DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
20 ADVISORIES SHOWN
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CISA-KEV-2026-07-27
CISACVE-2025-686862026-07-27

CISA KEV: Fortinet FortiOS SSL-VPN Sensitive Information Exposure — Patch Bypass Actively Exploited (CVE-2025-68686)

CVE-2025-68686 is an information exposure vulnerability (CWE-200) in Fortinet FortiOS SSL-VPN that allows a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism used in post-exploitation persistence cases. The attacker must first gain filesystem-level access via a separate vulnerability before abusing this flaw to re-access sensitive resources that should have been sealed by the prior patch. CISA added it to the KEV on July 27, 2026 with a remediation deadline of August 10, 2026.

AFFECTED:Fortinet FortiOS SSL-VPN (multiple versions — consult FortiGuard PSIRT advisory for full version matrix)FULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: cisco-sa-notice-L4XfJg8S
Cisco PSIRT2026-07-29

Cisco Advance Notification — August 5, 2026 Security Advisories: IOS, IOS XE, Catalyst SD-WAN IMC

Cisco PSIRT issued an advance notification on July 29, 2026 that on August 5, 2026 it will publish security advisories for vulnerabilities in Cisco IOS Software, IOS XE Software, and Catalyst SD-WAN Integrated Management Controller (IMC). These products are high-value attack targets and have been subject to sustained nation-state and criminal exploitation in prior cycles. Defenders should prepare patching workflows immediately ahead of the August 5 disclosure.

AFFECTED:Cisco IOS Software (multiple releases)Cisco IOS XE Software (multiple releases)Cisco Catalyst SD-WAN Integrated Management Controller (IMC)FULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: FG-IR-26-141
Fortinet PSIRTCVE-2026-TBD2026-06-09

Fortinet FortiSandbox Unauthenticated OS Command Injection via Web UI (FG-IR-26-141)

Fortinet PSIRT advisory FG-IR-26-141 discloses an improper neutralization of special elements in an OS command (CWE-78) vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS Web UI that may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted requests. FortiSandbox is a critical detection layer in many enterprise security stacks; unauthenticated RCE in the web UI represents a high-impact attack surface for threat actors seeking to blind sandboxing and malware analysis infrastructure.

AFFECTED:Fortinet FortiSandbox (on-premises, multiple versions — consult FG-IR-26-141 for full matrix)Fortinet FortiSandbox CloudFortinet FortiSandbox PaaSFULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: ICSA-26-211-03
CISACVE-2026-125622026-07-30

CISA ICS Advisory: Toptech Systems RCU II+ / Multiload II+ Unauthenticated Root Access via Exposed Debug Interface (CVE-2026-12562)

CISA published ICS Advisory ICSA-26-211-03 on July 30, 2026, disclosing a critical unauthenticated root access vulnerability in Toptech Systems RCU II+ and Multiload II+ petroleum load control devices used in the Energy sector. The flaw exposes a network-accessible Target Communications Framework (TCF) debug service port that requires no authentication, granting full root-level Linux system access to any attacker on the network. Successful exploitation allows full system control and manipulation of connected OT networks and resources.

AFFECTED:Toptech Systems RCU II+ versions prior to 2025-11-24Toptech Systems Multiload II+ versions prior to 2025-11-24FULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: cisco-sa-ise-multi-G5WP8vv
Cisco PSIRTCVE-2026-20181CVE-2026-201902026-06-17

Cisco Identity Services Engine (ISE) Critical RCE and Information Disclosure (CVE-2026-20181, CVE-2026-20190)

Cisco disclosed two critical vulnerabilities (CVSS 9.1) in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), affecting deployments regardless of configuration. CVE-2026-20181 is a remote code execution flaw caused by improper validation of user-supplied input; an authenticated administrator can exploit it via crafted HTTP requests to execute arbitrary OS commands. CVE-2026-20190 enables unauthorized information disclosure. No workarounds are available, and earlier versions require migration to supported releases — making ISE a high-priority patch target across enterprise networks.

