Cisco released fixes for CVE‑2026‑20045, a remote code execution flaw in Unified Communications products that is already being exploited in the wild. Organizations should prioritize emergency patching and assume exposure where UC services are Internet‑reachable, monitoring for anomalous process launches and configuration changes post‑update.
Source: SecurityWeek
FortiGate firewalls hit by surge of automated configuration hijacks
Threat actors are bypassing FortiCloud SSO protections to create persistence accounts, alter device settings, and exfiltrate configurations from FortiGate appliances. The attacks mirror recent clusters seen since late 2025; defenders should audit admin accounts, review recent config diffs, rotate credentials, and enable out‑of‑band change alerts.
Source: SecurityWeek
SmarterMail auth bypass exploited two days after patch release
An authentication bypass in SmarterMail (WT‑2026‑0001) is under active exploitation, with attackers obtaining admin access shortly after vendor Build 9511 shipped. Admins should update immediately to the latest build, rotate credentials and API keys, and review admin/audit logs for suspicious logins and rule changes.
Source: SecurityWeek
Pwn2Own Automotive exposes 76 zero‑days across infotainment and EV chargers
Researchers earned over $1M for compromising systems from Tesla, Sony, Alpine and multiple EV charging platforms, disclosing 76 vulnerabilities over three days. The results highlight systemic weaknesses in automotive software supply chains and the urgency for rigorous SBOMs, hardening, and rapid patch pipelines for connected vehicles.
Source: SecurityWeek
Energy sector targeted by multi‑stage AiTM phishing and BEC using SharePoint
Microsoft warns that attackers are abusing trusted SharePoint file‑sharing to deliver adversary‑in‑the‑middle phishing, harvest credentials, and establish persistence with inbox rules before launching BEC. The campaign uses “NEW PROPOSAL – NDA” lures from compromised partners, reinforcing the need for conditional access, MFA hardening, and tenant‑to‑tenant trust controls.
Source: The Hacker News
North Korea‑linked KONNI pivots to developers with AI‑assisted lures
Check Point reports KONNI’s latest campaign targets software developers and engineering teams in blockchain/crypto projects, using project‑like documentation and AI‑enhanced tradecraft. The shift from diplomatic targets to technical staff with infrastructure access underscores the need for developer‑focused controls, including code signing, workstation hardening, and least‑privilege secrets access.
Source: Check Point Blog
Critical GNU InetUtils telnetd bug enables remote auth bypass to root
A newly disclosed flaw (CVE‑2026‑24061) in GNU InetUtils telnetd allows remote attackers to bypass login and gain root on affected systems — an issue lingering for nearly 11 years. While telnetd is legacy, its presence in older or embedded environments makes immediate removal or patching, and network‑level blocking of telnet, a priority.
Source: The Hacker News
You May Also Be Interested In...
GitLab patches critical 2FA bypass vulnerabilityZoom addresses critical remote code execution vulnerability
Malicious PyPI package impersonates SymPy to deploy XMRig miner