🚨 ACTIVE EXPLOITS & INCIDENTS
- Progress confirms ShareFile zero-day behind Storage Zone shutdown - Progress Software confirmed a high-severity zero-day exploited in the wild forced emergency shutdown of ShareFile Storage Zone Controllers. Security updates have been released; immediate patching is critical.
- LastPass, Bitwarden users targeted with fake security alerts - Ongoing phishing campaign uses spoofed security notices to lure password manager users to malicious sites. Increased vigilance on phishing vectors targeting credential vault users is advised.
- US Treasury sanctions First VPN Service and affiliates for aiding ransomware gangs - Sanctions target 1VPNS and operators linked to ransomware obfuscation tools (“cryptors”). This impacts threat actor infrastructure and may disrupt ransomware operations relying on these VPN services.
🔓 VULNERABILITIES & CVEs
- Seven severe VMware Avi Load Balancer vulnerabilities patched - Flaws enable authentication bypass, RCE, privilege escalation, and directory traversal. Immediate patching advised to prevent lateral movement and takeover.
- CISA: ABB T-MAC Plus critical vulnerabilities - Multiple CVEs (CVE-2025-14771 to CVE-2025-14774) with CVSS up to 9.9 affecting ABB T-MAC Plus 4.0-24. Issues include authorization bypass and XSS, risking critical manufacturing infrastructure.
- CISA: Rockwell Automation 1715-AENTR EtherNet/IP Adapter missing auth - CVE-2026-10577 (CVSS 10) allows unauthorized file access and memory modification, impacting energy and water sectors globally. Urgent patching required.
- CISA: ABB Ability Edgenius Linux kernel privilege escalation - CVE-2026-31431 enables local or containerized root escalation on ABB Ability Edgenius versions <3.2.4.1. Critical for industrial control environments.
- Fortinet FortiOS buffer over-read vulnerabilities - Affecting FortiOS 7.2 to 7.6.2 and FortiProxy variants, these flaws allow authenticated attackers to leak device memory. Multiple related CVEs (e.g., CVE-2025-43892) and XSS (CVE-2026-23573) also disclosed. Patch immediately.
- Sonatype Nexus Repository Manager insufficient entropy in API key generation - Allows remote unauthorized access to repository operations. CVSS 8+; patch or mitigate access to Nexus instances.
- Easy!Appointments SSRF in CalDAV connection test - Versions prior to 1.6.0 vulnerable to server-side request forgery, enabling internal network reconnaissance or pivoting. Also multiple authorization bypass and data exposure issues in Easy!Appointments.
- openSIS Classic 9.3 authenticated path traversal - Allows reading arbitrary files via sent-mail attachment download. Patch to prevent data leakage in education sector deployments.
- svgdotjs svg.js prototype pollution - Vulnerability in EventTarget.on function may lead to remote code execution or denial of service in npm package svg.js <=3.2.5. Update dependencies.
- Cloudflare quiche unbounded path event queue growth - Memory exhaustion via client migration events, enabling DoS attacks on QUIC connections. Patch recommended for affected quiche versions.
📋 VENDOR BULLETINS & ADVISORIES
- AWS WAF Bot Control for authenticating legitimate AI agent traffic - New AWS capability to distinguish legitimate AI-driven bot traffic from malicious actors in multi-tenant environments, improving bot management and reducing false positives.
- CISA: ABB Advant Master Online Builder uncontrolled search path element - CVE-2025-13162 (CVSS 4.4) patched to prevent potential code execution via manipulated search paths. Industrial control systems should update promptly.
🕵️ THREAT RESEARCH & DEEP DIVES
- Picus TTP chaining for exploitability validation - New methodology to assess vulnerability exploitability by validating attack techniques without running live exploits, reducing risk during testing of critical systems.
- ClickFix attack ecosystem expands, evading AV/EDR - Attack vector available for rent at scale, bypassing traditional defenses; YARA rules currently best detection method. Security teams should update detection strategies accordingly.
- Source review of 200+ self-hosted multi-tenant AI/SaaS apps reveals 78 cross-tenant data leaks - Highlights widespread tenant isolation failures in popular apps, raising urgent concerns for SaaS security in multi-tenant environments.
📰 LESSER-KNOWN / UNDER-REPORTED
- Cloudflare introduces EDE 33 DNS error code after .AL DNSSEC rollover failure - New DNS error code signals DNSSEC validation bypass, improving client-side visibility into DNS security failures.
- Cursor code editor executes local git.exe files blindly - Local code editor vulnerability allows arbitrary execution of git.exe files within source repos, posing a risk for supply chain and developer environment compromise.
- Telegram’s t.me short URL domain restored after OFAC compliance suspension - Domain suspended likely due to US Treasury sanctions on VPN providers linked to ransomware infrastructure, causing temporary disruption of Telegram short links.