Archive for April, 2026

Malicious Trading Site Drops “Needle Stealer” to Harvest Browser Data

Posted in Commentary with tags on April 22, 2026 by itnerd

Researchers have uncovered a new attack campaign using a previous malware loader to deliver a different threat: Needle Stealer, a data-stealing malware designed to quietly harvest sensitive information from infected devices, including browser data, login sessions, and cryptocurrency wallets. This time, attackers use a website promoting a tool called TradingClaw (tradingclaw[.]pro), which claims to be an AI-powered assistant for TradingView, a legitimate platform used by traders to analyze financial markets. The fake TradingClaw site is not part of TradingView, nor is it related to the legitimate startup tradingclaw[.]chat. Instead, it’s being used here as a lure to trick people into downloading malware.

More details can be found here: https://www.malwarebytes.com/blog/threat-intel/2026/04/malicious-trading-website-drop-malware-that-hands-over-your-browser-to-attackers  

Ensar Seker, CISO at SOCRadar, commented:

“This campaign reflects a growing shift where threat actors weaponize trust in legitimate platforms like TradingView by building highly convincing AI-themed lures around them. The use of “AI trading assistants” is particularly effective because it targets both curiosity and financial motivation, lowering user skepticism. What stands out here is the reuse of a known loader to deploy a different payload, which shows how modular and scalable modern malware operations have become.

More importantly, the focus on harvesting browser sessions and crypto wallets signals that attackers are prioritizing immediate monetization over persistence. Once session tokens are stolen, MFA becomes irrelevant, and accounts can be hijacked in real time. Organizations and individuals need to treat any third-party tool claiming integration with financial platforms as high risk unless it is directly verified.

This is not just malware delivery, it is identity compromise at scale disguised as innovation.”

This is scary as this is a big jump in terms of what threat actors can do. Thus you really need to by hyper aware to threats as they can come from anywhere and pop up in the most unexpected places.

Guest Post: Mythos access by Discord group reveals real danger of AI-powered hacking

Posted in Commentary with tags on April 22, 2026 by itnerd

By Stefanie Schappert

A Discord group’s unauthorized access to Anthropic AI’s powerful Mythos model on Tuesday is doing more than raising questions about the guardrails around powerful AI cybersecurity tools.

It’s exposing a bigger problem for the cybersecurity industry: AI can now find flaws and exploit them so quickly that defenders may be the ones left truly exposed.

A group of AI-fueled Discord info-seekers – one of them linked to a third-party vendor of the AI startup – managed to access the highly gatekept cybersecurity defense system in February, the same day of its debut. 

Using a mixed bag of insider access, web-scouring bots, and some raw ingenuity, the breach is triggering a fresh wave of alarm across an already spooked industry.

Ironically, as the Discord incident was unfolding, the Cloud Security Alliance – in a rapid-response briefing published days after Mythos was unveiled – warned that AI was accelerating vulnerability discovery faster than organizations could keep up, creating the perfect storm for defenders.

Finding thousands of flaws and zero days across hundreds of software systems, the introduction of Mythos has effectively shrunk the patch window defenders have relied on for years – from days to just a few hours.

If released in the wild and adopted by hackers, security teams will inevitably be tasked with building an entirely new playbook to help decide how to prioritize and fix what matters – and there’s still no guarantee they can stem the cyber bleeding. 

More than 250 security leaders helped shape the briefing, which argues the challenge is no longer just finding flaws, but deciding which ones actually pose real risk – and fixing them before they can be turned into working exploits.

It’s a shift some security experts say the industry is still underestimating. The problem is no longer discovery alone. It is remediation, accountability, and whether defenders can keep up as AI moves from identifying vulnerabilities to showing how they can be exploited in the real world.

The Mythos moment may ultimately be less about a single powerful cybersecurity model and more about what happens in the shrinking window between finding a flaw and weaponizing it.

