← Carolina Clear Tech

Cyber Threat Brief

2026-06-30

Listen to this brief (26:18)

Download MP3
Show Notes

Show Notes - 2026-06-30

Stories Covered

CVEs Referenced

CVE-2023-26360, CVE-2023-29298, CVE-2023-29300, CVE-2024-1212, CVE-2025-11001, CVE-2025-54136, CVE-2025-59536, CVE-2025-61882, CVE-2026-12569, CVE-2026-12957, CVE-2026-20245, CVE-2026-21852, CVE-2026-30615, CVE-2026-33691, CVE-2026-33825, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-35273, CVE-2026-41947, CVE-2026-41948, CVE-2026-43503, CVE-2026-43707, CVE-2026-43715, CVE-2026-43716, CVE-2026-43745, CVE-2026-46817, CVE-2026-48558, CVE-2026-50110, CVE-2026-56413, CVE-2026-56415, CVE-2026-8037

Indicators of Compromise

Domains: dev-tunnels[.]com, perplexity-ai[.]online

IP Addresses: 7.2.63.2, 7.2.54.18, 8.0.4.29

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief -- June 30, 2026

Generated from 40 articles. Sources: The Hacker News, SecurityWeek, Check Point Research, DFIR Report, Huntress, Dark Reading, CISA, Microsoft Security Blog, DataBreaches.net, CyberScoop.


Today: Oracle E-Business Suite CVE-2026-46817 (CVSS 9.8) moved from patched-but-quiet to actively exploited over the weekend, with no prior exploitation history and no public PoC when attacks began. SimpleHelp CVE-2026-48558 (CVSS 10.0) is in the CISA KEV catalog and attackers are already deploying TaskWeaver and Djinn Stealer through it, stripping developer machines of cloud, AI, and infrastructure credentials. Microsoft Defender's BlueHammer flaw (CVE-2026-33825) now has a ransomware tag on its CISA KEV entry, rounding out a heavy patch day for defenders.


Critical Alerts

Oracle E-Business Suite CVE-2026-46817 (CVSS 9.8) -- Active Exploitation Confirmed

CVE-2026-46817 is an improper privilege management and authentication flaw in the Oracle Payments component of EBS, affecting versions 12.2.3 through 12.2.15. Defused Cyber observed active exploitation against their honeypots over the weekend, with no prior in-the-wild exploitation history and no public PoC at the time attacks began. An unauthenticated attacker with HTTP access can take over Oracle Payments outright. This flaw arrives alongside two other Oracle enterprise platform exploits in concurrent active use: CVE-2025-61882 (CVSS 9.8, CISA KEV, EPSS 99.7%, Cl0p ransomware-linked) and CVE-2026-35273 (CVSS 9.8, CISA KEV, EPSS 92.3%), the PeopleSoft zero-day used by ShinyHunters to breach Nissan (payroll records, SSNs, bank details for US/Canada/Mexico/Brazil employees) and the National Association of Insurance Commissioners (3.1TB of regulatory filings and cloud configs claimed). The PeopleSoft exploit chain combines multiple vulnerabilities to plant a malicious file that executes on server restart, indicating a threat actor with deep codebase familiarity.

SimpleHelp CVE-2026-48558 (CVSS 10.0, CISA KEV) -- TaskWeaver and Djinn Stealer Deployed

CVE-2026-48558 is a critical authentication bypass in SimpleHelp's OpenID Connect flow affecting servers configured with generic OIDC or Azure AD OIDC. An unauthenticated attacker forges an identity token to obtain a fully authenticated Technician session, bypassing MFA entirely because first-time technicians can self-register their own MFA method. From that session, attackers have the same remote management capabilities as a legitimate IT admin over all managed endpoints. Blackpoint Cyber documented an active campaign deploying TaskWeaver (a heavily obfuscated Node.js loader disguised as jquery.js, with C2 at a.dev-tunnels[.]com) followed by Djinn Stealer. Djinn targets credentials for AWS, Azure, GCP, Okta, Cloudflare, GitHub, npm, PyPI, Maven, Gradle, SSH keys, AI tool configs (Claude, Gemini, Codex, Cline, OpenCode), and cryptocurrency wallets. All stolen data is AES-256-GCM encrypted before exfiltration. SimpleHelp serves over 6,000 organizations.

BlueHammer CVE-2026-33825 -- Microsoft Defender Now Confirmed Ransomware-Linked in CISA KEV

CISA updated the KEV entry for CVE-2026-33825 (BlueHammer), a Microsoft Defender privilege escalation flaw, to flag active use in ransomware campaigns. It was publicly disclosed April 2 by a researcher dissatisfied with Microsoft's vulnerability handling, patched April 14, and exploited as a zero-day before patches were available. Huntress observed pre-patch exploitation. The ransomware group responsible is not publicly identified.

