CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (1 July 2026)

Published: Loading…

At a Glance

  • Attackers exploited SimpleHelp RMM flaw CVE-2026-48558 to deploy Djinn Stealer and TaskWeaver malware against managed service provider environments.
  • Ransomware gangs are exploiting the Windows Defender privilege escalation flaw BlueHammer, CVE-2026-33825, to obtain SYSTEM privileges after patching.
  • Attackers actively exploit Oracle E-Business Suite Payments flaw CVE-2026-46817, taking over instances without any public proof-of-concept available.
  • Apple patched over 30 iOS, macOS and Safari flaws, including WebKit bugs discovered using Anthropic Claude and OpenAI tools.
  • Researchers disclosed AirDrop and Quick Share vulnerabilities affecting five billion devices, enabling crashes and check bypasses by nearby attackers.
  • Nissan and Aflac Japan disclosed employee and customer data breaches linked to the Oracle PeopleSoft zero-day exploitation campaign.

Summary

Attackers are actively exploiting CVE-2026-48558, a critical authentication bypass in SimpleHelp RMM, to deploy Djinn Stealer and TaskWeaver malware. The flaw bypasses multi-factor authentication via forged OpenID Connect tokens. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue.

CISA confirmed ransomware gangs are exploiting BlueHammer, a Microsoft Defender privilege escalation flaw tracked as CVE-2026-33825. The bug allows local attackers to steal password hashes and reach SYSTEM privileges. Microsoft patched it in April 2026 after zero-day exploitation.

Exploitation of Oracle E-Business Suite Payments flaw CVE-2026-46817 began roughly six weeks after Oracle's patch. The vulnerability allows unauthenticated takeover of affected instances. Nissan and Aflac Japan separately disclosed breaches tied to the related Oracle PeopleSoft zero-day campaign, exposing 4.38 million records.

Apple released patches for more than 30 flaws across iOS, macOS, and Safari. Several WebKit bugs were identified using AI tools including Anthropic Claude. Kernel flaws could allow malicious apps to corrupt memory or leak information.

Researchers disclosed multiple vulnerabilities in AirDrop and Quick Share, wireless file-sharing protocols used on five billion devices. Nearby attackers can crash sharing services or bypass permission checks without pairing. Fixes for both platforms are beginning to roll out.

A supply-chain campaign used ten npm maintainer accounts to publish roughly 30 packages impersonating Polymarket and DeFi tooling. The packages delivered a JavaScript infostealer targeting crypto wallets, browser credentials, and SSH keys. Separately, a "BioShocking" prompt-injection technique tricked AI browsers including ChatGPT Atlas and Claude's extension into leaking user credentials.

Highlights of the Day

SimpleHelp Authentication Flaw Enables Technician Access

Arctic Wolf reported active exploitation of CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp RMM caused by improper OpenID Connect token signature validation, allowing attackers to forge identity tokens, bypass multi-factor authentication and obtain technician-level access without valid credentials when group-authenticated OIDC logins are enabled. Threat actors have used the flaw to deploy custom malware for credential theft and persistent access across managed environments, while CISA has added the vulnerability to its Known Exploited Vulnerabilities catalogue and internet scans indicate around 14,000 externally exposed SimpleHelp servers, with approximately 1,000 directly vulnerable.

Ransomware Gangs Exploit Windows BlueHammer Defender Flaw

CISA confirmed ransomware groups are exploiting CVE-2026-33825, the high-severity Microsoft Defender privilege escalation vulnerability known as BlueHammer, which stems from insufficient access control and allows authorised local attackers to access the Security Account Manager database, obtain password hashes and escalate to SYSTEM privileges. Microsoft patched the flaw during April 2026 Patch Tuesday after zero-day exploitation was reported, and CISA has updated its Known Exploited Vulnerabilities catalogue to identify its use in ransomware campaigns despite Microsoft not yet marking it as actively exploited.

