Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (26 February 2026)
Published: Loading…
At a Glance
- Cisco SD-WAN Controller zero-day CVE-2026-20127 has been actively exploited since 2023, enabling attackers to bypass authentication and gain administrative privileges.
- Former L3Harris executive Peter Williams sentenced to 87 months for selling eight zero-day exploits to a Russian broker, causing $35 million losses.
- UFP Technologies suffered a cyberattack affecting IT systems, leading to file theft and disruption of billing, labelling, and operational functions.
- GRIDTIDE cyber espionage campaign by UNC2814 was disrupted, targeting telecom and government networks across 42 countries using Google Sheets API for C2 traffic.
- Agent Tesla malware campaign used phishing, obfuscated scripts, and in-memory execution to harvest Windows user credentials and browser cookies.
- FreeScout authenticated RCE CVE-2026-27636 enables full system takeover via configuration file overwrite on publicly accessible Laravel-based helpdesk servers.
Summary
Critical infrastructure and network devices remained a primary target, exemplified by active exploitation of Cisco SD-WAN Controller zero-day CVE-2026-20127. Attackers bypassed authentication to gain administrative privileges, with some operations escalating to root access using software downgrades.
Trade-secret theft from defence contractors continued to affect international cyber operations. Peter Williams, a former L3Harris executive, was sentenced to 87 months for selling eight zero-day exploits to a Russian broker, resulting in $35 million in losses and targeting allied government networks. U.S. authorities additionally sanctioned the involved foreign cyber-tools broker.
Healthcare and medical device providers experienced disruptive incidents, including UFP Technologies, where attackers accessed IT systems, exfiltrated files, and disrupted billing and labelling operations. The breach was detected in February, with recovery and system continuity maintained while the investigation into data compromise continues.
State-aligned cyber espionage was highlighted by disruption of the GRIDTIDE campaign, operated by UNC2814. Targeting telecom and government organisations across 42 countries, attackers abused Google Sheets API for command-and-control traffic and metadata exfiltration. Coordinated takedown included revoking API access and disabling infrastructure.
Malware campaigns targeting end users persisted, with Agent Tesla leveraging phishing emails, obfuscated JSE scripts, and reflective in-memory execution to steal credentials and browser cookies. The multi-stage attack chain incorporated anti-analysis checks to maintain persistence on Windows systems.
Web application vulnerabilities continued to enable remote compromise. FreeScout RCE CVE-2026-27636 allowed authenticated attackers to overwrite configuration files, execute arbitrary commands, and access mailbox and support data. Similarly, Koa CVE-2026-27959 enabled userinfo-based Host header injection to manipulate URL generation for password resets and sensitive workflows.
Highlights of the Day
SolarWinds Fixes Critical Serv-U Flaws Enabling Root Code Execution
SolarWinds has released patches for four critical vulnerabilities in Serv-U 15.5 that could allow remote code execution with root privileges. The flaws, all rated 9.1 on the CVSS scale, include broken access control, type confusion, and insecure direct object reference issues, and require administrative privileges to exploit. The vulnerabilities are resolved in Serv-U version 15.5.4, with no indication of active exploitation.
A former general manager at a U.S. defence contractor has been sentenced to 87 months in prison for stealing and selling sensitive cyber-exploit components to a Russian broker. Peter Williams admitted transferring eight trade secret components over three years in exchange for cryptocurrency, causing an estimated $35 million in losses and affecting U.S. and allied government customers. The court also ordered forfeiture of $1.3 million and additional assets, while U.S. authorities announced separate measures targeting the Russian cyber-tools broker involved.
Hackers Exploit Cisco SD-WAN Zero-Day for Admin Access
Cisco Talos reports active exploitation of CVE-2026-20127, a zero-day flaw in Cisco Catalyst SD-WAN Controller that allows unauthenticated attackers to bypass authentication and gain administrative privileges. The activity, tracked as UAT-8616, has reportedly been ongoing since at least 2023 and includes techniques to escalate to root access through software downgrades and exploitation of older vulnerabilities. Talos assesses the actor as highly sophisticated, with targeting focused on network edge devices, including those in critical infrastructure environments.
UFP Technologies Discloses Cyberattack Disrupting Billing Systems
Medical device manufacturer UFP Technologies has disclosed a cybersecurity incident involving unauthorised access to its IT systems, resulting in file theft and disruption to functions including billing and delivery labelling. The company detected the intrusion on 14 February and said some data appears to have been exfiltrated or destroyed, though the scope of compromised information remains under investigation. UFP stated that operations have continued in all material respects and that it does not expect a material financial impact, with some costs anticipated to be covered by insurance.
Google Disrupts Global GRIDTIDE Cyber Espionage Campaign
Google Threat Intelligence Group and Mandiant disrupted GRIDTIDE, a sophisticated backdoor operated by UNC2814, a suspected PRC-linked cyber espionage group. The campaign targeted telecommunications and government organisations in over 40 countries, using Google Sheets API to disguise command-and-control traffic and exfiltrate host metadata. Coordinated takedown actions included terminating attacker-controlled cloud projects, disabling infrastructure, revoking API access, and releasing indicators of compromise to aid global detection.
Agent Tesla Campaign Exploits Multi-Stage Phishing and In-Memory Attacks
FortiGuard Labs analysed a recent Agent Tesla campaign targeting Windows users through phishing emails carrying obfuscated JSE attachments. The malware chain employs in-memory execution via process hollowing, reflective .NET assembly loading, and anti-analysis checks to evade detection while harvesting browser cookies and credentials.
FreeScout Flaw Allows Authenticated RCE and Full Server Takeover
OX Security disclosed CVE-2026-27636, an authenticated remote code execution vulnerability in FreeScout, a PHP Laravel-based helpdesk platform. Exploitation enables attackers to overwrite configuration files, execute arbitrary commands, and potentially exfiltrate sensitive support and mailbox data. The vulnerability affects publicly accessible instances and could facilitate lateral movement within compromised networks.
Koa Vulnerability Allows Host Header Injection via Userinfo
Endor Labs reported CVE-2026-27959, a high-severity vulnerability in Koa where ctx.hostname can be manipulated using a crafted Host header containing a userinfo component. This allows attackers to generate URLs, such as password reset links, pointing to malicious domains while maintaining valid RFC 3986 syntax. Versions prior to 2.16.4 and 3.1.2 are affected, and the issue impacts both HTTP/2 and proxy scenarios.
Daily Coverage