Ubiquiti UniFi OS CVE-2026-34908 / 34909 / 34910 (CISA KEV) -- Mirai Botnet Exploitation

Three UniFi OS vulnerabilities allow unauthorized configuration changes (CVE-2026-34908, EPSS 82%), directory traversal and file read (CVE-2026-34909, EPSS 81%), and command injection (CVE-2026-34910, EPSS 100%). All three were added to CISA KEV with a due date of 2026-06-26. Active exploitation is tied to Mirai botnet activity on network appliances.

Progress Kemp LoadMaster CVE-2026-8037 (CVSS 9.8) -- Full PoC Published

CVE-2026-8037 is a pre-auth root command injection via the /accessv2 API endpoint. The root cause is a missing null terminator in the escape_quotes() sanitization function: without it, the system reads past the sanitized input into attacker-controlled JSON keys containing the payload. No credentials required; commands run as root. watchTowr Labs published a full technical breakdown and working PoC on June 29. No exploitation reported yet, but the public PoC changes that timeline. Fixed in GA v7.2.63.2 and LTSF v7.2.54.18. A second flaw in the same advisory, CVE-2026-33691, allows WAF bypass via whitespace-padded filenames. LoadMaster's CVE-2024-1212 (CVSS 10.0) is already in CISA KEV after confirmed exploitation.

PTC Windchill PDMlink / FlexPLM CVE-2026-12569 (CISA KEV) -- JSP Web Shells Deployed

CVE-2026-12569 is a critical RCE in PTC's product lifecycle management platforms actively exploited to deploy JSP web shells. Patches are available. CISA added to KEV with a due date of 2026-06-28.


Ransomware & Extortion

Bumblebee + AdaptixC2 + Akira: Full 44-Hour Attack Chain Documented

DFIR Report published a detailed case study of a July 2025 intrusion starting with SEO poisoning. A Bing search for "ManageEngine OpManager" led to a lookalike domain hosting a trojanized MSI. The installer side-loaded BumbleBee via msimg32.dll, which established C2 and within five hours dropped AdaptixC2 (a renamed Windows Address Book utility injected with shellcode). Attackers created Enterprise Admin domain accounts, installed RustDesk as a Windows service for persistence, pivoted to the domain controller via RDP, and dumped NTDS.dit using wbadmin.exe. Veeam credentials were extracted via DPAPI with custom PowerShell. The lsassy utility dumped LSASS memory across multiple hosts. Over 75GB (file shares, credentials, SYSVOL configs) was exfiltrated to Ukraine via FileZilla over SFTP. Akira ransomware (locker.exe) deleted Volume Shadow Copies via WMI and encrypted the root domain 44 hours after initial access. Attackers returned two days later for a child domain. A parallel incident used a BYOVD attack to kill endpoint security controls.

XSS Forum Takedown: 19-Day Median from Access Listing to Ransomware Victim

XSS.is was seized in July 2025 following the arrest of its administrator in Kyiv during Operation Ratatouille. Analysis of 123,241 leaked messages documents how initial access brokers listed corporate network footholds as structured auctions (one example: $25K start, $40K blitz for a US manufacturer at $800M revenue). Intel 471 tracked 4,878 access sales between June 2024 and May 2025 and measured a median of 19 days between access listing and the victim appearing on a ransomware leak blog. That 19-day number is the defender response window once access has been sold.

Black Basta Playbook: Cyber Insurance as a Ransom Pricing Signal

Leaked Black Basta chat logs reveal that ransomware operations use corporate-style structure with a scheduled call team (6 PM to 2 AM Moscow time), outsourced contractors, performance-based pay, and pre-negotiation victim profiling. Groups audit data sensitivity and specifically seek cyber insurance policy details to calibrate ransom demands. Negotiation timelines are deliberately manipulated to create urgency or panic. Black Basta attacked 520 victims in 39 industries and collected at least $107 million before shutting down in 2025. This directly informs incident response preparation: limit exposure of insurance policy details and backup architecture in any system accessible by attackers.


