Mythos-class AI has arrived, and security vendors are racing to build on it
In April 2026 Anthropic introduced Claude Mythos Preview through Project Glasswing, a restricted trusted-access program for critical codebases.
Read moreWeekly security briefing · 2026
Vulnerabilities, fixes, software updates, hardware, certifications and industry events across the platforms we engineer every day — Fortinet, Check Point, Cisco, Palo Alto, Juniper, F5 and AlgoSec — plus the frontier AI models reshaping security. Curated by AlphaTechnology, with a direct link to the original advisory for every item.
No reports match this filter combination
Try removing a filter or selecting a different period.
A week after a public proof of concept appeared, Cisco confirmed active exploitation of the SSRF flaw in Unified Communications Manager and Unified CM SME. Crafted HTTP requests can drop arbitrary files on the underlying OS and be leveraged to reach root. Only appliances with the WebDialer service enabled (off by default) are exposed.
Resolution: Upgrade to Unified CM 14SU6 (patched early June); the fix also lands in 15SU5, expected in September. Disable WebDialer where it is not required and hunt for unexpected file writes since early June.
SecurityWeekThe services announced at Cisco Live become available this month: a three-phase offering built on the premise that AI-enabled attacks have collapsed the exploit window from weeks to minutes. Cisco maps the attack surface, applies compensating controls where immediate patching is impossible, and drives estates to full remediation, alongside quantum-readiness assessments for “harvest now, decrypt later” exposure.
Cisco Executive Platform blogOpenAI shipped GPT-5.5, extending long-horizon agentic execution and native tool use, with an emphasis on enterprise security reviews and code-audit workflows that echo the frontier-defender race.
OpenAIThe R82.10 maintenance release rolls up the IKEv1 hotfixes and stability improvements for Quantum and Spark gateways.
Check PointThe compact 1200 series succeeds Firepower 1000 with integrated SD-WAN and an on-box AI assistant for branch sites.
CiscoThe XSIAM 3.0 beta previews agentic triage and a rebuilt detection engine for early-access customers.
Palo AltoThe agentic FortiAI SOC analyst now auto-triages alerts and drafts containment actions across the Security Fabric.
FortinetThe overhaul brings back NSE numbering as exam levels under the FCF, FCA, FCP, FCSS and FCX credentials, with same-track pairing and role tracks for Secure Networking, SASE, Cloud Security and Security Operations.
FortinetFortinet published its position on the FortiBleed dataset, pointing to advisories including FG-IR-25-647 and assessing the activity as credential reuse from earlier incidents combined with brute force against devices lacking MFA and password hygiene, “not related to any recent incident or advisory”. CISA issued a complementary hardening alert. The practical takeaway stands: there is no patch for valid credentials.
Resolution: Rotate all admin and VPN credentials, enforce MFA everywhere, remove management and SSL-VPN exposure from the internet, and enable login-lockout-upon-weaker-encryption on 7.2.x / 7.4.x to purge legacy SHA-256 hashes.
Bitdefender technical advisoryAfter threat-detection firm Defused observed exploitation attempts writing arbitrary files to exposed endpoints, CISA added the Unified CM SSRF to the KEV catalog with an unusually short remediation window under BOD 26-04. PTC Windchill / FlexPLM RCE CVE-2026-12569 received the same 28 June deadline.
Resolution: Patch Unified CM to 14SU6 or apply vendor mitigations before the deadline; treat internet-reachable instances as priority one.
BleepingComputerFortinet shipped FortiOS 7.6.2 as the recommended mature release, rolling up the FortiBleed hardening (PBKDF2 hashing, login lockout) and stability fixes across FortiGate, FortiProxy and FortiSASE.
Fortinet DocsBuilt on the fifth-generation NP7 and CP9 ASICs, the FortiGate 700G targets campus edge deployments with multi-hundred-Gbps firewall throughput, integrated FortiAI and a native SASE onramp.
FortinetGoogle DeepMind brought Gemini 3 to general availability across Workspace and Vertex AI, pushing multimodal reasoning and a hardened enterprise tier with data-residency and agent-governance controls.
