Weekly Threat Landscape Digest – Week 36

  1. Multiple Vulnerabilities in Cisco Nexus 9000, IOS XR, and SIP Phones

Overview

  • Critical issues include remote code execution, unauthorized access, and resource management flaws in Cisco Nexus 9000 Series Switches, Cisco IOS XR Software, and Cisco SIP Phones.
  • High-severity flaws involve improper exception handling, protection mechanism failures, and denial-of-service conditions.
  • A critical vulnerability in Nexus 9000 Series (Silicon One-based) allows unauthenticated remote attackers to execute code with root privileges.
  • IOS XR hardening release addresses 7 umbrella CVEs, including two rated 9.8; no workaround available.

Impact

  • Arbitrary code execution with root privileges, unauthorized access to protected functions, device compromise, service disruption, and denial of service.

Affected / Fixed Versions

  • Cisco Nexus 9000 Series Switches with affected Silicon One ASICs.
  • Cisco IOS XR Software, including IOS XR7 (LNT) across impacted releases.
  • Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, Video Phone 8875 with specific Cisco SIP Software releases.

Recommendations

  • Apply available patches and mitigations from Cisco without delay.
  • Follow best practices for hardening Cisco IOS XR and SIP phone configurations.
  • Monitor for unusual activity and unauthorized access attempts.

Reference Links

  1. Actively Exploited Authentication Bypass in LiteLLM MCP (CVE-2026-59822)

Overview

  • A high-severity authentication bypass vulnerability (CVE-2026-59822, CVSS v4.0 8.8) exists in LiteLLM’s MCP Streamable HTTP endpoint.
  • Failed API-key validation may fall back to an empty UserAPIKeyAuth() object, allowing unauthenticated requests with arbitrary Bearer tokens to access MCP tooling.
  • Actively exploited in the wild.

Impact

  • Allows unauthenticated remote attackers to establish authenticated MCP sessions.
  • Enables enumeration and invocation of configured MCP tools.
  • Potential access to internal applications, databases, cloud services, development systems, or other privileged tools integrated with LiteLLM.

Affected / Fixed Versions

  • Affected: LiteLLM versions prior to 1.84.0.
  • Fixed: LiteLLM version 1.84.0 and later.

Recommendations

  • Upgrade all affected LiteLLM installations to version 1.84.0 or later.
  • Prioritize patching of internet-facing and externally accessible deployments.

Reference Links

  1. Multiple Vulnerabilities in Jenkins Core and Plugins

Overview

  • Jenkins released updates addressing deserialization flaws, improper access control, stored and reflected XSS, path traversal, privilege escalation, SSRF, CSRF, session fixation, and command injection.
  • High severity issues allow unauthorized access, sensitive data exposure or modification, privilege escalation, or arbitrary code execution.

Impact

  • Unauthorized access, exposure or modification of critical configuration and data, privilege escalation, and remote code execution on affected Jenkins instances.

Affected / Fixed Versions

  • Jenkins weekly: fixed in 2.580; Jenkins LTS: fixed in 2.568.3.
  • Allure Plugin 2.36.0; Customizable Header Plugin 330.v8a_8d87511ea_1; File Parameter Plugin 433.va_0b_80359d54d; GitLab Plugin 1.9.182144.vc1c369226a_52; LDAP Plugin 825.v2fca_37dd5b_cb_; Microsoft Entra ID Plugin 711.v34046f788fd7; Performance Plugin 1017.v9e9f7b_b_b_c5e7; Pipeline: Build Step Plugin 601.v6d4c6d1a_9dc7; Pipeline: Groovy Libraries Plugin 805.va_fc79344957d; SAML Plugin 4.623.v7875d61cd9f5; Script Security Plugin 1415.v9a_f9b_3a_c253d; SonarQube Scanner Plugin 2.19.0; ThinBackup Plugin 2.1.5; TICS Plugin 2026.1.0; XebiaLabs XL Deploy Plugin 26.3.0; update-center2 3.18.4.
  • No fix currently available for Parameterized Remote Trigger Plugin.

Recommendations

  • Immediately update Jenkins Core and all affected plugins to the latest fixed versions.
  • Remove or disable plugins without available fixes.
  • Restrict access to Jenkins administrative functions and monitor for suspicious activity.

