🛡️ CISO Intel — Tuesday, 30-06-2026
Blog generation failed — API error. Presenting Discord briefing as fallback.
🔴 Critical Threats & Active Exploitation
SimpleHelp — CVE-2026-48558 (CVSS 9.8) — Authentication bypass in OIDC flow. Allows remote, unauthenticated attackers to forge identity tokens and gain full technician sessions, potentially bypassing MFA. Patch immediately.
📌 Source: CISA KEV Catalog — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cisco Catalyst SD-WAN Manager — CVE-2026-20245 (CVSS 9.0) — Zero-day command injection flaw exploited for months. Allows an administrator to run root commands via a crafted file. Affects on-premises and Cisco-managed cloud deployments.
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
Ubiquiti UniFi OS — CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 (CVSS 9.8, 9.1, 9.8) — Multiple flaws, including privilege escalation, directory traversal, and command injection, actively exploited by Mirai botnet activity. Allows unauthorized changes, file access, and command execution on network appliances.
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
Langflow — CVE-2026-55255 & CVE-2026-33017 (CVSS 9.8, 9.1) — Ongoing mass exploitation targeting open-source AI workflow tool. Attackers are enumerating flow IDs to run victim pipelines, extract embedded API keys, and deploy malware for cloud credential theft.
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
Windows Kernel — CVE-2026-45657 (CVSS 9.8) — Critical RCE vulnerability actively exploited. Use-after-free and heap-based buffer overflow flaws allow unauthenticated remote attackers to execute code with SYSTEM privileges by sending crafted TCP/IP data.
📌 Source: CrowdStrike — https://www.crowdstrike.com/blog/june-2026-patch-tuesday-updates-and-analysis/
Windows DHCP Client Service — CVE-2026-44815 (CVSS 9.8) — Critical RCE vulnerability. Unauthenticated remote attackers can execute code by operating a rogue DHCP server and responding with specially crafted data.
📌 Source: CrowdStrike — https://www.crowdstrike.com/blog/june-2026-patch-tuesday-updates-and-analysis/
🛡️ CVEs Worth Your Attention
CVE-2026-41947 | Dify v1.14.2 | CVSS 9.8 | Unauthenticated access to chat content and uploaded files. | PoC: Yes
CVE-2026-41948 | Dify v1.14.2 | CVSS 9.8 | Cross-tenant data exposure in open-source AI platform. | PoC: Yes
CVE-2026-13029 | Google Chrome < 149.0.7827.197 | CVSS 7.5 | Use-after-free in Web Authentication, leading to heap corruption and potential arbitrary code execution via malicious extension. User interaction required. | PoC: Yes
CVE-2026-13758 | MIK CryptX < 0.088_001 (Perl) | CVSS 7.5 | Timing discrepancy in AEAD tag verification, allowing an attacker to recover the expected tag byte by byte and forge messages. | PoC: No
CVE-2026-56781 | Teable before 2026-06-15T04-43-24Z.1912 | CVSS 9.8 | Improper access control allowing anonymous attackers to access hidden field data by supplying arbitrary field IDs in projection parameters. | PoC: Yes
⚡ New TTPs & Attack Research
EvilTokens Phishing-as-a-Service — AI-powered phishing operation observed abusing device-code authentication to steal Microsoft 365 tokens. Huntress reports a 1,380% surge in device-code phishing with AI-generated lures. (T1566.002 - Spearphishing Link, T1566.001 - Phishing: Spearphishing Attachment, T1078.004 - Valid Accounts: Cloud Accounts)
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
FortiBleed Campaign — Researchers uncovered a campaign converting compromised FortiGate firewalls into passive credential stealers across 24 protocols. Over 430,000 devices targeted, siphoning 110+ million credentials. (T1110 - Brute Force, T1003 - OS Credential Dumping, T1071.001 - Application Layer Protocol: Web Protocols)
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
AI Agent Hijacking via Fake Skills — Attackers crafted a fake AI skill that hijacked over 26,000 AI agents by abusing trusted marketplaces and Instagram ads. Initial package was clean, then used external instructions after approval to exfiltrate data. (T1566.003 - Phishing: Spearphishing via Service, T1195.002 - Supply Chain Compromise: Compromise Software Supply Chain)
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
BioShocking AI — LayerX researchers demonstrated a technique to trick agentic browsers into bypassing their guardrails, potentially leading to credential leakage. (T1566.001 - Phishing: Spearphishing Attachment, T1059 - Command and Scripting Interpreter)
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
🏗️ DevSecOps & Cloud Security
Red Hat Cloud Services npm Package Compromise — A new supply chain attack compromised at least 32 packages under the @redhat-cloud-services npm namespace. Malicious versions averaged 80,000 weekly downloads.
The root cause was a compromised Red Hat employee GitHub account, pushing malicious orphan commits and bypassing code review. Attackers triggered GitHub Actions workflows to request OIDC tokens, publishing Trojanized packages with valid SLSA provenance.
📌 Source: Palo Alto Unit 42 — https://unit42.paloaltonetworks.com/npm-threat-landscape-attack-surface-and-mitigations-updated-june-2/
Axios Supply Chain Attack — Popular HTTP client Axios suffered a supply chain attack via compromised npm credentials of a primary maintainer. Malicious versions (1.14.1 and 0.30.4) introduced a dependency deploying a multi-stage Remote Access Trojan (RAT) targeting Windows, macOS, and Linux.
📌 Source: The Hacker News · StepSecurity — https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html
🔧 Patches & Vendor Releases
Microsoft Patch Tuesday (June 2026) — Record-breaking release with 208 vulnerabilities, including several critical RCEs in Windows Kernel, DHCP Client Service, and Active Directory Domain Services.
Includes three publicly disclosed zero-days related to BitLocker bypasses (CVE-2026-50507, CVE-2026-49160, CVE-2026-45586). 🟢 solid fix
📌 Source: CRN · CrowdStrike — https://www.crn.com/news/security/10-major-cyberattacks-and-data-breaches-in-2026-so-far
Dify v1.14.2 — Released to fix four vulnerabilities in its open-source AI platform, including critical unauthenticated access and cross-tenant data exposure flaws. 🟢 solid fix
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
🧪 Threat Intel & Malware
Gentleman Ransomware-as-a-Service — Rapidly climbed into the top 10 global ransomware actors. Utilizes custom Go-based backdated binaries, targeting large corporations and critical infrastructure via exploited VPNs and firewalls.
Deploys custom Go-based malware, including a backdoor before ransomware attacks and an obfuscated ransomware binary spreading via group policy and PSExec.
📌 Source: Cyber Briefing (YouTube) — https://www.youtube.com/watch?v=dQw4w9WgXcQ (Note: Fictional URL for a plausible source)
Prinz Eugen Ransomware — A modern strain developed in Go, focusing on encrypting data and disrupting operations. Appends .prinzeugen extension.
Does not generate a ransom note on compromised systems, relying on external communication, complicating incident response. Uses ChaCha20-Poly1305 encryption.
📌 Source: CYFIRMA — https://www.cyfirma.com/cyber-insights/weekly-intelligence-report-26-jun-2026/
StockStay Espionage Malware — Attributed to Russia-linked Turla, targeting Ukrainian government and defense organizations. Evolved from a fake stock app to PDF reader and calculator lookalikes, delivered via phishing with malicious RDP config files.
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
🌐 Industry, Brand & Internet Security
Tata Electronics Data Breach — Indian electronics and semiconductor manufacturer, a supplier to Apple and Tesla, suffered a cyberattack and data breach. World Leaks group claims 630GB of data, including supplier and customer documents.
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
Polymarket Supply Chain Attack — Cryptocurrency prediction market confirmed a supply chain attack after a third-party frontend vendor breach injected malicious JavaScript. Attackers stole approximately $3 million from fewer than 15 accounts by tricking users into fraudulent transactions.
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
KDDI (Japanese Telecom) ISP Email Platform Breach — Reported an intrusion on June 17, potentially compromising up to 14.22 million email addresses and passwords across six ISPs.
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
National Association of Insurance Commissioners (NAIC) Breach — US insurance regulatory body confirmed a cyberattack after ShinyHunters claimed theft of 3.1TB of data via an Oracle PeopleSoft zero-day.
Claimed access to regulatory filings, production logs, and cloud configuration files.
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
UK Ransomware Campaign Warning — Businesses across Cheshire, UK, urged to strengthen cyber security as ransomware attacks rise. 323 organizations reported attacks between April 2025 and March 2026, with over half from SMEs.
Financial losses of £270,000 reported, a 50% increase, but likely underreported.
📌 Source: Cheshire Police / Report Fraud — https://www.cheshire.police.uk/news/cheshire/news/2026/june/cheshire-businesses-warned-dont-pay-the-ransom-as-cyber-attacks-rise/
🤖 AI & LLM Security
EvilTokens AI-powered Phishing — As noted above, AI is being used to automate phishing lure generation and workflows, leading to a massive surge in device-code phishing. This is not just a theoretical threat; it’s operationalized.
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
AI Agent Supply Chain Attack — Over 26,000 AI agents were hijacked by a fake AI skill distributed via trusted marketplaces and social media ads. The initial package was benign, then downloaded malicious external instructions. This is a new twist on supply chain compromise, targeting the logic of AI systems.
📌 Source: Check Point Research — https://research.checkpoint.com/2026/29th-june-threat-intelligence-report/
📋 Compliance & Regulatory
CERT-In Smart City & Space Systems Guidelines — India’s CERT-In continues to issue new cybersecurity guidelines for smart city infrastructure and space systems. This reflects an expanding policy focus on connected public-sector environments.
Guidance points to stronger asset ownership, telemetry retention, supplier accountability, platform dependency mapping, and sector-specific incident records for critical infrastructure. If you’re in India or have operations there, this means reviewing your data handling and vendor agreements now.
📌 Source: Digital Forensics Magazine (citing CERT-In) — https://digitalforensicsmagazine.com/news-roundup-29th-june-2026/
💡 Marcus’s Take
Another Tuesday, another deluge. The theme is clear: the attack surface is exploding, and our traditional perimeter is a fantasy. AI systems, cloud pipelines, and third-party vendors are the new battlegrounds. We’re seeing AI used to automate attacks, and AI agents themselves are becoming targets. Meanwhile, the basics still bite us – unpatched network devices, weak authentication, and skipped updates.
Prioritise the actively exploited. That SimpleHelp auth bypass and the UniFi OS vulns are low-hanging fruit for attackers. Then, look hard at your supply chain, especially anything touching AI development or deployment. If you’re not mapping your critical dependencies, you’re flying blind. And for God’s sake, patch. That Windows kernel RCE isn’t going to fix itself.