CVE-2026-20127
Get tomorrow's brief in your inbox
Today: FBI wiretapping systems breached in suspected China-linked intrusion. White House executive order prioritizes cybercrime crackdown and signals private sector hack-back operations. Chrome extensions turn malicious after ownership transfer, injecting code and stealing credentials. Cisco SD-WAN vulnerability CVE-2026-20127 under widespread exploitation.
Cisco Catalyst SD-WAN Vulnerability Under Widespread Exploitation (CVE-2026-20127)
CVE-2026-20127 is now seeing exploitation attempts from numerous unique IP addresses according to WatchTowr. This vulnerability was added to CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of February 27, 2026, and has an EPSS score of 0.026 (85th percentile). The window for patching has passed, and active exploitation is confirmed.
FBI Investigating Breach of Wiretapping Systems
The FBI confirmed it is investigating suspicious activity on its networks affecting systems related to wiretapping and foreign intelligence surveillance warrants. CNN reported the breach involves the network managing legal process for pen register and trap and trace surveillance. The compromised system is unclassified but contains law enforcement sensitive information including personally identifiable information of investigation subjects. The FBI notified Congress on February 17 after detecting abnormal log activity. The breach follows China's Salt Typhoon compromising telecommunications wiretapping systems and stealing data on nearly every American.
Chrome Extensions Turn Malicious After Ownership Transfer
Two Chrome extensions, QuickLens (7,000 users) and ShotBird (800 users), turned malicious after ownership changes. Both were originally developed by BuildMelon before being transferred to new owners in February 2026. The malicious updates strip security headers (X-Frame-Options) from HTTP responses, bypass CSP protections, fingerprint users, and poll external servers every five minutes to receive JavaScript payloads. The code is stored in local storage and executed on every page load via a 1x1 GIF image element, making static analysis ineffective. ShotBird displays fake Chrome update prompts using ClickFix tactics to trigger PowerShell downloads of googleupdate.exe, which harvests credentials, form data, and browser history.
Chinese Threat Actor Targets Asian Critical Infrastructure (CL-UNK-1068)
Palo Alto Networks Unit 42 identified a previously undocumented Chinese threat group (CL-UNK-1068) targeting aviation, energy, government, law enforcement, pharmaceutical, technology, and telecommunications sectors in South, Southeast, and East Asia. The campaign uses web server exploits to deliver web shells (Godzilla, ANTSWORD), Xnote Linux backdoor, and Fast Reverse Proxy (FRP) for persistent access. Attack chains start with web server exploitation, followed by lateral movement and credential theft using Mimikatz, LsaRecorder, DumpItForLinux, Volatility Framework, and SQL Server Management Studio password export tools. The group exfiltrates data by Base64-encoding WinRAR archives and printing them through web shells to avoid file uploads. Python executables are used for DLL side-loading attacks.
AI Assistants Expose Organizations to New Insider Threats (OpenClaw)
Researchers found hundreds of OpenClaw AI agent installations with misconfigured web interfaces exposed to the Internet. These exposed instances allow external parties to read complete configuration files including API keys, bot tokens, OAuth secrets, and signing keys. With this access, attackers can impersonate operators, inject messages into conversations, exfiltrate data through existing integrations, pull complete conversation histories, and manipulate the agent's perception layer. Microsoft reports North Korea's Coral Sleet is using development platforms to rapidly create and manage attack infrastructure at scale using AI agents for reconnaissance, network scanning, and natural language infrastructure management.
Europol Dismantles Tycoon2FA Phishing Platform and LeakBase
Europol announced the takedown of Tycoon2FA, the world's dominant phishing-as-a-service platform with 2,000 active monthly subscribers paying $200-$300/month since 2023. By mid-2025, Tycoon2FA was responsible for 62% of all phishing attempts blocked by Microsoft. The platform provided ready-made phishing kits for Microsoft 365 and Google Workspace with session cookie theft and MFA bypass capabilities. The operation also dismantled LeakBase, a stolen data marketplace with 142,000 registered users. Authorities executed over 100 takedown actions on March 3-4, including measures against 37 of LeakBase's most active users. All users are now under investigation.
White House Executive Order Prioritizes Cybercrime and Signals Hack-Back Operations
President Trump signed an executive order directing federal agencies to prioritize investigations of cyber fraud, scam schemes, ransomware, phishing, and sextortion. The order directs the Attorney General to establish a victim restoration program for seized assets and orders the State Department to pressure foreign governments sheltering cybercrime operations. The National Coordination Center was instructed to identify the largest criminal organizations and "eliminate barriers to dismantling" them. The simultaneously-released National Cyber Strategy states "We will unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities" and "We will establish a new level of relationship between the public and private sectors to defend America in peace and war." This language signals authorization for private sector offensive cyber operations against cybercrime infrastructure.
Russian Campaign Targets Signal and WhatsApp Accounts
Dutch intelligence agencies (AIVD and MIVD) warned of a large-scale Russian campaign targeting Signal and WhatsApp accounts of government officials, journalists, and military personnel globally. Attackers approach targets via chat and persuade them to share security verification codes or PINs, giving full account access without breaking encryption. Some attackers impersonate Signal support bots. Another technique abuses Signal's linked devices feature to mirror messages in real time. The campaign has successfully compromised Dutch government employees. Indicators of compromise include contacts appearing twice in contact lists or numbers showing as "deleted account."
Threat Actors Abuse .arpa DNS and IPv6 for Phishing
Infoblox discovered a phishing campaign abusing the .arpa DNS infrastructure domain and IPv6 reverse DNS to evade domain reputation checks and email gateways. Attackers obtain IPv6 address blocks via tunneling services (Hurricane Electric, Cloudflare), generate reverse DNS hostnames from the IPv6 range, and configure A records (instead of the expected PTR records) pointing to phishing infrastructure. Because ip6.arpa is a special-use infrastructure domain with good reputation, the phishing domains bypass traditional security filters. The campaign exploits DNS management platforms that allow record types beyond PTR in reverse DNS zones.
ClickFix Attacks Evolve to Use Windows Terminal
Attackers are modifying ClickFix social engineering attacks to instruct victims to paste malicious commands into Windows Terminal instead of the Run dialog, evading detection. Fake CAPTCHA pages and fake update prompts now target the newer Windows Terminal interface. A related campaign called InstallFix clones AI tool installation webpages and replaces legitimate commands with malicious PowerShell.
AI-Powered Vulnerability Discovery Finds Decades-Old Bugs
Microsoft Azure CTO Mark Russinovich demonstrated Claude Opus 4.6 decompiling 1986 Apple II machine code and finding security vulnerabilities. Anthropic's Red Team reports the model found high-severity bugs in well-tested codebases that had accumulated millions of hours of fuzzing, including vulnerabilities that went undetected for decades. Anthropic found 14 high-severity bugs in Mozilla Firefox. The company warned this creates a time-sensitive window for defenders to scan and patch code before attackers leverage the same capabilities. However, AI also generates high volumes of false positives, burdening open source maintainers.
New Wi-Fi Attack Enables Full Machine-in-the-Middle (AirSnitch)
Researchers disclosed AirSnitch, a new Wi-Fi attack exploiting cross-layer identity desynchronization between Layers 1 and 2. Unlike previous attacks, AirSnitch achieves full bidirectional machine-in-the-middle capability, allowing attackers to view and modify data in transit. The attack exploits core Wi-Fi features and the failure to bind client identity across layers and network names (SSIDs).
EU Court Adviser: Banks Must Immediately Refund Phishing Victims
EU Court of Justice Advocate General Athanasios Rantos issued an opinion stating that under the Payment Services Directive (PSD2), banks must immediately refund unauthorized transactions even when caused by customer negligence, unless the bank has reasonable grounds to suspect customer fraud. Banks can later seek recovery if they prove gross negligence or intentional security failures. The opinion is not a binding ruling but indicates likely direction for EU courts.
Today's brief is dominated by supply chain trust failures (Chrome extensions changing hands, AI agents exposed by misconfiguration) and evasion techniques that abuse trusted infrastructure (.arpa domains, Windows Terminal instead of Run dialog). The FBI wiretapping breach and Dutch warnings about Signal/WhatsApp account takeovers demonstrate that encrypted channels are only as secure as the account credentials protecting them. The White House's explicit language about private sector offensive operations signals a policy shift that may complicate legal and ethical boundaries for defenders. Cisco's SD-WAN exploitation highlights the gap between CISA KEV deadlines and real-world patch deployment timelines.