Cyber Intelligence

Xcelericx Cyber Intelligence

Cybersecurity intelligence that matters.

Stay informed about the latest cyber threats, vulnerabilities, data breaches, ransomware campaigns and security developments affecting businesses in South Africa and around the world.

Get the Xcelericx Cyber Brief — Free

Get the most important cybersecurity news, vulnerabilities, threats and practical security advice delivered directly to your inbox.

No spam. No cost. Unsubscribe anytime.

Critical Threats

Critical

Critical RCE Vulnerability in Fortinet FortiOS SSL-VPN

Vendor: FortinetProduct: FortiOS SSL-VPN

A critical remote code execution vulnerability in Fortinet FortiOS SSL-VPN is being actively exploited in the wild. Attackers are leveraging this flaw to gain unauthenticated access to enterprise network perimeters.

Recommended action: Apply the vendor patch immediately. If patching is not immediately possible, disable SSL-VPN access and review firewall logs for signs of exploitation. Verify whether exposed systems have been compromised.

Critical

Microsoft Windows CLFS Zero-Day Actively Exploited

Vendor: MicrosoftProduct: Windows CLFS Driver

A zero-day privilege escalation vulnerability in the Windows Common Log File System (CLFS) driver is being exploited by ransomware operators to gain SYSTEM-level privileges on compromised endpoints.

Recommended action: Deploy the Microsoft emergency patch via Windows Update. Prioritise patching of internet-facing and critical systems. Review EDR telemetry for suspicious CLFS activity.

Critical

Cisco IOS XE Web UI Authentication Bypass

Vendor: CiscoProduct: IOS XE Web UI

A critical authentication bypass vulnerability in the Cisco IOS XE Web UI allows unauthenticated remote attackers to create administrator-level accounts and take full control of affected network devices.

Recommended action: Disable the HTTP/HTTPS server feature on internet-facing IOS XE devices immediately. Apply Cisco's patch as soon as available. Audit device configurations for unauthorised accounts.

Latest Cyber Intelligence

RansomwareCritical

RansomHub Ransomware Group Targets South African Financial Sector

The RansomHub ransomware-as-a-service operation has been observed targeting financial institutions across sub-Saharan Africa, with multiple South African organisations reportedly affected.

|BleepingComputer
Read More
VulnerabilityHigh

Palo Alto Networks PAN-OS Privilege Escalation Flaw Patched

Palo Alto Networks has released patches for a high-severity privilege escalation vulnerability in PAN-OS that could allow authenticated attackers to gain root access on affected firewalls.

|SecurityWeek
Read More
Data BreachHigh

Major Healthcare Provider Discloses Data Breach Affecting 2.3 Million Patients

A large healthcare provider has disclosed a data breach affecting over 2.3 million patients after attackers exploited an unpatched vulnerability in their patient management system.

|The Hacker News
Read More
Threat IntelligenceHigh

APT Group Targets African Telecoms with Custom Malware

A state-sponsored threat actor has been observed deploying custom malware against telecommunications providers across Africa, with the campaign focused on long-term persistent access and intelligence gathering.

|Palo Alto Unit 42
Read More
Cloud SecurityMedium

Microsoft Entra ID Misconfiguration Exposes Thousands of Tenants

Security researchers have identified a widespread misconfiguration pattern in Microsoft Entra ID deployments that exposes sensitive resources to unauthorised access through overly permissive conditional access policies.

|KrebsOnSecurity
Read More
AI SecurityMedium

Prompt Injection Attacks Against Enterprise AI Assistants on the Rise

Security researchers are documenting a significant increase in prompt injection attacks targeting enterprise AI assistants integrated with business applications, enabling data exfiltration and unauthorised actions.

|SANS Internet Storm Center
Read More

Vulnerabilities & Security Advisories

CVESeverityAction
CVE-2026-40112CriticalApply MS emergency patch via Windows Update immediately.
CVE-2026-38201CriticalPatch immediately or disable SSL-VPN. Review logs for IOCs.
CVE-2026-20198CriticalDisable HTTP/HTTPS server on internet-facing devices. Audit for rogue accounts.
CVE-2026-3109HighApply October Patch Tuesday update. Restrict external access to OWA.
CVE-2026-44228HighUpdate to patched version. Restrict management interface access.
CVE-2026-6241HighApply Cisco security advisory patch. Review VPN access logs.
CVE-2026-11023MediumApply patch in next maintenance window. Monitor for exploitation.
CVE-2026-9001MediumUpdate to latest version. Restrict admin interface to trusted IPs.

