
Hello all,
Unlike the prior week, there was a lot to report on this week, starting with a brand-new way to extract your information from wireless networks, three-year old Cisco zero-day exploit, and more. The good guys had some nice wins with the sentencing of a dirtbag, sanctions on another, disruption of a Chinese espionage organization and serious disruption of the ransomware ecosystem. So on to the news.
Headline NEWS:
- AirSnitch WiFi Exploit enables a malicious actor to perform man-in-the-middle attacks and steal information that traverses the same physical access point. This attack only requires that the threat actor be joined to the access point. It can be the supposedly isolated guest network. However, due to the newly discovered exploit, the traffic from other networks can be accessed and tapped into. Complexity is a bit high so far, and it requires access to the network, but it is only a matter of time before evil people weaponize this defect. The race is on now for manufacturers to fix their underlying software to plug this hole.
- Cisco SD-WAN has a defect that apparently has been exploited since 2023. In a new warning regarding Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager, the manufacturer urges clients to update to the latest version and check for signs of compromise. CISA gave government agencies until Friday of this past week to collect all logs and forensic snapshots from their systems, to upgrade them to patched versions, search for signs of compromise, to follow vendor guidance to harden their devices, and finally to report a detailed inventory and any findings. The “Five Eyes” governments are all urging similar for their agencies. This cannot and should not be ignored. It is as serious as it gets.
- SolarWinds Serv-U released patches for multiple defects this past week. Four identified ones can enable a threat actor to gain root access on the file transfer system. Multiple other fixes are proffered with updated version 15.5.4. And while this is not suspected of being publicly exploited, it would be advisable to patch quickly.
- Zyxel Routers have a critical RCE. At least a dozen different models have defects that can allow a threat actor to gain unauthenticated remote code execution. A caveat is that by default WAN configuration is disabled. If this hasn’t been enabled, then the router is not exploitable. Nevertheless, Zyxel urges all clients to update to the latest firmware as soon as possible.
In Ransomware, Malware, and Vulnerabilities News:
- CrowdStrike 2026 Global Threat Report came out Tuesday and revealed some disturbing numbers. The most troubling being that the average time a threat actor took from initial access to moving to other systems in a network dropped to 29 minutes in 2025. And the fastest recorded time dropped to an astonishing 27 seconds! Of the cases that they worked, an astounding 82% didn’t use any malware, relying instead on living-off-the-land (LotL) techniques to escalate and pivot. BlackFog’s 2025 State of Ransomware Annual Report which came out a couple of weeks ago reports that there were 1,174 publicly disclosed ransomware attacks, however 86% of ransomware incidents went undisclosed, showing that the problem is significantly larger than most press reports indicate. 96% of ransomware exfiltrates data for extortion and resale. Despite these statistics, indications are that number of companies paying the extortion demands is decreasing, which is causing threat actors to ramp up the quantity attacks to make up the difference. Their gambit seems to be working as total payouts have increased year-over-year. This is an ever evolving evil and we cannot let down our guard.
In Other News Events of Note and Interest:
- Anthropic vs. Department of War. In a dispute over AI tools for military applications. The Department of War had ordered Anthropic to remove restrictions on the military’s use of its AI tools, which Anthropic refused to do. This refusal has led to termination of a $200 million deal with the Department of War. The dispute is centered on safety concerns regarding sensitive applications like mass surveillance, weapons development, and autonomous systems. The Department of War has now designated Anthropic as a ‘supply chain risk,’ which requires companies that work with the US military to cut ties with Anthropic. For its part, Anthropic plans to fight the designation in court, calling it an unprecedented and legally unsound move against an American company. Barring any changes, the US Government now plans to cease use of anything by Anthorpic within six months.
Musings
I spend multiple hours a week of my own time creating the RedDotSecurity.new newsletter. Every now and then one of my viewers or readers will let me know that they found something in the content that I put out to be useful, amusing, or even vital to them or those they support. I love hearing from you, don’t stop! However, as I’ve been at this several years now, I’ve found that this publishing process is invaluable to me. By personally researching the articles, blogs, and videos, from the various publications and news sources that I use weekly, I have opportunity to see various sides and viewpoints regarding current and highly relevant events, tools, trends, activity, and methodologies that are being used and abused in our industry. So, if you benefit from what I put out, you’re welcome, and thank you for your support. And thank also you for being there, because it encourages me to continue to learn and to continue to better myself.