Reference Links

  1. Actively Exploited Critical Authentication Bypass in JFrog Artifactory (CVE-2026-82329)

Overview

  • Critical authentication bypass vulnerability (CVE-2026-82329, CVSS 9.8) allows unauthenticated remote attackers to bypass authentication and gain administrative privileges.
  • Requires no authentication or user interaction and has low attack complexity.
  • Active exploitation reported in the wild.

Impact

  • Complete compromise of affected Artifactory instances including unauthorized access to stored artifacts, modification of repositories and packages, administrative configuration changes, and disruption of artifact management services.

Affected / Fixed Versions

  • Artifactory 7.161.0–7.161.19: fixed in 7.161.20.
  • Artifactory 7.146.0–7.146.36: fixed in 7.146.38.
  • Artifactory 7.133.0–7.133.28: fixed in 7.133.29.
  • Artifactory 7.125.0–7.125.19: fixed in 7.125.20.
  • Artifactory 7.117.0–7.117.27: fixed in 7.117.28.
  • Artifactory 7.111.4–7.111.21: fixed in 7.111.21.

Recommendations

  • Upgrade self-managed Artifactory installations to the latest fixed versions immediately.

Reference Links

  1. Security Updates – Google Chrome (September 2, 2026)

Overview

  • Chrome Stable Channel versions 152.0.7977.75/.76 (Windows/macOS) and 152.0.7977.75 (Linux) address 26 security vulnerabilities.
  • Critical vulnerabilities include two use-after-free issues in Shared Tab Groups (CVE-2026-84353) and WebGL (CVE-2026-84352).
  • High-severity flaws affect FileSystem, Skia, Omnibox, Proxy, Browser, V8, Dawn, GPU, and DataTransfer.

Impact

  • Use-after-free vulnerabilities could lead to memory corruption and arbitrary code execution. Other flaws could allow unauthorized actions, information disclosure, buffer overflows, and resource mismanagement.

Affected / Fixed Versions

  • Chrome 152.0.7977.75/.76 for Windows and macOS; 152.0.7977.75 for Linux.

Recommendations

  • Update Google Chrome to the latest stable versions promptly.

Reference Links

  1. Multiple Vulnerabilities in Mozilla Firefox, Firefox ESR, and Thunderbird

Overview

  • Mozilla released security updates addressing multiple high-severity vulnerabilities including privilege escalation, use-after-free, sandbox escapes, memory corruption, and incorrect boundary conditions.
  • Key CVEs: CVE-2026-84117 to CVE-2026-84126, CVE-2026-84143 to CVE-2026-84145, CVE-2026-75874, CVE-2026-16365, CVE-2026-84639.

Impact

  • Successful exploitation may lead to remote code execution, sandbox escape, privilege escalation, and memory corruption, compromising confidentiality, integrity, and availability.

Affected / Fixed Versions

  • Firefox 155; Firefox ESR 153.2, 140.15, 115.40; Thunderbird 155, 153.2, 140.15.

Recommendations

  • Install the latest Mozilla updates promptly to mitigate risks.

Reference Links

  1. Critical Vulnerabilities in ServiceNow AI Platform

Overview

  • CVE-2026-18885: Code injection in GraphQL Composite Data API allowing unauthenticated remote code execution and data access/modification.
  • CVE-2026-18886: Improper access control in image upload processor enabling unauthorized data creation/modification and potential privilege escalation.
  • CVE-2026-74820: SQL injection in dynamic schema ORDER BY clause permitting unauthenticated execution of arbitrary SQL statements.
  • CVE-2026-6876 (High): Sandbox escape allowing arbitrary code execution by unauthenticated users within the Now Platform.

Impact

  • Execution of arbitrary code, unauthenticated access and modification of instance data, privilege escalation, and potential database manipulation.

Affected / Fixed Versions

  • Fixed in Xanadu: Patch 11 Hot Fix 7a; Yokohama: Patch 12 Hot Fix 3b / Patch 13 Hot Fix 4; Zurich: multiple Patch/HF combinations; Australia: Patch 2 Hot Fix 3 through Patch 5.

Recommendations

  • Apply the latest ServiceNow patches and hot fixes corresponding to your platform version promptly.

Reference Links

  1. Actively Exploited Critical SSRF and RCE in SonicWall SMA1000 (CVE-2026-83548/83549)

Overview

  • CVE-2026-83548: Critical pre-authentication SSRF (CVSS 10.0) in WorkPlace interface.
  • CVE-2026-83549: High severity post-authentication OS Command Injection (CVSS 7.8) in Management Console (AMC).
  • Active exploitation of both vulnerabilities confirmed.

