CISA’s new Binding Operational Directive, BOD 26-04, compresses federal patch deadlines to as little as three days — and it lands the same week Fortinet’s FortiSandbox and Cisco’s Catalyst SD-WAN are under active exploitation. The gap between a vulnerability’s disclosure and the deadline to fix it is collapsing fast. This is squarely a SOC-operations story, and one I’ll be watching closely.
Sources: CISA, BleepingComputer, The Hacker News
Vulnerabilities & Exposure
Fortinet FortiSandbox under active attack. Three vulnerabilities — CVE-2026-39813 (path traversal), CVE-2026-39808 (OS command injection) and CVE-2026-25089 — have been exploited in the wild over the past 24 hours; the path-traversal flaw allows unauthenticated attackers to bypass authentication entirely.
Cisco Catalyst SD-WAN Manager exploited. CVE-2026-20262, a path-traversal flaw (CVSS 6.5), was added to CISA’s Known Exploited Vulnerabilities catalog on June 15; Cisco has shipped fixes.
So what: The items already being exploited in the wild — Fortinet and Cisco — are the ones that matter most for the new federal patch clocks.
AI Impact on Security
Cisco ships SOC agents and DefenseClaw. Cisco’s Automation Builder and Triage agents are launching this June, with Detection Builder and Guided Response in prerelease. DefenseClaw is designed to secure AI-agent supply chains, including a Skills Scanner, MCP Scanner, AI Bill of Materials, and CodeGuard.
The agentic SOC is now the whole field. Microsoft has widened autonomous triage into identity and cloud; Palo Alto took its Cortex AgentiX standalone; Google added threat-hunting and detection-engineering agents; and CrowdStrike launched a seven-agent “agentic security workforce.”
So what: Every major platform now has named agents. The differentiator is shifting from whether a vendor has agents to whether those agents have the data visibility to actually be right — that’s exactly the thesis I’ve been tracking.
Cyberattacks & Breaches
SprySOCKS goes cross-platform. Researchers documented two previously unseen Windows variants of a backdoor long thought to be Linux-only.
ClickFix loaders proliferating. Campaigns are actively delivering the BabaDeda, “Lorem Ipsum,” and Potemkin malware loaders.
Rokarolla Android banking trojan. The malware targets 217 banking and cryptocurrency apps.
Regulatory & Policy
CISA’s BOD 26-04. The new Binding Operational Directive supersedes BOD 22-01, accelerating remediation timelines for federal civilian agencies, with some windows as short as three days.
White House AI executive order. The administration issued “Promoting Advanced AI Innovation and Security” in June 2026.
FY2026 NDAA and DFARS harmonization. New supply-chain and domestic-sourcing rules direct the Department of Defense to harmonize its industrial-base cyber requirements by June 1.
So what: The federal cyber-policy angle is unusually rich right now, and it’s where my federal and FedRAMP background gives me a lens few others in the industry can offer.