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises
- Researchers discover massive Wi-Fi vulnerability affecting multiple access points — AirSnitch lets attackers on the same network intercept data and launch machine-in-the-middle attacks
- Governments issue warning over Cisco zero-day attacks dating back to 2023
- Critical Cisco SD-WAN bug exploited in zero-day attacks since 2023
- Threat actor leveraged Cisco SD-WAN zero-day since 2023 (CVE-2026-20127)
- Critical Juniper Networks PTX flaw allows full router takeover
- SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution
- Zyxel warns of critical RCE flaw affecting over a dozen routers
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- CISA Confirms Active Exploitation of FileZen CVE-2026-25108 Vulnerability
- CISA warns that RESURGE malware can be dormant on Ivanti devices
- Poll: Top NATO allies believe cyberattacks on hospitals are an act of war
- Ukrainian gets 5 years for helping North Koreans infiltrate US firms
- US sanctions Russian broker for buying stolen zero-day exploits
- RAMP Forum Seizure Fractures Ransomware Ecosystem
- Google and friends disrupt suspected Beijing espionage op
- Vulnerabilities and Exploits
- CrowdStrike says attackers are moving through networks in under 30 minutes
- Hackers Abuse Windows File Explorer and WebDAV for Stealthy Malware Delivery
- Multiple VMware Aria Vulnerabilities Allow Remote Code Execution Attacks
- Multiple Zero-Day Flaws in PDF Platforms Enable XSS and One-Click Attacks
- Critical Trend Micro Apex One Vulnerabilities Allows Malicious Code Execution
- Fake CAPTCHA attacks exploded by 563% last year
- Detecting and preventing distillation attacks
- When identity isn’t the weak link, access still is
- PoC Released for Windows Vulnerability That Allows Attackers to Cause Unrecoverable BSOD Crashes
- VPN flaws allowed Chinese hackers to compromise dozens of Ivanti customers, says report
- AI in the Middle: Turning Web-Based AI Services into C2 Proxies & The Future Of AI Driven Attacks
- ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket
- Hackers Leverage DeepSeek and Claude to Attack FortiGate Devices Worldwide
- Claude’s collaboration tools allowed remote code execution
- GrayCharlie Injects Malicious JavaScript into WordPress Sites to Deliver NetSupport RAT and Stealc
- Microsoft warns OpenClaw could quietly turn your everyday workstation into a high-risk automation gateway
- GitHub Copilot Exploited to Perform Full Repository Takeover via Passive Prompt Injection
- PCI Council Says Threats to Payments Systems Are Speeding Up
- 900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks
- Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API Enablement
- Phishing, Malware, and similar
- Arkanix Stealer pops up as short-lived AI info-stealer experiment
- Threat Actors Using Fake Avast Website to Harvest Users Credit Card Details
- Hackers turn Facebook ads into crypto draining traps
- Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens
- APT28 Targeted European Entities Using Webhook-Based Macro Malware
- New ClickFix Attack Targets Crypto Wallets and 25+ Browsers with Infostealer
- Silver Fox APT Uses DLL Sideloading and BYOVD Techniques in Sophisticated Malware Attacks
- Hackers Hide Pulsar RAT Inside PNG Images in New NPM Supply Chain Attack
- MuddyWater Targets Orgs With Fresh Malware Amid Rising Tensions
- Breaches, Leaks, and Ransomware
- The DJI Romo robovac had security so poor, this man remotely accessed thousands of them
- Ransomware payment rate drops to record low as attacks surge
- Poll: Top NATO allies believe cyberattacks on hospitals are an act of war
- Ad tech firm Optimizely confirms data breach after vishing attack
- Wynn Resorts says hackers stole employee data
- US Healthcare Diagnostic Firm Says 140,000 Affected by Data Breach
- Conduent data breach already one of largest in U.S. history and keeps getting worse
- North Korean Lazarus group linked to Medusa ransomware attacks
- Marquis sues firewall provider SonicWall, alleges security failings with its firewall backup led to ransomware attack
- CarGurus data breach affects 12.5 million accounts
- Data breach at Clackamas Community College prompts class-action lawsuit
- Olympique Marseille confirms ‘attempted’ cyberattack after data leak
Other News Events of Note and Interest
- Enigma Cipher Device Still Holds Secrets for Cyber Pros
- 1Password announces big price increases coming next month
- Discord delays global rollout of age verification after backlash
- Wisconsin Reverses Decision to Ban VPNs in Age-Verification Bill
- Firefox 148.0 arrives with AI kill switch, drag-and-drop fixes, and more
- US State Colorado Wants Operating Systems (Including Linux) to Tell Every App How Old You Are
- Orbital datacenters are a pie-in-the-sky idea: Gartner
- Who will regulate Elon Musk and China’s data centers in space?
- Japanese firm stops production of Blu-ray disc drives
- LibreOffice resumes work on its self-hosted Google Docs alternative
- Collabora clashes with LibreOffice over move to revive LibreOffice Online
- AI, LLM’s, and Skynet
- Amazon introduces three personality styles for Alexa+
- Anthropic vs. the Pentagon: What’s actually at stake?
- Trump orders federal agencies to stop using Anthropic’s technology. Anthropic says it will fight back
- Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning
- Statement from Dario Amodei on our discussions with the Department of War
- Chrome Update Turns Browser’s Address Bar Into an AI Prompt Box
- Google launches Nano Banana 2 model with faster image generation
- Treasury Announces Public-Private Initiative to Strengthen Cybersecurity and Risk Management for AI
- Use Lyria 3 to create music tracks in the Gemini app
- Microsoft execs worry AI will eat entry level coding jobs
- Microsoft develops Copilot Advisors to debate on any topic
- Unitree showcases 49 humanoid robots performing synchronized martial arts demo at Temple of Heaven after Spring Festival Gala show
- A Meta AI security researcher said an OpenClaw agent ran amok on her inbox
- 8 billion tokens a day forced AT&T to rethink AI orchestration — and cut costs by 90%
- Career Decisions If You Take AGI Seriously
- ServiceNow resolves 90% of its own IT requests autonomously. Now it wants to do the same for any enterprise
- Microsoft
- Microsoft announces new ESU programs for more versions of Windows
- Microsoft’s Copilot Tasks AI uses its own computer to get things done
- Microsoft says bug in classic Outlook hides the mouse pointer
- Microsoft refreshes Planner with new design and features, users have already found issues
- Introducing a refreshed design, task chat, and more in Microsoft Planner
- Windows Server Secure Boot playbook for certificates expiring in 2026
- Microsoft moves yet another feature to Settings as it plans to scrap the Control Panel
- Windows 11 24H2 and 25H2 get big update with new emojis, improved taskbar and more
- Microsoft Edge will automatically open Copilot when you click links from Outlook
- Microsoft explains the confusion around printer drivers in Windows 11
- Microsoft updates security baseline package for Windows Server 2025
- Sysmon Overview – from Microsoft Learn
- After 14 years, Windows Server finally gets ReFS boot support
- Microsoft Introduces New SharePoint Experience
