Weekly Threat Landscape Digest – Week 41

HawkEye Managed MDR
  1. Argo CD Critical Command Execution and Access Bypass (CVE-2026-77459, CVSS 9.9)

Overview

  • Four critical CVSS 9.9 vulnerabilities in Argo CD’s argocd-repo-server and AppProject access controls.
  • Issues include command execution via Kustomize Remote Reference, unauthorized file read via Jsonnet, AppProject hook bypass, and Kustomize Helm Config Home flaws.
  • Argo CD 2.x and versions 3.0–3.2 are end-of-life and will not be patched.

Impact

  • Arbitrary command execution with repo-server privileges. Unauthorized reading of sensitive files and credentials. Bypass of AppProject restrictions to deploy unauthorized resources under Argo CD controller privileges.

Affected / Fixed Versions

  • Fixed in Argo CD versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2.

Recommendations

  • Immediately upgrade Argo CD to one of the fixed versions listed above.

Reference Links

  1. Splunk Enterprise Multiple Critical Vulnerabilities Including Improper Access Control (CVE-2026-76281, CVSS 9.8)

Overview

  • Multiple critical to low-severity vulnerabilities in Splunk Enterprise versions 9.4.0–10.4.2.
  • Critical issues: improper access control, missing authentication in Patroni REST API, and improper neutralization.
  • Enables unauthorized access, privilege escalation, SQL injection, SSRF, log injection, and denial of service.

Impact

  • Bypassing authentication/authorization, privilege escalation, sensitive data disclosure, and service disruption.

Affected / Fixed Versions

  • Affected: Splunk Enterprise 9.4.0–9.4.14, 10.0.0–10.0.9, 10.2.0–10.2.6, 10.4.0–10.4.2.
  • Fixed: Splunk Enterprise 9.4.15, 10.0.10, 10.2.7, 10.4.3.

Recommendations

  • Upgrade to the applicable fixed or later versions of Splunk Enterprise.
  • Apply additional remediation steps for CVE-2026-76264, CVE-2026-76265, CVE-2026-76272, and CVE-2026-76280.
  • Monitor for exploitation attempts targeting critical and high-severity flaws.

Reference Links

  1. Cisco Nexus Switches and NX-OS Multiple RCE Vulnerabilities (CVE-2026-76485, CVE-2026-76471)

Overview

  • Multiple critical, high, and medium vulnerabilities across Cisco Meraki, License Smart Software Manager On-Prem, Nexus 3000/9000 Series, NX-OS, APIC, and Finesse.
  • Critical: RCE in Nexus 3000/9000 (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501) and NX-OS NX-API (CVE-2026-76471).
  • High: SSRF in Cisco Finesse (CVE-2026-20362). Medium: DoS, sandbox escape, command injection, unauthorized file access.

Impact

  • Remote arbitrary code execution, security control bypass, unauthorized file access, command injection, SSRF, and denial-of-service.

Affected / Fixed Versions

  • Detailed affected versions in official Cisco security advisory.

Recommendations

  • Apply Cisco’s provided mitigations, workarounds, or security updates promptly.

Reference Links

  1. HPE ClearPass Policy Manager 28 Vulnerabilities Including Critical RCE and Auth Bypass (CVE-2026-79798, CVSS 9.9)

Overview

  • 28 vulnerabilities in HPE ClearPass Policy Manager: 10 Critical, 11 High, 7 Medium.
  • Critical flaws enable unauthenticated RCE, authentication bypass, unauthorized administrative access, arbitrary database commands, and path traversal.
  • Highest severity: CVE-2026-79798 — authenticated SQL injection in web-based management interface (CVSS 9.9).

Impact

  • Remote code execution by unauthenticated or low-privileged attackers. Authentication bypass enabling unauthorized admin access. Arbitrary SQL commands compromising CPPM databases. Arbitrary code execution on client and OnGuard agents.

Affected / Fixed Versions

  • Fixed in CPPM versions 6.14.1 or later, and 6.11.16 or later. CVE-2026-79800 fixed only in 6.14.1.

Recommendations

  • Upgrade CPPM immediately to version 6.14.1 or 6.11.16 as applicable.
  • Restrict access to CPPM CLI and web-based management to trusted administrative networks.

