Confidential · 26 Jun 2026
🛡️ Daily Cybersecurity Briefing — 2026-06-26 (Friday)¶
Window: last 24–48h. Severity: 🔴 CRITICAL · 🟡 HIGH · 🟢 MEDIUM. Last updated: 2026-06-26T09:06Z.
Threat level ELEVATEDVictims L30D 241Top actor QilinM&A L30D $720M
💼 M&A ACTIVITY¶
Cyera→Otterize — June 26 (today) — undisclosed (~tens of millions)MediumIsraeli cloud-native non-human identity (NHI) security startup acquired; Otterize's eBPF agent discovers and controls sensitive data flows in microservices and cloud-native workloads in runtime; Cyera's sixth acquisition in 2026; co-founders are IDF 8200 alumni and former MuleSoft CTO; extends Cyera's DSPM platform with workload-identity controls and data-lineage visibility. Cyera PR · CTech
Dream — $260M Series C (June 18) — $3B valuationMediumSovereign AI / national cyber defense platform for governments; products: Sphere (CNI/nation-state defense), Hero (AI autonomous vulnerability hunting), Atlas (national intelligence integration); $130M+ ARR; 6 government clients; co-founded by Shalev Hulio (former CEO, NSO Group), Sebastian Kurz (former Austrian PM), and Gil Dolev; HQ Tel Aviv. Positioned as sovereign alternative to US/Chinese hyperscaler AI dependency — significant for allied governments seeking to retain data residency and AI sovereignty over their national cyber defense stack. SecurityWeek · PR Newswire
L30D (May 27 – June 26): 7 named deals, ~$4.48B+ total disclosed. Dominant move: Accenture's three-way acquisition of Dragos, runZero, and NetRise (~$4.17B, Jun 18) — the clearest signal yet that strategic OT/ICS/attack-surface-management consolidation has crossed from niche to board-level. Supporting: Dream $260M funding (Jun 18, sovereign AI for nations), Databricks→Panther (Jun 16, AI SOC/lakehouse SIEM), Dragos→Phosphorus (Jun 1, xOT/xIoT), Cisco→WideField (Jun, undisclosed), and Cyera→Otterize (Jun 26, NHI/eBPF runtime). Theme: AI-native detection plus OT/NHI-first visibility — the 2026 consolidation thesis is now firmly an agentic-AI governance play as much as an OT security one.
⚠️ CRITICAL BREACHES & INCIDENTS¶
ShinyHunters campaign: 36+ named victimsCriticalmulti-vector extortion (Oracle PeopleSoft CVE-2026-35273, Salesforce/Okta vishing, Anodot/Snowflake SaaS supply-chain) with permanent leak infrastructure; Deep Well Services (oilfield services/US; 7,000+ customer PII and internal data; DLS June 15; ransom deadline June 18 passed without publication) newly added. See threat actor section for full named-victim list. HookPhish · BreachNews · ransomware.live
Qilin adds Pacific Lamp & SupplyCriticalmanufacturing/US; DLS June 20; data scope undisclosed; 🟥 unverified — verify before treating as breach. Qilin holds the #1 global rank (546 YTD). RedPacket Security · ransomware.live
GitHub internal repo breach (TeamPCP / Lapsus$)Critical3,800–4,000 internal repos exfiltrated May 20 via poisoned Nx Console VS Code extension (nrwl.angular-console v18.95.0); TeamPCP (UNC6780) primary; Lapsus$ extortion partner; GitHub confirmed breach of internal repositories, stated customer repos and user data unaffected. The Record · BleepingComputer
Nintendo of America via TinyPulse (ShadowByt3$)High859MB claimed (employee bank statements, W-9s, HR records 2016–2026); $2M ransom refused; data leaked June 16; Nintendo confirmed breach limited to internal survey content — TinyPulse's cloud environment was the attack target, not Nintendo's network. 🟨 breach confirmed, broader scope unverified. HackRead · TechNadu
Cherry Health (Michigan FQHC) — healthcare ransomware, patient PHIHighMichigan's largest federally qualified health center detected ransomware on April 19, 2026 (days-long network outage); breach notice published June 18; unauthorized actor accessed and copied patient and staff data including names, addresses, dates of birth, health insurance IDs, patient IDs, SSNs, and provider/service information; affected count not yet disclosed (prior incident 2023 affected 184,000); actor unattributed. DataBreaches.net · The Record
24B infostealer credential dumpHigh24 billion credentials aggregated from 36 breach sources found in exposed Elasticsearch cluster (online June 12, taken down June 15); includes plaintext passwords and session cookies from multiple infostealer campaigns. Malwarebytes · Cybernews
🔓 CRITICAL VULNERABILITIES¶
CVE-2026-12569 — PTC Windchill / FlexPLM — CVSS 10.0 (v3.1) / 9.3 (v4.0) — NEW CISA KEV (June 25)Criticalunauthenticated RCE via deserialization of untrusted data; all Windchill and FlexPLM versions prior to 11.0 M030 are affected; actively exploited in the wild; PTC patch available since June 15; Germany BSI issued emergency advisory overnight June 25. Windchill is the leading PLM platform in aerospace, defense, and automotive manufacturing — exploitation enables IP theft, production disruption, and lateral pivot into OT environments. PTC Advisory · CISA KEV
