Cisco confirmed active exploitation of two vulnerabilities in Catalyst SD‑WAN Manager (CVE‑2026‑20128 and CVE‑2026‑20122), originally patched in February 2025. The company also released fixes across its firewall portfolio, underscoring that internet‑facing edge gear remains a prime target. Organizations should accelerate patch rollouts and review vManage access, credentials, and logging for signs of misuse.
Source: Help Net Security
Iran‑linked MuddyWater embedded in US bank, airport, and software firm networks
Researchers observed an Iranian APT with ties to the Ministry of Intelligence maintaining persistence inside multiple US organizations since early February, including a bank, an airport, and a software company. The activity indicates ongoing pre‑positioning and living‑off‑the‑land tactics, raising the risk of follow‑on operations. Security teams should hunt for atypical PowerShell/WMI use, rogue scheduled tasks, and suspicious outbound connections from edge systems.
Source: SecurityWeek
China‑nexus UAT‑9244 hits South American telcos with three new implants
Cisco Talos attributed a telecom‑focused intrusion set in South America to UAT‑9244, assessed as closely associated with Famous Sparrow. The group deployed three previously unreported implants across Windows, Linux, and edge devices, highlighting continued interest in telecom infrastructure for access and collection. Telcos and ISPs should harden management interfaces, segment out‑of‑band networks, and baseline device telemetry where EDR coverage is sparse.
Source: Cisco Talos
Global takedown disrupts ‘Tycoon 2FA’ phishing‑as‑a‑service that bypassed MFA
Law enforcement and industry partners dismantled Tycoon 2FA, a major phishing‑as‑a‑service platform that supplied reverse‑proxy kits to intercept and replay MFA tokens. Active since 2023, Tycoon 2FA was implicated in a large share of blocked phishing attempts, including against hospitals and schools. Expect successor services; prioritize phishing‑resistant MFA (FIDO2/WebAuthn), conditional access, and continuous session risk assessment.
Source: Help Net Security
LeakBase credential‑trading forum seized; 142,000 users impacted
Authorities seized LeakBase, an open‑web hub for selling breached databases and stealer logs used in account takeover and fraud. Active since 2021 and counting over 142,000 users by late 2025, the forum’s takedown will temporarily disrupt stealer‑log monetization. Defenders should still assume broad credential exposure: enforce SSO and MFA, accelerate password rotations, and monitor for reused passwords and suspicious logins.
Source: Help Net Security
Google: 90 zero‑days exploited in 2025 as attackers shift hard toward enterprise tech
Google’s Threat Intelligence Group tracked 90 in‑the‑wild zero‑days last year, with a record 48% targeting enterprise technologies like security and networking appliances. Commercial spyware vendors surpassed traditional state actors in attributed zero‑day use, while PRC‑nexus groups remained the most prolific among nation‑states. The findings reinforce that edge devices lacking EDR are prime entry points; prioritize configuration hardening, rapid patch paths, and continuous anomaly detection around these assets.
Source: Google Threat Intelligence (Cloud)
CISA adds Apple WebKit, Rockwell Logix, and Hikvision camera flaws to KEV catalog
CISA added actively exploited vulnerabilities affecting Apple WebKit, Rockwell Automation Logix environments, and Hikvision IP cameras to its Known Exploited Vulnerabilities list. The inclusion signals ongoing attacker focus on consumer cameras and industrial control gear that are often exposed and under‑monitored. Agencies and enterprises should patch or mitigate per vendor guidance, restrict internet exposure, and enforce strict access controls on OT and physical security devices.
Source: Security Affairs
You May Also Be Interested In...
FBI is probing ‘suspicious’ breach into bureau networks
FreeScout zero‑click RCE via email (CVE‑2026‑28289)
Microsoft exposes ClickFix campaign abusing Windows Terminal to deploy Lumma Stealer