Security researchers report a surge in cyberattacks leveraging AI-driven automation, unpatched software vulnerabilities, and malicious repository packages to compromise enterprise systems and steal sensitive user credentials globally.
Key Points
- Palo Alto Networks confirmed active exploitation of a medium-severity authentication bypass vulnerability (CVE-2026-0257) affecting PAN-OS and Prisma Access firewalls.
- A critical zero-day vulnerability in the Gogs Git service allows unauthenticated remote code execution, enabling attackers to dump credentials and modify repository code.
- CrowdStrike and partners dismantled the GlassWorm malware operation, which distributed trojanized VS Code extensions and malicious Python packages via Russian-linked infrastructure.
- CERT-In issued new guidance urging organizations to patch critical internet-facing vulnerabilities within 12 hours to counter the rapid speed of AI-assisted exploitation.
- A sophisticated phishing campaign using the EvilTokens platform is abusing OAuth 2.0 device authorization flows to conduct large-scale credential theft.