Juniper released an out-of-band fix for CVE-2026-21902, a critical remote code execution flaw affecting Junos OS Evolved on PTX Series routers—hardware that underpins ISP backbones and large-scale networks. Organizations running impacted versions should prioritize immediate patching and review exposure of management services to limit blast radius. The severity and placement of PTX in core networks make exploitation particularly consequential.
Source: SecurityWeek
Chrome charts the path to quantum‑safe HTTPS with Merkle Tree Certificates
Google outlined a multi‑year plan to make HTTPS resilient against quantum attacks by moving from traditional X.509 chains to Merkle Tree Certificates (MTCs). The approach drastically reduces bandwidth overhead for post‑quantum algorithms, bakes in transparency by design, and introduces a new Chrome Quantum‑resistant Root Store, with staged rollout and industry collaboration through the IETF’s PLANTS working group.
Source: Google Online Security Blog
Public Google API keys can now expose Gemini AI data
Researchers warn that Google Cloud API keys long treated as non‑sensitive can unlock access to Gemini endpoints, potentially exposing private AI interactions and data. Teams should immediately inventory client‑side code for embedded keys, restrict scopes, rotate any exposed keys, and enforce server‑side proxies and allowlists to prevent direct client access to sensitive Gemini APIs.
Source: Malwarebytes Blog
Botnet resilience via blockchain: Aeternum hides C2 in Polygon smart contracts
The Aeternum loader uses smart contracts on the Polygon blockchain to store and distribute commands, making its command‑and‑control infrastructure decentralized and difficult to disrupt. This technique sidesteps traditional takedown paths and complicates detection, underscoring the need for behavior‑based controls and threat intel tuned to Web3 abuse patterns.
Source: SecurityWeek
Metasploit adds exploits for Ollama RCE, BeyondTrust PRA/RS, and Grandstream VoIP
Rapid7’s latest Metasploit release introduces multiple high‑impact modules, including Ollama path traversal to unauthenticated RCE (CVE-2024-37032), BeyondTrust PRA/RS command injection (CVE-2026-1731), and Grandstream GXP1600 unauth RCE (CVE-2026-2329) with credential theft and SIP interception post‑modules. The arrival of turnkey exploits raises the urgency to patch, harden exposed services, and add detections for newly supported techniques and payloads.
Source: Rapid7
900+ Sangoma FreePBX systems still web‑shell compromised after command injection attacks
More than 900 Internet‑exposed FreePBX instances remain infected with web shells following exploitation of a post‑authentication command injection in the endpoint manager interface. Affected operators should patch, hunt for persistence (web shells and rogue cron jobs), rotate credentials and keys, and restrict administrative interfaces from public access.
Source: SecurityWeek
12 million exposed .env files reveal widespread secrets leakage
A large‑scale scan found 12 million IPs exposing .env files, often leaking API keys, database passwords, and cloud credentials due to basic misconfigurations. Teams should audit web server rules, block directory/file listings, remove environment files from deploy artifacts, and rotate any secrets found to be exposed; CI/CD guardrails can prevent these leaks from reaching production.
Source: Security Affairs
You May Also Be Interested In...
Android 17 second beta expands privacy controls for contacts, SMS and local networksEuropol goes after The Com’s ransomware and extortion networks
Trend Micro patches critical Apex One bugs