Skip to content

Confidential · 25 Jun 2026

🛡️ Daily Cybersecurity Briefing — 2026-06-25 (Thursday)

Window: last 24–48h plus newly confirmed items from the past week. Severity: 🔴 CRITICAL · 🟡 HIGH · 🟢 MEDIUM.

Threat level ELEVATEDVictims L30D 223Top actor QilinM&A L30D $720M

💼 M&A ACTIVITY

Databricks→Panther (Jun 16) — AI SOC lakehouse-native SIEM adds 4th named June 2026 dealMediumDatabricks agreed June 16 to acquire Panther, an AI SOC / agentic detection platform built natively on a security-lakehouse model. Panther enables real-time threat detection at Databricks-scale data volumes; it integrates with Lakewatch, Databricks' open agentic SIEM launched in March 2026 (via Antimatter+SiftD.ai acquisitions), completing the security stack from data ingestion through AI-agent investigation. Databricks is now a full-stack security analytics vendor — combining a data-lake backbone, a detection-engineering layer (SiftD.ai), an AI agent authentication layer (Antimatter), and a SIEM/detection platform (Panther). The move accelerates the "security lakehouse" category trend (with Snowflake entering security separately) and directly challenges legacy SIEM vendors (Splunk, QRadar, LogRhythm). June 2026 now has 4 named deals. Databricks PR · Infosecurity Magazine
Dragos→Phosphorus (Jun 1) — previously uncaptured June 2026 dealHighDragos announced June 1 the acquisition of Phosphorus, the Nashville-based xIoT/xOT security specialist (~$65M total funding). Phosphorus adds asset discovery, vulnerability management, and threat detection for billions of connected IIoT/medical IoT/smart-building devices embedded in critical infrastructure, extending the Dragos Platform into the Extended Operational Technology (xOT) market and pushing Dragos's estimated TAM past $50B. Deal closed before the Accenture acquisition announcement (June 18), meaning Dragos entered Accenture's OT software portfolio with Phosphorus already integrated. Dragos PR · BusinessWire · SecurityWeek
L30D summary (May 26 – Jun 25):5 named deals tracked; ~$4.22B+ in disclosed value.
Biggest🔴 Accenture→Dragos (majority) + runZero + NetRise — ~$4.17B (Jun 18); ~$208M ARR, +53% YoY; closes Aug–Sep. OT security software at enterprise scale. SecurityWeek
Databricks→Pantherundisclosed (Jun 16); AI SOC/lakehouse-native SIEM; positions Databricks as full-stack security analytics challenger to legacy SIEMs. Databricks PR
Dragos→Phosphorusundisclosed (Jun 1); xOT/xIoT device security for critical infrastructure; TAM $50B+. Dragos PR
Cisco→WideField Securityundisclosed (Jun); identity/credential telemetry for agentic SOC. SecurityWeek
Cyera→Genie Security~$50M (May 24); endpoint DLP preventing genAI data leakage; Cyera's fifth acquisition. CTech
ThemeOT/ICS software consolidation + identity as the agentic SOC binding layer + security lakehouse disrupting legacy SIEM. Platforms buying depth, not adjacencies.

