🔐 Security Pulse · 2026-09-29 16:00 UTC

⚡ TL;DR

Russian special services are confirmed responsible for a destructive fire targeting an Estonian military robotics firm, highlighting escalating hybrid threats in the Baltics. Multiple critical vulnerabilities disclosed in FreePBX IP PBX software pose ongoing cyber risk. Overall threat level elevated.

🔐 CYBER THREATS

  • 🔴🔴🔴 Russian special services executed an arson attack on an Estonian military robotics company’s building last month, indicating active sabotage against defense industry targets in Estonia [1].
  • 🔴 CVE-2026-54710 and CVE-2026-75600: Critical remote code execution and privilege escalation vulnerabilities affecting FreePBX IP PBX systems prior to versions 16.0.40, 17.0.7, and 17.0.9 risk compromise of VoIP infrastructure [2] [3].
  • 🟡 CVE-2026-101909 Axios HTTP client has a serialization flaw that could be exploited in browser and Node.js environments, affecting web applications from versions 0.28.0 to 0.34.0 and 1.15.1 to 1.20.0 [4].
  • 🟡 Multiple security flaws in Joomla extensions (Vehicle Manager, Real Estate Manager, Book Library) including unauthenticated SQL injection and reflected XSS may impact websites using versions prior to their latest patches [5] [6] [7] [8] [9].
  • 🟡 Several vulnerabilities in DeepSeek AI's harness component and supporting libraries could permit code execution or privilege abuse prior to their latest releases 0.1.0-rc7 through 0.1.7-rc2 [10].
  • 🟢 CISAgov advance physical security partnership supporting critical infrastructure at major religious facilities to bolster protection against physical threats.

🛡️ NATIONAL SECURITY

  • 🟡 Russian state aggression extends into hybrid warfare with sabotage targeting Estonia’s military innovation sector, signaling persistent Kremlin covert operations in the Baltics [1].
  • 🟡 U.S. forces scheduled to fully withdraw from Iraq imminently; Iran and allies celebrate this as a strategic victory, potentially reshaping regional power balances.
  • 🟡 France adapts artillery tactics based on drone warfare lessons from Ukraine conflict, indicating evolving battlefield doctrine in European military forces.
  • 🟢 Australia and New Zealand formalize integrated naval cooperation under “Plan Tasman,” enhancing regional maritime security collaboration.
  • 🟢 Russia announces a 27% defense budget increase for 2027 to $202 billion, underscoring Kremlin’s military expansion and potential intensification of strategic competition.

⚠️ RISK FLAGS

  • ⚠️⚠️⚠️ FreePBX RCE and authenticated access flaws are critical and exploitable in widely deployed telephony infrastructure—urgent patching required to mitigate potential compromise of communications in enterprises and governments [2] [3].
  • ⚠️⚠️ Russian covert sabotage of Estonian defense sector assets is an active threat with physical and economic implications; vigilance and enhanced protective measures needed for sensitive military R&D facilities [1].

🧭 THREAT MOOD

Elevated 🟡

Active hybrid operations and critical vulnerabilities in key infrastructure software require focused cyber hygiene and vigilant national security posture adjustments.

📎 Sources

  1. Russian special services were behind the fire at a building us… — @defense_news
  2. CVE-2026-54710 FreePBX is an open source IP PBX. Prior to vers… — @CVEnew
  3. CVE-2026-75600 FreePBX is an open source IP PBX. Prior to vers… — @CVEnew
  4. CVE-2026-101909 Axios is a promise-based HTTP client for the b… — @CVEnew
  5. CVE-2026-101108 Joomla Extension - https://t.co/gkuPXgJVxm - U… — @CVEnew
  6. CVE-2026-100752 Joomla Extension - https://t.co/gkuPXgJVxm - U… — @CVEnew
  7. CVE-2026-101110 Joomla Extension - https://t.co/gkuPXgJVxm - U… — @CVEnew
  8. CVE-2026-101109 Joomla Extension - https://t.co/gkuPXgJVxm - R… — @CVEnew
  9. CVE-2026-101111 Joomla Extension - https://t.co/gkuPXgJVxm - R… — @CVEnew
  10. CVE-2026-101102 A vulnerability was found in deepseek-ai deeps… — @CVEnew

Educational & informational only — not financial advice. Markets carry risk; do your own research.
Serial 20260929-16-v85 · 2026-09-29 16:00 UTC · pulse.uzylab.com