Weekly Threat Intelligence Briefing — Monday, February 2, 2026

Weekly Threat Intelligence Briefing — February 02, 2026

February 02, 2026

Weekly Threat Intelligence Briefing · Monday, February 2, 2026


Monday, February 2, 2026

PSY Logistics Technology Partners

January closed with an avalanche of zero-days and mega-breaches. If your vulnerability management program isn’t keeping pace, this week’s headlines explain why it should be your #1 priority heading into February.

⚡ Top Exploits This Week

🔸 Fortinet CVE-2026-24858 (CVSS 9.4)

Critical FortiCloud SSO authentication bypass affecting FortiOS, FortiManager, and FortiAnalyzer. Attackers bypassed SSO to create rogue admin accounts and exfiltrate configurations within seconds. Approximately 10,000 exposed instances identified globally. Patches are available for FortiOS 7.4.11 and 7.6.6.

🔸 Ivanti EPMM CVE-2026-1281 & CVE-2026-1340 (CVSS 9.8)

Dual zero-day remote code execution flaws in Ivanti Endpoint Manager Mobile. Unauthenticated attackers can inject bash commands via HTTP requests. CISA issued a 3-day remediation deadline. Public proof-of-concept exploit code is now available.

🔸 Microsoft January Patch Tuesday

112 CVEs patched, including actively exploited Windows DWM information disclosure (CVE-2026-20805) and Office security feature bypass (CVE-2026-21509). Both have been added to CISA’s Known Exploited Vulnerabilities catalog.

📋 Major Breaches

  • Under Armour — 72 million customer records exposed by Everest ransomware group (343 GB stolen). A class action lawsuit has been filed.
  • Nike — Investigating 1.4 TB data theft by WorldLeaks. Stolen files reportedly include product intellectual property and manufacturing workflows.
  • Marquis Software — Supply chain ransomware attack via unpatched SonicWall firewall impacted 1.35 million banking customers across dozens of financial institutions.

🎯 DIB Takeaways for CMMC Compliance

If you’re a Defense Industrial Base contractor heading toward CMMC Level 2:

  • Fortinet and Ivanti products are in many DIB environments. Patch NOW and document your remediation for assessment evidence.
  • The Marquis breach is a textbook supply chain risk (NIST 800-171 SR-3). Do you know the security posture of YOUR vendors?
  • Malicious VS Code AI extensions (1.5M installs, exfiltrating to China) are a direct threat to CUI in development environments.
  • Review NIST SP 800-171 controls SI-2, SI-5, and RA-5 against this week’s CISA KEV additions.

The pace of zero-day exploitation is accelerating. CISA’s KEV catalog grew 20% in 2025 and 2026 is starting even faster. Your vulnerability management cadence needs to match the threat tempo.

Stay vigilant. Stay patched. Stay compliant.

CEO & Founder, PSY Logistics Technology Partners, Inc.

CMMC Certified Assessor (CCA) Lead Assessor

[email protected] | psylogistics.com

Back to Blog