⚠️ CRITICAL BREACHES & INCIDENTS

ShinyHunters campaign (35+ named orgs) remains the dominant headline. Latest run (19:04Z) added: Qilin/ISOPLUS (pharmaceuticals/Greece, June 25 DLS); 5 previously uncaptured ShinyHunters victims — DentaQuest (2.6M dental PHI, 234GB exfiltrated, confirmed June 2), Marcus & Millichap (30M Salesforce records, April 12), Zayo Group+Allstream (telecom/US+Canada, June 12), Inter-Con Security Systems (physical security/US, 2.7M records, June 18), Adapt (🟥 unverified, June 24). ShinyHunters now 35+ named victims in 2026. Prior run (18:04Z) added: Nintendo/ShadowByt3$ (third-party TinyPulse HR SaaS breach June 12; Nintendo confirmed survey-content scope; new extortion actor); Scattered Spider TfL guilty pleas (June 23 UK trial); DOJ Huione Group seizure Operation Riptide ($4B+ illicit crypto). Prior run (16:05Z) added: SharePoint CVE-2025-49706/CVE-2025-49704 (Storm-2603 ransomware + concurrent espionage actor dual-team exploitation — Microsoft June 22 disclosure, previously uncaptured); 2 new DLS victims: Morpheus/Delegal Poindexter & Underkofler P.A. (legal/US, new actor) and KRYBIT/San Silvestre School (🟥 Peru). Prior run (15:06Z) added: Databricks→Panther (Jun 16 M&A deal, previously uncaptured); Gaslight macOS malware (North Korea-attributed, SentinelOne — prompt injection against AI malware analyzers, Telegram C2); Phantom Taurus (new undocumented Chinese APT targeting government/military in Africa, Middle East, Asia). Prior run (14:05Z) added: ADT (5.5M individuals, Okta SSO vishing → Salesforce, April 20 2026, confirmed); American Tower Corporation (5.2M records claimed incl. GPS/gate codes, June 12 🟥); Lapsus$/TeamPCP breach of GitHub Internal (3,800–4,000 internal repos, May 20 via poisoned VS Code extension, Lapsus$ DLS claim June 13); NGINX CVE-2026-42530 (CVSS 9.2) added to Vulnerabilities. Prior run (13:05Z) added: 5 ShinyHunters education sector victims (Infinite Campus, Glendale CC, Illinois Central CC, Houston City College, Moody Bible Institute — PeopleSoft CVE-2026-35273 and Salesforce vishing vectors; Google Cloud/Mandiant confirmed); The Gentlemen/AmiGest (IT services/France — June 20); Nova/Dosab (industrial zone/Turkey — June 20). Prior run (12:07Z) added: 3 new June 25 DLS victims (The Gentlemen: BDS CZ, Bell Hardware, Beran Concrete); 7 previously uncaptured tracker entries from June 3–19 (DragonForce x6: Copamex, SETS Solutions, REHA-ACTIV, Sayre Associates, Areco, INK; Qilin x1: PJ Daly Contracting); M&A back-fill (Cellebrite→SCG Canada, Feb 11 2026 — drone/UAV forensics). Prior run (11:04Z) added: 5 new June 25 DLS victims (The Gentlemen x3 incl. Au Vieux Campeur; Stormous; AuditTeam new actor); CVE-2026-20245 Cisco SD-WAN 7th zero-day (Mandiant investigation, previously uncaptured); Oracle CSPU June 16 (245 patches, CVE-2026-35273 PeopleSoft now patched — previously uncaptured); fixed Ubiquiti deadline label. Prior runs (10:04Z) added: Dragos→Phosphorus (Jun 1 M&A deal, previously uncaptured); 2 Nova DLS victims (One Believing Interiors, MIT HJERTE — June 20); AIR fake AI agent skill research (June 23, new agentic supply-chain attack class); 7 CISA ICS advisories (June 23, Siemens/ABB/B&R/Hubbell Aclara); Secure Boot KEK CA 2011 expiry (June 24).
ShinyHunters breaches Amazon One Medical (Iora Health) — 8.8TB healthcare data, confirmed unauthorized accessCriticalShinyHunters claimed 8.8 TB of data stolen from One Medical's file storage system between June 8 and June 11, 2026. One Medical (an Amazon subsidiary operating under the Iora Health brand for its seniors division) confirmed to state attorneys-general that unauthorized access was identified June 13; the breach was limited to a legacy file storage system containing demographic and clinical records for One Medical Seniors patients across nine US cities: Atlanta, Cape Cod, Charlotte, Piedmont Triad, Denver, Houston, Phoenix, Tucson, and Seattle. Core One Medical operational systems and EHR, non-Seniors patient data, and Amazon systems were not affected. ShinyHunters set a June 22 ransom deadline; One Medical did not confirm whether negotiations occurred or ransom was paid; no data dump has been published. This is confirmed as a breach — One Medical's own regulatory notifications align with the ShinyHunters timeline, making this one of the most substantive confirmed healthcare breaches of 2026. Attack vector unconfirmed as Oracle PeopleSoft CVE-2026-35273 (likely direct file storage compromise). HIPAA Journal · Cybernews · BankInfoSecurity
ShinyHunters claims NAIC — 3.1TB insurance regulatory data for all 50 US states (PeopleSoft CVE-2026-35273 confirmed vector)CriticalThe National Association of Insurance Commissioners (NAIC), the US standard-setting and regulatory support organization for all 50 state insurance departments, confirmed unauthorized access to its PeopleSoft system beginning June 11, 2026. ShinyHunters claimed the breach June 18, alleging 3.1 TB and 105,000+ files including 2.1 million insurer regulatory filing PDFs, 40,000 quarterly statistical CSVs with federal EINs and company identifiers, and data from key regulatory systems: INSData (market conduct/financial data), Vision credit feeds, SERFF (filing system), OPTINS (out-of-state premium collection), UCAA (company licensing), EDP, and RDC. The Insurance Journal confirmed June 24 that the attack vector was NAIC's PeopleSoft system — consistent with ShinyHunters' CVE-2026-35273 campaign now credited with 100+ victims. NAIC stated no consumer PII or payment data was accessed and disputes ShinyHunters' claimed scope. No data samples published; NAIC published updates June 17 and June 18. 🟨 Breach acknowledged; scope disputed. Structural risk: NAIC holds insurance-industry data aggregated across all 50 US states; regulatory filing data (insurer financial health, rating agency files, premium statistics) has intrinsic intelligence value for competitive surveillance, financial fraud, and insurance-sector targeting. Insurance Journal · DeXpose · ransomware.live · HIPAA Journal
ShinyHunters claims JCPenney / Catalyst Brands — SSNs, W-2 forms, payroll records (🟥 unverified, no victim statement)HighShinyHunters claimed JCPenney and several subsidiaries under Catalyst Brands and Authentic Brands Group on June 12, 2026, threatening to publish data by June 15. Claimed data: Social Security numbers, dates of birth, W-2 tax forms, payroll records, driver's licenses, and government-issued ID scans for hundreds of thousands of individuals (scope not independently confirmed). Neither JCPenney, Catalyst Brands, nor Authentic Brands Group has issued a public statement acknowledging the breach; no proof-of-theft samples have been published. Law firm Edelson Lechtzin LLP announced a data privacy investigation June 18. The June 15 threat deadline passed without data publication, which may indicate ongoing negotiations or limited actual access. 🟥 Treat as claimed only pending victim statement. Cybernews · DeXpose · RedPacket Security