Google DeepMindThe cloud update expands Marvis self-driving actions and AI root-cause across wired, wireless and WAN.
JuniperThe ruggedised 1600 gateway targets OT and industrial edges with hardened enclosures and SCADA-aware inspection.
Check PointResearchers uncovered a mass credential-compromise operation against internet-facing FortiGate firewalls and SSL-VPN gateways across 194 countries. Attackers harvested configuration files and cracked legacy SHA-256 password hashes; by 19 June validated credentials existed for roughly 86,600 devices, with SOCRadar confirming a database of 30,000+ working admin logins organized by country and sector. Because the logins are valid, no exploit signature fires.
Resolution: FortiOS 7.2.11 / 7.4.8 / 7.6.1 introduced PBKDF2 hashing, but old hashes persist until each admin logs in post-upgrade. Force those logins, rotate every admin and VPN credential, enforce MFA, and restrict management interfaces to trusted networks.
Arctic WolfA malicious authenticated administrator can persist a JavaScript payload via the PAN-OS web UI on PA-Series, VM-Series and Panorama. Cloud NGFW and Prisma Access are not affected. Low urgency, but relevant wherever admin roles are delegated broadly.
Resolution: Upgrade to the fixed PAN-OS maintenance releases listed in the advisory and review admin role assignments.
Palo Alto Networks advisoryThe new extended-maintenance IOS XE 17.15.1 lands for Catalyst switching and SD-WAN edge, while Cisco set the end-of-software-maintenance date for the 17.9 train, pushing estates to plan upgrades before support lapses.
CiscoCisco published the end-of-sale and end-of-life milestones for the Firepower 1000 appliances, steering customers toward the Secure Firewall 1200 series; the last day of support runs into 2030.
CiscoMeta released the Llama 4.2 family under open weights, adding a long-context mixture-of-experts variant that security teams are already fine-tuning for on-prem detection and triage use cases.
Meta AIThe endpoint release adds AI-driven behavioural detection and lighter agents for managed Windows and macOS fleets.
Check PointPrisma AIRS adds runtime protection for enterprise AI agents, models and MCP tools against prompt-based attacks.
Palo AltoA logic flaw in certificate validation for the deprecated IKEv1 key exchange lets an unauthenticated attacker establish a Remote Access or Mobile Access VPN session without a valid password. Exploitation dates back to 7 May across a few dozen organizations, with one intrusion tied to a Qilin ransomware affiliate whose infrastructure also targets Palo Alto, Fortinet and F5 VPN flaws. Spark firewalls are affected too. CISA added it to KEV with a three-day deadline. A second issue found during the investigation, CVE-2026-50752 (CVSS 7.4, IKEv1 site-to-site MITM), was fixed in the same hotfix.
Resolution: Install the hotfix takes from sk185033 (R81.20, R82, R82.10 Jumbo and Spark builds); R81.10 and older are end of support and need an upgrade path. Audit VPN logs and configuration history back to 7 May, and retire IKEv1 where possible.
Check Point blog / sk185033Anthropic released Claude Fable 5, the first Mythos-class model made generally available, with safeguards that reroute offensive-cyber and biology requests to the less capable Opus 4.8 (triggered in under 5% of sessions). The unrestricted Claude Mythos 5 went to Project Glasswing partners and select defenders, deployed in collaboration with the US government. Both are priced at 10 / 50 dollars per million input / output tokens.
SecurityWeekFortinet fixed a critical, remotely exploitable command-injection flaw in the FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS web UI, the most severe of the month’s PSIRT batch. No in-the-wild exploitation was reported at disclosure. Ivanti patched a CVSS 10 Sentry command injection (CVE-2026-10520) the same week, keeping the pressure on edge appliances.
Resolution: Update FortiSandbox to the fixed releases in the June PSIRT advisories and keep the management UI off the internet.
SecurityWeekCisco patched a Catalyst SD-WAN Manager web-UI weakness that lets an authenticated user with write access create or overwrite arbitrary files and pivot to root; limited exploitation was observed in June, including a malicious “suspicious.war” deployment in shared IOCs. It joins seven other SD-WAN flaws flagged as exploited in 2026.
