Security researchers at WatchTowr are observing widespread exploitation attempts against Cisco Catalyst SD-WAN devices vulnerable to CVE-2026-20127 from numerous unique IP addresses. Organizations should prioritize vendor fixes, reduce internet exposure of management services, and increase telemetry around edge devices to detect exploitation attempts.
Source: SecurityWeek
Critical Nginx UI flaw (CVE-2026-27944) exposes server backups without auth
A CVSS 9.8 vulnerability in Nginx UI allows unauthenticated attackers to download and decrypt full server backups, potentially exposing sensitive configurations and secrets when the management interface is publicly reachable. Immediate upgrades and removal of public exposure are advised, alongside credential rotation and rekeying for any affected systems.
Source: Security Affairs
Chinese threat actor targets Asian critical infrastructure with web exploits and Mimikatz
Palo Alto Networks Unit 42 details a years-long campaign against high-value organizations across South, Southeast, and East Asia, including aviation, energy, government, law enforcement, pharmaceutical, technology, and telecom sectors. Attackers leveraged web server exploits for initial access and Mimikatz for credential theft, underscoring the urgency of patching internet-facing apps and enforcing strong credential protections.
Source: TheHackerNews
Chrome extensions turn malicious after ownership transfer, enabling code injection and data theft
Two Google Chrome extensions reportedly became malicious following an ownership change, giving attackers a path to inject arbitrary code, deliver malware to downstream users, and harvest sensitive data. Enterprises should audit extension inventories, enforce allowlists via browser policies, and scrutinize unexpected permission or publisher changes.
Source: TheHackerNews
MuddyWater deploys Dindoor malware using the Deno runtime to target U.S. networks
SOCRadar reports Iran-aligned APT MuddyWater using a new strain dubbed Dindoor that leverages the Deno runtime to execute JavaScript/TypeScript outside the browser. The atypical runtime can evade detections tuned to more common scripting engines; defenders should monitor for Deno binaries, unusual script executions, and anomalous outbound C2 from developer tool paths.
Source: SocRadar
How agentic AI is reshaping the enterprise threat model
KrebsOnSecurity explores how autonomous AI assistants with access to local files, credentials, and cloud services are shifting security priorities—blurring the lines between data and code, trusted co-worker and insider threat. As adoption accelerates, organizations need least-privilege sandboxes, human-in-the-loop approvals for sensitive actions, and robust, immutable action logging.
Source: KrebsOnSecurity
Open-source ‘Sage’ adds an ADR safety layer between AI agents and the OS
Sage inserts a mediation layer between autonomous AI agents and operating system operations—intercepting shell commands, network fetches, and file writes for review before execution. Positioned as Agent Detection & Response (ADR), the tool brings EDR-like guardrails to machine-initiated actions and offers a practical path to pilot agentic workflows more safely.
Source: Help Net Security
You May Also Be Interested In...
FBI is investigating breach that may have hit its wiretapping toolsMassive GitHub malware operation spreads BoryptGrab stealer
Submarine cables move to the center of critical infrastructure security debate