CVE-2026-20230 — Cisco Unified Communications Manager — CVSS 8.6 — CISA KEV (June 25)CriticalWebDialer SSRF leading to root file-write; exploitation observed in the wild June 21–22; PoC publicly available since patch release June 3; formally added to CISA KEV June 25. Patch immediately. CISA
CVE-2026-41089 — Windows Netlogon RCE — CVSS 9.8 — actively exploitedCriticalunauthenticated RCE enabling full domain-controller takeover from an unauthenticated network position; exploitation in the wild since June 1–2; PoC available. SecurityWeek · MSRC
CVE-2026-34908/34909/34910 — Ubiquiti UniFi OS — CVSS 10.0 each — BOD 26-04 deadline TODAY (June 26)Highchain: unauthenticated network access → unauthorized configuration changes → file traversal → command injection; federal agencies must remediate by end of day today. CISA KEV
CVE-2026-20262 — Cisco SD-WAN — CVSS 9.1 — deadline June 29 (3 days remaining for federal agencies)Highauthenticated command injection; patch available. CISA KEV
🚨 INTELLIGENCE AGENCY ALERTS & POLICY¶
CISA KEV — two additions June 25CriticalCVE-2026-12569 (PTC Windchill/FlexPLM, CVSS 10.0, unauthenticated RCE, actively exploited) and CVE-2026-20230 (Cisco Unified CM, CVSS 8.6, SSRF→root write, actively exploited). Both carry confirmed exploitation evidence. CISA
BOD 26-04 outstanding escalationsCriticalSplunk CVE-2026-20253: federal deadline June 21, now 5 days overdue; Ubiquiti CVE-2026-34908/09/10: deadline TODAY June 26, end of day; Cisco SD-WAN CVE-2026-20262: deadline June 29. Agencies not in compliance must escalate through their respective CISO chains.
NCSC — 75% of UK CNI cyber incidents linked to state actors (RUSI Annual Security Lecture, June 17)HighNCSC CEO Richard Horne: 200+ cyber incidents affecting UK critical national infrastructure managed in the year to May 2026, with ~75% attributed to state actors (Russia, China, Iran). Horne warned adversaries are "pre-positioning inside British systems today to enable rapid exploitation and mass disruption during a future conflict" — citing Volt Typhoon as the canonical playbook. Frontier AI tooling is now accelerating vulnerability discovery and exploitation at scale. Horne called on boards to shift from "risk management" framing to "active contest posture." NCSC · The Record · Infosecurity Magazine
Scattered Spider / TfL trialHighJubair and Flowers entered guilty pleas June 23 (Day 1, London); sentencing July 16. The Record · Krebs on Security
DOJ / Operation Riptide — Huione GroupHighJune 23: $4B+ in illicit cryptocurrency infrastructure disrupted; Lazarus Group and ransomware-as-a-service nexus confirmed. DOJ
FIFA World Cup 2026 — IC3 advisory active; ransomware hitting hospitality sectorHighFBI IC3 PSA260527 (May 27): ~19,000 FIFA-themed spoofed domains created since January 2026 targeting credentials and payment data; at least two hospitality providers have confirmed ransomware incidents linked to World Cup-themed malicious attachments (operational disruptions + customer data exposure). Nation-state APTs (Russia, Iran, China) are actively pre-positioned against event infrastructure. World Cup runs through mid-July across US/Canada/Mexico — transit systems, stadium operations, and hospitality networks remain elevated-risk environments for the duration. IC3 · Dark Reading
CISA ICS advisories — 6 new (June 25, ICSA-26-176)HighDelta Electronics DTM Soft (deserialization → arbitrary code execution, all versions); Daktronics Controller Firmware (below v8.117/v9.43/v10.34: unauthenticated root-level access); H.VIEW HV-500S6 IP Camera (arbitrary code execution + malicious file upload); EVoke Systems EV Charging CSMS (unauthorized admin control/DoS); pydicom pynetdicom library v1.0.0–v3.0.4 (unauthenticated arbitrary file write in medical DICOM environments); OHIF DICOM Viewers (separate medical advisory). OT/ICS and medical imaging operators should review patch availability. CISA ICS advisories
Operation Endgame Phase 2 (StealC + Amadey)HighJune 15–19 multinational law enforcement action (Netherlands, Canada, US, Germany + Europol/Eurojust + Microsoft, Bitdefender, ESET, IBM X-Force); 326 servers + 142 domains dismantled; 27M stolen credentials recovered; $47M crypto restricted; first use of RICO to link two separate malware operations as a single criminal conspiracy. Europol · ESET
🌐 THREAT ACTOR & CAMPAIGN ACTIVITY¶
Ransomware DLS — June 24–26 window:
QilinCritical(#1, 546 YTD) — Pacific Lamp & Supply (manufacturing/US; DLS June 20; 🟥 unverified), Grupo Indi (civil engineering/Mexico; DLS June 15; 🟥 unverified). Prior June named victims: ISOPLUS (pharma/Greece, June 25), Cash Canada (financial/Canada, June 24), Lee International (US, June 23), Central Bank of Libya (SWIFT targeted, confirmed).