Resolution: Apply the fixed SD-WAN Manager releases, review deployment and service-proxy logs for unexpected WAR files, and keep controller access restricted to management networks.
The Hacker NewsPalo Alto Networks opened the PAN-OS 12.0 early-availability program, previewing an AI-assisted policy analyzer and a dedicated cookie-signing certificate on by default; production GA is expected later in the year.
Palo Alto NetworksAt WWDC, Apple detailed a larger on-device foundation model and opened its models to third-party apps through an expanded framework, keeping inference private on Apple silicon.
AppleThe QFX5240 brings 800GbE data-center fabric density on Trio silicon with Apstra-driven intent networking.
JuniperThe SaaS update improves bot defence and API discovery and adds tighter policy sync with BIG-IP estates.
F5The new AI Gateway secures and load-balances LLM traffic with prompt inspection and token-aware rate limiting.
F5After retiring the PCNSE, Palo Alto's role-based tracks such as NGFW Engineer and Network Security Architect span Foundational to Architect levels, with exams now delivered in person only at Pearson VUE.
Palo AltoCisco’s flagship event centered on Cloud Control, an agentic management plane that takes operators from a single prompt to cross-domain troubleshooting, with zero trust, identity intelligence and AI guardrails built in, plus Splunk data unification for machine-speed response. Keynotes framed AI as both the attack accelerant and the defense, with Cisco IQ extending agentic operations into regulated and air-gapped environments.
Cisco Newsroom keynote recapAnthropic extended its trusted-access program for Mythos-class capability to roughly 150 new organizations in more than fifteen countries, adding power, water, healthcare, communications and hardware vendors whose compromise could affect over 100 million people each. Alongside it, Claude Security launched: codebase scanning and patch suggestions powered by public frontier models. Dragos, Tenable, Trend Micro, Netskope, BeyondTrust, Rubrik, BT and Hitachi confirmed participation.
AnthropicCisco disclosed a CLI input-validation flaw in Catalyst SD-WAN Controller and Manager allowing an authenticated local attacker to run commands as root via a crafted CSV upload. Google Mandiant later showed exploitation as early as March, with the actor cleaning up files and reverting configs to erase traces, part of the “living off the edge” pattern. Cisco also patched the critical Unified CM SSRF (CVE-2026-20230) on 3 June, before exploitation began.
Resolution: Upgrade all Catalyst SD-WAN deployments (on-prem, cloud and FedRAMP) to fixed releases, and forensically review orchestrator activity back to March: peering events, config reverts and CSV uploads.
Infosecurity MagazineHorizon's new AI-driven application-discovery module reached general availability, mapping flows to business applications automatically; AlgoSec also opened a private beta for an agentic change-automation assistant.
AlgoSecThe service release addresses IKE and routing-daemon fixes and adds inline flow telemetry to the MX and SRX lines.
JuniperThe FortiOS 7.8 early preview showcases deeper agentic FortiAI automation and generative-AI governance controls.
FortinetThe Catalyst 9350 access switches add high-density multi-gig, UPOE++ and built-in Cisco AI Assistant hooks.
CiscoThe updated Certified Security Administrator and Expert exams align with R82, adding AI-assisted operations, Infinity and cloud-security content.
Check PointA proof of concept for the GlobalProtect authentication-override cookie bypass was released on 29 May, and Palo Alto Networks confirmed limited exploitation against unpatched, unmitigated devices. CISA’s KEV deadline was set at 1 June. Notably, PAN says it found the flaw internally using frontier AI tools, a live example of AI-assisted code auditing beating attackers to a bug, if only by days.
Resolution: Upgrade every portal and gateway to the fixed PAN-OS builds (users re-authenticate once as cookies are regenerated), or as interim mitigation use a dedicated cookie certificate or disable authentication override.
Unit 42 threat briefThe new fixed PTX10002-36QDD brings 800GbE-native core and peering density on Express 5 silicon, alongside Junos Evolved features for inline flow telemetry and post-quantum-ready MACsec.
