CVE-2022-20775, CVE-2025-1924, CVE-2025-48019, CVE-2025-48020, CVE-2025-48021, CVE-2025-69873, CVE-2025-71210, CVE-2025-71211, CVE-2026-1241, CVE-2026-20127, CVE-2026-21654, CVE-2026-21656, CVE-2026-21657, CVE-2026-21718, CVE-2026-21902, CVE-2026-24663, CVE-2026-25085, CVE-2026-27571, CVE-2026-27965, CVE-2026-27969, CVE-2026-3062, CVE-2026-3063
IP Addresses:
79.110.49.15
Get tomorrow's brief in your inbox
Today: Five Eyes issues urgent joint alert for two Cisco SD-WAN vulnerabilities under active exploitation since 2023, including a 10.0-severity flaw granting attackers root access. Trend Micro patches critical Apex One RCE bugs with no evidence of exploitation yet. CISA discloses 23 CVEs across Copeland industrial controllers, multiple EV charging platforms face authentication bypass flaws, and ransomware payment rates hit record lows despite surging attack volumes.
Cisco Catalyst SD-WAN Zero-Days Under Active Exploitation (CVE-2022-20775, CVE-2026-20127)
Five Eyes intelligence agencies issued a rare joint alert confirming active exploitation of two Cisco Catalyst SD-WAN vulnerabilities. CVE-2026-20127 (CVSS 10.0) is an authentication flaw in SD-WAN Controller/Manager allowing admin access and NETCONF reconfiguration. CVE-2022-20775 (CVSS 7.8) is a 2022-era path traversal bug enabling privilege escalation. Cisco Talos attributes attacks to UAT-8616, a sophisticated threat actor exploiting these flaws since at least 2023. Attack chain: gain admin via CVE-2026-20127, downgrade software via CVE-2022-20775 to achieve root access, then establish persistent backdoors. Targets include high-value organizations in critical infrastructure sectors. Both vulnerabilities are now tracked on CISA KEV with a 2026-02-27 due date.
Trend Micro Apex One Critical RCE Vulnerabilities (CVE-2025-71210, CVE-2025-71211)
Trend Micro patched two critical path traversal flaws in the Apex One management console allowing unauthenticated remote code execution. Both CVE-2025-71210 and CVE-2025-71211 affect different executables but share similar exploitation vectors. Exploitation requires attackers to access the management console, so organizations with internet-exposed consoles face elevated risk. No evidence of active exploitation yet, but Trend Micro's history includes 10 Apex vulnerabilities tracked on CISA KEV for confirmed in-the-wild abuse. Critical Patch Build 14136 also fixes two high-severity privilege escalation flaws in Windows agents and four affecting macOS agents.
Copeland XWEB Industrial Controllers (23 CVEs)
CISA published an advisory covering 23 vulnerabilities in Copeland XWEB and XWEB Pro industrial control devices (models 300D PRO, 500D PRO, 500B PRO, all versions 1.12.1 and prior). Flaws include authentication bypass (CVE-2026-25085, CVE-2026-21718), OS command injection (CVE-2026-24663), and multiple memory corruption issues enabling remote code execution, DoS, and authentication bypass. Devices are used in Commercial Facilities sector worldwide. Copeland released patches and recommends updating to latest firmware via their software update portal or directly from device menu (SYSTEM - Updates | Network).
Johnson Controls Frick Quantum HD Pre-Auth RCE (6 CVEs)
Six vulnerabilities in Johnson Controls Frick Controls Quantum HD (versions 10.22 and prior) enable pre-authentication RCE, information disclosure, and DoS. CVE-2026-21654, CVE-2026-21656, CVE-2026-21657 all stem from insufficient input validation allowing OS command injection and code injection before authentication. Affects Food and Agriculture critical infrastructure. Versions 10.22 through 11 are legacy and end-of-support. Johnson Controls recommends upgrading to Quantum HD Unity version 12 or higher, then applying hardening guide configurations.
