- # Morningsþjónustu fyrir stjórnendur
- Dagsetning:** 2026-06-07 | **Tími:** 08:00 UTC | **Fjölskyldu:** Fyrirtækið öryggisstjóra, CISO ## Þjónustu samantekt Virk nýting á kritískum veikleikum í ytri og netkerfi halda áfram með háan hraða, með **SolarWinds Serv-U**, **Cisco SD-WAN** og **Palo Alto PAN-OS** allar undir virkri nýtingu. Aðfangakeðjuangreifðir eru aukinnar, með nýjum auðkenningarháðum vírskírðum sem komast í **npm** og flóknuðum stjórnarstjórnunargreifðum (**OP-512**) sem ákveða **Microsoft IIS** netþjóni með sérstökum netveiðum. Nýr, hákostur **HTTP/2 Bomb** þjónustuneitunaveikleiki (CVE-2026-49975) getur kastað út á vefþjóna með háan hraða. ## ⚠️ Þörf á augnablikshandkenni
- *🏢 Palo Alto Networks PAN-OS GlobalProtect Auðkenningarframhjáhlaup** Óauðkenndir hættulegir notendur geta stofnað óþýðaðar VPN tengingar með hjálp við CVE-2026-0257. Virk nýting er staðfest.
- *CVE:** CVE-2026-0257 (CVSS: 9.1)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** PAN-OS fyrir 10.2.7
- *Lagfært í:** Útgáfa 10.2.7
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [Unit 42: Þjónustuþekking: Virk nýting á PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/?p=182026)
- *🏢 Cisco Catalyst SD-WAN Manager kritískar vegabrot** Fjöldi kritískra veikleika, með CVE-2026-20127 (CVSS 10.0), leyfir óauðkenndum aðgangi til stjórnenda. Nýtt er í virkri nýtingu.
- *CVE:** CVE-2026-20127 (CVSS: 10.0)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Fjöldi útgáfa SD-WAN Manager og Controller (Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda)
- *Lagfært í:** Uppfærslur og aðgerðir eru tiltækar (Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda)
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [The Hacker News: Cisco Catalyst SD-WAN Manager CVE-2026-20245 vegabrot nýtt í virkri nýtingu – Engin uppfærsla](https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html)
- *SolarWinds Serv-U þjónustuneitunaveikleiki** Óauðkenndar POST tengingar geta kastað út Serv-U útgáfum með hjálp við CVE-2026-28318. Bætt við CISA's KEV katalog.
- *CVE:** CVE-2026-28318 (CVSS: 7.5)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Útgáfur fyrir 15.5.4
- *Lagfært í:** Útgáfa 15.5.4 HF1
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [The Hacker News: CISA bætir við virkri nýtingu SolarWinds Serv-U þjónustuneitunaveikleika í KEV katalog](https://thehackernews.com/2026/06/cisa-adds-actively-exploited-solarwinds.html)
- *HTTP/2 Bomb þjónustuneitunaveikleiki** Nýr aðgerð sem sameinar HPACK samsetningar og Slowloris-stíl flæði stýring (CVE-2026-49975) getur snúið út minni og kastað út NGINX, Apache, IIS og Cloudflare þjónum.
- *CVE:** CVE-2026-49975 (CVSS: Ekki tilgreint)
- *Staða:** Birt
- *Veikar útgáfur:** NGINX, Apache, IIS, Envoy, Cloudflare (ekki nákvæmlega lýst)
- *Lagfært í:** Uppfærslur og aðgerðir eru útvegaðar (Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda)
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [The Hacker News: Nýr HTTP/2 Bomb veikleiki leyfir fjarþjónustuneitun á NGINX, Apache, IIS, Envoy & C](https://thehackernews.com/2026/06/new-http2-bomb-vulnerability-allows.html)
- *Linux kérna 'Dirty Frag' réttindaaukning** Kritískur veikleiki í Linux kérnu leyfir óþýðaðan notanda að ná að rót. Nýtt er í virkri nýtingu.
