CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (25 June 2026)

Published: Loading…

At a Glance

  • Operation Endgame dismantled over 200 Amadey and StealC command-and-control domains, recovering 27 million stolen credentials in a Europol-Microsoft-led action.
  • CVE-2026-20230 in Cisco Unified CM is being actively exploited via WebDialer SSRF to drop webshells and achieve unauthenticated remote code execution.
  • A zero-day flaw CVE-2026-20245 in Cisco Catalyst SD-WAN Manager enabled attackers to escalate privileges to root via malicious CSV upload.
  • The codfish/semantic-release-action GitHub Action was compromised on June 24, hijacking CI/CD runners to steal OIDC tokens and PATs across v2–v5 tags.
  • KDDI confirmed unauthorized access to its managed email platform exposed up to 14.2 million email addresses and passwords across six Japanese ISPs.
  • Mistic backdoor, active since April 2026, is deployed by Woodgnat access broker and feeds Qilin, Rhysida, Akira, and Black Basta ransomware operations.

Summary

A Europol- and Microsoft-led action under Operation Endgame has dismantled more than 200 command-and-control servers and domains supporting the StealC and Amadey malware operations. Law enforcement partners recovered approximately 27 million stolen credentials as part of the takedown. The operation involved private sector participants including ESET, Bitsight, Bitdefender, and IBM X-Force, and Microsoft applied RICO statutes in a novel legal approach targeting the full cybercrime supply chain.

Two separate Cisco vulnerabilities are under active exploitation. CVE-2026-20230, a server-side request forgery flaw in Unified Communications Manager, is being exploited via automated sweeps through Tor to drop webshells and achieve remote code execution. A separate zero-day, CVE-2026-20245 in Cisco Catalyst SD-WAN Manager, was used by a threat actor to escalate from compromised administrative access to root-level control via a malicious CSV upload, with anti-forensic techniques employed throughout the intrusion.

The codfish/semantic-release-action GitHub Action was compromised on June 24 through a force-pushed commit and tag repointing affecting versions v2 through v5. The malicious payload steals GitHub OIDC tokens and personal access tokens from CI/CD runners, exfiltrating data via commit-based dead-drop channels. A separate class of Cordyceps CI/CD workflow weaknesses was also disclosed, enabling unauthenticated attackers to hijack workflows across repositories belonging to Microsoft, Google, and Apache.

KDDI confirmed unauthorized access to its managed email infrastructure, exposing up to 14.2 million email addresses and passwords across six Japanese ISPs. The breach exploited a vulnerability in third-party software used on the email platform. Separately, a supply-chain attack on market intelligence platform Klue compromised OAuth tokens and exposed customer data stored in Salesforce environments at LastPass, BeyondTrust, and over a dozen other organisations.

The Mistic backdoor, active since April 2026, has been linked to the Woodgnat initial access broker and feeds ransomware operations including Qilin, Rhysida, Akira, Interlock, 8Base, and Black Basta. The backdoor executes entirely in memory and includes a self-deletion kill switch. The FortiBleed campaign continues to target Fortinet FortiGate firewalls using CyberStrike Harvester tooling to conduct credential stuffing, configuration harvesting, and offline cracking pipelines against VPN and internal network credentials.

A phishing attack on healthcare technology firm Xsolis resulted in unauthorised network access affecting 1.4 million individuals. The SharkLoader malware family, identified in the StrikeShark campaign, is being used to deploy Cobalt Strike Beacon by exploiting internet-facing applications including Microsoft Exchange and SharePoint across government and diplomatic targets in multiple countries. CISA issued warnings for actively exploited critical flaws in Ubiquiti UniFi OS and Lantronix EDS5000 Series devices, with CVE-2025-67038 in Lantronix carrying a CVSS score of 9.8.

Highlights of the Day

Microsoft disrupts StealC and Amadey infostealer infrastructure

Microsoft reported a coordinated disruption with Europol and partners targeting StealC and Amadey infrastructure, taking down over 200 command-and-control domains and IPs across operations. StealC operates as a malware-as-a-service infostealer collecting browser credentials, cookies and tokens, while Amadey acts as a modular loader distributing StealC and other payloads. Infostealer operations harvest corporate credentials and session cookies, enabling account takeover and MFA bypass, with stolen data rapidly monetised and reused for enterprise intrusion campaigns.

Mistic backdoor linked to ransomware access broker operations

Backdoor.Mistic has been observed in intrusions since April 2026 and is deployed via DLL sideloading using MpExtMs.exe and EndpointDlp.dll masquerade. It has been seen alongside ModeloRAT activity linked to Woodgnat access broker operations associated with Qilin ransomware deployments across multiple sectors. The backdoor executes payloads entirely in memory, includes a kill switch for self-deletion, and supports file operations and remote command execution.

