Critical zero-days in Microsoft Active Directory, SonicWall SMA1000, GitHub malware campaign
ID: 9700f19e-0374-5602-9973-c36a90a8203a
STIX ID: report--9700f19e-0374-5602-9973-c36a90a8203a
Feed Name: defend.network
Microsoft pushed a record 622 fixes including two zero-days being actively exploited against Active Directory and SharePoint; SonicWall released emergency patches for two actively-exploited SMA1000 zero-days (CVE-2026-15409, CVE-2026-15410). A coordinated supply-chain campaign published nearly 300 fake GitHub repositories to distribute infostealer malware, SAP patched a critical NetWeaver ABAP flaw (CVE-2026-44747, CVSS 9.9), and Spanish police dismantled a €140M BEC/money-laundering ring. Immediate actions recommended are emergency patching, log/audit monitoring, repository/dependency audits, and enforcement of email authentication controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
