- ## Þjónustu samantekt Fjölmargir kritískir veikleikar í kerfisstofnkerfum eru í virkri nýtingu í dag, sem býður á umhugsun. Þarf að úthluta með uppfærslum á **Fortinet FortiSandbox**, **Cisco SD-WAN Manager**, **Palo Alto Networks PAN-OS GlobalProtect VPN** og **Oracle PeopleSoft**, allar sem hafa CVE númer á CISA KEV lista. Aðfangakeðjuáráðstæður halda áfram að auka, með stórum nálgunum á **npm** skráðum og **Arch Linux AUR** geymslu, sem senda framleitt hugbúnað. Þar að aðallega eru ógnaraðilar að nýta veikleika í AI-þjónustu (**Microsoft 365 Copilot**, **OpenClaw**, **Langflow**) og kritískum þjónustum (**Redis**, **Microsoft Defender**) til að taka gagni og halda sig á kerfinu. ## ⚠️ Þörf á augnablikshandkæringu
- *🏢 Fortinet FortiSandbox Fjarkeyrsla kóða** Fjölmargir kritískir veikleikar (CVSS upp á 9.8) í FortiSandbox leyfa óauðkenndum hópum að keyra óvæntan kóða fjar. Í virkri nýtingu hefur verið staðfest.
- *CVE:** CVE-2026-39813, CVE-2026-39808, CVE-2026-25089, CVE-2026-26083, CVE-2026-44277 (CVSS: Upp á 9.8)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Útgáfur fyrir 5.0.6 og 4.4.9
- *Lagfært í:** FortiSandbox 5.0.6, 4.4.9
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [SC Media: Þrjár kritískir FortiSandbox veikleikar með 9.8 nýtingu](https://www.scworld.com/news/three-critical-fortisandbox-bugs-rated-98-actively-exploited)
- *🏢 Cisco Catalyst SD-WAN Manager Auðkenningarframhjáhlaup** Kritískur veikleikur (CVSS 10.0) í Cisco Catalyst SD-WAN Manager leyfir óauðkenndum hópum að ná aðgangi til stjórnenda. CISA hefur gefið út vextiþjónustu vegna nýtingar.
- *CVE:** CVE-2026-20127 (CVSS: 10.0)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Fjölmargar útgáfur fyrir 20.9.8.2
- *Lagfært í:** Útgáfa 20.9.8.2 og síðar
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [Help Net Security: Cisco birtir annan nýtaðan SD-WAN veikleika í tvö vikur](https://www.helpnetsecurity.com/?p=374774)
- *🏢 Palo Alto Networks PAN-OS GlobalProtect VPN Auðkenningarframhjáhlaup** Kritískur vandinn í PAN-OS GlobalProtect VPN geymslum leyfir hópum að framhjálpa auðkenningu og stofna óþýða VPN tengingar. Palo Alto Networks hefur staðfest nýtingu.
- *CVE:** CVE-2026-0257 (CVSS: 9.1)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** PAN-OS útgáfur fyrir 10.2.7
- *Lagfært í:** PAN-OS 10.2.7
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [The Hacker News: Palo Alto varnar fyrir nýtingu PAN-OS GlobalProtect veikleika](https://thehackernews.com/2026/06/palo-alto-warns-of-active-exploitation.html)
- *Oracle PeopleSoft Núll-daga fjarkeyrsla kóða** Þjónustuþjónninn ShinyHunters er í virkri nýtingu á kritískum núll-daga veikleika í Oracle PeopleSoft til að ná aðgangi og taka gagni. Þetta er áföng á daglegu skýrslu.
- *CVE:** CVE-2026-35273 (CVSS: 9.8)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** PeopleTools 8.61, 8.62
- *Lagfært í:** Uppfærslur tilgengilegar; skoðið útgefandastofnun fyrir sérstakar útgáfur.
- *Tímabundin lausn:** Ekki tilgreint í heimildum — skoðið útgefandastofnun
- *Heimild:** [Rapid7 Research: Nýting á Oracle PeopleSoft núll-daga veikleika (CVE-2026-35273)](https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273)
- *Check Point VPN Auðkenningarframhjáhlaup (Qilin gíslatökuhugbúnaður)** Kritískur vandinn í Check Point Remote Access og Mobile Access VPN (IKEv1) er nýtt af Qilin gíslatökuhugbúnaðarhópum til að ná óþýðum aðgangi.