IOCs & Detection

Djinn Stealer / TaskWeaver Campaign (via SimpleHelp CVE-2026-48558) - C2 domain: a.dev-tunnels[.]com (high confidence, active intrusion documented by Blackpoint Cyber) - File indicator: jquery.js executing via node.exe -- the TaskWeaver loader, deployed via compromised RMM Technician session - Exfiltration: AES-256-GCM with RSA-2048 key; watch for large encrypted blobs to unknown destinations - Credential targets: cloud provider configs, package registry auth files, SSH ~/.ssh/, AI tool session directories

Malicious Perplexity-Spoofing Chromium Extension - Typosquatted infrastructure: perplexity-ai[.]online (not the legitimate perplexity.ai) - Routes all Omnibox queries AND real-time keystroke suggestions through attacker infrastructure - Extension removed from Chrome Web Store but may persist on already-installed browsers; hunt in DNS/proxy logs

ConsentFix OAuth Token Hijacking - Delivery: Dropbox- and DocSend-hosted lures with a localhost callback drag-and-drop trap - Infrastructure: Cloudflare Pages, workers.dev, Pipedream webhooks - Attacker recon using LinkedIn, ZoomInfo, Hunter.io for targeted lure construction - Result: M365 OAuth token theft without password entry or MFA challenge; grants email, OneDrive, Teams access

Sources: Dark Reading | Microsoft Security Blog | Huntress


Business & Infrastructure Threats

Amazon Q VS Code Extension CVE-2026-12957 -- MCP Auto-Execution Steals Cloud Credentials

A high-severity flaw in the Amazon Q Developer VS Code extension allowed attackers to execute arbitrary code and steal cloud credentials by getting a developer to open a malicious repository. Amazon Q automatically loaded and executed MCP server configurations from workspace files without user approval. Spawned processes inherited the developer's full environment, exposing AWS credentials, API keys, and SSH agent sockets -- all before the developer reviewed a single line of code. Fixed in Language Server version 1.65.0. Wiz Research notes this is part of a broader MCP pattern: similar auto-execution issues exist in Claude Code (CVE-2025-59536, CVE-2026-21852), Cursor (CVE-2025-54136), and Windsurf (CVE-2026-30615). MCP vulnerabilities exist at the architectural level and cannot be fully addressed by patching alone.

ConsentFix: OAuth Token Hijacking Targeting Microsoft 365

Huntress detailed ConsentFix, a phishing technique abusing M365 OAuth consent flows to steal session tokens without triggering MFA. Attackers deliver lures via Dropbox or DocSend (often password-protected to evade AV inspection), present a realistic M365 sign-in page, and instruct victims to complete a localhost callback step via drag-and-drop. That action hands over OAuth tokens for email, OneDrive, and Teams. A complete tutorial with working code was posted to a Russian cybercrime forum in March 2026. Attacker recon via LinkedIn, ZoomInfo, and Hunter.io produces highly targeted lures.

Major Breaches: KDDI (14.22M accounts), Tata Electronics, NAIC via Oracle Zero-Day

KDDI (Japan) confirmed a breach of its ISP email platform after an intrusion on June 17, exposing up to 14.22 million email addresses and passwords across six ISPs including J:COM and Biglobe. Tata Electronics (Apple/Tesla supplier) suffered a breach; World Leaks claimed 630GB of data including supplier and customer documents. NAIC confirmed a breach after ShinyHunters claimed 3.1TB via the Oracle PeopleSoft zero-day, including regulatory filings, production logs, and cloud configuration files.


Windows / AD Security

Steganographic Webshell + 10-Step Defence Impairment in Active Intrusion

Huntress documented a June 7 web server compromise via a webshell embedded steganographically inside an image file (UA4fp7R.aspx placed in wwwroot\Images). The webshell spawned from w3wp.exe (IIS worker process), which is the primary detection indicator. Initial access was likely via Adobe ColdFusion bugs CVE-2023-26360 (CISA KEV, EPSS 97%), CVE-2023-29298 (CISA KEV, EPSS 99.8%), and CVE-2023-29300 (CISA KEV ransomware-linked, EPSS 100%). The attacker then ran nearly a dozen defence impairment techniques: disabling IIS logs, tampering with Defender, using WMI Event Consumer subscriptions to clear Windows Event Logs, and timestomping.

EvilTokens: 1,380% Surge in Device-Code Phishing Against Microsoft 365

Check Point confirmed Huntress research on EvilTokens, an AI-powered phishing-as-a-service operation abusing M365 device-code authentication flows to steal tokens without credential entry. Early 2026 saw a 1,380% surge in device-code phishing. AI-generated lures and automated workflows reduce attacker effort significantly. Combined with ConsentFix, token-based M365 session hijacking without credentials or MFA is a primary attack vector this quarter.


General Security News

Apple Patches 30+ Flaws Including AI-Discovered WebKit Bugs; Accelerating Release Cadence

Apple released iOS 26.5.2, macOS Tahoe 26.5.2, iPadOS 26.5.2, and Safari 26.5.2, addressing over 30 vulnerabilities. Four WebKit bugs were discovered using AI tools: CVE-2026-43715 (use-after-free, credited to Anthropic researchers and Claude), CVE-2026-43707, CVE-2026-43716, and CVE-2026-43745 (credited to OpenAI Codex Security). None are confirmed exploited in the wild. Apple stated it is shortening the time between vulnerability discovery and public update release specifically because AI tools are shrinking the window before a patch can be weaponized. This is the first public acknowledgment from a major vendor that AI-accelerated exploit development is changing patch release strategy.

