🔴 Critical Threats & Active Exploitation
Cisco Secure Firewall Management Center (FMC) / Security Cloud Control (SCC) — CVE-2026-20131 (CVSS 9.8 - assumed critical) — Unauthenticated remote attackers are exploiting a deserialization vulnerability in the web-based management interface to gain root privileges. This zero-day is actively leveraged by ransomware groups for initial access and deeper network compromise. Patch immediately.
Google Chrome — CVE-2026-3909 and CVE-2026-3910 (CVSS undisclosed, but actively exploited zero-days) — These are out-of-bounds memory and V8 JavaScript engine flaws allowing remote code execution just by visiting a malicious webpage. CISA has added both to the KEV catalog. Update Chrome ASAP.
F5 BIG-IP APM — CVE-2025-53521 (CVSS 9.8 - assumed critical) — Reclassified from DoS to unauthenticated RCE, this vulnerability is being actively exploited to deploy web shells. The original October 2025 fixes mitigate the RCE vector. Internet-exposed APM virtual servers are at highest risk. Patch if you haven’t already applied the October 2025 fix.
Open-source JavaScript library Axios — (No CVE assigned yet, but actively exploited supply chain attack) — North Korea-linked threat actor UNC1069 compromised the npm account of the lead maintainer, publishing malicious versions (axios@1.14.1, axios@0.30.4) that deploy a cross-platform remote access trojan. This is a highly sophisticated supply chain attack. If you use Axios, pin your version immediately and audit your lockfiles.
🛡️ CVEs Worth Your Attention
CVE-2026-32113 | Discourse v2026.1.0-latest to <2026.1.3, v2026.2.0-latest to <2026.2.2, v2026.3.0-latest to <2026.3.0 | CVSS Not yet assigned | Improper URL validation in SSO redirection could lead to arbitrary redirects. | PoC: No (details restricted)
CVE-2026-34605 | Discourse (specific versions not fully detailed) | CVSS Not yet assigned | SVG file served without Content Security Policy allows embedded script execution when opened directly. | PoC: No (details restricted)
CVE-2026-20929 | Microsoft Active Directory Certificate Services (AD CS) | CVSS 7.5 | Kerberos authentication relay via DNS CNAME abuse, enabling persistent access through certificate enrollment. Patched in January 2026, but the attack vector is still relevant for detection. | PoC: Yes (research detailed)
⚡ New TTPs & Attack Research
Kerberos Relay Attack via DNS CNAME Abuse — Research details how CVE-2026-20929 (patched in January) allows attackers to relay Kerberos authentication by manipulating DNS CNAME records. This is particularly dangerous when relayed to AD CS for certificate enrollment, granting persistent access. Defenders need to focus on detecting these relay patterns, not just patching the initial flaw. (T1558.003 - Kerberoasting, T1550.002 - Steal or Inherit Alternate Authentication Material: Pass-the-Ticket).
Sophisticated npm Supply Chain Attack — The Axios incident demonstrates advanced supply chain compromise. Attackers didn’t tamper with the core library but injected a malicious dependency plain-crypto-js@4.2.1 via a compromised maintainer account. The payload is a cross-platform RAT that wipes its own tracks after execution, making detection harder. This is a masterclass in stealthy persistence. (T1195.002 - Supply Chain Compromise: Compromise Software Supply Chain).
Ransomware Blending with Normal Operations — Cisco Talos 2025 review highlights ransomware actors increasingly using legitimate tools like RDP, PowerShell, and PsExec for lateral movement and execution. This makes detection harder as their activity blends with normal admin tasks. Focus on behavioral anomalies and strong identity protections. (T1021.001 - Remote Services: RDP, T1059.001 - Command and Scripting Interpreter: PowerShell, T1569.002 - System Services: Service Execution).
🏗️ DevSecOps & Cloud Security
North Korean Supply Chain Attack on Axios npm package — As noted in Critical Threats, a highly popular JavaScript library, Axios, was targeted. Malicious versions were published to npm, injecting a cross-platform RAT. This highlights the critical risk of open-source package dependencies and compromised maintainer accounts. Immediate action required: pin versions, audit lockfiles.