ShinyHunters — Rockstar Games breach (previously uncaptured, April 2026) — 78.6M records via Anodot/Snowflake SaaS supply chainHighShinyHunters posted Rockstar Games to its dark web leak site April 11, 2026, claiming 78.6 million records obtained by compromising Anodot — a third-party AI analytics SaaS platform with privileged access to Rockstar's Snowflake data environment — rather than attacking Rockstar infrastructure directly. After the April 14 ransom deadline expired, ShinyHunters published partial data including internal analytics and business metrics (GTA Online and Red Dead Online performance data, player counts, session telemetry, revenue analytics). Rockstar confirmed "a limited amount of non-material company information was accessed" with no impact on players, game services, or operations. Snowflake confirmed its infrastructure was not breached — the compromise stemmed from stolen Anodot credentials. Notable for attack vector: unlike ShinyHunters' ongoing Oracle PeopleSoft CVE-2026-35273 campaign, this breach exploited a third-party SaaS analytics platform — a distinct supply-chain vector that broadens the ShinyHunters access portfolio beyond PeopleSoft and Salesforce. Benzinga · Bitdefender · DeepWatch
GitHub Internal repositories breached (May 20, 2026) — 3,800–4,000 internal repos exfiltrated via poisoned VS Code extension; Lapsus$ claims partnership with primary actor TeamPCPCriticalGitHub confirmed to The Record that threat actor TeamPCP (UNC6780) exfiltrated approximately 3,800–4,000 internal source code repositories beginning May 20, 2026, via a compromised "Nx Console" VS Code extension (nrwl.angular-console v18.95.0, published to the VS Code Marketplace May 18 by the attacker). The malicious extension was designed to harvest developer credentials and establish persistence in build environments. Lapsus$ (operating as "Scattered Lapsus$ Hunters") listed GitHub on its dark web site June 13, 2026, claiming operational collaboration with TeamPCP since March 2026 and advertising the stolen data at $50K (TeamPCP standalone) / $95K (TeamPCP x Lapsus$ joint listing). Exfiltrated content reportedly includes: GitHub Actions internal tooling, GitHub Copilot source, CodeQL security analysis tools, internal security tooling, Codespaces infrastructure, and Dependabot source code. GitHub confirmed customer repositories, enterprise accounts, and user data were NOT accessed or affected. GitHub patched the VS Code Marketplace extension and has engaged law enforcement. Attribution: TeamPCP (UNC6780) — assessed by Resecurity as a financially motivated threat actor with operational ties to Lapsus$ since early 2026; Lapsus$ is claiming extortion leverage rather than having conducted the initial intrusion. The Record · Infosecurity Magazine · The Hacker News · BleepingComputer
Nintendo of America employee data exposed via TinyPulse breach — ShadowByt3$ extortion actor; Nintendo confirmed survey content onlyHighExtortion-as-a-service group ShadowByt3$ (emerged October 2025; targets third-party HR/survey SaaS vendors rather than victim networks) claimed on June 12, 2026 that it had compromised TinyPulse, an HR and employee-engagement SaaS platform used by Nintendo of America, and obtained 859MB of Nintendo employee data including full names, email addresses, bank statements, W-9 tax forms, employee IDs, HR progress plans, analytics, and survey data spanning 2016–2026. ShadowByt3$ demanded a $2M ransom with a 48-hour deadline; Nintendo declined; the group redirected the demand to TinyPulse directly on June 14 with a June 16 secondary deadline; data was leaked June 16 after the deadline passed. Nintendo confirmed the incident: "limited to internal survey content comprising a small subset of our employees" — Nintendo's own network was not compromised; the attack targeted TinyPulse's cloud environment. 🟨 Breach confirmed by Nintendo (survey content); ShadowByt3$'s broader data-scope claims (bank statements, W-9s) unverified. Attack-vector significance: ShadowByt3$ bypasses victim-network defenses entirely by targeting the HR/survey SaaS vendor — a supply-chain pattern distinct from the ShinyHunters PeopleSoft/Salesforce vectors. HackRead · Nintendo Life · TechNadu · DeXpose
France's Tchap government messaging platform breached via hijacked account — 73,000+ civil servants, 643K messages, 13.5GB claimed — actor "misere" (previously uncaptured, June 7-8 disclosure)HighFrance's national digital agency DINUM confirmed on June 8, 2026 that its Tchap messaging platform — a Matrix-protocol secure chat service mandated for all civil servants by Prime Minister Bayrou in August 2025 — was breached on June 7 via social-engineering of an account in Tchap's education environment. A threat actor using the handle "misere" (no prior public record; identity unconfirmed) claimed responsibility, alleging access to 73,000+ state employee accounts, 643,000 messages, ~60,000 files (13.5 GB), and ~90 items marked "Diffusion Restreinte" (FR semi-sensitive classification, equivalent to UK Official-SENSITIVE). DINUM stated that only public chat rooms were accessible, disputed the attacker's scope claims, and notified the CNIL (French data protection authority). France's national cybersecurity agency ANSSI is investigating; no data has been independently verified as exfiltrated. 🟥 Attacker claims unverified — ANSSI/DINUM dispute scope. Impact: even if only the confirmed 73K accounts and metadata are verified, this exposes email addresses, display names, and French civil service org chart data for a messaging platform with 800,000+ registered users that handles government communications across defence, justice, and education. SecurityWeek · BleepingComputer · Help Net Security
Kyushu Electric Power subsidiary loses unencrypted SSD with 10.9M customer records — Japan's largest-ever personal data breach (previously uncaptured, disclosed June 8)HighKyushu Electric Power Transmission and Distribution Co. (a subsidiary of Kyushu Electric Power Co., Japan) disclosed on June 8, 2026 that an unencrypted portable SSD containing data for up to 10.9 million customers went missing during a contractor maintenance operation. The SSD was created April 27 as a workaround when a server lacked capacity; the contractor returned May 26 to find the cabinet unlocked and the drive missing — a 30-day window during which 57 individuals from 10 contractors had site access. Data exposed: customer names, service-location addresses, electricity usage records, telephone numbers, and retail electricity supplier names. No bank account or payment card data. The company must submit a full incident report to Japan's Ministry of Economy, Trade and Industry by July 8, 2026. This is a physical security incident — not a network intrusion — but scale (10.9M accounts) makes it the largest personal data breach in Japanese history, surpassing the 2016 JTB breach (7.93M). BleepingComputer · SC Media · TechTimes

