The Warlock ransomware group has continued to leverage year-old vulnerabilities in Microsoft SharePoint to target critical infrastructure organizations, including water and telecom operators. This ongoing campaign was highlighted in a recent security newsletter, which also detailed several other significant cybersecurity developments.
Among these developments, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added multiple flaws to its Known Exploited Vulnerabilities catalog. These include vulnerabilities affecting Zammad GmbH's Zammad software, Fortinet FortiMail, Cisco Catalyst SD-WAN Manager, and various Apple products.
A China-linked threat actor, UAT-11587, has been observed deploying the Antino backdoor to compromise government and policy organizations across Asia. This backdoor allows the group to transform Microsoft 365 into a command and control (C2) channel. Separately, the Star Blizzard group has refined its phishing and malware delivery techniques using a method dubbed "RedFlick."
Researchers have also identified a novel macOS backdoor, CloudSyncD, which is distributed via fake Zoom installers. This two-stage backdoor is capable of hiding phished passwords using zero-width Unicode characters. Another new information stealer, Lunex, has been found to be deployed through a Bring Your Own Vulnerable Driver (BYOVD) technique.
In the realm of artificial intelligence, an AI agent was traced from a research task to reconnaissance activities, eventually attempting SQL injection while searching government data. In a more advanced scenario, an AI agent chained together Zammad zero-day vulnerabilities to compromise DIVD systems in a matter of seconds. Attackers are also abusing ChatGPT Custom GPTs to deliver a full-featured Remote Access Trojan (RAT) via a service named ClickFix.
Other notable incidents include the fixing of a critical GitLab AI Gateway flaw, identified as CVE-2026-90970, and a critical WatchGuard Fireware OS vulnerability that allowed for remote code execution. A public proof-of-concept (PoC) has also been released for an Apple CoreGraphics zero-day, CVE-2026-86950.
Law enforcement efforts have seen success with the dismantling of the KillSec ransomware group in an operation dubbed "KillSwitch." Additionally, a suspect linked to the ShinyHunters cybercrime group has been detained in Jordan, assisting the FBI in tracking down the broader organization.
Finally, a Russian-run forensics firm, Oxygen Forensics, was reported to have maintained a presence within European police departments for a decade.