Reference Links

  1. Arista CloudVision CUE WiFi Backend Critical Unauthenticated Access (CVE-2026-102159, CVSS 9.8)

Overview

  • Six vulnerabilities in the CloudVision CUE (CV-CUE) backend: 1 Critical, 4 High, 1 Medium.
  • CVE-2026-102159: Unauthenticated network access to internal service functionality, risking sensitive location data exposure or service disruption.
  • CVE-2026-102161: Adjacent network IP spoofing for admin session privileges. CVE-2026-102155: XXE enabling local file disclosure. CVE-2026-102160: Super User OS command injection via backup requests.

Impact

  • Unauthenticated access to restricted functions. Privilege escalation. File disclosure. OS command execution. SQL injection and IDOR affecting availability and data confidentiality.

Affected / Fixed Versions

  • Affected: Arista WiFi deployments using CV-CUE backend since WiFi 2021.2.0; CVE-2026-102159 from WiFi 2022.3.0. Fixed: Arista WiFi version 2026.2.1.

Recommendations

  • Immediately upgrade to Arista WiFi version 2026.2.1. Confirm CV-CUE backend is enabled/running.
  • Until patching, limit network access to the CV-CUE backend to trusted hosts and networks.

Reference Links

  1. Veeam Backup & Replication Critical RCE via Insecure Deserialization (CVE-2025-64393)

Overview

  • CVE-2025-64393: Critical RCE via insecure deserialization in the Backup Server’s Mount Service, exploitable by low-privileged Backup Viewer role users.
  • CVE-2026-93026: Backup Viewer role users can modify/delete Enterprise Manager master key and alter stored antivirus update credentials.
  • CVE-2025-64392: Reflected XSS in Backup Enterprise Manager allowing script execution in authenticated user browsers.

Impact

  • Remote code execution on Backup Server by low-privileged users. Unauthorized manipulation of security-sensitive credentials. Session hijacking or data theft via XSS.

Affected / Fixed Versions

  • Affected: Veeam Backup Enterprise Manager version 12.3.2.4854 and all prior 12.x builds. Fixed: version 12.3.2 P4 (build 12.3.2.4934). Version 13 builds are not affected.

Recommendations

  • Update to Veeam Backup & Replication 12.3.2 P4 or later. Review and monitor Backup Viewer role permissions.

Reference Links

  1. SonicWall SMA1000 Multiple Vulnerabilities Including Critical Pre-Auth SSRF (CVE-2026-102255)

Overview

  • CVE-2026-102255: Critical pre-auth SSRF in WorkPlace interface allowing unauthenticated remote attackers to perform unauthorized internal requests.
  • CVE-2026-102256: Post-auth OS command injection enabling RCE.
  • CVE-2026-102257: Zip Slip path traversal in Appliance Management Console allowing arbitrary file extraction.
  • CVE-2026-102258: Stored XSS in Appliance Management Console.

Impact

  • Unauthorized RCE and control over affected appliances. SSRF enabling unauthorized internal network access. Arbitrary file extraction. Session hijacking via XSS.

Affected / Fixed Versions

  • Affected: SMA1000 versions 12.4.3-03526 and earlier; 12.5.0-02952 and earlier.
  • Fixed: 12.4.3-03670 and later; 12.5.0-03082 and later.

Recommendations

  • Immediately update SonicWall SMA1000 appliances to fixed or later versions.

Reference Links

  1. Google Chrome 155 – 247 Fixes Including 4 Critical Use-After-Free Vulnerabilities

Overview

  • Chrome 155 addressed 247 security fixes including four critical use-after-free vulnerabilities.
  • Affected components: Chromecast (CVE-2026-106382), Browser (CVE-2026-106197), Navigation (CVE-2026-106358), Track (CVE-2026-106347).
  • Other affected areas: Site Isolation, V8, ANGLE, WebRTC, Media, PDF, Autofill.

Impact

  • Use-after-free vulnerabilities can lead to arbitrary code execution or browser compromise.

Affected / Fixed Versions

  • Fixed in Chrome 155.0.8059.39/.40 (Windows/Mac) and 155.0.8059.39 (Linux).

Recommendations

  • Update Google Chrome to version 155.0.8059.39/.40 or later immediately.

Reference Links

  1. Langflow OSS 25 Vulnerabilities Including Critical Unauthenticated RCE (CVE-2026-104334, CVSS 9.8)

Overview

  • IBM disclosed 25 vulnerabilities in Langflow OSS versions 1.0.0–1.12.2: 2 Critical, 19 High, 4 Medium.
  • CVE-2026-104334 and CVE-2026-93674: Unauthenticated RCE without user interaction (CWE-94 — improper control of code generation). 15 vulnerabilities could lead to code execution.

