The art of being ungovernable
2026-05-21T20:51:53Z•25e4078b8cd9e04fbfd7fa9ad825b78d47a2fa9702428162253868a3b6c72d30
AI-securityAPTAdobe PhotoshopBadIISCVE-2026-20182CloudZMaaSMicrosoft Patch TuesdayNorton VPNOTP-theftOpenVPNPhenoRATSD-WANTP-LinkUAT-8302exploitationhoneypotspatchingphone-number-IOCsthreat-intelvulnerability-disclosure
What happened
This Cisco Talos feed aggregates recent threat intelligence and research: active exploitation of CVE-2026-20182 (authentication bypass in Cisco Catalyst SD‑WAN Controller/Manager); multiple third‑party vulnerability disclosures (TP‑Link, Adobe Photoshop, OpenVPN, Norton VPN) that have been patched; discovery of a BadIIS commodity malware ecosystem (identified by embedded "demo.pdb" strings) likely operating as MaaS; an ongoing APT campaign tracked as UAT‑8302 targeting governments; and a CloudZ RAT intrusion deploying a new "Pheno" plugin that may steal OTP messages. It also highlights the May
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisco_talos
- Record identifier
- 25e4078b8cd9e04fbfd7fa9ad825b78d47a2fa9702428162253868a3b6c72d30
- Enrichment time
- 2026-05-21T20:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.