Anthropic’s answer, for now, is Project Glasswing – a tightly controlled effort to use Mythos to help secure critical software before comparable models become more widely available.

But even that highlights the larger issue at hand: the industry knows what is coming and is still scrambling to build that much-needed playbook in time to defend against larger threats, such as nation-state or ransomware attackers.

If a group of AI nerds could get into Mythos – allegedly without malicious intent – imagine the fallout if the next ones to slide through that door were actual criminals.

ABOUT THE EXPERT

Stefanie Schappert, a senior journalist at Cybernews, is an accomplished writer with an M.S. in cybersecurity, immersed in the security world since 2019.  She has a decade-plus experience in America’s #1 news market working for Fox News, Gannett, Blaze Media, Verizon Fios1, and NY1 News.  With a strong focus on national security, data breaches, trending threats, hacker groups, global issues, and women in tech, she is also a commentator for live panels, podcasts, radio, and TV. Earned the ISC2 Certified in Cybersecurity (CC) certification as part of the initial CC pilot program, participated in numerous Capture-the-Flag (CTF) competitions, and took 3rd place in Temple University’s International Social Engineering Pen Testing Competition, sponsored by Google.  Member of Women’s Society of Cyberjutsu (WSC), Upsilon Pi Epsilon (UPE) International Honor Society for Computing and Information Disciplines.

OVHcloud and Alchemy enter strategic relationship 

Posted in Commentary with tags on April 22, 2026 by itnerd

 OVHcloudand Alchemy today announced a strategic relationship. Together, the two companies will enable decentralized app and chain developers to benefit from Alchemy’s powerful suite of tools and Supernodes, Alchemy’s blockchain engine, on the secure, de-centralized and high-performance foundation of OVHcloud’s cloud infrastructure.

The strategic relationship has already started to have an impact. The performance-price ratio offered by OVHcloud has enabled Alchemy to scale to new regions ahead of schedule, even in highly regulated markets, helping developers around the world to launch decentralized apps and chains faster. The OVHcloud platform seamlessly interconnects with Alchemy’s existing cloud infrastructure, including hyperscale offerings, giving Alchemy a truly multi-cloud environment. 

Earlier this year, Alchemy supported OVHcloud’s blockchain startup accelerator, helping to build an ecosystem where startups, enterprises, and partners co-innovated and worked to deliver the next generation of blockchain services at global scale.

Inside RAMP: What a leaked database reveals about Russia’s ransomware marketplace

Posted in Commentary with tags on April 22, 2026 by itnerd

Comparitech researchers have publised an in-depth analysis of RAMP (Russian Anonymous Marketplace), a Russian-language cybercrime forum that operated from late 2021 until being seized by the FBI in January 2026. 

Comparitech researchers gained exclusive access to a leaked database from RAMP, the dump containing user records, forum threats, private messages, IP logs, and admin activity from November 2021 through January 2024. 

In the analysis of this dump, the researchers have broken down details regarding the access market, the biggest listings, the affiliate splits, the criminal job market, the top vendors, the top buyers, and more. 

You can read the analysis here: https://www.comparitech.com/news/inside-ramp-what-a-leaked-database-reveals-about-russias-ransomware-marketplace/

National IT Service Providers Day Is Today

Posted in Commentary on April 22, 2026 by itnerd

With National IT Service Providers Day being today, I wanted to share a perspective that goes beyond the standard “keep systems running” narrative.

Jason Tierney, SVP of Managed Services at C3 Integrated Solutions had this to say:

“For defense contractors, the challenge today goes beyond traditional IT support. In real-world assessment scenarios, challenges can come up when internal IT must work with external compliance teams, including process assumptions, incorrect documentation and a lack of coordination during a formal third-party assessment. Many organizations are also navigating multiple compliance frameworks, each with its own language, requirements and techniques. Even seemingly minor admin or system changes right before an assessment can create real problems. 


