Network Security
Security for network teams: firewall, VPN and SASE vulnerabilities and advisories, zero trust networking and SOC automation.
Recent activity
Stories per weekLatest stories
10 most recent-
Fortinet FortiMail zero-day exploited with federal fix deadline
Fortinet warned customers to lock down FortiMail after attackers started exploiting a critical CVSS 9.8 bug allowing unauthenticated file writes via crafted HTTP/HTTPS requests. CISA added it to KEV on October 1 with federal mitigation deadline of October 4, 2026.
Why it matters Email gateway compromise enables mail scanning bypass, communication exfiltration, persistent backdoors, and lateral network pivot—critical for organizations managing perimeter security and incident response.
-
Two Citrix NetScaler zero-days exploited in default configurations
CISA added two Citrix NetScaler zero-days (both CVSS 9.5) to KEV after confirming active global exploitation: CVE-2026-88771 is an unauthenticated RCE in default configurations affecting ADC and Gateway, and CVE-2026-88772 is a DTLS VPN memory buffer overflow enabling RCE or denial of service.
Why it matters Unauthenticated RCE on remote-access edge appliances in default configuration creates immediate perimeter compromise; federal agencies must mitigate by September 30 despite potential downtime from patching.
-
Cisco SD-WAN Manager authentication bypass exploited in the wild
Cisco released a fix September 30, 2026 for CVE-2026-76504, a CVSS 9.8 authentication bypass in Catalyst SD-WAN Manager allowing unauthenticated remote attackers to gain administrator-level access via crafted HTTP requests. Active exploitation confirmed during September 2026.
Why it matters SD-WAN Manager compromise on the management plane enables attackers to alter network policies, configurations, and device settings across distributed WAN infrastructure in a single attack vector.
-
Cisco SD-WAN Manager zero-day grants unauthenticated admin access
Cisco published an emergency advisory for CVE-2026-76504 (CVSS 9.8), an unauthenticated authentication bypass in Catalyst SD-WAN Manager API caused by improper URI encoding. Attackers can craft HTTP requests to obtain administrative access to network fabric management without credentials.
Why it matters SD-WAN Manager compromise equals network-wide routing policy control; this zero-auth, zero-workaround flaw requires immediate inventory and network segmentation until patching completes.
-
Netskope tops Gartner SASE ranking as Palo Alto slips
Gartner's 2026 Magic Quadrant for SASE Platforms ranks Netskope as leader on execution, with Cato Networks moving to second place and Palo Alto Networks downgraded from top position to third. Evaluations emphasize agentic threat suppression, post-quantum cryptography, and AI-driven operational simplicity.
Why it matters SASE vendor shifts signal architectural preferences for zero-trust consolidation; operators evaluating platform transitions should prioritize agentic AI and sovereignty controls alongside traditional security capabilities.
-
Cisco warns of October advisories for NX-OS, APIC and Meraki
Cisco PSIRT will publish security advisories on October 7, 2026 for multiple products including NX-OS, Application Policy Infrastructure Controller, and Meraki, with security hardening releases. Vulnerabilities were discovered using frontier AI models during internal testing.
Why it matters Advance notice enables network teams to prepare patches for Cisco infrastructure before disclosure; AI-assisted vulnerability discovery signals accelerating attack surface exposure.
-
Citrix NetScaler zero-days exploited with 50,000 instances exposed
On September 27, 2026, Citrix disclosed eight vulnerabilities affecting NetScaler ADC and Gateway, including two critical RCE flaws actively exploited globally. Palo Alto Networks identified 50,277 exposed instances vulnerable to these CVEs as of September 27.
Why it matters Pre-disclosure attackers exploited these zero-days for 17 days; enterprises must assume compromise on exposed NetScaler appliances and implement forensic response for potential persistence.
-
WatchGuard flaw lets rogue VPN servers root Firebox appliances
WatchGuard disclosed CVE-2026-86131, a critical Fireware vulnerability (CVSS 9.2) allowing attacker-controlled VPN servers to obtain root access to connected Firebox appliances via improper BOVPN over TLS certificate validation.
Why it matters VPN appliances trusting upstream VPN concentrators as security boundaries become an attack surface; validates defense-in-depth principle for remote access infrastructure.
-
Seceon claims unified NDR automates 70% of L1 response
Seceon OTM delivers unified NDR with agentless DPI, encrypted traffic analysis, and automated response via aiSOAR playbooks, automating ~70% of L1 response actions for network threat detection and SOC automation.
