From the Desk of Melissa Irace, CISO
The threats this week reinforce a simple truth: attackers are focusing on the technologies that keep organizations connected and protected. The question isn’t if these systems will be targeted — it’s whether your organization can detect and respond quickly enough to limit the impact.

Weekly executive summary
This week’s cyber activity highlights a clear trend: attackers are targeting the very systems organizations rely on to stay secure — firewalls, VPNs, and management platforms. Active exploitation of Cisco Secure FMC, NetScaler, and WatchGuard devices shows that security infrastructure has become a high-value entry point for ransomware and espionage.
We’re also seeing increased browser exploitation with a new BlueMoon exploit kit, and AI-powered attacks being used to rapidly compromise vulnerable PaperCut systems.
The takeaway for leaders: it’s not just about patching. Organizations must validate whether their defenses are working, detect compromise early, and ensure critical systems can continue operating if technology is disrupted.
Melissa’s perspective
“The biggest risk this week isn’t just new vulnerabilities — it’s the targeting of the systems we trust most. Security platforms, remote access, and management tools are now prime targets. Organizations should prioritize visibility, validate their defenses, and assume a breach could happen even after patching.”
This week’s top threats
01 · Severe
Cisco Secure FMC under active exploitation
Attackers are actively targeting Cisco’s firewall management platform, which controls and manages network security devices. A successful attack can give criminals broad access to internal networks, security configurations, and sensitive data.
How Intuitus helps
- External Attack Surface Assessments
- Penetration Testing as a Service (PTaaS)
- Network Security Assessments
- Security Architecture Reviews
- Vulnerability Assessments
Source: BleepingComputer, “Cisco confirms Secure FMC flaw exploited in attacks”
02 · High
NetScaler authentication bypass exploited
Attackers are exploiting a critical vulnerability in NetScaler appliances, which are commonly used for secure remote access. This can allow unauthorized access to internal systems, putting sensitive data and business operations at risk.
How Intuitus helps
- Penetration Testing as a Service (PTaaS)
- Identity Security Assessments
- Network Security Assessments
- Vulnerability Assessments
- Managed Detection & Response (MDR)
Source: SecurityWeek, “Critical NetScaler Vulnerability Exploited in Attacks”
03 · High
WatchGuard Firebox RCE used in ransomware attacks
Cybercriminals are actively exploiting a vulnerability in WatchGuard Firebox devices to gain unauthorized access. This is now being used in ransomware attacks, which can lead to data loss, operational disruption, and significant financial impact.
How Intuitus helps
- Network Security Assessments
- Vulnerability Assessments
- Penetration Testing as a Service (PTaaS)
- Ransomware Readiness Assessments
- Managed Detection & Response (MDR)
Source: BleepingComputer, “CISA: WatchGuard RCE flaw now exploited in ransomware attacks”
04 · High
BlueMoon exploit kit targets Chrome and Windows
A new exploit kit is being used to target web browsers, including Chrome, to gain control of computers. This can lead to credential theft, unauthorized access, and espionage, with government, defense, and other organizations among the targets.
How Intuitus helps
- Endpoint Security Assessments
- Penetration Testing as a Service (PTaaS)
- Vulnerability Assessments
- Security Awareness Training
- Managed Detection & Response (MDR)
Source: BleepingComputer, “New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws”
05 · Medium
AI-powered PaperCut campaign compromises hundreds of organizations
Threat actors are using AI to automate and scale attacks against vulnerable PaperCut systems. Hundreds of organizations have been compromised, showing how quickly attackers can now find and exploit weaknesses.
How Intuitus helps
- Application Security Assessments
- External Attack Surface Assessments
- Vulnerability Assessments
- Internal Infrastructure Reviews
- Managed Detection & Response (MDR)
Source: BleepingComputer, “AI-powered attack exploited PaperCut flaws to hack 395 organizations”
Our approach
We don’t simply report threats. We help organizations understand their business impact, validate their defenses, and build resilience before an incident occurs. Our intelligence-driven approach transforms emerging cyber threats into practical, prioritized actions that strengthen security, improve operational resilience, and support informed executive decisions.
Five actions to take this week
- Patch priority. Immediately patch firewalls, VPNs, and other exposed systems.
- Check for compromise. Review logs and activity on security appliances and critical systems for signs of unauthorized access.
- Strengthen access controls. Enforce multi-factor authentication and review administrative access across key systems.
- Update endpoints. Ensure browsers, operating systems, and enterprise applications are fully updated.
- Prepare and respond. Validate incident response plans and test recovery procedures for ransomware and service disruptions.