JuniperThe A34.00 platform release adds broader multi-cloud connectivity and refreshed compliance packs for NIS2 and DORA.
AlgoSecThe cloud firmware brings Wi-Fi 7 improvements and AIOps insights to Meraki MR access points.
CiscoThe data-center FortiGate 3800G delivers terabit firewalling with fifth-gen ASICs and hardware-accelerated SASE.
FortinetFollowing the HPE acquisition, Juniper streamlines its JNCIA to JNCIE tracks and expands the AI-Native Networking and Mist certifications for campus and data-center roles.
JuniperDays after disclosure, Rapid7 recorded successful bypasses across multiple customer environments, with a first wave on 17 May and a second on 21 May attributed to the same actor; in two cases the attacker obtained a VPN IP assignment and internal network reach. The pattern echoes the year’s theme: edge VPN flaws are weaponized within days of publication.
Resolution: Patch on an emergency basis and hunt GlobalProtect logs for gateway-connected events with anomalous host IDs and device names.
CyberScoopNvidia's next-generation accelerators began shipping into Oracle Cloud's expanded AI regions, part of a wave of sovereign-compute buildouts that underpin the frontier-model and security-tooling boom.
NvidiaThe management-plane update aligns policy automation with FortiOS 7.6 and adds agentic FortiAI incident summaries.
FortinetThe new BX-series blade doubles VELOS chassis throughput and adds hardware SSL offload for large service providers.
F5The automation suite adds closed-loop assurance and expanded device onboarding for service-provider networks.
JuniperThe Infinity AI Copilot gains new skills for policy authoring, incident summaries and guided troubleshooting.
Check PointThe biggest CCNA revision in years adds a security-first mindset and a pillar on AI in network operations, while the CCIE lab now includes a mandatory AI-assisted troubleshooting module.
CiscoCisco patched a peering-authentication bypass in Catalyst SD-WAN Controller and Manager that grants remote attackers high-privileged access via crafted packets, exploited since mid-April by the UAT-8616 cluster to register rogue peers inside SD-WAN fabrics. It was the sixth exploited SD-WAN flaw of 2026; Talos documented ten activity clusters delivering miners, stealers and webshells through the family. CISA gave agencies three days.
Resolution: Upgrade to fixed releases (no workaround exists), restrict control-plane and management interfaces to trusted networks, and validate every peering event in controller logs against change records.
BleepingComputerPalo Alto’s monthly drop included two authentication bypasses: CVE-2026-0257 abuses reused certificates behind GlobalProtect authentication-override cookies to establish unauthorized VPN sessions, while CVE-2026-0265 lets an unauthenticated attacker bypass login on interfaces with Cloud Authentication Service enabled on PA-Series, VM-Series and Panorama.
Resolution: Patch per the product-status tables (remaining 0265 streams landed 28 May). Interim: dedicated certificate for auth-override cookies, or disable the feature; verify whether any CAS-enabled auth profile is attached to a login interface.
Palo Alto Networks advisoryF5’s Q2 notification resolved 19 high and 32 medium issues. The standout is CVE-2026-42945, a heap overflow in NGINX’s rewrite module that crashes workers and can reach code execution if ASLR is off; CVE-2026-41225 (8.6) allows command execution via iControl REST for Manager-role users, plus three authenticated RCE / command-injection bugs in BIG-IP. Nothing exploited in the wild at publication.
Resolution: Apply the K000160932 release matrix during the next maintenance window, prioritizing internet-facing NGINX and any BIG-IP with broad iControl REST role assignments.
SecurityWeek / K000160932F5 published the end-of-software-development notice for the BIG-IP 15.1.x branch, with technical support ending in 2027; customers are advised to migrate to 17.5.x or the new 21.x line.
F5The data-center Quantum Force 19000 targets high-throughput AI-era workloads with terabit firewalling and Maestro scaling.
Check PointThe on-prem suite update refreshes risk analytics and adds new device support for hybrid firewall estates.
AlgoSecA new Express 5 line card boosts PTX10008 core and peering density with native 800GbE and inline MACsec.
