Security News

Cybersecurity news aggregator

📰
INFO News

Security Evening Update - July 16, 2026

  • ## Þjónustu samantekt Þjónustuþróunin á 16. júlí 2026 er skilgreind með víðsælum, í virkri nýtingu veikleikum á kerfisþjónustu fyrirtækja. Þarf á aðgerð á skammti fyrir nýlega birtum núll-daga veikleikum í **SonicWall SMA1000** tækjum og kritískum uppfærslum fyrir **Adobe ColdFusion**, báðar undir virkri nýtingu. Aðfangakeðja **npm** er að breytast, nú að ræða útvegaðar auðkenni fyrir forritarar á GitHub Actions. Þar að auki eru rússnesk stjórnarskipulagðir aðildar (FSB Center 16) að nýta gamla veikleika í rúttarum (CVE-2018-0171) og óstýrðar SNMP stillingar til að útvegaða netkerfisstillinger heimsins. ## ⚠️ Aðgerð á skammti
  • *Núll-daga veikleikar í SonicWall SMA1000 að nýta** Tvær kritískar núll-daga veikleikar í SonicWall Secure Mobile Access (SMA) 1000 seríu tækjum eru að nýta, sem leyfir fjarkeyrslu kóða og auðkenningarframhjáhlaup.
  • *CVE:** CVE-2026-15409, CVE-2026-15410 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** SMA 1000 seríu útgáfa 12.4.3-03245 og síðar (einkenni útgáfa ekki fullt skýrt)
  • *Lagfært í:** Ekki tilgreint í heimildum — skoðið framleiðandastillingu
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [Rapid7 Research](https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410)
  • *Kritískar RCE veikleikar í Adobe ColdFusion að nýta** Adobe hefur uppfært margar kritískar veikleikar í ColdFusion, meðal annars CVE-2026-48282, sem er staðfest sem í virkri nýtingu. Þessi veikleikar leyfa fjarkeyrslu kóða, réttindaaukning og gagnaleiki.
  • *CVE:** CVE-2026-48282 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** ColdFusion 2023 og 2025 áður en tilteknu uppfærslum (útgáfur ekki tilgreindar)
  • *Lagfært í:** Ekki tilgreint í heimildum — skoðið framleiðandastillingu
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [BSI Germany](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2364)
  • *🏢 Fortinet FortiSandbox kritískar RCE veikleikar** Fjöldi kritískra veikleika í Fortinet FortiSandbox, með CVSS stig upp á 9.8, eru í virkri nýtingu, sem leyfir óauðkenndar fjarkeyrslur kóða.
  • *CVE:** CVE-2026-39813, CVE-2026-39808, CVE-2026-25089 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Útgáfur áður en 5.0.6 og 4.4.9
  • *Lagfært í:** 5.0.6, 4.4.9
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [SecurityWeek](https://www.securityweek.com/?p=47207)
  • *Splunk Enterprise kritísk RCE undir virkri nýtingu** Einn kritískur veikleikur í Splunk Enterprise (CVE-2026-20253) er í virkri nýtingu, sem leyfir óauðkenndar fjarkeyrslur kóða og gagnasýningu.
  • *CVE:** CVE-2026-20253 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Splunk Enterprise útgáfur 10.x og 9.x áður en nýjar uppfærslur
  • *Lagfært í:** Ekki tilgreint í heimildum — skoðið framleiðandastillingu
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [Help Net Security](https://www.helpnetsecurity.com/?p=375286) ## 🔍 Þjónustu aðgerð
  • *Rússnesk stjórnarskipulagðir að ræða heimsins rúttarum** Þjónustu aðili FSB Center 16 er að nýta óstýrðar SNMP stillingar og gamla veikleika í Cisco IOS (CVE-2018-0171) (CVSS 9.8) til að útvegaða rúttarstillingar heimsins. Þessi aðgerð hefur áhættu af óuppfærðum netkerfisþjónustum.
  • *TTPs:** Nýting á CVE-2018-0171 (misnotkun Smart Install protocol) og óstýrðar SNMP stillingar.
  • *Brotavísir:** Útvegaðar stillingar frá rúttum.
  • *Mætti:** Uppfæra veikleika CVE-2018-0171, slökkt á ónýtaða SNMP þjónustu og stýrðu SNMP samfélagsnöfnum.
  • *Heimild:** [CSO Online](https://www.csoonline.com/article/4196447/governments-to-enterprises-improve-your-router-security-hygiene.html)