Edgecution browser extension delivers Python backdoor via Edge hijack

Initial access uses Microsoft Teams impersonation with fake update portal delivering scripts and encrypted ZIP containing Python runtime and Edge extension deployed via scheduled task launching headless Edge. The extension uses Chrome native messaging to execute a Python backdoor via batch host, with registry AppKey decrypting strings, and communicates over WebSockets on AWS CloudFront C2 infrastructure. Commands enable system information collection, process enumeration, PowerShell execution and file operations using ephemeral Python processes per request.

Cisco Unified CM flaw exploited for root file writes

Attackers are exploiting CVE-2026-20230 in Cisco Unified Communications Manager and Unified CM SME, using crafted HTTP requests to trigger unauthenticated SSRF. Exploitation requires Cisco WebDialer service enabled, with researchers observing active attacks using proof-of-concept file:// payloads enabling arbitrary file writes toward root. Cisco patched versions 14SU6 and 15SU5, while SSD Secure Disclosure detailed flaw enabling unauthenticated file writes and potential code execution via WebDialer component.

FortiBleed campaign harvests FortiGate credentials via CyberStrike tools

FortiBleed credential compromise campaign targeting Fortinet FortiGate devices using CyberStrike Harvester and sniffer tooling to extract configurations and authentication material. Operators use credential stuffing, password spraying, configuration exports, and offline cracking pipelines to recover VPN, Kerberos and SMB credentials for internal access validation. Arctic Wolf Labs reverse engineered CyberStrike Harvester components, linking FortiGate capture pipelines to global credential monetisation and internal network exfiltration workflows.

StrikeShark Campaign Uses SharkLoader to Deploy Cobalt Strike

Researchers identified StrikeShark campaign deploying SharkLoader loader to install Cobalt Strike Beacon exploiting Microsoft Exchange, SharePoint, Openfire and other internet-facing applications. Intrusions leveraged CVE-2021-26855, CVE-2023-32315 and CVE-2024-36401 alongside custom droppers impersonating installers establishing persistence via DLL sideloading and scheduled tasks. SharkLoader modules load encrypted components deploy Cobalt Strike Beacon in memory and install API hooks for evasion with attribution remaining low confidence.

Cisco SD-WAN Zero-Day Enables Root via Malicious CSV Upload

In early 2026, attackers accessed Cisco Catalyst SD-WAN Manager via rogue peering connections enabling SSH access with vmanage-admin and altering admin credentials. Using CVE-2026-20245, attackers escalated to root via malicious CSV upload that modified system authentication files and added a privileged troot account. Mandiant observed anti-forensic actions including deletion of payload files, restoration of modified configurations, and execution of validation scripts to remove intrusion traces.

Leaked PyPI Tokens Expose 125 Packages Across GitHub

GitGuardian analysed 3,714 decoded PyPI API tokens sourced from GitHub and Docker Hub, identifying 62 still-valid credentials tied to accounts and projects via macaroon restrictions. Validation using PyPI upload simulation distinguished active tokens via HTTP 400 responses, revealing 62 valid tokens mapped to 125 packages generating 25,000 monthly downloads. PyPI security team revoked exposed credentials and notified affected users after coordinated disclosure, while GitGuardian highlighted gaps in GitHub secret scanning coverage.

Codfish Semantic-Release Action Compromised via Tag Hijacking

On 24 June 2026, codfish/semantic-release-action was compromised through force-pushed commits and tag repointing affecting versions v2 to v5, executing attacker-controlled code in GitHub Actions runners. The action.yml was replaced with a composite workflow that installs Bun via setup-bun and runs a heavily obfuscated index.js payload stealing CI/CD secrets. The payload extracts GitHub OIDC tokens and personal access tokens (PATs), using GitHub commit-based dead-drop C2 channels for exfiltration. The compromise enables credential theft and potential lateral movement across connected developer environments via repository-level execution and workflow abuse.

Daily Coverage

Developments
Operation Endgame ActionCisco Unified Cm ExploitationCisco Sd-Wan Zero-DayCodfish Action Compromise
Vulnerabilities
CVE-2026-20230Cisco Unified Communications Manager N/ACVE-2026-20245Cisco Catalyst Sd-Wan Controller 20.6.4 (High)CVE-2025-67038N/A N/A (Critical)CVE-2026-8461Ffmpeg (High)CVE-2021-26855Microsoft Exchange Server 2016 Cumulative Update 19 15.01.0 (Critical)CVE-2023-32315Openfire >= 3.10.0, < 4.6.8CVE-2024-36401Geoserver >= 2.23.0, < 2.23.6CVE-2026-50263X_Server 21.1.23 (Medium)CVE-2026-50262An Out-Of-Bounds Read Flaw Was Found In The X.org X Server And Xwayland In __Glxdisp_Changedrawableattributes(). A Wrong Size Validation Check Can Read A Client-Controlled Number Of Bytes, Exceeding The Request Buffer, Leading To Information Disclosure. A Write Path Also Exists But Requires Byte-Swapped Clients Which Is Disabled By Default.CVE-2026-50261X_Server 21.1.23 (High)
Threat Groups
PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.MuddyWaterMuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.