View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

CISA Warns of Exploited Cisco Secure Firewall Management 0-Day

๐Ÿšจ ACTIVE EXPLOITATION

  • CISA Warns of Exploited Cisco Secure Firewall Management 0-Day CVE-2026-20316 CVE-2026-20316
    A hard-coded credential vulnerability in Cisco Secure Firewall Management Center is actively exploited.
    • Applies to Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center
    • Vulnerability CVE-2026-20316 involves a hard-coded password allowing unauthenticated low-privilege login
    • Attackers can remotely access sensitive firewall configurations, policies, and logs
    • Exploitation enables lateral movement and privilege escalation in targeted networks
    • CISA confirms active exploitation but no confirmed ransomware campaigns yet
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ’ฅ BREACHES & INCIDENTS

  • ShinyHunters claims breach of Brinks Home, threatens to leak 4.9M records
    Hackers breached Brinks Home and threaten to leak stolen customer and employee data.
    • Applies to Brinks Home, a residential security company serving 1M+ customers in US, Canada, Puerto Rico
    • Attack compromised over 4.9 million Salesforce records including customer PII and 3.8 million support chat logs
    • Breach occurred via Microsoft Entra voice phishing (vishing) social engineering attack on July 13, 2026
    • Threat actors stole employee data including names, emails, job titles, and phone numbers
    • Brinks Home detected breach on July 20, engaged forensics experts, and confirmed no impact on alarm systems
      ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ”“ CVEs & KEV

  • CVE-2026-12940 โ€” IBM Langflow OSS 1.0.0-1.10.1 โ€” CVSS 9.8 โ€” unauthenticated remote code execution via environment variable injection [KEV]

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • IBM Langflow OSS 1.0.0-1.10.1 vulnerable to unauthenticated RCE via MCP stdio launcher CVE-2026-12940
    IBM Langflow OSS versions 1.0.0 through 1.10.1 have an unauthenticated remote code execution vulnerability.

    • Applies to IBM Langflow OSS versions 1.0.0 through 1.10.1
    • Vulnerability is unauthenticated remote code execution via environment variable injection
    • Exploited through the MCP (Model Context Protocol) stdio launcher component
    • Root cause is incomplete environment variable blocklist missing SHELLOPTS, BASHOPTS, and PS4
    • CVE-2026-12940 with CVSS 9.8, CWE-78 OS Command Injection
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Generic TV Streaming Sticks Used for Ad Fraud and Residential Proxy Abuse
    Generic TV streaming sticks are exploited to commit ad fraud and operate residential proxies.

    • Applies to generic Android-based TV streaming sticks, notably the H96 brand
    • Devices spoof themselves as mobile phones to click ads on AI-generated websites
    • When TV is on, devices act as residential proxies renting out users' internet connections
    • When TV is off, devices perform resource-intensive ad fraud tasks via Blockly-coded routines
    • Operation traced to Zhejiang Fengwo IoT Technology Ltd, linked to ad fraud and proxy networks
      ๐Ÿ“Ž Coverage: krebsonsecurity.com ยท ๐Ÿ‘ via Krebs on Security, @briankrebs@infosec.exchange (+2)

๐Ÿ“‹ ADVISORIES

  • VMware patches five vulnerabilities including three critical flaws enabling auth bypass and VM escapes
    Broadcom fixed five VMware vulnerabilities including critical auth bypass and VM escape flaws.
    • Applies to VMware vCenter, ESX, Workstation, Fusion, Cloud Foundation, vSphere, Telco Cloud Platform, and Telco Cloud Infrastructure
    • Critical flaws include authentication bypass in VMware Directory Service and directory traversal in vCenter Syslog server
    • VMXNET3 virtual network adapter flaw allows VM escape to ESX host via out-of-bounds write
    • Other issues include out-of-bounds read causing info disclosure or DoS, and insufficient logging in ESX
    • Exploits require network access or local admin in VM; patches released for affected versions including vCenter 9.1.0.0300+ and ESXi 9.1.0.0200+
      ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check