EV Charging Platform Authentication Bypass (Multiple Vendors)
CISA disclosed authentication and session management flaws affecting six EV charging platform vendors: Chargemap, EV Energy, Mobility46, CloudCharge, EV2GO, and SWITCH EV. Common vulnerabilities: missing authentication on WebSocket endpoints (CWE-306), lack of rate limiting enabling brute-force attacks (CWE-307), predictable session identifiers enabling hijacking (CWE-613), and publicly accessible charging station credentials (CWE-522). Attackers can impersonate charging stations, manipulate backend data, and conduct large-scale DoS. Energy and Transportation Systems critical infrastructure affected. None of the vendors responded to CISA coordination attempts.
Yokogawa CENTUM VP Industrial Systems (6 CVEs)
Six vulnerabilities in Yokogawa Vnet/IP Interface Package for CENTUM VP R6 and R7 (versions R1.07.00 and prior) could allow attackers to terminate software stack processes, cause DoS, or execute arbitrary code via maliciously crafted network packets. CVE-2025-1924 is an out-of-bounds write flaw, while CVE-2025-48019, CVE-2025-48020, CVE-2025-48021 cause process termination via reachable assertions. EPSS scores are low (0.000, 1st percentile) indicating no observed exploitation attempts yet. Affects Critical Manufacturing, Energy, and Food and Agriculture sectors worldwide. Yokogawa released patch R1.08.00.
Pelco Sarix Pro 3 IP Camera Authentication Bypass (CVE-2026-1241)
Authentication bypass in Pelco Sarix Professional 3 Series IP Cameras (all models, versions 02.52 and prior) allows unauthenticated viewing of live video streams. Flaw stems from inadequate access control enforcement in web management interface. Affects multiple critical infrastructure sectors: Commercial Facilities, Defense Industrial Base, Energy, Government Facilities, Healthcare, and Transportation. Pelco released firmware version 02.53 fixing the issue.
Juniper PTX Routers Critical RCE (CVE-2026-21902)
Out-of-band security update for Junos OS Evolved patches critical remote code execution vulnerability CVE-2026-21902 affecting PTX routers. EPSS score of 0.003 (48th percentile) suggests early-stage vulnerability with limited observed exploitation attempts. Juniper released emergency patches outside normal release cycle, indicating vendor assessment of high risk.
Zyxel Critical UPnP Vulnerability (Multiple Models)
Critical vulnerability in UPnP function of multiple Zyxel device models could be exploited for remote code execution. Minimal details provided, but severity warrants immediate attention. Zyxel released patches across affected product lines.
Microsoft Vitess Database Vulnerabilities (CVE-2026-27965, CVE-2026-27969)
Two vulnerabilities in Vitess database platform published by MSRC. CVE-2026-27965 allows users with backup storage access to gain unauthorized access to production environments. CVE-2026-27969 enables writing to arbitrary file paths on restore operations. EPSS scores are extremely low (0.000, 12-13th percentile) indicating newly disclosed vulnerabilities with no observed exploitation. Both affect organizations using Vitess for MySQL horizontal scaling.
NATS Server WebSocket Pre-Auth Memory DoS (CVE-2026-27571)
NATS server vulnerable to pre-authentication memory-based denial of service via WebSockets. EPSS 0.001 (17th percentile). Affects organizations using NATS messaging system for microservices communication.
AJV JSON Validator ReDoS (CVE-2025-69873)
Another JSON Schema Validator (ajv) before version 8.18.0 vulnerable to Regular Expression Denial of Service when $data option is enabled. Attacker can inject malicious regex pattern causing catastrophic backtracking. A 31-character payload causes 44 seconds of CPU blocking, with exponential growth per additional character. Enables complete DoS with single HTTP request. EPSS 0.001 (21st percentile).
Chromium Vulnerabilities in Edge (CVE-2026-3062, CVE-2026-3063)
Microsoft Edge (Chromium-based) inherits two vulnerabilities from upstream Chromium. CVE-2026-3062 is an out-of-bounds read/write in Tint graphics component (EPSS 0.000, 7th percentile). CVE-2026-3063 is inappropriate implementation in DevTools (EPSS 0.000, 0th percentile). Both patched via automatic Chromium ingestion.