Why it matters Reduces MTTR and automates firewall blocks, host isolation, and credential blocking for network-based threats—addressing the alert fatigue and manual response bottleneck in SOCs.
-
Mid-market security teams face 4,000 alerts a day
Enterprise threat detection increasingly relies on AI, ML, behavioral analytics, and SOAR to process network, endpoint, and identity telemetry—addressing alert volumes exceeding 4,000 alerts per day at mid-market enterprises.
Why it matters Network security teams must integrate SOC automation and AI-driven detection to process firewall/VPN alerts at scale; manual triage is no longer operationally viable.
Coverage history
123 earlier storiesSeptember 2026 34
- Sep 29Check Point VPN gateway flaws exploited since September 12Check Point Blog
- Sep 29Network alerts return as SOCs handle 2,566 incidents dailyOptiv / Palo Alto Networks
- Sep 28Attackers exploit two critical Citrix NetScaler zero-daysRapid7
- Sep 27Microsoft adds agent discovery and network-layer data controlsMicrosoft Security Blog
- Sep 27OpenAI and Anthropic log tens of thousands of agent incidentsAxios
- Sep 24Microsoft Unveils Integrated Security Operations Center in Defender for AI AgentsSiliconANGLE
- Sep 24Palo Alto Automates Vulnerability Hunting as Competitor Pressure Escalates in AI SecurityGuruFocus
- Sep 24Microsoft Brings ISOC to Defender—Consolidating SIEM and XDR for Agentic SOC OperationsUnite.AI
- Sep 23Unit 42 Continuous Frontier AI Defense: Agentic Offensive Security with Claude Mythos and GPT-5.6Palo Alto Networks
- Sep 21CrowdStrike and Palo Alto Weekly Surge Reflects AI-Driven Security Spending Thesis, But Durability Uncertain24/7 Wall St.
- Sep 19Citrix Session Insights: AI-powered browser activity analysis for user and agent workflowsHelp Net Security
- Sep 19AI-driven cyber risk dominates market narrative; CrowdStrike positioned as primary beneficiary of AI-era threat accelerationHIPTHER
- Sep 17CrowdStrike Launches SafeMind Agentic AI Models for Cybersecurity Defense with NVIDIAVentureBeat
- Sep 17Palo Alto Cortex Data Security Unified DDR Now GA: Real-Time Detection Across Cloud, SaaS, AIPalo Alto Networks Blog
- Sep 16Google Mandiant: Autonomous AI Systems Create New SOC Defense ChallengeHelp Net Security
- Sep 15FortiSOAR 8.0 introduces native agentic AI framework with 19 pre-built autonomous security agentsFortinet Blog
- Sep 15CrowdStrike, Palo Alto Networks, Fortinet stocks surge on AI threat recognition and agentic security demandUA.NEWS
- Sep 13Enterprise-Wide AI Adoption Drives Explosive SOC Alert Growth: 685% Increase in AI-Triggered Alerts Since FebruaryBellator Cyber / The Hacker News
- Sep 13Versa Extends Zero Trust Controls to AI Agent Actions via Patent-Pending MCP ArchitectureVersa Networks
- Sep 12Wedbush Initiates Cybersecurity Coverage: Platform Consolidation Over Budget Expansion Reshapes Vendor HierarchyInvesting.com / Wedbush Securities
- Sep 12Your Newest Privileged Identity Is An AI Agent: Identity Governance Gap Blocks Production DeploymentSecurity Boulevard
- Sep 11Anthropic Discloses Fourth Incident of AI Model Breaking into Third-Party SystemsThe Hacker News
- Sep 11Cisco and CISA Flag Active Exploitation of CVE-2026-20079 in Secure Firewall Management CenterSecurity Boulevard
- Sep 10CrowdStrike Unveils Charlotte Agentic SOAR with Multi-Agent Coordinated InvestigationsChannel Insider
- Sep 10Microsoft September 2026 Patch Tuesday: 973 CVEs Mark Vulnerability Discovery Inflection PointCrowdStrike
- Sep 10CVE Brief September 10: Network Edge and Security Appliance Infrastructure Dominate Active ExploitationCVE Brief
- Sep 8Threat actors are giving AI agents a bigger role in cyberattacksHelp Net Security / Google Threat Intelligence Group
- Sep 5Palo Alto Networks FY2027 Guidance: NGS ARR Growth Moderates, Billings Signal Consolidation Momentum Cooling24/7 Wall St.
- Sep 4F5 WAF with Agentic Threat Intelligence, Ping Personal Agent Access, Superna 2.15 ReleasedHelp Net Security
- Sep 4Cisco Nexus 9000 Critical Unauthenticated RCE with Three Hardening Drops in 30 DaysThe Hacker News
- Sep 3Palo Alto Networks Acquires Console to Agentify SecurityNetwork World
- Sep 2CrowdStrike Unveils Falcon Guardian: AI Detection and Response at the EndpointCrowdStrike Holdings, Inc.
- Sep 2CrowdStrike at Fal.Con Day 1: AI Defense Moves to Machine Speed with Ecosystem AlliancesInvesting.com
- Sep 2CrowdStrike Adds Runtime Security Platform for AI Agents at the EndpointSecurity Boulevard
August 2026 29
- Aug 31ServiceNow Accelerates Autonomous Security Vision with Six Unified SolutionsHelp Net Security
- Aug 23CrowdStrike Fal.Con 2026 Announces Record 150+ Ecosystem Sponsors, Sold-Out ConferenceCrowdStrike
- Aug 23Intezer Launches Native Workflows Automation Platform, Consolidating Alert Triage and ResponseHelp Net Security
- Aug 22Palo Alto Networks beats Q3 earnings with 60% NGS ARR growth; flags 25% false-positive rate in AI models as structural challengeAd Hoc News / Investing.com
- Aug 22CrowdStrike Fal.Con 2026 attracts record 150+ sponsors, 10,000+ attendees as AI-driven security dominates industry agendaBusiness Wire
- Aug 21CrowdStrike's Fal.Con 2026 Unites Cybersecurity's Ecosystem to Secure the AI RevolutionBusiness Wire
- Aug 21Crogl Announces Its Enterprise AI SOC Agent Available as a Free DownloadManufacturing Business Technology
- Aug 20Tufin Advances Multi-Vendor Agentic Network Security with TOS 5.3 Unified Control PlaneBusiness Wire
- Aug 20Intezer Launches Workflows: Integrated Response Automation Within AI SOC PlatformHelp Net Security
- Aug 19Corma CEO on defensive AI gap: autonomous agents catching live attacks with human-in-the-loop authorizationThe Register
- Aug 18Fortinet Advances Continuous AI Protection with the Acquisition of Virtue AIGlobeNewswire / Fortinet
- Aug 17Weekly Tech Roundup: AI's Next Battle Is Capital, Trust and Control—Cybersecurity Closes the LoopThe CODEW
- Aug 17Weekly Tech Roundup: AI Hits the Physical, Financial and Political Walls—Hyperscaler Capex at $725B, Meta Guidance Triggers Investor PushbackThe CODEW
- Aug 16ScienceLogic Releases Skylar AI 2.5 with Enhanced Secure Deployment and AI PerformanceHelp Net Security
- Aug 15Fortinet Releases Critical Authentication Patches for FortiWeb, FortiManager, FortiClientNews4Hackers
- Aug 15Cisco Patches Zero-Day in Secure Firewall ASA/FTD Exploited for Remote Access DoS; CISA Mandates Federal Patch by August 14Cybersecurity News Review - Week 33 (2026)
- Aug 12Fortinet Q2 2026: SASE Firewall Grows 34%, AI-Driven SecOps Billings Climb 25%Fortinet Investor Relations
- Aug 12CrowdStrike, Palo Alto Hit Record Highs After Black Hat; Analysts See AI Agents as New Foremost Attack VectorQuartz
- Aug 11CrowdStrike, Palo Alto Networks stocks hit new highs after Black Hat—AI agents emerge as foremost attack vectorCNBC
- Aug 9Versa Networks Publishes AI-Native Operations Framework for Unified SASE DeploymentVersa Networks Blog
- Aug 8Cloudflare Named Only Vendor as Visionary in 2026 Gartner SASE and SSE Magic QuadrantsCloudflare Blog
- Aug 7Microsoft Extends Zero Trust Assessment with AI, SecOps, and Infrastructure PillarsMicrosoft Security Blog
