Resources
Recent public security alerts, in plain language, plus guidance on the technology decisions that matter for mission-driven organizations.
Recent public security alerts worth knowing about
A plain-language roundup of alerts from the FBI/IC3 and CISA over the last several months. We track these so the organizations we serve don’t have to. Each card links to the official source.
July 29, 2026
Hard-coded password in Cisco firewall management software
CISA confirmed active exploitation of a hard-coded password in Cisco Secure Firewall Management Center. If you run it, patch and rotate credentials right away.
Read the alert CISAJuly 27, 2026
Fortinet and Arista flaws under active attack
Two more exploited vulnerabilities added, in Fortinet FortiOS and Arista VeloCloud Orchestrator. Both sit at the network edge, so patch promptly if you run either.
Read the alert FBI / IC3July 20, 2026
Scammers are impersonating the FBI’s own fraud reporting center
Criminals are running fake IC3 pages and AI-generated deepfake videos to re-target people who have already lost money. IC3 keeps no social media presence and never asks for payment to recover funds.
Read the alert CISAJuly 14, 2026
On-premises SharePoint servers under active attack
CISA reports five vulnerabilities being used to break into on-premises SharePoint Server, including stealing IIS machine keys to hold on to access. Patch, switch on AMSI, and rotate those keys.
Read the alert FBI / IC3June 18, 2026
Hijacked websites are quietly funneling visitors to scam pages
Criminals take over legitimate sites through weak passwords and outdated plugins, then redirect visitors to phishing and malware. That access is often resold to ransomware crews. Audit your CMS logins and keep plugins patched.
Read the alert FBI / IC3May 2026
“Kali365” phishing kit hijacks Microsoft 365, no password needed
A phishing-as-a-service kit abuses Microsoft’s device-code sign-in to steal access tokens and walk past MFA. The FBI urges blocking device-code flow in Entra ID and using phishing-resistant MFA.
Read the alert CISAApril 20, 2026
Eight actively-exploited vulnerabilities added to CISA’s catalog
CISA flagged eight vulnerabilities being exploited in the wild. If any of your software is on the list, patch it promptly.
Read the alert CISAApril 6, 2026
New actively-exploited vulnerability flagged by CISA
CISA added a vulnerability with confirmed active exploitation to its Known Exploited Vulnerabilities catalog.
Read the alert CISAMarch 20, 2026
Five actively-exploited vulnerabilities added to CISA’s catalog
Five more flaws confirmed as exploited in the wild. Worth checking your systems and updates against the list.
Read the alert CISAFebruary 3, 2026
SolarWinds, GitLab, and FreePBX flaws under active attack
CISA added four exploited vulnerabilities, including issues in SolarWinds Web Help Desk, GitLab, and Sangoma FreePBX. Patch promptly if you run these.
Read the alert CISAJanuary 7, 2026
Two actively-exploited vulnerabilities added to CISA’s catalog
CISA confirmed two more vulnerabilities being exploited in the wild and added them to its catalog.
Read the alertSources: FBI IC3 and the CISA Known Exploited Vulnerabilities catalog. This roundup is updated periodically; it is not a complete list of every advisory.