AFFECTED:Cisco ISE versions prior to 3.3 Patch 11Cisco ISE versions prior to 3.4 Patch 6Cisco ISE 3.5 prior to Patch 4 (fix planned August 2026)Cisco ISE-PIC (Passive Identity Connector) — same version matrixFULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: cisco-sa-fmc-authbypass-CSCwt95974
Cisco PSIRTCVE-2026-200792026-08-01

Cisco Secure FMC Critical Authentication Bypass Enabling Root RCE (CVE-2026-20079)

Cisco updated its advisory for CVE-2026-20079 (CVSS 10.0) on July 29, 2026 — a critical authentication bypass in Cisco Secure FMC Software caused by an improper system process created at boot time. An unauthenticated remote attacker can bypass authentication and execute arbitrary executable scripts to obtain root access via crafted HTTP requests, without requiring any credentials or prior device access. Cisco published the same /var/tmp/license.tmp indicator of compromise as for the actively exploited CVE-2026-20316, strongly suggesting these two flaws are being chained in active attacks.

AFFECTED:Cisco Secure FMC Software 7.0.xCisco Secure FMC Software 7.2.xCisco Secure FMC Software 7.4.xCisco Secure FMC Software 7.6.xCisco Secure FMC Software 7.7.xCisco Secure FMC Software 10.0.xFULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: ICSA-26-211-01
CISACVE-2026-142272026-07-30

CISA ICS Advisory: MikroTik RouterOS WireGuard Private Key Extraction via Session Management Flaw (CVE-2026-14227)

CISA published ICS Advisory ICSA-26-211-01 on July 30, 2026, disclosing a session management vulnerability (Insufficient Session Expiration, CWE-613) in MikroTik RouterOS affecting all versions with the RouterOS API enabled. An attacker with low-privilege API access can extract the router's WireGuard VPN private key in plaintext due to improper session expiration and permission retention, enabling full VPN impersonation and decryption of all WireGuard-protected traffic. This advisory affects a globally deployed product used widely in IT and critical infrastructure environments.

AFFECTED:MikroTik RouterOS — all versions with API enabled (vers:all/*)FULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: cisco-sa-fmc-static-cred-BET3Cjh
Cisco PSIRTCVE-2026-20316CVE-2026-200792026-07-29

Cisco Secure FMC Hard-Coded Password — Zero-Day Under Active Exploitation, Chains with CVSS 10.0 Auth Bypass (CVE-2026-20316 + CVE-2026-20079)

CVE-2026-20316 is an actively exploited use of hard-coded credentials in Cisco Secure Firewall Management Center (FMC) that allows an unauthenticated remote attacker to log in via a low-privileged account and access sensitive data. CISA added it to the KEV on July 29, 2026 with a federal patch deadline of August 1, 2026. In tandem, Cisco updated its advisory for the CVSS 10.0 authentication bypass CVE-2026-20079 — which enables arbitrary script execution with root access — to include shared indicators of compromise, suggesting threat actors may be chaining both flaws for full FMC compromise.

AFFECTED:Cisco Secure Firewall Management Center (FMC) Software 6.4.xCisco Secure Firewall Management Center (FMC) Software 7.0.xCisco Secure Firewall Management Center (FMC) Software 7.1.xCisco Secure Firewall Management Center (FMC) Software 7.2.xCisco Secure Firewall Management Center (FMC) Software 7.3.xCisco Secure Firewall Management Center (FMC) Software 7.4.xCisco Secure Firewall Management Center (FMC) Software 7.6.xCisco Secure Firewall Management Center (FMC) Software 7.7.xFULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CISA-KEV-2026-07-27 / Arista SA CVE-2026-16812
CISA KEV / Arista PSIRTCVE-2026-168122026-07-27

Arista VeloCloud Orchestrator On-Prem — CVSS 10.0 Unauthenticated OS Command Injection (CVE-2026-16812)

A maximum-severity (CVSS 10.0) unauthenticated OS command injection flaw in Arista VeloCloud Orchestrator On-Prem allows remote attackers to reach privileged internal functionality, execute arbitrary commands, and fully compromise the orchestrator host and all managed SD-WAN edge devices. Active exploitation was confirmed by Arista and CISA added it to the KEV catalog on July 27, 2026 with a federal FCEB remediation deadline of July 30. Hosted and dedicated VCO versions were patched ahead of the disclosure; only on-premises deployments require customer action.