Impact

  • CVE-2026-83548 allows unauthorized access via SSRF.
  • CVE-2026-83549 enables administrator-level remote code execution.

Affected / Fixed Versions

  • Affected: SMA 6210, 7210, 8200v running versions 12.4.3-03453 and earlier, and 12.5.0-02835 and earlier.
  • Fixed: 12.4.3-03526 or later, and 12.5.0-02952 or later.

Recommendations

  • Upgrade affected appliances immediately to fixed versions.
  • Prioritize internet-facing SMA1000 appliances for remediation.
  • Review systems for indicators of compromise; if compromised, re-image or redeploy, reset all passwords and TOTP tokens.

Reference Links

  1. Critical Microsoft Exchange Server RCE via NTLM Relay (CVE-2026-62911)

Overview

  • Critical elevation of privilege and RCE vulnerability (CVE-2026-62911, CVSS 8.0) affects the Microsoft Exchange Server Mailbox Replication Proxy Service (MRSProxy).
  • Allows an unauthenticated attacker with local network access to execute arbitrary code with SYSTEM privileges via NTLM authentication relay.
  • Public proof-of-concept exploit code is available.

Impact

  • Successful exploitation enables full compromise of the Exchange server; attackers can execute arbitrary code as SYSTEM, risking sensitive enterprise communications and data.

Affected / Fixed Versions

  • Exchange Server 2016 CU23: fixed in build 15.1.2507.072.
  • Exchange Server 2019 CU14: fixed in build 15.2.1544.044.
  • Exchange Server 2019 CU15: fixed in build 15.2.1748.049.
  • Exchange Server Subscription Edition RTM: fixed in build 15.2.2562.046.

Recommendations

  • Apply Microsoft security updates immediately to all affected on-premises Exchange Server installations.
  • Monitor Exchange and Windows authentication logs for suspicious NTLM relay activity.
  • Restrict unnecessary RPC and SMB connections and enforce SMB signing where possible.
  • Inspect Exchange servers for unauthorized files such as webshells.

Reference Links

  1. Critical cPanel/WHM Domain Parking Vulnerability (CVE-2026-65643)

Overview

  • An authenticated cPanel user with permission to add parked or addon domains can create arbitrary files on the server, potentially leading to root-level code execution and full server control.

Impact

  • Root privileges compromise and complete server takeover.

Affected / Fixed Versions

  • All supported cPanel/WHM versions prior to the fixes.
  • Fixed: 11.110.0.141+, 11.134.0.53+, 11.136.0.37+, 11.138.0.2+, WP2 11.138.1.7+.

Recommendations

  • Update cPanel/WHM installations to one of the fixed versions immediately.
  • Monitor users with domain parking permissions until patching is complete.

Reference Links

  1. Actively Exploited Critical PaperCut NG/MF Zero-Day Vulnerabilities

Overview

  • CVE-2026-82078 (CVSS 9.4): Unsafe Dynamic Class Loading allows arbitrary Java bytecode execution via manipulation of system configuration parameters.
  • CVE-2026-81578 (CVSS 8.8): Authentication Bypass permits unauthenticated remote attackers to perform certain administrative actions before access validation.
  • Both vulnerabilities are actively exploited in the wild.

Impact

  • Execution of arbitrary code on PaperCut servers, unauthorized modification of system configurations, and potential compromise of PaperCut environments.

Affected / Fixed Versions

  • Affected: All versions of PaperCut NG and PaperCut MF.
  • Fixed: Emergency Patch Release 2.

Recommendations

  • Immediately apply Emergency Patch Release 2.
  • Restrict public internet access to PaperCut Application Server web interfaces.
  • Monitor for indicators of compromise: suspicious pc-app.exe activity, altered/missing server.log files, unexpected .class/.cmd/.out files, Remote Access Service running SimpleService.exe, unexpected AnyDesk installations.

Reference Links

  1. Critical WordPress Plugin and Theme Vulnerabilities

Overview

  • CVE-2026-76581 (CVSS 9.8): Authentication bypass in WPMU DEV Dashboard allows unauthenticated attackers to gain administrator access.
  • CVE-2026-18431 (CVSS 9.8): Arbitrary file write in Avada theme enables unauthenticated RCE and full site compromise.
  • CVE-2026-19632 (CVSS 9.8): Sensitive information exposure in TranslatePress may disclose admin password reset details enabling account takeover.
  • CVE-2026-19598 (CVSS 9.8): Privilege escalation in Pods permits unauthenticated attackers to acquire administrator privileges or overwrite user passwords.
  • CVE-2026-82222 (CVSS 10.0): PHP object injection in GiveWP allows arbitrary command execution on affected servers.

