Cisco Patches Sixth SD-WAN Zero-Day of 2026 as UAT-8616 Gains Admin Access via CVSS 10.0 Auth Bypass
Cisco has disclosed CVE-2026-20182, a CVSS 10.0 authentication bypass in its Catalyst SD-WAN Controller — the sixth acti...
ASEAN edition · Tue, 18 Aug 2026 · Signal over noise
AI-curated tech news, ASEAN business intelligence, and cybersecurity updates — written for the region.
Cisco has disclosed CVE-2026-20182, a CVSS 10.0 authentication bypass in its Catalyst SD-WAN Controller — the sixth acti...
Microsoft confirmed active exploitation of CVE-2026-42897, a cross-site scripting flaw in Exchange's Outlook Web Access...
CVE-2026-48172 in the LiteSpeed User-End cPanel Plugin carries a CVSS v4.0 score of 10.0 and was added to CISA's KEV cat...
A China-aligned intrusion cluster designated SHADOW-EARTH-053 maintained covert access inside government ministries, def...
A short, practical read of the week's most urgent vulnerabilities: a critical pre-authentication flaw in the OTRS servic...
Our weekly read of the threat landscape: a state-backed actor ran a bespoke espionage operation against Malaysian govern...
On 10 May an internet-exposed marimo notebook was breached through CVE-2026-39987 — and then an autonomous LLM agent too...
On 6 May 2026, Singapore-headquartered ThreatBook launched Flocks and SafeSkill — landing in an AI SOC category that alr...
Megalodon pushed 5,718 malicious commits into 5,561 GitHub repos in six hours. The Payload ransomware group listed Singa...
On 22 May 2026, an attacker rewrote version tags across the Laravel-Lang ecosystem to deliver a 5,900-line PHP credentia...
An automated campaign called Megalodon pushed 5,718 malicious commits to 5,561 GitHub repos between 18-21 May 2026, exfi...
The OffensiveCon Pwn2Own contest wrapped on Wednesday with $1.4 million paid out across 27 zero-days. A Chrome sandbox e...
In a public write-up, Anthropic describes threat actors who induced Claude — by posing as defensive testers — into mappi...
In a quietly-published security bulletin, AWS confirmed an indirect prompt-injection attack in production Bedrock Agents...
Google's Threat Intelligence Group has described what it believes is the first case of an AI-developed zero-day exploit...
Cisco shipped an emergency advisory for CVE-2026-20182 on 15 May 2026, a peering authentication bypass in Catalyst SD-WA...
A 732-byte Python script is all an unprivileged local user needs to take root on Ubuntu 24.04, RHEL 10.1, SUSE 16 and ne...
EchoLeak shows a malicious email can trigger Microsoft 365 Copilot into exfiltrating enterprise data without a single us...
A small group of unauthorised users reached Mythos via a third-party vendor environment on the same day Anthropic announ...
Project Glasswing pairs Anthropic's restricted Mythos model with a roster of hyperscalers, banks and the Linux Foundatio...
Microsoft disclosed CVE-2026-42897 on 14 May 2026 — an XSS spoofing flaw in Exchange OWA exploited via crafted email. CV...
After ShinyHunters stole 3.65TB of data from 8,809 schools using the Canvas LMS, Instructure quietly paid the ransom. Wh...
Hacking group ShinyHunters claims to have stolen data on 275 million people from Canvas LMS operator Instructure, exposi...
CVE-2026-0300, a critical PAN-OS buffer overflow enabling unauthenticated root-level RCE, is being actively exploited by...