TABLE OF CONTENT
This week’s intelligence highlights severe vulnerabilities striking the core of enterprise environments alongside highly evasive supply chain and botnet operations. Threat actors are exploiting critical authentication bypasses in virtualization platforms, leveraging decentralized blockchain networks to hide botnet infrastructure, and hijacking global advertising CDNs to inject cryptocurrency stealers directly into end-user browsers.
SISA Weekly Threat Watch – our weekly feature brings to you a quick snapshot of all the major security vulnerabilities that posed a threat to organizations worldwide. These recurring actionable threat advisories will also provide information and recommendations that will help security teams take appropriate actions to defend against the latest and critical threats.
1. Critical Enterprise & Edge Infrastructure Exploitation
Core virtualization, network management, and enterprise software platforms are facing maximum-severity vulnerabilities that allow complete unauthenticated system takeover.
- VMware vCenter and ESXi Critical Flaws (VMSA-2026-0006) — Broadcom has released emergency patches for a critical authentication bypass (CVE-2026-59309) and directory traversal (CVE-2026-59310) in vCenter Server (CVSS 9.8). Unauthenticated attackers can bypass controls to gain administrative access or execute arbitrary code. Additionally, an out-of-bounds write in the VMXNET3 virtual adapter (CVE-2026-47876) allows malicious guest VMs to execute code on the underlying ESXi hypervisor host.
- Cisco Secure FMC & Ruflo MCP Flaws — Active, in-the-wild exploitation has been confirmed for a static credential flaw in Cisco Secure FMC (CVE-2026-20316), allowing remote attackers to log in using hardcoded credentials and escalate to root. Concurrently, a maximum-severity flaw in Ruflo AI orchestration (CVE-2026-59726) leaves the Model Context Protocol (MCP) bridge exposed without authentication, allowing attackers to steal LLM API keys and poison persistent AI memory stores.
- Adobe Campaign Classic Unauthenticated RCE — Adobe released a Priority 1 security update to address CVE-2026-48449. This CVSS 10.0 Incorrect Authorization vulnerability allows unauthenticated remote attackers to execute arbitrary code on the host machine over the network. Adobe Bridge also faces multiple critical local code execution vulnerabilities (APSB26-89) triggered via malicious files.
2. Supply Chain Stealth and Botnet Operations
Adversaries are actively hijacking third-party advertising networks and utilizing decentralized Web3 infrastructure to silently compromise users and obfuscate command-and-control operations.
- Adform Advertising Network CDN Hijack — Threat actors compromised the core CDN infrastructure (
s2.adform.net) of global advertising platform Adform. They injected malicious JavaScript intotrackpoint-async.js, embedded on tens of thousands of corporate websites. The script executes as a persistent clipboard hijacker inside end-user browsers, constantly polling for and replacing copied cryptocurrency addresses with attacker-controlled wallets while exfiltrating user telemetry. - Dysphoria Botnet Evolution — This rapidly evolving botnet has infected over 200,000 IoT and legacy network devices globally. It now utilizes Ethereum Name Service (ENS) and Solana Name Service (SNS) blockchain domains to completely obfuscate its C2 locations, decoding fake IPv6 strings to find attacker servers. It also abuses UPnP for automated port mapping, converting infected inner-network devices into covert C2 proxies to launch massive 4 Tbps DDoS attacks.
3. Ransomware and Data Extortion
Extortion groups are bypassing encryption entirely, relying on identity compromise to steal and weaponize highly confidential corporate and financial data.
- Triple X Ransomware Group — Operating primarily via Email Account Compromise (EAC) and credential stuffing, Triple X executed a major data extortion attack against the Bank of Baroda. Leveraging compromised employee credentials, the group bypassed perimeter defenses to exfiltrate and leak highly confidential internal audit reports, loan appraisals, and customer PII (including Aadhaar details) to dark web leak sites.
Proactive Steps for the Week
- Remediate Virtualization and Network Zero-Days: Schedule emergency maintenance windows to apply the VMSA-2026-0006 updated builds for VMware vCenter and ESXi immediately, as no workarounds are available. Apply the latest Cisco Secure FMC software hotfixes to eradicate static credential exposure.
- Secure Third-Party Web Assets: Enforce Subresource Integrity (SRI) on all third-party script tags to prevent compromised CDN assets (like the Adform tracking script) from executing manipulated files in end-user browsers. Configure robust Content Security Policy (CSP) headers to block unauthorized outbound AJAX/WebSocket requests.
- Mitigate UPnP & Blockchain C2s: Disable UPnP on all edge routers to prevent unauthorized internal hosts from establishing automated port forwarding rules utilized by the Dysphoria botnet. Filter public Web3/ENS gateways at the perimeter firewall unless strictly required for operational purposes.
- Harden AI Orchestration: Redeploy Ruflo environments using v3.16.3+ where the MCP bridge binds strictly to loopback (
127.0.0.1), requires Bearer token authentication, and disables terminal execution (MCP_ENABLE_TERMINAL=false). - Defend Against Identity-Driven Extortion: To combat threat groups like Triple X, mandate phishing-resistant MFA (FIDO2/WebAuthn) across all email accounts, web portals, and VPNs. Implement Continuous Access Evaluation (CAE) to immediately revoke active OAuth tokens if anomalous data exfiltration or impossible travel is detected.
Explore our DFIR Solutions to discover how our advanced incident response support, compromise assessments, and threat hunting frameworks can insulate your enterprise infrastructure against these campaigns.
.png)