Google Drive Ransomware Detection & File Recovery GA — Google has moved its AI-powered ransomware detection and bulk file restoration features for Google Drive out of beta to general availability. It pauses syncing on detection, notifies users/admins, and allows bulk rollback to pre-infection states. This is a solid step for cloud-native ransomware defense.
🔧 Patches & Vendor Releases
Google Chrome — Version 146.0.7680.75/76 (Windows/Mac) and 146.0.7680.75 (Linux) released to patch CVE-2026-3909 and CVE-2026-3910. 🟢 solid fix
F5 BIG-IP APM — Patches released in October 2025 for CVE-2025-53521 are confirmed to mitigate the now-exploited RCE vector. If you applied it then, you’re good. If not, get on it. 🟢 solid fix
Cisco Secure Firewall Management Center (FMC) / Security Cloud Control (SCC) — Patches for CVE-2026-20131 are available. Prioritize this. 🟢 solid fix
🧪 Threat Intel & Malware
North Korean UNC1069 Group — Attributed to the sophisticated supply chain attack on the Axios npm package. This group has a history of supply chain attacks, often targeting cryptocurrency, and uses cross-platform RATs. Their backdoors resemble WAVESHAPER malware.
Iranian Nation-State Actors & Ransomware Proxies — KELA reports Iranian state-sponsored groups are increasingly blurring lines with financially motivated cybercrime, acting as initial access brokers, collaborating with ransomware affiliates (e.g., NoEscape, RansomHouse, ALPHV/BlackCat), and deploying pseudo-ransomware. This creates significant OFAC sanctions risk for victims if they pay. (T1078 - Valid Accounts, T1583 - Establish Accounts).
Leak Bazaar — A new dark web service is emerging, aiming to monetize exfiltrated data from ransomware attacks more systematically. It pitches itself as a “data-processing business” to structure and sell stolen information, rather than just using it for double extortion. This could change the economics of data theft.
Stolen Credentials Fueling Attacks — A report highlights that stolen logins are underpinning a vast array of attacks, from ransomware to nation-state operations. Infostealers and AI are accelerating identity-based threats. Focus on strong identity protections and monitoring for misuse of legitimate access.
Tax Season Malvertising Campaign (US) — Active since January 2026, this campaign uses Google Ads to serve fake installers for tax documents, deploying tools to disable endpoint security. With tax deadlines approaching, this remains a high risk for US businesses and individuals.
🌐 Industry, Brand & Internet Security
Massive Email Credential Breach — Hold Security’s Alex Holden reported a Russian hacker claiming over 1 billion hacked email addresses for sale, with 250M+ unique email/password combos from Mail.ru, Yahoo, Hotmail, and Gmail. While “historical,” this fuels credential stuffing.
Brand Impersonation & Phishing Evolution — ESET notes phishing is evolving with AI, typosquatting (e.g., eseet.com), quishing (malicious QR codes), and calendar invites. Mobile devices are a growing attack surface due to smaller screens hiding malicious URLs. Organizations need prevention-first approaches.
Quantum Threat to Cryptocurrency Encryption — Google’s Quantum AI research suggests breaking Bitcoin/Ethereum’s elliptic curve cryptography could require 20x fewer qubits than previously thought, potentially in as little as nine minutes. While not an immediate threat, it accelerates the timeline for post-quantum cryptography transition.
📋 Compliance & Regulatory
[Clear — enjoy it]
💡 Marcus’s Take
We’re seeing a clear trend: attackers are getting smarter about blending in. Whether it’s nation-states using ransomware proxies to muddy attribution and evade sanctions, or threat actors leveraging legitimate admin tools for lateral movement, the lines are blurring. The Axios npm compromise is a prime example – not a direct vuln, but a supply chain attack via a compromised maintainer, deploying a self-cleaning RAT. This isn’t just about patching; it’s about deep visibility into your supply chain, behavioral analytics, and robust identity controls. Assume compromise, and focus on detecting the subtle shifts in “normal.”