| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Feb 26, 2026 | CERT-EU | Advisory | 2026-002: Multiple Vulnerabilities in Cisco Products If exploited, these vulnerabilities could allow attackers to gain administrative access to It is recommended to capture forensic evidence, hunt for indicators of compromise, and apply One of the vulnerabilities, CVE-2026-20127, is exploited in the wild since 2023. | ASD/ACSC, CERT-EU |
| Feb 25, 2026 | CISA | Alert | CISA and Partners Release Guidance for Ongoing Global Exploitation of Cisco SD-WAN Systems CISA and partners have observed malicious cyber actors targeting and compromising Cisco SD-WAN systems of organizations, globally. These actors have been observed exploiting a previously undisclosed authentication bypass vulnerability, CVE-2026-20127, for initial access before escalating privileges using CVE-2022-20775 and establishing long-term persistence in Cisco SD-WAN systems. | ASD/ACSC, CCCS, CISA, NCSC-NZ, NCSC-UK, NSA |
| Feb 25, 2026 | NSA | Advisory | Cisco SD-WAN Threat Hunt Guide The purpose of this guide is to assist organisations in investigating their Cisco Software-Defined Wide Area Network (SD-WAN) for indicators of cyber compromise. The guide is written for cybersecurity professionals and network administrators that utilise Cisco SD-WAN technology. | NSA |
| Feb 25, 2026 | NSA | Advisory | CSA: Exploitation of SD-WAN Appliances Malicious cyber threat actors are targeting Software-Defined Wide Area Networks (SDWANs) of organizations globally. These actors exploited a Cisco Catalyst SD-WAN controller authentication bypass vulnerability, CVE-2026-20127. After exploitation of this vulnerability the malicious actors add a rogue peer, and eventually gain root access to establish long-term persistence in SD-WANs. | ASD/ACSC, CCCS, CISA, NCSC-NZ, NCSC-UK, NSA |
| Feb 19, 2026 | FBI | Alert | Increase in Malware-Enabled ATM Jackpotting Incidents Across United States Threat actors exploit physical and software vulnerabilities in ATMs and deploy malware to dispense cash without a legitimate transaction. Out of 1,900 ATM jackpotting incidents reported since 2020, over 700 of them with more than $20 million in losses occurred in 2025 alone. | FBI |
| Feb 12, 2026 | JPCERT/CC | Alert | Microsoft Releases February 2026 Security Updates Microsoft has released February 2026 Security Updates to address the vulnerabilities in their products. Attackers leveraging these vulnerabilities may be able to gain SYSTEM privileges, among other impacts. According to Microsoft, among the vulnerabilities, the following vulnerability has been confirmed to be exploited in the wild. | JPCERT/CC |
| Feb 10, 2026 | CISA | Alert | Poland Energy Sector Cyber Incident Highlights OT and ICS Security Gaps The purpose of this Alert is to amplify Poland’s Computer Emergency Response Team (CERT Polska’s) Energy Sector Incident Report published on Jan. 30, 2026, and highlight key mitigations for Energy Sector stakeholders. In December 2025, a malicious cyber actor(s) targeted and compromised operational technology (OT) and industrial control systems (ICS) in Poland’s Energy Sector—specifically renewable energy plants, a combined heat and power plant,… | CISA |
| Feb 10, 2026 | CISA | Advisory | Barriers to Secure OT Communication: Why Johnny Can’t Authenticate CISA developed this guidance in partnership with operational technology (OT) equipment manufacturers and standard development organizations, by interviewing OT asset owners and operators to understand: What motivates owners and operators to secure communication, and What barriers prevent successful adoption from design through deployment and operations. | CISA |
| Feb 5, 2026 | CISA | Advisory | Reducing the Attack Surface for End-of-Support Edge Devices The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.K.’s National Cyber Security Centre (NCSC) are releasing this fact sheet to urge defensive action against malicious cyber activity by nation-state threat actors. Nation-state threat actors exploit end-of-support (EOS) edge devices—including load balancers, firewalls, routers, and VPN gateways—to gain network access, maintain persistence, and compromise sensitive data. | ASD/ACSC, CISA, FBI, NCSC |