Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (25 June 2026)
Published: Loading…
At a Glance
- Operation Endgame dismantled over 200 Amadey and StealC command-and-control domains, recovering 27 million stolen credentials in a Europol-Microsoft-led action.
- CVE-2026-20230 in Cisco Unified CM is being actively exploited via WebDialer SSRF to drop webshells and achieve unauthenticated remote code execution.
- A zero-day flaw CVE-2026-20245 in Cisco Catalyst SD-WAN Manager enabled attackers to escalate privileges to root via malicious CSV upload.
- The codfish/semantic-release-action GitHub Action was compromised on June 24, hijacking CI/CD runners to steal OIDC tokens and PATs across v2–v5 tags.
- KDDI confirmed unauthorized access to its managed email platform exposed up to 14.2 million email addresses and passwords across six Japanese ISPs.
- Mistic backdoor, active since April 2026, is deployed by Woodgnat access broker and feeds Qilin, Rhysida, Akira, and Black Basta ransomware operations.
Summary
A Europol- and Microsoft-led action under Operation Endgame has dismantled more than 200 command-and-control servers and domains supporting the StealC and Amadey malware operations. Law enforcement partners recovered approximately 27 million stolen credentials as part of the takedown. The operation involved private sector participants including ESET, Bitsight, Bitdefender, and IBM X-Force, and Microsoft applied RICO statutes in a novel legal approach targeting the full cybercrime supply chain.
Two separate Cisco vulnerabilities are under active exploitation. CVE-2026-20230, a server-side request forgery flaw in Unified Communications Manager, is being exploited via automated sweeps through Tor to drop webshells and achieve remote code execution. A separate zero-day, CVE-2026-20245 in Cisco Catalyst SD-WAN Manager, was used by a threat actor to escalate from compromised administrative access to root-level control via a malicious CSV upload, with anti-forensic techniques employed throughout the intrusion.
The codfish/semantic-release-action GitHub Action was compromised on June 24 through a force-pushed commit and tag repointing affecting versions v2 through v5. The malicious payload steals GitHub OIDC tokens and personal access tokens from CI/CD runners, exfiltrating data via commit-based dead-drop channels. A separate class of Cordyceps CI/CD workflow weaknesses was also disclosed, enabling unauthenticated attackers to hijack workflows across repositories belonging to Microsoft, Google, and Apache.
KDDI confirmed unauthorized access to its managed email infrastructure, exposing up to 14.2 million email addresses and passwords across six Japanese ISPs. The breach exploited a vulnerability in third-party software used on the email platform. Separately, a supply-chain attack on market intelligence platform Klue compromised OAuth tokens and exposed customer data stored in Salesforce environments at LastPass, BeyondTrust, and over a dozen other organisations.
The Mistic backdoor, active since April 2026, has been linked to the Woodgnat initial access broker and feeds ransomware operations including Qilin, Rhysida, Akira, Interlock, 8Base, and Black Basta. The backdoor executes entirely in memory and includes a self-deletion kill switch. The FortiBleed campaign continues to target Fortinet FortiGate firewalls using CyberStrike Harvester tooling to conduct credential stuffing, configuration harvesting, and offline cracking pipelines against VPN and internal network credentials.
A phishing attack on healthcare technology firm Xsolis resulted in unauthorised network access affecting 1.4 million individuals. The SharkLoader malware family, identified in the StrikeShark campaign, is being used to deploy Cobalt Strike Beacon by exploiting internet-facing applications including Microsoft Exchange and SharePoint across government and diplomatic targets in multiple countries. CISA issued warnings for actively exploited critical flaws in Ubiquiti UniFi OS and Lantronix EDS5000 Series devices, with CVE-2025-67038 in Lantronix carrying a CVSS score of 9.8.
Highlights of the Day
Microsoft disrupts StealC and Amadey infostealer infrastructure
Microsoft reported a coordinated disruption with Europol and partners targeting StealC and Amadey infrastructure, taking down over 200 command-and-control domains and IPs across operations. StealC operates as a malware-as-a-service infostealer collecting browser credentials, cookies and tokens, while Amadey acts as a modular loader distributing StealC and other payloads. Infostealer operations harvest corporate credentials and session cookies, enabling account takeover and MFA bypass, with stolen data rapidly monetised and reused for enterprise intrusion campaigns.