JuniperA buffer overflow in the Captive Portal service (ports 6081 / 6082) allows crafted packets to trigger an out-of-bounds write and execute code as root. Palo Alto confirmed limited in-the-wild exploitation against exposed instances and CISA added the flaw to KEV on 6 May. Wiz measured publicly exposed PAN-OS in about 7% of environments.
Resolution: Upgrade to the fixed PAN-OS releases and never expose the Authentication Portal to untrusted networks; verify 6081 / 6082 reachability from the internet as the primary exploitability check.
Wiz researchThe data-center release adds telemetry and automation improvements for Nexus 9000 fabrics plus assorted security fixes.
CiscoCloudFlow's guided risk-remediation for cloud security groups reaches general availability across AWS, Azure and GCP.
AlgoSecThe maintenance build resolves Captive Portal and User-ID issues and refreshes content-update handling.
Palo AltoNew API-security features add automated discovery, schema enforcement and abuse detection for exposed APIs.
F5AlgoSec refreshes its certified-professional curriculum around the Horizon platform, adding application-centric policy and cloud-security modules.
AlgoSecCISA updated its ongoing SD-WAN alert to add CVE-2026-20133 to the Known Exploited Vulnerabilities catalog, extending the global campaign first flagged in February under Emergency Directive 26-03. The mid-April timeframe also marks the earliest observed exploitation of what would later be disclosed as CVE-2026-20182.
Resolution: Follow the ED 26-03 sequence: inventory SD-WAN systems, capture snapshots and logs for threat hunting, patch to fixed releases, then hunt using the joint CISA / NSA / international threat-hunt guide.
CISA joint alertThe rolling cloud update brings AI-powered app acceleration and tightened default posture for the SASE service.
Palo AltoThe new FortiAP 4xxK series adds Wi-Fi 7 throughput with tighter integration into the FortiGate-secured LAN edge.
FortinetThe CloudGuard update expands CNAPP coverage with AI risk scoring across AWS, Azure and GCP workloads.
Check PointCortex Cloud adds unified CNAPP runtime protection with agentic remediation across multi-cloud estates.
Palo AltoOlder 7.2 and 7.4 exam versions are retired as Fortinet consolidates its tracks; existing certifications stay valid until expiry and renew with the new exams.
FortinetAnthropic published its cybersecurity assessment of Mythos Preview, the restricted model behind Project Glasswing. Against roughly 7,000 OSS-Fuzz entry points it achieved full control-flow hijack on ten fully patched targets where prior frontier models managed almost none, and it surfaced thousands of high and critical vulnerabilities now moving through coordinated disclosure, with expert reviewers agreeing with the model’s severity call in 89% of sampled reports. The industry conversation about patch-window economics changed in one week.
Anthropic Red TeamThe quarterly cycle addressed DoS, privilege escalation, information disclosure and filter-bypass issues, including CVE-2026-33778 where a malformed first ISAKMP packet crashes kmd / iked on SRX and MX platforms, plus lo0 and IRB egress-filter enforcement bugs relevant to anyone using firewall filters as a control plane guard.
Resolution: Apply the fixed Junos / Junos Evolved releases from the 2026-04 bulletins; prioritize IKE-terminating SRX clusters and boxes relying on lo0 filters in the default routing instance.
Juniper 2026-04 bulletins (via HKCERT)NGINX Plus R34 lands on the 1.29 core with HTTP/3 refinements and native OpenTelemetry for app-delivery fleets.
F5Cisco published end-of-sale and end-of-life milestones for the Catalyst 9200L switches, pointing to the 9300X line.
CiscoApstra 5.1 broadens multivendor data-center automation with richer intent validation and drift remediation.
JuniperWired Assurance gains AI-native switch health and Marvis conversational troubleshooting for campus fabrics.
JuniperThe refreshed F5 Certified Administrator, BIG-IP replaces two 90-minute exams with five 30-minute topic exams, and F5 begins offering online-proctored delivery via Certiverse.
