ThreatsDay Bulletin: PAN-OS RCE, AI Privacy Updates, and Critical Data Leaks
This cybersecurity bulletin highlights several critical vulnerabilities and emerging threats. Palo Alto Networks released patches for CVE-2026-0300, a critical remote code execution flaw in PAN-OS actively exploited by threat actors to deploy malware like EarthWorm. Meta introduced Incognito Chat for WhatsApp and its app, utilizing Trusted Execution Environments to ensure private AI interactions where data is not accessible to the company. Meanwhile, defense contractor Schemata suffered a significant data leak due to missing authorization checks on API endpoints, exposing military training materials and user records, though no third-party exploitation was confirmed. The U.S. FCC extended the deadline for security updates on banned foreign routers to January 2029 to maintain device safety. Additionally, new cyber campaigns were identified, including Operation GriefLure targeting Vietnamese telecom and Philippine healthcare sectors via spear-phishing, and a multi-stage intrusion using weaponized PowerShell disguised as JPEG files to deliver trojanized ConnectWise ScreenConnect. These events underscore ongoing risks in supply chain security, social engineering, and infrastructure protection.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection