Confidential · 24 Jun 2026
🛡️ Daily Cybersecurity Briefing — 2026-06-24 (Wednesday)¶
Window: last 24–48h. Severity: 🔴 CRITICAL · 🟡 HIGH · 🟢 MEDIUM.
Threat level HIGHVictims L30D 209Top actor QilinM&A L30D $720M
💼 M&A ACTIVITY¶
No new deals announced June 24.June 2026 monthly roundup has not yet published (month still open). Most recent named deal remains Cisco→WideField Security (Jun, undisclosed; identity-lifecycle security for Splunk Agentic SOC).
L30D summary (May 25 – Jun 24):3 named deals tracked; ~$4.22B+ in disclosed value.
Biggest🔴 Accenture→Dragos (majority) + runZero + NetRise — ~$4.17B (Jun 18); ~$208M ARR, +53% YoY; closes Aug–Sep. OT security software at enterprise scale. SecurityWeek
Cisco→WideField Securityundisclosed (Jun); identity/credential telemetry for agentic SOC. SecurityWeek
Cyera→Genie Security~$50M (May 24); endpoint DLP preventing genAI data leakage; Cyera's fifth acquisition. CTech
ThemeOT/ICS software consolidation + identity as the agentic SOC binding layer. Platforms buying depth, not adjacencies.
⚠️ CRITICAL BREACHES & INCIDENTS¶
London Hydro data breach — Canadian electricity utility, 160,000 customers affectedHighLondon Hydro, an Ontario-based utility, disclosed that an attacker exploited a vulnerability in a customer account on or around June 18 to access account information for other customers. The utility's CEO became aware of the suspicious activity June 18; impacted customers were notified June 20. Data exposed: names, addresses, email addresses, phone numbers, account and billing numbers, service addresses, pricing plans, contract start dates, and meter information. Financial data (banking, payment cards, government IDs, dates of birth) were not involved. No ransomware group has claimed the attack; the full scope of exfiltration, attack method, and affected customer count remain under investigation by local law enforcement. The exposed data is sufficient for convincing phishing and fake-billing fraud campaigns. SecurityWeek · CTV News · SC Media
ShinyHunters breaches Council of Europe — 297 GB HR/payroll data published, 10,000+ employees exposedCriticalShinyHunters publicly claimed the Council of Europe on June 14, 2026, setting a June 16 negotiation deadline; the intergovernmental body did not respond, and the group published 297 GB of data after the deadline. Content: 409,000+ payslips (2011–2026), 3,700+ in-house personnel files, 14,000+ CVs, and wide-ranging employee personal and financial records including names, dates of birth, home addresses, phone numbers, employee IDs, salaries, bank account details, tax and Social Security information, and medical records for 10,000+ staff. Claimed attack vector: Oracle PeopleSoft CVE-2026-35273 (the same vulnerability ShinyHunters claims to have used against 100+ organisations). The Council of Europe stated it is "investigating the matter" and has made no further comment. Not yet confirmed as a confirmed breach by independent forensics; treat payslip/HR content as potentially authentic pending Council verification. SecurityWeek · BleepingComputer · Cybernews · UpGuard
Texas Parks & Wildlife licensing vendor breach — 3,087,721 Texans exposed; driver's license and passport numbers, contact dataHighTexas Parks & Wildlife Department (TPWD) publicly disclosed June 18 that a third-party vendor managing its hunting and fishing license sales system suffered a breach, exposing the records of 3,087,721 customers. Exposed data: driver's license numbers, passport numbers (where provided), email addresses, phone numbers, and residential addresses. TPWD and Texas Cyber Command detected unauthorized access on May 13, 2026; formal breach notification was published June 12; public disclosure June 18. Not confirmed: Social Security numbers, dates of birth, and payment-card data were not in the affected system. Attribution: threat intelligence firm Brinztech reported in May 2026 that an actor using the handle "Wikkid" was selling an alleged TPWD dataset of 3.19M+ records (including SSNs and DOBs — figures TPWD disputes) on dark web forums; the same actor has been linked to a similar breach at Virginia's Department of Wildlife Resources, suggesting a targeted campaign against state wildlife licensing platforms that share common vendor software. The vendor's identity has not been publicly disclosed; no ransomware group has claimed the breach. Affected individuals are offered one year of free credit monitoring via Kroll (enrollment deadline September 14, 2026). SecurityWeek · SecurityAffairs · TechTimes
Fortinet formally responds to FortiBleed — old credentials, three prior CVEs, no new zero-dayHighFortinet's PSIRT issued an official response clarifying that the FortiBleed credential-harvesting campaign (430,000 firewalls, 110M credentials) does not exploit a new vulnerability. Fortinet says actors are reusing credentials from three prior incidents: CVE-2026-24858 (patched January 2026) and CVE-2025-59718 / CVE-2025-59719 (patched December 2025) — all FortiCloud SSO login authentication bypass defects. The structural risk is unchanged: any FortiGate device that has not fully rotated credentials post-patching and did not enforce MFA remains exposed. CISA's June 18 hardening guidance remains operative. SecurityWeek · CISA
🔓 CRITICAL VULNERABILITIES¶
CISA KEV update — 4 new entries added June 23 (not previously captured in this briefing).See dedicated bullet below. Additional outstanding deadlines: CVE-2026-20262 (Cisco Catalyst SD-WAN Manager, deadline June 29 — five days remaining) and CVE-2026-20253 (Splunk Enterprise, CVSS 9.8; deadline June 21, now 3 days overdue — BOD 26-04 escalation required for non-compliant federal agencies). CISA KEV
CVE-2026-20253 · Splunk Enterprise · CVSS 9.8 · Unauthenticated RCE — 3 days past federal deadline, actively exploitedCritical(Patched June 10; CISA KEV added June 18; not previously captured as a standalone bullet.) A critical flaw in the Splunk Enterprise PostgreSQL sidecar service allows an unauthenticated attacker to create or truncate arbitrary files via a misconfigured endpoint. Two days after Splunk's June 10 patch release, WatchTowr demonstrated a full remote code execution chain using the file-truncation primitive — pointing it at Splunk's main service initialization file to force a restart in a degraded state that then executes attacker-controlled commands as the Splunk OS user. Proof-of-concept code is public. Splunk confirmed active exploitation on June 18, the same day CISA added CVE-2026-20253 to the KEV with a June 21 federal remediation deadline under BOD 26-04. That deadline is now three days overdue as of June 24; non-compliant federal agencies must trigger BOD escalation procedures. Affected versions: Splunk Enterprise 10.2 before 10.2.4 and 10.0 before 10.0.7. Splunk is the dominant SIEM and observability platform across US federal and Fortune 500 environments — a compromised Splunk instance yields full visibility into an organization's security telemetry and log pipeline, enabling an attacker to suppress alerts, manipulate detections, and pivot to downstream systems. SecurityWeek · BleepingComputer · Help Net Security · Rescana
KEV deadline JUNE 26 (2 DAYS REMAINING) — CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 · Ubiquiti UniFi OS (CVSS 10.0 each) + CVE-2025-67038 · Lantronix EDS5000 (CVSS 9.8) — 4 flaws added June 23CriticalCISA added four actively exploited vulnerabilities on June 23, 2026, with a June 26 remediation deadline under BOD 26-04. Three affect Ubiquiti UniFi OS at CVSS 10.0 each — the maximum severity score — and chain for full device compromise from an unauthenticated network position: CVE-2026-34908 (improper access control: unauthorized system configuration changes), CVE-2026-34909 (path traversal: read or manipulate system files), CVE-2026-34910 (command injection: arbitrary command execution). Chaining these three gives an unauthenticated attacker on the same network segment root-level control over any reachable UniFi controller or gateway. CVE-2025-67038 (Lantronix EDS5000, CVSS 9.8) is an unauthenticated OS command injection flaw in the HTTP RPC module — the username parameter is concatenated into a shell command without sanitization, enabling root-level code execution with no credentials required; upgrade to EDS5000 v2.2.0.0R1. UniFi devices are the dominant enterprise and SMB Wi-Fi management platform; Lantronix EDS serial-to-Ethernet converters are common in OT and ICS environments. Effective remediation deadline for US federal agencies is June 26 (two days remaining). CISA KEV · CyberSecurityNews · SC Media · WindowsNews
CVE-2026-35273 · Oracle PeopleSoft · ShinyHunters' 100+ victim campaignHighShinyHunters claims CVE-2026-35273 as the access vector for the Council of Europe breach and describes it as the same vulnerability used against 100+ organisations in an ongoing campaign. This Oracle PeopleSoft flaw was first patched in the June 2026 Oracle CPU (June 17-18); any internet-exposed PeopleSoft instance not yet on that patch level is at active risk. Organisations using PeopleSoft for HR/payroll (the Council of Europe's apparent exposure) face the highest data-exfiltration risk given the sensitivity of that data. SecurityWeek · Oracle June 2026 CPU
KEV deadline JUNE 29 — CVE-2026-20262 · Cisco Catalyst SD-WAN ManagerCriticalFive days remaining for federal agencies to remediate this path-traversal flaw (CVSS 6.5; authenticated write → arbitrary file creation → root escalation). No workarounds; upgrade required. Eighth Cisco SD-WAN CVE confirmed exploited in 2026. CISA · SecurityWeek
CVE-2026-55200 · libssh2 ≤1.11.1 · CVSS 9.2 · No official patch — unauthenticated RCE in widely embedded SSH libraryCriticalSecurity researcher Tristan Madani disclosed a critical integer overflow in `ssh2_transport_read()` (transport.c); insufficient validation of `packet_length` allows an unauthenticated remote attacker to trigger an out-of-bounds write and achieve remote code execution via crafted SSH packets (CWE-680). CVSS v4 attributes low attack complexity and no user interaction — making exploitation straightforward wherever libssh2 is statically linked in automated services, embedded systems, or back-end SSH clients. No official release is yet available; a patch commit (7acf3df) exists but is not packaged. Mitigate now by restricting SSH access to trusted hosts and monitoring for anomalous SSH traffic. A companion flaw, CVE-2026-55199 (CVSS 8.2, DoS), is present in the same codebase. GBHackers · Cybernews · Cyber Kendra
CVE-2026-39813 + CVE-2026-39808 · Fortinet FortiSandbox · CVSS 9.1 each · Unauthenticated RCE and auth bypass, actively exploitedCriticalTwo critical FortiSandbox vulnerabilities disclosed April 14, 2026 and patched then, with a third (CVE-2026-25089) patched June 9, are now under active exploitation. CVE-2026-39813 is a path traversal in the FortiSandbox JRPC API enabling unauthenticated authentication bypass via crafted HTTP requests. CVE-2026-39808 is an OS command injection vulnerability enabling unauthenticated remote code execution via crafted HTTP requests. Exploitation attempts across all three flaws were observed June 15-16, originating from multiple sources (not a single campaign). FortiSandbox is Fortinet's sandboxing/malware-analysis appliance deployed in-network; compromise yields analysis-evasion capability and potential lateral access to monitored environments. Organizations running FortiSandbox must update to 4.4.9+ or 5.0.6+. BleepingComputer · The Hacker News · Help Net Security · Qualys
CVE-2026-50751 · Check Point VPN · CVSS 9.3 · Actively exploited by Qilin ransomware affiliatesCritical(Disclosed June 8; not previously captured.) A logic flaw in certificate validation for the deprecated IKEv1 key exchange protocol allows an unauthenticated attacker to establish a VPN session without a valid password, bypassing authentication entirely. Affects Check Point Remote Access VPN and Mobile Access blades, including Spark SMB firewalls. Attacks began May 7 and surged in early June 2026; at least one incident is attributed with medium confidence to a Qilin ransomware affiliate (Tox protocol C2 + Rclone data exfiltration observed post-exploitation). A "few dozen" confirmed victims to date. Emergency hotfixes are available from Check Point; apply without waiting for a regular patch cycle. SecurityWeek · Rapid7 ETR · Help Net Security
CVE-2026-44748 · SAP NetWeaver AS ABAP · CVSS 9.9 · Full authentication bypass via SAML XML Signature WrappingCritical(SAP June 2026 Patch Day, June 11; not previously captured.) An XML Signature Wrapping vulnerability in SAP NetWeaver Application Server ABAP's SAML authentication implementation allows an unauthenticated attacker to bypass authentication entirely and gain access to SAP ERP environments with no valid credentials. CVSS 9.9 — the highest SAP severity rating in this patch cycle, with no authentication or user interaction required over the network. SAP Security Note 3746332. A companion critical flaw, CVE-2026-40128 (SAP NetWeaver Java Web Container, CVSS 9.0, path traversal allowing file read/write or DoS via malicious HTTP login requests, SAP Note 3727078), was patched in the same cycle. SAP NetWeaver is the integration and application layer for SAP S/4HANA, SAP ECC, and SAP Business Suite — internet-exposed instances in large enterprises and government agencies are the primary risk. Both CVEs require immediate patching; no workarounds are available for CVE-2026-44748. SOCRadar · Onapsis · BleepingComputer
