🚨 ACTIVE EXPLOITS & INCIDENTS
- Russia Used Cellebrite on Jailed Activist's iPhone Months After Sales Cutoff — The Hacker News Russian authorities exploited Cellebrite UFED forensic tools to access the iPhone of detained activist Andrey Pivovarov in June 2021, three months after Cellebrite officially ceased sales to Russia and Belarus. Citizen Lab’s findings link forensic traces on the device with official Russian sources, highlighting ongoing unauthorized use of forensic tech despite sanctions.
- $3 Million Reportedly Stolen in Polymarket Hack — SecurityWeek Decentralized prediction market Polymarket suffered a breach via a third-party vendor compromise, resulting in approximately $3 million stolen from user accounts. This incident underscores supply chain risk in DeFi platforms and the need for enhanced vendor security controls.
🔓 VULNERABILITIES & CVEs
- First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild — SecurityWeek CISA added CVE-2026-12569 (remote code execution) affecting PTC Windchill to its Known Exploited Vulnerabilities catalog after confirmed active exploitation. Organizations using Windchill should prioritize patching to mitigate risk of full system compromise.
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution — CIS Advisories Several critical Chrome vulnerabilities have been disclosed, with the most severe enabling arbitrary code execution under the logged-in user context. Exploitation could lead to privilege escalation, data manipulation, or persistence. Immediate patching is recommended, especially for users with elevated privileges.
🕵️ THREAT RESEARCH & DEEP DIVES
- Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks — The Hacker News Google Threat Intelligence Group uncovered a new .NET backdoor named STOCKSTAY deployed by Russian APT Turla targeting Ukrainian government and military entities, as well as organizations linked to Italian foreign policy. The backdoor shows ongoing development and sophisticated espionage capabilities.
- Russian APT Deploys ‘StockStay’ Backdoor Against Ukrainian Targets — SecurityWeek Further analysis confirms Turla’s use of STOCKSTAY in active espionage campaigns against Ukraine. The backdoor’s modular design and stealth features represent a significant escalation in Turla’s toolkit, demanding enhanced detection and response measures.
- New Enterprise-Ready MCP Specification Brings New Security Challenges — SecurityWeek The revamped Model Context Protocol (MCP) shifts critical security responsibilities from the protocol itself to developers and platform operators, increasing the risk of misconfigurations and vulnerabilities. Security teams should review MCP implementations closely to mitigate emerging risks.
- Cyber Resilience Act – Part I — Compass Security The EU’s Cyber Resilience Act introduces mandatory cybersecurity requirements for digital products sold in the EU, covering IoT devices, OSes, and standalone software. This regulation will impact product security lifecycles and compliance strategies for vendors and integrators.