CVE-2022-20775, CVE-2024-28986, CVE-2025-40536, CVE-2025-40552, CVE-2025-40553, CVE-2025-40554, CVE-2025-49113, CVE-2025-59536, CVE-2025-68461, CVE-2026-0628, CVE-2026-20127, CVE-2026-21509, CVE-2026-21513
Domains:
wellnesscaremed[.]com, 67[.]63
IP Addresses:
127.0.0.1
Get tomorrow's brief in your inbox
Today: A CVSS 10 authentication bypass in Cisco SD-WAN (CVE-2026-20127) has been exploited since 2023, with CISA's emergency directive deadline already past - patch immediately if you haven't. APT28 was tied to an MSHTML zero-day (CVE-2026-21513) before its February Patch Tuesday fix; the CISA KEV deadline is tomorrow (March 3). Roundcube webmail is under active exploitation via two KEV-listed bugs with a March 13 deadline, and SolarWinds Web Help Desk is exposed to a pre-auth RCE chain across multiple KEV entries.
ShinyHunters Breaches Wynn Resorts; Qilin Targets NYC Transit Union; UFP Technologies Hit
Multiple high-profile incidents surfaced this week. ShinyHunters claimed access to Wynn Resorts employee data - HR records, contact details, and employment history for current and former staff - with the company confirming access occurred but reporting no operational disruption. UFP Technologies, a medical device manufacturer, disclosed a cyberattack that resulted in data exfiltration, data wiping, and disruptions to shipping and labeling workflows. Qilin ransomware listed Transport Workers Union of America Local 100 on its leak site, putting personal data for roughly 67,000 NYC transit union members at risk. European home improvement marketplace ManoMano also disclosed a breach tied to a third-party customer support portal, exposing customer names, email addresses, phone numbers, and support ticket details (passwords and payment data were not affected).
Cisco SD-WAN Authentication Bypass CVE-2026-20127 (CVSS 10, KEV Deadline Passed)
CVE-2026-20127 is a CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN Controller and Manager. An unauthenticated remote attacker can bypass authentication, gain admin privileges, add rogue SD-WAN peers, and chain to CVE-2022-20775 for root access on controllers. Cisco tracks the exploitation cluster as UAT-8616, described as a highly sophisticated actor. Active exploitation has been ongoing since at least 2023. CISA issued an emergency directive with a remediation deadline of February 27 - that deadline has passed. The Australian Cyber Security Centre reported the vulnerability to Cisco.
APT28 Exploited MSHTML Zero-Day Before February Patch Tuesday (CVE-2026-21513, KEV Deadline Tomorrow)
CVE-2026-21513 (CVSS 8.8) is an MSHTML security feature bypass patched in February 2026 Patch Tuesday. Akamai identified it was exploited as a zero-day, linked to APT28 infrastructure. Attackers deliver crafted LNK files that manipulate browser and Windows Shell handling to bypass Mark-of-the-Web and Internet Explorer Enhanced Security Configuration, then execute code via ShellExecuteExW outside the browser sandbox. The malicious LNK communicates with wellnesscaremed[.]com, an APT28-attributed domain. The attack uses nested iframes and multiple DOM contexts to manipulate trust boundaries. A related Microsoft Office flaw (CVE-2026-21509, CVSS 7.8) was exploited in the same campaign. CISA KEV deadline for CVE-2026-21513 is March 3 - tomorrow.
Roundcube Webmail Actively Exploited - Two KEV Entries (Deadline March 13)
CVE-2025-49113 is a post-authentication remote code execution flaw in Roundcube Webmail (EPSS 90th percentile, CISA KEV deadline March 13). CVE-2025-68461 is an unauthenticated cross-site scripting flaw in the same product (CISA KEV deadline March 13). Both are confirmed exploited in the wild, including against cPanel-hosted Roundcube deployments. Widely deployed on-premises instances are the primary exposure.
SolarWinds Web Help Desk Pre-Auth RCE Chain (Multiple KEV Entries)
Researchers disclosed a pre-authentication RCE chain in SolarWinds Web Help Desk. CVE-2025-40552 (EPSS 90th percentile) and CVE-2025-40554 (EPSS 91st percentile) are authentication bypass flaws; CVE-2025-40553 (EPSS 94th percentile) is a deserialization RCE. Chained together, an attacker with network access to an exposed help desk server achieves full takeover without credentials. CVE-2025-40536 and CVE-2024-28986 (EPSS 99th percentile) are also part of the detection and exploitation surface, both previously KEV-listed.
North Korea's Famous Chollima Publishes 26 Malicious npm Packages (StegaBin Campaign)
The North Korean threat cluster Famous Chollima (Contagious Interview campaign) published 26 malicious npm packages that use text steganography to conceal C2 addresses within benign-looking Pastebin essays. The packages install a credential stealer and RAT targeting Windows, macOS, and Linux. Capabilities include VS Code persistence via a malicious tasks.json file, keylogging, clipboard theft, browser credential harvesting, TruffleHog secret scanning, and SSH key exfiltration. The RAT connects to 103.106.67[.]63:1244. C2 infrastructure is hosted on Vercel. Package names include argonist, bcryptance, bee-quarl, bubble-core, corstoken, daytonjs, ether-lint, expressjs-lint, fastify-lint, formmiderable, hapi-lint, and 15 others.