In regulated environments, IT service providers are taking on a different role, with responsibility that extends beyond downtime and outages the risk of not passing an assessment or annual re-attestation. Strong change management, close coordination and consistent compliance process documentation are critical to getting organizations to an assessment-ready state and helping them stay there.”
 

Jeff Cratty,VP of Cloud & Integration at Blue Mantis adds this:

“National IT Service Provider Day is a reminder that the right technology partner does more than keep systems running. The best providers help organizations assess where they are, strengthen security, modernize what matters most and manage change in ways that support business goals. They create a secure foundation for innovation and help teams move forward with greater clarity and confidence.

As companies navigate AI adoption, cloud transformation and rising operational demands, they need service providers that can connect strategy to execution, protect critical data and reduce risk and stay engaged beyond deployment. That means identifying practical use cases, strengthening data governance and supporting internal teams through change.

When providers deliver that kind of guidance and accountability, they do more than solve technical challenges. They help businesses adapt faster and turn technology investments into measurable value.”

This link provides some suggestions on how you can say thanks to the people who keep your organization running. Trust me when I say that a thank you can go a long way for these people.

SafeBreach launches AI-driven CTEM to close the execution gap 

Posted in Commentary with tags on April 22, 2026 by itnerd

SafeBreach today announced the launch of its AI-powered Continuous Threat Exposure Management (CTEM) solution. This solution is designed to help organizations move beyond siloed security activities toward a complete, closed-loop CTEM program that continuously identifies, prioritizes, and remediates cyber risk at scale.

As enterprises struggle with challenges like AI-generated threats, tool fatigue, and alert overload, traditional reactive security measures are no longer sufficient. Organizations are increasingly turning to the five-phased CTEM framework developed by Gartner™ as a more proactive way to manage exposures, but this has historically required the manual integration of disparate tools, datasets and processes.

SafeBreach is changing that with a unified solution that operationalizes the full CTEM lifecycle. The solution is grounded in the SafeBreach Exposure Validation Platform, which provides the safe, scalable adversarial exposure validation (AEV) capabilities that underpin the entire CTEM framework. Building on this foundation, the SafeBreach Helm AI Agent unifies the platform’s AEV capabilities with data and insights from a customer’s existing security ecosystem to provide a complete 360-degree CTEM solution that ensures exposures are not only identified but continuously validated and resolved.

SafeBreach Helm accomplishes this with a specialized set of capabilities aligned to each CTEM stage. Users query Helm with simple, conversational prompts to initiate each CTEM phase:

  1. The Scoping Phase: SafeBreach Helm leverages contextual data from Threat Intelligence (TI) tools to identify critical assets, business priorities, and relevant segments of the attack surface.
  2. The Discovery Phase: SafeBreach Helm continuously aggregates and correlates exposure data across internal and external environments, using Vulnerability Management (VM) and External Attack Surface Management (EASM) tools.
  3. The Prioritization Phase: SafeBreach Helm uses asset context from the Discovery phase to precisely highlight the exposures that present the greatest risk, helping users cut through the noise. 
  4. The Validation Phase: SafeBreach Helm utilizes the breach and attack simulation (BAS) of SafeBreach Validate and the attack path validation of SafeBreach Propagate to confirm the exploitability of the highlighted exposures and map realistic attack paths using real-world adversary techniques.
  5. The Mobilization Phase: SafeBreach Helm uses SafeBreach’s AI Remediation technology to translate validated findings into actionable guidance that can be shared with Security Information and Event Management (SIEM); Security Orchestration, Automation, and Response (SOAR); and other workflow management and ticketing tools—including ServiceNow and Jira— to enable teams to remediate risk efficiently and effectively.

