CVE-2016-3088, CVE-2023-46604, CVE-2025-10371, CVE-2025-5873, CVE-2026-1354, CVE-2026-1731, CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20133, CVE-2026-32201, CVE-2026-34197, CVE-2026-40372, CVE-2026-5752
Get tomorrow's brief in your inbox
Today: CISA added four Cisco SD-WAN flaws to its KEV catalog with a Friday patch deadline. Apache ActiveMQ faces active exploitation targeting 6,400 exposed servers. Microsoft shipped emergency ASP.NET Core patches for a critical authentication bypass that lets attackers forge session cookies and gain SYSTEM privileges.
CISA Flags Four Cisco SD-WAN Vulnerabilities as Actively Exploited (CVE-2026-20133, CVE-2026-20128, CVE-2026-20122, CVE-2026-20127)
CISA added CVE-2026-20133 to its Known Exploited Vulnerabilities catalog on Monday, ordering federal agencies to patch Cisco Catalyst SD-WAN Manager systems by April 24. The information disclosure flaw allows unauthenticated remote attackers to read sensitive files due to insufficient file system access restrictions. CVE-2026-20133 on KEV with EPSS 0.020 (84th percentile), due April 23. CVE-2026-20128 and CVE-2026-20122 were flagged as exploited one week earlier. CVE-2026-20127, a critical authentication bypass exploited since 2023, has EPSS 0.333 (97th percentile). Over the last several years, CISA has tagged 91 Cisco vulnerabilities as exploited, six of which have been used by ransomware operations.
Apache ActiveMQ Code Injection Flaw Impacts 6,400 Servers (CVE-2026-34197)
Over 6,400 Apache ActiveMQ servers exposed online are vulnerable to CVE-2026-34197, a high-severity code injection flaw discovered by Horizon3 using Claude AI after remaining hidden for 13 years. The vulnerability allows authenticated attackers to execute arbitrary code on unpatched systems due to improper input validation. CISA added the flaw to KEV on Thursday with EPSS 0.596 (98th percentile), ordering federal agencies to patch by April 30. ShadowServer tracking shows most vulnerable systems in Asia (2,925), North America (1,409), and Europe (1,334). Two prior ActiveMQ flaws (CVE-2016-3088, CVE-2023-46604) were exploited by TellYouThePass ransomware.
Microsoft SharePoint Zero-Day Under Active Attack (CVE-2026-32201)
Over 1,300 Microsoft SharePoint servers remain unpatched against CVE-2026-32201, a spoofing vulnerability exploited as a zero-day and still under active attack. The flaw affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Successful exploitation allows unauthenticated attackers to perform network spoofing by exploiting an improper input validation weakness. CISA added the vulnerability to KEV with EPSS 0.020 (84th percentile), ordering federal agencies to patch by April 28. Fewer than 200 systems have been patched since Microsoft released security updates last week.
Microsoft ASP.NET Core Emergency Patches for Critical Privilege Escalation (CVE-2026-40372)
Microsoft released out-of-band security updates to patch CVE-2026-40372, a critical ASP.NET Core privilege escalation vulnerability in Data Protection cryptographic APIs. The flaw allows unauthenticated attackers to gain SYSTEM privileges by forging authentication cookies. Microsoft discovered the issue after user reports of decryption failures following .NET 10.0.6 installation. A regression in Microsoft.AspNetCore.DataProtection 10.0.0-10.0.6 NuGet packages causes the managed authenticated encryptor to compute HMAC validation over wrong bytes and discard the hash, allowing attackers to forge payloads that pass authenticity checks and decrypt protected data in auth cookies, antiforgery tokens, TempData, and OIDC state.
SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
Check Point researchers discovered a SystemBC command-and-control server linked to The Gentlemen ransomware-as-a-service operation, revealing a botnet of over 1,570 compromised victims. SystemBC establishes SOCKS5 network tunnels and connects to its C2 using custom RC4-encrypted protocol, downloading and executing additional malware with payloads written to disk or injected directly into memory. The Gentlemen has claimed over 320 victims on its data leak site since emerging in July 2025, targeting Windows, Linux, NAS, and BSD systems with a Go-based locker. The group uses Group Policy Objects for domain-wide compromise, deploys SystemBC for data exfiltration and remote access, and disables Windows Defender by pushing PowerShell scripts during lateral movement.