F5Cisco patched ten vulnerabilities in the Integrated Management Controller of UCS C-Series servers, including CVE-2026-20093, where a crafted HTTP request abuses password-change handling to seize the BMC, below the OS and every EDR / SIEM control. Four companion bugs allow authenticated root command execution and five are XSS. Many Cisco appliances built on UCS C-Series (APIC, Secure Firewall Management Center and others) inherit the exposure. No exploitation observed.
Resolution: Install the April IMC updates (no workarounds exist) and treat out-of-band management as a Tier-0 asset: never internet-facing, strictly segmented, VPN or zero-trust access only.
Help Net SecurityThe SMB firmware update hardens IKEv1 handling and improves cloud management for Quantum Spark appliances.
Check PointThe new PA-1500 branch firewalls roughly double throughput over the PA-1400 while keeping the single-slot form factor.
Palo AltoThe identity-services patch improves posture assessment and adds resilience for large policy deployments.
CiscoA new out-of-the-box pack adds NIS2 and DORA compliance reporting mapped to firewall and cloud policy state.
AlgoSecThe 35th RSAC Conference at Moscone drew 700+ speakers and 600+ exhibitors under the theme “Power of Community”. Agentic AI dominated: Cisco’s Jeetu Patel argued security must protect agents from the world, protect the world from agents, and respond at machine speed, while the Innovation Sandbox crown went to Geordie AI for real-time visibility and governance of enterprise AI-agent footprints. Fortinet, Check Point, F5 and the rest of the vendor landscape exhibited.
RSAC press releaseHorizon took Best Risk / Policy Management Solution at the SC Awards for its application-centric, AI-assisted approach to policy automation across virtual, cloud and physical estates, following a Globee Gold and a Global InfoSec award for AI-powered cybersecurity earlier in the month. Useful validation for teams standardizing multi-vendor policy hygiene on the platform.
SC MediaThe 21.4 train reaches end-of-engineering, with Juniper steering customers to 23.4R2 or the 24.x releases.
JuniperF5 published end-of-sale dates for several BIG-IP iSeries appliances, steering customers to the rSeries platform.
F5The FortiSASE update expands global PoPs and adds unified ZTNA and inline CASB with agentic monitoring.
FortinetThe next-gen Maestro orchestrator scales gateways into multi-terabit security groups for large data centers.
Check PointFortinet’s flagship event marked 25 years of FortiOS with the 8.0 release, positioning AI-native controls for generative-AI governance directly in the fabric. The FortiAI story shifted from assistant to agentic: autonomous alert triage, risk-based prioritization and containment playbooks that execute without waiting for an analyst, plus multimodal input up to topology-diagram uploads. Ken Xie set the tone: security operations must run at the same speed and coordination as the attackers. Customer sessions came from Lowe’s, TJX, Adobe, the International Red Cross and ExxonMobil.
Field report: Forge TechnologiesRapid7 Labs detailed how the February SD-WAN Controller authentication bypass lets an attacker inject a malicious SSH key and reach the NETCONF service, the mechanism behind the rogue-peer intrusions. Essential reading for anyone writing detections around Catalyst SD-WAN control-plane events.
Rapid7 analysisThe change-management release adds native work-order support for AWS, Azure and GCP firewall policies.
AlgoSecNew Harmony SASE capabilities extend zero-trust private access with device posture and agentless clientless options.
Check PointThe Kubernetes ingress release adds gateway-API support and stronger mTLS defaults for containerised apps.
F5Cisco AI Defense extends its SSE with model validation and runtime guardrails for enterprise generative-AI use.
CiscoCisco disclosed an authentication bypass in Catalyst SD-WAN Controller and Manager exploited in the wild by UAT-8616, who downgraded compromised systems to re-expose CVE-2022-20775 and escalate to root. CISA added both CVEs to KEV the same day, gave federal agencies roughly 48 hours, and co-published a threat-hunt guide with NSA, ACSC, the Canadian Cyber Centre, NCSC-NZ and NCSC-UK.
Resolution: Upgrade per branch: 20.9.8.2, 20.12.5.3 / 20.12.6.1, or 20.15.4.2 and above; anything below 20.9 must migrate. Manually validate every control-connection peering event against maintenance windows and documented device assignments.
