← All Intelligence

Government Industry Intelligence

55 briefings11 vulnerability reports

Government agencies at all levels face threats from nation-state actors, hacktivists, and criminal groups seeking sensitive data or disruptive impact. Federal mandates like CISA directives create specific patch timelines that government security teams must meet. defend.network tracks threats targeting government infrastructure, including CISA advisories, federal agency breaches, and attacks against election and critical infrastructure systems.

55
briefings
3
critical
26
high
59%
of all briefings

Threat Briefings

2026-06-20

Apple A12/A13 unpatchable exploit; Gentlemen RaaS doubles EDR killers; Fortinet FortiBleed escalates

Apple A12/A13 SecureROM exploited with unpatchable code execution; Gentlemen RaaS expands EDR-evasion toolkit targeting 400 processes; Fortinet FortiBleed now hits 86,644 devices. Klue OAuth breach spreads Salesforce credential theft to cybersecurity vendors.

2026-06-14

Splunk RCE, Arch Linux supply-chain hijack, Velvet Ant decade-long backdoor

Splunk Enterprise CVE-2026-20253 (CVSS 9.8) enables unauthenticated RCE; 400+ Arch Linux AUR packages hijacked with infostealer/rootkit; China-linked Velvet Ant maintained decade-long PAM/OpenSSH backdoor.

2026-06-10

Microsoft 200-patch record, Veeam RCE critical, GitHub supply-chain worm ongoing

Microsoft released record 200 Patch Tuesday fixes including critical flaws; Veeam Backup & Replication RCE (CVE-2026-44963, CVSS 9.4) requires immediate patching; 73 GitHub repos remain compromised as Miasma supply-chain attack investigation continues.

2026-06-08

Miasma worm hits Microsoft GitHub, SolarWinds Serv-U actively exploited, WordPress Everest Forms RCE

Miasma worm compromises 73 Microsoft GitHub repositories; SolarWinds Serv-U DoS flaw confirmed actively exploited; WordPress Everest Forms Pro critical RCE under active attack; Meta AI bot abused to reset Instagram accounts.

2026-06-07

Miasma worm hits Microsoft GitHub; SolarWinds actively exploited; Chrome 429 patches

Microsoft GitHub hit by Miasma self-replicating worm across 73 repositories; SolarWinds Serv-U actively exploited for DoS; Chrome 149 patches record 429 vulnerabilities.

2026-06-05

Cisco Unified CM RCE, Claude GitHub Action Hijack, AI Agent Exploits

Cisco patches critical Unified CM RCE with public PoC; Claude Code GitHub Action flaw enables repository hijack via GitHub issues; AI agents exploited in defense networks; Hola Browser compromised with cryptominer.

2026-06-03

Android, WinRAR, WordPress Kirki: Three critical zero-days under active exploitation

Google Android zero-day (CVE-2025-48595) actively exploited; Gamaredon APT weaponizing WinRAR; WordPress Kirki plugin hijacking admin accounts. CISA adds Oracle WebLogic to KEV catalog.

2026-06-02

Red Hat npm, WordPress, Instagram under active attack; critical Windows vulnerability patching urgent

Red Hat npm packages compromised with Miasma credential-stealing worm; WordPress RCE via CVE-2026-8732; Instagram accounts hijacked via Meta AI bot exploit. Patch WP Maps Pro immediately, rotate developer credentials, enable MFA.

2026-06-01

PAN-OS GlobalProtect actively exploited; Russian infrastructure dismantled; Linux kernel flaw

Palo Alto PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) actively exploited; Dutch authorities arrest two hosting operators supporting Russian cyberattacks; Linux kernel CIFSwitch flaw allows privilege escalation.

2026-05-31

Active exploits: Palo Alto GlobalProtect, CISA credential leak, Linux kernel RCE

Palo Alto PAN-OS GlobalProtect flaw (CVE-2026-0257) under active exploitation; CISA contractor exposed AWS GovCloud keys on GitHub; Linux kernel CIFSwitch privilege escalation disclosed.