CVE-2026-10735 / CVE-2026-49777 · ShapedPlugin WordPress premium plugins · CVSS 9.8 / 10.0 · Supply chain attack backdoors 400,000+ WordPress sitesCritical(Disclosed June 22; not previously captured.) Attackers compromised ShapedPlugin's Easy Digital Downloads (EDD) build pipeline on May 21, 2026, injecting a persistent backdoor loader into three premium WordPress plugins: Product Slider Pro for WooCommerce (before 3.5.4), Real Testimonials Pro (3.2.5), and Smart Post Show Pro (before 4.0.2). Customer reports surfaced June 10; Wordfence confirmed the breach June 12; ShapedPlugin acknowledged June 16; Wordfence published full disclosure June 22. The backdoor loader activates on every WordPress admin page, fetches a remote payload from 194.76.217[.]28:2871, installs itself as a hidden fake plugin, and self-erases to cover tracks. Capabilities: WordPress/database/SMTP credential theft, 2FA secret exfiltration (targeting WP 2FA, Wordfence Login Security, Really Simple SSL 2FA), REST API backdoor for arbitrary file writes, Tiny File Manager and Adminer for GUI file/database access, and a URL-parameter webshell. Full site takeover is achievable. CVE-2026-49777 (CVSS 10.0) covers Product Slider Pro; CVE-2026-10735 (CVSS 9.8) covers the broader incident. Clean versions now available: 3.5.4, 3.2.6, 4.0.2. Anyone who installed ShapedPlugin premium plugins between April and June 2026 should treat their site as potentially compromised: rotate all credentials, audit for `woocommerce-subscription` / `woocommerce-notification` hidden plugins, and regenerate 2FA secrets. Free WordPress.org versions are unaffected. The Hacker News · BleepingComputer · Wordfence
CVE-2026-41089 · Windows Netlogon · CVSS 9.8 · RCE on domain controllers — actively exploited in the wildCritical(Patched May 12, 2026; not previously captured in this briefing.) A stack-based buffer overflow in the Windows Netlogon service allows an unauthenticated network attacker to send a specially crafted packet to a domain controller and achieve SYSTEM-level remote code execution — full Active Directory domain compromise in a single unauthenticated step: create privileged accounts, dump credentials, and move laterally across every system that authenticates against that controller. Microsoft initially assessed exploitation as "less likely," but threat actors weaponised the flaw after May 12 and public proof-of-concept code is now available. Active exploitation in the wild was confirmed by the Centre for Cybersecurity Belgium (CCB) in early June; SecurityWeek flagged it again June 24 as attack volume continues to grow from multiple threat-actor clusters. Any Windows Server acting as a domain controller that has not been patched with Microsoft's May 2026 security update is at immediate risk. Apply KB updates from Patch Tuesday May 2026 without delay; treat unpatched domain controllers as potentially compromised and audit privileged account creation since May. SecurityWeek · Help Net Security · MSRC · CCB
CVE-2026-20230 · Cisco Unified Communications Manager (CUCM) WebDialer · CVSS 8.6 → SIR Critical · SSRF → root file-write, actively exploitedHigh(Patched June 3, 2026; not previously captured in this briefing.) A server-side request forgery (SSRF) flaw in CUCM WebDialer — due to improper validation of HTTP request parameters — allows an unauthenticated remote attacker to send crafted HTTP requests that write arbitrary files to the underlying OS, which can then be used to escalate to root. Cisco released patches June 3 and simultaneously elevated the Security Impact Rating (SIR) to Critical beyond the CVSS 8.6 score because file-write primitives are the direct precursor to full root compromise. A public proof-of-concept was available at patch release. Active exploitation was observed over the weekend of June 21-22, 2026, originating from a single IP using `file://` URL payloads to create attacker-controlled files on target systems. Affected: CUCM 14.x before 14SU6 and 15.x before 15SU5. Mitigation: disable the WebDialer service immediately if patching is delayed (WebDialer is disabled by default but may be enabled in call-centre and directory-integrator deployments). CUCM is widely deployed in enterprise and government telephony environments. SecurityWeek · BleepingComputer · Cisco PSIRT
AutoJack · Microsoft AutoGen Studio · Localhost RCE via malicious webpage (dev builds only, now patched)Medium(Disclosed June 18; not previously captured.) Microsoft researchers identified and disclosed a chained exploit in AutoGen Studio's development branch, dubbed AutoJack, where a malicious webpage rendered by a local AI browsing agent can reach the AutoGen Studio localhost MCP WebSocket and execute arbitrary shell commands on the host — no credentials required. Three weaknesses are chained: an origin allowlist bypass (browsing agents running as localhost bypass checks), missing authentication on MCP endpoints, and unsafe parameter handling that passes attacker-controlled values to shell commands. Impact was contained: the vulnerable code never shipped in any PyPI release; only two pre-release builds (0.4.3.dev1, 0.4.3.dev2) exposed the handler. AutoJack is significant as a proof-of-concept for the attack class targeting AI agents with browsing capability and localhost services — a surface that expands with every new agentic deployment. As agentic AI moves from developer workstations to production, the architectural pattern (browser-capable agent + privileged localhost service) will become a standard target. The Hacker News · BleepingComputer · CSO Online
CVE-2026-50656 · Microsoft Defender · CVSS 7.8 · RoguePlanet zero-day grants SYSTEM privileges on fully patched Windows — no patch yetHigh(Published June 10, 2026; not previously captured in this briefing.) Security researcher "Chaotic Eclipse" (also known as "Nightmare Eclipse") published a proof-of-concept exploit for a race condition in Microsoft Defender's file-processing workflow, designated RoguePlanet. The flaw is a Time-of-Check to Time-of-Use (TOCTOU) issue inside the Microsoft Malware Protection Engine: Defender checks a file path during a scan, then reopens it for analysis under the SYSTEM account. Between those two actions, the PoC replaces the file with a malicious payload that executes at SYSTEM level — full privilege escalation from a local user account on an otherwise fully patched machine. Affects Windows 10 and Windows 11 with the June 2026 Patch Tuesday updates applied; does not function on Windows Server in current form. Microsoft confirmed the vulnerability and states a patch is in development; no patch available at the time of this briefing. No in-the-wild exploitation observed. Disabling Defender real-time protection is not a mitigation: the PoC works regardless of Defender protection state. RoguePlanet is part of a series of Windows zero-days released by the same researcher in an ongoing dispute with Microsoft over disclosure and bug bounty practices; prior releases include BlueHammer (CVE-2026-33825), UnDefend (CVE-2026-45498), and RedSun (CVE-2026-41091). Severity flagged HIGH rather than CRITICAL because exploitation requires local access and no exploitation in the wild is confirmed. SecurityWeek · The Hacker News · Help Net Security · BleepingComputer