Key Offerings of the CTEM by SafeBreach Solution:

  • SafeBreach Helm: The AI CTEM Agent that unifies data from sources including AEV, TI, VM, EASM, SIEM, SOAR, and other workflow management and ticketing tools into a single, intelligent interface for proactive risk management.
  • AEV: The SafeBreach Exposure Validation Platform, which combines SafeBreach Validate to test control effectiveness and SafeBreach Propagate to reveal how adversaries could traverse environments to reach critical assets.
  • AI Remediation: Provides context-aware, AI-driven guidance and integrates with SIEM, SOAR, and ticketing systems to operationalize remediation workflows and accelerate risk reduction.
  • Breach Studio: Advanced capabilities to design custom attack scenarios, including a VS Code extension for environment-specific testing.
  • Exposure Hub (Upcoming): A centralized hub that correlates data from VM, EASM, and other tools to provide comprehensive visibility into the attack surface.

Built for large, distributed environments, the CTEM by SafeBreach solution empowers organizations to evolve from fragmented, reactive security practices to a unified, AI-driven CTEM program—grounded in proven AEV and elevated by SafeBreach Helm—to deliver continuous, measurable risk reduction aligned to real-world attacker behavior.

To learn more about the CTEM by SafeBreach solution or the SafeBreach Helm Agent: 

Read the recent blog about SafeBreach Helm

Today Is Earth Day

Posted in Commentary on April 22, 2026 by itnerd

Today is Earth Day and Earth Day matters because the systems we’ve built, especially in tech, don’t just run in isolation, they draw power, consume resources, and scale globally, which means every decision we make at the infrastructure level has a real, cumulative impact on the world around us. The companies that take that seriously and design for efficiency, smarter data placement, and sustainable operations aren’t just being good citizens, they’re building more resilient, cost-effective, and future-proof IT environments that actually perform better under pressure.

Richard Copeland, CEO, Leaseweb USA and Marie-Pier Angers, Sales Director, Leaseweb Canada had this to say: 


Richard Copeland, CEO, Leaseweb USA:

“From a tech and business perspective, I’d bet most people haven’t thought about Earth Day in terms of server utilization, but that’s exactly where this lives. You walk into most environments and what you find isn’t some cutting-edge, perfectly tuned system. It’s racks of infrastructure running at a fraction of their capacity, powered on, cooled, maintained, and barely doing anything. Then on the other end, you’ve got teams overcompensating in the cloud, spinning things up ‘just in case,’ because nobody wants to be the one who underbuilt. So you end up paying for excess on both sides. More machines than you need. More energy than you should be using. A lot of complexity layered on top of it.

When organizations step back and actually place workloads where they make sense, in infrastructure that’s designed to run efficiently at scale, things start to normalize. Utilization goes up. The number of systems required goes down. Cooling demand drops. You can see it in the power draw, you can see it in the monthly bill, and you can feel it operationally because everything is just simpler to run. That’s the part that doesn’t get enough attention. Sustainability in IT isn’t some separate initiative. It’s what naturally happens when you stop running inefficient environments and start treating infrastructure like something that should actually be optimized.”

Marie-Pier Angers, Sales Director, Leaseweb Canada: 

“Many IT environments are inefficient by design. Not because people are careless, but because they’re trying to solve for risk. So they overbuild. They duplicate. They leave capacity sitting there unused because it feels safer than coming up short. Then they layer in cloud on top of that, sometimes the right way, sometimes not, and suddenly you’ve got this sprawl of infrastructure that’s expensive to run and even harder to reason about. The environmental impact is just a byproduct of that inefficiency.

When you start running workloads in infrastructure that’s actually built for efficiency, where higher utilization is the goal, where resources are shared intelligently, and where you’re not defaulting to one model for everything, the math changes pretty quickly. Fewer machines doing more work. Less power required to run them. Less cooling to keep them stable. At the same time, better performance and more predictable costs. That’s why this isn’t a tradeoff conversation. The same decisions that make your environment easier to operate and cheaper to run are the ones that reduce your footprint. That’s the alignment most teams don’t realize is sitting right in front of them.”

Once Agentic Smartphones Act Without User Permission, What Could Go Wrong? 