2026-05-29

FortiClient EMS, GitHub secrets, CISA breach: critical exploitation ongoing

FortiClient EMS actively exploited to deploy credential stealer; CISA contractor leaked AWS GovCloud keys on GitHub; BTMOB Android RAT spreading via phishing with builder interface.

2026-05-28

FortiClient EMS, Gogs RCE actively exploited; CISA GitHub leak exposes AWS keys

FortiClient EMS and Gogs RCE vulnerabilities actively exploited in the wild. CISA contractor exposed AWS GovCloud credentials on GitHub. FIFA World Cup fraud campaigns register 4,300+ malicious domains.

2026-05-27

Critical RCEs and credential leaks: Microsoft SharePoint, CISA AWS exposure, MuddyWater espionage

Microsoft patched SharePoint RCE (CVE-2026-45659); CISA contractor exposed AWS GovCloud keys on GitHub; MuddyWater targeted nine organizations across four continents using DLL side-loading.

2026-05-25

GitHub npm supply chain attacks, LiteSpeed RCE, CISA credentials exposed

Supply-chain attacks hit npm and Composer ecosystems; LiteSpeed cPanel CVE-2026-48172 actively exploited; CISA contractor exposed AWS GovCloud credentials on GitHub.

2026-05-23

GitHub supply-chain attack, Drupal RCE, AWS GovCloud credential leak

GitHub campaign injects malware into 5,561 repos; Drupal SQL injection actively exploited; CISA contractor exposes AWS GovCloud credentials.

2026-05-22

Critical RCEs: Microsoft Defender, Linux kernel, Cisco Workload; Showboat targets telcos

Microsoft Defender vulnerabilities actively exploited; 9-year-old Linux kernel flaw enables root execution; Cisco Workload max-severity RCE patched; Showboat malware targets telcos across Middle East and Central Asia.

2026-05-20

Microsoft, Drupal, Linux critical patches; OAuth phishing bypasses MFA on 340+ orgs

Microsoft disrupted Fox Tempest malware-signing service; Drupal critical patches May 20; OAuth phishing bypasses MFA on 340+ Microsoft 365 organizations. CVE-2026-31635 Linux PoC public.

2026-05-18

Zero-days exploited: NGINX, MS Exchange, Cisco SD-WAN; TanStack hit

Critical zero-days in NGINX, Microsoft Exchange, and Cisco SD-WAN actively exploited in the wild. TanStack supply chain attack compromises OpenAI and AI companies. Immediate patching required.

2026-05-17

Critical RCEs exploited: Cisco SD-WAN, Exchange, Funnel Builder

Critical vulnerabilities in Cisco SD-WAN (CVSS 10.0), Microsoft Exchange, and Funnel Builder WordPress plugin under active exploitation. Supply chain attacks compromise npm packages. Immediate patching required.

2026-05-16

MS Exchange zero-day exploited; npm hits OpenAI; Turla evolves Kazuar

Critical Microsoft Exchange zero-day exploited in wild; npm supply chain attacks compromise OpenAI; Turla APT evolves Kazuar into P2P botnet; WordPress plugins actively harvesting payment cards.

2026-05-15

Cisco SD-WAN zero-day exploited; TanStack supply-chain hits OpenAI

Critical Cisco SD-WAN zero-day exploited in the wild; supply chain attacks compromise TanStack and node-ipc; state APTs target government; education platform disrupted by extortion.

2026-05-07

vm2, Palo Alto, DAEMON Tools exploited; Iran APT false-flag operations

Critical vulnerabilities in vm2, Palo Alto firewalls, and DAEMON Tools combined with Russian military intelligence token harvesting and Iranian APT false-flag campaigns demand immediate patching and investigation.

2026-05-06

Apache HTTP/2 & MetInfo exploited; DAEMON Tools supply-chain hit

Critical vulnerabilities in Apache HTTP/2 and MetInfo CMS, supply-chain compromise of DAEMON Tools, and persistent OAuth backdoors require immediate response.

2026-05-04

Linux root vulnerability in KEV; cPanel mass-exploitation continues

Critical Linux root access vulnerability added to CISA KEV with active exploitation confirmed. Multiple critical threats including cPanel mass-exploitation, source code breaches, and state-sponsored APT campaigns.