Impact

  • Remote arbitrary code execution with full confidentiality, integrity, and availability impact (CVSS 9.8).

Affected / Fixed Versions

  • Affected: Langflow OSS 1.0.0–1.12.2. Fixed: Langflow OSS 1.12.3.

Recommendations

  • Immediately upgrade Langflow OSS to version 1.12.3 or later. Prioritize internet-facing deployments.

Reference Links

  1. Dell System Update Critical Path Traversal and Privilege Escalation (CVE-2026-86360, CVSS 9.6)

Overview

  • CVE-2026-86360 (CVSS 9.6): Critical path traversal allowing unauthenticated remote attackers to execute code with root privileges.
  • CVE-2026-86361 and CVE-2026-86362 (CVSS 8.2): Improper permission assignment and access control enabling local privilege escalation.
  • CVE-2026-63697 (CVSS 7.6): Improper certificate validation allowing RCE by high-privileged remote attacker.
  • CVE-2026-71168 (CVSS 7.3): Path traversal leading to RCE by low-privileged local attacker.

Impact

  • Complete system compromise including root-level code execution and privilege escalation.

Affected / Fixed Versions

  • Affected: Dell System Update (DSU) versions prior to 2.3.0.0. Fixed: DSU version 2.3.0.0 and later.

Recommendations

  • Update Dell System Update (DSU) to version 2.3.0.0 or later immediately.

Reference Links

  1. Microsoft Exchange Server Elevation of Privilege (CVE-2026-96940, CVSS 8.8)

Overview

  • CVE-2026-96940: Weak authentication (CWE-1390) in Microsoft Exchange Server allowing authenticated attackers to elevate privileges over a network.
  • Can result in unauthorized access to other users’ mailboxes within the same organization. Attackers can read email messages and attachments but cannot access data across tenant boundaries.

Impact

  • Unauthorized mailbox access within the same organization. Exposure of sensitive email content and attachments.

Affected / Fixed Versions

  • Fixed: Exchange Server Subscription Edition RTM 15.02.2562.053; Exchange 2016 CU23 15.01.2507.075; Exchange 2019 CU15 15.02.1748.053; Exchange 2019 CU14 15.02.1544.048.

Recommendations

  • Apply the latest Microsoft security updates corresponding to the fixed builds.

Reference Links

  1. Atlassian Data Center Critical Arbitrary File Access (CVE-2026-21589, CVSS 9.3)

Overview

  • Critical arbitrary file access vulnerability in multiple Atlassian Data Center products allowing unauthenticated attackers to access specific files in the web application root directory.
  • Requires prior knowledge of exact filename and path. No directory listing or enumeration possible. No confirmed exploitation reported. Atlassian Cloud already patched.

Impact

  • Potential exposure of sensitive/confidential files. Increased risk of further compromise depending on system configuration.

Affected / Fixed Versions

  • Bitbucket DC: fixed in 9.4.26, 10.2.8, 10.5.1. Confluence DC: 9.2.26, 10.2.19. Jira Service Mgmt DC: 5.12.40, 10.3.26, 11.3.12. Jira Software DC: 9.12.40, 10.3.26, 11.3.12. Bamboo DC: 10.2.24, 12.1.12. Crowd DC: 6.3.7, 7.0.3, 7.1.7, 7.2.4. Crucible/Fisheye: 4.9.15.

Recommendations

  • Immediately upgrade all affected Atlassian Data Center installations to applicable fixed versions.
  • Conduct access-log reviews for path traversal or arbitrary file access attempts (URL-decode request lines up to two times).

Reference Links

  1. Actively Exploited Zammad RCE and Privilege Escalation (CVE-2026-102489, CVE-2026-102490)

Overview

  • CVE-2026-102489: Session fixation. CVE-2026-102490: Improper privilege management.
  • Chained: RCE as the zammad user escalating to root. Both actively exploited in the wild.

Impact

  • Remote code execution as zammad user. Full system compromise via root privilege escalation.

Affected / Fixed Versions

  • Affected: Zammad 6.3.0–6.5.4, 7.0.0–7.1.3, and 1.5.0–7.1.0-alpha. Fixed: version 7.2.0 or later.

Recommendations

  • Update Zammad to version 7.2.0 or later as soon as possible. Monitor for unusual activity.

