# Threat Intel Brief — June 25, 2026
TL;DR
- Critical infrastructure under siege: Active exploitation of Cisco Unified Communications Manager (CVE-2026-20230) and Cisco SD-WAN (CVE-2026-20245) zero-days grants attackers root access to enterprise voice and networking infrastructure.
- Massive credential harvest: Russian-speaking initial access broker harvested 110 million credentials from 430,000+ FortiGate firewalls globally in the FortiBleed campaign, creating persistent access for ransomware operators.
- Supply chain threats escalate: GitHub CI/CD vulnerability "Cordyceps" exposes 300+ repositories at Microsoft, Google, and Apache; LastPass breached via Klue OAuth token theft; malicious AI skills evade scanners in ClawHub marketplace.
- Law enforcement wins: Europol-led Operation Endgame disrupted Amadey and StealC infostealer infrastructure, recovering 27 million stolen credentials; Scattered Spider members plead guilty to Transport for London breach.
- Federal agencies on deadline: CISA orders remediation of Lantronix EDS5000 code injection flaw (CVE-2025-67038) by June 26 amid active exploitation.
---
Critical Threats
Cisco Infrastructure Under Active Zero-Day Exploitation
What happened: Attackers are exploiting two critical Cisco vulnerabilities in production environments. CVE-2026-20245 in Cisco Catalyst SD-WAN allows unauthenticated attackers to gain root access and create persistent rogue administrator accounts. Separately, CVE-2026-20230 in Cisco Unified Communications Manager (CVSS 8.6) enables unauthenticated remote exploitation through improper HTTP input validation, leading to arbitrary file writes and root compromise. Mandiant has published technical details on the SD-WAN exploitation methodology.
Impact: Organizations using Cisco voice and SD-WAN infrastructure face immediate risk of complete system compromise. Attackers achieving root access can intercept communications, disrupt telephony services, pivot to connected networks, and establish persistent backdoors. Unified Communications Manager handles enterprise VoIP for thousands of organizations globally; SD-WAN devices sit at critical network segmentation boundaries.
Recommendations:
- 0–24h: Audit all Cisco Catalyst SD-WAN and Unified CM systems for unauthorized root accounts, suspicious user additions, and anomalous HTTP requests in web server logs.
- 0–24h: Apply Cisco security patches immediately when released; monitor Cisco Security Advisories for updates.
- 0–24h: Isolate management interfaces behind strict firewall ACLs; restrict access to trusted IP ranges only.
- 24–72h: Review authentication and system logs for indicators of compromise published by Mandiant and Cisco.
- This week: Implement enhanced logging and forward device logs to SIEM for behavioral anomaly detection.
---
FortiBleed: 110 Million Credentials Harvested from FortiGate Devices
What happened: A Russian-speaking initial access broker has systematically targeted over 430,000 FortiGate firewalls worldwide since February 2026, harvesting approximately 110 million credentials through brute-force attacks, service enumeration, and deployment of bespoke credential-harvesting tools. The campaign, dubbed FortiBleed, represents one of the largest documented credential theft operations targeting enterprise network perimeter devices.
Impact: Organizations relying on FortiGate infrastructure face severe risk of unauthorized network access, credential replay attacks, and sale of access to ransomware operators. Compromised credentials provide attackers with VPN access, internal routing information, and potential lateral movement paths. The scale suggests thousands of organizations globally have been compromised, with credentials likely circulating in initial access broker marketplaces.
Recommendations:
- 0–24h: Force password resets for all accounts with FortiGate access; implement minimum 16-character complexity requirements.
- 0–24h: Audit FortiGate authentication logs since February 2026 for login attempts from unexpected geolocations or rapid sequential authentication patterns.
- 24–72h: Enforce multi-factor authentication on all FortiGate administrative interfaces and VPN endpoints.
- This week: Deploy network-based detection for anomalous service enumeration and port scanning targeting FortiGate management interfaces.
- This week: Review firewall rules and VPN access policies; revoke unnecessary privileges and implement least-privilege access controls.
---
CISA: Lantronix and Ubiquiti Flaws Exploited in the Wild
What happened: CISA added CVE-2025-67038, a critical code injection vulnerability (CVSS 9.8) in Lantronix EDS5000 Series devices, to the Known Exploited Vulnerabilities catalog. Federal agencies must remediate by June 26, 2026. Separately, CISA warned of maximum-severity vulnerabilities in Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers under active exploitation. CVE identifiers for the Ubiquiti/Lantronix flaws have not been publicly disclosed.
