Cybersecurity Intelligence Report — 25 June 2026

Written by

in

CRITICAL SECTION

  • [13] Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks (TheHackerNews)
    Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains.
  • [11] Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) (HelpNetSecurity) — CVEs: CVE-2026-20230

    CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. “Our honeypots are seeing automated sweeps dropping webshells, all via Tor,” threat intelligence firm Defused warned today, after observing initial attacks over the weekend. “The observed chain abuses the WebDialer SSRF to deploy a rog

  • [10] CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited (TheHackerNews) — CVEs: CVE-2025-67038
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 26, 2026.
  • [10] Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered (TheHackerNews)
    A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC.
  • [10] LastPass customer data exposed through Klue supply chain attack (HelpNetSecurity)

    LastPass disclosed that attackers used OAuth tokens compromised in a supply chain attack on Klue, a market intelligence platform that integrates with CRM and sales tools across organizations, to access customer data stored in its Salesforce environment. “On June 12th LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams which integrates with our Salesforce and Gong systems,“ LastPass said. “We imm

CISA KEV SECTION

CVE Vendor/Product Score Required Action

RANSOMWARE VICTIMS (DLS Monitoring)

  • anubis: Quest Health Solutions
  • stormous: mlit.com.my UPDATE-FULL DATA DUMP NEW LINK 10GB, jaggroup.com UPDATE-FULL DATA DUMP NEW LINK, maglificioliliana.com, lorenzoni-store.com, montechiaro-store.com, impulso-store.com
  • shinyhunters: Adapt******
  • nova: lpgroup, alejandria, transvill, transvill.com.pe, alejandria.biz, lpgroup.pt
  • akira: Jit Ex, Miami Machine
  • qilin: Cash Canada

NEWS

  • [9] Law enforcement hits StealC and Amadey malware networks (HelpNetSecurity) —

    Operation Endgame, the largest international law enforcement operation aimed at disrupting ransomware and cybercrime infrastructure across the world, has claimed its latest targets: StealC and Amadey. The notice on disrupted websites (Source: Microsoft) While developed by separate criminal groups, those two malware families work in tandem to compromise devices and harvest sensitive data. Law enforcement and private sector partners, including Microsoft and Proofpoint, coordinated action agains

  • [8] Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking (SecurityWeek) —

    The security defects allow unauthenticated users to take control of the open source software supply chain.

  • [7] Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access (BleepingComputer) — New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. […]
  • [6] Brinqa BYOAI lets organizations use any AI platform with trusted risk data (HelpNetSecurity) —

    Brinqa BYOAI (Bring Your Own AI), a capability that enables organizations to connect any AI agent, large language model (LLM), or automation platform to Brinqa’s exposure intelligence layer. As enterprises adopt AI, they need to ensure that AI systems use accurate, up-to-date risk data. BYOAI connects existing AI tools to a common source of exposure intelligence, providing a consistent foundation for analysis and decision-making. For enterprises, the difference between AI that delivers meanin

SUMMARY

Total new items: 51. Critical items: 5. Ransomware victims today: 17. Top CVEs to patch: CVE-2026-20230, CVE-2025-67038, CVE-2026-20245.

Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

Companion report: Cyber report (HTML)

Companion HTML report: Download report

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *