Heroes, your curated look at the current cybersecurity landscape for Feb 04, 2026.
Critical Threats
Ivanti EPMM Under Active Attack via Dual Zero-Days
Attackers are actively exploiting two critical zero-day vulnerabilities in Ivanti's Endpoint Manager Mobile (EPMM) software, allowing unauthorized control over mobile device management systems. These flaws enable attackers to bypass authentication and execute arbitrary commands on the network edge.
Business Impact
If exploited, attackers gain full control over managed mobile devices and corporate applications - expect potential data exfiltration, complete network compromise, and significant regulatory fines under SOX and FISMA.
Recommended Action
Ask your IT team: "Have we isolated our Ivanti EPMM appliances from the internet and applied the emergency mitigations for the new zero-days immediately?"
CISA Adds SolarWinds Web Help Desk RCE to KEV Catalog
CISA has confirmed active exploitation of a critical Remote Code Execution (RCE) vulnerability in SolarWinds Web Help Desk and added it to the Known Exploited Vulnerabilities (KEV) catalog. This flaw allows attackers to run malicious code on the server without needing valid credentials.
Business Impact
If exploited, attackers could gain a foothold in the internal IT support infrastructure - expect operational disruption, theft of employee data, and mandatory disclosure requirements.
Recommended Action
Ask your IT team: "Is our SolarWinds Web Help Desk patched against the active RCE threat, and have we scanned logs for indicators of compromise prior to the patch?"
Critical RCE in vLLM AI Library Allows Server Takeover
A critical vulnerability with a CVSS score of 9.8 has been discovered in vLLM, a popular library for serving Large Language Models, allowing remote code execution via malicious video URLs. This flaw permits unauthenticated attackers to take over servers hosting AI models.
Business Impact
If exploited, attackers could hijack expensive GPU resources, steal proprietary AI models, or inject malicious data into AI outputs - expect intellectual property theft and reputational damage.
Recommended Action
Ask your DevOps team: "Are we running the vLLM library in our AI stack, and have we updated to the version that sanitizes video URL inputs?"
Docker Fixes Critical RCE in Ask Gordon AI Assistant
A critical flaw in Docker's "Ask Gordon" AI assistant allowed attackers to execute code and exfiltrate data via malicious image metadata. This vulnerability highlights the risks associated with integrating AI assistants into development workflows.
Business Impact
If exploited, attackers could compromise developer environments and inject malicious code into the software supply chain - expect delays in product releases and potential downstream compromises.
Recommended Action
Ask your Development leads: "Have all developers updated Docker Desktop to the latest version that patches the Ask Gordon AI vulnerability?"
High Severity
Python Infostealers Target macOS via Fake Ads
Microsoft warns that Python-based information stealers are now actively targeting macOS users, spreading through fake advertisements and installers. This marks a significant expansion of malware campaigns that traditionally focused on Windows.
Business Impact
If exploited, attackers could steal employee credentials and session cookies from macOS devices - expect unauthorized access to corporate cloud resources and potential data theft.
Recommended Action
Ask your Security team: "Do our endpoint protection systems on macOS specifically detect Python-based infostealers, and are we blocking known malicious ad domains?"
Varonis Acquires AllTrue.ai to Secure AI Systems
Orca Security Expands to Tencent Cloud
Orca Security has become the first third-party CNAPP to support agentless security assessments for Tencent Cloud workloads. This allows organizations with multi-cloud footprints in Asia to maintain consistent security posture.
Other Noteworthy
Varonis Acquires AllTrue.ai to Secure AI Systems
Orca Security Expands to Tencent Cloud
Orca Security has become the first third-party CNAPP to support agentless security assessments for Tencent Cloud workloads. This allows organizations with multi-cloud footprints in Asia to maintain consistent security posture.
Executive Briefing
AttackIQ and Accenture are advocating for a shift to threat-informed defense by combining adversarial testing with AI-driven validation. This approach moves SOCs from reactive posturing to continuous, evidence-based verification of defensive effectiveness.
Vendor Spotlight
Specialization: Cloud Native Application Protection Platform (CNAPP)
Why Orca Security Today: The threat summary details 'Cloud Malware' that utilizes fileless execution and exploits IAM misconfigurations, alongside the Google Looker cloud vulnerability. Orca's agentless SideScanning technology is specifically engineered to detect these deep cloud risks, malware, and misconfigurations across AWS and Google Cloud environments without requiring the installation of agents on workloads.
Key Capability: Agentless detection of cloud malware and IAM risks
Recommended Actions: 1. Navigate to Alerts → Malware → Filter by 'Category: Malware' and 'Cloud Provider: GCP/AWS' 2. Navigate to Risks → Attack Paths → Filter by 'Risk Category: Identity & Access Management' 3. Navigate to Vulnerabilities → All Vulnerabilities → Search/Filter for 'Looker' or specific CVE ID
Verification Steps: - Trigger an On-Demand Scan (or wait for the next daily SideScan cycle) on the affected Cloud Accounts. - Review the 'Top Risky Assets' widget in the Dashboard.
Detection & Response
⚠️ Disclaimer: Test all detection logic in non-production environments before deployment.
1. Vendor Platform Configuration - Orca Security
2. YARA Rule for vLLM RCE Exploitation Attempts
3. SIEM Query — SolarWinds WHD RCE (CVE-2025-40551)
4. PowerShell Script — Check for Ivanti EPMM Version
This rundown should provide a solid overview of the current threat landscape. Thank you to all our cyberheroes for your diligence and hard work. Stay vigilant!