Impact: Lantronix EDS5000 devices are industrial serial-to-Ethernet converters commonly deployed in OT/ICS environments. The code injection flaw allows unauthenticated remote code execution, enabling attackers to pivot into operational technology networks and disrupt industrial processes. Ubiquiti UniFi OS manages enterprise network infrastructure; compromise exposes entire network topology and traffic. Active exploitation significantly elevates risk.
Recommendations:
- 0–24h: Identify all Lantronix EDS5000, Ubiquiti UniFi OS, and Lantronix serial-to-ethernet devices using asset discovery tools.
- 0–24h: Apply vendor patches immediately; monitor Lantronix and Ubiquiti security advisories for updates.
- 0–24h: Isolate unpatched devices behind firewalls with strict ACLs; disable remote access if patching is delayed.
- 24–72h: Review device logs for suspicious outbound connections or unexpected administrative access.
- This week: Implement network segmentation to limit lateral movement from compromised OT/ICS devices.
---
Supply Chain Threats: Cordyceps, LastPass, and Malicious AI Skills
What happened: Researchers at Novee Security disclosed "Cordyceps," a critical CI/CD workflow vulnerability exposing 300+ GitHub repositories to supply-chain attacks at Microsoft, Google, and Apache. The flaw allows attackers to hijack GitHub Actions workflows and gain full repository control. Separately, LastPass confirmed a data breach resulting from the Klue supply chain attack, where stolen OAuth tokens enabled unauthorized access to customer data in LastPass's Salesforce environment. Unit 42 also discovered malicious AI skills in ClawHub's marketplace that evade automated scanners and deploy infostealers.
Impact: Organizations using affected GitHub repositories face risk of backdoored releases, secret exfiltration, and downstream customer compromise. LastPass users may be targeted with phishing based on leaked support data. The AI supply chain threat represents a novel attack vector where compromised AI components bypass traditional security controls.
Recommendations:
- 0–24h: Audit GitHub Actions workflows for unsafe
pull_request_targettriggers and untrusted input usage; restrict workflow permissions to least privilege. - 0–24h: Revoke unnecessary OAuth tokens with access to Salesforce, CRM, and support platforms; implement token expiration policies.
- 24–72h: If using LastPass, monitor for phishing attempts and review account activity logs for anomalies.
- This week: Audit all AI skills sourced from ClawHub marketplace; suspend untrusted skills until manual code review is complete.
- This week: Implement branch protection rules requiring code review for
.github/workflowsdirectory changes.
---
Threat Actor Activity
Scattered Spider: Guilty Pleas in Transport for London Breach
Two members of the Scattered Spider cybercrime group pleaded guilty in the UK to charges related to an August 2024 cyberattack that disrupted Transport for London's public transportation network. The guilty pleas occurred on the first day of trial. Scattered Spider, also tracked as Roasted 0ktapus and Octo Tempest, is known for sophisticated social engineering, identity-based attacks, and deployment of ransomware including BlackCat/ALPHV. The group has historically targeted enterprises with extensive cloud infrastructure.
Defensive focus: Implement FIDO2/WebAuthn-based MFA resistant to social engineering; monitor for suspicious domain account enumeration and cloud infrastructure discovery; detect NTDS credential dumping attempts; audit email forwarding rules and mailbox access patterns.
---
KongTuke Deploys Mistic Backdoor as Ransomware Access Broker
A new backdoor called Mistic has been discovered in financially motivated attacks targeting insurance, education, IT, and professional services sectors. The backdoor is linked to KongTuke, a ransomware access broker that specializes in gaining initial access and establishing persistent footholds for sale to ransomware operators. The use of custom backdoor malware indicates investment in tooling designed to evade detection while maintaining reliable command and control.
Defensive focus: Monitor for unusual outbound connections and C2 beaconing patterns; implement robust EDR to identify unauthorized remote access tools; conduct threat hunting for initial access broker activity including unusual account creation and credential access attempts; harden external-facing assets and enforce MFA on all remote access points.
---
Operation Endgame Disrupts Amadey and StealC Infrastructure
Europol, Microsoft, and international partners including Bitdefender, Bitsight, and ESET disrupted criminal infrastructure supporting Amadey botnet and StealC infostealer operations on June 24, 2026. The operation recovered 27 million stolen credentials and targeted infrastructure used to launch ransomware, financial fraud, and attacks on critical infrastructure. Both malware families represent commoditized cybercrime-as-a-service platforms distributed through malvertising, exploit kits, and phishing campaigns.
Defensive focus: Monitor for Amadey loader indicators including suspicious process execution chains; deploy credential theft detection controls for LSASS access and browser credential store access; implement application allowlisting and PowerShell logging; rotate passwords for accounts potentially exposed in the 27 million credential dataset; enforce MFA on critical systems.