Cordyceps · GitHub Actions CI/CD · No CVE · 300+ repositories fully exploitable at Microsoft, Google, Apache, Cloudflare — supply chain pipeline hijacking by any free-account user (June 23 disclosure)HighNovee Security researcher Elad Meged published findings from a scan of ~30,000 high-impact open-source repositories: 654 flagged, 300+ confirmed fully exploitable. Cordyceps is a class of GitHub Actions YAML misconfigurations — command injection, broken authentication, artifact poisoning chains, and privilege escalation — exploitable by any actor with a free GitHub account (no organisation membership required). Demonstrated impacts in named repositories: (1) Microsoft Azure Sentinel — a comment on a pull request was sufficient to steal a non-expiring GitHub App key; (2) Google AI Agent Development Kit — a single pull request could grant an attacker Google Cloud's highest IAM role; (3) Cloudflare Workers SDK — unauthorized command execution and login credential theft; (4) Apache Doris — automation token exfiltration; (5) Black (Python Software Foundation, 130M downloads/month) — full CI/CD pipeline takeover. All named projects were notified and fixed before disclosure. The structural risk is uncontained: AI coding agents generate GitHub Actions YAML at scale while reproducing the same insecure patterns, meaning the attack surface expands with every AI-generated workflow file. Millions of repositories are potentially affected by this pattern. No CVE assigned — the flaw spans a configuration pattern, not a single vendor product. Review your own GitHub Actions workflows for `pull_request_target` triggers accepting untrusted input, unconstrained `permissions`, and unvalidated artifact references. The Hacker News · SecurityWeek · Novee Security · Dark Reading
CVE-2026-41948 / CVE-2026-41947 · Dify AI Platform · CVSS 9.4 / 9.1 · DifyTap: unauthenticated internal API access and cross-tenant AI chat exfiltration (June 22 disclosure)CriticalZafran Security disclosed four vulnerabilities in Dify, the open-source agentic workflow platform powering 1 million+ applications with 146,000+ GitHub stars. The two critical flaws: CVE-2026-41948 (CVSS 9.4) is an unauthenticated path traversal in the plugin icon endpoint — the `filename` parameter is injected unsanitised into an internal URL, giving any unauthenticated attacker traversal access to Dify's Plugin Daemon API and the ability to trigger cross-tenant internal API calls. CVE-2026-41947 (CVSS 9.1) allows any standard user to configure malicious tracing on any public application ID, creating a persistent exfiltration channel that silently captures all future AI conversations across tenant boundaries — "wiretapping" other customers' AI chat histories without detection. Two companion flaws — CVE-2026-41949 and CVE-2026-41950 (CVSS 6.5 each) — add unauthorized document preview and cross-user file access within tenants. Patched in Dify v1.14.2 for CVE-2026-41947, -41949, and -41950; CVE-2026-41948 has a fix merged on GitHub but not yet in a formal release — deploy WAF rules on the plugin icon endpoint until the full patch ships. No known active exploitation at disclosure. Dify is widely used in enterprise agentic deployments and in multi-tenant SaaS AI products; the cross-tenant scope means a single compromised account can exfiltrate conversations from unrelated customers on the same platform. The Hacker News · SecurityWeek · Dark Reading · Zafran
🚨 INTELLIGENCE AGENCY ALERTS & POLICY¶
Trump signs Executive Order on Post-Quantum Cryptography — 2030/2031 migration deadlinesCriticalPresident Trump signed "Securing the Nation Against Advanced Cryptographic Attacks" (June 22, 2026). Key mandates: federal agencies must inventory high-value assets and transition to PQC for key establishment by December 31, 2030 and digital signatures by December 31, 2031. Each agency must designate a PQC migration lead. Commerce Department must launch a PQC pilot by December 31, 2027. The order explicitly cites "harvest now, decrypt later" (HNDL) — adversaries are currently exfiltrating encrypted data to decrypt once cryptographically relevant quantum computers arrive. OMB and the National Cyber Director lead implementation; NSA/DHS/Commerce provide guidance. The 2030 deadline gives the federal enterprise roughly four years to complete a migration that typically takes larger organizations six to eight years; the clock is running. White House · Cybersecurity Dive · SecurityWeek · CyberScoop
Algerian cybercrime marketplace operator extradited from Spain — "SPOX" charged with running Market0Day and Spoxy.usHighAbdellah Belmili, 26, (alias: SPOX, Dila Belmili) was arrested in Spain and extradited to the US in June 2026, facing up to 30 years in federal prison. Belmili operated market0day.com and spoxy.us: black-market platforms selling phishing kits, compromised server access, and financial credentials for Bitcoin only, active 2020–2023. FBI investigation began September 2020; ~595 phishing kits identified, ~5,600 victims globally, ~$900,000 in traced crypto proceeds. Spoxy specialised in phishing kits targeting US financial institutions. Extradition is a Joint DOJ/FBI operation enabled by Spanish law-enforcement cooperation. SecurityWeek · CyberScoop · SC Media
CISA BOD 26-04 reminderHighCVE-2026-20253 (Splunk Enterprise, CVSS 9.8) is now 3 days overdue as of June 24; non-compliant agencies must trigger the escalation procedures required by BOD 26-04. CVE-2026-28318 (SolarWinds Serv-U, deadline June 19) remains overdue. CISA BOD 26-04
