Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (6 June 2026)
Published: Loading…
At a Glance
- CVE-2026-20245 in Cisco Catalyst SD-WAN Manager allows root command execution via crafted file upload, with no patch available.
- UNC3753 targeted dozens of US law firms with vishing and RMM tool abuse, escalating to physical USB-based data theft.
- IronWorm, a Rust infostealer in 37 trojanised npm packages, used an eBPF rootkit and Tor C2 to harvest developer credentials.
- VerdantBamboo deployed BRICKSTORM backdoors on edge appliances including an Egnyte Storage Sync system, persisting undetected for 18 months.
- PCPJack converted 230 AWS, GCP, and Azure servers into SMTP relay proxies using Chisel reverse SOCKS5 tunnels.
- ShinyHunters leaked 234 GB of DentaQuest data, while Dashlane disclosed encrypted vault theft affecting some customer accounts.
Summary
CVE-2026-20245 in Cisco Catalyst SD-WAN Manager remains unpatched while active exploitation has been confirmed. The command injection flaw allows authenticated local attackers with netadmin privileges to execute arbitrary commands as root via a crafted file upload. It is the seventh Cisco SD-WAN vulnerability confirmed exploited in 2026 and can be chained with CVE-2026-20182 and CVE-2026-20127.
UNC3753 (Luna Moth, Silent Ransom Group) conducted a sustained vishing and extortion campaign against US law firms and financial services organisations from January through May 2026. Actors impersonated IT helpdesk staff to deploy RMM tools including AnyDesk and Zoho Assist and exfiltrate data via WinSCP and Rclone. In a confirmed escalation corroborated by an FBI Cyber FLASH Alert, operatives posed as on-site IT technicians and attempted USB-based data theft at victim premises.
IronWorm, a Rust-built infostealer, was embedded in 37 trojanised npm packages targeting developers in the Arweave/WeaveDB ecosystem. The malware harvested 86 environment variables spanning cloud, CI/CD, and AI provider credentials, concealed activity using an eBPF kernel rootkit, and communicated via Tor. A separate npm supply-chain attack involving a Miasma worm variant also hit the ecosystem, with over 50 packages affected across both incidents.
Chinese threat actor VerdantBamboo (UNC5221, WARP PANDA) maintained undetected access to an Egnyte Storage Sync appliance and a managed service provider's pfSense firewall for at least 18 months using BRICKSTORM backdoors. Two previously undocumented malware families, PLENET and AGENTPSD, were also deployed across compromised Linux and BSD appliances. After initial remediation, the actor regained access via an internet-exposed firewall administrative interface and deployed PLENET to a Synology NAS device. A separate espionage-focused cluster, OP-512, was assessed with moderate to high confidence as China-linked and observed deploying custom web shells against Microsoft IIS servers.
PCPJack hijacked 230 Linux servers across AWS, GCP, and Azure to build a covert SMTP relay network using Chisel reverse SOCKS5 tunnels, with a verification daemon syncing confirmed proxies every five minutes. Multiple data breach disclosures also featured prominently: ShinyHunters leaked approximately 234 GB of DentaQuest data affecting 2.6 million individuals, and Dashlane disclosed a brute-force attack that resulted in encrypted password vaults being copied from some customer accounts. An IDOR vulnerability in an RCI Hospitality IIS web server exposed personal records of approximately 40,000 individuals including Social Security numbers and driver's licence details.
Chrome 149 patched 429 vulnerabilities, including over 100 rated critical or high severity. A critical remote code execution flaw, CVE-2026-3300 (CVSS 9.8), in the WordPress Everest Forms Pro plugin is under active exploitation affecting installations up to version 1.9.12. CISA separately warned of active exploitation of a high-severity SolarWinds Serv-U vulnerability being used to crash servers.
Highlights of the Day
PCPJack Campaign Expanded: 230 Cloud Servers Turned Into Hidden Email Relay Network
Hunt.io researchers discovered an unauthenticated open directory on a server linked to the PCPJack threat actor, exposing a 12-file toolkit including source code, compiled Chisel binaries, and deployment state logs confirming 230 successful compromises across AWS, GCP, and Azure in a single March 2026 deployment run. The operation converts hijacked Linux servers into SMTP relay proxies using unmodified Chisel reverse SOCKS5 tunnels, with a persistent verification daemon testing each tunnel against smtp.gmail.com:587 and syncing confirmed proxies via SCP every five minutes to a downstream server at 38.242.204[.]245. Three generations of Python deployer scripts recovered from the server reveal iterative development, with infrastructure pivots via JARM TLS fingerprints and a shared "OpenClaw CA" certificate identifying additional related servers across Contabo, Hetzner, and Tencent Cloud hosting.
