Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245: Netadmin-to-Root, Exploited for Months Before Disclosure
Cisco disclosed CVE-2026-20245 on 5 June 2026, a high-severity command-injection flaw in Catalyst SD-WAN Manager that Ma...
ASEAN edition · Tue, 18 Aug 2026 · Signal over noise
AI-curated tech news, ASEAN business intelligence, and cybersecurity updates — written for the region.
Cisco disclosed CVE-2026-20245 on 5 June 2026, a high-severity command-injection flaw in Catalyst SD-WAN Manager that Ma...
FortiBleed is a large-scale credential-exposure campaign against internet-facing Fortinet FortiGate firewalls and SSL VP...
CVE-2026-46331, nicknamed pedit COW, is a Linux kernel local privilege-escalation flaw in the traffic-control act_pedit...
CISA added CVE-2026-12569, a critical remote code execution flaw in PTC Windchill PDMLink and FlexPLM, to its Known Expl...
CISA added CVE-2026-20230, a server-side request forgery flaw in Cisco Unified Communications Manager, to its Known Expl...
CISA added three maximum-severity Ubiquiti UniFi OS vulnerabilities (CVE-2026-34908, -34909 and -34910) to its Known Exp...
CISA added CVE-2026-48907, a maximum-severity flaw in the Widget Factory Joomla Content Editor extension (JCE / JCE Pro)...
Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, an authentication-bypass flaw in PAN-OS GlobalPro...
Oracle issued an out-of-band alert on 10 June for CVE-2026-35273, a CVSS 9.8 unauthenticated remote-code-execution flaw...
Researchers at D3Lab say a new wave of the NFCShare Android trojan, running since mid-May 2026, poses as banking-app upd...
On 3 June, two days after the Red Hat npm compromise, the Miasma worm returned with a new delivery trick: a 157-byte bin...
MyCERT's 6 June advisory details an active Android banking-trojan campaign using three lure brands — Delivery4U, KerjaEx...
SolarWinds Serv-U CVE-2026-28318 is now in CISA’s Known Exploited Vulnerabilities catalogue after a June 2026 hotfix. Th...
Singapore's CSA rates a GlobalProtect authentication-bypass flaw critical (9.1) — sterner than Palo Alto's own HIGH rati...
The Cyber Security Agency of Singapore is evaluating whether to extend regulatory requirements to non-critical informati...
Cisco has patched CVE-2026-20230, a Unified CM and Unified CM SME server-side request forgery flaw that can lead to root...
Google’s June 2026 Android security bulletin includes CVE-2025-48595, a Framework vulnerability flagged for limited, tar...
Two major consumer brands confirmed breaches days apart — Carnival began notifying nearly six million people, and Charte...
A phone call took millions of records out of two large companies this week. A firewall bug let attackers walk past the e...
Attackers are exploiting a flaw in Palo Alto Networks' PAN-OS that lets them slip past security controls and open an una...
Nova ransomware claimed Badan Pangan Nasional — Indonesia's National Food Agency — on 29 May 2026, citing 133 compromise...
Vietnam's national cybersecurity authority disclosed on 22 May 2026 that hackers breached two ministerial-level agencies...
On 16 May 2026 HDFC AMC's IT administrator detected anomalies in the company's infrastructure and received an extortion...
India's national cybersecurity agency has told organisations running internet-facing systems to patch, mitigate, or isol...