- Aug 7CrowdStrike 2026 Threat Report: 88% of Public Exploits Weaponized Within 48 HoursASIS Online
- Aug 7Microsoft Defender Expands with AI Agent Protection and Third-Party Coverage via SentinelMicrosoft Community Hub
- Aug 6Fortinet Launches FortiGate 1200G: Firewall-SASE Convergence with 397 Gbps ThroughputFortinet
- Aug 5CrowdStrike 2026 Threat Hunting Report: AI Operationalized in Adversary Attacks, Exploitation Windows Collapse to 24–48 HoursCrowdStrike
- Aug 4SentinelOne expands security operations automation with governed AIHelp Net Security
- Aug 4Versa recognized in 2026 Gartner Magic Quadrant for SASE Platforms for fourth consecutive yearYahoo Finance / Business Wire
- Aug 3CrowdStrike 2026 Threat Hunting Report: AI is Now Embedded Across Modern Adversary OperationsCrowdStrike
July 2026 26
- Jul 31Cortex XSIAM 3.6 and Cortex AgentiX 1.4: Frontier AI Models and Agentic Response CapabilitiesPalo Alto Networks Blog
- Jul 30One In Four Breaches Are AI-Enabled—And That's Before Hugging FaceForbes
- Jul 29Hush Security Raises $30M Series A to Govern Enterprise AI Agents with Scoped JIT AccessSecurityWeek
- Jul 29NVIDIA Forms 37-Member Open Secure AI Alliance Following Hugging Face Autonomous Agent IncidentNVIDIA Blog
- Jul 25CrowdStrike and Cerebras Partner to Accelerate AI-Driven Threat Detection with High-Speed InferenceCrowdStrike
- Jul 23Palo Alto Networks to Acquire Embrace for Real User Monitoring Capabilities in Observability PlatformPalo Alto Networks Investor Relations
- Jul 23Unit 42 2026 Global Incident Response Report: AI Acceleration in Attack Chains Demands Automated DefensePalo Alto Networks Unit 42
- Jul 21FortiSandbox vulnerabilities exploited in wild: CISA orders July 19 patch deadline for critical command injection flawsTechTimes
- Jul 17CrowdStrike Appoints AJ Shipley as Chief Product Officer to Advance Agentic Era SecurityCrowdStrike IR / SDxCentral
- Jul 17July 2026 Patch Tuesday: Microsoft Fixes 622 Vulnerabilities with Critical Windows VMSwitch Elevation FlawCrowdStrike
- Jul 17Benchmark Raises CrowdStrike Price Target to $230 on AI-Driven Security Demand Across Agentic SOC ProductsStocksToTrade / BTIG Analyst Research
- Jul 16Check Point AI Security Report 2026: AI Crossed From Assistant to Autonomous Attack OperatorCheck Point Research
- Jul 16CrowdStrike Falcon AIDR: Defining the Next Era of Cybersecurity with AI Detection and ResponseCrowdStrike Blog
- Jul 16CrowdStrike Extends Falcon AIDR to Kubernetes Workloads and Integrates Claude Compliance APICrowdStrike Release Notes
- Jul 11CrowdStrike Expands AI Detection and Response with 5x AIDR Demand, Record ARR Growth, and Identity Security PartnershipsSimply Wall St / CrowdStrike investor news
- Jul 11Coforge Launches SecureEdge2Cloud: AI-Powered Zero Trust Security Built on Zscaler PlatformHPCwire
- Jul 11Codenotary Releases AgentMon 3: Enterprise AI Security with Adaptive Runtime Policies for Agentic WorkloadsHelp Net Security
- Jul 9Preparing Zero Trust for AI Disruption: Machine Identities, LLMs, and Automated Decision-MakingISACA
- Jul 7Modernizing SOC Operations with AI-Driven Detection: Agentic AI now handles 30%+ of workflows at large enterprisesVectra AI
- Jul 7CrowdStrike Surges 5%, Palo Alto and Okta Gain 4% as Cybersecurity Stocks Rally on Analyst Upgrades24/7 Wall St.
