AUTO-UPDATED

Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited

Recent cybersecurity developments include the active exploitation of a Cisco Unified CM vulnerability, a major credential-harvesting campaign targeting FortiGate firewalls, and ongoing international efforts to disrupt global malware networks.

Key Points

  • Cisco Unified CM is under active attack via CVE-2026-20230, a server-side request forgery flaw used to deploy webshells.
  • A widespread credential-harvesting campaign has compromised thousands of organizations utilizing FortiGate firewalls.
  • Operation Endgame successfully targeted the StealC and Amadey malware networks as part of a global law enforcement initiative.
  • Research indicates that 282 of 444 analyzed iOS apps with AI features expose sensitive backend credentials or access mechanisms.
  • A supply chain attack on the platform Klue resulted in unauthorized access to customer data within LastPass’s Salesforce environment.

Why it Matters

These incidents highlight the persistent vulnerability of enterprise infrastructure to both legacy software flaws and sophisticated supply chain compromises. As organizations increasingly integrate AI and third-party vendors into their workflows, the resulting expansion of the attack surface necessitates more rigorous security oversight and proactive vulnerability management.
Help Net Security Published by Help Net Security
Read original