Operation Endgame — StealC and Amadey infostealer infrastructure dismantled, 27M stolen credentials recovered, $47M crypto restricted (June 24)CriticalLaw enforcement from the Netherlands, Canada, the United States, and Germany, coordinated by Europol and Eurojust, executed a two-week disruption operation (June 15-19) against the infrastructure powering Amadey and StealC, two of the most widely deployed commodity malware families on Windows. Private-sector partners included Microsoft Digital Crimes Unit, Bitdefender, Bitsight, ESET, Proofpoint, and IBM X-Force. Results: 326 servers dismantled, 142 domains seized or neutralized, 27 million stolen login credentials recovered, $47 million in criminal cryptocurrency identified and restricted. Microsoft's AI analysis identified that despite being developed by separate criminal groups, Amadey and StealC shared infrastructure — enabling prosecutors to charge the operation under RICO (Racketeer Influenced and Corrupt Organizations Act) as a single criminal conspiracy, the first time RICO has been applied to link two distinct malware operations. Amadey functions as the loader (initial access), StealC as the stealer (credential and data monetization); the partnership enabled factory-style ransomware, fraud, and critical-infrastructure attacks at scale. The two malware families were linked to 140,000+ infected computers globally as of early May 2026; Microsoft identified and severed criminal control from 18,000+ victim devices. This is the latest phase of Operation Endgame, which began in 2024 targeting Emotet, IcedID, SystemBC, Pikabot, Smokeloader, and Bumblebee botnets. Help Net Security · The Hacker News · CyberScoop · Microsoft Security Blog
DraftKings credential-stuffing attacker sentenced — $1.8M forfeiture, 3 years supervised releaseMediumNathan Austad was sentenced June 24, 2026 for a credential-stuffing attack against DraftKings that exploited credentials sourced from third-party breaches to compromise customer sports-betting and fantasy accounts. Austad was ordered to pay approximately $1.8 million in forfeiture and restitution and will serve three years of supervised release. The case is the latest in a line of DOJ credential-stuffing prosecutions and reinforces that account takeover operations — even those using others' credentials rather than independently harvested data — carry multi-year sentencing exposure. SecurityWeek · CyberWebSpider
Canada's CSIS first-ever botnet neutralization via judicial threat-reduction warrant (June 15 public ruling)High(Disclosed June 15; not previously captured.) The Canadian Federal Court publicly released its previously sealed ruling on June 15, disclosing that the Canadian Security Intelligence Service obtained a judicial warrant from Justice Catherine Kane (originally granted May 1, 2024; renewed August 2024) authorizing CSIS operatives to enter, modify, and neutralize devices infected by two separate foreign-run botnets on Canadian soil. Targeted infrastructure: Canada-based servers, SOHO routers, and IoT devices (Ring doorbells, security cameras, Wi-Fi appliances). CSIS employed its "threat reduction warrant" provisions — which had existed in Canadian law for years but had never previously been applied in this manner — to alter, degrade, and destroy botnet data on infected machines without device-owner consent. This is the first known instance of a Western intelligence agency obtaining court authority to actively remediate malware on devices it does not own, setting a precedent for how democratic nations can counter foreign botnet infrastructure hosted domestically. The Hacker News · The Canadian Press
🌐 THREAT ACTOR & CAMPAIGN ACTIVITY¶
DLS activity — June 24 window:
DLS volume and named June 24 victimsHighransomware.live summary shows approximately 39+ new victim postings in the last 24h; Q2 volume at 1,803+. Named victims confirmed so far: Cash Canada (financial services/Canada — Qilin DLS), Alexandria (telecom — Nova DLS), LP Group (construction/real estate — Nova DLS), Miami Machine Inc. (manufacturing/US — Akira DLS), Transvill SRL (road transport/Peru — Nova DLS), and JIT-EX LLC (trucking-logistics/US — Akira DLS; ~40GB employee PII including SSNs, W-9 forms, passport copies, and driver's license documents). Qilin, The Gentlemen, and Akira remain the highest-cumulative-volume groups. ransomware.live · RedPacket Security · RedPacket Security · RedPacket Security
INC Ransom hits two US healthcare providers — 7TB claimed at Horizon Family Medical GroupCriticalTwo healthcare organizations newly confirmed on INC Ransom's DLS. Horizon Family Medical Group (Hudson Valley, New York — June 18 posting): INC Ransom claims 7 terabytes of data including patient medical records (diagnoses, prescriptions, treatments, lab results), SQL databases, and QuickBooks financial data; the group states it notified management, received no response, and plans to distribute data publicly. No Horizon public statement; treat as 🟥 unverified pending victim confirmation. Horizon Eye Care (June 23 posting): ophthalmology services provider (LASIK, cataract, contact lens, eyewear); data scope unconfirmed, no public victim statement. INC Ransom continues targeting US healthcare aggressively — seven confirmed US healthcare victims since June 17. DeXpose · RedPacket Security · ransomware.live
Lapsus$ claims AYA Bank (Myanmar) — full platform dump offered for sale (June 23)HighThe Lapsus$ extortion group posted AYA Bank, a Myanmar-based private retail and corporate bank, to its data leak site on June 23, claiming a full dump of the main banking platform including customer PII. Lapsus$ states it will sell the data if its ransom demands are not met; no ransom figure was specified. AYA Bank has not issued a public statement. Context: the "Lapsus$" brand operating in 2026 is tracked as part of a loosely affiliated cluster dubbed "Scattered Lapsus$ Hunters" (including individuals with ties to ShinyHunters and Scattered Spider), not necessarily the original 2021-2022 Lapsus$ core group that targeted NVIDIA, Samsung, and Microsoft. AYA Bank is one of Myanmar's largest private banks; the claimed scope could expose sensitive retail banking and correspondent banking records. 🟥 Treat as unverified pending corroboration. ransomware.live · RedPacket Security · HookPhish
The Gentlemen — GentleKiller EDR killer suite (ESET June 18):
GentleKiller: 400+ security processes disabled across 48 vendors — centrally developed and maintained for affiliatesCritical(Disclosed June 18; not previously in this briefing.) ESET published analysis of The Gentlemen's in-house BYOVD EDR-killer framework. GentleKiller has at least 8 variants, each abusing a different vulnerable or malicious driver, and is designed to terminate processes from CrowdStrike, SentinelOne, Microsoft Defender, Sophos, Palo Alto, Trend Micro, ESET, Bitdefender, Kaspersky, and McAfee/Trellix — 400+ tracked processes across 48 products. Three additional third-party killers (HexKiller, ThrottleBlood, HavocKiller) are operationally integrated. An affiliate-developed credential stealer, OxideHarvest, was also identified in the ecosystem. What distinguishes The Gentlemen is that operators centrally develop and maintain these evasion tools and distribute them to affiliates, unlike most RaaS groups that leave affiliates to source their own. This guarantees consistent EDR bypass capability across the entire affiliate base — raising the operational floor for every attack. ESET/WeLiveSecurity · Help Net Security · The Hacker News
