ISC2 domain 4

Communication and Network Security

The network and the equipment at its edge: firewalls, VPNs, routers, protocols, and the attacks that arrive that way.

News

70 articles in this subject area

Updated , first published

Citrix reports multiple vulnerabilities in NetScaler ADC and Gateway

Citrix has published a bulletin covering multiple NetScaler ADC and Gateway vulnerabilities, scored 6.9 to 8.8 in CVSSv4 and requiring no authentication.

Fake recruiters talked IT staff into installing a VPN client that ran hidden code

CERT-UA describes how the threat cluster UAC-0145 approaches IT professionals on job sites and runs a full hiring process, complete with a Telegram conversation and a genuine Zoom interview. The candidate is eventually asked to download a VPN client called SopraVPN, built from WireGuard source code and running PowerShell code hidden in the SymmetricKey configuration option.

A fake job offer ended with a rootkit in the Windows kernel

Check Point Research attributes a new wave of Operation Dream Job to Lazarus, where fake job offers in the defence and aviation industries ended in exploitation of the zero-day CVE-2026-68820 in the Windows AFD.sys driver. Microsoft fixed the flaw on 11 August 2026 after Check Point reported it, and the same investigation found command traffic running through hijacked Roundcube and WordPress servers.

How attackers reached a Polish power plant through a shared mobile network

CERT Polska published a follow-up report on 8 August covering the 29 December 2025 attacks on Poland's energy supply. It describes an attack on a heat and power plant serving around 50,000 residents, where the way in ran through the grid operator's private mobile network.

An eighteen-year-old Linux kernel flaw hands ordinary users root

Tencent Zhuque Lab has found a flaw in the SCTP part of the Linux kernel that has been there since 2008. An ordinary user can use it to gain root, and to escape a container.

Cisco closes top-severity holes in SD-WAN and IOS XE, and there is no way around them

Cisco published security updates for Catalyst SD-WAN, IOS XE and the Integrated Management Controller on 5 August 2026. Three of the SD-WAN vulnerabilities carry a CVSS score of 9.9, and Cisco states that no workarounds exist for any of the advisories.

Critical authentication bypass in Check Point management servers

Check Point has fixed a critical vulnerability in Security Management Server and Multi-Domain Security Management Server. CVE-2026-18574 is scored at 9.3 and lets an attacker without login run arbitrary commands on a server reachable over the network.

CISA warns of increased attacks on control units in water and wastewater

CISA issued an alert on 30 July 2026 about a rise in threat actors attacking programmable logic controllers in the water and wastewater sector. Attackers changed passwords and altered IP addresses, leaving operators without control of their own plants. The consequences have been boil water notices and long periods of manual operation.

Unit 42: Chinese speaking actor ran autonomous attacks with an AI agent

On 30 July 2026 Unit 42 published a campaign in which a Chinese speaking actor let an AI agent find targets, fetch exploit code and attempt exploitation on its own. The autonomous attempts failed, while manual attacks against Citrix NetScaler led to confirmed data exfiltration at three organisations.

AI agent chose targets and switched vulnerability on its own in Chinese campaign

Unit 42 describes a Chinese speaking actor who paired the DeepSeek language model with the Hermes Agent framework, and let the setup find targets, pull exploit code from GitHub and switch vulnerability when the attack failed. The autonomous attempts produced no confirmed compromise. The operation was exposed by the automation itself.

Static account in Cisco Secure FMC actively exploited

On 29 July 2026 CISA added CVE-2026-20316 to its catalog of known exploited vulnerabilities. The vulnerability is a static user account in the web interface of Cisco Secure Firewall Management Center, and Cisco states that it is being actively exploited.

CI Fortify: six steps to isolate vital OT systems in a crisis

The Australian Signals Directorate has published CI Fortify, guidance on disconnecting vital operational technology from all other networks. It sets out six steps leading to an isolation plan that has to be exercised.

CISA issues seven new ICS advisories, critical flaw in Siemens building automation

Seven new advisories cover Siemens, MikroTik, igloohome and ABB. The most severe is a 9.8-rated vulnerability in the Desigo CC building automation platform, and several weaknesses currently have no fix.

Pexip rushes out fixes for critical Infinity vulnerability

Pexip has disclosed a critical vulnerability in Infinity with a CVSS score of 9.8. All customers are urged to upgrade immediately, and One-Touch Join-only systems are affected too.

Russian espionage campaign exploits Zimbra flaw without a single click

Unit 42 has uncovered a persistent Russian-linked campaign exploiting CVE-2025-66376 in unpatched Zimbra installations. The recipient does not need to click anything.

Chaos hides command traffic behind the browser

Cisco Talos has analysed msaRAT, a Rust-based remote access trojan that lets the browser do the work so the traffic looks legitimate.

Check Point patches two critical management server flaws

Check Point has fixed CVE-2026-16232 and CVE-2026-62144, both giving unauthenticated access to the management server; the first has been seen exploited.

Urgent updates released for SonicWall SMA 100

SonicWall has fixed several flaws in the SMA 100 series, including critical ones that may allow remote code execution.

Joint advisory on Russian activity against poorly secured routers

Nineteen agencies from 13 countries warn of Russian activity targeting routers exposing the legacy SNMPv1 and SNMPv2 protocols.

Palo Alto releases a fix for a PAN-OS vulnerability

CVE-2026-0288 can, under specific conditions, let an authenticated attacker affect confidentiality and integrity in PAN-OS.

UAT-7810 builds covert proxy networks from hijacked routers

Cisco Talos describes how UAT-7810 hijacks unpatched routers to build proxy networks it leases to other threat actors.

ESET: Gamaredon hides command traffic behind everyday web services

ESET reports Gamaredon ran 35 spearphishing campaigns in 2025 and increasingly hid its command infrastructure behind legitimate services.

Mandiant: Cisco SD-WAN Manager zero-day exploited for months

Mandiant describes how an actor exploited CVE-2026-20245 in Cisco Catalyst SD-WAN Manager from late 2025 to January 2026 and gained root access.

F5 issues out-of-band update for two critical NGINX flaws

Two NGINX vulnerabilities can be triggered remotely without authentication to restart worker processes, with possible code execution.