AFFECTED:Arista VeloCloud Orchestrator (VCO) On-Prem — all versions prior to vendor-supplied fixFULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: MSRC-2026-Jul
Microsoft MSRCCVE-2026-56155CVE-2026-56164CVE-2026-50522CVE-2026-58644CVE-2026-506612026-07-14

Microsoft July 2026 Patch Tuesday — Two Actively Exploited Zero-Days: AD FS EoP (CVE-2026-56155) and SharePoint EoP (CVE-2026-56164)

Microsoft's record-breaking July 2026 Patch Tuesday (570–622 CVEs) included two actively exploited zero-days: CVE-2026-56155, an elevation of privilege flaw in Active Directory Federation Services discovered by Microsoft DART during active attack investigations, and CVE-2026-56164, a missing authentication vulnerability in SharePoint Server that allows unauthenticated remote privilege escalation. Both were added to CISA KEV on July 14, 2026. The release also patches critical unauthenticated RCE flaws in Windows DHCP Server and SharePoint (CVE-2026-50522, CVE-2026-58644) and a publicly disclosed BitLocker bypass (CVE-2026-50661).

AFFECTED:Active Directory Federation Services (Windows Server 2019, 2022, 2025)Microsoft SharePoint Server Subscription EditionMicrosoft SharePoint Server 2019Windows 10 (multiple versions)Windows 11 (multiple versions)Windows Server 2019 / 2022 / 2025FULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CVE-2026-63030 / CVE-2026-60137
CERT/CCCVE-2026-63030CVE-2026-601372026-07-21

WordPress Core 'wp2shell' Pre-Auth RCE Chain — CVE-2026-63030 & CVE-2026-60137 (CISA KEV, Mass Exploitation Underway)

Dubbed 'wp2shell', this critical exploit chain in WordPress Core combines CVE-2026-63030 (REST API batch-route confusion, CWE-664) and CVE-2026-60137 (SQL injection in WP_Query author__not_in parameter, CWE-89) to achieve fully unauthenticated remote code execution on default WordPress installations requiring no plugins or special configuration. Disclosed July 17, 2026, public PoC exploits appeared within hours and mass exploitation was confirmed by July 18–21; CISA added both CVEs to KEV on July 21, 2026. The attack surface covers an estimated 500+ million WordPress installations worldwide.

AFFECTED:WordPress Core 6.8.0 – 6.8.5 (SQL injection only; no full RCE chain)WordPress Core 6.9.0 – 6.9.4 (full wp2shell RCE chain)WordPress Core 7.0.0 – 7.0.1 (full wp2shell RCE chain)FULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: ICSA-26-209-01 / ICSA-26-209-05
CISACVE-2026-16347CVE-2026-165812026-07-28

CISA ICS Advisory Batch — MikroTik RouterOS API Auth Brute-Force & Multiple OT/IIoT Vulnerabilities (ICSA-26-209-01 through -05)

CISA published five ICS advisories on July 28, 2026. Most notably, ICSA-26-209-05 covers a lack of effective rate-limiting and account lockout controls in MikroTik RouterOS and Cloud Hosted Router API authentication (CVE-2026-16347), allowing attackers to rapidly brute-force passwords and gain unauthorized system access across all current RouterOS versions. MikroTik devices are widely deployed as enterprise and ISP routers globally, and unpatched API exposure represents a significant network perimeter risk.

AFFECTED:MikroTik RouterOS – all versions (CVE-2026-16347)MikroTik Cloud Hosted Router – all versions (CVE-2026-16347)igloohome Smart Lock Mobile Application (Android) 3.2.3 and prior (CVE-2026-16581)FULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CISA-KEV-2026-07-27
CISACVE-2026-168122026-07-27

CISA KEV: Arista VeloCloud Orchestrator On-Prem OS Command Injection (CVE-2026-16812) — Actively Exploited Zero-Day

CVE-2026-16812 is a CVSS 10.0 unauthenticated OS command injection flaw in Arista VeloCloud Orchestrator On-Prem that allows remote attackers to access privileged internal functionality and execute arbitrary OS commands on the VCO host. Arista confirmed active exploitation and stated the on-premises orchestrator is exposed by default with no configuration capable of removing that exposure entirely. CISA added it to the KEV on July 27, 2026, with a federal remediation deadline of July 30, 2026 under BOD 26-04.

