Urgent Threats & Advisories

Active and archived focus items for SOC teams and threat hunters

ACTIVE RIGHT NOW

CRITICALADVISORY1d ago

Cisco warns customers of actively exploited zero-day in email gateways

Cisco Secure Email Gateway contains a critical unauthenticated root privilege escalation vulnerability (CVE-2026-76461) that was actively exploited in the wild before patches were available. Multiple customers are likely already compromised. This is now tracked in CISA's Known Exploited Vulnerabilities catalog.

Action required
Immediately identify all Cisco Secure Email Gateway instances in your environment and patch to the latest available version. If you cannot patch immediately, isolate affected systems and conduct forensic analysis for signs of unauthorized root access or lateral movement.
Secure Email GatewayCisco
CRITICALADVISORY1d ago

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

Chinese threat actor UTA0560 is exploiting Chrome and Windows zero-days in coordinated attacks against NGOs using spear-phishing and reflected XSS on compromised university sites. Victims receive malicious redirects that deploy GRIMWEDGE, a JavaScript backdoor enabling reconnaissance and further compromise. This is a live campaign with no public patches available.

Action required
Immediately hunt for GRIMWEDGE indicators in browser processes and JavaScript execution logs. Monitor for suspicious Chrome crashes, unexpected child processes from browser engines, and beaconing to unknown C2 infrastructure. Isolate any affected systems and preserve forensics.
Google ChromeMicrosoft Windows
CRITICALADVISORY1d ago

Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco Secure Email Gateway has a critical zero-day (CVE-2026-76461) that allows unauthenticated attackers to execute arbitrary commands as root via malicious SQL in crafted emails. This is actively exploited in the wild. Any organization running SEG is at immediate risk of full compromise.

Action required
Immediately patch all Cisco Secure Email Gateway instances to the latest patched version. If patching cannot be completed within 24 hours, isolate affected gateways from production email flow.
Cisco Secure Email GatewayCisco AsyncOS SoftwareCiscoCisco Secure Firewall Management Center

ARCHIVE

Category:
Severity:
No focus items found.
Try a different filter.