2026-05-03

cPanel RCE ransomware; 30K Facebook hacked; Trellix source leaked

Critical cPanel RCE exploited for ransomware; Russian military harvesting Office tokens; 30K Facebook accounts compromised; Trellix source code breached; automated Azure OAuth attacks.

2026-05-02

cPanel auth bypass; state token harvesting; SaaS extortion attacks

Critical vulnerabilities, state-sponsored token harvesting, large-scale phishing operations, and coordinated SaaS extortion attacks demand immediate defensive action across government and technology sectors.

2026-05-01

PyTorch Lightning & SAP supply-chain; AI cuts attack time to 24h

Critical supply chain attacks compromise PyTorch Lightning and SAP packages; Russian state-sponsored actors steal Office tokens; AI-accelerated exploitation shrinks time-to-compromise to 24 hours.

2026-04-28

Developer platform supply-chain attacks; Windows RPC zero-day

Critical supply chain attacks on developer platforms, Russian state-sponsored token theft via router exploits, and unpatched Windows RPC privilege escalation demand immediate defensive action.

2026-04-27

FIRESTARTER federal Cisco persistence; Chinese APT GopherWhisper

Critical threats include FIRESTARTER backdoor persistence on federal Cisco devices, Russian military token theft via router exploitation, Chinese APT GopherWhisper attacks, and four actively exploited CISA KEV vulnerabilities with May 2026 federal patching deadline.

2026-04-26

FIRESTARTER on federal Cisco gear; 4 critical CVEs added to CISA KEV

FIRESTARTER backdoor persists on federal Cisco infrastructure despite patches; Russian state actors harvesting Office tokens via router exploits; four critical CVEs added to CISA KEV with May 2026 deadline; APT campaigns targeting U.S. defense sector; AI-powered phishing escalates to personalized 1-to-1 attacks.

2026-04-25

FIRESTARTER persists on federal Cisco; APT spear-phishes NASA

FIRESTARTER backdoor persists on federal Cisco infrastructure despite patches. Russian military intelligence harvesting Office tokens via router exploits. Chinese APT targeting NASA and defense sector with spear-phishing. AI-powered phishing and FakeWallet credential theft escalating.

2026-04-24

Bitwarden CLI & Checkmarx compromised; Russian Office 365 token theft

Critical supply-chain compromises affecting Bitwarden CLI and Checkmarx tools; Russian state actors harvesting Office 365 tokens; AI-powered attacks outpacing human response capabilities.

2026-04-22

Russian APT token theft; Gentlemen ransomware claims 1,570 victims

Russian state-backed APT harvesting Microsoft tokens, 1,570+ Gentlemen ransomware victims, critical SD-WAN and RMM exploits, Windows Defender flaws—urgent patching required across infrastructure.

2026-04-21

SGLang & Anthropic MCP RCE; APT campaigns hit OT/healthcare auth

Critical RCE vulnerabilities in AI infrastructure (SGLang, Anthropic MCP) combined with state-sponsored APT campaigns targeting authentication systems and OT/healthcare infrastructure demand immediate patching and access controls.

2026-04-20

Defender zero-day; protobuf.js RCE; APT28 hits Ukrainian government

Critical Microsoft Defender zero-days actively exploited, 68% of cloud breaches from unmanaged service accounts, Russian state actors harvesting Office tokens, protobuf.js RCE with public exploit, APT28 targeting Ukrainian government.

2026-04-19

Microsoft Defender zero-days; 68% cloud breaches from ghost identities

Critical Microsoft Defender zero-days under active exploitation, 68% of cloud breaches from unmanaged service accounts, and Russian state-sponsored token harvesting campaigns demand immediate action.

2026-04-17

Apache ActiveMQ exploited; Defender zero-day; ZionSiphon hits water

Apache ActiveMQ actively exploited; Microsoft Defender zero-day disclosed; Russian state actors harvesting Office 365 tokens; ZionSiphon targets water infrastructure.