- *CVE:** CVE-2026-50751 (CVSS: 9.3)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Remote Access og Mobile Access VPN sem tengdir með IKEv1
- *Lagfært í:** Uppfærslur útgefnar
- *Tímabundin lausn:** Ekki tilgreint í heimildum — skoðið útgefandastofnun
- *Heimild:** [Help Net Security: Vísindamenn birta upplýsingar, PoC fyrir nýtaðan Check Point VPN vandann](https://www.helpnetsecurity.com/?p=374393) ## 🔍 Þjónustu aðgerð
- *Aðfangakeðjuáráðstæður hækkar:** Þjónustuþjónnur hafa náð að 400 Arch Linux AUR pakka, með innsetningu af Rust-búnaði og eBPF rútskúr. Þar að aðallega er **npm** skráður í áráðstæðum af sjálfvirkum hugbúnaði (IronWorm, Miasma worm) sem tók aðgang að útvegaða aðgangslykilorðum og heimilisum.
- *Stjórnarsamþykkt spjall:** **FishMonger APT** hópur, tengdur Kína, hefur breytt **SprySOCKS** baktíð í Windows, með notkun á skráðum kärnufyrirritum (WIN_DRV, WIN_PLUS útgáfur) til að ná aðgangi í skjóttu og ávallt aðgangi til stjórnendur.
- *Norður-Kóresk spjallþjónusta:** **APT37 (ScarCruft)** er að gera spjallþjónustu með óþýðum Microsoft vörnarskýrslum til að senda **NarwhalRAT** hugbúnað með óþýðum LNK skráum í ZIP tengslum.
- *Android gíslatökuhugbúnaður:** **Rokarolla** hugbúnaður er skemmtandi sem algengar forrit (TikTok, Chrome) til að ná aðgangi að 217 fjármála- og kriptó forritum, með notkun á aðgangsþjónustu fyrir fullan aðgang og tók gagni. ## 📋 Uppfærslur og uppfærslur
- *Microsoft Defender:** Uppfærsla fyrir tvo nýtaða veikleika (CVE-2026-41091, CVE-2026-45498) leyfir réttindaaukning og þjónustuneitun. Uppfærðu Microsoft Defender Antimalware Platform útgáfu 4.18.2604 eða síðar.
- *Redis:** Fjölmargir kritískir veikleikar (þar með CVE-2026-23479) leyfir fjarkeyrslu kóða og DoS uppfærðar. Uppfærðu í nýjasta staðla útgáfu fyrir útgáfurnar þínar (6.x, 7.x, 8.x).
- *Splunk:** Uppfærðu fyrir fjölmargan kritískan veikleika í Splunk Enterprise og Cloud Platform, þar með pre-auðkenningu fjarkeyrslu kóða. Þær útgáfur sem eru ávallt fyrir 10.2.2 og önnur.
- *Rsync:** Red Hat, Debian og Ubuntu hafa útgefið uppfærslur sem aðgreina fjölmargan kritískan og háa vigt veikleika sem leyfir réttindaaukning og gögnaræði. ## Daglegar árangurir 1. **Uppfærðu á augnablik:** Fyrirsjá uppfærslur fyrir **FortiSandbox**, **Cisco SD-WAN Manager**, **Palo Alto GlobalProtect** og **Oracle PeopleSoft**. Athugaðu uppfærslu úthlutaðar á sérstakar veikar útgáfur sem lýst eru. 2. **Athugaðu VPN og fjarþjónustu:** Athugaðu stillingar fyrir Check Point VPN (að halda IKEv1 slökkva ef ekki þörf) og skoðaðu loggum fyrir óþýða auðkenningu á Palo Alto GlobalProtect geymslum. 3. **Leitaðu að aðfangakeðju nálgun:** Athugaðu notkun á npm pakka (`@automagik/genie`, `pgserve`) og Arch Linux AUR pakka. Leitaðu að gagnagjöf eða óþýðum net tengingum á útvegaðum vinnusvæðum og byggingarþjónum. 4. **Uppfærðu endapunktsvörn:** Gakðu út að Microsoft Defender Antimalware Platform er uppfærður í útgáfu 4.18.2604 eða síðar á öllum Windows endapunkta. ## 🔗 Heimildir - [SC Media: Þrjár kritískir FortiSandbox veikleikar með 9.8 nýtingu](https://www.scworld.com/news/three-critical-fortisandbox-bugs-rated-98-actively-exploited) - [Help Net Security: Cisco birtir annan nýtaðan SD-WAN veikleika í tvö vikur](https://www.helpnetsecurity.com/?p=374774) - [The Hacker News: Palo Alto varnar fyrir nýtingu PAN-OS GlobalProtect veikleika](https://thehackernews.com/2026/06/palo-alto-warns-of-active-exploitation.html) - [Rapid7 Research: Nýting á Oracle PeopleSoft núll-daga veikleika (CVE-2026-35273)](https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273) - [The Hacker News: Yfir 400 Arch Linux AUR pakka náðir til að senda infostealer og eBPF rútskúr](https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html)
