Authorities moved against the Aisuru and Kimwolf DDoS botnets, also targeting the lesser-known JackSkid and Mossad networks in a coordinated international operation. The takedown aims to blunt record-scale DDoS activity sourced from millions of compromised IoT devices, though operators may attempt to rebuild quickly.
Source: SecurityWeek
Interlock exploited Cisco FMC zero-day 36 days before disclosure (CVE-2026-20131)
Amazon’s MadPot honeypot data indicates the Interlock ransomware gang weaponized a critical Cisco Secure Firewall Management Center flaw more than five weeks before Cisco released a patch. Organizations should urgently apply updates, hunt for signs of exploitation dating back to late January, and segment management planes.
Source: Help Net Security
Trivy supply-chain compromise spawns self-spreading “CanisterWorm” across npm
Attackers who previously hijacked Trivy GitHub Actions to steal CI/CD secrets are suspected of launching follow-on attacks, compromising 47 npm packages with a novel self-propagating worm. The campaign underscores cascading software supply-chain risk; rotate tokens, audit workflows for “aquasecurity/trivy-action” and “setup-trivy,” and pin trusted versions.
Source: The Hacker News
Langflow RCE exploited within 20 hours of disclosure (CVE-2026-33017)
A critical auth-bypass and code-injection bug in Langflow allowed unauthenticated remote code execution, with in-the-wild exploitation observed less than a day after public release. AI app teams should patch immediately, restrict public access to flows, and review server logs for suspicious POSTs to /api/v1 endpoints.
Source: SecurityWeek
Unpatched ScreenConnect servers remain hijack-prone (CVE-2026-3564)
ConnectWise fixed a critical flaw that abuses ASP.NET machine keys to forge authentication and seize ScreenConnect sessions, but many instances are still exposed. MSPs and IT teams should update urgently, rotate keys, and reduce internet exposure for remote-access tooling to curb mass exploitation risk.
Source: Help Net Security
Ubiquiti UniFi bug poses account takeover risk; patch now
A maximum-severity vulnerability in the UniFi Network Application could enable account compromise for administrators managing fleets of networking devices. While no in-the-wild exploitation is reported, Ubiquiti customers should update promptly and enforce MFA to prevent lateral movement from controller compromise.
Source: CyberScoop
US links Handala to Iran’s government, seizes hacktivist leak sites
US officials confirmed the pro-Palestinian persona “Handala” is operated by Iran’s Ministry of Intelligence and Security, seizing multiple domains used for cyber-enabled psychological operations. The action follows the destructive attack on Stryker and highlights the growing use of hacktivist façades by state actors.
Source: SecurityWeek
You May Also Be Interested In...
Google adds 24-hour delay for unverified Android sideloading to curb scamsThousands of Magento sites defaced in ongoing campaign
Fake “job brief” on Google Forms drops PureHVNC for full device control