Yet another Cisco SD-WAN 0-day under attack, and no patch in sight

2026-06-05T19:23:58Zc9d13a349ca0f065f32b88224923532d89e5c3db9080c28063fa20c67d495d5a
active-exploitationai-abusedata-breachdoshttp2incident-responsenation-state-activitynpm-malwarephishingrcesd-wansocial-engineeringsupply-chainunpatched-vulnerabilityvpnvulnerability-managementzero-day

What happened

A batch of high-impact security stories: a Cisco SD‑WAN zero‑day is being actively exploited with no available patch; a Palo Alto VPN authentication‑bypass flaw has moved from advisory to in‑the‑wild exploitation; an unpatched critical RCE in open‑source Gogs has an exploit module public; multiple large data‑breaches and leaks (World Food Programme — ~600k families, ShinyHunters — millions of customer records, Charter, Carnival); malicious and typosquatted npm packages and malware-infected packages were discovered; researchers demonstrated how free/open AI models can be used to build self‑sp​​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
c9d13a349ca0f065f32b88224923532d89e5c3db9080c28063fa20c67d495d5a
Enrichment time
2026-06-05T19:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.