daily cyber × ai intelligence

index

tagged

[kongtuke]

2 items

June 30, 2026

Edge Appliances Bleed: watchTowr Drops Kemp LoadMaster Pre-Auth RCE as Oracle EBS Joins the Exploited List

watchTowr published a critical pre-auth RCE exploit for Progress Kemp LoadMaster (CVE-2026-8037), a network-edge appliance commonly fronting enterprise services. Oracle E-Business Suite (CVE-2026-46817) and SimpleHelp (CVE-2026-48558) vulnerabilities are being actively exploited in the wild; the latter drops Djinn Stealer, a new cross-platform infostealer targeting cloud and AI credentials. Microsoft removed 119 malicious Edge extensions in the StegoAd campaign (2.6M installs) that used steganography to hide credential-stealing and ad-fraud payloads, while Mustang Panda exploits Zoho WorkDrive against Indian government targets and ShinyHunters breaches Oracle PeopleSoft systems affecting NAIC and Nissan. Coinbase and other major tech companies are shifting internal AI workloads to Chinese open-weight models (GLM 5.2, Kimi 2.7, DeepSeek V4) to reduce costs, raising supply-chain and data-leakage concerns.

June 25, 2026

Cisco SD-WAN Manager Zero-Day Gives Root via a Malicious CSV as Operation Endgame Smashes Amadey and StealC

Cisco Catalyst SD-WAN Manager zero-day CVE-2026-20245 allows attackers to escalate from admin accounts to root by uploading malicious CSV files, as disclosed by Mandiant. Microsoft and Europol disrupted the shared infrastructure behind Amadey and StealC infostealers in Operation Endgame, recovering ~27M credentials and seizing over $47M. Anthropic alleges Alibaba illicitly extracted capabilities from Claude, highlighting emerging model-distillation IP-theft disputes. A stealthy Mistic RAT serves as entry point for initial-access broker Woodgnat (aka KongTuke), feeding multiple ransomware families including Qilin, Interlock, and Black Basta.