Posted in Commentary with tags on April 21, 2026 by itnerd

When a smartphone’s AI agent can execute actions across apps, read messages, interpret meaning, pull data from various apps and act autonomously outside of the user’s knowledge or intent, outcomes can potentially go sideways very quickly.

For the last 15 years, smartphones have responded to their users’ commands. Now, Android 17 threatens this user interaction model and its inherent safety guardrails.

Agentic mobile’s risks are explained in “Android 17: Your Phone’s AI is Evolving to be More Autonomous,” new analysis by Approov Senior Manager Joyce Kuo.  The full analysis is embedded at bottom.

Here’s the upshot:

Android 17 represents a major step towards moving toward the agentic mobile model, in which a device can coordinate tasks across apps as a personal agent. The upside is convenience. The downside is a new class of risk where nothing is technically compromised, but the result is unpredictable and potentially quite wrong. Data may be exposed, actions may be triggered, and workflows may be executed based on manipulated or misunderstood context.

Kuo looks at this expansion of the mobile attack surface beyond traditional app boundaries and user interaction norms, and why existing protections like sandboxing and permissions won’t address this new layer of risk.

Android 17 represents more than just a UX update; it’s a fundamental security and architecture shift – for brands on mobile, for their developers, and for users.

The core issues are straightforward: when systems start acting on your behalf, potentially without the user’s knowledge, how do you as a smartphone-using consumer prevent them from doing exactly what they may otherwise be allowed to do at the wrong time and for the wrong reasons? And how to brands and other app publishers (and their developers) contain these risks?

ZionSiphon malware targets Israeli water and desalination systems

Posted in Commentary with tags on April 21, 2026 by itnerd

Researchers at Darktrace have identified a new malware strain dubbed ZionSiphon designed to target Israeli water treatment and desalination systems, with code specifically built to interact with industrial control system (ICS) and operational technology (OT) environments.

The malware was first detected on June 29, 2025, and includes functionality to identify processes associated with reverse osmosis, chlorine handling, and plant control systems.

Researchers said the malware appears designed to activate only when two conditions are met: a geographic trigger and an environmental trigger tied to desalination or water treatment systems.

Once executed, ZionSiphon scans devices on the local network, attempts communications using Modbus, DNP3, and S7comm industrial protocols, and alters configuration settings related to chlorine levels and pressure controls. Analysis found the Modbus-based attack functionality is the most developed, while the DNP3 and S7comm components appear incomplete, suggesting the malware may still be under development.

The malware appears configured to focus on Israeli IP ranges and includes politically themed embedded strings, according to reporting. 

Josh Marpet, Senior Product Security Consultant, Finite State had this to say:

   “The rise of Hacktivist actions is increasing.  From nation-state (stuxnet), to this apparent politically motivated terroristic action, it is becoming easier and easier to build, configure, and deploy malware against Operational Technology (OT) targets. These targets include water, power, sewer, and other utilities and critical infrastructures. Without an OT specific security program and/or partner, it’s almost impossible for the utility companies to protect against these types of attacks.

   “OT devices are fundamentally different from Information Technology (IT) devices. Compare a laptop to a thermostat, or a factory full of valves and switches. Without specialized knowledge and experience, the normal IT security firms are simply not enough. After all, laptops rarely explode. Factories full of chemicals…can.”

Damon Small, Board of Directors, Xcape, Inc. adds this comment:

   “ZionSiphon is an intent-driven Operational Technology (OT) sabotage malware targeting the logic of water desalination and treatment plants. The immediate business risk is physical process disruption, specifically manipulating hydraulic pressure and chemical dosing, with the possibility of infrastructure damage or public health incidents.

