Show notes
This episode of Prime Cyber Insights analyzes the sophisticated exploitation of Cisco Catalyst SD-WAN zero-days and the increasing targeting of edge infrastructure and European industrial sectors. We detail new Mandiant findings on CVE-2026-20245, a privilege escalation flaw used to gain root-level control via malicious CSV uploads and rogue peering connections as early as March 2026. The briefing also covers the supply chain breach at LastPass through the third-party tool Klue, where the Icarus extortion group exploited OAuth tokens to access sales-related records. We examine Unit 42’s discovery of malicious 'skills' on the OpenClaw marketplace, ClawHub, which deliver infostealers to developer environments. Finally, the show reviews the sharp rise in ransomware activity across Europe, which saw a 55 percent increase in the first four months of 2026, and ASIO’s warning regarding nation-state actors mapping Australian critical infrastructure for future sabotage. This briefing provides practitioners with technical context on anti-forensic techniques and the shift toward targeting devices lacking native EDR support.