BioShocking: AI Browser Agents Tricked Into Credential Exfiltration via Game-Framing

LayerX demonstrated BioShocking, an indirect prompt injection attack that frames a malicious web page as a puzzle game where wrong answers win. Once an AI browser agent accepts game logic over safety logic, the final puzzle step instructs it to pull SSH credentials from the user's GitHub account and send them to the attacker. Six AI browsers were tested: ChatGPT Atlas (patched by OpenAI), Perplexity Comet (report closed without action), Claude browser extension (Anthropic fix did not hold), Fellou, Genspark, and Sigma. An AI browser in agent mode carries implicit access to every signed-in session in the browser.

Malicious Chromium Extension Spoofs Perplexity AI for Search Traffic Interception

Microsoft Threat Intelligence identified a Chromium extension using Manifest V3 and declarativeNetRequest rules to transparently route all Omnibox queries and real-time search suggestions through perplexity-ai[.]online before forwarding to legitimate search engines. The extension forces itself as the browser default search provider. No confirmed credential theft, but the level of access and permissions requested creates elevated risk. Extension removed from Chrome Web Store.

AirDrop and Quick Share Proximity Flaws

Researchers found six security flaws across Apple AirDrop and Google/Samsung Quick Share. AirDrop bugs crash sharingd, taking down AirPlay, Handoff, Universal Clipboard, and Continuity Camera simultaneously. The most serious Quick Share flaw (Google for Windows) is a use-after-free when two connections collide, with a plausible code execution path because Control Flow Guard is disabled. Apple patched one AirDrop flaw; Google has a code fix for Quick Share Windows. No exploitation in the wild.


Patch Priority


Vulnerability Disclosures

Cisco Catalyst SD-WAN Manager CVE-2026-20245 (CISA KEV, EPSS 99th percentile)

High-severity command injection in Catalyst SD-WAN Manager exploited as a zero-day for months before disclosure. An admin-level user can run root commands via a crafted file on on-premises and Cisco-managed cloud deployments. CISA KEV due date: 2026-06-23.

Dify AI Platform CVE-2026-41947 / CVE-2026-41948

Two critical vulnerabilities in Dify (open-source AI workflow platform) patched in version 1.14.2. Allow unauthenticated access and cross-tenant data exposure including chat content and uploaded files.

DirtyClone Linux Kernel CVE-2026-43503 -- Local Root via Cloned Packets

A DirtyFrag variant allowing local users to gain root via cloned packets on Debian, Ubuntu, and Fedora with default namespace configurations. Highest risk in multi-tenant cloud environments and Kubernetes clusters where unprivileged user namespaces are enabled. Kernel patches available.

Mitsubishi Electric MELSOFT Update Manager -- ICS (CVE-2025-11001, EPSS 98th percentile)

Four CVEs including arbitrary code execution via a 7-Zip component flaw in MELSOFT Update Manager versions <=1.014Q. Affects critical manufacturing environments. Update to version 1.015R.

StoneFly Storage Concentrator -- ICS Critical

Multiple critical flaws including hardcoded credentials reversible to plaintext spanning all internal services (CVE-2026-50110), unauthenticated root command injection on TCP port 9000 (CVE-2026-56413), and pre-auth root command injection via debug.pl (CVE-2026-56415). Affects defense, energy, financial services, healthcare, and IT sectors globally. Update to version 8.0.4.29.

OFFIS DCMTK Medical Imaging Toolkit -- Healthcare ICS

Five CVEs in DCMTK <=3.7.0 including path traversal allowing file writes outside intended directories, memory leak leading to service DoS, and unauthenticated worklist data disclosure across departmental boundaries. Healthcare environments should update to the latest GitHub snapshot.


Trends & Context

Three threads run through today's stories. Oracle enterprise products are under sustained, coordinated attack from groups with genuine codebase familiarity; the PeopleSoft exploit chain is multi-step and plants a file that waits for a server restart, which is not the work of script kiddies scanning for CVEs. RMM and AI development tooling (SimpleHelp, Amazon Q, AI coding extensions) are primary targets because they carry administrative reach into developer and cloud environments, making a single compromised endpoint a gateway to cloud credentials, package registry auth, and supply chain access. The 19-day median between initial access broker listing and ransomware victim publication quantifies the available response window: that number treats access purchase as a clock that started ticking, not a future theoretical risk.