Cisco Discloses Seventh Exploited SD-WAN Zero-Day of 2026
CVE-2026-20245, an unpatched command injection vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, allows an authenticated local attacker with 'netadmin' privileges to execute arbitrary commands as root by uploading a specially crafted file. The flaw has been observed in limited active exploitation resulting in configuration changes pushed to edge devices, and can be chained with previously exploited vulnerabilities CVE-2026-20182 or CVE-2026-20127 to satisfy the privilege requirement. Mandiant reported the vulnerability to Cisco, whose PSIRT identified in-the-wild exploitation in June 2026; no patches or workarounds are currently available.
RCI Hospitality Data Breach Exposes 40,000 Records via IDOR Vulnerability
RCI Internet Services, a subsidiary of US adult nightclub operator RCI Hospitality Holdings, suffered a data breach on 19 March 2026 when an insecure direct object reference (IDOR) vulnerability in an IIS web server allowed unauthorised access to personal records. The breach, discovered on 13 May 2026, exposed names, contact information, dates of birth, Social Security numbers, and driver's licence numbers belonging to approximately 40,178 independent contractors. The FBI has been notified and RCI has filed breach notifications with the Maine Attorney General, with 257 Maine residents among those affected.
Luna Moth Vishing Campaign Hits US Law Firms with Physical Office Intrusions
Mandiant and Google Threat Intelligence Group have attributed a financially motivated data theft and extortion campaign active from January through May 2026 to UNC3753, also known as Luna Moth and Silent Ransom Group, targeting dozens of US legal, professional, and financial services organisations. The threat cluster initiates attacks via invoice-themed email lures followed by vishing calls in which actors impersonate internal IT helpdesk staff, directing targets to install RMM tools including AnyDesk, Bomgar, and Zoho Assist before exfiltrating data via WinSCP, Rclone, or direct uploads to actor-controlled cloud storage accounts. In a documented escalation corroborated by an FBI Cyber FLASH Alert, actors have also sent individuals posing as IT technicians to victim premises to exfiltrate data directly to USB storage media when remote social engineering attempts fail.
IronWorm: Rust Infostealer Uses eBPF Rootkit and Tor C2 in npm Supply-Chain Attack
JFrog researchers discovered IronWorm, a custom Rust-built infostealer embedded in 37 trojanised npm packages published via the compromised asteroiddao account, targeting developers in the Arweave/WeaveDB ecosystem through preinstall hooks that execute a hidden binary without user interaction. The malware harvests 86 environment variables covering cloud, CI/CD, and AI provider credentials including Anthropic, OpenAI, and Gemini keys, targets the Exodus desktop wallet via JavaScript injection to capture seed phrases, and exfiltrates data over a Tor-based C2 channel while concealing processes and network connections using an eBPF kernel rootkit. Using stolen GitHub credentials, IronWorm pushed 57 backdated malicious commits across nine organisations, modifying build scripts in npm, PyPI, and Cargo packages to propagate itself, with the operator's own BIP-39 wallet recovery phrase hardcoded into the malware's credential skip-list.
Chinese Threat Actor VerdantBamboo Maintained 18-Month Access via Edge Appliance Backdoors
Volexity's incident response investigation revealed that VerdantBamboo (also tracked as WARP PANDA and UNC5221) compromised an Egnyte Storage Sync appliance and a victim organisation's managed service provider pfSense firewall, deploying BRICKSTORM backdoors that persisted undetected for at least 18 months on both devices. The threat actor exploited a sudo misconfiguration on the Storage Sync appliance allowing arbitrary file writes as root, used the appliance's SOCKS5 proxy to access the victim's Microsoft 365 environment whilst bypassing Conditional Access policies, and deployed two previously undocumented malware families: PLENET, a .NET Core Native AOT backdoor, and AGENTPSD, a PyInstaller-packaged Python reverse shell. After initial remediation, VerdantBamboo regained access by connecting to the victim's internet-exposed firewall administrative interface using stolen unprotected credentials, then pivoted internally to deploy PLENET on a Synology NAS device.
Daily Coverage