- # Morningsfyrirlestur fyrir stjóra
- Dagsetning:** 2026-06-25 | **Tími:** 08:00 UTC
- Fjölskyldu:** Fyrirtækjastjóra og öryggisstjóra (CISO) ## Fyrirlestrarháttur Þjóðarhættirnar eru ennþá kynntar með **fjölmargum kritískum veikleikum í virkri nýtingu**, sem krefjast áætlaðra uppfærslu umferða. **Cisco** er aðalmarkmið, með nýjum tilfelli um webshell útbreiðslu með einnæðisútgáfunni Unified CM SSRF (CVE-2026-20230) og halda nýtingu á SD-WAN auðkenningarframhjáhlaup (CVE-2026-20127). **FortiBleed** gagnaleki hefur breiddist, nú með tilgátu um 110 milljón auðkenni frá yfir 86.000 tækin. Þar að auki, hefur **aðfangakeðjubrot** áhrif á 42 TanStack npm pakka með stjórnartóknum OIDC lyklum, sýnilega sýn á sýnilegri aðferð á stjórnendur. Lögheimildin **Operation Endgame** hefur brotlega stóða á mikilvægum gíslatökuhugbúnaði, en undirliggjandi veikleikar sem þeir nýttu eru ennþá farþegar. ## ⚠️ Þarf á augnablikshandkenni
- *Cisco Unified Communications Manager SSRF nýtt fyrir webshells** Kritískur Server-Side Request Forgery (SSRF) veikleiki er í virkri nýtingu til að skrifa óvænta skrár og hækka réttindi til rótt á Cisco Unified Communications Manager (Unified CM) tækin.
- *CVE:** CVE-2026-20230 (CVSS: 8.6)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Útgáfur 14 fyrir 14SU6, útgáfur 15 fyrir 15SU5
- *Lagfært í:** Útgáfur 14SU6 og 15SU5
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** Help Net Security ([Cisco Unified CM veikleiki er í virkri nýtingu til að setja webshells (CVE-2026-20230)](https://www.helpnetsecurity.com/?p=375890))
- *Cisco Catalyst SD-WAN Manager auðkenningarframhjáhlaup** Auðkenningarframhjáhlaup (CVSS 10.0) leyfir óauðkenndum hættum að fá stjórnarréttindi á Cisco Catalyst SD-WAN Manager og stjórnandinn. Þetta veikleiki er á CISA's KEV lista og er í virkri nýtingu.
- *CVE:** CVE-2026-20127 (CVSS: 10.0)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Fjölmargar útgáfur fyrir 20.9.8.2
- *Lagfært í:** Útgáfu 20.9.8.2
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** The Hacker News ([Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 nýtt til að fá rótt aðgang](https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-zero-day-cve-2026.html))
- *Oracle PeopleSoft Zero-Day fjarkeyrsla kóða** Kritískur zero-day veikleiki í Oracle PeopleSoft er í virkri nýtingu af ShinyHunters hættum fyrir óauðkenndar fjarkeyrslur kóða og gagnasafnshátt.
- *CVE:** CVE-2026-35273 (CVSS: 9.8)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** PeopleTools 8.61 og 8.62
- *Lagfært í:** Mættir útgefnar; fullar uppfærslur í vinnu
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** Rapid7 Research ([Virk nýting á Oracle PeopleSoft Zero-Day (CVE-2026-35273)](https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273))
- *Splunk Enterprise óauðkennd fjarkeyrsla kóða** Kritískur veikleiki í Splunk Enterprise leyfir óauðkennd fjarkeyrsla kóða og er í virkri nýtingu áður en útgefin var.
