VOL. III · ISSUE 22THURSDAY, MAY 28, 2026
CipherGuard
Investigative cybersecurity reportingLondon · Bangalore · Online edition
Server racks in a dark data centre, illuminated by amber status lights
Photo · Unsplash / Taylor Vick
InvestigationCRITICALMITRE: T1078, T113312 months of reporting · 47 sources

Inside the Volt Typhoon playbook: a year of pre-positioning inside US critical infrastructure

Court records, leaked router configs, and interviews with five utility operators trace how a PRC-linked group quietly built persistence across water, energy, and transit networks — and why "living-off-the-land" made it invisible to most defenders until it was already inside.

Threat Advisories

CipherGuard-issued bulletins, updated as reporting changes. Each links to source filings and our coverage.

CG-ADV-26-018CRITICALCVSS 9.8

Cisco IOS XE web UI — unauthenticated remote code execution

A flaw in the management web interface allows an unauthenticated attacker to create a privileged account and execute arbitrary commands. Mass-scanning observed within 48 hours of disclosure.

Vendor
Cisco
Affected
IOS XE 17.x with HTTP server enabled
Status
Patch available
First seen
May 26, 2026
CG-ADV-26-017HIGHCVSS 8.6

Ivanti Endpoint Manager — unauthenticated SQL injection

Pre-auth SQLi in the Ivanti EPM agent endpoint allows extraction of credentials and lateral movement. CISA added the flaw to the KEV catalog on May 24.

Vendor
Ivanti
Affected
EPM 2022 SU5 and earlier
Status
Exploited
First seen
May 22, 2026
CG-ADV-26-016HIGHCVSS 7.5

Apache Tomcat — path traversal via crafted URI

A normalisation bug allows reading of files outside the document root. Proof-of-concept is public; no exploitation observed in production telemetry yet.

Vendor
Apache Software Foundation
Affected
Tomcat 9.x, 10.x, 11.x
Status
PoC public
First seen
May 20, 2026
CG-ADV-26-015MEDIUMCVSS 6.5

PostgreSQL — privilege escalation via pg_extension

Certain extensions allow a non-superuser to register functions that execute as superuser at install time. Configuration mitigation available pending the next minor release.

Vendor
PostgreSQL Global Development Group
Affected
PostgreSQL 14, 15, 16, 17
Status
Patched
First seen
May 18, 2026
CG-ADV-26-014CRITICALCVSS 9.4

Fortinet FortiManager — out-of-bounds write in fgfmd

A heap overflow in the FortiManager daemon allows pre-auth code execution. CISA flagged active exploitation by a state-aligned actor on May 19.

Vendor
Fortinet
Affected
FortiManager 7.4.0–7.4.4, 7.2.x
Status
Exploited
First seen
May 19, 2026
CG-ADV-26-013LOWCVSS 4.3

OpenSSL 3.4 — denial of service via crafted certificate

A specially crafted X.509 certificate can trigger excessive memory allocation during chain verification. Practical impact is limited to TLS clients that auto-fetch chains.

Vendor
OpenSSL Project
Affected
OpenSSL 3.4.0–3.4.1
Status
Patched
First seen
May 16, 2026

Latest investigations & analysis

5 reports
Browse the full archive →
Long read · ongoing

The software supply chain, in numbers

A standing scoreboard CipherGuard updates with each major disclosure. Illustrative figures from CISA, OSV.dev and our own SBOM corpus.

Disclosed critical vulns by month (rolling 12)Source: CipherGuard composite — illustrative
4003002001000JunJulAugSepOctNovDecJanFebMarAprMaylog4j-class spike

Most-reported ecosystems (12 mo)

  • 01npm1,842
  • 02PyPI1,208
  • 03Maven Central974
  • 04NuGet612
  • 05crates.io338
  • 06RubyGems281

Counts include both vendor-issued and community-reported advisories.

Skip to content
Inside the Volt Typhoon playbook: a year of pre-positioning inside US critical infrastructure

Court records, leaked router configs and interviews with five utility operators trace how a PRC-linked group quietly built persistence across water, energy and transit networks — and why 'living-off-the-land' made it invisible to most defenders until it was already inside.

Manias and Minds: How Emotion Drives Markets

What we found in the leaked Conti chats, two years later

Re-reading 60,000 internal messages with fresh eyes — what they reveal about the affiliate market, OPSEC fatigue, and how the brand splintered into the groups still extorting hospitals today.

Why your CASB is lying to you about Shadow IT

We tested four leading Cloud Access Security Brokers against a controlled set of 312 SaaS apps. Discovery rates ranged from 38% to 71% — and the gaps tracked predictably with how vendors source their app catalogs.

Mergers, IPOs and Corporate Actions Explained

The Financial Ratios That Actually Matter

An SBOM workflow that would have caught log4j in 45 minutes

Most SBOM programmes are theatre. A working pipeline needs three things shops keep skipping: deterministic builds, a queryable graph store, and a triage process that does not depend on a single hero.

Crypto and Blockchain in 2026: Beyond the Hype, Into the Infrastructure

The AI Investment Landscape in 2026: What Every Tech Professional Should Know

The DNS rebinding revival: 2026 edition

A class of attack we declared dead in 2018 is back, exploiting the way modern browsers handle WebRTC and Private Network Access. We walk a working proof-of-concept against three popular IoT controllers.