Open the companion HTML intelligence dashboard
Executive signal: Today’s collection produced 106 new unique intelligence items. The highest scoring signals are concentrated around ransomware data-leak activity, exploited Cisco SD-WAN exposure, a WordPress plugin supply-chain compromise, and recently added CISA Known Exploited Vulnerabilities.
1. Critical section — score ≥ 10
No collected item reached the score ≥ 10 critical threshold in this run. Teams should still prioritise the exploited Cisco SD-WAN issue, current KEV additions, and ransomware leak signals below.
2. CISA KEV — Known Exploited Vulnerabilities
| CVE | Vendor/Product | Score | Required action |
|---|---|---|---|
| CVE-2026-54420 | CVE-2026-54420: LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability – LiteSpeed cPanel Plugin | 6 | LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability – LiteSpeed cPanel Plugin. Required action: Apply mitigations in accordance with vendor instructions,… |
| CVE-2026-20262 | CVE-2026-20262: Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability – Cisco Catalyst SD-WAN Manager | 6 | Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability – Cisco Catalyst SD-WAN Manager. Required action: Apply mitigations in accordance with vendor… |
3. Ransomware victims — DLS monitoring
nova: Kedah (MY)
qilin: Misericórdia de Santo Tirso (PT), Q Link Wireless (US)
4. News section — other scored items
[8] ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More (TheHackerNews)
Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail, and forgotten software keeps becoming someone else's entry point. Scroll…
[7] Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks (BleepingComputer)
CVEs: CVE-2026-20262. Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges. […]
[6] OptinMonster WordPress plugin hacked in CDN supply-chain attack (BleepingComputer)
WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN). […]
[6] Infinite Campus data breach affects 137,000 school staff accounts (BleepingComputer)
The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March. […]
[5] Council of Europe investigates ShinyHunters data breach claims (BleepingComputer)
The Council of Europe, the continent's oldest intergovernmental body, is probing claims of a data breach made by the ShinyHunters extortion group over the weekend. […]
[5] Chinese hackers breach REDCap servers, steal medical research (BleepingComputer)
A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America. […]
[5] Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw (TheHackerNews)
CVEs: CVE-2026-0257. Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS…
[5] Chinese hackers breached North American research institutions via REDCap servers (HelpNetSecurity)
<p>A China-linked cyber espionage operation targeted North American medical research institutions through compromised REDCap servers, using custom malware to gain persistent access and collect sensitive information, Google’s Threat Intelligence Group (GTIG) researchers found. UNC6508 exploits vulnerable REDCap servers GTIG attributed the campaign to…
[5] Delinea and Cyera integrate for data-aware identity security (HelpNetSecurity)
<p>Delinea and Cyera announced a product integration that connects privileged access to sensitive data exposure, automatically correlating identities with the data they can access. Together, Delinea and Cyera help security teams identify, prioritize, and remediate the highest-risk access paths across every human, machine, and AI agent. As identities…
5. Summary
Total new items: 106. Critical count: 0. Ransomware groups active today: 2. Top CVEs to patch urgently: CVE-2026-20262, CVE-2026-54420, CVE-2026-0257.
Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live
Leave a Reply