ShinyHuntersCriticalDeep Well Services (oilfield/US; 7,000+ records; DLS June 15; no victim statement; 🟥 unverified) brings named-victim total to 36+. Running tally: 36+ named organizations across three attack vectors. Named 2026 victims include: University of Nottingham (454,600 records), Instructure/Canvas (275M users), Council of Europe (297 GB HR data), Charter/Spectrum (40-42M records), One Medical (8.8TB elderly PHI), NAIC (3.1TB insurance regulatory data), ADT (5.5M customers), DentaQuest (2.6M members' PHI), Madison Square Garden (26M records), Rockstar Games (78.6M records), Pitney Bowes (8.2M), Wynn Resorts (800K+), and 20+ more.
The GentlemenHigh(#2, ~335 YTD) — 9 new named victims posted June 25 (BDS CZ, Bell Hardware, Beran Concrete, Au Vieux Campeur, Al-Dhow, Gegenbauer IT, AmiGest, Canada Wide Media, GIA Partners); Mahajak Development (technology distribution/Thailand) added June 15.
AkiraHigh(#3, ~228 YTD) — JMS Southeast (business services/US; temperature measurement products; ~25GB; employee PII + government entity NDAs; DLS June 25) and Padget Technologies (robotics/automation/US; DLS June 25) are the two newest named victims. Also active: DragonForce (#4, 248 YTD) with Synex International Pvt Ltd (MEP systems/solar energy/India; 13.63GB; DLS June 1 — newly confirmed); Abyss (School Facility Consultants, education/US California, DLS June 1 — newly confirmed); INC Ransom (Horizon Family Medical Group 7TB + Horizon Eye Care); Stormous (Maglificio Liliana full-group compromise across 4 Italian domains); Anubis (Quest Health Solutions, 239 GB); SafePay (#6, Kawai Musical Instruments/Japan + Hugh Stirling Ltd/UK, both June 15). Nova added Kedah State Government (Malaysia, June 16). Aur0ra added ALS Global (testing/inspection/Australia; 500+ employees' home directories + credentials + lab data; DLS June 19; breach confirmed by ALS, ACSC notified) and NationsBuilders Insurance Services (US specialty insurance; 2.7M file-tree entries claimed; DLS June 22 — 🟥 verify before treating as breach). ShadowByt3$ added Cropwise (Syngenta Group's digital farming platform; agri-tech/global; 10.4 MB incl. GIS/field data/credentials; DLS June 2 — 🟥 unverified).
APT / Nation-state:
DPRK Gaslight macOS malwareCriticalSentinelOne June 25: Rust-based backdoor with prompt-injection AI-evasion to defeat EDR, Telegram C2, Keychain and browser credential harvesting; targets cryptocurrency sector. Represents a generation leap in DPRK tooling sophistication. SentinelOne
Phantom TaurusHighnewly documented Chinese APT (Dark Reading June 25); targets government, military, and embassy networks across Africa, Middle East, and Asia; early-stage attribution, further technical detail expected. Dark Reading
MuddyWater / Chaos false-flagHighconfirmed by NCC Group Threat Pulse + Rapid7: Iran MOIS-linked MuddyWater operated under Chaos ransomware branding in early 2026 for state-espionage operations; used Teams interactive screen-sharing for MFA credential harvest. Chaos tracker entries should be reviewed for misattribution.
