NIST is moving the National Vulnerability Database to a risk-based model, fully enriching only CVEs in CISA’s KEV catalog, affecting federal software, or deemed “critical.” Driven by a 263% surge in CVE submissions since 2020, the shift means many entries will lack timely analysis—forcing security teams to lean more on vendor advisories, SBOMs, EPSS, and third‑party intel for triage and patching prioritization.
Source: SecurityWeek
Cisco patches critical Webex and Identity Services flaws enabling remote code execution and impersonation
Cisco fixed multiple critical vulnerabilities in Webex and Identity Services Engine (ISE) that could let remote attackers impersonate users or execute arbitrary commands on the underlying OS. Given the prevalence of both products in enterprise environments, admins should expedite updates, audit SSO and admin access, and monitor for anomalous service activity.
Source: SecurityWeek
Fortinet fixes critical FortiSandbox bugs exploitable without authentication
Two critical FortiSandbox vulnerabilities (CVE‑2026‑39813, CVE‑2026‑39808) allow unauthenticated attackers to bypass authentication and run unauthorized code or commands via crafted HTTP requests. Because FortiSandbox verdicts feed other Fortinet controls, organizations should patch immediately, restrict management exposure, and review sandbox connectivity for abuse.
Source: Help Net Security
Active exploitation: Apache ActiveMQ CVE-2026-34197 added to CISA KEV
A high‑severity RCE in Apache ActiveMQ Classic (CVE‑2026‑34197) is being exploited in the wild and is now on CISA’s KEV list. Organizations should upgrade to patched versions without delay, isolate brokers from untrusted networks, and hunt for suspicious broker traffic and post‑exploitation activity.
Source: SecurityWeek
Nginx UI flaw (CVE‑2026‑33032) under active attack enables full server takeover via MCP
A missing authentication issue in Nginx UI’s Model Context Protocol (MCP) interface (CVSS 9.8) lets unauthenticated attackers issue privileged actions against managed Nginx servers—even in default IP allowlist configurations. Rapid7 reports exploitation in the wild; update to the latest release, lock down the management plane, and restrict network access immediately.
Source: Rapid7
Microsoft: North Korea’s “Sapphire Sleet” targets macOS with social engineering and fake updates
Microsoft details a Sapphire Sleet campaign abusing user‑driven execution on macOS, including lures that trick targets into running a fake Zoom update to steal credentials, crypto, and sensitive data. Defenders should harden macOS Gatekeeper controls, block untrusted installers, and deploy EDR capable of detecting script‑based and user‑assisted intrusions.
Source: Microsoft Security Blog
AI code agents from Anthropic, Google, and Microsoft susceptible to “comment” prompt injection
Research shows Claude Code, Gemini CLI, and GitHub Copilot Agents can be steered via malicious code comments, a “Comment and Control” technique that turns routine reviews into supply‑chain risk. Teams should sandbox tool actions, restrict agent permissions, scan repositories for malicious prompts, and validate agent‑proposed changes with strict policy gates.
Source: SecurityWeek
You May Also Be Interested In...
53 DDoS Domains Taken Down by Law Enforcement