Active exploitation of Cisco Catalyst SD-WAN by UAT-8616

Active exploitation of Cisco Catalyst SD-WAN by UAT-8616

• Active exploitation of Cisco Catalyst SD-WAN by UAT-8616 Cisco Talos is tracking the active exploitation ofCVE-2026-20127, a vulnerability in Cisco Catalyst SD-WAN Controller, fo

Threat Intelligence · February 25, 2026 (updated February 25, 2026) · 2 min · 258 words
VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)

VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)

• Executive Summary On Feb. • 6, 2026, BeyondTrust released a security advisory regarding CVE-2026-1731. • BeyondTrust is an identity and access management platform. • This specifi

Cybersecurity · February 19, 2026 (updated February 25, 2026) · 2 min · 379 words
From Exposure to Exploitation: How AI Collapses Your Response Window

From Exposure to Exploitation: How AI Collapses Your Response Window

• From Exposure to Exploitation: How AI Collapses Your Response Window We’ve all seen this before: a developer deploys a new cloud workload and grants overly broad permissions just

Cybersecurity · February 19, 2026 (updated February 24, 2026) · 2 min · 237 words
Child exploitation, grooming, and social media addiction claims put Meta on trial

Child exploitation, grooming, and social media addiction claims put Meta on trial

• Child exploitation, grooming, and social media addiction claims put Meta on trial Meta is facing two trials over child safety allegations in California and New Mexico. • The laws

Threat Intelligence · February 12, 2026 (updated February 24, 2026) · 2 min · 244 words
Analysis of active exploitation of SolarWinds Web Help Desk

Analysis of active exploitation of SolarWinds Web Help Desk

• The Microsoft Defender Research Team observed a multi‑stage intrusion where threat actors exploited internet‑exposed SolarWinds Web Help Desk (WHD) instances to get an initial fo

Cybersecurity · February 7, 2026 (updated February 24, 2026) · 2 min · 370 words
IR Trends Q4 2025: Exploitation remains dominant, phishing campaign targets Native American tribal organizations

IR Trends Q4 2025: Exploitation remains dominant, phishing campaign targets Native American tribal organizations

• Threat actors predominately exploited public-facing applications for the second quarter in a row, with this tactic appearing in nearly 40 percent of Cisco Talos Incident Response

Threat Intelligence · January 29, 2026 (updated February 24, 2026) · 2 min · 289 words

Windows Exploitation Techniques: Winning Race Conditions with Path Lookups

• This post was originally written in 2016 for the Project Zero blog. • However, in the end it was published separately in the journal PoC||GTFO issue #13 as well as in the second

Threat Intelligence · December 16, 2025 (updated February 24, 2026) · 2 min · 246 words

Windows Exploitation Techniques: Winning Race Conditions with Path Lookups

• This post was originally written in 2016 for the Project Zero blog. • However, in the end it was published separately in the journal PoC||GTFO issue #13 as well as in the second

Cybersecurity · December 16, 2025 (updated February 20, 2026) · 2 min · 259 words