- Jul 4CrowdStrike Advances AI and Cloud Security Operations on AWSCrowdStrike Press Release
- Jul 3FortiBleed: 86,644 Fortinet Firewalls Compromised — Large-Scale Credential Harvest Across 194 CountriesSOCRadar Research
- Jul 3FortiBleed Signals End of Legacy SSL VPN Era; Industry Shift Toward Cloud SASE and Identity-First Zero TrustTech Insider
- Jul 3Rapid7 Confirms Active Exploitation of CVE-2026-0257 PAN-OS GlobalProtect Authentication Bypass; Attackers Gaining Internal Network AccessRapid7 Labs
- Jul 2Palo Alto, CrowdStrike both have best quarter ever as AI threats bolster cyber demandCNBC
- Jul 1Palo Alto Networks Introduces Secure Agentless Access (SAA): Zero Trust for Unmanaged DevicesPalo Alto Networks Blog
June 2026 34
- Jun 24IBM X-Force Advisory: Active Exploitation of Fortinet FortiGate & Palo Alto GlobalProtect VPN CompromiseIBM Security
- Jun 24CrowdStrike Named Leader in IDC MarketScape 2026 for Worldwide SIEM—Agentic SOC Emerging StandardCrowdStrike
- Jun 24CrowdStrike Expands Falcon AI Detection & Response (AIDR) on AWS—AI Runtime Security for Bedrock, Kiro, Strands AgentsCrowdStrike
- Jun 23Zscaler Redefines Zero Trust SASE for AI Era with ZAgent Framework and Multi-Cloud ExtensionsZscaler
- Jun 23Zscaler Extends AI Guardian Initiative with AI Broker and Endpoint AI SecurityZscaler
- Jun 23CrowdStrike Advances Continuous, Risk-Aware Identity for Autonomous AI AgentsCrowdStrike
- Jun 22Zscaler Unveils Zero Trust Platform for Agentic AI with AI Broker, Endpoint Security, and Access GraphGlobe Newswire / MarketScreener
- Jun 22Autonomous SOC: AI Security Operations in 2026 — Alert Automation and Machine-Speed DetectionRedHub.ai
- Jun 22Five New AI SOC Analyst Platforms: Shipped Autonomy vs. Announced Autonomy in 2026Prophet Security
- Jun 21FortiBleed: 86,644 Fortinet Firewalls Compromised Across 194 Countries in Large-Scale Credential Theft CampaignSecurityWeek
- Jun 21CrowdStrike Q1 FY2027 Earnings Beat on AI Security Momentum; Record ARR Growth and 4-for-1 Stock Split AnnouncedCybersecurity Dive
- Jun 21Palo Alto Networks Raises FY2026 Profit Guidance on AI-Driven Security Platformization AccelerationBloomberg
- Jun 20Fortinet Launches FortiSOC Cloud Platform with Agentic AI for Autonomous Alert InvestigationHelp Net Security
- Jun 20Tigera Launches Lynx: Unified Control Plane for Kubernetes-Native AI AgentsHelp Net Security
- Jun 19Zscaler Expands Zero Trust SASE With ZAgent Framework for AI-Era AdministrationManufacturing Today India
- Jun 19Zero Trust for AI Agents: SASE Vendors Race to Secure Non-Human UsersFierce Network
- Jun 19Zscaler Announces AI-Guardian Project and Platform Integrations for Enterprise AI SecuritySimply Wall Street
- Jun 18Zscaler Expands Zero Trust SASE with ZAgent Framework for AI-Era Security OperationsSDxCentral
- Jun 18Fortinet Introduces FortiSOC: Unified Cloud-Delivered SOC Platform with Agentic AIFortinet
- Jun 18FortiBleed: 73,932 Fortinet Firewalls Compromised via Configuration Exfiltration and Credential Hash CrackingBleepingComputer
- Jun 17Zscaler expands Zero Trust SASE with ZAgent Framework for agentic administrationManufacturing Today India
- Jun 16Zscaler Expands Zero Trust SASE with ZAgent Framework for Autonomous OperationsSDxCentral
- Jun 15Zscaler Expands Zero Trust SASE with ZAgent Framework for Agentic AI OperationsSiliconANGLE
- Jun 15BlueVoyant Launches BlueVoyant AI Agentic Security Operations PlatformIT Brief
- Jun 15Tata Communications ThreadSpan: AIOps and Network Observability Platform UpdateTata Communications
- Jun 14Cybersecurity Weekly News Roundup (June 6 – June 12, 2026)Boston Institute Of Analytics
- Jun 13Zscaler Unveils ZAgent Framework to Automate Zero-Trust SASE OperationsSiliconANGLE
- Jun 13Zero Trust for AI Agents: SASE Vendors Race to Secure Non-Human UsersFierce Network
- Jun 13Palo Alto Networks Addresses Cortex XSIAM and XSOAR Vulnerabilities in CommvaultSecurityIQ IntegrationCanadian Centre for Cyber Security
- Jun 12Zscaler Expands Zero Trust SASE with ZAgent Framework for Agentic AI OperationsSiliconANGLE
- Jun 12Versa Brings Zero Trust Controls to AI Agent Actions with Patent-Pending MCP ArchitectureVersa Networks
- Jun 12SASE Vendors Race to Secure Non-Human Users as Agentic AI Floods Enterprise NetworksFierce Network
- Jun 11Zscaler Expands Zero Trust SASE with ZAgent Framework for Natural-Language AdministrationSecurity Brief
- Jun 11How AI Is Automating IT Operations in 2026European Express