CISA joint alertAn out-of-cycle Juniper bulletin fixed an incorrect-permission flaw in the On-Box Anomaly detection framework of Junos OS Evolved on PTX Series: an internal REST service that schedules shell-command workflows was reachable on an externally exposed port, handing a network-based attacker code execution as root on core and peering routers. watchTowr later demonstrated how directly the command DAGs could be driven.
Resolution: Upgrade to 25.4R1-S1-EVO or the equivalent fixed EVO releases per the bulletin, and filter management-plane reachability on PTX platforms in the interim.
watchTowr LabsThe recommended 7.4.9 build consolidates SSL-VPN hardening and PBKDF2 password migration for the 7.4 branch.
FortinetThe compact ACX7020 brings 400G metro-aggregation and hardened timing for 5G transport and edge deployments.
JuniperThe SD-WAN release hardens controller peering after the year's incidents and adds AI-driven path insights.
CiscoThe high-capacity management appliance scales policy orchestration and analytics for very large Fabric deployments.
FortinetInstead of one flagship CPX per region, Check Point announced Engage 2026: a two-day format travelling to roughly ten global cities through the year, aimed at both executives and practitioners. Tracks cover Hybrid Mesh Network Security, Workspace Security, AI Security and Exposure Management, with 2026 roadmap previews from the executive team. CheckMates reaction was mixed; deep-technical R82.10 content remains concentrated in the community webinars.
Check Point CheckMatesThe maintenance rebuild ships cumulative security fixes for Catalyst switching and wireless controllers.
CiscoAppViz adds AI-assisted discovery that infers business-application connectivity from live flows to speed rule recertification.
AlgoSecThe management platform update improves device lifecycle workflows and hardens role-based access control.
JuniperThe high-end r10000 brings F5OS tenancy and hardware acceleration to demanding service-provider app delivery.
F5The Q1 notification fixed a bd-process DoS in BIG-IP Advanced WAF / ASM (CVSS 4.0 score 8.2), an NGINX flaw letting a man-in-the-middle inject responses on proxied upstream TLS, and issues in Container Ingress Services and Edge Client. F5 also flagged a BIG-IP SMTP configuration exposure (K000156643) enabling unauthorized relay.
Resolution: Patch per K000159076 and apply the SMTP configuration hardening introduced in 17.5.1.4 / 21.0.0.1; prioritize virtual servers running AWAF / ASM policies.
SecurityWeek / K000159076A remote, unauthenticated attacker can knock over TelePresence CE and RoomOS endpoints simply by sending a malicious meeting invitation; Cisco fixed it alongside a Meeting Management input-validation bug (CVE-2026-20098) exploitable by authenticated users.
Resolution: Update to CE / RoomOS 11.27.5.0 or 11.32.3.0 and Meeting Management 3.12.1 MR.
SecurityWeekAlgoSec’s vendor-agnostic survey of 500+ professionals across 28 countries found 65% have already adapted their security strategy to AI-powered attacks, consolidation replacing sprawl as the dominant architecture goal, Fortinet becoming the most used SD-WAN at 31% just ahead of Cisco at 30.7%, and organizations without any SASE solution dropping to 27.5%.
AlgoSec reportThe maintenance build resolves management-UI and GlobalProtect issues and refreshes threat-prevention content handling.
Palo AltoThe FortiSwitch 700 access line adds multi-gig PoE and tighter Security Fabric integration for the secured LAN edge.
FortinetThe agentless cloud-security update expands container and IaC scanning with prioritised attack-path analysis.
AlgoSecThe modular Nexus 9800 spine adds 800G data-center fabric density with Silicon One and telemetry at scale.
CiscoActive DevNet certifications automatically move to CCNA, CCNP and CCIE Automation, with revamped exams emphasising infrastructure-as-code and AI-ready networking.
CiscoThe abuse seen the previous week received its CVE: any attacker holding a FortiCloud account and one registered device could log in to other customers’ devices wherever FortiCloud SSO was enabled, even on units already patched for December’s CVE-2025-59718 / 59719. Fortinet globally disabled FortiCloud SSO on 26 January and restored it a day later only for patched devices; CISA added the flaw to KEV on 27 January with a 30 January federal deadline. FortiWeb and FortiProxy are also in scope.
