# Threat Intel Brief — June 26, 2026

TL;DR

  • Critical Cisco vulnerabilities under active exploitation: CVE-2026-20245 (SD-WAN) and CVE-2026-20230 (Unified Communications Manager) enable root-level compromise; immediate patching required.
  • CISA warns of maximum-severity flaws: CVE-2025-67038 in Lantronix EDS5000 devices actively exploited; federal agencies face June 26 remediation deadline. Ubiquiti UniFi OS vulnerabilities also under attack.
  • Supply-chain risk escalates: "Cordyceps" CI/CD vulnerability exposes 300+ GitHub repositories at Microsoft, Google, and Apache to workflow hijacking and malicious code injection.
  • Law enforcement disrupts infostealer infrastructure: Operation Endgame takedown of Amadey and StealC networks recovers 27 million stolen credentials; threat actors expected to rebuild operations.
  • Ransomware access broker KongTuke deploys Mistic backdoor: Multi-sector campaign targeting insurance, education, IT, and professional services since April 2026.

---

Critical Threats

Cisco Catalyst SD-WAN Zero-Day Exploitation (CVE-2026-20245)

What happened
Mandiant disclosed that threat actors exploited CVE-2026-20245, a privilege escalation vulnerability in Cisco Catalyst SD-WAN Manager, at least two months before public disclosure. The flaw (CVSS 7.8) allows authenticated local attackers to execute arbitrary commands with root privileges and create persistent rogue administrative accounts. The zero-day exploitation window suggests potential widespread compromise of SD-WAN infrastructure.

Impact
Organizations running Cisco Catalyst SD-WAN face immediate risk of full device compromise. Attackers achieving root access can intercept network traffic, manipulate routing configurations, establish persistent backdoors, and pivot to connected network segments. SD-WAN devices represent high-value targets controlling wide-area network connectivity across enterprise environments.

Recommendations

  • Apply Cisco security patches for CVE-2026-20245 immediately to all Catalyst SD-WAN devices.
  • Audit local user accounts on SD-WAN infrastructure for unauthorized additions; review authentication logs for suspicious privilege escalation activity over the past 90 days.
  • Isolate SD-WAN management interfaces from untrusted networks and enforce strict access controls with multi-factor authentication.
  • Hunt for indicators of compromise including unexpected configuration changes, new scheduled tasks, or outbound connections from SD-WAN systems.

---

Cisco Unified Communications Manager Under Active Attack (CVE-2026-20230)

What happened
Threat actors are actively exploiting CVE-2026-20230, a critical vulnerability (CVSS 8.6) in Cisco Unified Communications Manager and Unified CM SME. The flaw involves improper input validation in HTTP requests, allowing unauthenticated remote attackers to achieve arbitrary file write access and escalate to root compromise. Proof-of-concept code is publicly available.

Impact
Successful exploitation grants attackers root-level system access without authentication, enabling complete compromise of voice and video communications infrastructure. Organizations face risks of data exfiltration, persistent backdoor installation, and disruption of critical communications services. The unauthenticated remote attack vector significantly lowers the exploitation barrier.

Recommendations

  • Immediately patch CVE-2026-20230 on all Cisco Unified Communications Manager instances; isolate unpatched systems from untrusted networks.
  • Review HTTP access logs for suspicious POST/PUT requests with unusual file paths or payloads indicating exploitation attempts.
  • Implement network segmentation to restrict administrative interface access to trusted management networks only.
  • Monitor for indicators of compromise including unexpected file modifications, new user accounts, or anomalous outbound connections from CUCM servers.

---

CISA: Critical Lantronix Flaw Actively Exploited (CVE-2025-67038)

What happened
CISA added CVE-2025-67038 to the Known Exploited Vulnerabilities catalog, warning of active exploitation of a critical code injection vulnerability (CVSS 9.8) in Lantronix EDS5000 Series devices. Federal agencies must remediate by June 26, 2026, under Binding Operational Directive 22-01. The devices are commonly deployed in government and critical infrastructure for serial-to-IP connectivity.

Impact
Attackers can execute arbitrary code on affected devices, potentially gaining full control of industrial serial-to-Ethernet gateways. This enables network pivoting, operational disruption, and data exfiltration in OT/ICS environments. The maximum severity rating indicates potential for complete system compromise with minimal exploitation complexity.

Recommendations

  • Apply vendor-supplied firmware patches immediately; check Lantronix support portal for CVE-2025-67038 remediation guidance.
  • Identify all EDS5000 devices using asset inventory and network scanning; isolate unpatched systems behind firewalls with management access restricted to trusted networks.
  • Monitor network traffic to/from EDS5000 devices for unusual connections or command injection attempts; review authentication logs for anomalies.
  • Federal agencies: ensure compliance with CISA BOD 22-01 by June 26 deadline.

