7secure logo

Blog

Editorial articles, analysis, and long-form security commentary from the 7secure team.

CISA KEV Update: Eight Exploited Flaws Target Cisco, PaperCut, JetBrains

vulnerability management

CISA KEV Update: Eight Exploited Flaws Target Cisco, PaperCut, JetBrains

CISA incorporated eight actively exploited vulnerabilities into the KEV catalog, including three Cisco SD-WAN Manager flaws requiring urgent patching by federal agencies.

4/26/2026

CISA Flags Actively Exploited Catalyst SD-WAN Vulnerability

threat intel

CISA Flags Actively Exploited Catalyst SD-WAN Vulnerability

CISA mandated U.S. government agencies patch Catalyst SD-WAN Manager systems within four days due to active exploitation of CVE-2026-20133. Cisco's advisory currently states they are unaware of public exploitation, cr...

4/26/2026

CVE-2026-5752: Cohere Terrarium Sandbox Escape to Root

vulnerabilities

CVE-2026-5752: Cohere Terrarium Sandbox Escape to Root

A critical vulnerability, CVE-2026-5752 (CVSS 9.3), in Cohere's Terrarium sandbox allows remote attackers to achieve root code execution via Pyodide prototype traversal, leading to container escape. This finding under...

4/26/2026

Identity Attacks Dominate Breaches; AI Accelerates Response Timelines

threat intel

Identity Attacks Dominate Breaches; AI Accelerates Response Timelines

Stolen credentials remain the primary initial access vector across modern breaches, often leading directly to ransomware deployment and persistence. The integration of AI is compressing the window for incident respons...

4/26/2026

Incident Responder Pleads Guilty in BlackCat Ransomware Scheme

threat intel

Incident Responder Pleads Guilty in BlackCat Ransomware Scheme

A former ransomware negotiator has pleaded guilty to actively assisting the BlackCat/ALPHV ransomware group in attacks conducted between April and November 2023. This case highlights severe insider risk when trusted i...

4/26/2026

Vercel Confirms Expanded Compromises Linked to Context.ai Breach

threat intel

Vercel Confirms Expanded Compromises Linked to Context.ai Breach

Vercel identified an expanded set of compromised customer accounts following an investigation into a security incident tied to Context.ai, highlighting risks associated with third-party OAuth access. The ongoing probe...

4/26/2026

French Secure Document Agency Confirms 11.7M Account Data Breach

government

French Secure Document Agency Confirms 11.7M Account Data Breach

France Titres (ANTS), the agency managing secure administrative documents, confirmed a data breach impacting 11.7 million accounts after a threat actor began offering the stolen citizen data for sale. The agency has e...

4/26/2026

TGR-STA-1030: New Activity in Central and South America

threat intel

TGR-STA-1030: New Activity in Central and South America

Unit 42 research reports that TGR-STA-1030 remains an active threat, particularly in Central and South America.

4/26/2026

Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering

industry news

Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering

Fast16 malware from 2005 predates Stuxnet by five years, targeting engineering software to sabotage calculations and reshape cyberwar history.

4/26/2026

CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline

industry news

CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline

CISA adds 4 exploited CVEs including CVSS 9.9 SimpleHelp flaw, mandating FCEB mitigation by May 8, 2026 to reduce ransomware and botnet risk.

4/26/2026

The npm Threat Landscape: Attack Surface and Mitigations

threat intel

The npm Threat Landscape: Attack Surface and Mitigations

Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more.

4/26/2026

Frontier AI and the Future of Defense: Your Top Questions Answered

threat intel

Frontier AI and the Future of Defense: Your Top Questions Answered

What are the next steps for security leaders in this new age of frontier AI? We answer the top 10 questions customers are asking.

4/26/2026

Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud

threat intel

Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud

Unit 42 reveals how multi-agent AI systems can autonomously attack cloud environments. Learn critical insights and vital lessons for proactive security.

4/26/2026

Why Threat Intelligence Is the Missing Link in CTEM Prioritization and

industry news

Why Threat Intelligence Is the Missing Link in CTEM Prioritization and

96% struggle to validate exploitability in 2026 CTEM programs, with 42% SOC time wasted, slowing real threat response.

4/26/2026

Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs

industry news

Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs

Monday cybersecurity recap on evolving threats, trusted tool abuse, stealthy in-memory attacks, and shifting access patterns.

4/26/2026

Vercel Breach Tied to Context AI Hack Exposes Limited Customer

industry news

Vercel Breach Tied to Context AI Hack Exposes Limited Customer

Context.ai breach enabled Google Workspace takeover at Vercel, exposing limited customer credentials and prompting $2M data sale claim.

4/26/2026

Unit 42 Frontier AI Defense Archives - Unit 42

threat intel

Unit 42 Frontier AI Defense Archives - Unit 42

Unit 42 Frontier AI Defense neutralizes AI-powered attacks before they operationalize at scale. We combine AI models with world-class expertise.

4/26/2026

Fracturing Software Security With Frontier AI Models

threat intel

Fracturing Software Security With Frontier AI Models

Unit 42 finds frontier AI models enhance vulnerability discovery, acting as full-spectrum security researchers. They enable autonomous zero-day discovery and faster N-day patching.

4/26/2026

Vercel confirms breach as hackers claim to be selling stolen data

industry news

Vercel confirms breach as hackers claim to be selling stolen data

Cloud development platform Vercel has disclosed a security incident after threat actors claimed to have breached its systems and are attempting to sell stolen data.

4/26/2026