---
Geopolitical Context
U.S. Sanctions Cyber Scam Money Laundering Networks in Cambodia
The U.S. Department of Justice seized cloud computing accounts belonging to HuiOne Group subsidiaries allegedly used for cyber scam money laundering. The Treasury Department simultaneously sanctioned nine individuals and 26 entities linked to Prince Group for assisting in the transfer of illicit proceeds. Cambodia has emerged as a significant hub for cyber-enabled fraud operations, including "pig butchering" investment scams and forced labor compounds facilitating large-scale financial crime. The coordinated enforcement action reflects sustained U.S. efforts to disrupt transnational cybercrime infrastructure in Southeast Asia.
---
WhatsApp Campaign Targets Nine Countries with RMM Tools
An active WhatsApp campaign distributes malicious VBScript files disguised as documents to WhatsApp Desktop and Web users, leading to installation of ManageEngine RMM software. Discovered by Kaspersky, the campaign targets users across Malaysia, Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, and Australia. The abuse of trusted communication platforms and legitimate remote management software demonstrates defense evasion tactics to bypass security controls.
---
Recommended Actions
Immediate (0–24 hours)
1. Patch Cisco infrastructure: Apply security updates for CVE-2026-20230 and CVE-2026-20245; audit for unauthorized accounts and suspicious activity.
2. Lantronix remediation: Identify and patch all EDS5000 devices; isolate unpatched systems behind firewalls (federal deadline: June 26).
3. FortiGate credential reset: Force password changes for all FortiGate administrative and VPN accounts; audit authentication logs since February 2026.
4. GitHub workflow audit: Review Actions workflows for unsafe triggers; restrict permissions and enable branch protection.
5. OAuth token review: Revoke unnecessary tokens with access to Salesforce and CRM systems; implement token expiration policies.
Near-term (24–72 hours)
1. Deploy MFA: Enforce multi-factor authentication on FortiGate, Cisco, and all remote access points.
2. Ubiquiti/Lantronix patching: Apply vendor updates for actively exploited vulnerabilities; monitor security advisories.
3. LastPass monitoring: If using LastPass, watch for phishing attempts and review account activity logs.
4. Credential rotation: Rotate passwords for privileged accounts and users with access to sensitive systems.
5. EDR tuning: Deploy detection rules for infostealer behavior, browser data exfiltration, and credential harvesting.
This week
1. Network segmentation: Isolate SD-WAN management interfaces, OT/ICS devices, and critical infrastructure from general network access.
2. AI supply chain audit: Review all third-party AI skills from ClawHub; suspend untrusted components until manual security review.
3. Threat hunting: Conduct proactive searches for initial access broker activity, unauthorized accounts, and lateral movement preparation.
4. Log forwarding: Enable comprehensive logging on network devices and forward to SIEM for behavioral anomaly detection.
5. User awareness training: Educate users on WhatsApp-based social engineering, ClickFix tactics, and risks of executing unexpected file attachments.
---
Watch List
- Totolink EX1200L routers: Stack-based buffer overflow (CVE-2026-44089) could enable remote code execution; monitor for proof-of-concept release and mass exploitation attempts.
- Edgecution malware: Malicious Microsoft Edge extension abuses Native Messaging to escape browser sandbox and deploy Python backdoors in ransomware attacks.
- npm supply chain: Three malicious packages (aes-decode-runner-pro, postcss-minify-selector, postcss-minify-selector-parser) delivered Windows RAT; audit package.json files and scan developer workstations.
- GitHub pwn request attacks: GitHub updating actions/checkout to block common attack patterns effective June 18, 2026; test workflows before enforcement date.
- Xsolis healthcare breach: Phishing attack compromised healthcare technology company, impacting approximately 1.4 million individuals.
- Tata Electronics breach: Indian electronics manufacturer confirmed cyberattack and data leak; implications for global technology supply chains.
---
Sources
- BleepingComputer: Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
- BleepingComputer: Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
- The Hacker News: CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited
- The Hacker News: FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
- The Hacker News: Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
- BleepingComputer: LastPass confirms data breach in Klue supply chain attack
- Unit 42 (Palo Alto): OpenClaw's Skill Marketplace and the Emerging AI Supply Chain Threat
- BleepingComputer: Scattered Spider members plead guilty to hacking Transport for London
- BleepingComputer: Amadey, StealC malware operations disrupted in Operation Endgame action
- The Hacker News: DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering
- The Hacker News: WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
- CERT.PL: Vulnerability in Totolink EX1200L router software
- Microsoft Security: StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them
- Krebs on Security: Scattered Spider Hackers Plead Guilty on Day 1 of Trial
---
Report compiled: June 25, 2026
Classification: Unclassified
Distribution: Professional IT audience
