The art of being ungovernable

2026-05-21T20:51:53Z25e4078b8cd9e04fbfd7fa9ad825b78d47a2fa9702428162253868a3b6c72d30
AI-securityAPTAdobe PhotoshopBadIISCVE-2026-20182CloudZMaaSMicrosoft Patch TuesdayNorton VPNOTP-theftOpenVPNPhenoRATSD-WANTP-LinkUAT-8302exploitationhoneypotspatchingphone-number-IOCsthreat-intelvulnerability-disclosure

What happened

This Cisco Talos feed aggregates recent threat intelligence and research: active exploitation of CVE-2026-20182 (authentication bypass in Cisco Catalyst SD‑WAN Controller/Manager); multiple third‑party vulnerability disclosures (TP‑Link, Adobe Photoshop, OpenVPN, Norton VPN) that have been patched; discovery of a BadIIS commodity malware ecosystem (identified by embedded "demo.pdb" strings) likely operating as MaaS; an ongoing APT campaign tracked as UAT‑8302 targeting governments; and a CloudZ RAT intrusion deploying a new "Pheno" plugin that may steal OTP messages. It also highlights the May

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisco_talos
Record identifier
25e4078b8cd9e04fbfd7fa9ad825b78d47a2fa9702428162253868a3b6c72d30
Enrichment time
2026-05-21T20:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.