Reference Links

  1. Google Chrome Critical Out-of-Bounds Write in WebGL (CVE-2026-103628)

Overview

  • 11 vulnerabilities in Chrome: 1 Critical, 9 High, 1 Medium.
  • CVE-2026-103628: Critical out-of-bounds write in WebGL. High: incorrect authorization, integer overflow, use-after-free, type confusion, and buffer overflow across FileSystem, Compositing, FedCM, V8, Skia, MediaStream, WebRTC.

Impact

  • Memory corruption, information disclosure, and other security impacts.

Affected / Fixed Versions

  • Chrome 154.0.8037.97/.98 (Windows/Mac); 154.0.8037.97 (Linux); 154.0.8037.126 (Android); Extended Stable 152.0.7977.152 (Windows/Mac).

Recommendations

  • Update Google Chrome to the latest version immediately.

Reference Links

  1. Thales SConnect Critical Unauthenticated RCE (CVE-2026-18397, CVSS 9.4)

Overview

  • Critical RCE in Thales SConnect native host component leveraging cryptographic weaknesses, memory-management issues, and an unrestricted messaging interface between attacker-controlled web pages and the SConnect native host.
  • CWEs: CWE-130 (length parameter inconsistency), CWE-252 (unchecked return value), CWE-347 (improper cryptographic signature verification), CWE-457 (uninitialized variable).

Impact

  • Remote code execution without privileges. Requires user interaction (visiting a malicious web page). Low exploitation complexity.

Affected / Fixed Versions

  • Affected: Thales SConnect versions prior to 2.16.1.0. Fixed: 2.16.1.0 or later.

Recommendations

  • Upgrade Thales SConnect to 2.16.1.0 or later immediately. Restrict access to untrusted websites on vulnerable systems.

Reference Links

  1. Actively Exploited Citrix NetScaler ADC/Gateway Memory Overflow DoS (CVE-2026-88779, CVSS 8.7)

Overview

  • High-severity memory overflow in Citrix NetScaler ADC and Gateway when configured as SAML SP or IdP. Remotely exploitable without authentication. Actively exploited in the wild.
  • Attack complexity is low, requires no privileges or user interaction.

Impact

  • Denial of service from memory overflow on network-exposed NetScaler appliances in SAML roles. Secure Private Access Hybrid deployments also impacted.

Affected / Fixed Versions

  • NetScaler ADC/Gateway 14.1: before 14.1-73.41 → fixed in 14.1-73.41+. 13.1: before 13.1-64.28 → fixed in 13.1-64.28+. FIPS/NDcPP: 13.1-37.282+.

Recommendations

  • Identify SAML SP or IdP appliances and prioritize upgrades. Apply fixed builds corresponding to affected versions immediately.

Reference Links

  1. CUPS Double-Free Vulnerability Leading to Denial of Service (CVE-2026-107886)

Overview

  • OpenPrinting CUPS before 2.4.20 has a double-free in printer-class management. When modifying class member lists, a freed pointer is not cleared; if validation fails, a dangling pointer remains causing a second free during class deletion.
  • Requires authorized client with @SYSTEM privileges.

Impact

  • Denial of service on the CUPS print scheduler, disrupting printing services.

Affected / Fixed Versions

  • Affected: OpenPrinting CUPS before 2.4.20. Fixed: 2.4.20 and later.

Recommendations

  • Upgrade to OpenPrinting CUPS 2.4.20 or later. Restrict privileges to authorized clients.

Reference Links

  1. OpenPrinting CUPS Resource Exhaustion Denial of Service (CVE-2026-107885)

Overview

  • CUPS through 2.4.20 has a resource exhaustion vulnerability in cupsdCheckJobs submission-timeout handling. A client with IPP access can hold an incomplete HTTP request blocking unrelated jobs from timing out, accumulating until MaxJobs limit is reached.

Impact

  • Exhaustion of print job resources resulting in denial of legitimate print submissions.

Recommendations

  • Monitor and limit access to the IPP service. Apply patches when released. Consider network controls or job submission restrictions.

Reference Links

  1. FBI Seizes Chinese Hacking Tools Microscan and FishHub (Flax Typhoon/Integrity Technology Group)

Overview

  • FBI and DOJ seized seven domains linked to Microscan (Python-based vuln scanner with 1,300+ pentest scripts) and FishHub (spearphishing and malware deployment tool) operated by China-based Integrity Technology Group (ITG).
  • Integrity Technology Group used a Mirai-based botnet of infected consumer devices for scanning and intrusion since at least 2017. Operation targeted infrastructure, not specific breaches.

