Press "Enter" to skip to content

OSINT / CyberSec report 27.06.2026 00:07

1. Attackers are actively exploiting a critical vulnerability in Cisco Unified CM and Unified CM SME deployments that enables server side request forgery and privilege escalation to root (Dark Reading).

2. A critical code injection vulnerability in Lantronix EDS5000 series devices tracked as CVE 2025 67038 is being actively exploited in the wild (The Hacker News).

3. Threat actors exploited the Cisco Catalyst SD WAN zero day vulnerability CVE 2026 20245 to gain root access on targeted infrastructure (The Hacker News).

4. The Russian state sponsored group Turla is deploying a new .NET backdoor called STOCKSTAY against government and military organizations in Ukraine (The Hacker News).

5. A new Rust based macOS malware named Gaslight uses prompt injection to disrupt and deceive AI assisted malware analysis tools (The Hacker News).

6. Polish authorities arrested four members of an organized cybercrime group responsible for SIM swapping attacks that resulted in millions of dollars in cryptocurrency theft (Bleeping Computer).

7. An ad blocker extension for Google Chrome with over 10 million installs was found to contain dormant script injection capabilities (The Hacker News).

8. Law enforcement agencies disrupted the infrastructure of the Amadey and StealC malware operations, recovering 27 million stolen credentials (The Hacker News).

9. Attackers are abusing the Shopify order tracking app Shop to conduct callback phishing attacks by inserting fake purchase receipts (Bleeping Computer).

10. A new backdoor called Mistic has been identified in financially motivated campaigns targeting the insurance, education, and IT sectors (The Hacker News).

11. Researchers identified a CI/CD workflow vulnerability pattern codenamed Cordyceps that exposes hundreds of GitHub repositories to supply chain attacks (The Hacker News).

12. Russian authorities used Cellebrite forensic tools to access the iPhone of a detained activist months after the company announced it would stop selling services to Russia (The Hacker News).

13. A hybrid toolkit including the custom TinyRCT backdoor is being used by attackers to target government entities and critical infrastructure in Southeast Asia (Unit 42).

14. A malicious Microsoft Edge extension named Edgecution was used to escape the browser sandbox and deploy a Python based backdoor (Bleeping Computer).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *