Ivanti disclosed two pre‑auth code injection flaws in Endpoint Manager Mobile that allow remote arbitrary command execution, with exploitation observed before disclosure. CISA added CVE‑2026‑1281 to the KEV catalog with a 3‑day remediation deadline, and a public PoC is available—raising mass exploitation risk. Organizations should apply the vendor’s RPM patches on an emergency basis, hunt for hits to the “/mifs/c/(app|aft)store/fob/” endpoints, and restrict access until updated.
Source: Rapid7
Russia-linked Sandworm bricked ICS devices in coordinated strike on Polish energy sites
Investigators say Sandworm/Electrum targeted communication and control systems across more than 30 sites, leaving industrial devices inoperable. The incident underscores persistent OT exposure to basic weaknesses and the cascading impact when operator visibility is lost. Asset inventory, network segmentation, default-credential eradication, and tested incident playbooks remain critical for grid resilience.
Source: SecurityWeek
ShinyHunters expands to vishing-fueled SaaS data theft and aggressive extortion
Mandiant reports clusters tied to ShinyHunters are impersonating IT, driving targets to credential-harvesting sites, enrolling rogue MFA devices, and raiding cloud apps like SharePoint, Slack, Salesforce, and DocuSign. Operators have escalated to harassment and DDoS to pressure victims, while deleting security emails to hide traces. This is not a vendor flaw—shift to phishing‑resistant MFA (FIDO2/passkeys), harden help‑desk workflows, and tighten IdP and SaaS logging and detections.
Source: Google Cloud Threat Intelligence
Report finds 175,000 internet‑exposed Ollama AI servers at risk of abuse
Researchers identified a vast population of exposed Ollama instances—23,000 of which consistently accounted for most observed activity—potentially enabling model misuse, data exfiltration, or pivoting. Administrators should require authentication, restrict network access, and avoid exposing management endpoints to the public internet.
Source: SecurityWeek
Hugging Face abused to deliver Android RAT via malicious apps
Attackers lured users to Android apps that fetched a remote payload hosted in a Hugging Face repo, turning the AI ecosystem into a malware delivery channel. The campaign highlights the risks of sideloaded apps and supply‑chain trust in public model/code repositories. Mobile fleets should disable unknown sources and monitor DNS/HTTP egress for unusual repository fetches.
Source: SecurityWeek
OpenSSL fixes 12 flaws, including a high‑severity RCE—update widely
The OpenSSL project patched a dozen issues spanning memory safety and parsing problems, with one remote code execution bug rated high severity. Given OpenSSL’s ubiquity in servers, containers, appliances, and SDKs, organizations should fast‑track updates across distributions and vendor firmware to reduce exposure.
Source: SC Media
Ex‑Google engineer convicted for stealing AI trade secrets for China
A federal jury found Linwei “Leon” Ding guilty on seven counts of economic espionage and seven counts of trade‑secret theft tied to Google’s AI technology, exposing ongoing insider risks around high‑value models and tooling. The case reinforces the need for least‑privilege access, source‑code governance, DLP, and robust insider‑threat programs across AI R&D.
Source: Help Net Security
You May Also Be Interested In...
White House scraps ‘burdensome’ software security rules
Google disrupts IPIDEA residential proxy network used in cybercrime
CISA issues insider threat guidance amidst AI misuse concerns