QTFY disruption exposes the weakness of source-IP trustCISA’s two-SOC test makes response authority a control requirementActively exploited Gitea flaw puts the software forge in scopePublic SharePoint chain converts authentication bypass into RCE
QTFY disruption exposes the weakness of source-IP trust
Court-authorised seizures disabled QScan and QTRouter, but enterprises still need to determine whether compromised IoT devices or proxy infrastructure made hostile activity appear local and trusted.
Security.io Intelligence Desk · Wednesday, 26 August 2026
Executive consequence
US authorities say QTFY used QScan to infect internet-connected devices and QTRouter to conceal the origin of intrusion activity.
Decision today
Task network engineering to identify unmanaged IoT devices and proxy services reachable from privileged networks.
Read the full decision briefPrimary reporting: United States Department of Justice · Federal Bureau of Investigation
Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Six-minute executive briefing
Security.io Daily Headlines
Five equally weighted stories: what happened and the leadership decision each creates.
CISA’s side-by-side red-team assessments show that tuned detections and empowered responders can terminate initial access quickly, but both organisations retained identity, cloud and Tier 0 paths capable of supporting wider compromise.
Do today
Audit Machine Account Quota and ADCS templates for unauthorised domain-escalation paths.
CISA added CVE-2026-60004 to KEV after evidence of active exploitation. Gitea instances before 1.27.1 require urgent upgrade or isolation, followed by repository, process and credential investigation.
Do today
Inventory every self-hosted Gitea instance, version and exposure path.
VulnCheck published a complete chain combining CVE-2026-55040 and CVE-2026-63520 for unauthenticated SharePoint code execution. The first flaw is actively exploited; successful exploitation of the second was not established at the edition cutoff.
Do today
Verify every SharePoint farm against both fixed build thresholds.
Reporting on August 25 added compromise and exposure telemetry for an actively exploited Zimbra path while separately highlighting a Laundry Bear zero-click Zimbra espionage campaign. The sources do not establish a shared technical cause or common operator.
Do today
Inventory every internet-facing Zimbra instance and supported version.