 2023 (CVE-2026-20127, CVE-2022-20775)
Cisco disclosed two vulnerabilities in Catalyst SD-WAN that have been actively exploited since at least 2023. CVE-2026-20127 (CVSS 10.0) allows unauthenticated remote attackers to bypass authentication and obtain administrative privileges. Attackers exploited this to create rogue peers in SD-WAN networks, then downgraded software to exploit CVE-2022-20775 (CVSS 7.8) for root privilege escalation before restoring the original version. The campaign, tracked by Cisco Talos as UAT-8616, targeted federal networks and critical infrastructure globally. Both CVEs are now on CISA's Known Exploited Vulnerabilities catalog with a February 27, 2026 remediation deadline.
Scattered LAPSUS$ Hunters Recruiting Women for Vishing Attacks
Scattered LAPSUS$ Hunters (SLH), the cybercrime supergroup combining LAPSUS$, Scattered Spider, and ShinyHunters, is now recruiting women specifically for voice phishing campaigns targeting IT help desks. The group offers $500-1,000 upfront per call plus pre-written scripts. The recruitment aims to increase success rates by using female voices that may bypass traditional attacker profiles that IT staff are trained to identify. SLH continues to use advanced social engineering to sidestep MFA through prompt bombing, SIM swapping, and help desk impersonation, followed by lateral movement to virtualized environments and data exfiltration leading to ransomware deployment.
RAMP Forum Seizure Disrupts Ransomware Ecosystem
Law enforcement seizure of the RAMP underground forum has fractured the ransomware ecosystem. The forum served as a marketplace and coordination point for ransomware affiliates and initial access brokers. Defenders should monitor how these groups re-form and consolidate threat intelligence to guide detection and response strategies during the reshuffling period.
Marquis Sues SonicWall Over Backup Breach Leading to Ransomware Attack
Marquis Software Solutions filed a lawsuit against SonicWall accusing the cybersecurity vendor of gross negligence that led to a ransomware attack disrupting 74 U.S. banks in August 2025. The attack was not caused by an unpatched firewall vulnerability as initially believed, but by attackers using configuration data extracted from SonicWall's MySonicWall cloud backup service. A SonicWall API code change in February 2025 created a security gap allowing unauthorized access to firewall configuration backups containing AES-256 encrypted credentials, configuration data, and MFA scratch codes. Mandiant attributed the attack to state-sponsored hackers. Marquis stated its firewall was fully patched with MFA enabled, but the threat actor compromised it using information from the SonicWall cloud breach. SonicWall disclosed the incident three weeks after the vulnerability was introduced and initially claimed it affected 5% of customers before confirming all clients were impacted. Marquis now faces 36 consumer class action lawsuits.
Google Disrupts GRIDTIDE Global Espionage Campaign
Google Threat Intelligence Group (GTIG) and Mandiant disrupted a global cyber espionage campaign by UNC2814, a suspected China-nexus threat actor tracked since 2017. The campaign targeted telecommunications and government organizations in 42 countries across four continents. UNC2814 deployed the GRIDTIDE backdoor, which used Google Sheets API calls for command-and-control to disguise malicious traffic as legitimate cloud activity. Google terminated all attacker-controlled Google Cloud Projects, disabled attacker accounts, revoked access to Google Sheets API, and released IOCs dating to 2023. The campaign affected 53 confirmed victims with suspected infections in 20 additional countries. This activity is distinct from Salt Typhoon and targets different victims using different TTPs. Initial access vector is unconfirmed but UNC2814 historically exploits web servers and edge systems.
Fake Next.js Job Interview Tests Deploy Backdoors on Developer Machines
Microsoft Defender identified a coordinated campaign targeting software developers using malicious Next.js repositories disguised as legitimate coding projects and technical assessment materials. Attackers created fake web app projects on Bitbucket (and other platforms) that execute malicious JavaScript automatically when developers clone and open the repository. Multiple execution triggers exist: VS Code .vscode/tasks.json with "runOn: folderOpen", trojanized assets during "npm run dev", and backend modules that decode C2 endpoints from .env files. The JavaScript payload profiles the host, registers with a C2 server, and upgrades to a tasking controller that supports remote code execution, file enumeration, and staged data exfiltration. Multiple repositories shared naming conventions and infrastructure, indicating a coordinated campaign rather than one-off attacks.