🔓 CRITICAL VULNERABILITIES

KEV deadline TOMORROW (June 26) — Ubiquiti UniFi OS CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 (CVSS 10.0 each) + Lantronix CVE-2025-67038 (CVSS 9.8) — federal remediation window closes tomorrow nightCriticalFour vulnerabilities added to CISA KEV June 23 carry a June 26 federal remediation deadline under BOD 26-04. Three Ubiquiti UniFi OS flaws chain for full unauthenticated device compromise: CVE-2026-34908 (improper access control — unauthorized system configuration changes), CVE-2026-34909 (path traversal — arbitrary file read/manipulation), CVE-2026-34910 (command injection — arbitrary OS command execution). CVE-2025-67038 (Lantronix EDS5000, CVSS 9.8) enables unauthenticated OS command injection via the HTTP RPC module — upgrade to v2.2.0.0R1 immediately. Federal agencies not yet remediated must escalate under BOD 26-04 today. CISA KEV · CyberSecurityNews
CVE-2026-20245 · Cisco Catalyst SD-WAN Manager · CVSS 7.8 · Zero-day exploited months before June 10 patch — Mandiant investigation (previously uncaptured)HighThe seventh Cisco SD-WAN CVE exploited in 2026; disclosed June 5 as an active zero-day with no patch available, patched June 10. Flaw: authenticated local attacker uploads a crafted CSV file through the CLI tenant-upload feature of Cisco Catalyst SD-WAN Manager (formerly vManage) to execute arbitrary commands as root. Mandiant/Google Cloud GTIG investigated an unknown threat actor targeting SD-WAN infrastructure at a service provider beginning in early 2026, exploiting CVE-2026-20245 at least two months before Cisco's disclosure. Attacker technique: upload "evil_tenant.csv" via tenant-upload CLI to gain root, then push malicious configuration changes to SD-WAN edge devices. Action: apply Cisco Catalyst SD-WAN Manager fix (available June 10 2026). The Hacker News · Google Cloud/Mandiant · Help Net Security
CVE-2026-20262 · Cisco Catalyst SD-WAN Manager · Deadline June 29 — 4 days remainingCriticalPath-traversal flaw (CVSS 6.5; authenticated write → arbitrary file creation → root escalation); eighth Cisco SD-WAN CVE confirmed exploited in 2026. No workarounds; upgrade required. CISA · SecurityWeek
CVE-2026-20253 · Splunk Enterprise · CVSS 9.8 · Federal deadline 4 days overdue — active exploitation confirmedCriticalUnauthenticated RCE via PostgreSQL sidecar (BOD 26-04 deadline was June 21); WatchTowr public PoC; exploitation confirmed. Non-compliant federal agencies are in breach of BOD 26-04 escalation requirements. Affected: Splunk Enterprise 10.2 before 10.2.4 and 10.0 before 10.0.7. SecurityWeek · CISA BOD 26-04
CVE-2026-41089 · Windows Netlogon · CVSS 9.8 · Domain controller RCE, active exploitation ongoingCriticalUnauthenticated stack overflow allows full AD domain compromise from network position; PoC publicly available; active exploitation volume growing per CCB/SecurityWeek. Apply May 2026 Patch Tuesday if not yet done; treat unpatched domain controllers as potentially compromised. SecurityWeek · MSRC
npm supply-chain — abdrizak PostCSS RAT (JFrog June 22) — 3 malicious packages live on registry, typosquatting 150M+ weekly download libraryHighJFrog security researchers disclosed June 22 that npm account "abdrizak" published three malicious packages — `aes-decode-runner-pro` (145 downloads), `postcss-minify-selector` (256 downloads), and `postcss-minify-selector-parser` (615 downloads) — typosquatting `postcss-selector-parser` (150M+ weekly downloads). Packages chain to deliver a Windows RAT that steals Google Chrome credentials and extension data, executes arbitrary shell commands, and communicates with C2 at 95.216.92.207:8080 (RC4-encrypted). All three packages remain live on the npm registry. Action: check `package.json`/`package-lock.json` for the three lookalike names; treat any build environment that pulled them as potentially compromised. The Hacker News · GBHackers
CVE-2026-42530 · NGINX · CVSS 9.2 · HTTP/3 use-after-free RCE — F5 out-of-band patch June 2026HighUse-after-free vulnerability in NGINX's HTTP/3 module (ngx_http_v3_module) allows a remote unauthenticated attacker to send a crafted HTTP/3 request that triggers a use-after-free condition, potentially resulting in DoS or remote code execution. Affected: NGINX 1.31.0–1.31.1 (mainline branch) with HTTP/3 enabled (--with-http_v3_module compile flag). Fixed: NGINX 1.31.2 (F5 out-of-band patch, June 2026). No confirmed in-the-wild exploitation at time of publication; CVSS 9.2 indicates critical severity. Action: upgrade to NGINX 1.31.2 immediately; sites not running HTTP/3 are not exposed but should upgrade as a precaution given active mainline branch users. F5 PSIRT · NGINX Advisory
Oracle CSPU June 16 — 245 patches, 120 critical, 100 remotely exploitable without authentication — CVE-2026-35273 PeopleSoft now patched (previously uncaptured)HighOracle's second monthly Critical Security Patch Update (released June 16, 2026) addressed 245 vulnerabilities across Communications, E-Business Suite, Fusion Middleware (100+ patches; majority critical/high), JD Edwards, MySQL, PeopleSoft, and Siebel CRM. Approximately 120 CVEs are rated critical; 100 are exploitable remotely without authentication. Critically: Oracle PeopleSoft CVE-2026-35273 — the zero-day ShinyHunters used to breach the Council of Europe, NAIC, University of Nottingham, Madison Square Garden Sports Corp., Kodak, and 100+ other organisations — is addressed in this update; Oracle confirmed active exploitation in the wild before the patch shipped. This is the first patch for the ShinyHunters campaign's primary attack vector. Enterprise action: apply Oracle June 16 2026 CSPU immediately; prioritise Oracle Fusion Middleware and Oracle PeopleSoft PeopleTools. Oracle CSPU Jun 2026 · SecurityWeek · Tenable
CVE-2025-49706 / CVE-2025-49704 · Microsoft SharePoint · Two threat actors exploited the same unpatched servers simultaneously — Storm-2603 deployed ransomware while a second unattributed actor exfiltrated NTDS.dit (Microsoft MSTIC disclosure June 22, previously uncaptured)HighMicrosoft MSTIC disclosed June 22 that two distinct threat actors concurrently exploited unpatched on-premises SharePoint servers using CVE-2025-49706 and CVE-2025-49704. Storm-2603 deployed ransomware in the victim environment; a second unidentified threat actor (assessed espionage-motivated) simultaneously used DLL sideloading and custom backdoors to exfiltrate NTDS.dit — the Active Directory credential database containing hashed passwords for all domain accounts. The two actors operated independently in the same victim network, neither apparently aware of the other. This is the first publicly documented case of concurrent ransomware deployment and espionage-motivated credential harvesting via the same unpatched SharePoint vector in a single victim environment. Action: patch SharePoint immediately; do not treat ransomware infection as the only impact — NTDS.dit exfiltration requires full domain-wide credential rotation regardless of whether ransomware was detected or remediated. Microsoft Security Blog · CyberSecurityNews · CSO Online
For full vulnerability list from June 24 (FortiSandbox, SAP NetWeaver, libssh2, Dify, ShapedPlugin, AutoJack, RoguePlanet, CVE-2026-50751 Check Point VPN) see [cyber-briefing-2026-06-24.md](./cyber-briefing-2026-06-24.md).