Resolution: Upgrade all affected products per FG-IR-26-060. Where IoCs are present, treat the device as breached: restore a known-clean configuration, rotate local and connected LDAP / AD credentials, and keep management access behind local-in policies.
CISA guidance / FG-IR-26-060The point release rolls up Advanced WAF, iControl REST and SMTP configuration fixes across the platform.
F5Meraki introduced an SD-WAN Plus tier with AIOps path selection and unified policy across MX and Catalyst edges.
CiscoThe switch-management update improves fabric provisioning and adds richer PoE analytics for the secured LAN.
FortinetNew executive risk dashboards roll up application, cloud and firewall exposure into board-ready security posture views.
AlgoSecArctic Wolf reported unexpected SSO logins creating local admin accounts and exfiltrating configurations, including on devices fully patched at the time, pointing to a new attack path. Fortinet’s PSIRT confirmed the investigation on 22 January and disabled the abused FortiCloud accounts on 23 January, recommending local-in policies to restrict administrative reachability while analysis continued.
Resolution (interim): Restrict admin interfaces with local-in policy, review admin accounts and recent config exports, and monitor the PSIRT feed; the formal fix followed in Week 05.
Fortinet PSIRT blogThe release adds FireFlow work-order support for Google Cloud Network Firewall Policy, report-driven remediation straight from Disabled Rules and Unused Rules analytics, application-context risk prioritization to simplify rule recertification, and out-of-the-box compliance packs including a CIS baseline for Palo Alto Networks plus NIS2 and SOC 2 mapped controls.
AlgoSec press releaseA new recommended Jumbo Hotfix take consolidates stability and security fixes for R81.20 gateways and management.
Check PointNew XSIAM capabilities add agentic investigation and auto-containment playbooks driven by Palo Alto's security models.
Palo AltoThe Prisma SD-WAN update adds autonomous path health and tighter integration with Prisma Access SASE.
Palo AltoThe SRX2300 brings AI-predictive threat prevention and higher throughput to campus and branch security.
JuniperJuniper’s January advisory round addressed vulnerabilities in management-plane products, covering Policy Enforcer releases prior to 24.1R3 and Paragon Automation prior to 24.1.1. Lower drama than the quarters that followed, but management and automation platforms remain a favorite pivot point once an edge device falls.
Resolution: Upgrade Policy Enforcer to 24.1R3+ and Paragon Automation to 24.1.1+ per the January bulletins.
Canadian Centre for Cyber SecurityThe service release stabilises the 23.4 train with routing, filter and management-plane fixes across SRX and MX.
JuniperThe mid-range r5000 brings F5OS containerised tenancy and hardware acceleration to enterprise app-delivery estates.
F5The Secure Firewall software adds encrypted-visibility improvements and an AI assistant for policy authoring.
CiscoA new FortiSASE capability secures enterprise access to public generative-AI services with DLP and usage governance.
Fortinet2026 opened with in-the-wild exploitation of a Microsoft Office zero-day (CVE-2026-21509) and a critical Cisco flaw (CVE-2026-20045), setting the tempo for the quarter before Fortinet’s SSO bypass joined them late in the month. Context from the Verizon DBIR: vulnerability exploitation is up 34% year over year and now drives one in five breaches, with the median time to mass exploitation still shrinking.
Resolution: Apply the January cumulative updates and vendor advisories for both CVEs, and assume edge and productivity zero-days will be weaponized before public disclosure when planning patch SLAs for the year.
SOC Prime recapThe endpoint-management update improves ZTNA posture checks and adds cloud EMS onboarding for hybrid fleets.
FortinetNew Playblocks automations coordinate cross-product response across Quantum, Harmony and CloudGuard from a single console.
Check PointThe gateway update embeds SD-WAN steering with threat prevention and centralised Infinity management.
Check PointThe compact PA-460 refreshes the small-branch line with higher throughput and cloud-delivered security services.
Palo Alto