Today’s Field Note

Three things are actually on fire today, the rest is AI think-pieces. Cisco’s Secure FMC has a static-credential flaw, CVE-2026-20316, exploited in the wild and now sitting in CISA’s KEV catalog. It lets an unauthenticated remote attacker log straight into your firewall management plane, which is exactly the box you do not want owned. Meanwhile Void Blizzard (Laundry Bear) is exploiting a Microsoft Exchange OWA zero-day to drop the OWAReaper backdoor and keep mailbox access after you rotate credentials, so your usual reset playbook does not evict them. And more than 30 Minnesota community water systems were hit in a coordinated OT attack, a reminder that small utilities remain soft targets.

Today’s Action

  • Patch Cisco Secure FMC now for CVE-2026-20316 and confirm the management interface is not reachable from untrusted networks. Hunt logs for unexpected admin logins.
  • Apply Microsoft’s OWA fix and hunt for OWAReaper artifacts and rogue mailbox rules or persistence that survived a password reset. Rotating credentials alone will not clear Void Blizzard.
  • If you run VMware, patch vCenter for CVE-2026-59309 (auth bypass, CVSS 9.8) while you are in the change window.
  • Water and OT operators: verify remote-access paths to control systems, enforce MFA, and confirm manual failover works without the network.
  • Review privileged account activity across firewall, mail, and OT management planes for the last two weeks.

Resources

Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.

The credentials were static. The attackers were not.

More: Issues · Field Notes · RTFM


Daily field notes, weekly Issues. Follow @itsalreadywhen or subscribe via RSS.