Attackers are exploiting a privilege escalation 0-day in Cisco Catalyst SD-WAN Manager that can lead to arbitrary command execution as root. Cisco says exploitation requires netadmin privileges or chaining from CVE-2026-20182/CVE-2026-20127, and it has observed limited in-the-wild activity while a fix is still pending. Organizations should urgently restrict admin access, monitor for anomalous netadmin actions, and apply Cisco’s interim mitigations.
Source: Help Net Security
Magento sites under active attack via Mirasvit Cache Warmer RCE; added to CISA KEV
A flaw in the Mirasvit Full Page Cache Warmer extension (CVE-2026-45247) is being actively exploited to achieve unauthenticated remote code execution on Magento servers. Researchers note the bug can be abused via serialized PHP object payloads; CISA added the issue to its Known Exploited Vulnerabilities catalog, accelerating patch urgency for federal agencies and downstream merchants alike.
Source: SecurityWeek
Researcher drops VS Code bug enabling one‑click GitHub token theft
A security researcher publicly released full details and a working exploit for a Visual Studio Code vulnerability that can steal GitHub tokens with a single click. The disclosure—posted with minimal advance notice amid frustration over Microsoft’s bug-handling process—puts developers and CI/CD secrets at immediate risk and underscores the need to review link-handling and OAuth scopes in dev environments.
Source: SecurityWeek
FIFA World Cup 2026 already drawing coordinated cybercrime targeting fans and core sectors
Check Point reports a year-long pre‑positioning campaign aimed at finance, travel/hospitality, and gambling ecosystems вокруг the tournament—complete with fake apps, phishing domains, fraud schemes, and ransomware. With billions set to watch and spend, the infrastructure to harvest credentials and drain accounts is already live; enterprises supporting ticketing, payments, and travel should harden controls now and watch for brand abuse.
Source: Check Point Blog
Five Eyes warn Chinese spies are posing as recruiters to steal secrets
Intelligence agencies from the US, UK, Canada, Australia, and New Zealand say Chinese officers are using job platforms and front companies to recruit insiders with access to classified or privileged information. Tactics include LinkedIn/Indeed outreach, encrypted messaging, bogus NDAs, and crypto payments—aimed at government, military, and anyone with sensitive access.
Source: SecurityWeek
Anthropic: AI is helping low‑skill actors execute advanced cyberattacks
An analysis of 832 banned accounts mapped to MITRE ATT&CK shows AI systems are being misused to plan, script, and execute complex operations by attackers with limited expertise. The findings highlight how generative and agentic AI lower barriers to entry—pressuring defenders to strengthen detection, governance, and controls around AI‑assisted workflows.
Source: Help Net Security
Google patches Android Gemini prompt‑injection that could trigger risky device actions
Researchers showed Gemini could be hijacked via messaging notifications to take unsafe actions—such as controlling Google Home devices or starting video calls—by exploiting how the assistant processed prompts. Google has issued a fix, but the incident underscores the growing attack surface from on‑device AI agents and the need for strong guardrails around notification and intent handling.
Source: SecurityWeek
You May Also Be Interested In...
Critical Redis vulnerability CVE-2026-23479 allows remote code execution
OAuth marketplace apps keep access after publishers vanish
Critical vulnerability in Hugging Face Transformers allowed arbitrary code execution