daily cyber × ai intelligence

index

June 30, 2026

Edge Appliances Bleed: watchTowr Drops Kemp LoadMaster Pre-Auth RCE as Oracle EBS Joins the Exploited List

33 sources 245 gathered 245 triaged 43 clustered 43 written

A heavy day for enterprise exploitation, led by a fresh pre-auth RCE write-up against Progress Kemp LoadMaster and a wave of in-the-wild attacks on Oracle and SimpleHelp gear. Offensive tooling and AI-supply-chain risk round out the rest.

Vulnerabilities & Exploits

  • watchTowr published a deep-dive on CVE-2026-8037, an uninitialized-heap bug in Progress Kemp LoadMaster that escalates to unauthenticated pre-auth RCE on an appliance that typically sits at the network edge. Classic “the way in rather than the thing keeping people out” exposure for anyone fronting services with LoadMaster. watchTowr Labs
  • Oracle E-Business Suite CVE-2026-46817 (CVSS 9.8), an improper-privilege/auth flaw in Oracle Payments, is now being exploited in the wild per Defused, allowing instance takeover. The Hacker News, BleepingComputer
  • SimpleHelp CVE-2026-48558, a critical authentication-bypass, is being exploited to drop Djinn Stealer, a previously undocumented cross-platform infostealer (Windows/macOS/Linux) that explicitly hunts cloud and AI service credentials linking dev and admin environments. BleepingComputer, Dark Reading
  • CVE-2026-6307 (“Longinus”) — a single V8 bug that pierces both Chrome’s renderer and V8 sandbox boundaries — got a detailed exploitation write-up, a notable double-boundary primitive. nebusec
  • A reliable Linux LPE / jail and container escape via ipv6_frag_escape was released with PoC code, relevant for anyone assessing container breakout surface. GitHub
  • CVE-2026-46215, a use-after-free in DRM GEM’s change_handle, gives unprivileged-to-root on Linux, with a full write-up. cyberstan
  • “The Biometric AuthToken Heist” details cracking PINs and bypassing Credential Encryption via a long-ignored attack surface. DarkNavy

New Tools & Releases

  • ShadowDumper improvements demonstrate disk-touch-free LSASS dumping with syscalls resolved from on-disk ntdll.dll, dynamic encryption + compression, and no Dbghelp dependency. practicalsecurityanalytics
  • Chronic is a Chrome DevTools Protocol toolkit for browser-based post-exploitation and surveillance — a modular take on hijacking a live browser session. otterpwn
  • Strix is an open-source AI-driven penetration testing tool that autonomously finds and exploits application vulnerabilities. GitHub

Threat Activity

  • Unit 42 detailed a new Kongtuke (ClickFix) campaign sideloading Havoc C2 via a signed WinWrapIDE binary, with an evasive loader using window cloaking, sandbox sleep, and native callback evasion to run a memory-only infostealer. Unit 42
  • The DFIR Report walked an intrusion from a poisoned Bing search result through Bumblebee loader and AdaptixC2 to Akira ransomware deployment. The DFIR Report
  • The Gentlemen, a RaaS operation that ramped up in early 2026, is profiled by Kaspersky/Securelist for its custom backdoors and rapidly evolving TTPs. Securelist
  • Microsoft removed 119 Edge extensions (2.6M installs) in the StegoAd campaign, which hid payloads inside image and font files via steganography and activated days after install to steal credentials and run ad fraud. A separate fake Perplexity Chrome extension was found logging every search and address-bar keystroke. The Hacker News, Malwarebytes, Perplexity ext.
  • Mustang Panda is running two campaigns against Indian government and hydropower targets, abusing Zoho WorkDrive as a legitimate-cloud command channel, per Acronis. The Hacker News
  • NAIC confirmed a breach by ShinyHunters via an Oracle PeopleSoft zero-day (group claims 3.1 TB stolen); Nissan disclosed an employee-data breach tied to the same PeopleSoft exploitation campaign. NAIC, Nissan
  • Qilin kept up a high publishing tempo, adding victims across Japan, Thailand, the US, France, Peru and Germany to its leak site. FalconFeeds

AI & Model Security

  • Coinbase confirmed switching internal AI workloads to open-weight Chinese models (GLM 5.2, Kimi 2.7, DeepSeek V4), cutting AI spend ~50% with reported ~9x per-workload cost gaps versus Claude — part of a broader procurement shift now naming Cursor, Shopify, Airbnb, Siemens and others moving to Chinese models. The Decoder
  • Meta is restricting engineer use of Claude Code and Codex to keep rival AI output out of its own training data. The Decoder
  • A vendor analysis argues agentic AI’s privileged, non-human identities are an emerging attack surface attackers are already probing — relevant context for anyone deploying tool-using agents. BleepingComputer

Threat Intelligence & Policy

  • The US State Department posted a $10 million reward for information on Russia-linked groups UNC5792 and UNC4221, which have socially engineered their way into Signal and WhatsApp accounts of government, military and allied officials. The Record, BleepingComputer
  • Nation-state operators from Iran, Russia and China are breaching water utilities via weak passwords, exposed PLCs and poor segmentation — low-sophistication access, high sabotage potential. Dark Reading
  • Mandiant/Google details how the pro-Russia influence ecosystem has matured into a global strategic asset four years into the Ukraine invasion, with revitalized hacktivism at scale. Google TIG