Fortinet reports attacker persistence that began through CI/CD compromise, including exposed Jenkins credentials, followed by AWS escalation and activity consistent with a Redshift breach. The incident underscores how build pipelines and automation credentials can become stepping stones into cloud data stores—often before defenders notice abnormal query or access patterns. The key takeaway for teams: treat CI/CD secrets and cloud data access telemetry as first-class detection priorities.
Source: Fortinet
Amazon Q Developer (CVE-2026-12957): malicious repositories could trigger command execution and cloud credential theft
Researchers and reporting indicate that CVE-2026-12957 (CVSS 8.5) can let attackers execute arbitrary commands and steal cloud credentials by abusing how Amazon Q handles MCP-related configurations. The attack path described is operationally realistic: a developer opens a malicious repository, the assistant trusts the workspace, and automation does the rest. Organizations should urgently patch, and also add guardrails limiting what AI coding assistants can run from untrusted project configuration.
Source: Help Net Security
CISA adds PTC Windchill and FlexPLM flaw (CVE-2026-12569) to KEV—web shells keep arriving
CISA has added a critical remote code execution vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The coverage is a reminder that industrial and enterprise product-management stacks are increasingly targeted for initial access, then weaponized for persistence such as web shells. The practical message: validate exposure, patch immediately, and hunt for web shell indicators where internet-facing access exists.
Source: Security Affairs
DirtyClone (CVE-2026-43503): a new Linux kernel escalation in the DirtyFrag family pushes more root risk to patch queues
Security researchers describe “DirtyClone” as another DirtyFrag-class Linux kernel privilege escalation that can silently rewrite executables in memory, leaving minimal forensic traces. A working exploit walkthrough was published quickly, which raises the probability of opportunistic exploitation in the wild—especially on fleets with slower patching. Teams should prioritize kernel patching and validate that mitigations and reboot requirements are met.
Source: Security Affairs
Polymarket $3M+ crypto theft: compromise of a third-party vendor enabled malicious code injection
Polymarket confirmed attackers stole funds from some users after adversaries injected malicious code via a compromised third-party vendor. This case reinforces a consistent theme for 2026 incident response: supply-chain and third-party risks often bypass traditional perimeter controls, but still translate into direct customer impact. The action item is clear—tighten vendor security requirements, monitor for web integrity changes, and enforce least-privilege for integrations.
Source: SecurityWeek
Russia-Linked pressure tactics: Signal compromise attempts now focus on stealing backup recovery keys
The FBI and CISA updated guidance indicating Russian intelligence phishing efforts increasingly coax targets into handing over Signal Backup Recovery Keys. Possessing the recovery key can enable account restoration, private message history access, and continued account takeover—making this a high-value credential theft scenario. Defenders should treat recovery keys like passwords: protect them, educate users against “backup” social engineering lures, and monitor for related account behaviors.
Source: The Hacker News
NO FAKES Act advances: policy momentum for deepfake and synthetic media “likeness” protections
The U.S. Senate Judiciary Committee unanimously approved the NO FAKES Act, which would create federal protections against unauthorized AI-generated replicas of individuals’ voices and images. While framed around privacy and identity rights, the bill has security relevance: enterprises will increasingly need verification controls to prevent scams that use synthetic media to authorize transactions or impersonate leadership. Expect deeper scrutiny from boards, compliance teams, and regulators as synthetic identity risks move from “emerging” to “material.”
Source: TechTarget
You May Also Be Interested In...
Mystery hackers use novel SharkLoader dropper against governments and software developers
Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials
ZeroTier Quantum RC2 brings post-quantum security closer to general availability