ShinyHunters — escalating 2026 campaign (9+ confirmed victims, parallel attack chains: PeopleSoft CVE-2026-35273 + Salesforce vishing):
Charter Communications (Spectrum)Critical(attack April 1, disclosed May 26) — 40–42M records claimed (13M+ individually confirmed by independent analysis). ShinyHunters placed a single vishing call to a Charter employee on April 1, 2026, obtained their Microsoft Entra (Azure AD) credentials, and pivoted to Charter's Salesforce CRM. Data exfiltrated: customer names, email and physical addresses, phone numbers, subscription plan details, support tickets, and CPNI (Customer Proprietary Network Information). Charter disclosed publicly on May 26 — one day before ShinyHunters' May 27 ransom deadline — but refused to pay; 50 GB was published the following day. Charter disputes CPNI exfiltration; ShinyHunters provided screenshots contesting the claim. Access via Salesforce/Entra (not PeopleSoft CVE-2026-35273). Among the largest US telecom breaches on record. BleepingComputer · TechRadar · SC Media
Cushman & WakefieldHigh(attack May 1, data published May 7) — 500,000+ Salesforce records (310,400 accounts confirmed in HIBP); primarily business contact data: names, job titles, company addresses, phone numbers, email addresses. ShinyHunters used vishing to obtain Salesforce credentials from a C&W employee on May 1, published 50 GB after the May 6 ransom deadline passed. Qilin separately listed Cushman & Wakefield on its DLS May 4 — no confirmed partnership between the groups on this target; may reflect separate opportunistic access or intelligence sharing. Access via Salesforce (not PeopleSoft CVE-2026-35273). Cybernews · The Register · SOCRadar
Council of EuropeCritical(June 14 claim, June 16 data published) — 297 GB HR/payroll/personnel records for 10,000+ employees published after ransom deadline. Attack vector: Oracle PeopleSoft CVE-2026-35273. See Critical Breaches above. SecurityWeek
Instructure/CanvasCritical(attack April 25, disclosed May 1, ransom paid May 11) — 275 million users across 8,809 universities and institutions; largest educational data breach on record; ransom paid, FBI warning issued. Malwarebytes · Bitdefender
Madison Square Garden Sports Corp.Critical(breach June 5, data published June 16) — 45 GB published after the June 15 ransom deadline was ignored: 26 million customer and corporate records including facial recognition surveillance records and internal threat assessments. MSG's second major breach within six months; Cl0p hit MSG via Oracle eBusiness Suite in February 2026, exposing 131,070 employees. PeopleSoft CVE-2026-35273 is claimed vector for this incident too. The Next Web · DeXpose
KodakHigh(listed June 15, confirmed June 17) — ShinyHunters claimed 2.2M records (customer PII and internal corporate data) and set a June 18 deadline. Kodak confirmed "an unauthorized third party illegally gained temporary access to a limited amount of company data" and engaged cybersecurity experts and law enforcement. No proof samples published; no data dump confirmed. Cybernews · BleepingComputer
🟥 Sysco (listed June 15) — 61M Salesforce records claimed; no Sysco confirmation. Notably, Qilin ransomware separately targeted Sysco in a distinct prior incident — two different extortion actors targeting the same large food distributor. Treat as claimed only pending Sysco disclosure. Cybernews
BCD TravelHigh(data published June 2, 2026) — 396,313 customer email addresses and 700,000+ Salesforce records (30 GB+ compressed) published after a June 1 ransom deadline. BCD Travel is a Dutch corporate travel management company serving Fortune 500 clients globally. Access via direct Salesforce/SharePoint compromise — not the Oracle PeopleSoft CVE-2026-35273 vector — confirming ShinyHunters runs parallel attack chains across SaaS stacks. Cybernews · DutchNews.nl
University of NottinghamCritical(attack May 27–June 9; confirmed June 11, 2026) — 454,600+ student and alumni records confirmed stolen via Oracle PeopleSoft CVE-2026-35273; includes passport numbers, ethnicity and disability data, home addresses, and academic records. Among the most sensitive data profiles in any of the 100+ PeopleSoft victims — passport and ethnicity data create identity-fraud and discrimination risk beyond standard PII. BleepingComputer · The Register
Campaign scopeGoogle Threat Intelligence / Mandiant confirmed June 11 that ShinyHunters exploited CVE-2026-35273 (Oracle PeopleSoft, CVSS 9.8) to breach 100+ organisations across 300+ PeopleSoft instances between May 27 and June 9 alone. Access vector rotates between PeopleSoft, Salesforce integrations, SharePoint credential abuse, and vishing — targeting telecom, government, education, hospitality, entertainment, travel, real estate, and food distribution simultaneously. New permanent leak infrastructure vows stolen data will remain accessible via mirrors and torrents indefinitely. Google Cloud Blog · Cybersecurity Dive · Cybernews
AryStinger botnet — 4,300+ D-Link and QNAP routers hijacked as global proxy network:
AryStinger: end-of-life routers turned into a distributed reconnaissance and proxy networkHigh(Disclosed June 22; not previously captured.) A previously undocumented botnet named AryStinger has compromised 4,300+ D-Link (DIR-850L, DIR-818LW) and QNAP NAS devices by exploiting unpatched legacy vulnerabilities (CVE-2013-3307, CVE-2016-5681, CVE-2025-11837) on end-of-life hardware. Each infected router becomes an "Executor" — a remotely controlled node for network scanning, proxying, tunneling, DNS hijacking, and command execution. Geographic distribution: South Korea (48.5%), China (31.8%), Sweden (6.4%), Malaysia (3.5%), Singapore (2.5%). The botnet's primary purpose is reconnaissance-at-scale: the controller pushes parallel scanning jobs across Executors to map networks, identify vulnerable services, and stage downstream compromises. DNS tampering capability redirects victim browser traffic to phishing or malware pages. Attribution not yet established. First detected March 12, 2026; widely reported June 22. Owners of end-of-life D-Link or QNAP devices should audit for compromise and replace hardware — no vendor patches are available. Malwarebytes · The Hacker News · TechRadar
Icarus — Klue supply-chain victims reach 15 (3 new disclosures June 24):
