Amazon researchers and others report the Interlock ransomware group abused a maximum‑severity remote code execution flaw (CVE-2026-20131) in Cisco Secure Firewall Management Center as a zero‑day starting in late January—over a month before public disclosure. Organizations should patch immediately, restrict management plane exposure, and scrutinize FMC access logs for anomalous admin actions or new users.
Source: SecurityWeek
CISA: SharePoint RCE (CVE-2026-20963) is under active exploitation
Microsoft patched a remote code execution bug in SharePoint in January, but CISA has now confirmed in-the-wild exploitation and added it to the KEV catalog. The flaw stems from deserialization of untrusted data and can enable unauthorized code execution; patch eligible SharePoint instances, prune exposed endpoints, and review for suspicious child processes from w3wp.exe.
Source: SecurityWeek
International operation disrupts IoT botnets behind record DDoS attacks
The U.S. Justice Department, with partners in Canada and Germany, dismantled infrastructure for four massive IoT botnets—Aisuru, Kimwolf, JackSkid, and Mossad—that together compromised more than 3 million devices and powered record‑smashing DDoS campaigns. Enterprises should harden edge and consumer‑grade gear by changing default creds, disabling UPnP, and segmenting untrusted IoT networks.
Source: KrebsOnSecurity
DarkSword iOS exploit kit targets unpatched iPhones in multi‑actor campaigns
Researchers uncovered “DarkSword,” a full‑chain iOS exploit kit reportedly used since November 2025 by multiple state‑linked operations and commercial surveillance vendors. The kit strings together multiple vulnerabilities—including zero‑days—to silently compromise devices; update iPhones to the latest iOS immediately and enable background security responses wherever supported.
Source: Help Net Security
CISA urges immediate hardening of endpoint management after destructive Intune abuse
Following the Stryker incident—where attackers abused Microsoft Intune to wipe roughly 200,000 systems and reportedly exfiltrated 50 TB—CISA is warning that foreign cyber activity tied to Middle East conflicts is spilling into U.S. operations. Lock down EMM/MDM by enforcing MFA and least privilege for admins, restricting console access, enabling change auditing, and validating all mass‑action workflows.
Source: Help Net Security
EDR killers now standard in ransomware playbooks
ESET research tracked nearly 90 tools designed to disable EDR before encryption, with many using BYOVD techniques to abuse signed vulnerable drivers. Defenders should enable kernel‑mode protections (e.g., HVCI/driver blocklists), enforce EDR tamper protection, limit admin privileges, and monitor for security service stoppage and driver loading anomalies.
Source: Help Net Security
Critical Langflow flaw exploited within hours; unauthenticated RCE risk for AI apps
A newly disclosed Langflow vulnerability was weaponized mere hours after going public, enabling unauthenticated remote code execution when attacker‑supplied flow data is used in public flows. Patch immediately, restrict public exposure of Langflow instances, rotate credentials/secrets accessed by affected flows, and review execution logs for suspicious commands.
Source: SecurityWeek
You May Also Be Interested In...
Google limits Android accessibility API to curb malware abuse
Russian hackers exploit Zimbra flaw to breach Ukrainian maritime agency
Thousands of Magento sites hit in ongoing defacement campaign