Security Alerts

Recent public security alerts worth knowing about

A plain-language roundup of alerts from the FBI/IC3 and CISA over the last several months. We track these so the organizations we serve don’t have to. Each card links to the official source.

CISA

July 29, 2026

Hard-coded password in Cisco firewall management software

CISA confirmed active exploitation of a hard-coded password in Cisco Secure Firewall Management Center. If you run it, patch and rotate credentials right away.

Read the alert
CISA

July 27, 2026

Fortinet and Arista flaws under active attack

Two more exploited vulnerabilities added, in Fortinet FortiOS and Arista VeloCloud Orchestrator. Both sit at the network edge, so patch promptly if you run either.

Read the alert
FBI / IC3

July 20, 2026

Scammers are impersonating the FBI’s own fraud reporting center

Criminals are running fake IC3 pages and AI-generated deepfake videos to re-target people who have already lost money. IC3 keeps no social media presence and never asks for payment to recover funds.

Read the alert
CISA

July 14, 2026

On-premises SharePoint servers under active attack

CISA reports five vulnerabilities being used to break into on-premises SharePoint Server, including stealing IIS machine keys to hold on to access. Patch, switch on AMSI, and rotate those keys.

Read the alert
FBI / IC3

June 18, 2026

Hijacked websites are quietly funneling visitors to scam pages

Criminals take over legitimate sites through weak passwords and outdated plugins, then redirect visitors to phishing and malware. That access is often resold to ransomware crews. Audit your CMS logins and keep plugins patched.

Read the alert
FBI / IC3

May 2026

“Kali365” phishing kit hijacks Microsoft 365, no password needed

A phishing-as-a-service kit abuses Microsoft’s device-code sign-in to steal access tokens and walk past MFA. The FBI urges blocking device-code flow in Entra ID and using phishing-resistant MFA.

Read the alert
CISA

April 20, 2026

Eight actively-exploited vulnerabilities added to CISA’s catalog

CISA flagged eight vulnerabilities being exploited in the wild. If any of your software is on the list, patch it promptly.

Read the alert
CISA

April 6, 2026

New actively-exploited vulnerability flagged by CISA

CISA added a vulnerability with confirmed active exploitation to its Known Exploited Vulnerabilities catalog.

Read the alert
CISA

March 20, 2026

Five actively-exploited vulnerabilities added to CISA’s catalog

Five more flaws confirmed as exploited in the wild. Worth checking your systems and updates against the list.

Read the alert
CISA

February 3, 2026

SolarWinds, GitLab, and FreePBX flaws under active attack

CISA added four exploited vulnerabilities, including issues in SolarWinds Web Help Desk, GitLab, and Sangoma FreePBX. Patch promptly if you run these.

Read the alert
CISA

January 7, 2026

Two actively-exploited vulnerabilities added to CISA’s catalog

CISA confirmed two more vulnerabilities being exploited in the wild and added them to its catalog.

Read the alert

Sources: FBI IC3 and the CISA Known Exploited Vulnerabilities catalog. This roundup is updated periodically; it is not a complete list of every advisory.

Not sure how your Microsoft 365 is configured?

We’ll review your settings, forwarding rules, multi-factor authentication, and legacy access, then lock down the gaps. It’s part of our free 30-minute assessment.