CVE Tools

We've got one word for it, and it's usually the wrong one

Cisco TalosBy Joe Marshall

Reported exploitedMicrosoft DefenderUAT-10820WebDAV

Our summary

Cisco Talos has identified an active infection chain abusing WebDAV protocols, attributed to the Russian threat actor UAT-10820, which successfully compromised a Ukrainian government entity. The campaign deploys the Amatera information stealer along with secondary payloads, including ZigCryptoStealer and the NetSupport Manager remote access tool, to establish persistent control and exfiltrate credentials. Simultaneously, the security landscape has tightened with the release of a "ShieldCrash" zero-day exploit that grants SYSTEM-level access to Microsoft Defender, appearing shortly after the September 2026 Patch Tuesday updates were distributed.

Read at Cisco Talos

Cisco Talos publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store