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

CISA ICS Advisories — 7 advisories released June 23 (ICSA-26-174-01 through -07) — Siemens, ABB, B&R, Hubbell Aclara affectedHighCISA published seven ICS advisories on June 23, 2026. Key affected products: (1) Siemens WinCC Certificate Manager (ICSA-26-174-01) — insufficient key-material protection, sensitive-information extraction; (2) Siemens SIPROTEC 5 / DIGSI 5 Protocol (ICSA-26-174-02) — authenticated arbitrary file upload enabling malicious config injection → permanent DoS on protective relays; (3) Siemens Products using OpenSSL (ICSA-26-174-03) — stack-based buffer overflow, remote DoS or potential RCE; (4) Siemens SINEC INS before V1.0 SP2 Update 6 (ICSA-26-174-04) — multiple vulnerabilities; (5) ABB Freelance Security Lock (ICSA-26-174-05) — underlying OS function access while DCS is active; (6) B&R Products / Linux Kernel (ICSA-26-174-06) — publicly reported Linux kernel vulnerabilities affecting B&R product firmware; (7) Hubbell Aclara Metrum Cellular Web Interface (ICSA-26-174-07) — attacker manipulation of critical device settings, repeated operational disruption. OT/ICS operators should prioritize ICSA-26-174-02 (Siemens SIPROTEC relay permanent DoS via config file) and ICSA-26-174-07 (Hubbell Aclara metering device DoS) given critical infrastructure impact potential. CISA
Microsoft Secure Boot KEK CA 2011 expired June 24 — devices not yet updated with 2023 certificates are now cut off from boot-level security patchesHighThe "Microsoft Corporation KEK CA 2011" certificate, which Windows has used to validate Secure Boot updates since 2011, expired June 24, 2026. Additional UEFI CA 2011 certificates expire June 27. Any Windows device that has not received the new 2023-series certificates (Windows UEFI CA 2023 / Microsoft Corporation KEK 2K CA 2023) through Windows Update is now cryptographically frozen: it cannot receive updates to the Windows Boot Manager, Secure Boot databases (allowed/revoked lists), or boot-level vulnerability mitigations going forward. Normal Windows operation and standard application updates continue unaffected. Microsoft began rolling out the new certificates via Windows Update in April 2026 (KB5083769). Enterprise IT: audit endpoints for Secure Boot certificate status under Privacy > Security > Device Security > Core isolation > Firmware protection; remediate via WSUS/Intune before adversaries exploit the update gap. Older devices without compatible UEFI firmware may require vendor-issued firmware updates or will remain permanently unable to receive boot-level security patches. Microsoft TechCommunity · HowToGeek · Malwarebytes
Scattered Spider members plead guilty to TfL attack — UK criminal proceedings begin June 23; sentencing July 16HighTwo members of the Scattered Spider (UNC3944) network entered guilty pleas in UK court on June 23, 2026, the first day of trial, in connection with the September 2024 cyberattack on Transport for London (TfL). Named defendants: Fahim Jubair and Tyler Flowers (both connected to the wider Scattered Spider affiliate network). The TfL attack — a social-engineering intrusion — disrupted Oyster card top-up services, online journey planning, and internal systems for weeks and exposed customer data including approximately 5,000 bank sort codes and account numbers. The UK prosecution is separate from parallel US federal charges against Scattered Spider members (Tyler Buchanan, sentenced October 2025). Sentencing is scheduled for July 16, 2026. The guilty pleas confirm attribution and mark the first UK criminal convictions in the TfL investigation. The Record · Krebs on Security · Help Net Security
DOJ seizes Huione Group cryptocurrency infrastructure — Operation Riptide, June 23; $4B+ illicit transactions; Lazarus/ransomware nexusHighThe US Department of Justice announced June 23 the seizure of cryptocurrency accounts and infrastructure tied to Huione Group (also known as Haowang Guarantee), a Cambodian marketplace linked to $4 billion or more in illicit cryptocurrency transactions including proceeds from North Korean Lazarus Group heists, ransomware payment laundering, and pig-butchering fraud. Operation Riptide targeted Huione's network of nested exchange accounts, stablecoin infrastructure, and USDH (Huione's own stablecoin), with DOJ coordinating with FinCEN, OFAC, and international partners. Tether (USDT issuer) and Circle (USDC) had previously frozen ~$132M in Huione-linked addresses. DOJ indictment names Huione Guarantee CEO and key personnel. The action follows a May 2025 FinCEN "primary money laundering concern" designation. Strategic read: Huione was a critical cash-out layer for both state-sponsored (DPRK) and criminal ransomware operations; its disruption raises friction costs for illicit crypto monetization globally. DOJ Press Release · Washington Times
Outstanding operational items:
BOD 26-04 escalation required: Splunk CVE-2026-20253 (June 21 deadline, 4 days overdue), SolarWinds Serv-U CVE-2026-28318 (June 19 deadline, 6 days overdue). Non-compliant federal agencies must trigger formal escalation procedures.
Ubiquiti KEV deadline is TOMORROW (June 26) — federal agencies must remediate by end of day Thursday; any that miss it are in violation of BOD 26-04.
PQC Executive Order (June 22): inventory and migration planning deadlines binding. 2030 (key establishment) / 2031 (digital signatures) federally mandated.
Operation Endgame Phase 2: 326 servers and 142 domains dismantled June 15-19 (StealC+Amadey); 27M credentials recovered, $47M crypto restricted; RICO first applied to link two malware operations as a single criminal conspiracy. [See June 24 briefing for full detail.] Separate sub-action June 18: Dutch National Police + Canada/US/Germany seized 106 SocGholish servers and 101 domains (TA569 / Evil Corp linkage); 14,971 infected WordPress sites cleaned via HaveIBeenPwned and Shadowserver victim notification. The Hacker News · Help Net Security