Impact

  • Full site takeover, remote code execution, sensitive data exposure, and unauthorized administrative access across affected WordPress installations.

Affected / Fixed Versions

  • WPMU DEV Dashboard: fixed in 5.0.2+.
  • Avada (Fusion) Builder: fixed in 3.16.1+; Avada Website Builder: fixed in 7.16.1+.
  • TranslatePress: fixed in 3.3.2+.
  • Pods: fixed in 2.8.23.4, 2.9.19.4, 3.0.10.4, 3.1.4.2, 3.2.8.3, 3.3.9.1+.
  • WordPress GiveWP Plugin: fixed in 4.16.7.2+.

Recommendations

  • Update all affected plugins and themes to the specified fixed versions immediately.
  • Monitor for signs of compromise on sites running vulnerable versions.

Reference Links

  1. Multiple Vulnerabilities in NVIDIA NemoClaw and OpenShell

Overview

  • Critical issues include sandbox escape (CVE-2026-65093) and incomplete input validation (CVE-2026-65083) in OpenShell for Linux.
  • High severity vulnerabilities involve OS command injection, path traversal, weak authentication, untrusted code execution, improper certificate validation, missing authentication, and code injection across NemoClaw components.

Impact

  • Sandbox escape, arbitrary code/command execution, privilege escalation, information disclosure, data tampering, credential exposure, and denial of service.

Affected / Fixed Versions

  • NemoClaw: fixed in versions 0.0.1 (various commits), 0.0.3, 0.0.4, 0.0.17, 0.0.21, and 0.0.25.
  • OpenShell: fixed in v0.0.34.

Recommendations

  • Update to the latest NVIDIA versions as specified to mitigate these vulnerabilities.

Reference Links

  1. Multiple Vulnerabilities in SonicWall NetExtender Linux Client

Overview

  • CVE-2026-66152 (CVSS 8.8): Arbitrary File Write via Path Traversal in OPSWAT tarball processing.
  • CVE-2026-66153 (CVSS 7.0): Improper Link Resolution Before File Access in NEService auto-upgrade.
  • Both allow attackers to write or modify arbitrary files with elevated privileges.

Impact

  • Arbitrary file modification with root privileges. Potential for full system compromise.

Affected / Fixed Versions

  • Affected: SonicWall NetExtender Linux Client 10.3.5 and earlier.
  • Fixed: SonicWall NetExtender Linux Client 10.3.6 and later.

Recommendations

  • Update to SonicWall NetExtender Linux Client version 10.3.6 or later immediately.

Reference Links

  1. CVE-2020-1938: Apache Tomcat Ghostcat – New Python 3 PoC Released

Overview

  • CVE-2020-1938 (Ghostcat) is a file read and file inclusion vulnerability in the Apache Tomcat AJP protocol.
  • A Python 3 proof-of-concept exploit has been released, adapted from an original Python 2 version.
  • The exploit allows reading arbitrary files on the target Tomcat server via the AJP connector (default port 8009).

Impact

  • Unauthorized reading of sensitive files on servers running vulnerable Tomcat versions. Potential information disclosure leading to further attacks.

Recommendations

  • Disable or properly secure the AJP connector if not in use.
  • Apply vendor patches to fix CVE-2020-1938.
  • Restrict network access to the AJP port to trusted sources only.

Reference Links

  1. Botnet Takedowns Are Working – But DDoS Operators Are Already Adapting

Overview

  • Coordinated international takedown operations in March 2026 disrupted major botnets including Aisiru and Kimwolf, reducing botnet sizes from 13.5 million devices in Q1 to 2.09 million in Q2 2026.
  • Botnet operators are adapting by rebuilding quickly and leveraging blockchain-based C2 using smart contracts on Polygon and Ethereum blockchains.
  • Geographic distribution of botnets is becoming more dispersed, making country-based filtering less effective.
  • Modern DDoS attacks increasingly combine network-layer volume attacks with sophisticated application-layer attacks.

Impact

  • Despite takedowns, attackers rapidly rebuild. Blockchain-based botnets make traditional C2 disruption more difficult.
  • Geographic dispersion dilutes effectiveness of location-based filtering.

Recommendations

  • Treat botnet takedowns as disruption, not eradication; prepare for persistent and evolving threats.
  • Employ coordinated defensive measures across both network and application layers.
  • Use behavioral analysis, adaptive filtering, and continuous traffic inspection rather than country-based filtering.

Reference Links

  1. HPE Patches Critical ArubaOS-CX Remote Code Execution Flaw

Overview

  • HPE released a security update to address a critical remote code execution vulnerability in ArubaOS-CX, the network operating system for Aruba switches.

Impact

  • Successful exploitation could allow attackers to execute arbitrary code remotely, potentially leading to full system compromise.

Affected / Fixed Versions

  • Specific versions affected and fixed are detailed in the official HPE advisory.

Recommendations

  • Apply the latest ArubaOS-CX patches promptly to mitigate the risk of remote code execution attacks.

Reference Links

  1. USN-8724-1: rabbitmq-c Vulnerabilities

Overview

  • Credential exposure via command line (CVE-2023-35789); improper AMQP frame length calculation causing size_t underflow (CVE-2026-44235); invalid frame size validation during AMQP login causing heap buffer overflow (CVE-2026-44236).
  • Integer overflow on 32-bit systems leading to out-of-bounds read (CVE-2026-59986); heap buffer overflow in frame serialization (CVE-2026-61547).

Impact

  • Potential for credential exposure to local attackers. Remote attackers could cause denial of service or potentially execute arbitrary code.

Affected / Fixed Versions

  • Affected: Ubuntu 14.04 LTS, 16.04 LTS, 18.04 LTS, 20.04 LTS.

Recommendations

  • Apply security updates for rabbitmq-c as provided by Ubuntu Security Notices.
  • Avoid running rabbitmq-c tools with sensitive credentials on shared or untrusted systems until patched.

Reference Links

  1. Cisco IOS XR Software Security Hardening Release: September 2026

Overview

  • Cisco conducted an internal security review of IOS XR Software, identifying multiple internally discovered vulnerabilities grouped by CWE with assigned CVE identifiers.
  • No active exploitation of these vulnerabilities is known. Security Impact Rating is Critical.

Impact

  • Critical security impact rating due to the nature of the identified vulnerabilities.

Affected / Fixed Versions

  • Software updates addressing these vulnerabilities have been released; specific versions detailed in Cisco’s advisory.

Recommendations

  • Apply the released software updates promptly as no effective workarounds exist.

Reference Links

  1. Actively Exploited Critical Elementor Pro WordPress Flaw (CVE-2026-32475)

Overview

  • A critical vulnerability in the Elementor Pro WordPress plugin (CVE-2026-32475) is actively exploited.
  • Exploits deploy webshells and allow arbitrary command execution on affected servers.

Impact

  • Full site takeover with remote code execution capabilities.

Affected / Fixed Versions

  • Vulnerable versions pertain to Elementor Pro before the patched release.

Recommendations

  • Update Elementor Pro to the latest patched version immediately.
  • Monitor for webshell indicators and unusual command execution activity.

Reference Links

  1. CVE-2026-62906: Microsoft Discovery Studio Information Disclosure

Overview

  • Microsoft Discovery Studio contains a vulnerability related to improper neutralization of special elements in data query logic, allowing an unauthorized attacker to disclose sensitive information over a network.

Impact

  • Information disclosure to unauthorized parties.

Recommendations

  • Apply available security updates from Microsoft to mitigate the vulnerability.

Reference Links

  1. CVE-2026-70178: Microsoft Fabric Elevation of Privilege

Overview

  • A missing authorization flaw in Microsoft Fabric enables privilege escalation by an authorized attacker over a network.

Impact

  • Elevated privileges may allow attackers to gain higher access than intended.

Recommendations

  • Apply security updates released by Microsoft to remediate the issue.

Reference Links

  1. USN-8723-1: SPICE vdagent Vulnerabilities

Overview

  • CVE-2026-57965: Integer overflow in buffer size calculation when writing to the daemon socket, leading to denial of service.
  • CVE-2026-57966: Improper filename sanitization during file transfers, allowing a malicious host to write arbitrary files anywhere on the guest OS with spice-vdagent process privileges.

Impact

  • Potential denial of service via crash; remote arbitrary file write with process privileges enabling possible unauthorized code execution or system compromise.

