daily cyber × ai intelligence

index

June 22, 2026

Unpatchable iPhone BootROM Exploit Drops as a New Call-Stack Bypass Defeats 2024-Era EDR

24 sources 223 gathered 223 triaged 41 clustered 41 written

A heavy day for offensive tradecraft: a public usbliter8 SecureROM exploit reopens permanent boot-chain compromise on Apple A12/A13 devices, and the LACUNA Chain writeup shows how to evade the call-stack-based detection that became standard EDR practice. Elsewhere, OAuth token theft burned a wave of Salesforce tenants, North Korea kept poisoning npm, and a 4,300-router reconnaissance proxy net surfaced.

Offensive & Red Team

  • usbliter8, a novel BootROM/SecureROM exploit for Apple A12/A13 chips (iPhone XS, iPhone 11, Apple Watch 4/5, HomePod mini), was disclosed with a public PoC — the first unpatchable hardware-level iPhone exploit in six years. It chains a USB-controller hardware bug with a firmware configuration flaw to achieve application-processor boot-chain compromise; physical access plus a Raspberry Pi are required, and there is no software fix. Paradigm Shift writeup, PoC, CyberInsider.
  • LACUNA Chain (“Ghost Frames”) picks up where HookChain left off, defeating call-stack-based EDR detection layers — the technique class that succeeded userland NTDLL hook evasion. A practical read for anyone tuning or bypassing telemetry that leans on stack-walk integrity. 0xmaz writeup.
  • A PoC smuggles C2 traffic through Slack link previews in locked-down tenants: a modified Mythic/Medusa implant embeds responses in preview content fetched by Slack’s backend, side-stepping egress restrictions. Writeup, code.
  • A walkthrough wires Claude to HexStrike AI and NetExec for AI-assisted Active Directory pentesting in a lab, illustrating how agentic tooling is being plugged into standard AD enumeration/exploitation chains. Hacking Articles.
  • Censys published fingerprinting for the open-source AdaptixC2 framework — useful for both blue-team internet-scale hunting and understanding the framework’s network footprint. Censys.

Cloud & Identity

  • The Klue security incident exposed Salesforce CRM data across many customers via OAuth token theft and abuse of compromised integrations, attributed to the Icarus actor. Huntress confirmed its own systems were untouched, and Recorded Future published its own impact analysis. Huntress, Recorded Future.

Supply Chain

  • A malicious npm package, node-fetch-utils, masquerades as a fetch helper but declares a remote GitHub tarball dependency that npm resolves and runs at install. Its obfuscated Windows postinstall pulls a bundled Python runtime, drops it as %LOCALAPPDATA%\Microsoft\EdgeBroker\pythonw.exe for persistence, and executes a fileless, in-memory-decrypted Python implant via hidden wscript; the dropper self-deletes. C2: node22[.]lunes[.]host:3258. Nextron Research.

Vulnerabilities & Exploits

  • Threat actors are actively exploiting CVE-2026-4020, an unauthenticated information-disclosure flaw in the Gravity SMTP WordPress plugin (~100,000 installs) to extract config data, API keys, secrets, and OAuth tokens. The Hacker News, BleepingComputer.
  • A public PoC exists for “Copy Fail” (CVE-2026-31431), a local privilege-escalation bug in the Linux kernel affecting every mainstream distro shipping kernels built since 2017; the mainline fix landed in April but no distribution has yet shipped a patched package, so interim mitigations are the only defense. CERT-EU.
  • CVE-2026-56099 in OpenBSD causes an out-of-bounds kernel read and remote info disclosure when handling crafted MPLS frames carrying 16 labels without a bottom-of-stack marker. Argus advisory.
  • A Khan Academy HackerOne report details a 1-click account takeover via a regex weakness in redirect validation that lets an attacker capture and replay auth tokens through crafted subdomain URLs. HackerOne #3723458.
  • A dark-web seller is advertising an alleged 10-bug “0-day package” against an unnamed cryptographic library (crypto_box_open_easy), claiming DoS, heap OOB read, and nonce-reuse exploits — for 200 BTC, with no verifiable PoC. Treat as unverified marketing until reproduced. Daily Dark Web.