BeyondTrust, 8×8, and Pendo confirm Klue Salesforce breach — 15 downstream victims now confirmedHighSecurityWeek reported June 24 that BeyondTrust (PAM/cybersecurity), 8×8 (communications technology), and Pendo (product analytics) have all disclosed impact from the Icarus actor's June 11-12 compromise of Klue's OAuth integrations. BeyondTrust was notified June 12 and disclosed via its Trust Center June 24; 8×8 and Pendo disclosed through SecurityWeek's rolling roundup. All three had Salesforce CRM data accessed — business contact information, sales account data, and support records. No threat intelligence, vault content, or engineering systems were affected at any of the 15 victims. The campaign now has 15 named downstream victims from a single Klue credential compromise: Huntress, Recorded Future, Tanium, Jamf, HackerOne, Snyk, Kudelski Security, Insurity, Gong, OneTrust, Sprout Social, LastPass, BeyondTrust, 8×8, and Pendo. Icarus began posting stolen data on a leak site June 22 and is applying incremental extortion pressure. Attribution: Icarus "mr bean" alias matched to Session Messenger ID from Huntress extortion comms (high confidence). SecurityWeek · SecurityWeek · BeyondTrust
FortiBleed attribution — Russian IAB "SantaAd" identified (June 23-24):
"SantaAd": Russian-speaking IAB behind FortiBleed — 1.16B credential attempts, multi-vendor scope confirmedHighSecurityWeek and The Hacker News published attribution analysis June 23-24 identifying the actor behind FortiBleed as a Russian-speaking initial access broker operating under the alias "SantaAd" on the Exploit forum. SantaAd initially advertised access to thousands of Fortinet devices at $30,000 and raised the price to $60,000 within hours of the campaign going public. Scale is larger than initially reported: the operation ran 1.16 billion credential-stuffing attempts against FortiGate devices and a separate 2.1 billion brute-force attempts against Microsoft SQL Server systems from February 28, 2026. Multi-vendor scope: not limited to Fortinet — Synology NAS, Sophos firewalls, Citrix SSL-VPN, and RDWeb portals were also targeted. The dataset includes confirmed Kerberos hash cracks and targeted exfiltration of DFS backup data from at least one NATO-aligned defense contractor — suggesting SantaAd may collaborate with or sell to Russian state-adjacent buyers beyond pure criminal ransomware groups. SecurityWeek · The Hacker News · SOCRadar
KongTuke IAB — Mistic backdoor analysis (Symantec June 24):
Mistic: new in-memory backdoor links KongTuke access broker to Qilin, Akira, Interlock, and four more ransomware groupsHighSymantec published analysis June 24 (via BleepingComputer) of a newly developed backdoor called Mistic, attributed with medium-high confidence to KongTuke (also tracked as Woodgnat), a financially motivated IAB active since at least 2024. KongTuke sells deep-enterprise access to ransomware affiliates; confirmed downstream buyers include Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta — making a Mistic-implanted network disproportionately likely to face a Tier-1 ransomware deployment weeks to months after initial compromise. Mistic profile: fully fileless (payloads execute in memory only; nothing written to disk), Beacon Object File (BOF) loader for modular in-memory capability extension (consistent with Cobalt Strike Beacon tradecraft), and a self-deletion kill switch for post-access trace removal. Delivery: social engineering over Microsoft Teams (ModeloRAT deployed first for initial access, Mistic planted for long-term persistence). Targeted sectors observed to date: insurance, education, IT, and professional services. No named organizational victims confirmed at publication. Defenders should correlate Teams anomaly alerts with process-injection telemetry. BleepingComputer · Security.com/Symantec
TA4922 — China-linked cybercrime group expanding to Europe and Africa (Proofpoint June 5):
TA4922: highest-volume cybercrime campaign actor now targeting UK, Germany, Italy, South Africa with AI-assisted malwareHighProofpoint published analysis June 5, 2026 of TA4922, a suspected Chinese-speaking financially motivated cybercrime group that currently runs more unique phishing campaigns than any other tracked actor in Proofpoint data. Geographic expansion to UK, Germany, Italy, and South Africa in March–April 2026, using localized lure themes (HR, payroll, tax forms, invoices) written in the victim's language. New malware arsenal: Atlas RAT (full-featured — reconnaissance, file exfiltration, keylogging, screen/audio/video capture, reboot/shutdown), SilentRunLoader (Python-based Chrome credential and cookie stealer; internal code artifacts — hardcoded placeholder "your_secret_key_here" — indicate AI-assisted development), RomulusLoader, and ValleyRAT (Chinese-nexus infrastructure also linked to the Kaspersky WhatsApp campaign reported June 23). TA4922 pivots victims from phishing email to WhatsApp, LINE, or Microsoft Teams for out-of-band social engineering. Financially motivated: data theft, fraud, access resale. No named organizational victims confirmed in reporting; no confirmed state-intelligence link, though the boundary is structurally ambiguous under China's 2017 National Intelligence Law. Proofpoint · The Hacker News · SecurityWeek
Leaderboard (unchanged — June monthly report pending):
Qilin #1 (546 YTD), The Gentlemen #2 (504 DLS total), Akira #3 (184 L3M). May total: 646. June report due when month completes.
New battle card: Interlock (#Tier 2) — see [actors/interlock.md](./actors/interlock.md). Double extortion, FreeBSD variant, CISA advisory AA25-203A, Cisco zero-day exploitation in 2026.
🌍 GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense · cyber · economics.
Trump's PQC deadline is a four-year sprint against a six-to-eight-year migration problem, and adversaries are already banking encrypted data.CriticalThe executive order's 2030/2031 federal PQC mandate is the first binding timeline for US agencies, but the "harvest now, decrypt later" threat the order explicitly cites is already operational: state actors (principally China's Salt Typhoon and affiliated programs) have been exfiltrating high-value encrypted communications and records since at least 2023. The gap between the 2030 deadline and current adversary data collection means any encrypted data exfiltrated now — classified communications, health records, financial transactions, diplomatic cable traffic — is held pending the quantum decryption window. CISOs should treat PQC migration not as a 2030 compliance exercise but as a 2026 triage decision: identify what you are exfiltrating-risk data and start the migration now.
