Latest Internet & Cybersecurity News

đź“…February 27, 2026 at 1:00 AM
February 2026 sees major breaches at Cisco, Conduent, Adidas partner, and Substack, alongside CISA's Cisco patch directive, Winter Olympics defenses, and rising supply chain threats.
1

Cisco Catalyst SD-WAN Zero-Day CVE-2026-20127 Actively Exploited

Threat actor UAT-8616 has exploited CVE-2026-20127, an authentication bypass in Cisco SD-WAN Controller, since 2023, enabling root access and persistence.Source 2Source 6 CISA issued Emergency Directive 26-03 on February 26, 2026, mandating federal agencies to patch by February 27 and assess for compromise.Source 3Source 5 Global agencies urge immediate patching due to risks to network integrity.Source 5

2

Conduent Third-Party Breach Impacts 25 Million Americans

The Conduent breach, claimed by SafePay ransomware, escalated from 10 million to 25 million affected, including SSNs, medical data from Medicaid and insurers.Source 4 Attackers exfiltrated 8TB over three months, hitting state benefits and corporate clients like Volvo.Source 4 This ranks among largest US healthcare breaches, enabling long-term identity theft.Source 4

3

Adidas Investigates Third-Party Data Breach

Adidas is probing a breach at an independent licensing partner, where attackers claimed access to 800,000 rows of names, emails, and details.Source 1 Adidas reports no impact to its own systems or consumer data.Source 1 Incident underscores risks from supply chain partners.Source 1

4

Substack Confirms User Data Breach

Substack disclosed unauthorized access exposing user email addresses and phone numbers, raising phishing risks for its high-profile users.Source 1 Passwords were not compromised, but contact data increases impersonation threats.Source 1 Highlights need for minimal data storage and strong access controls.Source 1

5

Winter Olympics 2026 Bolsters Cyber Defenses

Milan-Cortina Olympics organizers deployed AI monitoring, stress-testing, and simulations against cyber threats targeting large events.Source 1 Focus was on service availability amid warnings of disruptions for visibility and damage.Source 1 Reinforces trends of opportunistic attacks on global sporting events.Source 1

6

CISA Orders Federal Patch for Cisco Vulnerabilities Amid Exploitation

CISA's ED 26-03 requires FCEB agencies to inventory Cisco SD-WAN systems, patch CVE-2026-20127 and CVE-2022-20775, despite DHS shutdown strains.Source 3 Acting director urges immediate action based on forensic analysis showing easy exploitation.Source 3 Report due by May 1, 2026, on implementation.Source 3

7

Global Agencies Urge Cisco SD-WAN Patching

UK, US, Canada, Australia, New Zealand agencies demand patches for CVE-2026-20127 exploited since 2023 in SD-WAN Manager/Controller.Source 5 Cisco released fixes; federal deadline is 5pm ET February 27, 2026.Source 5 Targets control plane for broad network influence.Source 3

8

Supply Chain Attacks Top Global Cyber Threats in 2026

New report identifies supply chain attacks as leading threat, with internet and financial services facing over 80% of phishing.Source 13 February incidents like Adidas and Conduent exemplify opaque third-party risks.Source 1Source 4 Organizations urged to reduce exposed digital footprints.Source 1

9

2026 Cybercrime Trends: AI Agents and Data Exfiltration Rise

Cybercriminals shift to data theft over encryption, use AI agents for 90% of nation-state intrusions, and innovate amid ransomware competition.Source 7 Social engineering remains top initial access vector.Source 7 AI transforms malware and full attack lifecycles.Source 7

10

Ransomware Payments Drop 8% to $820M in 2025 Despite More Attacks

Chainalysis reports 2025 on-chain ransomware fell to $820 million amid 50% rise in claimed attacks, due to sanctions and proxy disruptions like IPIDEA takedown.Source 8 Private sector actions hit infrastructure for ransomware and espionage.Source 8 Trends persist into 2026.Source 8

11

NCSC Seeks Input on External Attack Surface Management

UK's NCSC requests industry feedback for EASM research amid concerns over unknown internet-facing assets.Source 1 Proactive digital footprint reduction key to cyber resilience.Source 1 Public sector breaches highlight employee data as entry points.Source 1

12

SMBs Face High Cyber Risks Despite Precautions

Proton's 2026 report: Nearly 1 in 4 SMBs hit by attacks in past year, revealing gaps in cyber risk management.Source 12 Trends emphasize persistent threats to smaller entities.Source 12