Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access.
This article details a threat actor's exploitation of CVE-2026-20245 in Cisco Catalyst SD-WAN Manager, escalating from a compromised admin account to root via a malicious CSV upload. The attacker maintained operational security through anti-forensic techniques and the article also explains the basics of SD-WAN technology.
Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-level access.
Unit 42's analysis of OpenClaw's ClawHub marketplace reveals evasive malicious skills that bypass automated scanners to deploy infostealers and conduct agentic financial fraud. The research highlights the emerging AI supply chain threat as agentic AI platforms grow in popularity.
Unit 42's analysis of OpenClaw's ClawHub marketplace reveals evasive malicious skills that bypass automated scanners to deploy infostealers and conduct agentic financial fraud. The research highlights the emerging AI supply chain threat as agentic AI platforms grow in popularity.
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.