2026-04-16

nginx-ui auth bypass exploited; SharePoint zero-day in 169 patches

Critical nginx-ui authentication bypass actively exploited; Microsoft releases 169 patches including SharePoint zero-day; n8n webhooks weaponized for phishing; WordPress plugins and signed software compromised.

2026-04-15

Microsoft zero-days exploited; Mirax RAT hits 220K; PHP supply chain

Critical Microsoft zero-days under exploitation, Russian state hackers harvesting Office tokens via routers, and 220K users compromised by Mirax RAT. Supply-chain risks escalating across PHP and development ecosystems.

2026-04-14

Adobe zero-day exploited; APT37 attacks; AI-powered exploitation

Critical Adobe zero-day under active exploitation, Russian state-sponsored token harvesting, and APT37 social engineering campaigns compound with AI-powered vulnerability discovery threats.

2026-04-13

Adobe Reader zero-day; CPUID STX RAT supply-chain; Iran hits 4,000 ICS

Critical Adobe Reader zero-day, CPUID supply-chain compromise distributing STX RAT, Russian APT harvesting Office tokens via router exploits, and Iranian actors targeting 4,000+ U.S. industrial control systems.

2026-04-11

Marimo RCE exploited; Iran targets 4,000 US PLCs; Russian token theft

Critical exploitation of Marimo RCE, Iranian targeting of 4,000 US PLCs, and Russian token harvesting via routers demand immediate patching and access controls.

2026-04-09

APT28 PRISMEX on NATO; ActiveMQ 13-yr RCE; Russian router token theft

APT28 deploys PRISMEX malware targeting NATO allies; 13-year-old ActiveMQ RCE and Russian router-based token theft critical; new botnets and healthcare ransomware disruptions.

2026-04-08

APT28 DNS hijack via routers; Iran hits PLCs; Docker RCE

Russian APT28 conducting large-scale DNS hijacking via compromised routers for token theft; Iranian hackers targeting U.S. critical infrastructure PLCs; critical Docker and Flowise vulnerabilities under active exploitation.

2026-04-07

Iran & DPRK target Microsoft 365; GitHub C2 supply-chain attacks

State-sponsored APT campaigns targeting Microsoft 365 and supply chains escalate with GitHub C2 usage and zero-day exploits deployed within 24 hours of breach.

2026-04-05

TA416 PlugX on EU govts; UNC1069 Axios npm; device code phishing 37x

Nation-state campaigns targeting European governments and supply chain infrastructure. TA416 resumes targeting with PlugX. North Korean UNC1069 compromises Axios npm. Device code phishing surges 37x.

2026-04-04

TrueConf zero-day; TA416 hits EU govts; UNC1069 npm compromise

Critical zero-day in TrueConf, resurgent Chinese APT targeting European governments, North Korean npm supply chain compromise, and third-party vendor breaches require immediate response

2026-04-02

Chrome & TrueConf zero-days exploited; widespread malware campaigns

Critical zero-day vulnerabilities in Chrome and TrueConf under active exploitation, combined with widespread malware campaigns targeting mobile and enterprise infrastructure.

2026-04-01

TrueConf zero-day exploited; North Korea Axios npm compromise

Critical zero-day exploits in TrueConf and North Korean Axios compromise, plus wiper attacks and AI platform over-privilege vulnerabilities demand immediate response across cloud, government, and healthcare sectors.

2026-03-31

Citrix exploited; Axios npm RAT supply-chain; OpenAI data theft

Critical Citrix vulnerability actively exploited, Axios npm supply chain attack spreading RAT, OpenAI vulnerabilities enabling data theft, state-sponsored APT operations escalating against telecom and healthcare sectors

2026-03-30

FBI Director email breached; Citrix & F5 zero-days exploited

FBI Director's email breached by Iran-linked hackers; critical Citrix and F5 vulnerabilities under active exploitation; wiper attacks target Stryker; nation-state exploit kits leaked publicly.

2026-03-29

Iran breaches FBI Director email; Citrix & F5 zero-days unpatched

Iran-linked actors breached FBI Director Kash Patel's email and launched wiper attacks on Stryker. Critical Citrix and F5 vulnerabilities under active exploitation with no patches available.

