CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (26 February 2026)

Published: Loading…

At a Glance

  • Cisco SD-WAN Controller zero-day CVE-2026-20127 has been actively exploited since 2023, enabling attackers to bypass authentication and gain administrative privileges.
  • Former L3Harris executive Peter Williams sentenced to 87 months for selling eight zero-day exploits to a Russian broker, causing $35 million losses.
  • UFP Technologies suffered a cyberattack affecting IT systems, leading to file theft and disruption of billing, labelling, and operational functions.
  • GRIDTIDE cyber espionage campaign by UNC2814 was disrupted, targeting telecom and government networks across 42 countries using Google Sheets API for C2 traffic.
  • Agent Tesla malware campaign used phishing, obfuscated scripts, and in-memory execution to harvest Windows user credentials and browser cookies.
  • FreeScout authenticated RCE CVE-2026-27636 enables full system takeover via configuration file overwrite on publicly accessible Laravel-based helpdesk servers.

Summary

Critical infrastructure and network devices remained a primary target, exemplified by active exploitation of Cisco SD-WAN Controller zero-day CVE-2026-20127. Attackers bypassed authentication to gain administrative privileges, with some operations escalating to root access using software downgrades.

Trade-secret theft from defence contractors continued to affect international cyber operations. Peter Williams, a former L3Harris executive, was sentenced to 87 months for selling eight zero-day exploits to a Russian broker, resulting in $35 million in losses and targeting allied government networks. U.S. authorities additionally sanctioned the involved foreign cyber-tools broker.

Healthcare and medical device providers experienced disruptive incidents, including UFP Technologies, where attackers accessed IT systems, exfiltrated files, and disrupted billing and labelling operations. The breach was detected in February, with recovery and system continuity maintained while the investigation into data compromise continues.

State-aligned cyber espionage was highlighted by disruption of the GRIDTIDE campaign, operated by UNC2814. Targeting telecom and government organisations across 42 countries, attackers abused Google Sheets API for command-and-control traffic and metadata exfiltration. Coordinated takedown included revoking API access and disabling infrastructure.

Malware campaigns targeting end users persisted, with Agent Tesla leveraging phishing emails, obfuscated JSE scripts, and reflective in-memory execution to steal credentials and browser cookies. The multi-stage attack chain incorporated anti-analysis checks to maintain persistence on Windows systems.

Web application vulnerabilities continued to enable remote compromise. FreeScout RCE CVE-2026-27636 allowed authenticated attackers to overwrite configuration files, execute arbitrary commands, and access mailbox and support data. Similarly, Koa CVE-2026-27959 enabled userinfo-based Host header injection to manipulate URL generation for password resets and sensitive workflows.

Highlights of the Day

SolarWinds Fixes Critical Serv-U Flaws Enabling Root Code Execution

SolarWinds has released patches for four critical vulnerabilities in Serv-U 15.5 that could allow remote code execution with root privileges. The flaws, all rated 9.1 on the CVSS scale, include broken access control, type confusion, and insecure direct object reference issues, and require administrative privileges to exploit. The vulnerabilities are resolved in Serv-U version 15.5.4, with no indication of active exploitation.

Former Defence Contractor Executive Jailed for Selling Cyber Secrets

A former general manager at a U.S. defence contractor has been sentenced to 87 months in prison for stealing and selling sensitive cyber-exploit components to a Russian broker. Peter Williams admitted transferring eight trade secret components over three years in exchange for cryptocurrency, causing an estimated $35 million in losses and affecting U.S. and allied government customers. The court also ordered forfeiture of $1.3 million and additional assets, while U.S. authorities announced separate measures targeting the Russian cyber-tools broker involved.

Hackers Exploit Cisco SD-WAN Zero-Day for Admin Access

Cisco Talos reports active exploitation of CVE-2026-20127, a zero-day flaw in Cisco Catalyst SD-WAN Controller that allows unauthenticated attackers to bypass authentication and gain administrative privileges. The activity, tracked as UAT-8616, has reportedly been ongoing since at least 2023 and includes techniques to escalate to root access through software downgrades and exploitation of older vulnerabilities. Talos assesses the actor as highly sophisticated, with targeting focused on network edge devices, including those in critical infrastructure environments.

UFP Technologies Discloses Cyberattack Disrupting Billing Systems

Medical device manufacturer UFP Technologies has disclosed a cybersecurity incident involving unauthorised access to its IT systems, resulting in file theft and disruption to functions including billing and delivery labelling. The company detected the intrusion on 14 February and said some data appears to have been exfiltrated or destroyed, though the scope of compromised information remains under investigation. UFP stated that operations have continued in all material respects and that it does not expect a material financial impact, with some costs anticipated to be covered by insurance.

Google Disrupts Global GRIDTIDE Cyber Espionage Campaign

Google Threat Intelligence Group and Mandiant disrupted GRIDTIDE, a sophisticated backdoor operated by UNC2814, a suspected PRC-linked cyber espionage group. The campaign targeted telecommunications and government organisations in over 40 countries, using Google Sheets API to disguise command-and-control traffic and exfiltrate host metadata. Coordinated takedown actions included terminating attacker-controlled cloud projects, disabling infrastructure, revoking API access, and releasing indicators of compromise to aid global detection.

Agent Tesla Campaign Exploits Multi-Stage Phishing and In-Memory Attacks

FortiGuard Labs analysed a recent Agent Tesla campaign targeting Windows users through phishing emails carrying obfuscated JSE attachments. The malware chain employs in-memory execution via process hollowing, reflective .NET assembly loading, and anti-analysis checks to evade detection while harvesting browser cookies and credentials.

Source: Fortinet

FreeScout Flaw Allows Authenticated RCE and Full Server Takeover

OX Security disclosed CVE-2026-27636, an authenticated remote code execution vulnerability in FreeScout, a PHP Laravel-based helpdesk platform. Exploitation enables attackers to overwrite configuration files, execute arbitrary commands, and potentially exfiltrate sensitive support and mailbox data. The vulnerability affects publicly accessible instances and could facilitate lateral movement within compromised networks.

Koa Vulnerability Allows Host Header Injection via Userinfo

Endor Labs reported CVE-2026-27959, a high-severity vulnerability in Koa where ctx.hostname can be manipulated using a crafted Host header containing a userinfo component. This allows attackers to generate URLs, such as password reset links, pointing to malicious domains while maintaining valid RFC 3986 syntax. Versions prior to 2.16.4 and 3.1.2 are affected, and the issue impacts both HTTP/2 and proxy scenarios.

Source: Endor Labs

Daily Coverage

Developments
Cisco Sd-Wan Zero-DayL3Harris Zero-Day SaleUfp CyberattackGridtide Takedown
Vulnerabilities
CVE-2026-20127A Vulnerability In The Peering Authentication In Cisco Catalyst Sd-Wan Controller, Formerly Sd-Wan Vsmart, And Cisco Catalyst Sd-Wan Manager, Formerly Sd-Wan Vmanage, Could Allow An Unauthenticated, Remote Attacker To Bypass Authentication And Obtain Administrative Privileges On An Affected System. This Vulnerability Exists Because The Peering Authentication Mechanism In An Affected System Is Not Working Properly. An Attacker Could Exploit This Vulnerability By Sending Crafted Requests To An …CVE-2026-27959CVE-2026-27636
Threat Groups
LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.