View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Mini Shai-Hulud worm defeats SLSA provenance across npm and PyPI

🚨 ACTIVE EXPLOITS & INCIDENTS

  • CVE-2026-20182: Critical Cisco Catalyst SD-WAN Auth Bypass Under Active Exploitation (Tenable) CVE-2026-20182 (CVSS 10.0) is a critical authentication bypass in Cisco Catalyst SD-WAN Controller/Manager actively exploited by a sophisticated threat actor (UAT-8616) since 2023. Multiple additional threat clusters have joined exploitation following public PoC release. Patches are available; CISA mandates immediate remediation. All SD-WAN deployments must prioritize patching and monitoring for related IOCs.

🔓 VULNERABILITIES & CVEs

🕵️ THREAT RESEARCH & DEEP DIVES

  • Verizon DBIR 2026: Vulnerability Exploitation Surges as Leading Initial Access Vector (Tenable) Vulnerability exploitation accounts for 31% of breaches, overtaking phishing and credential theft. Median patching time increased by 11 days year-over-year. AI-driven vulnerability discovery and exploitation accelerate risk exposure. Organizations must adopt continuous attack surface management and automated remediation orchestration to keep pace.

📋 VENDOR BULLETINS & LAW ENFORCEMENT

📰 LESSER-KNOWN / UNDER-REPORTED

(No significant under-reported items this cycle.)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check