   “Technically, it is highly sector-specific, with dual-trigger checks for Israeli IP ranges and process names like “ChlorineCtrl.” Though a current flaw prevents payload activation, functional Modbus sabotage routines and DNP3/S7comm stubs indicate active development. Despite post-Stuxnet awareness, critical infrastructure remains exposed to 45-year-old unauthenticated protocols. Mitigation requires urgent OT/IT network segmentation, deep packet inspection for unauthorized register writes, and verified hard-coded failsafes to prevent dangerous chemical or pressure levels, irrespective of compromised software.

   “Relying on unauthenticated Modbus to protect the water supply is like locking your front door with a Post-it note that says, “Please don’t come in.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs follows up with this comment:

   “AI has compressed the timeline for developing ICS malware from months to days, and ZionSiphon demonstrates exactly where that trajectory leads. The malware’s dual trigger design, requiring both an Israeli IP range and the presence of desalination or water treatment processes before activating, reflects deliberate targeting of infrastructure that is both nationally critical and geopolitically charged.

   “Israel depends on desalination for a significant share of its drinking water, and ZionSiphon’s target list names specific facilities including Mekorot, Sorek, Hadera, and Palmachim. Darktrace’s analysis found the Modbus sabotage path is fully implemented while DNP3 and S7comm remain incomplete. That development gap will close faster than the industry expects when the structured technical knowledge required to build this tooling is exactly what AI models accelerate.

   “The protocols ZionSiphon targets date to the late 1970s. Modbus has no authentication and no encryption. DNP3 and S7comm carry the same fundamental weakness. Any device on the network segment can issue commands that a controller will execute without question. As geopolitical tensions continue to drive threat actors toward critical infrastructure, these protocols represent an expanding attack surface defended by decades old assumptions.

   “When malware can identify processes associated with reverse osmosis, chlorine handling, and plant control systems, and then communicate directly with the controllers managing them, the only meaningful barrier is the network architecture surrounding those protocols.

   “Every ICS protocol should sit behind multiple layers of network segmentation, with strict access controls governing what can reach those segments. If Modbus traffic is reachable from an IT network or an internet facing system, the architecture has already failed before the malware arrives. The industry also needs sustained investment in zero trust solutions layered on top of these legacy protocols. Modbus and DNP3 are not going away. The installed base is too large, and the replacement cost is too high. The security model has to evolve around them.”

This illustrates the fact that critical systems like these are prime targets for threat actors. Which means that everything possible must be done to protect those systems from getting pwned. Otherwise the consequences would potentially be massive.

The CISA adds eight Cisco SD-WAN flaws to KEV and gives organizations four days to fix them

Posted in Commentary with tags on April 21, 2026 by itnerd

The CISA has added eight vulnerabilities to its KEV catalog, including CVE-2026-20133, another flaw affecting Cisco Catalyst SD-WAN Manager that Federal agencies have been given four days to secure their systems against.

CVE-2026-20133 is an information disclosure vulnerability caused by insufficient file system access restrictions, which can allow an unauthenticated remote attacker to access sensitive information on affected systems through the API. 

The KEV addition follows prior exploitation disclosures involving other Cisco SD-WAN vulnerabilities, including CVE-2026-20127, CVE-2026-20122, and CVE-2026-20128, which prompted earlier emergency directives and patching actions. CISA said the latest KEV update reflects continued active targeting of internet-exposed network infrastructure.

John Carberry, Solution Sleuth, Xcape, Inc. had this to say:

   “Cisco SD-WAN flaws, including the addition of CVE-2026-20133 and two other vulnerabilities to the KEV catalog, signal a critical escalation targeting software-defined perimeters. The main threat is not single bugs, but the rapid weaponization of vulnerability chains, using unauthenticated API access to enable severe file-overwrite and credential-extraction attacks.

   “CISA’s unusually short 4-day deadline confirms pervasive, automated exploitation linked to a Five Eyes-identified global campaign. These flaws stem from systemic API-level access control failures. Organizations must go beyond patching to implement the hardening steps in Emergency Directive 26-03: isolate management interfaces and immediately hunt for “rogue peering” or unauthorized root logins that occurred before the patch.

