Security news.
Active exploitation of enterprise edge infrastructure and open-source supply chains headlines today's security briefing, with attackers actively weaponizing recent flaws in SonicWall and AhsayCBS platforms. Concurrently, law enforcement actions intensify against the ShinyHunters extortion group alongside major disruptions to state-sponsored Chinese tooling. Software teams should also take note of weaponized GitHub Actions workflows targeting open-source repositories and critical pre-auth vulnerabilities in PaperCut.
Max-Severity SonicWall SMA1000 Flaw Under Active Exploitation
Attackers are actively exploiting CVE-2026-102255, a maximum-severity flaw in SonicWall SMA1000 appliances patched just days ago. Administrators should verify appliance firmware immediately to prevent unauthorized access.
Unpatched AhsayCBS Flaws Targeted to Drop Webshells and Miners
Threat actors are actively exploiting unpatched vulnerabilities CVE-2026-105133 and CVE-2026-105134 in the AhsayCBS backup management suite. The flaws permit authentication bypass and OS command injection, enabling deployment of web shells and cryptocurrency miners.
CISA Adds Five Flax Typhoon Exploits to KEV Catalog
CISA issued a binding directive adding five vulnerabilities exploited by the China-linked threat actor Flax Typhoon to its Known Exploited Vulnerabilities catalog. The exploited flaws include legacy issues like ProFTPD flaw CVE-2015-3306 alongside other network-facing bugs.
Malicious GitHub Actions Workflows Compromise Hundreds of Repositories
Attackers compromised high-profile open-source maintainer accounts to inject credential-stealing GitHub Actions workflows into over 340 repositories. Engineering teams should audit CI/CD workflow files and restrict build secret permissions across their dependency tree.
PaperCut Discloses Pre-Auth RCE Vulnerability Chain and Bypasses
Security researchers released technical details regarding a pre-authentication remote code execution chain and multiple patch bypasses affecting PaperCut servers (tracked under CVE-2026-82077, CVE-2026-82078, and CVE-2026-81578). Administrators are urged to update to the latest patched releases.
Cyber Executive Arrested in Crackdown on ShinyHunters Group
A Canadian cybersecurity executive has been arrested in the U.S. in connection with extortion operations tied to the ShinyHunters hacking ring. The arrest comes amidst a wider law enforcement push following the group's compromise of FBI personnel data.
New P7 DarkSword iOS Exploit Kit Targets Crypto Wallets
Researchers identified an updated P7 variant of the DarkSword iOS exploit kit featuring a reduced on-device footprint, bidirectional C2 communication, and automated theft of keychain and cryptocurrency wallet credentials.