2026-03-27

Chinese APT in telecom backbone; Langflow zero-day exploited

State-sponsored Chinese APT embedded in telecom backbone, critical Langflow AI vulnerability actively exploited, wiper malware targeting Iran systems, and zero-click AI assistant vulnerabilities require immediate response.

2026-03-26

AI autonomous espionage; device code phishing at 340+ orgs

AI-powered autonomous cyber espionage, device code phishing at 340+ organizations, and critical infrastructure vulnerabilities require immediate defensive action across all sectors.

2026-03-23

Russian phishing on Signal/WhatsApp; Oracle RCE exploited

Russian intelligence conducting mass Signal/WhatsApp phishing; critical Oracle RCE vulnerability; Trivy supply-chain attack spreads CanisterWorm across 47+ npm packages; VoidStealer bypasses Chrome encryption; Iran-backed wiper attacks on medical technology.

Vulnerability Reports

June 15 – 21

Vulnerability Report – Week 3 of June 2026

This week's verified vulnerability coverage is limited to one actively exploited CVE: CVE-2026-20253 affecting Splunk Enterprise, which CISA has added to its Known Exploited Vulnerabilities catalog wi

11 critical 9 high
June 1 – 7

Vulnerability Report – Week 1 of June 2026

Three verified CVEs dominated this week's reporting: one actively exploited Linux kernel vulnerability (CVE-2022-0492) now in CISA's Known Exploited Vulnerabilities catalog, one proof-of-concept relea

8 critical 6 high
May 18 – 24

Vulnerability Report – Week 3 of May 2026

This week presents an exceptionally high-risk threat landscape with multiple critical vulnerabilities under active exploitation across infrastructure, enterprise, and open-source ecosystems. Immediate

0 critical 2 high
May 11 – 17

Vulnerability Report – Week 2 of May 2026

This week marks a significant surge in actively exploited vulnerabilities, with three critical flaws requiring immediate patching across IT infrastructure and OT systems. The Ollama out-of-bounds read

2 critical 2 high
May 4 – 10

Vulnerability Report – Week 1 of May 2026

This week presents an exceptionally high-risk threat landscape dominated by active exploitation campaigns and critical infrastructure vulnerabilities. Federal agencies face an immediate Sunday deadlin

0 critical 0 high
April 27 – May 3

Vulnerability Report – Week 4 of April 2026

This week presents elevated risk from actively exploited vulnerabilities across network infrastructure, IoT devices, and enterprise software. Immediate patching is required for Cisco Firepower/ASA dev

3 critical 7 high
April 20 – 26

Vulnerability Report – Week 3 of April 2026

This week presents elevated risk across OT/ICS sectors with multiple critical RCE vulnerabilities in industrial control systems and emerging threats to cloud infrastructure. Active exploitation of Mic

5 critical 8 high
April 13 – 19

Vulnerability Report – Week 2 of April 2026

This week presents an elevated threat landscape dominated by actively exploited critical vulnerabilities in both IT and OT environments. Iranian-affiliated threat actors are actively targeting US crit

0 critical 0 high
April 6 – 12

Vulnerability Report – Week 1 of April 2026

This week presents elevated risk with five critical vulnerabilities actively exploited in the wild, including FortiClient EMS and video conferencing systems requiring immediate patching. Organizations

0 critical 0 high
March 30 – April 5

Vulnerability Report – Week 5 of March 2026

This week reflects sustained critical threats across OT/ICS and enterprise systems with multiple actively exploited vulnerabilities. F5 BIG-IP APM (CVE-2025-53521) and Citrix NetScaler (CVE-2026-3055)

0 critical 0 high
March 14–20

Vulnerability Report – Week 3 of March 2026

This week demands immediate attention. Two actively exploited vulnerabilities (VMware ESXi and FortiOS) require emergency patching. Organizations using Windows Server should prioritize the kernel priv

0 critical 0 high

Get the Daily Briefing in Your Inbox

Subscribe free and never miss a threat briefing.