Check Point warns of active exploitation of a critical authentication bypass impacting Remote Access VPN and Mobile Access deployments that still use the deprecated IKEv1 protocol. A certificate-validation logic flaw lets attackers establish a VPN session without a valid password; observed intrusions have targeted a few dozen orgs, with one linked to a Qilin ransomware affiliate. Organizations should immediately disable IKEv1, apply the vendor hotfix, and review VPN logs for anomalous connections.
Source: Check Point Blog
Unpatched Cisco SD-WAN Manager 0‑day (CVE-2026-20245) under active attack
A new flaw in Cisco Catalyst SD‑WAN Manager enables root-level command execution and is being actively exploited in the wild, with no patch currently available. Exposure of management interfaces dramatically increases risk; organizations should restrict network access, apply interim mitigations, and monitor for suspicious admin activity until fixes ship.
Source: CyberExpress
SolarWinds Serv‑U vulnerability exploited in the wild
SolarWinds patched a Serv‑U flaw that unauthenticated attackers can trigger via crafted POST requests to crash the service, and exploitation is already occurring. Admins should update immediately and review internet exposure and WAF rules to blunt exploitation attempts.
Source: SecurityWeek
Extortion crew UNC3753 blends vishing and physical intrusions
Mandiant details a financially motivated campaign targeting dozens of US legal, financial, and professional services firms between January and May 2026. The group used voice phishing, social engineering, and physical tactics to steal data for extortion, underscoring the need for strict identity verification, SIM‑swap protections, and incident response drills for blended attacks.
Source: The Hacker News
Meta admits 20,000 Instagram accounts hijacked via AI‑assisted recovery tool abuse
Meta says attackers abused its AI‑powered High Touch Support account recovery flow to reset passwords and take over more than 20,000 Instagram accounts. The company has notified authorities; impacted users should enable strong MFA, rotate credentials, and watch for further social engineering tied to compromised profiles.
Source: SecurityWeek
China‑nexus VerdantBamboo deploys BSD variant of BRICKSTORM on Linux appliances
Volexity tracks VerdantBamboo using a BSD build of the BRICKSTORM backdoor, plus PLENET (aka GRIMBOLT) and AGENTPSD, to target Linux systems and network appliances. The campaign highlights continued focus on edge devices; defenders should harden and monitor appliances, apply firmware updates, and scrutinize egress traffic for covert C2.
Source: The Hacker News
VS Code adds 2‑hour auto‑update delay for extensions to curb supply‑chain risk
Microsoft will delay automatic updates to VS Code extensions by two hours after publication, giving time to detect and yank malicious or compromised releases. Security teams should pair this with publisher verification, extension allowlists, and pinned versions for high‑risk environments.
Source: The Hacker News
You May Also Be Interested In...
OpenAI Rolling Out ChatGPT Account Security Controls
52% of direct-to-IP threats are missing from intelligence feeds
Cybercriminals create 19,000 FIFA-themed domains ahead of 2026 World Cup