---

Ubiquiti UniFi OS Maximum-Severity Vulnerabilities Exploited

What happened
CISA warned of maximum-severity vulnerabilities in Ubiquiti UniFi OS actively exploited by attackers. Specific CVE identifiers and affected versions were not disclosed in available reporting. UniFi OS manages network controllers, switches, and access points commonly deployed in enterprise environments.

Impact
Maximum severity rating indicates potential for complete system compromise. UniFi OS compromise could enable lateral movement, traffic interception, or persistent network access. Organizations face immediate risk to confidentiality, integrity, and availability of network infrastructure.

Recommendations

  • Identify all Ubiquiti UniFi OS devices in your environment using asset inventory and network scanning.
  • Isolate affected devices from internet exposure; restrict management access to trusted internal networks via firewall rules.
  • Check Ubiquiti security advisories for emergency patches and apply immediately when available.
  • Monitor logs from affected devices and upstream firewalls for unusual authentication attempts, configuration changes, or outbound connections.

---

Cordyceps: CI/CD Vulnerability Threatens 300+ GitHub Repositories

What happened
Novee Security researchers disclosed "Cordyceps," a critical CI/CD workflow vulnerability affecting 300+ GitHub repositories at major organizations including Microsoft, Google, and Apache. The flaw allows attackers to hijack GitHub Actions workflows and gain full repository control, enabling supply-chain attacks through malicious code injection into builds.

Impact
Organizations using affected repositories face supply-chain compromise risk. Attackers gaining repository control can inject malicious code into software builds, steal secrets, modify release artifacts, and compromise downstream consumers. The impact extends beyond directly affected organizations to their entire software supply chain.

Recommendations

  • Audit all GitHub Actions workflows for unsafe use of pull_request_target triggers, script injections, and untrusted input handling.
  • Review GitHub repository settings to restrict workflow permissions using principle of least privilege; enable required reviews for workflow changes.
  • Monitor GitHub audit logs for unexpected workflow modifications, new workflow files, or suspicious Actions executions.
  • Implement branch protection rules requiring code review and status checks before merging workflow changes.

---

Threat Actor Activity

KongTuke Deploys Mistic Backdoor in Multi-Sector Campaign

The ransomware access broker KongTuke has deployed a new stealthy backdoor named Mistic (also tracked as MLTBackdoor) in financially motivated attacks since April 2026. The campaign targets organizations across insurance, education, IT, and professional services sectors. KongTuke specializes in gaining initial access and establishing persistent backdoor access for subsequent sale to ransomware operators. The group's toolkit also includes ModeloRAT and leverages ClickFix social engineering techniques for initial compromise.

Organizations in targeted sectors should monitor for ClickFix-style social engineering lures, implement behavioral detection for backdoor persistence mechanisms, and deploy network monitoring for anomalous outbound connections consistent with RAT command-and-control traffic.

CL-STA-1062 Targets Southeast Asian Government and Critical Infrastructure

The CL-STA-1062 threat actor conducted espionage operations against Southeast Asian government entities and critical infrastructure using a hybrid toolkit centered around the custom TinyRCT backdoor. The targeting pattern suggests state-aligned or state-sponsored motivations focused on strategic intelligence collection. The actor's focus on government and critical infrastructure indicates objectives related to policy intelligence, diplomatic activities, and operational data on essential services.

Affected regions should enhance logging and behavioral detection for remote access tools, conduct threat hunting for TinyRCT indicators, and strengthen perimeter defenses against spear-phishing attempts targeting government personnel.

Law Enforcement Disrupts Amadey and StealC Infrastructure

Microsoft, Europol, and international partners disrupted infrastructure supporting Amadey and StealC infostealer operations on June 24, 2026, as part of Operation Endgame. The action recovered 27 million stolen credentials and targeted infrastructure used to launch ransomware, financial fraud, and attacks on critical infrastructure. While this specific infrastructure has been disrupted, threat actors typically rebuild operations using new domains and servers within weeks.

Organizations should review endpoint detection logs for Amadey and StealC indicators, force password resets for privileged accounts, and monitor for new infrastructure using threat intelligence feeds.

---

Geopolitical Context

U.S. Targets Cyber Scam Money Laundering Networks in Southeast Asia

The U.S. Department of Justice seized cloud computing accounts belonging to HuiOne Group subsidiaries allegedly used for cyber scam money laundering. Simultaneously, the Treasury Department announced sanctions against nine individuals and 26 entities linked to Prince Group for assisting in the transfer of illicit proceeds. The coordinated action reflects escalating U.S. efforts to disrupt transnational cyber-enabled financial crime networks operating in Cambodia, where online scam operations—often involving forced labor and human trafficking—have proliferated.

