Threat bulletins — Protectiva
Bulletins

Warnings, guidance and regulatory notes

What our analysts are picking up across Bulgarian and regional infrastructure, written for whoever has to decide what to do before Monday morning.

{{ shown }} · UPDATED WEEKLY
CRITICAL 04.09.2026 · WARNING WordPress core RCE chain, no login required — municipal sites exposed Two flaws chain together in core itself, not in a plugin, and produce remote code execution with no credentials involved. The exposure sits mostly on municipal portals left to run unattended. Patch first, then go looking for web shells — do not assume the patch alone cleared you. WORDPRESS · RCE · PUBLIC WEB HIGH 27.08.2026 · WARNING Credential replay at scale against internet-facing firewall VPN portals Old breach dumps are being fed back against administrative and SSL VPN interfaces in bulk. Treat any portal reachable from the internet without MFA as already enumerated by someone. FIREWALL · VPN · CREDENTIAL STUFFING REGULATORY 19.08.2026 · NOTE ZKS secondary rules: the incident classification changes landing this quarter The bar for a significant incident has moved down, and with it the moment your 24-hour early warning obligation starts running. How we read the change, and the four sentences worth adding to your internal procedure. ZKS · REPORTING · PUBLIC SECTOR HIGH 11.08.2026 · WARNING Hybrid Exchange misconfiguration lets phishing arrive as internal mail A common error in on-premises to cloud mail flow lets messages walk past SPF, DKIM and DMARC and land looking like trusted internal correspondence. Three settings worth checking today. EXCHANGE · EMAIL SPOOFING · PHISHING ADVISORY 30.07.2026 · GUIDANCE Twelve settings that protect Microsoft 365 admin accounts Most tenant takeovers we get called into would have failed against the same short list: separate admin identities, phishing-resistant MFA, conditional access baselines, mailbox audit retention. MICROSOFT 365 · IDENTITY · HARDENING CRITICAL 22.07.2026 · WARNING SMS campaign posing as state institutions hits citizens and staff alike Texts about unpaid fines or parking charges lead to payment pages good enough to work. Municipalities should post a warning on their own channels, because citizens go to verify with whichever institution they think sent it. SMISHING · CITIZEN FRAUD · BRAND ABUSE ADVISORY 15.07.2026 · GUIDANCE Log retention: what counts as long enough under NIS2 and ZKS Fourteen days is what we typically find, and it is not enough to reconstruct anything. What to collect, what to keep, and where the cost actually lands. SIEM · LOGGING · EVIDENCE REGULATORY 02.07.2026 · NOTE NIS2 supply-chain clauses: what to actually require from suppliers A short list of contractual terms — notification windows, evidence rights, sub-processor transparency — that meets the directive without making your procurement impossible to run. NIS2 · SUPPLY CHAIN · PROCUREMENT HIGH 24.06.2026 · WARNING Apache Tomcat flaw under exploitation days after the PoC went public On affected versions, specific but common configurations allow remote code execution or information disclosure. Sitting behind a reverse proxy does not make an internal application server safe here. TOMCAT · RCE · PATCH MANAGEMENT ADVISORY 10.06.2026 · GUIDANCE Tabletop template: hour zero to hour 24 of a ransomware incident Two hours with your management team on four questions: who declares the incident, who speaks to citizens or clients, who files the early warning, and what happens when the backup console is encrypted too. RANSOMWARE · TABLETOP · CONTINUITY

Our bulletins are advisory. Your obligations are not.

These notes record what we see and how we would respond to it. For national warnings and incident reporting the authoritative source is still CERT Bulgaria. Where something is an actual obligation on you, we say so in as many words.

Under attack right now? +359 2 495 0110 · 24/7 Already a client? Use the SOC escalation path in your runbook.