  • *npm aðfangakeðja aðgerð hefur breyst til að ræða GitHub Actions** Það er aðgerð á "Miasma" og "IronWorm" gíslatökuhugbúnaði sem ræða npm pakka. Þjónustu aðilar eru nú að fjarlægja pakka til að útvegaða forritarauðkenni, API lykla og kriptóvaluta upplýsingar, með sjálfstæðu útbreiðslu gíslatökuhugbúnaðs og aðgerð á GitHub Actions vinnusviðum.
  • *TTPs:** Notkun á ósællum `postinstall` skrifum í skemmdum npm pakka (@automagik/genie, pgserve). Útvegaðar auðkenni úr umhverfis breytum og stillingar.
  • *Brotavísir:** Óþekktar uppfærslur pakka, netkerfiskall til kunnugra C2 heimilis frá byggingarferli.
  • *Mætti:** Athuga `package-lock.json` og `node_modules` fyrir kunnugri pakka. Takmarka aðgangi og upplýsingar í CI/CD vinnusviðum.
  • *Heimild:** [The Hacker News](https://thehackernews.com/2026/06/miasma-malware-targets-npm-packages-and.html) ## 📋 Uppfærslur og uppfærslur
  • *Microsoft SharePoint uppfærslur fyrir í virkri nýtingu RCE** Microsoft hefur útgefið uppfærslur fyrir fjölda kritískra SharePoint veikleika, meðal annars CVE-2026-20963 (CVSS 8.8, RCE) og CVE-2026-32201 (CVSS 6.5, sýnileiki), sem eru staðfest sem í virkri nýtingu.
  • *CVE:** CVE-2026-20963 (CVSS: 8.8), CVE-2026-32201 (CVSS: 6.5)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Útgáfur áður en 16.0.19127.20442 og 16.0.19725.20210
  • *Lagfært í:** Uppfærslur í mars/apríl 2026
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [CSO Online](https://www.csoonline.com/article/4197775/cisa-urges-immediate-sharepoint-hardening-as-exploits-mount.html)
  • *🏢 Cisco ISE kritískar RCE og veikleikar í veikleikum** Cisco hefur uppfært fjölda kritískra veikleika í Identity Services Engine (ISE) og ISE-PIC, meðal annars veikleikum sem leyfa fjarkeyrslu kóða og veikleika með CVSS stig upp á 9.9.
  • *CVE:** CVE-2026-20181, CVE-2026-20190 (CVSS: Ekki tilgreint)
  • *Staða:** Birt
  • *Veikar útgáfur:** ISE og ISE-PIC (einkenni útgáfur ekki skýrt)
  • *Lagfært í:** Uppfærslur útgefnar júní 2026
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [Cisco Security](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv)
  • *Veeam Backup & Replication kritískar RCE uppfærslur** Fjöldi kritískra RCE veikleika í Veeam Backup & Replication leyfa auðkenndar notendur að keyra óskilgreindan kóða. Uppfærslur eru tiltækar.
  • *CVE:** CVE-2026-44963, CVE-2026-21708 (CVSS: Ekki tilgreint)
  • *Staða:** Birt
  • *Veikar útgáfur:** Útgáfur áður en 12.3.2.4854 og 13.0.2.29
  • *Lagfært í:** 12.3.2.4854, 13.0.2.29
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [SC Media](https://www.scworld.com/brief/veeam-releases-security-update-for-critical-backup-server-vulnerability) ## Daglegar árangurir 1. **Uppfæra SonicWall SMA1000 og Adobe ColdFusion á skammti.** Þessi eru staðfest sem í virkri nýtingu núll-daga veikleikar og eru með hæstu áhættu. 2. **Athuga og uppfæra öll rúttar.** Athuga að uppfærslur fyrir CVE-2018-0171 eru notuð og stýrðu SNMP stillingum til að minnka áhættu af rússneskum stjórnarskipulagðum aðgerðum. 3. **Athuga CI/CD vinnusvið og forritarafhengi.** Leita að skemmdum npm pakka (`@automagik/genie`, `pgserve`) og athuga GitHub Actions vinnusvið fyrir óþýða aðgang að upplýsingum. 4. **Uppfæra uppfærslur fyrir Fortinet FortiSandbox og Splunk Enterprise** vegna virkra nýtinga í heimsins. ## 🔗 Heimildir - [Rapid7 Research: SonicWall SMA1000 núll-daga veikleikar](https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410) - [BSI Germany: Adobe ColdFusion veikleikar](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2364) - [CSO Online: Rúttarþjónustu tilvísun](https://www.csoonline.com/article/4196447/governments-to-enterprises-improve-your-router-security-hygiene.html) - [The Hacker News: npm aðfangakeðja aðgerð](https://thehackernews.com/2026/06/miasma-malware-targets-npm-packages-and.html) - [SecurityWeek: FortiSandbox nýting](https://www.securityweek.com/?p=47207)
Read Full Article →