  • What is the real risk here? The risk is vulnerability chaining. CVE-2026-20133 (information disclosure) allows an unauthenticated attacker to scrape the API for system details, configurations, and internal IPs. This data is then used to weaponize more critical bugs, such as the file overwrite in CVE-2026-20122, essentially giving the attacker a ‘key’ to take control of the system.
  • Are we talking about a full-scale attack here? Sophisticated actors, confirmed by CISA and Five Eyes, have targeted SD-WAN management systems globally since at least 2023. This is a critical threat; owning the SD-WAN Manager grants them long-term persistence and control over all network traffic routing.
  • The “4-day deadline” is the most telling part. CISA’s four-day deadline (April 23, 2026), a significant cut from the usual 14–21 days for KEV items, indicates automated, large-scale exploitation is happening now. Patching without prior collection of forensic logs (admin-tech files) risks merely “painting over the mold” on an already backdoored system. 

   “Asking for a 4-day turnaround on a core networking product is Cisco’s subtle way of admitting they’ve left the screen door open during a hurricane.”

Sunil Gottumukkala, CEO, Averlon follows with this:

   “CISA’s KEV addition is a strong reminder that defenders should not treat CVE-2026-20133 as a routine information disclosure. In an SD-WAN manager, ‘sensitive information’ can include credentials and secrets that materially change the security of the entire environment. Public research shows this flaw can expose the vmanage-admin private key, compromise NETCONF used to manage SD-WAN devices, and leak confd_ipc_secret to enable root escalation.

   “When the vulnerable system is the management plane for distributed network infrastructure, the real-world impact is much larger than what its CVSS rating implies.”

Denis Calderone, CTO, Suzu Labs adds this:

   “Since late February, Cisco Catalyst SD-WAN Manager has been the target of a sustained, escalating campaign. CVE-2026-20127 was the CVSS 10.0 authentication bypass that triggered CISA Emergency Directive 26-03 and forced emergency federal patching. That was wave one. Wave two came in March: CVE-2026-20128, which exposes DCA user credentials, and CVE-2026-20122, which allows an attacker with low-level access to overwrite arbitrary files and escalate to full vManage administration. Both confirmed as actively exploited. Now CVE-2026-20133 is joining the KEV, giving an unauthenticated remote attacker access to sensitive files on the underlying OS through the API. Cisco hasn’t confirmed exploitation of this one. CISA clearly disagrees.

   “There’s also a scoring discrepancy here reviewing. Cisco’s PSIRT submitted this CVE to NVD as 6.5 MEDIUM, with low privileges required. NVD did their own independent analysis and scored it 7.5 HIGH, with no privileges required – matching Cisco’s own advisory, which also says 7.5 and no privileges required. So Cisco’s advisory and Cisco’s NVD submission tell different stories about the same vulnerability. NVD caught it. It is suggested, that since NIST announced they’re pulling back from independent CVE enrichment that this kind of vendor self-scoring inconsistency is exactly the gap that independent enrichment was closing. CVE-2026-20133 is that exact situation playing out in real time.

   “A defender running CVSS-based prioritization sees 6.5 MEDIUM and this sits in a longer queue. Meanwhile, exploitation is, according to CISA, already happening.

   “And CVSS still doesn’t score for chainability. CVE-2026-20133 is information disclosure. Add CVE-2026-20128 to harvest DCA credentials and CVE-2026-20122 to escalate those credentials to vManage admin, and you have full administrative control of a management platform capable of pushing configuration changes to thousands of SD-WAN devices simultaneously. The individual scores don’t capture that math. KEV does, because KEV reflects what’s actually happening in attacks, not what a scoring rubric says about a vulnerability in isolation.

   “If Catalyst SD-WAN Manager is in your environment, patch all three of these. Not because any single CVE is a ten. Because together they are.”

So once again, it’s time to patch all the things in order to keep your organization safe. Given the tight timeline, this should be considered to be a today problem.