Threat Activity & CTI

  • AryStinger has infected 4,300+ legacy D-Link routers — but unusually, it builds them into a distributed reconnaissance and proxy network for pre-intrusion staging rather than a DDoS botnet, per QiAnXin’s XLab. The Hacker News, XLab blog.
  • Operation Escaneo — exposed via an attacker server left open — is a sophisticated campaign against Latin American governments and financial institutions. CloudSEK.
  • The Popa botnet, which abuses consumer devices for residential-proxy resale, has been linked to a publicly-traded Israeli firm, tying together prior Vo1d and SuperProxy/SuperBox research. KrebsOnSecurity, Synthient.
  • Researchers shared fresh infrastructure tracking and IOCs for the ORB Charlie network, historically tied by Mandiant to China-nexus APT5 — part of the broader shift to scalable ORB networks that raise attribution cost. BushidoToken/Team Cymru.
  • A PowerShell sample attributed to APT38 (linked to the Axios npm compromise) and its dropped .bat both trigger existing THOR rules out of the box — shared persistence, User-Agent, and victim-UID logic make for easy hunting pivots. Florian Roth.
  • Icarus ransomware escalated supply-chain extortion against a major Canadian consulting/competitive-intelligence firm, now threatening to publish downstream client data — the same actor named in the Klue incident. Ido Cohen.
  • Europol dismantled the “AudiA6” crypto-laundering service, seizing over €336M and linking it to 15+ international cybercrime investigations involving ransomware groups. Europol.
  • WhatsApp intends to seek contempt charges against NSO Group, alleging fresh Pegasus targeting that bypassed court orders. Citizen Lab.

Data Breaches & Leaks

  • A threat actor is advertising an alleged 1.3 TB Eurail/Interrail dataset — claimed 100M+ deduplicated records sourced from Zendesk, GitLab, and S3 backups, reportedly including passport and national-ID data — for $15,000. Unverified. Daily Dark Web.
  • Several large French organizations were hit with leak/sale claims: Ornikar (~2M learners), Pulsy regional e-health (~5.7M), i-Run (~1.2M), Mairie de Paris (315k), and the national table-tennis federation (110k, including minors). Separately, actor “shabat” is offering paid lookups against French police systems (CHEOPS, TAJ, FPR, SIV), suggesting insider access or a compromised NEO-CRS terminal. i-Run, police DB access.
  • A third-party license vendor breach exposed personal data on ~3 million Texas Parks & Wildlife hunting/fishing license holders. SecurityWeek.
  • Additional unverified sale/leak claims: Coupang (33.2M e-commerce records with device fingerprints), Ralph Lauren (858k, attributed to ShinyHunters), and Nintendo of America employee data exposed via a supply-chain hit on engagement vendor TinyPulse. Coupang, Nintendo/TinyPulse.

Ransomware & Hacktivism

  • Nova ransomware added four victims, including Danish firm MIT HJERTE alongside two Turkish targets. FalconFeeds.
  • Qilin named a Taiwanese machinery maker, a Bangkok hotel, and a US lighting distributor; LockBit 5.0 posted four new victims across Italy, the Dominican Republic, the US, and Vietnam. Qilin, LockBit.
  • DDoS hacktivism continued: NoName057(16) hit French targets (EDF Entreprises, City of Dunkirk), and Dark Storm Team struck Belgian government and energy infrastructure including the electoral directorate and the Federal Agency for Nuclear Control. France, Belgium.

AI & Model Security

  • Reverse-engineered Windows Copilot API projects expose GPT-4/GPT-5 through an OpenAI-compatible REST interface without keys or billing by automating the Copilot web chat — a reminder of how client-side AI assistants can be turned into uncontrolled model proxies. GitHub.
  • A new whitepaper benchmarks 14 open-source deepfake detectors against social-media re-encoding using SDXL + InstantID, quantifying how robustness degrades after platform compression. Zenodo.