Android malware surge; AI-powered PaperCut campaign hits 395+ orgs
Mantax Otax and Gigabud banking trojans spread across Android, Russian-speaking actors deployed hundreds of AI agents to exploit PaperCut flaws on 395 organizations
AI-generated daily briefings and vulnerability analysis for security teams who need signal, not noise.
Mantax Otax and Gigabud banking trojans spread across Android, Russian-speaking actors deployed hundreds of AI agents to exploit PaperCut flaws on 395 organizations
| CVE | Product | CVSS | Exploited | Patch |
|---|---|---|---|---|
| CVE-2026-20079 | Cisco Secure Firewall Management Center (FMC) And Security Cloud Control (SCC) Firewall Management | 10 | KEV | advisory |
| CVE-2026-75650 | Adobe Commerce And Magento | 10 | KEV | ✓ available |
| CVE-2026-49869 | Kestra OSS | 10 | KEV | advisory |
| CVE-2026-83548 | SonicWall SMA1000 Appliances | 10 | KEV | advisory |
| CVE-2026-21962 | Oracle HTTP Server And Oracle Weblogic Server Proxy Plug-In | 10 | KEV | ✓ available |
KEV = listed in CISA catalog · IN WILD = active exploitation reported · PoC = public exploit code
Mantax Otax and Gigabud banking trojans spread across Android, Russian-speaking actors deployed hundreds of AI agents to exploit PaperCut flaws on 395 organizations
Cisco Secure FMC flaw CVE-2026-20079 under active attack; four China-linked espionage groups deployed BlueMoon exploit kit targeting Chrome and Windows; AI user accounts hijacked via infostealer logs to bypass MFA.
Microsoft released 974 security patches including two actively exploited zero-days. AI-driven credential harvesting compromised thousands of accounts in six hours. F5 BIG-IP devices are being breached to deploy Linux rootkits.
PEEP toolkit turns Chrome and Edge into post-compromise backdoors; Magento StyleSmuggler zero-day actively exploited to deploy Linux backdoors; BigBear phishing framework bypassed MFA at 258 organizations and stole 5,000+ Microsoft 365 credentials.
59 security tools indexed · free + paid + open source · updated regularly
No tools match your search. Try a different keyword.
Pick up to 4 tools to compare pricing, deployment, and capabilities
Once a day at 04:00 UTC, the pipeline pulls ten authoritative security feeds – including CISA advisories – and extracts the day’s most important stories and the CVEs they cite.
Every CVE is checked against NVD for canonical CVSS and cross-referenced with the CISA KEV catalog. Inline citations link each story to its sources, and a skeptical second AI pass flags – or blocks – claims it can’t substantiate.
Severity is scored from CVSS and confirmed exploitation – not editorial tone – so Critical is rare by design. Structured briefings tell your team exactly what to patch, investigate, or escalate.
Join security professionals who start their morning with defend.network intelligence. Free forever.