Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (29 June 2026)
Published: Loading…
At a Glance
- KDDI's breach of a shared email system exposed up to 14.2 million accounts across five Japanese ISPs via a third-party software flaw.
- Russian intelligence ran a long-term campaign targeting Ukrainian, European, and US officials' messaging accounts, uncovered jointly by the SSU and FBI.
- DCloud Uni-App framework underpins over 236,000 fraudulent investment domains including fake exchanges, wallet drainers, and recruitment scams.
- A DNS prompt injection attack against Claude Code used a Base64-encoded TXT record to deliver a reverse shell without storing payloads in the repository.
- The Athena AI coalition identified over 20,000 open source security findings and produced more than 2,000 patches across 500 projects.
Summary
KDDI Corporation disclosed a breach of a shared email system affecting five Japanese internet service providers. Attackers exploited a vulnerability in third-party software, potentially exposing up to 14.2 million email accounts across STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE. Exposed data includes email addresses and passwords stored in hashed or encrypted form.
The DCloud Uni-App framework has been linked to more than 236,000 domains hosting investment fraud globally. Identified schemes include fake exchanges, wallet drainers, and recruitment-based operations such as LSSC and Yuechi. Infrastructure relies on mainstream cloud providers alongside bulletproof hosting services including CTG Server.
A DNS-based prompt injection attack was demonstrated against Claude Code using a clean GitHub repository. The agent was directed to execute a setup script that retrieved a Base64-encoded reverse shell payload from a DNS TXT record at runtime. The technique exposed environment variables, API keys, and local credentials while leaving no malicious content in the repository itself.
The Athena coalition of approximately two dozen companies has used frontier AI models to surface more than 20,000 open source security findings and generate over 2,000 patches across 500 projects. A first wave of vulnerability disclosures is scheduled within weeks. The Linux Foundation-backed Akrites initiative is establishing coordinated vulnerability disclosure processes to manage the accelerating pace of AI-discovered flaws.
The SSU and FBI jointly uncovered a long-running Russian intelligence operation targeting messaging accounts of government officials, military personnel, politicians, and activists. The campaign swept across Ukraine, Europe, and the United States. Attackers used fake support texts to harvest credentials from targets' messaging applications.
Highlights of the Day
DNS Prompt Injection Hijacks AI Coding Agent
0DIN demonstrated an indirect prompt injection attack against Claude Code in which a benign-looking GitHub repository directed the agent to execute python3 -m axiom init, leading to a setup script that retrieved and executed a DNS TXT record at runtime. The DNS record contained a Base64-encoded reverse shell payload, allowing shell access with the developer's user privileges and exposure of environment variables, API keys, credentials and local configuration files, while no malicious payload was stored in the repository itself.
DCloud Framework Underpins Global Scam Infrastructure
Infoblox Threat Intelligence reported that DCloud Uni-App has been used to build large-scale scam infrastructure linked to cases like RainbowEx in San Pedro. The research identified over 236,000 domains hosting investment fraud, including fake exchanges, wallet drainers, and recruitment-based schemes such as LSSC and Yuechi operations. Most infrastructure relies on mainstream cloud providers while a smaller subset uses bulletproof hosting such as CTG Server, enabling persistent globally distributed abuse.
AI Coalition Accelerates Open Source Vulnerability Discovery
Athena coalition has used frontier AI models to identify more than 20,000 security findings and produce over 2,000 patches across 500 open source projects. First wave of vulnerability disclosures is scheduled within weeks, with members using Anthropic and OpenAI frontier models including Mythos Preview and GPT-5.5-Cyber. Linux Foundation-backed Akrites initiative establishes a shared security incident response team and coordinated vulnerability disclosure process to manage rapidly increasing AI-discovered open source flaws.
KDDI Breach Exposes ISP Email Credentials via Third-Party Flaw
KDDI Corporation disclosed a breach affecting an email system shared with five Japanese ISPs after attackers exploited a vulnerability in third-party software. Up to 14.2 million email accounts across STNet, JCOM, Chubu Telecommunications, NIFTY and BIGLOBE may have been exposed, including email addresses and passwords stored in hashed or encrypted form with unspecified methods. The intrusion was detected on 17 June, with KDDI blocking the attacker, notifying regulators, and coordinating remediation with affected providers.
Russian Intel Uses Fake Support SMS to Steal Credentials
Ukraine’s Security Service and the FBI reported a campaign by Russian intelligence sending SMS messages impersonating messaging platform support bots to capture credentials. Targets included government, military, political and activist accounts in Ukraine, Europe and United States; SSU did not attribute the campaign to a specific group.
Daily Coverage