CISA’s Latest KEV Additions Put Network Management Systems in the Spotlight

Meta Pixel. Google Analytics. Session replay. All CIPA liabilities hiding in plain sight

California's Invasion of Privacy Act is being used to target the exact tracking stack your business runs on. The claim is simple, if trackers fire before consent is obtained, the banner is just decoration. Cookiebot's auto-blocking stops every script until consent is given. Scan your site free to see what's firing right now.

From the Editor’s Desk

The past week has shown that security teams are being asked to move faster while the attack surface keeps growing. From actively exploited network flaws to AI systems being used in both attacks and defense, the gap between identifying a risk and acting on it is getting smaller. Is the bigger challenge now finding vulnerabilities, or having the right process to act on them fast enough?

🔎 Deep Brief

CISA’s Latest KEV Additions Put Network Management Systems in the Spotlight

CISA has added vulnerabilities affecting Arista VeloCloud Orchestrator and Fortinet FortiOS to its Known Exploited Vulnerabilities (KEV) catalog. The more urgent issue is CVE-2026-16812, a critical VeloCloud Orchestrator on-premises flaw with a CVSS score of 10.0. The vulnerability allows remote attackers to access privileged internal functions and potentially take control of the underlying host. Arista has confirmed active exploitation and published IP addresses associated with attacks.

The FortiOS issue, CVE-2025-68686, has a lower CVSS score of 5.3 but can allow attackers who already have filesystem-level access to bypass protections against malicious symbolic links. This makes it particularly relevant to post-compromise activity.

For security teams, the lesson is clear: KEV entries deserve more than a routine patching ticket. Teams should identify exposed assets, check logs for exploitation, apply vendor fixes, and review systems for signs of earlier compromise.

Takeaway

Treat CISA KEV additions as an immediate risk-prioritization signal, not simply another vulnerability list.

🧠 Strategy in Action

Open AI Models Become Part of the Cybersecurity Debate

The tech industry is taking a more active position on open-weight AI as concerns grow over how AI models should be secured and controlled. A coalition of 76 companies recently called for greater openness in AI, while 37 companies launched the Open Secure AI Alliance to promote open AI systems, security tools, and defensive capabilities.

The security argument is practical. Open models can be run on an organization's own infrastructure, giving defenders more control over sensitive data and model behavior. The Cybersecurity Dive report points to a recent Hugging Face incident in which an open model, GLM 5.2, helped analyze an attack after closed models declined to process the security data.

Takeaways: 

AI security planning should assess not only the risks of open models, but also where controlled access to them could improve defensive work.

🕵️ Threat Actor Spotlight

Agrius

Agrius is an Iranian threat actor tracked by MITRE ATT&CK as G1030. Active since at least 2020, the group has focused heavily on targets in Israel and the wider Middle East. Public reporting has linked Agrius to Iran's Ministry of Intelligence and Security (MOIS).

The group is notable for ransomware and wiper operations. That combination matters because a ransomware attack may be aimed at financial gain, while a wiper can focus on disruption or destruction. MITRE also tracks Agrius under several other names, including Pink Sandstorm, AMERICIUM, Agonizing Serpens, and BlackShadow.

🛠️ Tool Check

Cookiebot by Usercentrics – Simplifying Consent Management

Cookiebot by Usercentrics helps organizations automate website consent management while supporting privacy regulations such as GDPR, ePrivacy, LGPD, and CCPA. The platform automatically scans websites to identify cookies and trackers, categorizes them, and presents visitors with customizable consent banners. It also maintains detailed consent records that can help demonstrate regulatory compliance during audits.

🗣️ Community Signal

Cybersecurity is not just about technology. It's about relationships, communication, and building enough trust that teams can work together before challenges arise. - Erika Voss

📚 Don’t Miss This

Advertise with Comparitech
Does your business offer services or products in cybersecurity? Get your product seen by IT leaders and professionals.

Advertise with us →

Until Friday’s edition - Let’s keep that zero-day count at zero!