Recommendations

  • Update SPICE vdagent to the fixed version provided by the Ubuntu security notice.

Reference Links

  1. USN-8722-1: libssh2 Vulnerabilities

Overview

  • libssh2 mishandles certain SFTP server responses, AES-GCM cipher negotiation, and Encrypt-then-MAC cipher negotiation, allowing remote attackers controlling an SSH server to exploit these flaws.

Impact

  • Could cause libssh2 to crash leading to denial of service, or potentially allow arbitrary code execution by remote attackers.

Recommendations

  • Update libssh2 to the patched version provided by Ubuntu as per USN-8722-1.

Reference Links

  1. Plex Security Vulnerabilities – Update Required

Overview

  • Plex disclosed multiple security vulnerabilities affecting its desktop clients and media servers. Users are strongly urged to update their software promptly.

Impact

  • Exploitation of these vulnerabilities could lead to unauthorized access or compromise of Plex installations.

Recommendations

  • Immediately update both Plex desktop clients and media servers to the latest versions containing the security patches.

Reference Links

  1. Microsoft Teams IT Support Impersonation Campaign

Overview

  • Microsoft Threat Intelligence identified a human-operated intrusion campaign abusing Microsoft Teams external collaboration to impersonate IT/helpdesk staff.
  • Attackers use PowerShell to silently install a malicious MSI deploying a portable Node.js runtime and obfuscated JavaScript implant providing persistent C2 capabilities.
  • The campaign includes domain enumeration, lateral movement via WinRM, privilege escalation, security control disabling, data exfiltration, and potential ransomware deployment.

Impact

  • Credential-backed interactive access to internal enterprise infrastructure. Potential for data theft, extortion, ransomware, and widespread network compromise.

Recommendations

  • Enhance user training on social engineering, especially around granting remote support access.
  • Monitor for unusual use of remote support tools and PowerShell in conjunction with MSI installations.
  • Apply network segmentation and limit WinRM access.
  • Implement detection focused on Teams external collaboration abuse.

Reference Links

  1. Anatomy of a Silent Domain Takeover via Active Directory Abuse

Overview

  • Modern Active Directory attacks leverage legitimate Windows protocols — password spraying, SMB lateral movement, kerberoasting, DCSync replication abuse, and Golden Ticket forging — without malware.
  • An example attack took 54 minutes from password spray to Domain Admin Golden Ticket.
  • Traditional detection tools fail because the attack generates no executable files and abuses legitimate AD features.
  • Qualys AD Real-Time Monitoring enriches events with identities, source IPs, and Logon IDs, connecting disparate logs into a comprehensive attack timeline.

Impact

  • Complete domain takeover with Domain Admin privileges without malware or known exploit usage. Attackers gain persistent and undetectable control over the AD environment.

Recommendations

  • Implement real-time monitoring tools correlating identity, source IP, and logon events.
  • Regularly rotate service account passwords and remove unnecessary replication rights.
  • Address configuration weaknesses enabling replication abuse and weak credential policies.

Reference Links

  1. Cisco September 2, 2026 Security Advisories – Advance Notification

Overview

  • Cisco PSIRT published multiple security advisories covering critical to medium severity vulnerabilities.
  • Vulnerabilities include remote code execution in Cisco IOS XR Software and Cisco Nexus 9000 Series Switches Silicon One, DoS in Cisco phone series, and ciphertext decryption issues in Secure Email.
  • CVE identifiers CVE-2026-20274 through CVE-2026-20355 with CVSS scores ranging from 5.9 to 9.8.

Impact

  • Critical RCE vulnerabilities may allow full system compromise. DoS vulnerabilities can disrupt telephony services. Ciphertext decryption vulnerabilities impact email confidentiality and integrity.

Affected / Fixed Versions

  • Specific affected and fixed versions are detailed in the respective Cisco advisories.

Recommendations

  • Cisco strongly recommends upgrading to the indicated fixed software versions.

Reference Links

  1. Cisco SIP Phone Denial of Service Vulnerability

Overview

  • A remote, unauthenticated attacker can exploit improper memory management in Cisco SIP Software by sending a continuous stream of crafted HTTP packets, triggering continuous memory consumption and denial of service.
  • Affected phones must be registered to Cisco Unified Communications Manager and have Web Access enabled (disabled by default).

Impact

  • Successful exploit causes the device to become unresponsive, requiring a manual reboot to recover, disrupting telephony services.