Ransomware Payment Rates Hit Record Low 28%
Chainalysis reports ransomware victim payment rate dropped to 28% in 2025, down from 62.8% in 2024 and 78.9% in 2022. Despite this, on-chain ransomware payments reached $820 million in 2025, expected to approach $900 million after attribution completes. Total attack volume surged 50% year-over-year. Median ransom payment increased 368% from $12,738 to $59,556, indicating victims pay larger amounts hoping attackers will delete stolen data. Market fragmentation: 85 active extortion groups observed in 2025 versus small number of dominant groups in prior years. United States remains most targeted country followed by Canada, Germany, UK. Initial access broker revenue held steady at $14 million (1.7% of total ransomware revenue). Average network access price declined from $1,427 in Q1 2023 to $439 in Q1 2026 due to automation, AI-assisted tooling, and oversupply from infostealer logs.
UAT-10027 Targets US Education and Healthcare with Dohdoor Backdoor
Cisco Talos identified new threat cluster UAT-10027 targeting US education and healthcare sectors since December 2025. Attack chain begins with suspected phishing leading to PowerShell script execution, downloading Windows batch script from staging server, which retrieves malicious DLL (propsys.dll or batmeter.dll). DLL uses side-loading via legitimate Windows executables (Fondue.exe, mblctr.exe, ScreenClippingHost.exe) to launch Dohdoor backdoor. Dohdoor uses DNS-over-HTTPS for C2 communications to evade DNS-based detection, hides behind Cloudflare infrastructure making traffic appear as legitimate HTTPS to trusted IPs, and unhooks system calls to bypass EDR user-mode hooks in NTDLL.dll. Next-stage payload assessed to be Cobalt Strike Beacon. No data exfiltration observed yet, but victimology pattern (education/healthcare) suggests financially motivated activity. Tactical similarities to North Korean Lazarus Group's LazarLoader noted, though targeting diverges from Lazarus' typical cryptocurrency/defense focus.
Trojanized Gaming Tools Distribute Java-Based RAT
Attackers distribute trojanized gaming utilities via browsers and chat platforms to deploy Java-based remote access trojan. Malicious downloader stages portable Java runtime and executes malicious JAR file (jd-gui.jar). Attack chain uses PowerShell and living-off-the-land binaries like cmstp.exe for stealthy execution. Evades detection by deleting initial downloader and configuring Microsoft Defender exclusions for RAT components. Persistence via scheduled task and Windows startup script (world.vbs). RAT connects to 79.110.49.15 for C2, enabling data exfiltration and additional payload delivery.
Steaelite RAT Combines Data Theft and Ransomware
New Windows RAT family Steaelite advertised on criminal forums since November 2025 as "fully undetectable" malware compatible with Windows 10 and 11. Unlike typical RATs, Steaelite bundles data theft and ransomware into single web panel, with Android ransomware module in development. Features include keylogging, client-to-victim chat, file searching, USB spreading, wallpaper modification, UAC bypass, and clipper functionality. Removes competing malware, disables Microsoft Defender or configures exclusions, and installs persistence. Capabilities span remote code execution, file management, live streaming, webcam/microphone access, process management, clipboard monitoring, password theft, installed program enumeration, location tracking, arbitrary file execution, URL opening, DDoS attacks, and VB.NET payload compilation. Enables complete double extortion from single dashboard: browse files, exfiltrate documents, harvest credentials, deploy ransomware.
CrowdStrike: eCrime Breakout Time Drops to 29 Minutes
CrowdStrike 2026 Global Threat Report shows average eCrime breakout time (initial access to lateral movement) dropped to 29 minutes, a 65% speed increase from 2024. Luna Moth (aka Chatty Spider) achieved 4-minute initial-access-to-exfiltration in law firm intrusion. Primary acceleration factors: widespread abuse of legitimate credentials allowing attackers to blend into normal network traffic and bypass traditional security controls, coupled with AI-enhanced tooling. CrowdStrike observed 89% increase in attacks by AI-enabled adversaries compared to 2024 and 42% year-over-year increase in zero-day exploitation prior to public disclosure. China-nexus adversaries: 67% of exploited vulnerabilities provided immediate system access, 40% targeted edge devices lacking comprehensive monitoring. Malware-free attacks now represent 82% of intrusions, highlighting shift toward hands-on-keyboard operations and abuse of legitimate tools and credentials.
ManoMano Data Breach Impacts 38 Million Customers
European DIY chain ManoMano notifying customers of breach caused by attackers compromising third-party customer service provider. Company learned of incident in January 2026, determined 38 million individuals affected. Compromised data includes full name, email address, phone number, and customer service communications. Unconfirmed reports suggest breach occurred at Tunis-based support provider via Zendesk compromise. No passwords accessed, no data modifications occurred. ManoMano disabled provider access, revoked credentials, strengthened access controls, and notified CNIL and ANSSI. Investigation ongoing.
Google API Keys Expose Gemini AI Data
Google API keys embedded in public JavaScript for services like Maps can now authenticate to Gemini AI assistant and access private data. Before Gemini introduction, Google Cloud API keys were not sensitive and could be exposed online without risk. Gemini API integration suddenly granted these keys dangerous new privileges. TruffleSecurity scanned November 2025 Common Crawl and found 2,800+ live Google API keys publicly exposed, including keys from major financial institutions, security companies, and Google's own infrastructure. Attackers can copy API keys from website source code, make API calls for their benefit, and generate thousands of dollars in charges per day. Google acknowledged issue, implemented proactive measures to detect and block leaked API keys attempting to access Gemini API, defaulted new AI Studio keys to Gemini-only scope, and will send proactive notifications when leaks detected.
Microsoft Expands Windows Backup Restore to Hybrid Environments
Microsoft now allows more enterprise users to restore personal settings and Microsoft Store apps from previous Windows 11 devices via Windows Backup for Organizations. First sign-in restore experience previously limited to Microsoft Entra-joined devices, now extended to hybrid-managed environments, multi-user device setups, and Windows 365 Cloud PCs. When user logs into eligible device for first time, prompt offers option to restore from previous device backup or set up as new. Feature managed through existing Windows Backup for Organizations policies, configurable via Intune or Group Policy. General availability began with Windows updates released February 24, 2026, and later.
Microsoft to Auto-Launch Copilot in Edge from Outlook Links
Microsoft announced Edge will automatically open Copilot side pane when users open links from Outlook, rolling out May 2026. Feature will "provide contextual insights and actionable suggestion chips based on email and destination content." Unclear if opt-in or opt-out. Potential concern: Copilot surfacing suggestions based on email content could violate data security policies, especially for corporate emails. Vivaldi CEO Jon von Tetzchner warns: "Considering how sensitive corporate emails can be, the last thing you want is them being snooped on by an LLM hosted who knows where. This would be highly problematic from a corporate security and privacy point of view."
CrowdStrike FalconID Brings Phishing-Resistant MFA
CrowdStrike announced general availability of FalconID, phishing-resistant FIDO2-based authentication integrated into Falcon sensor and delivered through Falcon for Mobile app. Eliminates passwords, push notifications, and one-time codes through biometric authentication bound to trusted devices and legitimate domains. Physical device required to approve access. Authentication decisions based on real-time risk signals from identity, endpoint, SaaS security, threat detections, and adversary intelligence. For legacy applications not supporting FIDO, FalconID provides secure indirect authentication. CrowdStrike also acquired SGNL to add continuous authorization layer evaluating access decisions across cloud, SaaS, and enterprise environments based on changing risk conditions.