- *CVE:** CVE-2026-43284 (CVSS: 8.8)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Fjöldi kérna útgáfa (Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda)
- *Lagfært í:** Uppfærslur eru tiltækar fyrir sumar hluti; önnur eru ekki
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [SC Media: Nýr Linux réttindaaukningaveikleiki 'Fragnesia' birtur; PoC tiltækt](https://www.scworld.com/news/new-linux-privilege-escalation-flaw-fragnesia-disclosed-poc-available) ## 🔍 Þjónustu aðgerð
- *🏢 Stjórnarstjórnunargreifðir á IIS þjónum:** Þjónustuþekkingin **OP-512** er að búa til sérstök netveið á **Microsoft IIS** þjónum fyrir spáning. Fyrirtæki sem nota IIS ættu að skoða loggum fyrir óþýðaða aðgerðir og tryggja að öll þekktir veikleikar séu lagaðir.
- *Aðfangakeðju vírskírðir hlaða npm kerfi:** Óþýðaðar vírskírðir (**IronWorm**, **Miasma**) hlaða auðkenningum frá útvegar með óþýðaðum npm pakka, með 32 hættulegum **@redhat-cloud-services** pakka. Vírskírðin nota postinstall skrár og senda gögn til C2 þjóna.
- *Netveiðar gefa macOS bærtöku:** **FlutterShell** bærtöku er send á macOS notendur með óþýðaðum Google og YouTube vélbærum, oftar sem spáða eða PDF forrit. Það leyfir fjarþjónustu aðgang og vefsíðu áhrif.
- *Netveiðar aukast í heimslóð:** Þjónustuþekkingin **TA4922** hefur breytt aðgerð, með HR og fyrirtæki lúsur til að senda vírskírði eins og Atlas RAT til áhugamál í Stóra Bretlandi, Þýskalandi, Ítalíu og Suður-Afríku.
- *Stórt gagnaleki á Instructure Canvas:** Þjónustuþekkingin **ShinyHunters** bráðaði Canvas undirbúningi, útvegaði gögn frá 8,809 skólum og kvaðst að kosta. Þau ættu að tryggja að aðgangsorð sé breytt og MFA virkt. ## 📋 Uppfærslur og uppfærslur
- *🏢 Microsoft SharePoint RCE uppfærslur:** Fjöldi kritískra fjarkeyrslu kóða veikleika í **SharePoint Server** (CVE-2026-20963, CVSS 8.8) hefur verið lagað. Tryggðu að SharePoint 2016, 2019 og nýrra séu uppfærð.
- *🏢 Cisco Unified CM SSRF uppfærslur:** Kritískur Server-Side Request Forgery veikleiki (**CVE-2026-20230**, CVSS 8.6) í Cisco Unified Communications Manager, sem leyfir skrár og réttindaaukning, hefur verið lagað. Þjónustuþekking er opinber.
- *Google Chrome núll-daga uppfærslur:** Uppfærðu Chrome í útgáfu 145+ til að bæta við núll-daga veikleika **CVE-2026-2441**, sem leyfir fjarkeyrslu kóða.