## Executive Summary The threat landscape on July 16, 2026, is characterized by widespread, active exploitation of critical vulnerabilities across core enterprise infrastructure. Immediate attention is required for newly disclosed zero-days in **SonicWall SMA1000** appliances and critical patches for **Adobe ColdFusion**, both under active attack. The **npm** supply chain campaign continues to evolve, now targeting developer secrets via GitHub Actions. Additionally, Russian state-sponsored actors (FSB Centre 16) are actively exploiting legacy router vulnerabilities (CVE-2018-0171) and weak SNMP configurations to exfiltrate network configurations globally.

## ⚠️ Immediate Action Required

* **SonicWall SMA1000 Zero-Days Actively Exploited** Two critical zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series appliances are being exploited in the wild, allowing remote code execution and security bypass. * **CVE:** CVE-2026-15409, CVE-2026-15410 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** SMA 1000 Series firmware 12.4.3-03245 and later (specific versions not fully detailed) * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [Rapid7 Research](https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410)

* **Adobe ColdFusion Critical RCE Flaws Exploited** Adobe has patched multiple critical vulnerabilities in ColdFusion, including CVE-2026-48282, which is confirmed as actively exploited. These flaws allow remote code execution, privilege escalation, and data disclosure. * **CVE:** CVE-2026-48282 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** ColdFusion 2023 and 2025 prior to specific updates (versions not specified) * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [BSI Germany](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2364)

* **🏢 Fortinet FortiSandbox Critical RCE Vulnerabilities** Multiple critical vulnerabilities in Fortinet FortiSandbox, with CVSS scores up to 9.8, are under active exploitation, allowing unauthenticated remote code execution. * **CVE:** CVE-2026-39813, CVE-2026-39808, CVE-2026-25089 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Versions prior to 5.0.6 and 4.4.9 * **Fixed:** 5.0.6, 4.4.9 * **Workaround:** None mentioned in source * **Reference:** [SecurityWeek](https://www.securityweek.com/?p=47207)

* **Splunk Enterprise Critical RCE Under Active Attack** A critical vulnerability in Splunk Enterprise (CVE-2026-20253) is being actively exploited, allowing unauthenticated remote code execution and data manipulation. * **CVE:** CVE-2026-20253 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Splunk Enterprise versions 10.x and 9.x prior to recent patches * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [Help Net Security](https://www.helpnetsecurity.com/?p=375286)

## 🔍 Threat Activity

* **Russian State Actors Targeting Global Router Infrastructure** Threat actor FSB Centre 16 is exploiting weak SNMP configurations and the legacy Cisco IOS vulnerability CVE-2018-0171 (CVSS 9.8) to exfiltrate router configurations globally. This campaign highlights the risk of unpatched network infrastructure. * **TTPs:** Exploitation of CVE-2018-0171 (Smart Install protocol misuse) and insecure SNMP configurations. * **IoC:** Configuration theft from routers. * **Mitigation:** Apply patches for CVE-2018-0171, disable unused SNMP services, and implement SNMP community string hardening. * **Reference:** [CSO Online](https://www.csoonline.com/article/4196447/governments-to-enterprises-improve-your-router-security-hygiene.html)

