Security Intel Feed
Cyber Hose
Page 44 of 44
Vulnerabilities & CVEs
Cisco Catalyst SD-WAN CVSS 10 auth bypass under active exploitation
Read digest- Cisco Catalyst SD-WAN auth bypass under active exploitation — A CVSS 10.0 authentication bypass in Catalyst SD-WAN Controller and Manager (CVE-2026-20182) has been exploited by UAT-8616 since 2023; CISA mandates immediate remediation.
- Lawmakers demand answers on the CISA GovCloud data leak — Congress is pressing CISA for accountability after a contractor published AWS GovCloud keys and sensitive agency secrets on public GitHub.
- Mini Shai-Hulud worm compromises 170+ npm and PyPI packages — The self-propagating worm bypassed SLSA Build Level 3 provenance attestations to steal developer and cloud credentials, reaching OpenAI and Mistral AI environments.
- Microsoft May Patch Tuesday: 118 CVEs, no zero-days — Microsoft patched 118 CVEs (16 critical) across Azure, .NET, M365 and Windows, with no zero-days exploited in the wild this cycle.
- CrowdStrike leads Gartner's first threat-intel Magic Quadrant — CrowdStrike was named a leader in Gartner's first Magic Quadrant for Cyberthreat Intelligence Technologies alongside new AI-powered detection tools.
Active Exploits & Incidents
Trend Micro Apex One zero-day exploited in the wild, no workaround
Read digest- Trend Micro Apex One zero-day exploited in the wild — A directory traversal flaw in on-premise Apex One (CVE-2026-34926) is under active exploitation and now in CISA's KEV catalog; patch immediately — no workaround exists.
- Three max-severity Ubiquiti UniFi OS RCE flaws — Three CVSS 10.0 remotely exploitable, unauthenticated vulnerabilities were patched in UniFi OS — high exposure given UniFi's prevalence in SMB and enterprise networks.
- Megalodon supply-chain attack hits 5,561 GitHub repos — Attackers using forged CI bot identities pushed 5,718 malicious commits injecting payloads into GitHub Actions workflows to exfiltrate CI/CD secrets.
- Kimwolf botnet admin arrested — A 23-year-old Ottawa man was charged in the US and Canada with operating the ~2M-device Kimwolf IoT DDoS botnet and attacking the researchers who tracked him.
- CISA contractor exposed AWS GovCloud credentials on public GitHub — A contractor's public repo contained credentials to highly privileged AWS GovCloud accounts plus internal CISA build and deploy pipeline details.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check