The enforcement action signals Washington's willingness to employ both criminal and economic tools against enablers of cyber fraud infrastructure, even when such actions may complicate bilateral relations. Regional financial institutions may face heightened compliance pressure to screen transactions linked to designated entities.

Polish Authorities Dismantle SIM-Swapping Gang

Polish authorities arrested four members of an organized cybercrime group responsible for breaching telecommunications partners and conducting SIM-swapping attacks to steal millions in cryptocurrency. The gang compromised email accounts and exploited telecom infrastructure to hijack victim mobile numbers, bypassing two-factor authentication to access cryptocurrency accounts.

The disruption demonstrates increasing law enforcement capacity within Central Europe to counter financially motivated cybercrime targeting digital assets. The case underscores systemic vulnerabilities in SMS-based authentication and may prompt regulatory scrutiny of telecommunications account security procedures across the European Union.

---

Recommended Actions

Immediate (0-24 hours)

  • Patch critical Cisco vulnerabilities: Apply security updates for CVE-2026-20245 (SD-WAN) and CVE-2026-20230 (Unified Communications Manager) to all affected devices.
  • Remediate Lantronix CVE-2025-67038: Federal agencies must meet June 26 deadline; private sector organizations should treat with equivalent urgency.
  • Remove malicious Chrome extension: Disable "Adblock for YouTube" extension (10M+ installs) via enterprise policy due to dormant script injection capability.
  • Isolate Ubiquiti UniFi OS devices: Restrict management access to trusted networks until patches are available and applied.
  • Block Bluekit phishing infrastructure: Deploy known Bluekit hostnames at DNS/web gateway level; monitor for 70+ newly identified domains.

Within 24-72 hours

  • Audit GitHub Actions workflows: Review for Cordyceps vulnerability patterns including unsafe pull_request_target triggers and untrusted input handling.
  • Hunt for Cisco compromise indicators: Review SD-WAN and CUCM logs for unauthorized account creation, privilege escalation, and configuration changes over past 90 days.
  • Validate credential integrity: Check if organizational credentials appear in 27 million records recovered from Amadey/StealC disruption; force resets where necessary.
  • Assess Shopify order notification abuse: Alert users to verify order receipts directly through merchant websites, not via embedded phone numbers or links.

This week

  • Deploy phishing-resistant MFA: Implement FIDO2/WebAuthn hardware tokens to counter Bluekit browser-in-the-middle attacks and SIM-swapping threats.
  • Review hospitality sector defenses: Organizations in Europe and Asia should block execution of .LNK files from ZIP archives and hunt for suspicious Node.js processes.
  • Strengthen CI/CD security: Implement branch protection rules, workflow permission restrictions, and audit logging for GitHub Actions environments.
  • Conduct Mistic backdoor threat hunting: Organizations in insurance, education, IT, and professional services should search for ClickFix lures and ModeloRAT indicators.

---

Watch List

  • Edgecution malicious Edge extension: Monitor for browser extension abuse leveraging Native Messaging to escape sandbox and deploy Python-based backdoors in ransomware operations.
  • Cisco zero-day exploitation patterns: Track for additional Cisco infrastructure vulnerabilities as attackers demonstrate capability to identify and weaponize flaws before disclosure.
  • Amadey/StealC infrastructure rebuild: Expect threat actors to deploy new command-and-control domains and servers following Operation Endgame disruption.
  • GitHub Actions supply-chain risks: Monitor for exploitation attempts targeting Cordyceps-vulnerable repositories and related CI/CD workflow weaknesses.
  • Southeast Asian scam infrastructure migration: Following U.S. enforcement actions, watch for cyber scam operations relocating to alternative jurisdictions or payment channels.

---

Sources

  • BleepingComputer: Poland busts SIM-swapping gang; Shopify Shop app abuse; Bluekit phishing kit; Adblock for YouTube extension; Cisco SD-WAN zero-day; DraftKings hacker sentencing; Mandiant SD-WAN disclosure; Malicious Edge extension; CISA Ubiquiti warning; Amadey/StealC disruption; Mistic backdoor
  • The Hacker News: Chrome ad blocker vulnerability; Mistic backdoor; Cisco SD-WAN CVE-2026-20245; CISA Lantronix warning; Amadey/StealC network disruption; Cordyceps CI/CD flaws; HuiOne Group seizure; Cisco Unified CM exploitation
  • Microsoft Security: Hospitality industry Node.js implant campaign; StealC and Amadey technical breakdown
  • Unit 42 (Palo Alto Networks): CL-STA-1062 Southeast Asian targeting

---

*This report synthesizes threat intelligence from multiple sources as of June 26, 2026. Organizations should validate findings against their specific environments and consult vendor advisories for detailed remediation guidance.*