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

ShinyHunters — 35+ named victims in 2026, three attack vectors confirmed:
Campaign scope update: ADT (5.5M confirmed) and American Tower Corporation (5.2M claimed 🟥) added; 30+ named organisations, 400M+ people affected across the full 2026 campaignCriticalTwo additional ShinyHunters victims confirmed this run: (a) ADT — 5.5M individuals (names, phone numbers, addresses; partial SSNs/DOBs for a subset); vishing attack on ADT employee Okta SSO credentials → Salesforce CRM pivot; breach detected April 20, access revoked April 24; HIBP confirmed 5.5M records (ShinyHunters claimed 10M; ADT confirmed 5.5M); Salesforce vector (not PeopleSoft CVE-2026-35273); BleepingComputer · BankInfoSecurity. (b) American Tower Corporation — 5.2M records claimed including customer/landowner PII, data linking T-Mobile/Verizon/US DHS, tower asset GPS coordinates, and plaintext physical access/gate codes for cell tower compounds across the US; claimed June 12; ransom deadline June 15 passed with no confirmed data dump; no American Tower public statement; 🟥 treat as claimed only — DeXpose · Breachsense. Previously added (prior runs): Zara/Inditex, Mytheresa (🟥), Pitney Bowes, 7-Eleven (🟥), Udemy (🟥) via Anodot/BigQuery SaaS or Salesforce vishing vectors. Full named-victim list (33 named): ADT, American Tower Corp. (🟥), Mytheresa (🟥), Zara/Inditex, Pitney Bowes, Rockstar Games, Wynn Resorts, 7-Eleven (🟥), Carnival, Udemy (🟥), Instructure/Canvas, BCD Travel, Charter Communications, Cushman & Wakefield, One Medical, Kodak, JCPenney/Catalyst (🟥), MSG Sports Corp., NAIC (🟨), Council of Europe, University of Nottingham, Sysco (🟥), Match Group (🟥), Infinite Campus, Glendale Community College, Illinois Central College, Houston City College, Moody Bible Institute (🟥 scope unverified), DentaQuest (2.6M PHI confirmed), Marcus & Millichap (30M Salesforce records), Zayo Group + Allstream (telecom/US+Canada, June 12 DLS), Inter-Con Security Systems (2.7M records, June 18 DLS), Adapt (🟥 unverified, June 24 DLS), plus at least 2 additional unlisted organisations per Mandiant count. Three confirmed attack vectors: (1) Oracle PeopleSoft CVE-2026-35273 — 100+ orgs; (2) Salesforce/Okta vishing; (3) Anodot/BigQuery/Snowflake SaaS analytics supply chain. HIPAA Journal · BleepingComputer · The Register · Cybernews · TechRadar
ShinyHunters education sector campaign: 100+ PeopleSoft Campus Solutions endpoints compromised, 69% higher education — Google Cloud/Mandiant confirmedCriticalGoogle Cloud / Mandiant published a dedicated threat intelligence report (June 2026) documenting ShinyHunters' exploitation of Oracle PeopleSoft CVE-2026-35273 across the education sector. Activity window: May 27–June 9, 2026; 100+ PeopleSoft Campus Solutions endpoints compromised; 69% of victims are higher education institutions. Named education victims added to the tracker this run: Glendale Community College (62GB exfiltrated, 150,000+ student records including names, DOBs, enrollment, financial aid, and transcripts; DLS June 15–16; PeopleSoft vector); Illinois Central College (28GB claimed; DLS June 15; PeopleSoft vector); Houston City College (DLS June 9+; Mandiant-confirmed; PeopleSoft vector); Moody Bible Institute ("tens of millions of records" claimed across enrollment, donor relations, payroll, and communications; 1,300+ files; DLS June 16; 🟥 scope unverified); Infinite Campus (ed-tech platform serving 3,200+ districts and 11M students across 46 US states; Salesforce vishing vector March 18, 2026 — distinct from PeopleSoft CVE-2026-35273 campaign; 137,123 staff records exfiltrated: names, emails, phone numbers, addresses, job titles, usernames; company confirmed breach; HIBP notification June 15). University of Nottingham already in tracker. Patch: apply Oracle PeopleSoft June 16 CSPU immediately. Google Cloud/Mandiant · BleepingComputer · Cybernews · Higher Ed Dive
DLS activity — June 20-25 window:
29 new named victims across nine+ groups — Qilin adds ISOPLUS (Greek pharma, June 25); The Gentlemen adds French outdoor retailer Au Vieux Campeur (23-day ransom stalemate) plus BDS CZ, Bell Hardware, Beran Concrete (June 25), AmiGest (June 20); Nova adds Dosab/Turkey (June 20); AuditTeam (new actor) claims Russian IT firm; Anubis targets Quest Health Solutions (239 GB, healthcare/US); Stormous expands Italian knitwear group Maglificio Liliana to four brand/domain listings (400+ GB); WorldLeaks, INC Ransom, Qilin, CMD, Payload all activeHighJune 20-25 DLS postings confirmed: (1) 🟥 Flughafen Wien AG (Vienna Airport) — APT73/Bashe claims 500,000+ emails and 4,473 files including cargo manifests and weapons-transport records; airport confirmed limited attack, disputes scope, flight operations unaffected — 🟥 treat as claimed only; (2) FTL-Fast Transit Line (logistics/Belgium) — Nova June 23; (3) Randa Apparel & Accessories (apparel/US) — Chaos June 23; (4) Coldstat Refrigeration (refrigeration/US NJ) — CMD June 23 (first-observed actor); (5) Lee International (sector unknown/US) — Qilin June 23; (6) Super Finishing (manufacturing/Brazil) — WorldLeaks June 20; (7) L'Archevêque & Rivest Ltée (construction/Canada) — WorldLeaks June 20; (8) Newspaper Media Group (media/US) — INC Ransom June 20; (9) montechiaro-store.com (consumer/e-commerce) — Stormous June 24, complete customer/buyer data claimed; (10) mlit.com.my (government/Malaysia) — Stormous June 24, 10GB full data dump claimed including sensitive internal and financial records; (11) Preferred Properties (housing/property management/US Ohio) — Payload June 20; (12) One Believing Interiors (interior design/US) — Nova June 20, studio with National Gallery project portfolio; (13) MIT HJERTE (sector unknown/Denmark) — Nova June 20; (14) Au Vieux Campeur (auvieuxcampeur.fr) (outdoor retail/France) — The Gentlemen June 25; French outdoor equipment chain (24 stores) confirmed cyberattack June 2, posted to DLS June 25 after 23-day ransom negotiation window expired — timeline consistent with non-payment; data scope unconfirmed; (15) Al-Dhow (al-dhow.com) (business group/Kuwait) — The Gentlemen June 25; Kuwaiti diversified conglomerate; data scope unconfirmed; (16) Gegenbauer Elektrotechnik & IT (gegenbauer-it.at) (electrical/IT services/Austria) — The Gentlemen June 25; data scope unconfirmed; (17) impulso-store.com (e-commerce/Italy) — Stormous June 25; Italian online retail platform; data scope unconfirmed; (18) I-SYS (i-sys.ru) (IT services/Russia) — AuditTeam June 25 (new actor, limited public profile; first-observed DLS claim); Russian IT and systems integration firm; data scope unconfirmed; (19) BDS CZ (real estate/Czech Republic) — The Gentlemen June 25; Czech real estate agency; data scope unconfirmed; (20) Bell Hardware (commercial hardware/US) — The Gentlemen June 25; family-owned commercial hardware company; data scope unconfirmed; (21) Beran Concrete, Inc. (construction/US) — The Gentlemen June 25; concrete construction and materials company; data scope unconfirmed; (22) AmiGest (amigest.fr) (IT services/France) — The Gentlemen June 20; French IT integrator; DLS claim June 20; DeXpose-confirmed attribution; data scope unconfirmed; (23) Dosab/Demirtaş OSB (industrial zone/Turkey) — Nova June 20; organized industrial zone in Bursa; data scope unconfirmed; (24) Delegal Poindexter & Underkofler, P.A. (legal/employment law/US) — Morpheus June 25; employment law firm; data scope unconfirmed; HookPhish · DeXpose; (25) 🟥 San Silvestre School (education/Peru) — KRYBIT June 25; 148.75 GB claimed; 🟥 possible re-listing of prior Qilin-targeted school — treat as unverified; FalconFeeds. New this run (18:04Z): (26) 🟥 Quest Health Solutions (healthcare/US) — Anubis June 24; 239 GB claimed including employee data and internal files; data publication threatened within 2-3 days; Go-based malware with dual-threat encryption-and-wipe capability; no victim statement — DeXpose · HookPhish; (27) lorenzoni-store.com (fashion/knitwear retail/Italy) — Stormous June 24; Lorenzoni brand of Maglificio Liliana di Lorenzoni Andrea & C. s.n.c. (est. 1969 Montichiari; three brands: Lorenzoni, Montechiaro, Impulso); complete customer and buyer data claimed; part of the same parent-company incident as montechiaro-store.com (June 24) and impulso-store.com (June 25) — RedPacket Security · FalconFeeds; (28) maglificioliliana.com (textile/knitwear manufacturing/Italy) — Stormous June 24; parent company Maglificio Liliana di Lorenzoni Andrea & C. s.n.c.; 400+ GB of sensitive data claimed including product designs, orders, customer and operational records; the four-domain scope (Lorenzoni, Montechiaro, Impulso brands + parent) suggests a full-group compromise — HookPhish · FalconFeeds. New this run (19:04Z): (29) ISOPLUS (isoplus.gr) (pharmaceuticals/Greece) — Qilin June 25; Greek pharmaceutical company; data scope unconfirmed — DeXpose · hendryadrian.com. June 24 confirmed victims remain: Cash Canada (Qilin), Miami Machine Inc. (Akira), JIT-EX LLC (Akira), Alexandria (Nova), LP Group (Nova), Transvill SRL (Nova). Qilin, Akira, and The Gentlemen remain the highest-cumulative-volume groups. ransomware.live · DeXpose · RedPacket Security · HookPhish · RedPacket Security · FrenchBreaches
APT / nation-state:
MuddyWater (MOIS) operated behind Chaos ransomware brand as a false flag to conceal state espionage — NCC Group May 2026 Threat PulseCriticalNCC Group's Monthly Threat Pulse for May 2026 (published June 24) and Rapid7 independent analysis assess that MuddyWater, the Iranian Ministry of Intelligence and Security (MOIS) threat group, conducted targeted espionage intrusions in early 2026 while posing as the Chaos ransomware-as-a-service (RaaS) operation. The campaign began with high-touch social engineering via Microsoft Teams — attackers used Teams interactive screen-sharing sessions to harvest credentials and manipulate multi-factor authentication — before deploying Chaos ransomware as a decoy to obscure the espionage objective and delay attribution. Forensic analysis by both NCC Group and Rapid7 concluded the incidents were "consistent with a targeted state-sponsored operation" rather than financially motivated ransomware. Implication: organizations that attributed an early-2026 "Chaos ransomware" incident to cybercriminals may have experienced a state-sponsored intrusion; incident response scoping and threat intelligence should be revisited. Chaos DLS entries in this tracker should be treated as unverified for attribution — the MuddyWater false-flag operation creates ambiguity across the Chaos victim set. NCC Group May 2026 Threat Pulse · Rapid7 · Infosecurity Magazine · Industrial Cyber
AI agent supply-chain (new attack class):
AIR research: fake AI agent skill bypassed every commercial skill scanner and reached 26,000 agents — a new class of agentic supply-chain riskHighSecurity firm AIR disclosed June 23 that it built a malicious skill for a popular AI agent marketplace, promoted it via an Instagram ad alongside a repository pull request to a GitHub project with 36,000 stars, and watched it reach approximately 26,000 agents including corporate accounts — all while every commercial skill security scanner marked it clean. The fake skill ("brand-landingpage", claiming to build landing pages via Google's Stitch design tool) redirected agents to install a "Stitch SDK" from an AIR-controlled domain, bypassing scanner analysis by initially pointing to the legitimate Stitch docs and changing the payload after review. AIR kept the payload benign (email-address collection only) but confirmed a real attacker could have used the same foothold to read files, exfiltrate data, or move laterally into connected systems. The research also surfaced a structural scanner fragmentation problem: seven major skill-security scanners agree on fewer than 1 in 500 of their combined flags because each judges skills in isolation, blind to external links and post-review payload changes. Implication: AI agent marketplace skill-supply chains carry the same trust assumptions as npm/PyPI — and the same attack surface. Any skill that installs external packages or fetches URLs after installation is a potential vector. The Hacker News · The Next Web · CSO Online
Gaslight — North Korea-attributed Rust macOS implant uses prompt injection to defeat AI malware analysis — SentinelOne disclosure June 25CriticalSentinelOne Labs disclosed a novel North Korea-attributed macOS backdoor named "Gaslight," implemented in Rust. Primary technical novelty: the implant embeds 38 fabricated system-failure and error messages into its code, designed to deceive LLM-based malware analysis tools into aborting triage ("no malicious behavior detected — system error prevented complete analysis"). The prompt-injection technique exploits the growing use of AI co-pilots in malware analysis workflows, targeting the AI tool rather than the sandbox environment. Capabilities: Keychain credential harvesting, browser history and stored-password exfiltration, shell command history collection; persistence via LaunchAgent plist. C2 via Telegram bot API — an increasingly common evasion technique that routes C2 traffic through a legitimate cloud platform, making network-layer blocking highly disruptive. SentinelOne attributes Gaslight to North Korea-aligned threat actors with high confidence based on code overlap with prior DPRK macOS tooling (BlueNoroff/Lazarus Group tradecraft patterns). No confirmed victim count. Implication: AI-assisted malware triage — now a default in most enterprise SOC playbooks — has an emerging blind spot exploited by adversary-crafted prompt injection. SentinelOne Labs · The Hacker News
Phantom Taurus — new undocumented Chinese nation-state APT targeting government, military, and embassies across Africa, Middle East, and AsiaHighSecurity researchers disclosed June 25 a previously undocumented Chinese nation-state threat actor tracked as "Phantom Taurus." The group targets government agencies, embassies, and military organisations across Africa, the Middle East, and Asia with a custom toolkit designed for precision espionage. Limited technical details disclosed at initial publication; no CVE exploitation confirmed in public reporting. Attribution to China assessed with medium confidence based on infrastructure overlap and targeting profile. This is a newly named cluster — prior activity may have been mis-attributed or untracked. Relevance: aligns with the documented Chinese pre-positioning pattern (ODNI 2026 Threat Assessment) focused on building persistent access to coalition-adjacent and developing-world network infrastructure in advance of potential Taiwan contingency activation. Dark Reading (early report; further technical detail expected)
Leaderboard (unchanged — June monthly report pending):
Qilin #1 (546 YTD), The Gentlemen #2 (504 DLS total), Akira #3 (184 L3M). June report due when month completes (June 30).