- *Android núll-daga uppfærslur:** Google's júní 2026 Android öryggisuppfærslur bæta 124 veikleika, með núll-daga réttindaaukning veikleika **CVE-2025-48595**. Áhrif á Android 14.0 og fyrir. ## Þessar dagsetningar árangur 1. **Uppfærðu netkerfi:** Þú ættir að nota tilgengilegar uppfærslur fyrir **Palo Alto PAN-OS** (CVE-2026-0257) og **Cisco SD-WAN** veikleika. Þessi eru undir virkri nýtingu. 2. **Skoðaðu útvegaða vefþjóna:** Skoðaðu öll útvegaða **NGINX, Apache og IIS** vefþjóna fyrir útvegaða áhrif af nýju HTTP/2 Bomb þjónustuneitunaveikleika (CVE-2026-49975) og notaðu framleiðandann aðgerðir. 3. **Skannarðu fyrir hættulegum npm pakka:** Þjónustu ættu að skoða afhengi, sérstaklega fyrir **@redhat-cloud-services** og önnur npm pakka, og fjarlægðu hvaða óþýðaða eða þekkt hættulega útgáfur. 4. **Skoðaðu IIS vefþjóna:** Skoðaðu Microsoft IIS vefþjóna fyrir merki af **OP-512** netveiðar aðgerð, tryggðu að aðgerðir séu í samræmi og skoðaðu vefþjóna loggum fyrir óþýðaða aðgerðir. ## 🔗 Heimildir - [Unit 42: Þjónustuþekking: Virk nýting á PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/?p=182026) - [The Hacker News: Cisco Catalyst SD-WAN Manager CVE-2026-20245 vegabrot nýtt í virkri nýtingu – Engin uppfærsla](https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html) - [The Hacker News: Nýr HTTP/2 Bomb veikleiki leyfir fjarþjónustuneitun á NGINX, Apache, IIS, Envoy & C](https://thehackernews.com/2026/06/new-http2-bomb-vulnerability-allows.html) - [Microsoft Security Blog: Preinstall til aðgangsþjónustu: Innan í Red Hat npm Miasma auðkenningarháða aðgerð](https://www.microsoft.com/en-us/security/blog/?p=147916) - [The Hacker News: Nýr þjónustuþekkingur OP-512 ákveður Microsoft IIS vefþjóna með sérstökum netveiðum](https://thehackernews.com/2026/06/new-threat-cluster-op-512-targets.html)
# Morning Executive Threat Briefing **Date:** 2026-06-07 | **Time:** 08:00 UTC | **Audience:** Enterprise Security Administrators, CISOs
## Executive Summary Active exploitation of critical vulnerabilities in perimeter and network infrastructure continues at a rapid pace, with **SolarWinds Serv-U**, **Cisco SD-WAN**, and **Palo Alto PAN-OS** all under active attack. Supply chain attacks are evolving, with new credential-stealing worms hitting **npm** and a sophisticated state-sponsored campaign (**OP-512**) targeting **Microsoft IIS** servers with custom web shells. A novel, high-impact **HTTP/2 Bomb** DoS vulnerability (CVE-2026-49975) threatens to crash major web server platforms in seconds.
## ⚠️ Immediate Action Required * **🏢 Palo Alto Networks PAN-OS GlobalProtect Auth Bypass** Unauthenticated attackers can establish unauthorized VPN connections via CVE-2026-0257. Active exploitation is confirmed. * **CVE:** CVE-2026-0257 (CVSS: 9.1) * **Status:** Active exploitation detected * **Vulnerable:** PAN-OS prior to 10.2.7 * **Fixed:** Version 10.2.7 * **Workaround:** None mentioned in source * **Reference:** [Unit 42: Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/?p=182026)
* **🏢 Cisco Catalyst SD-WAN Manager Critical Flaws** Multiple critical vulnerabilities, including CVE-2026-20127 (CVSS 10.0), allow unauthenticated administrative access. Actively exploited. * **CVE:** CVE-2026-20127 (CVSS: 10.0) * **Status:** Active exploitation detected * **Vulnerable:** Various releases of SD-WAN Manager and Controller (Not specified in source — check vendor advisory) * **Fixed:** Patches and mitigations are available (Not specified in source — check vendor advisory) * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch](https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html)
* **SolarWinds Serv-U DoS Vulnerability** Unauthenticated POST requests can crash Serv-U installations via CVE-2026-28318. Added to CISA's KEV catalog. * **CVE:** CVE-2026-28318 (CVSS: 7.5) * **Status:** Active exploitation detected * **Vulnerable:** Versions prior to 15.5.4 * **Fixed:** Version 15.5.4 HF1 * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog](https://thehackernews.com/2026/06/cisa-adds-actively-exploited-solarwinds.html)
* **HTTP/2 Bomb DoS Vulnerability** A novel attack combining HPACK compression bombs with Slowloris-style flow control (CVE-2026-49975) can rapidly exhaust memory and crash NGINX, Apache, IIS, and Cloudflare servers. * **CVE:** CVE-2026-49975 (CVSS: Not specified) * **Status:** Disclosed * **Vulnerable:** NGINX, Apache, IIS, Envoy, Cloudflare (specific versions not detailed) * **Fixed:** Patches and mitigations are being rolled out (Not specified in source — check vendor advisory) * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & C](https://thehackernews.com/2026/06/new-http2-bomb-vulnerability-allows.html)