Anthropic Refuses Pentagon Demands to Remove AI Guardrails
Anthropic CEO Dario Amodei stated company will not comply with Department of War contract demands to remove guardrails on Claude AI for unrestricted military use. Pentagon threatened to cancel contracts and penalize company if it does not comply by Friday deadline. Amodei cited two use cases outside bounds of safe deployment: mass domestic surveillance (AI can now create comprehensive picture of any person's life automatically at massive scale) and fully autonomous weapons (frontier AI systems not reliable enough, cannot exercise critical judgment of trained troops). Amodei offered to work with Pentagon on R&D to improve system reliability but offer not accepted. Sets up showdown with Secretary of War Pete Hegseth.
LLMs Generate Predictable Passwords
Research shows LLMs are bad at generating passwords with strong noticeable patterns: all passwords start with letter (usually uppercase G followed by digit 7), character choices highly uneven (L, 9, m, 2, $, # appeared in all 50 passwords, but 5 and @ only appeared once), no repeating characters within any password, avoidance of asterisk symbol (likely due to Markdown formatting conflicts). In 50 generation attempts, only 30 unique passwords produced. Most common password G7$kL9#mQ2&xP4!w repeated 18 times (36% probability versus expected 2^-100 for true 100-bit password). Problem: if AI agents operate autonomously, they will create accounts using predictable passwords. Broader issue: authenticating autonomous agents has deep unresolved problems.
Microsoft Threat Modeling Guidance for AI Applications
Microsoft Security Blog published guidance on threat modeling AI applications, acknowledging traditional threat modeling evolved around deterministic software with known code paths and predictable failure modes. AI systems (especially generative and agentic) are probabilistic, operate over highly complex input spaces, and produce different outputs across executions. Three characteristics drive shift: nondeterminism (require reasoning about ranges of behavior including rare but severe failures), instruction-following bias (models optimized to be helpful making prompt injection easier when data and instructions blended), and system expansion through tools and memory (agentic systems invoke APIs, persist state, trigger workflows autonomously allowing failures to compound). AI threat modeling must treat human-centered risks (erosion of trust, overreliance on incorrect outputs, bias reinforcement, harm from persuasive but wrong responses) as first-class concerns alongside technical and security failures. Recommends starting with assets (user safety, user trust, privacy and security of data) rather than attacks.
Post-Quantum Cryptography Migration Urgency
Security experts recommend organizations begin Post-Quantum Cryptography (PQC) migration now to protect against "Harvest Now, Decrypt Later" (HNDL) strategy where adversaries steal encrypted data today for decryption with future quantum computers. Current quantum prototypes lack scale and error-correction for complex algorithms, but cryptographically relevant quantum computers (CRQC) expected by 2030-2035 could break modern encryption in minutes. Any data requiring long-term security (trade secrets, classified designs) vulnerable because its lifespan will outlive current encryption. Migration team should consist of cryptography experts, cybersecurity experts, and managers from systems being migrated. First step: establish scope and leadership for PQC migration process.
Block Announces 40% Layoffs Citing AI Tools
Jack Dorsey's fintech company Block announced 40% staff reduction (approximately 4,000 people) blaming new "intelligence tools" that "can do more and do it better." Q4 revenue $6.25 billion (up 3.6% YoY), full-year revenue $24.2 billion with $10.36 billion gross profit. Dorsey stated "intelligence tools have changed what it means to build and run a company" and "a significantly smaller team, using the tools we're building, can do more and do it better." Stock jumped 23% in after-hours trading despite being down 80% from 2021 peak. Dorsey said single large cut preferred over "repeated rounds of cuts" that are "destructive to morale, to focus, and to the trust that customers and shareholders place in our ability to lead."
Active exploitation of network edge devices continues as dominant threat vector, with Cisco SD-WAN zero-days exploited since 2023 demonstrating persistent adversary focus on high-value infrastructure entry points. Industrial control systems face widespread vulnerability disclosure with 23 CVEs in Copeland controllers and systemic authentication flaws across EV charging platforms indicating insufficient security-by-design in operational technology. Ransomware economics shift toward fewer but higher-value payments as organizations improve defenses and refuse to pay, though attack volumes surge 50% YoY suggesting threat actors compensate through increased targeting rather than retreating.