June 25, 2026
Cisco SD-WAN Manager Zero-Day Gives Root via a Malicious CSV as Operation Endgame Smashes Amadey and StealC
38 sources → 345 gathered → 345 triaged → 44 clustered → 44 written
Mandiant disclosed an actively exploited Cisco Catalyst SD-WAN Manager zero-day that lets an attacker jump from an admin account to root using a booby-trapped file upload. Separately, Microsoft and Europol disrupted the shared infrastructure behind the Amadey and StealC infostealer operations in the latest Operation Endgame action.
Vulnerabilities & Exploits
- Cisco Catalyst SD-WAN Manager zero-day CVE-2026-20245 was exploited in the wild against a service provider, with Mandiant detailing how a threat actor escalated from a compromised administrative account to root by uploading a malicious CSV through a file-upload feature that failed to filter the payload, then used anti-forensic log deletion to stay hidden. IOCs and remediation guidance are published. Google/Mandiant, BleepingComputer
- Cisco Unified Communications Manager SSRF flaw CVE-2026-20230 (CVSS 8.6) is being exploited after a public PoC chained the unauthenticated SSRF into a file-write primitive leading to root-level compromise. Horizon3, The Hacker News
- FFmpeg “PixelSmash” (CVE-2026-8461) in the libavcodec MagicYUV decoder enables RCE via crafted media files, putting video players, media servers, and NAS appliances at risk; fixed in FFmpeg 8.1.2. SecurityWeek, JFrog
- CISA flagged active exploitation of max-severity flaws in Ubiquiti UniFi OS and Lantronix EDS5000 serial-to-ethernet servers. The Lantronix bug, CVE-2025-67038 (CVSS 9.8), is a code-injection flaw FCEB agencies were ordered to patch by June 26. BleepingComputer (Ubiquiti), The Hacker News (Lantronix)
- Samsung KNOX kernel UAF CVE-2026-20971 in the PROCA/FIVE subsystem affects most Galaxy devices, enabling memory corruption and infoleak; patched January 2026 but partially mitigated only by Control Flow Integrity. LucidBit Labs, Security Affairs
- Two critical libssh2 vulnerabilities (CVE-2026-55200, CVE-2026-55199) in versions up to 1.11.1 allow remote code execution and DoS, exposing a wide range of software and embedded devices. Cybernews
- A chained macOS weakness lets a standard non-admin account silently disable endpoint security agents and integrated browser tooling by abusing legitimate OS behavior — no kernel exploit or admin rights required. Dark Reading, SecurityWeek
- An unverified Windows LPE 0-day (SYSTEM, Windows 10/11 and Server 2016+, claimed to work with or without EDR) is being advertised on DarkForums for $120,000 with a PoC offered to buyers — treat as unproven until validated. Daily Dark Web
New Tools & Releases
- Bitwarden C2 turns
icons.bitwarden.netinto a full command-and-control channel: commands inbound via PNG-metadata polyglots, results exfiltrated over DNS, with all traffic flowing to a trusted Azure-backed domain. thecontractor.io - Ghost-Sender documents a widespread Exchange Online misconfiguration that enables universal spoofing of both internal and external senders. InfoGuard Labs
- CrystalSliver swaps Sliver’s default reflective loader and post-ex execution path for Raphael Mudge’s Crystal Palace, improving evasion. GitHub
- AudioDG.exe DLL Hijacking is a Windows LPE that runs code as LOCAL SERVICE and escalates to SYSTEM via Scheduled Tasks, with a reboot-free restart primitive. GitHub
- SindriKit is an offensive-development framework that decouples C tooling techniques from execution mechanics using dependency injection and layered APIs, aiming for faster adaptation to detection changes. sibouzitoun.tech
Threat Intelligence
- Operation Endgame dismantled the shared infrastructure behind the Amadey and StealC infostealers, with Microsoft’s DCU, Europol, Bitdefender, Bitsight, and ESET taking down 300+ servers and 200+ domains, recovering ~27M stolen credentials, and seizing over $47M; Microsoft also leaned on AI to link the operations in a racketeering suit. Microsoft, The Record, The Register
- AryStinger, a previously undocumented Linux botnet, hijacks EoL routers and QNAP NAS as a covert reconnaissance-and-proxy network rather than for DDoS/mining. It uses an Executor/Controller model, n-day CVEs (CVE-2013-3307, CVE-2016-5681, CVE-2025-11837), Protobuf+XOR C2, and Dropbear/gs-netcat persistence; 4,300+ routers confirmed (mostly South Korea and China, ~75% D-Link DIR-850L), initial samples at 0/VirusTotal. XLab via FalconFeeds
- Mistic, a stealthy new RAT, is the entry point for initial-access broker Woodgnat (aka KongTuke), who feeds ransomware affiliates including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta, hitting insurance, education, IT, and professional-services targets. BleepingComputer, SecurityWeek
- StrikeShark uses a custom Chinese-speaking loader, SharkLoader, to deploy Cobalt Strike beacons via DLL hijacking and encrypted multi-stage droppers after exploiting internet-facing vulnerabilities across several sectors. Securelist
- A three-month mapping of Eastern European malicious infrastructure across 10 countries found 3,900+ active C2 servers spread over 302 hosting providers — with a single host carrying roughly half the load. Hunt.io
- A Browser-in-the-Browser kit was spotted delivering malware (not stealing credentials), using a draggable spoofed-URL pop-up to push a fake “software out of date” warning that instructs users to run the payload. Unit 42
- A ClickFix C2 campaign abuses Ghost CMS via CVE-2026-26980, injecting malicious JavaScript through compromised posts; infections persist after patching due to leaked API keys. SicuraNext
- Two Scattered Spider members pleaded guilty to the 2024 Transport for London intrusion, a £39M attack that disrupted services and exposed data on ~10 million customers. BleepingComputer, Hackread
AI & Model Security
- OpenClaw pulled five malicious packages from its ClawHub skills marketplace that smuggled infostealers and other payloads past security checks, with researchers warning the broad system access granted to AI “skills” makes the marketplace a soft AI supply-chain target. Dark Reading, Unit 42
- Anthropic alleges Alibaba illicitly extracted capabilities from Claude, raising the prospect of model-distillation/IP-theft as a recurring dispute between frontier labs. Reuters
- Researchers showed medical-diagnosis AI models can be coaxed into revealing membership of specific patient records in their training data — a privacy attack with obvious regulatory weight. The Register
- A malware author is now embedding fake “nuclear/biological weapons” policy-triggering text inside a JavaScript comment block to discourage automated LLM-based malware analysis, while keeping the real
eval()-wrapped payload intact below it. Schneier on Security
Supply Chain
- Following the JFrog report on hijacked npm packages, Nextron telemetry uncovered 15+ malicious Go packages using the same payload dating back to 2018, several still live on GitHub and the Go module mirror (latest confirmed
github.com/lambda-platform/lambda, Jun 19). Nextron Research
Industry & Policy
- A 21-year-old known as “Snoopy” (Nathan Austad) was sentenced to 18 months and ~$1.8M in forfeiture/restitution for the 2022 DraftKings credential-stuffing campaign that compromised ~60,000 accounts. BleepingComputer, SecurityWeek
- KDDI disclosed a breach exposing email data for up to 14.2 million managed users, raising phishing and identity-theft risk. The Register
Topics
Vendors
Threat actors
CVEs
Models