* **npm Supply Chain Attack Evolves to Target GitHub Actions** The ongoing "Miasma" and "IronWorm" malware campaigns targeting npm packages have evolved. Attackers are now poisoning packages to steal developer credentials, API keys, and cryptocurrency data, with malware self-propagating via republished versions and targeting GitHub Actions workflows. * **TTPs:** Use of malicious `postinstall` scripts in compromised npm packages (@automagik/genie, pgserve). Credential theft from environment variables and configuration files. * **IoC:** Suspicious package updates, network calls to known C2 domains from build processes. * **Mitigation:** Audit `package-lock.json` and `node_modules` for known malicious packages. Restrict CI/CD pipeline permissions and secrets exposure. * **Reference:** [The Hacker News](https://thehackernews.com/2026/06/miasma-malware-targets-npm-packages-and.html)

## 📋 Patches & Updates

* **Microsoft SharePoint Patches for Actively Exploited RCE** Microsoft has released patches for multiple critical SharePoint vulnerabilities, including CVE-2026-20963 (CVSS 8.8, RCE) and CVE-2026-32201 (CVSS 6.5, spoofing), which are confirmed as actively exploited. * **CVE:** CVE-2026-20963 (CVSS: 8.8), CVE-2026-32201 (CVSS: 6.5) * **Status:** Active exploitation detected * **Vulnerable:** Versions prior to 16.0.19127.20442 and 16.0.19725.20210 * **Fixed:** Patched in March/April 2026 updates * **Workaround:** None mentioned in source * **Reference:** [CSO Online](https://www.csoonline.com/article/4197775/cisa-urges-immediate-sharepoint-hardening-as-exploits-mount.html)

* **🏢 Cisco ISE Critical RCE and Path Traversal Patches** Cisco has patched multiple critical vulnerabilities in Identity Services Engine (ISE) and ISE-PIC, including flaws allowing remote code execution and path traversal with CVSS scores up to 9.9. * **CVE:** CVE-2026-20181, CVE-2026-20190 (CVSS: Not specified) * **Status:** Disclosed * **Vulnerable:** ISE and ISE-PIC (specific versions not detailed) * **Fixed:** Patches released June 2026 * **Workaround:** None mentioned in source * **Reference:** [Cisco Security](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv)

* **Veeam Backup & Replication Critical RCE Patches** Multiple critical RCE vulnerabilities in Veeam Backup & Replication allow authenticated users to execute arbitrary code. Patches are available. * **CVE:** CVE-2026-44963, CVE-2026-21708 (CVSS: Not specified) * **Status:** Disclosed * **Vulnerable:** Versions prior to 12.3.2.4854 and 13.0.2.29 * **Fixed:** 12.3.2.4854, 13.0.2.29 * **Workaround:** None mentioned in source * **Reference:** [SC Media](https://www.scworld.com/brief/veeam-releases-security-update-for-critical-backup-server-vulnerability)

## Today's Priorities 1. **Patch SonicWall SMA1000 and Adobe ColdFusion immediately.** These are confirmed as actively exploited zero-days and represent the highest risk. 2. **Audit and update all network routers.** Verify patches for CVE-2018-0171 are applied and harden SNMP configurations to mitigate ongoing Russian state-sponsored attacks. 3. **Review CI/CD pipelines and developer dependencies.** Scan for compromised npm packages (`@automagik/genie`, `pgserve`) and review GitHub Actions workflows for unauthorized secret access. 4. **Apply patches for Fortinet FortiSandbox and Splunk Enterprise** due to active exploitation in the wild.

## 🔗 References

  • [Rapid7 Research: SonicWall SMA1000 Zero-Days](https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410)
  • [BSI Germany: Adobe ColdFusion Vulnerabilities](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2364)
  • [CSO Online: Router Security Advisory](https://www.csoonline.com/article/4196447/governments-to-enterprises-improve-your-router-security-hygiene.html)
  • [The Hacker News: npm Supply Chain Attack](https://thehackernews.com/2026/06/miasma-malware-targets-npm-packages-and.html)
  • [SecurityWeek: FortiSandbox Exploitation](https://www.securityweek.com/?p=47207)

Share this article