AFFECTED:Arista VeloCloud Orchestrator On-Prem 5.2.x prior to 5.2.3.14Arista VeloCloud Orchestrator On-Prem 6.1.x prior to 6.1.3.4Arista VeloCloud Orchestrator On-Prem 6.4.x prior to 6.4.2.4Arista VeloCloud Orchestrator On-Prem 7.0.x prior to 7.0.0.1FULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: FG-IR-25-934
Fortinet PSIRTCVE-2025-686862026-08-01

Fortinet FortiOS Patch Bypass Actively Exploited — Symbolic Link Persistence Technique (CVE-2025-68686)

CISA added CVE-2025-68686 to its KEV catalog on July 27, 2026, after confirming active exploitation. The flaw (CWE-200) in Fortinet FortiOS allows a remote unauthenticated attacker to bypass the patch designed to prevent a symbolic link persistence technique used by threat actors to maintain post-exploitation access on compromised FortiGate devices. Exploitation requires the attacker to have first obtained filesystem-level access via a separate vulnerability. Federal FCEB agencies must apply mitigations by August 10, 2026 per BOD 26-04.

AFFECTED:Fortinet FortiOS (multiple versions — see FG-IR-25-934 for full version matrix)FortiGate appliances running affected FortiOS versionsFULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CVE-2026-49176
Microsoft MSRCCVE-2026-491762026-07-28

Microsoft Windows WalletService EoP — Public PoC Released, SYSTEM Privileges (CVE-2026-49176)

CVE-2026-49176 (CVSS 7.8) is a local privilege escalation vulnerability in Windows WalletService stemming from improper privilege management and link-following behavior (CWE-269/CWE-59). A standard local user can redirect the Documents known folder to an attacker-controlled path, causing WalletService to process a malicious wallet.db and execute code at SYSTEM level — requiring no memory corruption, race condition, or admin privileges. A full public proof-of-concept was published on July 27/28, 2026 by researcher David Carliez, significantly elevating exploitation risk despite no confirmed in-the-wild exploitation yet.

AFFECTED:Windows 10 1607, 1809, 21H2, 22H2Windows 11 24H2, 25H2, 26H1Windows Server 2016, 2019, 2022, 2025FULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: AA26-097A
CISACVE-2021-226812026-07-22

AA26-097A UPDATE — Iranian-Affiliated APT Expands PLC Targeting to Schneider Electric and Siemens Alongside Rockwell Automation

FBI, CISA, NSA, EPA, DOE, US Cyber Command, and Treasury updated joint advisory AA26-097A on July 22, 2026, expanding the confirmed scope of Iranian-affiliated (IRGC CEC / CyberAv3ngers) OT intrusions to include Schneider Electric and Siemens PLCs alongside Rockwell Automation/Allen-Bradley. Threat actors connect to internet-exposed PLCs using vendors' own legitimate engineering software (Studio 5000, EcoStruxure Control Expert, TIA Portal), manipulate ladder logic, alter SCADA displays, and in at least one confirmed U.S. victim site disabled alarm and safety shutdown logic. New July 2026 STIX-formatted IOCs were released alongside the update.

AFFECTED:Rockwell Automation CompactLogixRockwell Automation Micro850Schneider Electric BMX P34 / Modicon M340Siemens S7-1200 seriesAny internet-exposed PLCs using Rockwell Studio 5000, Schneider EcoStruxure Control Expert, or Siemens TIA PortalFULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: AA26-194A
CISACVE-2018-0171CVE-2008-41282026-07-13

AA26-194A — Russian FSB Center 16 Exploits Poorly Configured Routers Across Global Critical Infrastructure

A 19-agency joint advisory (NSA, CISA, FBI, DC3, and 15 international partners from 13 countries) details decade-long campaigns by Russian FSB Center 16 (aka Berserk Bear / Turla / Ghost Blizzard) exploiting internet-exposed routers with weak or default SNMP community strings. Actors issue SNMP Set-Requests abusing Cisco CISCO-CONFIG-COPY-MIB to exfiltrate device configurations and credentials via TFTP, providing persistent access to critical infrastructure across communications, defense industrial base, energy, financial services, state/local government, and healthcare sectors. No zero-day required — default credentials alone suffice for initial access.

