Cisco has confirmed active exploitation of two vulnerabilities, CVE-2026-20122 and CVE-2026-20128, in its Catalyst SD-WAN Manager software.
The company strongly urges administrators to upgrade to a fixed software release to remediate these actively exploited flaws.
Triage: Immediate patching is required due to active exploitation.
Attack Vector: CVE-2026-20122 allows a remote attacker with read-only credentials to overwrite arbitrary files. CVE-2026-20128 is an information disclosure flaw requiring a local attacker to have valid credentials.
Ease of Exploit: The exploits require valid credentials, either for remote API access (CVE-2026-20122) or local access (CVE-2026-20128).
Action Plan
Immediate Action: Cisco strongly recommends that all customers upgrade to a fixed software release to remediate these vulnerabilities.
Workaround: No workarounds have been provided; upgrading is the only remediation.
Detection: Administrators should monitor for unauthorized file modifications and unusual activity from authenticated users, especially concerning API access.
Relevant professional terms
SD-WAN (Software-Defined Wide Area Network)
A virtual WAN architecture that allows enterprises to leverage any combination of transport services - including MPLS, LTE, and broadband internet services - to securely connect users to applications.
Arbitrary File Overwrite
A type of vulnerability where an attacker can write data to any file on the target system. This can lead to remote code execution, denial of service, or elevation of privileges by overwriting critical system files.
A high-severity command injection vulnerability, identified as CVE-2026-22719, has been found in VMware Aria Operations.
The flaw is under active exploitation and allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution.
Triage: Urgent. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.
Attack Vector: An unauthenticated attacker can remotely exploit this command injection flaw. However, the vulnerability is only exposed during a support-assisted product migration, which makes the attack complexity high.
Ease of Exploit: The exploit requires a specific operational condition (product migration), making it complex but proven to be possible.
Action Plan
Immediate Action: Upgrade to a fixed version, such as VMware Aria Operations 8.18.6 or other resolved versions as specified by the vendor.
Relevant professional terms
Command Injection
A type of cyber attack that involves executing arbitrary commands on a host operating system. The attacker exploits a vulnerability in an application to extend its functionality and run commands, often to gain unauthorized access to the system or data.
Remote Code Execution (RCE)
A vulnerability that allows a malicious actor to execute any code of their choice over a network on a target machine. RCE vulnerabilities are often considered the most critical as they can grant an attacker full control over the compromised system.
Israeli intelligence reportedly hacked nearly all of Tehran's traffic cameras in a multi-year operation to gather intelligence and monitor the movements of Iran's Supreme Leader Ali Khamenei and his security detail, culminating in a lethal, targeted airstrike.
Key TTPs
Initial Access: Long-term compromise of nearly all traffic cameras in Tehran and penetration of mobile phone networks.
Execution: Used AI and complex algorithms to process surveillance data and build "pattern of life" models on key individuals.
Defense Evasion: Disrupted cellular service near the target area to prevent potential warnings from being communicated.
Campaign Analysis
This operation demonstrates a sophisticated fusion of long-term cyber-espionage with kinetic military action, turning civilian infrastructure into a tactical asset for assassination.
The extensive data analysis highlights a mature capability to process vast information for precise, real-world outcomes.
Targeting & Infrastructure
Target Profile: Iranian Supreme Leader Ali Khamenei and his senior security officials.
Infrastructure: Tehran's city-wide traffic camera network and local mobile phone towers.
Relevant Terms
Cyber-Espionage: The use of computer networks to gain illicit access to confidential information, typically held by a government or other organization.
Pattern of Life: An intelligence analysis method used to identify and understand the habits, routines, and relationships of a target through surveillance.
The U.S. and Israel launched "Operation Epic Fury" (also called "Operation Lion's Roar"), a coordinated kinetic and cyber campaign against Iran.
The operation aims to dismantle Iran's security and military infrastructure through integrated physical strikes and large-scale cyberattacks targeting critical systems.
Key TTPs
Initial Access: Widespread offensive cyber operations preceded or accompanied initial kinetic strikes. This included deep network intrusions and compromising satellite broadcasts for psychological operations.
Execution: A massive cyberattack caused a near-total internet blackout, with connectivity dropping to 1-4% of normal levels. This was synchronized with air and missile strikes on over 1,700 targets.
Campaign Analysis
This operation represents a significant evolution in warfare, seamlessly fusing large-scale kinetic strikes with a comprehensive cyber assault to paralyze a nation's command and control.
The campaign's goal was to degrade military capabilities while simultaneously creating a communications blackout and sowing internal disruption.