Mistic backdoor linked to ransomware access broker operations
Backdoor.Mistic has been observed in intrusions since April 2026 and is deployed via DLL sideloading using MpExtMs.exe and EndpointDlp.dll masquerade. It has been seen alongside ModeloRAT activity linked to Woodgnat access broker operations associated with Qilin ransomware deployments across multiple sectors. The backdoor executes payloads entirely in memory, includes a kill switch for self-deletion, and supports file operations and remote command execution.
Edgecution browser extension delivers Python backdoor via Edge hijack
Initial access uses Microsoft Teams impersonation with fake update portal delivering scripts and encrypted ZIP containing Python runtime and Edge extension deployed via scheduled task launching headless Edge. The extension uses Chrome native messaging to execute a Python backdoor via batch host, with registry AppKey decrypting strings, and communicates over WebSockets on AWS CloudFront C2 infrastructure. Commands enable system information collection, process enumeration, PowerShell execution and file operations using ephemeral Python processes per request.
Cisco Unified CM flaw exploited for root file writes
Attackers are exploiting CVE-2026-20230 in Cisco Unified Communications Manager and Unified CM SME, using crafted HTTP requests to trigger unauthenticated SSRF. Exploitation requires Cisco WebDialer service enabled, with researchers observing active attacks using proof-of-concept file:// payloads enabling arbitrary file writes toward root. Cisco patched versions 14SU6 and 15SU5, while SSD Secure Disclosure detailed flaw enabling unauthenticated file writes and potential code execution via WebDialer component.
FortiBleed campaign harvests FortiGate credentials via CyberStrike tools
FortiBleed credential compromise campaign targeting Fortinet FortiGate devices using CyberStrike Harvester and sniffer tooling to extract configurations and authentication material. Operators use credential stuffing, password spraying, configuration exports, and offline cracking pipelines to recover VPN, Kerberos and SMB credentials for internal access validation. Arctic Wolf Labs reverse engineered CyberStrike Harvester components, linking FortiGate capture pipelines to global credential monetisation and internal network exfiltration workflows.
StrikeShark Campaign Uses SharkLoader to Deploy Cobalt Strike
Researchers identified StrikeShark campaign deploying SharkLoader loader to install Cobalt Strike Beacon exploiting Microsoft Exchange, SharePoint, Openfire and other internet-facing applications. Intrusions leveraged CVE-2021-26855, CVE-2023-32315 and CVE-2024-36401 alongside custom droppers impersonating installers establishing persistence via DLL sideloading and scheduled tasks. SharkLoader modules load encrypted components deploy Cobalt Strike Beacon in memory and install API hooks for evasion with attribution remaining low confidence.
Cisco SD-WAN Zero-Day Enables Root via Malicious CSV Upload
In early 2026, attackers accessed Cisco Catalyst SD-WAN Manager via rogue peering connections enabling SSH access with vmanage-admin and altering admin credentials. Using CVE-2026-20245, attackers escalated to root via malicious CSV upload that modified system authentication files and added a privileged troot account. Mandiant observed anti-forensic actions including deletion of payload files, restoration of modified configurations, and execution of validation scripts to remove intrusion traces.
Leaked PyPI Tokens Expose 125 Packages Across GitHub
GitGuardian analysed 3,714 decoded PyPI API tokens sourced from GitHub and Docker Hub, identifying 62 still-valid credentials tied to accounts and projects via macaroon restrictions. Validation using PyPI upload simulation distinguished active tokens via HTTP 400 responses, revealing 62 valid tokens mapped to 125 packages generating 25,000 monthly downloads. PyPI security team revoked exposed credentials and notified affected users after coordinated disclosure, while GitGuardian highlighted gaps in GitHub secret scanning coverage.
Codfish Semantic-Release Action Compromised via Tag Hijacking
On 24 June 2026, codfish/semantic-release-action was compromised through force-pushed commits and tag repointing affecting versions v2 to v5, executing attacker-controlled code in GitHub Actions runners. The action.yml was replaced with a composite workflow that installs Bun via setup-bun and runs a heavily obfuscated index.js payload stealing CI/CD secrets. The payload extracts GitHub OIDC tokens and personal access tokens (PATs), using GitHub commit-based dead-drop C2 channels for exfiltration. The compromise enables credential theft and potential lateral movement across connected developer environments via repository-level execution and workflow abuse.
Daily Coverage