Cisco Patches Critical SD-WAN Zero-Day Exploited Since 2023; Google Disrupts Decade-Long Chinese Espionage Campaign
Summary
This cybersecurity brief for February 27, 2026, covers several critical developments. Cisco released an emergency patch for a CVSS 10.0 zero-day vulnerability (CVE-2026-20127) in its Catalyst SD-WAN products, which has been actively exploited since 2023. Google announced the disruption of a decade-long Chinese cyber-espionage campaign by the group UNC2814 that compromised 53 organizations across 42 countries. Other major stories include NATO's approval of Apple devices for handling restricted data, newly disclosed flaws in Anthropic's AI coding assistant, and a new Wi-Fi attack method called 'AirSnitch' that can bypass WPA3 encryption.
Today New Articles
NATO Certifies iPhones and iPads for "Restricted" Classified Data Handling
In a landmark decision, NATO has approved Apple's iPhones and iPads running iOS 26 and iPadOS 26 for handling classified data up to the "NATO Restricted" level. This makes them the first consumer mobile devices to achieve this certification without requiring a...
Critical Flaws in Anthropic's Claude AI Tool Allowed Silent System Takeover
Check Point Research has disclosed three significant, now-patched vulnerabilities in Anthropic's AI coding assistant, Claude Code. The flaws could have allowed an attacker to achieve remote code execution (RCE), steal sensitive API keys, and take full control...
"AirSnitch" Wi-Fi Attack Bypasses WPA3 Encryption to Intercept Traffic
Researchers have disclosed a novel Wi-Fi attack technique named "AirSnitch" that exploits architectural weaknesses in the Wi-Fi networking stack. The attack allows a threat actor already on the same network to bypass encryption, including on WPA3-protected net...
Discord Pauses Global Age Verification Rollout Until Late 2026 Amid Privacy Backlash
Discord has delayed the global implementation of its new age verification system until the second half of 2026. The decision follows widespread user criticism regarding privacy and data security, with many fearing mandatory ID uploads. Acknowledging it "missed...
RansomHouse Claims Cyberattack on European Outlet Giant Neinver
The RansomHouse ransomware group has claimed responsibility for a cyberattack against Neinver, a major Spanish-based company that operates retail outlet centers across Europe. On February 27, 2026, the group added Neinver to its dark web leak site, threatening...
INTERPOL's "Operation Red Card 2.0" Nabs 651 in African Cybercrime Sweep
An eight-week, INTERPOL-led crackdown on transnational online fraud across 16 African nations has concluded with significant results. Dubbed "Operation Red Card 2.0," the initiative led to the arrest of 651 individuals and the recovery of over $4.3 million in...
Chinese Hackers Used ChatGPT for Influence Operations, OpenAI Confirms
OpenAI has confirmed that threat actors linked to China have utilized its ChatGPT large language model to support cyberattack and influence operations. While not used for technical exploit development, the AI was leveraged to generate polished propaganda, craf...
Article Updates
Chinese APT UNC6201 Weaponizes Dell Zero-Day to Deploy GRIMBOLT Backdoor in VMware Environments
Update:The critical Dell RecoverPoint for Virtual Machines zero-day vulnerability (CVE-2026-22769), actively exploited by UNC6201 since mid-2024, has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. This inclusion underscores the severe risk posed...
Marquis Sues SonicWall, Alleging Vendor's Breach Led to Ransomware Attack on 74 Banks
Update:Further details from the lawsuit against SonicWall reveal the alleged mechanism of the MySonicWall cloud backup service vulnerability. Attackers reportedly exploited a defective API by guessing predictable device serial numbers to download firewall configurati...