Targeting & Infrastructure
Target Profile: Iranian leadership and the Islamic Revolutionary Guard Corps (IRGC), including command centers, air defense, missile sites, and naval assets.
Infrastructure: The cyberattack targeted critical national infrastructure, including internet connectivity, government websites, communications systems, and media outlets.
Relevant Terms
Kinetic Warfare: Military action involving physical force and conventional weapons, such as missile strikes and bombing campaigns.
Command and Control (C2): The infrastructure and systems used by military commanders to direct and control forces and operations. Disrupting C2 is a primary goal in modern warfare.
The Coruna exploit kit, a sophisticated toolkit with 23 exploits, has transitioned from state-sponsored espionage to financially motivated attacks.
Threat actors are now using it to target cryptocurrency users by compromising vulnerable iPhones.
Key TTPs
Initial Access: Victims are directed to malicious websites (watering hole attack), where a hidden iFrame delivers the exploit kit.
Execution: The framework fingerprints the device and iOS version to deliver a tailored WebKit remote code execution exploit.
Defense Evasion: The exploit kit checks for and aborts its execution if the device is in Lockdown Mode or using private browsing.
Campaign Analysis
Coruna's evolution from a targeted surveillance tool used by state actors to a commodity for mass-scale criminal operations marks a significant proliferation of advanced mobile threats. This shift dramatically expands the potential victim pool beyond traditional espionage targets.
Targeting & Infrastructure
Target Profile: Initially Ukrainian users and government targets, now broadened to global cryptocurrency and finance app users.
Infrastructure: A large network of fake Chinese websites related to finance and cryptocurrency are used to host the exploit kit.
Relevant Terms
Exploit Kit: A software toolkit designed to identify and attack vulnerabilities on a victim's device, typically through a web browser, to deploy malware.
Watering Hole Attack: A cyberattack strategy where an attacker compromises a website likely to be visited by a specific target group, rather than attacking the targets directly.
A suspected Iran-nexus threat actor, dubbed Dust Specter, is targeting Iraqi government officials by impersonating the nation's Ministry of Foreign Affairs.
The campaign, observed in January 2026, delivers a suite of new malware tools to compromise high-value targets.
Key TTPs
Initial Access: Social engineering lures with password-protected RAR archives delivered to targets.
Execution: In-memory PowerShell execution and commands polled from text files.
Defense Evasion: DLL sideloading via legitimate applications like VLC and WingetUI, alongside using invisible Windows forms to delay execution.
Campaign Analysis
This campaign marks an evolution in the actor's methods, utilizing four previously undocumented .NET malware families.
Evidence also suggests the use of generative AI in the malware development process, indicating experimentation with new techniques to enhance their toolkit.
Targeting & Infrastructure
Target Profile: Government officials within, or affiliated with, Iraq's Ministry of Foreign Affairs.
Infrastructure: Compromised Iraqi government-related infrastructure used to host malicious payloads and C2 domains.
Actionable Intelligence
Domains:meetingapp[.]site
Relevant Terms
DLL Sideloading: A technique where an attacker places a malicious DLL file in a location where a legitimate application will load it instead of the intended one, allowing the malicious code to be executed.
C2 (Command and Control): The server infrastructure that attackers use to send commands to and receive data from compromised systems (bots).
The Russian-linked threat actor APT28 is targeting Ukrainian entities with a new campaign. The operation uses phishing emails to deliver two new malware families, a loader called BadPaw and a backdoor named MeowMeow.
Key TTPs
Initial Access: Phishing emails from a compromised, legitimate Ukrainian email provider containing a link to a ZIP archive.
Execution: A malicious HTML Application (HTA) file, disguised as an HTML file, is launched from the ZIP archive to initiate the infection chain.
Defense Evasion: The malware checks for sandbox environments by querying the OS installation date and scans for analysis tools like Wireshark and ProcMon before executing. Both malware strains are obfuscated using the .NET Reactor packer.
Campaign Analysis
This campaign showcases APT28's continued focus on Ukraine, evolving its toolkit with previously undocumented malware.
The use of multi-layered defense evasion and legitimate infrastructure for initial access highlights the group's increasing sophistication.
Targeting & Infrastructure
Target Profile: Ukrainian entities.
Infrastructure: Phishing emails are sent from the legitimate Ukrainian provider ukr[.]net to increase credibility.
Relevant Terms
Backdoor: A type of malware that bypasses normal authentication procedures to grant a remote attacker unauthorized access to a system.
Loader: A malicious program used to download and execute other malware payloads onto a compromised system.