OpenClaw ClawJacked: Malicious Websites Could Hijack Local AI Agent
OpenClaw, a popular self-hosted AI agent platform, had a vulnerability where malicious websites could open a WebSocket connection to the local OpenClaw gateway (127.0.0.1), bypass CORS protections, and brute-force the management password at hundreds of guesses per second with no rate limiting on loopback connections. After gaining access, attackers could register as a trusted device and execute arbitrary commands across all connected nodes - including exfiltrating files, reading message histories, and stealing credentials. The fix is in version 2026.2.26, released February 26.
UNC2814 GRIDTIDE: China-Nexus Espionage Group Hit 53 Organizations in 42 Countries
Google disrupted the infrastructure of UNC2814, a China-linked espionage group that breached at least 53 organizations across 42 countries. The group's GRIDTIDE backdoor abuses the Google Sheets API as a C2 channel to blend with legitimate traffic, enabling data exfiltration and remote shell execution. Primary targets are international government agencies and telecommunications organizations across Africa, Asia, and the Americas. The group is described as prolific and elusive.
UK NCSC Warning: Elevated Iranian Cyber Threat; SIM-Swap Scams Follow Dubai Strikes
The UK NCSC issued an advisory warning British organizations of heightened Iranian cyberattack risk tied to escalating Middle East conflict. Despite Iran's near-total internet blackout (connectivity at approximately 1 percent of normal levels following US and Israeli strikes), state-sponsored groups are assessed to retain offensive cyber capability. The warning is primarily for organizations with presence or supply chains in the Middle East. Separately, opportunistic criminals in Dubai launched SIM-swap campaigns against civilians within hours of missile strikes, impersonating a fictitious "Dubai Crisis Management" department to harvest UAE Pass credentials and Emirates IDs for mobile banking fraud.
Windows Server 2016 Approaching End of Support - 20 Percent of Servers Still Running It
Lansweeper data shows 20.3 percent of monitored servers are still running Windows Server 2016, which Microsoft has announced is approaching end of support. Migration barriers are higher for server workloads than desktops due to service dependencies and downtime coordination. Windows 11 has crossed 72.57 percent of desktop market share; Windows 10 remains at 26.45 percent. Organizations on Windows 10 Extended Security Updates (ESU) are paying additional cost for continued patches.
Anthropic Claude Code RCE via Malicious Project Configurations (CVE-2025-59536)
Check Point Research disclosed vulnerabilities in Anthropic's Claude Code allowing attackers to achieve remote code execution and steal API credentials through malicious project configurations. Compromised API keys provide access to shared Workspaces, enabling file access and tampering. Anthropic patched the issues, including CVE-2025-59536. Development teams using Claude Code should confirm they are on the latest version.
Chrome CVE-2026-0628: Malicious Extensions Could Hijack Gemini AI Panel (Patched)
CVE-2026-0628 (CVSS 8.8) in Google Chrome allowed a malicious extension with basic permissions to inject JavaScript into Chrome's Gemini AI side panel via the declarativeNetRequest API, enabling privilege escalation, camera and microphone access without consent, screenshot capture, and local file access. Patched in Chrome 143.0.7499.192 for Windows/Mac in early January 2026. No evidence of in-the-wild exploitation. Discovered by Palo Alto Networks Unit 42.
LLMs Can Deanonymize Online Users with High Precision
New research demonstrates that LLM agents can identify anonymous online users from posts on Hacker News, Reddit, LinkedIn, and anonymized interview transcripts. From a handful of comments, the system infers location, occupation, and interests, then searches the web to link identities across platforms. The technique scales to tens of thousands of candidates. This has direct implications for threat actor attribution, employee OPSEC policies, and assumptions about data anonymization in incident response contexts.
Google Developing Merkle Tree Certificates for Quantum-Resistant HTTPS
Google is developing Merkle Tree Certificates (MTCs) as the next-generation HTTPS certificate infrastructure, designed to support post-quantum cryptography without the bandwidth overhead of traditional X.509 certificate chains. A Certification Authority signs a single Tree Head representing millions of certificates; browsers verify inclusion via lightweight proofs. Full rollout via the Chrome Quantum-Resistant Root Store is targeted for Q3 2027. No immediate action required, but organizations managing long-lived PKI infrastructure should monitor this standard as post-quantum TLS timelines solidify.
Wireshark 4.6.4 Released
Wireshark 4.6.4 fixes 3 vulnerabilities and 15 bugs. Update if Wireshark is deployed in your security operations or analyst workstations.
Google API Keys Usable Against Gemini Endpoints
Research found that Google Cloud API keys, normally used as project identifiers for billing, can be abused to authenticate to sensitive Gemini endpoints and access private data when users enable certain API scopes. Review your Google Cloud API key scopes and restrict keys to minimum necessary permissions.
Nation-state actors continue exploiting authentication bypass vulnerabilities in network and web infrastructure for months or years before public disclosure - Cisco SD-WAN (exploited since 2023), Roundcube (active in the wild), and SolarWinds Web Help Desk all represent cases where the patching window has been compressed to near-zero once KEV entries appear. AI platforms and browser integrations are a consistently expanding attack surface this week, with OpenClaw, Chrome's Gemini panel, and Claude Code all seeing significant vulnerability disclosures - reflecting how quickly new tooling outpaces security review. North Korean supply chain campaigns against developers remain persistent, with this npm package set using steganography for C2 concealment as a new evasion layer on top of their established Contagious Interview playbook.