Claude Code Flaws Allow RCE and API Key Exfiltration (CVE-2026-21852, CVE-2025-59536)
Check Point disclosed three vulnerabilities in Anthropic's Claude Code AI coding assistant that allow remote code execution and API key theft when developers open untrusted repositories. One flaw (CVSS 8.7, no CVE, fixed September 2025) bypassed user consent via malicious Hooks in .claude/settings.json. CVE-2025-59536 (CVSS 8.7, fixed October 2025) allowed automatic execution of arbitrary shell commands through Model Context Protocol (MCP) servers defined in repository configuration files. CVE-2026-21852 (CVSS 5.3, fixed January 2026) enabled API key exfiltration by setting ANTHROPIC_BASE_URL to an attacker-controlled endpoint before the trust prompt appeared. Simply opening a crafted repository triggered credential theft and enabled redirection of authenticated API traffic.
Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware
Socket discovered four malicious NuGet packages targeting ASP.NET developers: NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_. The packages accumulated 4,500 downloads between August 12-21, 2024, before removal. NCryptYo acted as a first-stage dropper establishing a localhost proxy on port 7152 relaying traffic to attacker C2. DOMOAuth2_ and IRAOAuth2.0 exfiltrated ASP.NET Identity data (user accounts, role assignments, permissions) and backdoored applications by modifying authorization rules to grant admin access. SimpleWriter_ enabled file writing and hidden process execution. The attack targeted deployed production applications, not developer machines directly. Separately, Tenable disclosed the npm package ambar-src with 50,000 downloads that used preinstall hooks to deliver platform-specific malware: msinit.exe on Windows (encrypted shellcode), ELF reverse shell on Linux, and scripts on macOS.
SolarWinds Patches Four Critical Serv-U Vulnerabilities
SolarWinds released patches for four critical vulnerabilities in Serv-U that could allow remote code execution. The flaws require administrative privileges to exploit, reducing the likelihood of external attack but creating significant risk if an attacker already has admin access through phishing or credential theft.
UFP Technologies Discloses Data Theft in Cyberattack
Medical device manufacturer UFP Technologies (4,300 employees, $600M annual revenue) disclosed a cyberattack detected February 14, 2026, that compromised IT systems and stole data. The company deployed isolation measures and engaged external advisors. Preliminary investigation indicates the threat actor has been removed, but data was stolen or destroyed, suggesting ransomware or wiper malware. Affected functions included billing and label-making for customer deliveries. The company has not yet determined if personal information was exfiltrated. UFP Technologies stated the incident is unlikely to have material impact on operations or financials. No ransomware group has publicly claimed the attack.
US Sanctions Russian Exploit Broker Operation Zero
The U.S. Treasury Department sanctioned Operation Zero, a Russian exploit broker that acquired eight zero-day exploits from a U.S. defense contractor executive now in prison for selling the vulnerabilities. Exploit brokers facilitate the sale of zero-day vulnerabilities to nation-state threat actors and intelligence services, creating a market for offensive cyber capabilities.
LLMs Enable Automated Deanonymization of Pseudonymous Users
Researchers demonstrated that large language models can automate the deanonymization of pseudonymous users across platforms like Hacker News, Reddit, and LinkedIn with 67% accuracy at 90% precision. The technique cost approximately $2,000 for the entire experiment ($1-4 per profile). LLMs extract identity-relevant signals from unstructured text, search across millions of candidate profiles, and reason about account ownership. Previous deanonymization techniques required manual effort and predefined feature schemas. LLMs make this process scalable and affordable. Governments could use this to target journalists or activists; corporations could identify employees or customers posting anonymously; threat actors could deanonymize security researchers or whistleblowers.
Today's brief is dominated by supply chain and infrastructure attacks targeting the development and operational layers of IT environments. The Cisco SD-WAN zero-days and the SonicWall cloud backup breach demonstrate that network edge devices and vendor cloud services remain high-value targets for sophisticated threat actors. Developer-focused attacks through malicious repositories (Next.js, Claude Code, NuGet, npm) show that attackers are shifting left to compromise software before it reaches production. Scattered Spider's recruitment of women for social engineering highlights the adversary's operational adaptation to bypass security awareness training. Organizations must defend at multiple layers: patch network edge devices immediately, scrutinize developer workflows as attack surfaces, and train staff to recognize evolving social engineering tactics.