Edgecution IAB — new access tool linked to Payouts King ransomwareHighZscaler ThreatLabz (June 25): an IAB associated with Payouts King (ex-BlackBasta, ~100 victims through May 2026) deploys a malicious Microsoft Edge extension ("Edge Monitoring Agent") to break out of the browser sandbox via Chrome Native Messaging. Attack chain: Teams IT-support impersonation → fake Outlook update page → Python 3.13 backdoor + extension → full shell/file/process/exfiltration access on the host. No CVE; exploits a legitimate browser protocol. Top targeted sectors: manufacturing, healthcare, construction. Zscaler ThreatLabz · BleepingComputer · SC Media
SafePay — Tokyo Civil Co., Ltd. (DLS June 26)MediumJapanese public-infrastructure civil engineering firm (river works, bridges, water supply, Edogawa City, Tokyo); SafePay DLS claim June 26; internal org data and employee files claimed; 🟥 unverified — no Tokyo Civil statement. CYFIRMA · ransomware.live
🌍 GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense · cyber · economics.
PTC Windchill CVSS 10.0 exploitation closes the gap between digital intrusion and factory-floor IP theft.CriticalWindchill is the backbone of engineering-change management in aerospace, defense, and automotive manufacturing across NATO allies; unauthenticated RCE at CVSS 10.0 means any internet-exposed PLM instance is a potential entry point into CAD/CAM archives, supplier networks, and production schedules. Germany BSI's emergency overnight advisory reflects awareness that supply-chain compromise at the design layer — not the shop-floor layer — is where strategic IP theft begins. Defense-industrial clients should treat Windchill patch compliance as critical-infrastructure remediation, not a routine IT update cycle. PTC Advisory · CISA KEV
ShinyHunters' NAIC breach illustrates how financial-sector regulatory data functions as state intelligence.HighInsurance supervisory filings contain carrier solvency ratios, reserve liabilities, and regulatory correspondence — data that supports competitive intelligence, market manipulation, or financial-stability analysis by a state actor. The regulatory-data-as-intelligence thesis (insurance + central bank + pension data) is a structural shift in targeting logic; treat insurance regulators and SROs as high-value soft targets for the same adversaries that target financial institutions. Insurance Journal
Iranian MOIS "Seedworm" backdoors pre-planted before the G7 Versailles ceasefire survive the diplomatic pause.HighMOIS embedded persistent access in a US bank, US airport, NGOs, and a defense-software company during the kinetic conflict period; those footholds were not rotated before the ceasefire. Post-conflict phases historically see the highest-tempo collection surges as intelligence agencies exploit pre-positioned access before discovery. Executives with dual-use or defense exposure should assume lateral-movement risk from existing Dindoor/Fakeset implants active since before June 17. CyberScoop · CSIS
Phantom Taurus targeting of African and Middle Eastern government infrastructure reflects China's BRI-adjacency espionage doctrine.HighAfrica and the Middle East are arenas where China is simultaneously deepening infrastructure investment (ports, rails, data centers) and expanding cyber-espionage — the overlap is not coincidental. Government procurement databases, diplomatic communications, and port/logistics access systems in these regions carry high intelligence value for trade-route control and counter-influence operations. Watch for follow-on attribution from Mandiant or CrowdStrike. Dark Reading
NCSC's "75% state-linked" CNI figure signals that the UK is now treating cyberspace as a pre-conflict operational domain, not a peacetime risk management problem.HighThree-quarters of UK critical infrastructure incidents traceable to Russia, China, and Iran — with explicit pre-positioning warnings — means the threat model for UK-exposed organisations has permanently shifted from "breach probability" to "adversary dwell-time." The board-level implication: existing exposure to state-adjacent suppliers, joint ventures, or digital infrastructure in these countries now carries an attribution risk that is no longer theoretical. Companies with dual-use or defense adjacency in the UK should audit FortiGate and edge-device postures immediately given the FortiBleed-to-Gentlemen targeting chain active in June 2026. NCSC · The Record
DPRK's Gaslight macOS backdoor signals that cryptocurrency targeting has matured beyond web3-specific tooling.MediumRust binaries, prompt-injection EDR evasion, and Keychain harvesting represent a generation leap from prior DPRK tools. This is not opportunistic theft; it is systematic capability investment aimed at institutional custodians and high-net-worth targets in Western markets. Financial institutions with crypto custody or fintech exposure should verify macOS endpoint controls and review Telegram-based C2 egress in network telemetry. SentinelOne Labs
M&A activity
Socure → Fravity—
Brinqa → PlexTrac—
Munich Re (via HSB) → $575M—
Fortinet → Virtue AI—