The rundown
- 1 Cisco warns that attackers are actively exploiting CVE-2026-76504, a critical authentication bypass in Catalyst SD-WAN Manager that can expose admin APIs and enable full system takeover without credentials. With no workaround available, organizations should patch immediately, restrict internet access, and review logs.
- 2 Bitget says a $387.5 million cryptocurrency theft resulted from a zero-day in third-party security products, enabling credential theft, control bypasses, and unauthorized withdrawals across 11 blockchains. The incident highlights how supplier vulnerabilities can rapidly become exchange-wide breaches and major financial losses.
- 3 A cyberattack disrupted South Africa’s air traffic control systems, forcing officials to use backup procedures while assessing the impact. The incident underscores the operational and safety risks facing critical aviation infrastructure, with potential consequences for airlines, regulators, and passengers.
+2 more stories