Impact

  • Targeted critical infrastructure globally: power companies, airports, universities, NGOs.
  • Attacks involved vulnerability scanning, password spraying, VPN persistence, automated email theft, and confirmed data theft from specific victims.

Recommendations

  • Review DNS, proxy, firewall, and endpoint logs for IOC matches from the advisory.
  • Patch exposed systems, disable unused services, enforce MFA, and monitor cloud app access.

Reference Links

  1. Citrix NetScaler ADC/Gateway Critical RCE in SAML Configurations (CVE-2026-88771/88772, CVSS 9.5)

Overview

  • Critical RCE vulnerability in NetScaler ADC and Gateway when configured as SAML IdP or SP via memory overflow (CWE-119). Remotely exploitable without user interaction but with high complexity.
  • Citrix published CTX697191; no public exploits or active campaigns reported at disclosure.

Impact

  • Arbitrary code execution or DoS on affected appliances (CVSS v4.0 score: 9.5).

Affected / Fixed Versions

  • Affected: 14.1-73.37–14.1-73.41 and 13.1-64.23–13.1-64.28 when configured as SAML IdP; older versions when configured as SAML IdP or SP. Fixed: 14.1-73.46+, 13.1-64.29+, FIPS/NDcPP 13.1-37.283+.

Recommendations

  • Verify SAML role (IdP or SP) and software version of each appliance. Apply fixed builds immediately.
  • Review samlAction and samlIdPProfile settings. Update Secure Private Access Hybrid NetScaler instances.

Reference Links

  1. USN-8910-1: libxml2 Vulnerabilities

Overview

  • Multiple vulnerabilities in libxml2: heap buffer overflows, improper handling of XML catalogs, large qualified names, URI strings, XPointer expressions, integer overflow checks, and XInclude directive parser options.

Impact

  • DoS via crashes, arbitrary code execution, XML external entity injection, and SSRF attacks.

Affected / Fixed Versions

  • Issue with escaping large URI strings affects Ubuntu 26.04 LTS.

Recommendations

  • Update libxml2 to fixed versions. Apply appropriate parser options to disable network access when handling XInclude directives.

Reference Links

  1. DOJ/FBI Seize Flax Typhoon-Linked Tools Microscan and FishHub

Overview

  • DOJ and FBI seized two hacking tools linked to Flax Typhoon and China-based Integrity Technology Group (sanctioned by U.S. government).
  • Microscan: vulnerability scanning tool. FishHub: spearphishing tool for malware download after network access.
  • Targeted critical infrastructure worldwide: power companies, airports, universities.

Impact

  • Cross-site scripting, password spraying, VPN persistence, email and credential exfiltration from targeted victims globally.

Recommendations

  • Monitor and mitigate vulnerabilities on Microsoft Exchange and other critical systems.
  • Employ robust email security and credential protection measures.

Reference Links

  1. Cisco Warns of Critical Flaws Allowing Nexus Switch Takeover

Overview

  • Cisco disclosed five critical vulnerabilities in NX-OS allowing arbitrary code execution with root privileges on affected Nexus switches.

Impact

  • Complete compromise of Nexus switches, affecting data center network operations.

Recommendations

  • Apply security updates from Cisco. Monitor advisories and implement best practices for network device security.

Reference Links

  1. CVE-2026-77900: Azure App Service Remote Code Execution

Overview

  • Missing authentication vulnerability in Azure App Service enables unauthenticated remote code execution.

Impact

  • Remote code execution leading to full compromise of the affected service.

Recommendations

  • Apply security updates from Microsoft. Review and enforce authentication mechanisms in Azure App Service.

Reference Links

  1. CVE-2026-69435: Azure SRE Agent Elevation of Privilege

Overview

  • Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges remotely over the network.

Impact

  • Privilege escalation within the affected environment.

Recommendations

  • Apply available security updates or mitigations from Microsoft.

Reference Links

  1. CVE-2026-83943: Azure API Center Information Disclosure

Overview

  • A vulnerability in Azure API Center allows unauthorized actors to disclose sensitive information over a network.

Impact

  • Exposure of sensitive information to unauthorized attackers.

Recommendations

  • Apply security updates provided by Microsoft to mitigate the vulnerability.