Oracle E-Business Suite Flaw Targeted in Active Attacks

Defused Cyber reported active exploitation of CVE-2026-46817, a critical Oracle Payments vulnerability in Oracle E-Business Suite caused by improper privilege management and authentication, allowing unauthenticated attackers with HTTP access to take over affected instances running versions 12.2.3 through 12.2.15. Oracle released patches in its June 2026 Critical Patch Update, while Defused Cyber observed attacks against Oracle E-Business honeypots despite no public proof-of-concept exploit or technical details of the exploitation method being available.

Apple Fixes Multiple Kernel and WebKit Vulnerabilities

Apple released iOS 26.5.2 and iPadOS 26.5.2, addressing numerous security vulnerabilities affecting supported iPhone and iPad models, including kernel flaws such as CVE-2026-43724, CVE-2026-43722 and CVE-2026-39868 that could allow kernel memory writes, memory corruption, information disclosure or unexpected system termination by malicious apps. The update also fixes multiple WebKit vulnerabilities, including cross-origin data leaks, sandbox escapes, clipboard hijacking, memory corruption and use-after-free issues, with flaws such as CVE-2026-43727, CVE-2026-43735 and CVE-2026-43720 enabling malicious websites to bypass browser protections or access sensitive user data.

Source: Apple

npm Supply Chain Campaign Delivers DeFi Infostealer

Researchers reported an npm supply-chain campaign involving ten maintainer accounts publishing around 30 packages impersonating Polymarket and DeFi tooling, using a fake arbitrage bot repository to distribute a JavaScript infostealer targeting developers. The campaign used multiple delivery methods including postinstall hooks, direct code embedding, dependency side-loading, and npm-based self-upgrade chains, with payloads exfiltrating crypto wallet data, browser credentials, SSH keys, AWS secrets, and npm tokens to attacker-controlled C2 infrastructure.

Source: SafeDep

ValleyRAT Campaign Spreads via Fake Installers and Emails

LevelBlue researchers reported ongoing ValleyRAT remote access trojan campaigns delivered through fake installers and malicious email attachments targeting Chinese and Japanese-speaking users, with infection chains using ZIP archives containing DLL sideloading payloads and executables disguised as VLC media player components. The malware deploys a downloader that retrieves ValleyRAT as the final payload and uses techniques including fileless execution via rundll32.exe, RC4-encrypted payload delivery with key “zenzensu”, and process injection using CreateProcessA and WriteProcessMemory. The campaign incorporates anti-analysis checks such as memory thresholds, sleep timing validation, processor count checks, and IsNativeVhdBoot() environment detection, alongside persistence via Windows Run registry keys and DLL-based execution chains.

Source: LevelBlue

Citrix NetScaler SAML Flaw Leaks Memory via Overread

Citrix NetScaler ADC and Gateway SAML identity provider parsing flaw, tracked as CVE-2026-8451, enables pre-auth memory overread through malformed AuthnRequest attribute handling. The issue stems from insufficient input validation in XML attribute termination logic, allowing out-of-bounds reads that surface uninitialised memory in responses and logs. Exploitation via /saml/login requests with crafted AuthnRequest structures affects multiple NetScaler ADC and Gateway versions, with CVSS 8.8 and memory leakage and occasional nsppe crashes.

Daily Coverage

Developments
Simplehelp ExploitationBluehammer RansomwareOracle Ebs AttacksApple Patches
Vulnerabilities
CVE-2026-48558Simplehelp 5.5.0 (Critical)CVE-2026-46817Oracle Payments 12.2.3 (Critical)CVE-2026-33825Microsoft Defender Antimalware Platform 4.0.0.0 (High)CVE-2026-8451Adc 14.1 (High)CVE-2026-43707SafariCVE-2026-8037Loadmaster V7.2.60.0 (Critical)CVE-2026-55200Libssh2 (High)CVE-2026-33017Langflow < 1.9.0 (Critical)CVE-2026-43722Ios And Ipados (Medium)CVE-2026-43720Safari (Medium)
Threat Groups
ToddyCatToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multistage infection chains against government and military targets across Europe and Asia.