ShinyHunters' breach of the Council of Europe is an attack on the institutional infrastructure of European human rights governance.CriticalThe Council of Europe is not an EU institution — it is the 47-nation body that enforces the European Convention on Human Rights, administers the European Court of Human Rights, and oversees anti-corruption (GRECO) and cybercrime (Budapest Convention) frameworks. Exfiltrating 15 years of HR/payroll data for 10,000+ civil servants exposes not just personal data but the financial and operational structure of an institution that foreign governments — including Russia (expelled March 2022) and China — have strong incentives to surveil. The claimed PeopleSoft vector, if confirmed, means the same access that opened the Council of Europe may have opened dozens of other intergovernmental bodies running the same platform.
The Fortinet response to FortiBleed reframes the scale of prior vulnerability management debt.HighFortinet's PSIRT confirms that three authentication bypass CVEs patched in December 2025 and January 2026 are the root cause of 430,000 compromised firewalls and 110 million harvested credentials. The lag between patch availability and credential rotation across an installed base of hundreds of thousands of devices is the operational gap that Russian-speaking actors filled. For executives managing distributed firewall estates: patch release closes the initial access vector, but does not remediate the access already established. Credential rotation and session invalidation are the actual remediation — and the FortiBleed timeline shows that at scale these lag the patch by months.
London Hydro is a template for low-sophistication utility sector attacks that scale through downstream fraud.HighThe exposed data set — account numbers, pricing plans, service addresses, meter readings — is the raw material for social-engineering campaigns ("your meter was identified for disconnection") and spear-phishing against 160,000 households. The utility sector's exposure is not primarily operational disruption; it is data harvesting that funds fraud networks. The absence of a claiming threat actor and the relatively narrow breach (no financial credentials exposed) is consistent with credential-sale operations rather than ransomware groups. Executives with utility or critical infrastructure portfolios should model the downstream fraud vector, not just the direct breach.
The Belmili/SPOX extradition demonstrates a durable US-Spain law enforcement channel for cybercrime prosecution.HighThe successful extradition of an Algerian national from Spain — six years after the FBI's investigation began — validates that the DOJ's long-horizon cybercrime prosecution strategy can reach actors operating in friendly but non-Five-Eyes jurisdictions. This is operationally relevant for criminal groups that treat European residency as insulation from US indictment: the Wynn Resorts/Canvas/Council of Europe ShinyHunters campaign members, The Gentlemen's identified administrator (Izhevsk, Russia — Russia's non-extradition is the constraint, not Spain's), and similar actors should note the precedent.
TA4922's European expansion connects Chinese cybercrime to PRC commercial intelligence structures — UK defense and finance now in-scope.HighProofpoint's June 5 analysis identifies TA4922 as the single highest-volume cybercrime campaign actor in their telemetry, now running localized HR/payroll/tax phishing operations in the UK, Germany, Italy, and South Africa alongside a prior East Asian base. The group's Atlas RAT (audio/video/keystroke capture capability) and AI-assisted SilentRunLoader (Chrome credential/cookie theft) combine enterprise access capability with LLM-assisted malware development — confirming that AI tooling is now standard tradecraft for Chinese-nexus actors, not just defenders. The ValleyRAT infrastructure overlap with the June 23 Kaspersky WhatsApp campaign suggests shared tooling or supply chains across multiple Chinese-nexus groups. Under China's 2017 National Intelligence Law, the distinction between financially motivated criminal exfiltration and state-directed intelligence collection is legally unresolvable for any Chinese-domiciled operator. UK defense contractors, financial services, and government supply-chain vendors are now active TA4922 targets and should treat localized HR/payroll/invoice impersonations as a current adversarial priority. Proofpoint · The Hacker News
Canada's CSIS botnet warrant sets a new template for offensive-defensive intelligence action against foreign cyber infrastructure.HighThe Federal Court ruling published June 15 confirms that CSIS used its threat-reduction warrant powers — provisions that existed on paper since the 2015 CSIS Act amendments but had never been exercised — to actively modify and destroy malware on devices it does not own on Canadian soil. The strategic signal is significant: Western intelligence services are no longer limited to passive observation of foreign botnet infrastructure hosted domestically. The warrant framework requires judicial oversight and is targeted at specific foreign threat actors, making it constitutionally defensible. For multi-portfolio executives: this is the first concrete instance of a democratic intelligence service crossing the line from "monitoring" to "active remediation" of adversary-controlled infrastructure — a precedent that the US, UK, and Australian equivalents are watching closely.
Iran signed the ceasefire on June 17; its hackers didn't — and the network access planted during the conflict does not expire with the truce.CriticalThe US-Israel-Iran military conflict (Operation Epic Fury / Operation Roaring Lion, February 28 – June 17, 2026) formally ended at the G7 Versailles summit, but the cyber front has not followed. In the final days of the kinetic phase, suspected US/Israeli offensive operations took down Iran's four largest state-linked banks — Melli, Saderat, Tejarat, and Tose Saderat — from June 13; the banks remained offline for nine-plus days. Hours after the June 17 signing, the leading IRGC-linked hacktivist coalition announced only a temporary "pause" on US targeting, explicitly reserving the right to resume "when the time is right." Security analysts are projecting an expansion — not a reduction — of cyber activity in the post-kinetic phase as both sides shift from battlefield operations to intelligence-gathering. The deeper structural risk is access already planted: Symantec/Broadcom disclosed in March that Seedworm (MuddyWater, a subordinate element of Iran's MOIS), active from February 2026, successfully backdoored a US bank, a US airport, US and Canadian NGOs, and the Israeli operations of a US defense-aerospace software company, deploying the Dindoor and Fakeset malware families. Those accesses predate the ceasefire and are unaddressed by it. For executives managing critical infrastructure, defense supply chains, or financial-sector networks: treat the Iran cyber threat as elevated, not resolved — ceasefire terms address kinetic exchanges, not dwell-time implants. Dark Reading · PBS News · Industrial Cyber · CSIS
M&A activity
Socure → Fravity—
Brinqa → PlexTrac—
Munich Re (via HSB) → $575M—
Fortinet → Virtue AI—