Reference Links

  1. USN-8906-1: Linux Kernel (IBM) Vulnerabilities

Overview

  • Numerous security issues in the Linux kernel affecting multiple architectures and drivers (ARM64, ARM32, MIPS, PowerPC, x86, and others).
  • Key issue: some Arm processors completing broadcast TLB invalidation prematurely, allowing local attackers to write to memory after permission revocation.
  • Flaws across networking drivers, file systems, Bluetooth, USB, audio codecs, and KVM subsystem.

Impact

  • Privilege escalation or system compromise.

Recommendations

  • Apply the security update provided by the vendor immediately.

Reference Links

  1. Quantum Computers Could Break Today’s Encryption – Federal Preparation Required

Overview

  • Quantum computing poses a significant threat to current encryption by potentially breaking cryptographic protections faster than classical computers.
  • NSA and White House initiated transition to quantum-resistant algorithms, targeting completion by 2030–2031.
  • ‘Harvest now, decrypt later’ attacks risk intercepted encrypted data being decrypted as quantum capabilities mature.

Impact

  • Sensitive data (emails, financial transactions, government communications, military systems) could be decrypted. Critical infrastructure, healthcare, banking, and communications face long-term vulnerabilities.

Recommendations

  • Urgent nationwide coordination to assess and mitigate quantum decryption exposure.
  • Accelerate adoption of post-quantum cryptography. Invest in R&D for emerging authentication and encryption methodologies.

Reference Links

  1. Cisco Meraki Security Hardening Release – October 2026

Overview

  • Cisco internal security review identified multiple Meraki vulnerabilities grouped by CWEs. Not known to be actively exploited. No workarounds available.

Impact

  • Critical security impact rating.

Recommendations

  • Apply released Cisco software updates to address the vulnerabilities.

Reference Links

  1. ShinyHunters Extorted Boeing Spin-off Prior to Arrests

Overview

  • Teenager from Jordan, suspected of leading ShinyHunters, detained and cooperating with FBI.
  • Group was extorting Jeppesen ForeFlight (Boeing divested aviation navigation unit).
  • Exploited zero-day PeopleSoft vulnerability (CVE-2026-35273) to steal data from dozens of organizations.
  • FBI recruitment website breached due to failure to patch; exposed sensitive personnel data including medical/psychiatric records.

Impact

  • Theft of sensitive aviation data. Data breaches in higher education, healthcare, government. FBI personnel data exposed.

Recommendations

  • Promptly patch PeopleSoft and other software vulnerabilities. Apply WAF rules and monitor for evasion.
  • Conduct thorough investigations when failure to patch occurs. Reinforce security posture.

Reference Links

  1. Cisco NX-OS Software Python Sandbox Escape

Overview

  • Authenticated local low-privileged attacker can escape the Python sandbox in Cisco NX-OS Software via insufficient input validation, manipulating specific Python interpreter functions.

Impact

  • Arbitrary command execution on the underlying OS with the authenticated user’s privileges. Requires Python execution privileges on the device.

Affected / Fixed Versions

  • Cisco has released software updates addressing this vulnerability.

Recommendations

  • Apply Cisco software updates to remediate. Refer to Cisco documentation on Python execution privileges.

Reference Links

  1. Cisco Nexus 3000/9000 MPLS OAM Unauthenticated RCE

Overview

  • Improper validation when processing MPLS echo-request packets in the NX-OS MPLS OAM feature allows unauthenticated remote attackers to execute arbitrary code with root privileges or cause DoS.

Impact

  • Remote code execution with root privileges. Process crashes and device reloads causing DoS.

Affected / Fixed Versions

  • Cisco has released software updates addressing this vulnerability.

Recommendations

  • Apply released software updates immediately. No workarounds available.

Reference Links

AI SOC

  1. Anthropic’s Cybersecurity Program for Critical Infrastructure and Open Source

Overview

  • Anthropic launched a cybersecurity program pairing Claude AI models, engineers, and threat researchers with security firms (Accenture, Booz Allen, CrowdStrike, Deloitte, and others).
  • Offers free periodic scans of open source projects providing PoC, explanations, and suggested patches (reports may include inaccuracies).
  • Supported U.S. states and infrastructure operators with AI-driven code scanning, incident response, and red teaming.
  • Long-term goal: automate vulnerability triage and patching and develop new security architectures and coding standards.
  • Represents defensive deployment of frontier AI for cybersecurity rather than AI operating a SOC directly.