## Executive Summary Multiple critical vulnerabilities in core enterprise infrastructure are under active, widespread exploitation this morning, posing an immediate threat. Urgent patching is required for **Fortinet FortiSandbox**, **Cisco SD-WAN Manager**, **Palo Alto Networks PAN-OS GlobalProtect VPN**, and **Oracle PeopleSoft**, all of which have CVEs on CISA's KEV list. Supply-chain attacks continue to escalate, with large-scale compromises of the **npm** registry and the **Arch Linux AUR** repository delivering sophisticated malware. Additionally, threat actors are exploiting vulnerabilities in AI-powered tools (**Microsoft 365 Copilot**, **OpenClaw**, **Langflow**) and critical services (**Redis**, **Microsoft Defender**) to steal data and gain persistence.
## ⚠️ Immediate Action Required
* **🏢 Fortinet FortiSandbox Remote Code Execution** Multiple critical vulnerabilities (CVSS up to 9.8) in FortiSandbox allow unauthenticated attackers to execute arbitrary code remotely. Active exploitation has been confirmed. * **CVE:** CVE-2026-39813, CVE-2026-39808, CVE-2026-25089, CVE-2026-26083, CVE-2026-44277 (CVSS: Up to 9.8) * **Status:** Active exploitation detected * **Vulnerable:** Versions prior to 5.0.6 and 4.4.9 * **Fixed:** FortiSandbox 5.0.6, 4.4.9 * **Workaround:** None mentioned in source * **Reference:** [SC Media: Three critical FortiSandbox bugs rated 9.8 actively exploited](https://www.scworld.com/news/three-critical-fortisandbox-bugs-rated-98-actively-exploited)
* **🏢 Cisco Catalyst SD-WAN Manager Authentication Bypass** A critical vulnerability (CVSS 10.0) in Cisco Catalyst SD-WAN Manager allows unauthenticated attackers to gain administrative access. CISA has issued an emergency directive due to active exploitation. * **CVE:** CVE-2026-20127 (CVSS: 10.0) * **Status:** Active exploitation detected * **Vulnerable:** Multiple releases prior to 20.9.8.2 * **Fixed:** Version 20.9.8.2 and later * **Workaround:** None mentioned in source * **Reference:** [Help Net Security: Cisco discloses second exploited SD-WAN vulnerability in two weeks](https://www.helpnetsecurity.com/?p=374774)
* **🏢 Palo Alto Networks PAN-OS GlobalProtect VPN Authentication Bypass** A critical flaw in PAN-OS GlobalProtect VPN gateways allows attackers to bypass authentication and establish unauthorized VPN connections. Palo Alto Networks has confirmed active exploitation. * **CVE:** CVE-2026-0257 (CVSS: 9.1) * **Status:** Active exploitation detected * **Vulnerable:** PAN-OS versions prior to 10.2.7 * **Fixed:** PAN-OS 10.2.7 * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw](https://thehackernews.com/2026/06/palo-alto-warns-of-active-exploitation.html)
* **Oracle PeopleSoft Zero-Day Remote Code Execution** The ShinyHunters extortion group is actively exploiting a critical zero-day in Oracle PeopleSoft to compromise systems and steal data. This is a follow-on to yesterday's reporting. * **CVE:** CVE-2026-35273 (CVSS: 9.8) * **Status:** Active exploitation detected * **Vulnerable:** PeopleTools 8.61, 8.62 * **Fixed:** Patches available; check Oracle advisory for specific versions. * **Workaround:** Not specified in source — check vendor advisory * **Reference:** [Rapid7 Research: Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)](https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273)
* **Check Point VPN Authentication Bypass (Qilin Ransomware)** A critical flaw in Check Point Remote Access and Mobile Access VPNs (IKEv1) is being exploited by Qilin ransomware affiliates to gain unauthorized access. * **CVE:** CVE-2026-50751 (CVSS: 9.3) * **Status:** Active exploitation detected * **Vulnerable:** Remote Access and Mobile Access VPNs configured with IKEv1 * **Fixed:** Patched versions released * **Workaround:** Not specified in source — check vendor advisory * **Reference:** [Help Net Security: Researchers release details, PoC for exploited Check Point VPN flaw](https://www.helpnetsecurity.com/?p=374393)