🌍 GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense · cyber · economics.
ShinyHunters' breach of the NAIC puts insurance-sector regulatory intelligence for all 50 US states in adversary hands — a structural intelligence prize beyond PII.CriticalThe NAIC does not hold consumer PII at scale, which explains why the group's claims are less alarming to the public than healthcare breaches. The strategic value is different: insurer financial condition data, rate filings, market conduct examination results, and statistical reports aggregated across all 50 US states represent a comprehensive map of the US insurance sector's health, pricing strategies, and regulatory vulnerabilities. For a foreign state intelligence service — particularly one with ambitions in sanctions evasion or financial-sector disruption — this dataset answers the question "which US insurers are financially weakest?" and "where are the regulatory arbitrage opportunities?" The PeopleSoft CVE-2026-35273 vector also confirms that ShinyHunters has now accessed at least one intergovernmental regulatory body (NAIC) and one international governance institution (Council of Europe) — extending the campaign from corporate and education targets into regulatory infrastructure.
ShinyHunters' One Medical breach crosses into protected health information at scale — and the June 22 deadline silence signals a likely data-sale outcome.CriticalOne Medical Seniors/Iora Health patients are predominantly elderly, enrolled in Medicare Advantage or integrated care programs — a demographic whose PHI includes both clinical data (diagnoses, prescriptions, lab results) and Medicare enrollment details. If ShinyHunters obtained this data and did not reach a settlement by the June 22 deadline, the outcome is likely either sale on dark markets or use as leverage in ongoing extortion cycles. Healthcare breach data for elderly patients commands a premium because it combines PHI with Social Security eligibility, enabling medical identity fraud and fraudulent Medicare billing. Amazon's ownership of One Medical adds enterprise reputational and regulatory risk; HIPAA breach notification requirements for healthcare data of this scale trigger federal OCR scrutiny.
The Rockstar Games breach illustrates a third ShinyHunters access vector that bypasses both PeopleSoft patching and Salesforce MFA enforcement.HighThe Anodot/Snowflake route — compromising a trusted analytics SaaS vendor with privileged data-lake access — replicates the technique ShinyHunters (and affiliated clusters) used in the 2024 Snowflake campaign that breached 165+ organisations including AT&T, Ticketmaster, and Advance Auto Parts. The implication for CISOs: patching Oracle PeopleSoft and hardening Salesforce MFA closes two of three known ShinyHunters vectors, but does not address the Snowflake/SaaS analytics pathway. Any cloud analytics platform with direct access to production data lakes (Anodot, ThoughtSpot, Looker, Sigma, Palantir) represents an equivalent risk surface. Audit third-party SaaS access to Snowflake, Databricks, and BigQuery environments now.
Iran's post-ceasefire cyber posture is expanding, not contracting — and the implants pre-planted during the conflict survivie the truce.HighODNI's 2026 Annual Threat Assessment (published March 2026) explicitly assessed Iran's cyber workforce as having "dispersed rather than disappeared" following the US-Israeli strikes on IRGC cyber infrastructure in February–March 2026. The assessment noted Iran retains the capacity for independent action through ideologically aligned groups. The Seedworm (MOIS/MuddyWater) implants confirmed at a US bank, US airport, Canadian NGOs, and a defense-aerospace software company predate the June 17 ceasefire and are unaddressed by it. Post-ceasefire, the expectation is the highest-tempo espionage period since the 2010 Stuxnet era: limited kinetic options concentrate pressure into the cyber domain. Executives with exposure to critical infrastructure, financial services, or defense supply chains should treat the ceasefire as an intelligence amplifier, not a threat reduction.
China's pre-positioned critical-infrastructure access is purpose-built for activation during a geopolitical crisis — and the access is already in place.HighThe 2026 ODNI assessment states explicitly that Chinese threat groups are "pre-positioned inside critical networks at scale, with access appearing intended for possible activation during a future geopolitical crisis, likely a Taiwan contingency." Salt Typhoon's documented access to South American telcos (new implants TernDoor, PeerTime, BruteEntry, June 2026) and UNC3886's confirmed access to all four major Singapore telcos represent the same pre-positioning playbook applied to alliance-adjacent networks — building the intelligence and disruption infrastructure that can be activated if diplomatic or military escalation over Taiwan crosses a threshold. For multi-portfolio executives: the question is not "is China collecting?" — they are, confirmed at scale — but "what is the activation threshold?" which sits inside intelligence assessments, not public reporting.
Threat actors
1 · Qilin546 YTD
2 · The Gentlemen335 YTD
3 · Akira228 YTD
4 · DragonForce248 YTD
M&A activity
SocureFravity
BrinqaPlexTrac
Munich Re (via HSB) → $575M
FortinetVirtue AI