THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Actively exploited Cisco SD‑WAN zero‑day grants unauthenticated admin access (CVE-2026-20127)

Cisco Talos reports active exploitation of an authentication bypass in Cisco Catalyst SD‑WAN Controller/Manager that lets remote, unauthenticated attackers obtain administrative privileges. Adversaries add rogue peers and can chain post-exploitation steps for root access; CISA has issued an emergency directive urging immediate patching and review of peering events in logs. Organizations should upgrade to fixed releases without delay and validate unexpected control-plane connections.

Source: Cisco Talos


Google and partners disrupt PRC‑linked “UNC2814” espionage using Google Sheets as C2 (GRIDTIDE)

Google Threat Intelligence, Mandiant, and partners dismantled a long‑running campaign that breached 53 organizations across 42 countries, primarily in telecoms and government. The actor abused legitimate Google Sheets API calls as command‑and‑control for the GRIDTIDE backdoor to blend into normal SaaS traffic; Google terminated attacker projects/accounts and released IOCs and hunting guidance. Defenders should monitor non‑browser use of Sheets API endpoints and investigate suspicious service accounts.

Source: Google Threat Intelligence


Critical Claude Code flaws enabled RCE and API key theft via malicious repo configs

Check Point researchers disclosed CVE‑2025‑59536 and CVE‑2026‑21852 in Anthropic’s Claude Code that allowed remote code execution and exfiltration of API keys by abusing repository‑level configurations. The attack could trigger simply by cloning and opening an untrusted project, leveraging Hooks, MCP integrations, and environment variables to bypass trust controls and redirect authenticated traffic. Findings underscore a growing AI supply‑chain risk where dev tooling becomes an execution vector.

Source: Check Point Blog


CISA adds actively exploited FileZen command injection bug to KEV (CVE-2026-25108)

CISA placed an OS command injection flaw in Soliton Systems’ FileZen secure file transfer solution on its Known Exploited Vulnerabilities catalog after the vendor confirmed in‑the‑wild attacks and multiple damage reports. Given speculation around recent ransomware activity in Japan, organizations should patch immediately, remove public exposure, and review FileZen logs for suspicious command execution.

Source: Help Net Security


SolarWinds Serv‑U patches four critical RCE‑level bugs; update ASAP

SolarWinds fixed four critical vulnerabilities in Serv‑U that could allow attackers to create system admin users and/or execute code with elevated privileges. Serv‑U is widely deployed on Windows and Linux for FTP/SFTP/HTTP(S) transfers, making timely patching essential—especially on internet‑exposed instances. Restricting admin access and monitoring for anomalous account creation are recommended until updates are applied.

Source: Help Net Security


US sanctions Russian exploit broker Operation Zero amid crackdown on zero‑day trade

The US sanctioned Operation Zero, a Russian exploit broker that acquired eight zero‑days from a former US defense contractor executive now jailed for his role. The action signals increased pressure on the commercial exploit market and raises compliance exposure for entities interacting—directly or indirectly—with sanctioned brokers. Security teams should assess vendor/supplier ties and update sanctions screening.

Source: SecurityWeek


Ex‑L3Harris (Trenchant) executive gets 87 months for selling cyber‑exploit trade secrets to Russia

Peter Williams was sentenced to more than seven years in prison after pleading guilty to stealing and selling sensitive cyber‑exploit trade secrets to a Russian broker, causing an estimated $35 million in losses. The court also ordered three years of supervised release and forfeitures, including a $1.3 million money judgment and crypto. The case highlights insider risk and the need for strict controls around exploit research and IP access.

Source: Help Net Security


You May Also Be Interested In...

Wireshark 4.6.4 resolves dissector flaws, plugin compatibility issue

Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware

Your MRI is Online: The Hidden Risks of Exposed DICOM Servers in UK Healthcare

Cybersecurity — February 26, 2026 | Briefing24