Three Former Ransomware Negotiators Plead Guilty to BlackCat Attacks
Angelo Martino, a former ransomware negotiator at DigitalMint, pleaded guilty to conspiring with BlackCat (ALPHV) ransomware operators to extort U.S. companies. While working as a negotiator for five victims, Martino shared confidential information about victims' negotiation positions and insurance policy limits with BlackCat attackers, helping maximize ransom demands. He also deployed ransomware alongside accomplices Ryan Goldberg and Kevin Tyler Martin between April 2023 and November 2023. Their victims paid ransoms totaling over $75 million, including a nonprofit that paid $26.8 million and a financial services firm that paid $25.7 million. Law enforcement seized $10 million in assets from Martino, including vehicles, digital currency, a food truck, and a luxury fishing boat.
Former FBI Official Urges Terrorism Designations, Homicide Charges for Hospital Ransomware Attacks
Former FBI cyber division chief Cynthia Kaiser testified before a House Homeland Security Committee hearing, urging Congress to investigate terrorism designations for ransomware groups targeting hospitals and critical infrastructure. Kaiser called for federal prosecutors to evaluate felony homicide charges when ransomware attacks on healthcare facilities cause patient deaths. A 2023 University of Minnesota study found hospital mortality rates increased by 20% during and after ransomware attacks, with at least 47 deaths attributable to hospital ransomware between 2016 and 2021. FBI statistics show healthcare ransomware incidents doubled from 238 in 2024 to 460 in 2025, making it the top targeted sector.
Surge in Bomgar RMM Exploitation Demonstrates Supply Chain Risk (CVE-2026-1731)
A critical remote code execution flaw in Bomgar remote monitoring and management tool is being exploited to spread ransomware and compromise supply chains. CVE-2026-1731 is on CISA KEV (ransomware-linked) with EPSS 0.815 (99th percentile), due February 16. The vulnerability allows attackers to leverage compromised MSP access to deploy ransomware across multiple client environments simultaneously.
Scattered Spider Member 'Tylerb' Pleads Guilty
Tyler Robert Buchanan, 24, a British national and senior Scattered Spider member, pleaded guilty to wire fraud conspiracy and aggravated identity theft. Buchanan admitted his role in SMS-based phishing attacks in summer 2022 that led to intrusions at Twilio, LastPass, DoorDash, and Mailchimp. The group used stolen data to conduct SIM-swapping attacks that siphoned at least $8 million in cryptocurrency from individual victims. FBI investigators tied Buchanan to phishing domains after discovering the same username and email address used to register numerous phishing sites. Buchanan fled the UK in February 2023 after a rival gang invaded his home and assaulted his mother, was arrested in Spain in June 2024, and extradited to the U.S. in April 2025. He faces over 20 years in prison.
Cisco Phishing and MFA Exploitation Trends (2025)
Cisco Talos reported that phishing attacks targeted MFA workflows in 40% of 2025 incidents, with cascaded phishing campaigns leveraging compromised accounts to create specialized attacks within networks and against trusted partners. IT-focused phishing keywords became more technical, using words like "tampering," "domain," "configuration," and "token." Attackers abused Microsoft 365 Direct Send to spoof internal email addresses and deliver lures from inside organizations without compromising real accounts. Nearly one-third of 2025 MFA spray attacks targeted identity and access management applications, while device compromise attacks surged 178%. Higher education was the most targeted sector for device compromise due to diverse unmanaged devices, poorly patched systems, and low device verification policies.
Microsoft: Detection Strategies Against Infiltrating IT Workers (Jasper Sleet)
Microsoft Threat Intelligence published guidance on detecting fraudulent remote IT workers (Jasper Sleet, North Korea-aligned) who pose as legitimate hires using stolen or fabricated identities and AI-assisted deception to gain trusted access. Threat actors systematically survey career sites and external hiring portals to identify technical roles, use generative AI to analyze job postings and construct tailored fake digital personas, and submit highly convincing applications. Microsoft observed Jasper Sleet accessing Workday Recruiting Web Service endpoints from known actor infrastructure, indicating discovery of open roles and recruitment workflows. Organizations using Workday can monitor and detect fraudulent activity in pre-recruitment and post-recruitment phases through Microsoft Defender for Cloud Apps.
