CISA Flags Actively Exploited Flaws in Wing FTP & Fortinet; Poland Thwarts Nuclear Site Attack

Publication Date: March 17, 2026

Summary

A critical day in cybersecurity for March 17, 2026, saw CISA add an actively exploited Wing FTP Server flaw (CVE-2025-47813) to its KEV catalog, while Fortinet rushed patches for three critical, exploited firewall vulnerabilities. Geopolitical tensions flared as Poland thwarted a cyberattack on its national nuclear research center, with officials suspecting a potential false flag operation. Meanwhile, the EU sanctioned Chinese and Iranian firms for cyberattacks, and the Medusa ransomware gang claimed responsibility for crippling attacks on a major U.S. hospital and a New Jersey county.

Today New Articles

Poland Blocks Cyberattack on Nuclear Research Centre; Suspects Iran-Linked False Flag

Poland's National Centre for Nuclear Research (NCBJ) successfully detected and blocked a cyberattack targeting its internal IT infrastructure. Officials confirmed that no systems were compromised and the 'MARIA' research reactor remained safe. While preliminar...


EU Sanctions Chinese and Iranian Hack-for-Hire Firms for Cyberattacks

The European Union has imposed sanctions on three companies and two individuals from China and Iran for their involvement in cyberattacks against EU interests. The sanctioned entities include Iranian firm Emennet Pasargad, linked to the Charlie Hebdo data leak...


Fortinet Patches Three Critical FortiGate Flaws Used in Active Attacks to Steal Credentials

Fortinet has released patches for three critical vulnerabilities in its FortiGate Next-Generation Firewalls (NGFWs), which were actively exploited by attackers between December 2025 and February 2026. Two of the flaws, CVE-2025-59718 and CVE-2025-59719 (CVSS 9...


Atlassian Bulletin Details 21 High-Severity Flaws, Including Critical RCEs in Bamboo

Atlassian has published its March 2026 Security Bulletin, addressing numerous vulnerabilities across its product suite, 21 of which are rated high-severity. Among the most critical fixes is for a Remote Code Execution (RCE) vulnerability in Bamboo Data Center...


Google Finalizes Acquisition of Cloud Security Firm Wiz to Bolster Multicloud Security

Google has officially completed its acquisition of Wiz, a leading cloud-native security platform. This major strategic investment is aimed at enhancing Google Cloud's security offerings, particularly for customers operating in multicloud environments. Wiz will...


Zapier Pledges Free AI Education for One Million People to Lower Skills Barrier

Workflow automation company Zapier has launched the "1 Million AIs" initiative, a public pledge to provide free AI education and training to one million people. The program aims to democratize AI skills, making them accessible to non-technical users and drivin...

Article Updates

WEF Report: AI Supercharges Cyber Arms Race, Widens Global 'Cyber Equity' Gap

Update:A new Armis report reinforces warnings about AI's role in cyberwarfare, stating it has reached a 'boiling point.' The study reveals 79% of IT leaders are concerned about nation-state AI attacks. Critically, 54% of organizations have already been hit by AI-led...


Cisco Scrambles to Patch Critical SD-WAN Zero-Day Exploited for Months

Update:Security firm VulnCheck reports that a high-severity vulnerability, CVE-2026-20133 (insufficient file system access restrictions), is being overlooked due to misattribution of a PoC exploit. While a PoC was widely believed to target the previously reported zer...


Ransomware Splinters as Attacks Surge 59% in Asia-Pacific, S-RM Report Finds

Update:Gartner forecasts that by 2028, half of all enterprise cybersecurity incident response efforts will be dedicated to incidents involving custom-built AI applications. This is due to their inherent complexity, dynamic nature, and deployment without adequate secu...