South African Cybersecurity

South AfricaCritical

Transnet Cyber Incident Disrupts Port Operations Across South Africa

A significant cyber incident affecting Transnet's operational technology systems has disrupted container terminal operations at multiple South African ports, causing supply chain delays.

· BusinessTech
Read More
South AfricaHigh

POPIA Enforcement: Information Regulator Issues First Major Fines

South Africa's Information Regulator has issued its first significant enforcement actions under POPIA, with fines issued to three organisations for failing to adequately protect personal information.

· ITWeb
Read More
South AfricaHigh

South African Banking Sector Reports Surge in Business Email Compromise

The South African Banking Risk Information Centre (SABRIC) has reported a 34% year-on-year increase in business email compromise incidents targeting South African businesses.

· Fin24
Read More

Need help protecting your organisation?

Our team specialises in South African threat landscapes, POPIA compliance and local incident response.

Talk to Xcelericx

Global Cybersecurity News

High

CISA Adds 12 New Vulnerabilities to Known Exploited Vulnerabilities Catalogue

The US Cybersecurity and Infrastructure Security Agency has added 12 new vulnerabilities to its KEV catalogue, including critical flaws in widely-used enterprise networking and security products.

|CISARead More
Critical

LockBit 4.0 Infrastructure Disrupted in International Law Enforcement Operation

An international law enforcement coalition has disrupted the infrastructure of the LockBit 4.0 ransomware operation, seizing servers and arresting key affiliates across multiple countries.

|EuropolRead More
High

Widespread Credential Stuffing Campaign Targets Enterprise SaaS Platforms

Security researchers have identified a large-scale credential stuffing campaign targeting enterprise SaaS platforms, using credentials from previous data breaches to compromise business accounts.

|SecurityWeekRead More
Medium

AWS Releases Security Guidance Following S3 Bucket Misconfiguration Incidents

Amazon Web Services has published updated security guidance and new automated controls following a series of high-profile data exposures caused by misconfigured S3 buckets.

|AWS Security BlogRead More

Xcelericx Analysis

Expert interpretation of critical cybersecurity developments — what happened, who is affected, and what to do.

Ransomware

RansomHub's Expansion into African Markets: What South African Organisations Need to Know

What happened?

The RansomHub ransomware-as-a-service group has significantly expanded its targeting of organisations in sub-Saharan Africa, with confirmed attacks against financial services, logistics and healthcare organisations in South Africa.

Who is affected?

South African financial institutions, logistics companies, healthcare providers and any organisation with internet-facing systems running unpatched vulnerabilities. Organisations with weak MFA enforcement are at elevated risk.

Why it matters

RansomHub affiliates are known for aggressive double-extortion tactics — encrypting data and threatening to publish sensitive information. South African organisations face reputational, regulatory (POPIA) and operational consequences from a successful attack.

Xcelericx recommendation

Conduct an immediate review of internet-facing systems and patch critical vulnerabilities. Enforce MFA across all remote access solutions. Ensure offline backups are current and tested. Engage your incident response provider to validate detection capabilities.

Vulnerability

Fortinet FortiOS SSL-VPN RCE: Why This Vulnerability Demands Immediate Action

What happened?

A critical unauthenticated remote code execution vulnerability in Fortinet FortiOS SSL-VPN is being actively exploited. Attackers are using this flaw to gain initial access to enterprise networks without requiring any credentials.

Who is affected?

Any organisation running Fortinet FortiOS with SSL-VPN enabled and exposed to the internet. This includes a significant number of South African enterprises that rely on Fortinet for network security.

Why it matters

SSL-VPN gateways are high-value targets because they sit at the network perimeter and provide direct access to internal resources. Successful exploitation gives attackers a foothold from which to conduct lateral movement, deploy ransomware or exfiltrate data.

Xcelericx recommendation

Patch immediately using Fortinet's emergency advisory. If patching cannot be completed within 24 hours, disable SSL-VPN access temporarily. Review FortiOS logs for indicators of compromise. Engage your security team to validate whether exploitation has occurred.

Cyber Brief Archive

Xcelericx Cyber Brief — October 2026

Critical threats, South African cybersecurity developments and Xcelericx analysis for October 2026.

Xcelericx Cyber Brief — September 2026

Ransomware trends, vulnerability roundup and POPIA enforcement update for September 2026.

Coming soon

Xcelericx Cyber Brief — August 2026

Mid-year threat landscape review, identity security focus and South African incident roundup.

Coming soon

Stay Ahead of the Threat

Subscribe to the free Xcelericx Cyber Brief and receive important cybersecurity developments, vulnerabilities and practical security recommendations.

Free subscription. Unsubscribe anytime.