AFFECTED:Internet-exposed routers with SNMPv1/v2c default community stringsCisco devices vulnerable to Smart Install (CVE-2018-0171, CVSS 9.8)End-of-life Cisco 871 routers (CVE-2008-4128)Any perimeter routing device with SNMP exposed to internetFULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: cisco-sa-hardening-roomos-AqNMbEq
CiscoCVE-2026-20150CVE-2026-20153CVE-2026-20156CVE-2026-20157CVE-2026-20158CVE-2026-201872026-07-15

Cisco RoomOS Security Hardening Release July 2026 — Multiple High-Severity Vulnerabilities (CVSS 8.8)

Cisco published a security hardening release for RoomOS on July 15, 2026, addressing multiple internally discovered vulnerabilities including improper access control flaws grouped under CWE-284 (CVE-2026-20150, CVE-2026-20153, CVE-2026-20156, CVE-2026-20157, CVE-2026-20158, CVE-2026-20187) rated High with CVSS 8.8. The vulnerabilities were found during internal testing as part of Cisco's new risk-based disclosure model and are not yet known to be actively exploited. There are no workarounds; software upgrade is the only remediation. The high CVSS score and network-attack-vector rating make this a priority patch for enterprise video conferencing infrastructure.

AFFECTED:Cisco RoomOS — all versions prior to the July 2026 hardening releaseFULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: CISA-ALERT-2026-07-14 (updated 2026-07-22)
CISACVE-2026-58644CVE-2026-32201CVE-2026-45659CVE-2026-56164CVE-2026-550402026-07-22

CISA Urges Emergency SharePoint Hardening — Active Exploitation of Multiple CVEs Including Zero-Days (CVE-2026-58644, CVE-2026-32201, CVE-2026-45659)

CISA issued an urgent alert documenting active exploitation of four on-premises SharePoint Server vulnerabilities — CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644 (CVSS 9.8) — with the latter two exploited as zero-days before Microsoft patched them on July 14, 2026. Threat actors are chaining these flaws to achieve RCE, steal IIS machine keys, perform deserialization-based persistence, and deploy malware across enterprise SharePoint farms. All supported on-premises SharePoint versions (Subscription Edition, 2019, 2016) are affected. The alert was updated on July 22 to add CVE-2026-50522 to the KEV catalog with a July 25 federal deadline.

AFFECTED:Microsoft SharePoint Server Subscription Edition (all pre-July 2026 CU builds)Microsoft SharePoint Server 2019 (all pre-July 2026 CU builds)Microsoft SharePoint Server 2016 (EOS July 14, 2026)FULL ADVISORY ▶
TLP:WHITEOPEN SOURCE ADVISORY
DOC: AA26-204A
CISACVE-2025-663762026-07-23

Russian APT LAUNDRY BEAR Exploits Zimbra Zero-Day XSS for Email Espionage (CVE-2025-66376)

CISA, NSA, FBI, and over two dozen international partners jointly warned that Russian state-sponsored APT LAUNDRY BEAR (aka Void Blizzard / TA488) has been exploiting a stored XSS flaw in Zimbra Collaboration Suite (ZCS) Classic UI since July 2025 — originally as a zero-day — to silently exfiltrate email, passwords, and 2FA tokens from government, defense, energy, law enforcement, and NGO targets across Western nations. The exploit requires only that a victim opens a malicious email in vulnerable Zimbra webmail; no click or download is needed. The implanted payload creates a fake app-specific credential ('ZimbraWeb') that survives password resets, and enables IMAP for persistent mailbox access.

AFFECTED:Zimbra Collaboration Suite Classic UI — all versions prior to the November 6 2025 patchZimbra Collaboration Suite 10.x (unpatched)Zimbra Collaboration Suite 9.0.x (unpatched)FULL ADVISORY ▶