This Week’s Verdict

The future arrived this week, and it looks suspiciously like the past wearing an AI costume. Attackers weaponized a Cisco flaw in under 24 hours, turned developers’ own AI coding assistants into reverse shells, and convinced Signal users to hand over their own backup keys. Meanwhile, three governments offered bounties, signed executive orders, and seized streaming domains, none of which patched a single firewall.

The Breaches

The week’s headline number belongs to FortiBleed: a Russian-speaking access broker built a Golang sniffer that turned 430,000 FortiGate firewalls into credential-stealing machines, harvesting an estimated 110 million credentials with valid admin and VPN logins for nearly 74,000 systems still floating around. When your perimeter device becomes the thing leaking your perimeter, you no longer have a perimeter. You have a liability with a CVE history.

Elsewhere, KDDI in Japan disclosed a breach exposing up to 14.2 million email logins across six ISPs sharing one email system, a reminder that “shared infrastructure” is a synonym for “shared blast radius.” The NAIC (the U.S. insurance regulators’ group) got hit through Oracle PeopleSoft, with ShinyHunters claiming 3.1 TB stolen. A Texas Parks and Wildlife vendor leaked passport and driver’s license data for over three million Texans, once again a high-value credential exposed through a low-value system that had no business holding it. And Polymarket lost $3 million when attackers compromised a third-party vendor and injected a script into the frontend; the company is reimbursing, which is more than most.

The throughline: nobody breached these organizations directly. They breached the vendor, the shared mailbox, the OAuth token. The Salesforce campaign expanding via breached vendor Klue says the same thing. Your security is now a weighted average of everyone you’ve ever integrated with.

Vulnerabilities Worth Your Attention

Three items demand action this week.

Cisco Unified CM (CVE-2026-20230) and Cisco Catalyst SD-WAN (CVE-2026-20245) are both being exploited. The SD-WAN flaw was hit as a zero-day two months before disclosure via rogue peering to reach root. The CUCM flaw went from PoC to in-the-wild exploitation in under 24 hours, and CISA gave federal agencies until Sunday to fix it. If you run Cisco voice or SD-WAN, you’re already late.

libssh2 (CVE-2026-55200, CVSS 9.2) flips the usual SSH threat model: a malicious server can corrupt memory on a connecting client, no credentials, no interaction. A public PoC is out, and this library is embedded in more software than anyone wants to inventory. Check your dependencies.

SimpleHelp (CVE-2026-48558) is being exploited to drop the new cross-platform Djinn Stealer. Oracle E-Business Suite (CVE-2026-46817), PTC Windchill, and Lantronix EDS5000 (CVE-2025-67038, CVSS 9.8) are all on CISA’s exploited list. On the Linux side, two local-root kernel bugs, DirtyClone (CVE-2026-43503) and pedit COW (CVE-2026-46331), both shipped with working public exploits within a day of disclosure. Patch your kernels; the proof-of-concept authors are not waiting for you.

Threat Actors & Campaigns

Russia owned the narrative. The FBI and CISA warned that intelligence-linked actors (UNC5792, UNC4221) phishing Signal users have evolved to steal Signal Backup Recovery Keys: hand it over once and the attacker reads your message history indefinitely. State offered $10 million for information on either group. Ukraine’s SSU and the FBI detailed the same campaign using fake support texts. Gamaredon ran 35 spear-phishing campaigns against Ukraine with upgraded loaders, and Turla debuted a new .NET backdoor called STOCKSTAY. The Cellebrite revelation (Russia using the tool on a jailed activist’s iPhone three months after the supposed sales cutoff) is a useful reminder that “we stopped selling” and “they stopped using” are different sentences.

China-aligned Mustang Panda abused Zoho WorkDrive as a command channel against Indian government and hydropower targets, while CL-STA-1062 dropped the TinyRCT backdoor on Southeast Asian energy and government systems. On the criminal side, two Scattered Spider members pleaded guilty over the Transport for London attack, and law enforcement disrupted the Amadey and StealC infrastructure, recovering 27 million credentials.

The Bigger Picture

This was the week AI stopped being a slide deck and became an attack surface. Researchers turned Claude Code into a reverse shell using a clean-looking repo. A flaw in Amazon Q Developer (CVE-2026-12957) let a malicious repo steal cloud credentials via MCP configs. Fake AI agent “skills” sailed through every security scanner and reached 26,000 agents. The Gaslight macOS stealer embeds prompt injection to derail AI analysts, and at least one malware author is now stuffing fake nuclear-weapons text into payloads so AI scanners refuse to read them. Schneier’s pointer to research on prompt injection explains why this isn’t a bug to be patched: role bo