Affected / Fixed Versions

  • Affected: Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with vulnerable SIP Software.
  • Fixed versions available via Cisco software updates.

Recommendations

  • Apply Cisco’s released software updates.
  • Disable Web Access if not required to reduce exposure. No workarounds are available.

Reference Links

  1. GeoNetwork Fixes Unauthenticated RCE Chain (CVE-2026-TBD)

Overview

  • Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution.
  • GeoNetwork is an open-source geospatial metadata catalog widely used by government and agency geoportals.

Impact

  • Attackers can remotely execute arbitrary code without authentication on affected GeoNetwork installations, potentially compromising sensitive government geoportal data.

Affected / Fixed Versions

  • Fixed in GeoNetwork versions 4.4.12 and 4.2.17, released July 8, 2026.

Recommendations

  • Upgrade to GeoNetwork 4.4.12 or 4.2.17 immediately.

Reference Links

  1. Philippines Nuclear Agency Breached via Unpatched ownCloud Vulnerabilities

Overview

  • Attackers exploited known, unpatched vulnerabilities in ownCloud software to breach the Philippines Nuclear Agency.
  • Stolen sensitive data includes nuclear reactor databases, personnel records, and credential stores.

Impact

  • Sensitive government and nuclear data exfiltrated including databases, personnel records, and credentials.

Recommendations

  • Promptly apply patches and updates for ownCloud and other critical infrastructure software.
  • Conduct thorough audits to identify and remediate unpatched vulnerabilities.
  • Implement enhanced monitoring for anomalous activity in critical networks.

Reference Links

  1. Counterfeit Installer Campaign Targeting Software Download Seekers

Overview

  • Microsoft Defender Experts are tracking an active malware campaign impersonating trusted vendors with counterfeit software-download websites targeting primarily China-based operations and Chinese-speaking users.
  • Malicious installers deploy malware establishing persistence, weakening security, and communicating with attacker infrastructure through a consistent attack chain: spoofed site → dynamic malicious installer → execution → persistence → privilege escalation → defense evasion → C2.
  • Key impersonated brands include Razer, Microsoft Edge, and Kaspersky.
  • Lure domains use .com.cn, .hl.cn, and .cn with brand-impersonation; payloads use randomized paths to evade naming detection.

Impact

  • Multiple organizations worldwide compromised through this campaign. Infection enables persistence, defense evasion, and potential full system compromise.

Recommendations

  • Avoid downloading software from untrusted sources or look-alike vendor websites.
  • Enable SmartScreen, network protection, tamper protection, and Microsoft Defender XDR.
  • Conduct network-level and endpoint telemetry analysis using ASN and nameserver pivots.

Reference Links

  1. TerminalFix Campaign: Reverse Tunnel Deployed via Multistage Intrusion

Overview

  • Microsoft Threat Intelligence identified the TerminalFix campaign — a ClickFix variant targeting multiple industries via compromised websites.
  • Attackers display a fake Cloudflare CAPTCHA prompting users to paste malicious PowerShell commands into Windows Terminal.
  • The attack chain involves DLL sideloading, steganographic payload extraction from PNG images, extensive Active Directory reconnaissance, and deployment of a Python-based reverse-tunnel implant.
  • Persistence is established through Registry Run keys and scheduled tasks.

Impact

  • Attackers gain persistent internal network access with full TCP proxy capabilities. Compromised hosts become pivot points for further intrusion, privilege escalation, and potential ransomware deployment.

Recommendations

  • Treat affected systems as compromised network pivot points and investigate for lateral movement.
  • Detect and block suspicious PowerShell execution and DLL sideloading activities.
  • Monitor for unusual reverse tunnel network connections and scheduled task modifications.

Reference Links

AI Threat Landscape

  1. Most of the Bugs Claude Mythos Found Have Never Been Checked by a Human

Overview

  • Anthropic’s Claude Mythos Preview AI analyzed 281 open-source projects, identifying 23,019 candidate vulnerabilities.
  • External security firms manually reviewed 1,900 findings; maintainers received 1,596 vulnerability reports, acknowledged 1,451, with 97 fixes merged upstream and 88 published as security advisories (as of May 22, 2026).
  • The remaining 21,119 candidate vulnerabilities have yet to be validated by humans due to a lack of sufficient reviewers.

Impact

  • Potentially thousands of unverified vulnerabilities remain unaddressed in open-source software, representing significant risk if exploited.

Recommendations

  • Increase human resources for vulnerability verification to complement AI detection.
  • Integrate AI-driven findings with traditional security workflows to accelerate vulnerability remediation.
  • Encourage open-source maintainers to prioritize reviewing AI-flagged vulnerabilities.

Reference Links

  1. OpenAI GPT-6 Astra Discovers Zero-Day Flaws and Builds Working Exploits

Overview

  • OpenAI released GPT-6 Astra, an AI model capable of identifying zero-day vulnerabilities and generating working proof-of-concept exploits in authorized cybersecurity testing.
  • The model scored 100% on ExploitBench and automates code analysis, terminal tool use, software testing, and iterative exploit refinement.
  • GPT-6 Astra’s action efficiency surpasses human baselines in vulnerability research; safety tests indicate it stays within authorized test scopes.
  • The technology’s dual-use nature raises concerns about potential misuse to weaponize vulnerabilities more easily.

Impact

  • GPT-6 Astra could accelerate authorized vulnerability discovery, patch development, and detection rule creation.
  • Conversely, it lowers technical barriers for attackers to develop exploits, increasing risk if misused.

Recommendations

  • Security teams should monitor use of AI-assisted offensive security tools and enhance safeguards.
  • Deploy strong access controls and usage policies for tools like GPT-6 Astra.
  • Integrate AI research findings rapidly into defensive measures to counter accelerated exploit development.

Reference Links

  1. OpenAI Investigates Elevated Errors Affecting ChatGPT and Codex Services

Overview

  • OpenAI is investigating an ongoing incident causing elevated error rates and degraded performance across ChatGPT and Codex AI services.
  • The incident affects multiple components, resulting in failed requests, error messages, delayed responses, and interrupted interactions.
  • No confirmed root cause, mitigation timeline, or evidence of cyberattack or data breach has been released.
  • Highlights operational risks for enterprises relying on external AI platforms for critical business functions.

Impact

  • Users may experience interruptions in AI-assisted conversations, code generation, debugging, and automation tasks. Security and development teams using these tools for incident analysis may suffer workflow delays.

Recommendations

  • Monitor OpenAI’s official status page for updates.
  • Employ fallback processes such as local development tools or manual review during disruptions.
  • Avoid repeatedly submitting sensitive content during elevated error periods.

Reference Links

  1. CVE-2026-70352: Azure AI Language Elevation of Privilege

Overview

  • A missing authentication vulnerability exists in Azure AI Language, allowing an unauthorized attacker to elevate privileges remotely over a network.

Impact

  • Elevation of privilege enabling attacker to gain unauthorized higher-level access.

Recommendations

  • Apply available security updates from Microsoft to mitigate the vulnerability.

Reference Links

  1. Researchers Use Claude to Port Pre-Auth RCE Exploit Between WAGO PLC Models

Overview

  • Forescout Research – Vedere Labs leveraged Anthropic’s Claude AI to successfully port a pre-authentication RCE exploit from one WAGO PLC model to another.
  • The exploit abuses CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server’s USER command.
  • The attack enables execution of attacker-supplied ARM shellcode on live hardware.

Impact

  • Exploitation allows remote attackers to execute arbitrary code on affected WAGO PLC devices without authentication, potentially leading to complete compromise of industrial control systems.

Recommendations

  • Patch affected devices against CVE-2021-31886 vulnerabilities.
  • Monitor for suspicious FTP USER command activity.
  • Limit network exposure of PLCs and apply network segmentation.

Reference Links

  1. Critical Langflow Vulnerability Actively Exploited (CVE-2026-0768)

Overview

  • Attackers are actively exploiting CVE-2026-0768, a critical vulnerability in Langflow, a low-code AI development platform.
  • The platform is increasingly targeted by adversaries in 2026 as interest in AI platform exploitation grows.

Impact

  • Exploitation can lead to unauthorized access or compromise of the AI platform, potentially affecting AI workflows and data integrity.

Recommendations

  • Apply available security patches for CVE-2026-0768 immediately.
  • Monitor security advisories and threat intelligence feeds for updated mitigation measures.

Reference Links

Ready to get started?

Contact us to arrange a half day
Managed SOC and XDR workshop in Dubai

Ready to get started?

Contact us to arrange a half day Managed SOC and XDR workshop in Dubai

© 2026 HawkEye – Managed CSOC and XDR powered by DTS Solution. All Rights Reserved.
This is a staging environment