* **Linux Kernel 'Dirty Frag' Privilege Escalation** A critical local privilege escalation flaw in the Linux kernel allows unprivileged users to gain root access. Actively exploited. * **CVE:** CVE-2026-43284 (CVSS: 8.8) * **Status:** Active exploitation detected * **Vulnerable:** Multiple kernel versions (Not specified in source — check vendor advisory) * **Fixed:** Patches available for some components; others lack fixes (Not specified in source — check vendor advisory) * **Workaround:** None mentioned in source * **Reference:** [SC Media: New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available](https://www.scworld.com/news/new-linux-privilege-escalation-flaw-fragnesia-disclosed-poc-available)
## 🔍 Threat Activity * **🏢 State-Sponsored Web Shells Target IIS Servers:** The China-linked threat cluster **OP-512** is deploying a custom web shell framework on **Microsoft IIS** servers for espionage. Organizations using IIS should review logs for suspicious activity and ensure all known vulnerabilities are patched. * **Supply Chain Worms Infect npm Ecosystem:** Self-propagating malware (**IronWorm**, **Miasma**) is stealing developer credentials via malicious npm packages, including 32 compromised **@redhat-cloud-services** packages. The malware uses postinstall scripts and exfiltrates data to C2 servers. * **Malvertising Delivers macOS Backdoor:** The **FlutterShell** backdoor is being distributed to macOS users via malicious Google and YouTube ads, often disguised as podcast or PDF apps. It enables remote shell access and browser hijacking. * **Phishing Campaigns Expand Geographically:** The China-linked actor **TA4922** has expanded operations, using HR and business lures to deliver malware like Atlas RAT to targets in the UK, Germany, Italy, and South Africa. * **Major Data Breach at Instructure Canvas:** The **ShinyHunters** group breached the Canvas education platform, exfiltrating data from 8,809 schools and issuing ransom demands. Affected institutions should enforce password resets and MFA.
## 📋 Patches & Updates * **🏢 Microsoft SharePoint RCE Patches:** Multiple critical Remote Code Execution vulnerabilities in **SharePoint Server** (CVE-2026-20963, CVSS 8.8) have been patched. Ensure SharePoint 2016, 2019, and later are updated. * **🏢 Cisco Unified CM SSRF Patched:** A critical Server-Side Request Forgery vulnerability (**CVE-2026-20230**, CVSS 8.6) in Cisco Unified Communications Manager, allowing file write and privilege escalation, has been patched. Exploit code is public. * **Google Chrome Zero-Day Patched:** Update Chrome to version 145+ to address the actively exploited zero-day **CVE-2026-2441**, which allowed remote code execution. * **Android Zero-Day Patched:** Google's June 2026 Android security patches address 124 flaws, including the actively exploited privilege escalation zero-day **CVE-2025-48595**. Affects Android 14.0 and earlier.
## Today's Priorities 1. **Patch Network Infrastructure:** Immediately apply available patches for **Palo Alto PAN-OS** (CVE-2026-0257) and **Cisco SD-WAN** vulnerabilities. These are under active attack. 2. **Assess Web Server Exposure:** Review all externally facing **NGINX, Apache, and IIS** servers for exposure to the new HTTP/2 Bomb DoS attack (CVE-2026-49975) and apply vendor mitigations. 3. **Scan for Compromised npm Packages:** Development teams must audit dependencies, particularly for **@redhat-cloud-services** and other npm packages, and remove any suspicious or known-malicious versions. 4. **Review IIS Server Hardening:** Audit Microsoft IIS servers for signs of the **OP-512** web shell campaign, ensure strict patch compliance, and review web server logs for anomalous activity.
## 🔗 References
- [Unit 42: Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/?p=182026)
- [The Hacker News: Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch](https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html)
- [The Hacker News: New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & C](https://thehackernews.com/2026/06/new-http2-bomb-vulnerability-allows.html)
- [Microsoft Security Blog: Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing cam](https://www.microsoft.com/en-us/security/blog/?p=147916)
- [The Hacker News: New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Fr](https://thehackernews.com/2026/06/new-threat-cluster-op-512-targets.html)