Windows Defender Exploits Turn Built-in Security into Attacker Tool
Three proof-of-concept exploits are being used in active attacks against Microsoft's Windows Defender; two remain unpatched. The exploits allow attackers to weaponize the built-in security platform for malicious purposes.
Vercel Breach Linked to Employee Account at Context.ai
A Context.ai employee was infected with an infostealer, allowing hackers (ShinyHunters group) to access the AI company's systems and pivot to Vercel's Google Workspace environment. Attackers used the access to steal credentials for Vercel's cloud infrastructure. Stolen data is being auctioned online.
France's ID Agency (ANTS) Breached
Hackers breached ANTS, the French government agency managing identity documents, driving licenses, and vehicle registrations. The hacker claims to have stolen 12.7 million data rows and is selling ANTS data on underground forums. The French government confirmed the breach on Monday.
Mustang Panda's New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles
Acronis researchers discovered a new LOTUSLITE backdoor variant attributed to Chinese nation-state group Mustang Panda. The backdoor communicates with dynamic DNS-based C2 over HTTPS and supports remote shell access, file operations, and session management. The latest variant targets India's banking sector using lures masquerading as HDFC Bank software and South Korean policy circles through spoofed Gmail accounts and Google Drive staging. The attack begins with a Compiled HTML (CHM) file embedding a legitimate executable and rogue DLL, using DLL side-loading to extract and run the LOTUSLITE malware.
Siemens Industrial Control Systems (Multiple Advisories)
CISA published 11 Siemens advisories covering vulnerabilities in SCALANCE W-700 wireless access points, SenseLive X3050 (11 CVEs allowing complete device takeover), Silex Technology SD-330AC and AMC Manager (13 CVEs including buffer overflows), Analytics Toolkit (improper certificate validation), SINEC NMS (authentication bypass), RUGGEDCOM CROSSBOW (privilege escalation), TPM 2.0 implementations (out-of-bounds read), Industrial Edge Management (authorization bypass allowing remote device access), and RUGGEDCOM Station Access Controller (SQLite memory corruption).
Hardy Barth Salia EV Charge Controller (CVE-2025-5873, CVE-2025-10371)
Two critical vulnerabilities in Hardy Barth Salia EV charge controller firmware 2.3.81 allow unrestricted file upload via /firmware.php and /api.php endpoints. Exploitation could crash the device or allow remote code execution. Hardy Barth did not respond to CISA coordination requests. No patches available.
Zero Motorcycles Bluetooth Pairing Vulnerability (CVE-2026-1354)
Zero Motorcycles firmware versions 44 and prior enable attackers to forcibly pair a device with motorcycles via Bluetooth. Once paired, attackers can use over-the-air firmware updating to upload malicious firmware. The motorcycle must be in Bluetooth pairing mode and the attacker must be in proximity and understand the full pairing process.
Cohere AI Terrarium Sandbox Escape (CVE-2026-5752)
A critical vulnerability (CVSS 9.3) in Cohere AI's Terrarium Python sandbox allows arbitrary code execution with root privileges via JavaScript prototype chain traversal in the Pyodide WebAssembly environment. The sandbox fails to prevent access to parent or global object prototypes, allowing sandboxed code to manipulate objects in the host environment. Successful exploitation enables container escape, unauthorized file access, network service reach, and potential privilege escalation. The project is no longer actively maintained and the vulnerability is unlikely to be patched.
Progress MOVEit WAF, LoadMaster Vulnerabilities
Progress patched multiple vulnerabilities in MOVEit WAF and LoadMaster that could be exploited for remote code execution, OS command injection, and WAF detection bypass.
Google Antigravity Remote Code Execution
Researchers discovered a remote code execution vulnerability in Google Antigravity. Cybercriminals are using its reputation to deliver malware.
Today's stories highlight the convergence of three persistent threats: actively exploited vulnerabilities in enterprise infrastructure (Cisco SD-WAN, Apache ActiveMQ, SharePoint), the professionalization of ransomware operations through insider threats (DigitalMint negotiators betraying clients), and the continued targeting of identity systems and MFA workflows as the primary attack vector. The calls for terrorism designations and homicide charges for hospital ransomware attacks reflect the escalating real-world impact of cyber operations beyond data loss and financial damage.