Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
Anubis ransomware operators are leveraging the Citrix Bleed 2 vulnerability (CVE-2025-5777) combined with legitimate RMM tools and supply chain credentials to breach enterprise networks. Security teams must prioritize patching and monitoring for these converging attack vectors.
Google's Threat Intelligence Group, working with the FBI and Lumen, has significantly degraded NetNut, a major residential proxy network that compromised millions of home devices. The coordinated action demonstrates how threat actors abuse consumer infrastructure to facilitate malicious traffic and bypass security controls.
Threat actors are exploiting search engine optimization techniques to direct users to fake software download sites hosting malicious installers. The campaign deploys AsyncRAT through ScreenConnect, targeting popular applications like OBS Studio and Bandicam across multiple languages and domains.
A 19-year-old dual U.S.-Estonian citizen has been extradited from Finland to face federal charges related to his alleged involvement with the Scattered Spider hacking group. The case highlights law enforcement's growing focus on dismantling organized cybercriminal networks targeting enterprise systems.
A critical vulnerability in Argo CD's repo-server component allows unauthenticated attackers to execute arbitrary code and compromise Kubernetes clusters. The flaw remains unpatched with no CVE assigned, posing immediate risk to organizations using the popular deployment tool.
CISA has added CVE-2026-45659, a critical SharePoint Server remote code execution vulnerability, to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. Organizations running affected SharePoint instances face immediate risk and should prioritize patching.
A new remote access trojan called ChocoPoC is being distributed through fraudulent proof-of-concept repositories on GitHub, specifically targeting vulnerability researchers and security professionals. The malware steals credentials, browser data, and establishes persistent system access when executed.
Ubuntu security advisory USN-8487-1 addresses four significant vulnerabilities in curl affecting connection reuse, authentication, and cookie parsing. Organizations using curl across multiple Ubuntu LTS versions should prioritize patching to prevent credential theft and TLS configuration bypass attacks.
Citrix released security updates addressing six vulnerabilities in NetScaler ADC and Gateway products that could allow attackers to read arbitrary files or trigger denial-of-service conditions. Organizations running affected versions should prioritize patching to mitigate exploitation risks.
Security researchers have uncovered an API-driven backend powering ClickFix campaigns, enabling attackers to distribute polymorphic malware variants at scale. The discovery also reveals new evasion techniques designed to bypass Windows script scanning defenses.