|
Hey there,
It was a patch-heavy week. Microsoft, 7-Zip, and WordPress core all shipped fixes for actively exploitable flaws, a SonicWall zero-day chain handed ransomware crews root access, and two Talos writers independently landed on the same lesson: you can't patch everything at once, so patch smart. Add in a $1.2B endpoint security debut and a fresh debate over whether AI is helping or handcuffing defenders, and you've got this week's CyberShield digest. Let's get into it.
π¨ Critical Threats & Vulnerabilities
Inc Ransomware Chains Two SonicWall Zero-Days for Root Access
Researchers found that two separate flaws in SonicWall's Secure Mobile Access appliances can be chained together to hand attackers root-level control β and Inc ransomware operators are already using the combo in the wild. If you're running SMA gear for remote access, this is a patch-today situation, not a patch-this-sprint one. Read more β
Microsoft Patches a Record 570 Security Flaws
Nearly triple last month's count, and largely credited to AI-assisted vulnerability discovery. Great news for finding bugs before attackers do β but it also means your patch queue just got a lot longer. Prioritize the exploitable ones first. Read more β
New wp2shell Flaw Lets Unauthenticated Attackers Run Code on Any WordPress Site
This one's in WordPress core itself β no plugins required β affecting versions 6.9 and 7.0. A CVE, a public exploit chain, and a working proof-of-concept are all already out there. If you manage WordPress infrastructure, this jumps the queue. Read more β
Update Now: 7-Zip Fixes RCE Flaw in Malicious Archives
Version 26.02 closes a remote code execution hole triggered by opening a specially crafted archive β the kind of thing that ends up in a phishing attachment. If 7-Zip is on your machine (or your users'), push the update. Read more β
Malvertising Campaign Makes Your Own Browser Build the Malware
The SourTrade campaign impersonates TradingView, Solana, and Luno, then delivers malware in pieces so your browser assembles the final executable itself using a legitimate Bun runtime β no single malicious file for signature-based tools to catch. A clever evolution worth knowing about. Read more β
A Rare Win: Police Dismantle the Kratos Phishing Kit
German and US authorities took down the infrastructure behind Kratos β one of the most widely used phishing kits for stealing Microsoft 365 sessions and bypassing MFA β and Indonesian police arrested its alleged operator. International coordination working as intended. Read more β
π οΈ Tools & Strategy
Begun, the Patch Wars Have
Talos Intelligence's Joe calls this the long-predicted "Great Patching" β a surge of updates across the stack that's testing every team's patch-management maturity. The advice holds regardless of the specific CVEs: build a real asset inventory, prioritize by risk, and don't let automation replace judgment. Read more β
Don't Swing at Everything
A companion piece to the above: Talos's Thorsten walks through Q2 2026 vulnerability data and makes the case that reacting to every single disclosure burns your team out for no security gain. Smart, prioritized patching beats swinging at every pitch. Read more β
Ransomware Is Accelerating β But AI Isn't the Reason
Dark Reading digs into what's actually driving the surge: a more fragmented ransomware ecosystem, new attackers entering the space, and a growing focus on under-defended organizations. Worth a read if you've been fielding the "is it all AI now?" question from leadership. Read more β
Glow Emerges From Stealth at a $1.2B Valuation to Rethink Endpoint Security
Glow is targeting a newer class of endpoint risk: AI agents and developer tools that enterprises are adopting faster than they can secure. A reminder that "endpoint" now means a lot more than laptops and phones. Read more β
CISOs vs. Boards: Myth or Misunderstanding?
Boards are paying more attention to security than ever β but a communication gap between boardrooms and security teams still slows down decisions and budget. If you're aiming for a CISO seat someday, translating technical risk into business language is the skill to build now. Read more β
π° Industry Notes
LG to Ban Residential Proxies From Smart TV Apps
Turns out over 42% of apps on LG's webOS store were quietly letting third parties route their traffic through your TV. LG is suspending them. A good reminder that "smart" devices are still endpoints β just ones nobody's threat-modeling. Read more β
How AI Guardrails Are Impeding Offensive Security Research
The same guardrails that keep AI tools from being weaponized are also blocking legitimate researchers from using them to simulate attacks and find vulnerabilities first. There's no clean answer here, but it's a tension every offensive security team is going to keep running into. Read more β
A couple of tools we actually use
Speaking of patch queues and content pipelines piling up β two things in our own stack that keep the busywork off our plate:
Make is the visual automation layer we use to pull CVE feeds, tag them by stack, and route only the high-signal hits to our team β no more manually triaging every advisory that lands in an inbox. Free tier available. Check it out (transparency: referral link β if you sign up, it may support CyberShield at no extra cost to you).
Hypefury is what we use to keep our own content ops β including this newsletter's companion posts β running on a schedule instead of a scramble: batch drafts, queue threads, resurface evergreen posts. Take a look (transparency: referral link β if you sign up, it may support CyberShield at no extra cost to you).
That's the week. Patch what's exploitable, question the "AI did it" headlines, and keep building the skills that get you into the room where these decisions get made. See you next Sunday.
β The CyberShield Team
|