What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree
Sygnia confirmed that the Fire Ant actor deployed purpose-built implants on Cisco IOS XR routers and TACACS servers that filter log output, hide GRE tunnel configuration from administrators, and exfiltrate credentials through a tac_plus library-injection technique it tracks as TacTap, with IoCs and YARA rules published for defensive validation. CISA added CVE-2026-60004 (Gitea code injection) and CVE-2026-8452 (Citrix NetScaler) to its KEV catalog, confirming active exploitation of both, while Shadowserver reported at least 274 internet-facing Zimbra instances already compromised via CVE-2026-73570.
Read this edition