## 🔍 Threat Activity * **Supply-Chain Attacks Surge:** A widespread campaign has compromised over **400 Arch Linux AUR packages**, injecting a Rust-based infostealer and an eBPF rootkit. Separately, the **npm** registry is under attack by self-propagating malware (IronWorm, Miasma worm) stealing developer credentials and secrets. * **State-Sponsored Espionage:** The China-linked **FishMonger APT** group has expanded its **SprySOCKS** backdoor to Windows, using signed kernel drivers (WIN_DRV, WIN_PLUS variants) for stealthy, persistent access targeting government organizations. * **North Korean Phishing Campaign:** **APT37 (ScarCruft)** is conducting spear-phishing campaigns using fake Microsoft security alerts to deliver the **NarwhalRAT** malware via malicious LNK files in ZIP attachments. * **Android Banking Trojan:** The **Rokarolla** trojan is masquerading as popular apps (TikTok, Chrome) to target 217 financial and crypto applications, using Accessibility Services for complete device takeover and credential theft.
## 📋 Patches & Updates * **Microsoft Defender:** Patch for two actively exploited vulnerabilities (CVE-2026-41091, CVE-2026-45498) allowing privilege escalation and denial of service. Update to Microsoft Defender Antimalware Platform version 4.18.2604 or later. * **Redis:** Multiple critical vulnerabilities (including CVE-2026-23479) allowing remote code execution and DoS have been patched. Upgrade to the latest stable release for your version (6.x, 7.x, 8.x). * **Splunk:** Apply patches for multiple critical vulnerabilities in Splunk Enterprise and Cloud Platform, including a pre-authentication remote code execution flaw. Affected versions are prior to 10.2.2 and others. * **Rsync:** Red Hat, Debian, and Ubuntu have released updates addressing multiple critical and high-severity vulnerabilities enabling privilege escalation and data manipulation.
## Today's Priorities 1. **Patch Immediately:** Prioritize patching for **FortiSandbox**, **Cisco SD-WAN Manager**, **Palo Alto GlobalProtect**, and **Oracle PeopleSoft**. Verify patch deployment against the specific vulnerable versions listed. 2. **Review VPN & Remote Access:** Audit configurations for Check Point VPN (ensure IKEv1 is disabled if not needed) and review logs for any anomalous authentication attempts on Palo Alto GlobalProtect gateways. 3. **Scan for Supply-Chain Compromise:** Review internal use of npm packages (`@automagik/genie`, `pgserve`) and Arch Linux AUR packages. Scan developer workstations and build servers for signs of credential theft or unexpected network connections. 4. **Update Endpoint Security:** Ensure Microsoft Defender Antimalware Platform is updated to version 4.18.2604 or later across all Windows endpoints.
## 🔗 References
- [SC Media: Three critical FortiSandbox bugs rated 9.8 actively exploited](https://www.scworld.com/news/three-critical-fortisandbox-bugs-rated-98-actively-exploited)
- [Help Net Security: Cisco discloses second exploited SD-WAN vulnerability in two weeks](https://www.helpnetsecurity.com/?p=374774)
- [The Hacker News: Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw](https://thehackernews.com/2026/06/palo-alto-warns-of-active-exploitation.html)
- [Rapid7 Research: Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)](https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273)
- [The Hacker News: Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit](https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html)