Impact

  • AI-assisted vulnerability discovery at scale for critical infrastructure and open source ecosystems.

Recommendations

  • Organizations managing critical infrastructure or open source projects should consider participating in AI-powered vulnerability scanning programs.
  • Validate AI-generated vulnerability findings carefully due to potential inaccuracies.

Reference Links

AI Threat Landscape

  1. ‘AgentCorruption’ Puts AWS Environments At Risk With Single Prompt

Overview

  • A vulnerability in AWS Bedrock AgentCore could allow attackers to use one AI chatbot to compromise an entire organization’s AWS environment. The issue has been patched by AWS.

Impact

  • Attackers could take over a full fleet of AI agents within AWS environments using a single prompt.

Recommendations

  • Apply the patch/update for AWS Bedrock AgentCore immediately. Monitor environments for suspicious AI agent behavior.

Reference Links

  1. Anthropic’s Claude Haiku 5.5 Improves Offensive Capabilities and Cybersecurity Safeguards

Overview

  • Claude Haiku 5.5, a budget AI model, demonstrates improved ability to find vulnerabilities and write exploits compared to Haiku 4.5.
  • Incorporates stricter cybersecurity safeguards than Haiku 4.5 but less stringent than advanced models.
  • Offensive capabilities tested against known Chrome V8 engine flaws with safeguards disabled.

Impact

  • Enhanced offensive capabilities in a budget model raises accessibility concerns for potential misuse.

Recommendations

  • Monitor developments in AI models with offensive security capabilities. Implement robust controls around AI model deployment.
  • Stay informed about AI-based attack techniques leveraging vulnerability discovery and exploit generation.

Reference Links

  1. Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

Overview

  • Critical vulnerability in LMCache, an open-source caching solution used by LLM servers such as vLLM.
  • Flaw in LMCache’s multiprocess mode (cache as standalone server via ZeroMQ messaging library) enables unauthenticated remote code execution. No fix released.

Impact

  • Remote unauthenticated code execution on LMCache servers, potentially compromising LLM infrastructure.

Affected / Fixed Versions

  • No fixed version released at time of publication.

Recommendations

  • Consider disabling multiprocess mode or isolating the cache server network until a patch becomes available. Monitor official LMCache channels for updates.

Reference Links

  1. Welcome to the Jungle: What We Found Inside 15,465 Public MCP Servers

Overview

  • MCP (Model Context Protocol) is a universal standard connecting AI models, agents, and IDEs to tools and data. Thousands of public MCP servers have been deployed and integrated into enterprise agent workflows.
  • OX Security discovered critical vulnerabilities in Anthropic’s MCP implementation earlier in 2026.

Impact

  • Critical vulnerabilities in widely deployed MCP servers expose risks across AI agent workflows and ecosystems relying on MCP.

Recommendations

  • Organizations using MCP servers should review their security posture and apply necessary patches and mitigations from vendors.

Reference Links

  1. 5th October Threat Intelligence Report

Overview

  • Phishing attack compromised Arizona’s state court system, exposing personal and case information.
  • Data breaches impacted Times Car (6.6M accounts) and Fakturownia invoicing platform.
  • Ransomware hit South Africa’s air navigation provider affecting aviation weather services.
  • Autonomous AI agents attempted (unsuccessful) hacking against U.S. and Canadian government websites.
  • Malicious Custom GPTs on ChatGPT distributed remote access malware.
  • JadePuffer AI threat actor automated cloud reconnaissance and destructive actions via compromised Azure credentials.
  • Critical vulnerabilities patched in Citrix NetScaler, Cisco Catalyst SD-WAN Manager, Apple CoreGraphics, and GitLab AI Gateway.

Impact

  • Exposure of personal, case, and company data. Aviation service disruption. RCE and unauthorized access via exploited vulnerabilities. AI-assisted automated post-compromise operations.

Recommendations

  • Apply latest patches from Citrix, Cisco, Apple, and GitLab.
  • Monitor for suspicious AI agent activities and unusual cloud operations. Enhance phishing defenses and credential protection.

Reference Links

Ready to get started?

Contact us to arrange a half day
Managed SOC and XDR workshop in Dubai

Ready to get started?

Contact us to arrange a half day Managed SOC and XDR workshop in Dubai

© 2026 HawkEye – Managed CSOC and XDR powered by DTS Solution. All Rights Reserved.
This is a staging environment