SSF Cyber Defence Digest
Issue Date: 7 March 2026Reporting Period: 7 February 2026 – 7 March 2026
Cyber threat alerts for security professionals to assess emerging risks, evaluate potential exposure, and investigate further using official advisories and trusted technical sources.
⚠ Microsoft February Patch Tuesday Addresses Six Zero-Days
Vulnerability Level: 🔴 Critical — Active ExploitationIncident Summary: Microsoft resolved six actively exploited zero-day vulnerabilities during the February Patch Tuesday release, affecting Windows security components and privilege management.
Attack Vector: Multiple CVEs | Privilege Escalation | Security Feature Bypass
Potential Impact: Local privilege escalation | Security bypass | Enterprise endpoint compromise
Defence: Deploy February Microsoft security updates immediately and verify enterprise patch compliance.
⚠ SolarWinds Web Help Desk Under Active Exploitation
Vulnerability Level: 🔴 CriticalIncident Summary: Threat actors actively exploited critical SolarWinds Web Help Desk vulnerabilities, deploying remote management tools and Velociraptor to establish persistence.
Attack Vector: CVE-2025-26399 | CVE-2025-40551 | Remote Code Execution
Potential Impact: Server compromise | Persistence | Credential theft | Security control evasion
Defence: Upgrade Web Help Desk immediately, investigate exposed servers, and review remote management tool activity.
⚠ Cisco Secure Firewall Security Advisory Bundle Released
Vulnerability Level: 🔴 CriticalIncident Summary: Cisco published multiple critical advisories affecting Secure Firewall Management Center, ASA and FTD software, including vulnerabilities with maximum severity ratings.
Attack Vector: Multiple CVEs | Remote Management Services | Firewall Infrastructure
Potential Impact: Firewall compromise | Service disruption | Administrative access
Defence: Prioritise Cisco Secure Firewall updates and review internet-facing firewall management interfaces.
⚠ MuddyWater Continues Targeting Critical Infrastructure
Vulnerability Level: 🟠 HighIncident Summary: European threat intelligence reporting highlighted continued activity by the Iran-linked MuddyWater group targeting government and critical infrastructure organisations using spear-phishing and remote access tools.
Attack Vector: Phishing | Remote Access Tools | Credential Theft
Potential Impact: Initial access | Espionage | Long-term persistence
Defence: Strengthen email filtering, enforce multi-factor authentication, and monitor remote administration activity.
⚠ Enterprise Patch Management Remains the Primary Defence Priority
Vulnerability Level: 🟠 HighIncident Summary: February and early March advisories demonstrated that attackers continued exploiting recently disclosed vulnerabilities within days of public release, reinforcing the need for rapid patch deployment.
Attack Vector: Unpatched enterprise systems | Internet-facing services | Known vulnerabilities
Potential Impact: Enterprise compromise | Ransomware deployment | Credential theft
Defence: Prioritise internet-facing assets, maintain continuous vulnerability management, and verify remediation through security monitoring.