- *CVE:** CVE-2026-20253 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Splunk Enterprise 10.0.0 til 10.2.3 og eldri
- *Lagfært í:** Nýjastar uppfærslur
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** Help Net Security ([Óauðkennd RCE í Splunk Enterprise í virkri nýtingu (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286)) ## 🔍 Hættu aðgerð
- *🏢 FortiBleed gagnaleki hefur breiddist:** FortiBleed aðgerð hefur tilgátu um að hafa birt gagni fyrir yfir **86.000 Fortinet tækin**, með hættum sem samlagðu **110 milljón auðkenni**. Gagnaleikið inniheldur stjórnar- og SSL VPN auðkenni frá internetfærum FortiGate tækin, sem leyfir netfjáráhrif með auðkenni úthluta. Það er kritískt að breyta auðkenni á meðferð og skoða VPN/FortiGate loggum fyrir óþekkt aðgang. Heimild: The Hacker News ([FortiBleed áhrif á FortiGate tækin í 110 milljón auðkenni úthluta](https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html))
- *Sýnileg npm aðfangakeðja aðgerð:** **TeamPCP** hættur hafði áhrif á 42 TanStack npm pakka með aðferðum sem notaði GitHub Actions til að stjóða OIDC lyklum, útgefnuðu óþekkt útgáfur með gildum SLSA upprunni. Gíslatökuhugbúnaðurinn samlagði auðkenni og stofnaði varanlega, áhrif á verkefni eins og Mistral AI og UiPath. Heimild: CyberScoop ([‘Mini Shai-Hulud’ gíslatökuhugbúnaður áhrif á hundruð af opnum kóða](https://cyberscoop.com/?p=88980))
- *Operation Endgame stóð gíslatökuhugbúnaðar net:** Þjóðarleg lögheimildar aðgerð, leidd af Europol, hefur stóð netið fyrir **Amadey** og **StealC** gíslatökuhugbúnað, sem hafa áhrif á yfir 140.000 tækin og samlagði 27 milljón auðkenni. Þó að þetta stóð hættum, eftirlátin gíslatökuhugbúnaðar ætti að vera ávallt ávallt. Heimild: The Hacker News ([Amadey og StealC gíslatökuhugbúnaðar net stóð, 27 milljón auðkenni fengin](https://thehackernews.com/2026/06/amadey-and-stealc-malware-network.html))
- *AryStinger botnet áhrif á gamla D-Link tækin:** AryStinger botnet hefur áhrif á þúsund af end-of-life **D-Link tækin** (t.d. DIR-850L) með þekktum veikleikum (CVE-2025-11837, CVE-2016-5681), sem breytir þeim í sameiginlega netvinnu fyrir upplýsingar, tengingar og DNS breytingar. Heimild: The Hacker News ([AryStinger gíslatökuhugbúnaður áhrif á 4.300 gamla tækin til að búa til upplýsingar net](https://thehackernews.com/2026/06/arystinger-malware-infects-4300-legacy.html)) ## 📋 Uppfærslur og uppfærslur
- *🏢 Fjölmargar kritískar veikleikar í nginx:** Red Hat og Ubuntu hafa útgefið uppfærslur fyrir fjölmargar kritískar veikleikar í nginx, þar á meðal CVE-2026-42945, sem leyfir óvænta kóða og þjónustuneitun. Þau tækin eru RHEL 8, 9, 10 og Ubuntu. Heimild: Red Hat Errata ([RHSA-2026:19374: Kritísk: nginx öryggisuppfærsla](https://access.redhat.com/errata/RHSA-2026:19374))
- *FFmpeg PixelSmash fjarkeyrsla kóða veikleiki (CVE-2026-8461):** Kritískur heap out-of-bounds skrúna veikleiki í FFmpeg's MagicYUV afraðgreining (CVSS 8.8) leyfir fjarkeyrslu kóða eða þjónustuneitun með úthlutaðum myndaröðum (AVI, MKV, MOV). Uppfærslur eru tiltækar. Heimild: Malwarebytes Labs ([PixelSmash veikleiki breytir myndaröðum í aðgerðarvélum](https://www.malwarebytes.com/blog/news/2026/06/pixelsmash-flaw-turns-video-files-into-attack-tools))
- *Google Chrome Zero-Day uppfærð:** Google hefur útgefið nýja uppfærslu fyrir Chrome (útgáfa 145) til að uppfæra kritískan zero-day veikleika (CVE-2026-2441) sem er í virkri nýtingu. Heimild: SC Media ([Google útgefir nýja uppfærslu fyrir fimm Chrome zero-day nýtt í vinnu](https://www.scworld.com/brief/google-releases-emergency-update-for-fifth-chrome-zero-day-exploited-in-the-wild-this-year)) ## Þessar dagsetningar 1. **Uppfæra nýtaða Cisco og Oracle kerfi:** Því miður, skaltu skila uppfærslum fyrir Cisco Unified CM (CVE-2026-20230), Cisco SD-WAN Manager (CVE-2026-20127), og skoða Oracle PeopleSoft útgáfur fyrir tilgengilegar mættir fyrir CVE-2026-35273. 2. **Breyta Fortinet auðkenni og skoða aðgang:** Því miður, takaðu eftir að hættur hafa áhrif á internetfærum FortiGate tækin. Því miður, breytaðu auðkenni fyrir öll stjórnar- og SSL VPN aðgangi og gera útfrá aðgangi fyrir teygjandi aðgerð. 3. **Skoða CI/CD aðgerðir og npm afhengi:** Skoðaðu GitHub Actions stillingar fyrir óþekktu OIDC lyklum og leitaðu að áhrifum á TanStack npm pakka (@tanstack/*). Uppfæra FFmpeg bætistæður sem notaðar eru í meðalvinnslu forritum. 4. **Skoða CISA KEV lista:** Tryggðu að öll kerfi séu uppfærð fyrir veikleikar sem nýlega bætt voru við CISA's Known Exploited Vulnerabilities lista, þar á meðal fyrir Splunk (CVE-2026-20253) og öðru. ## 🔗 Heimildir - [Help Net Security: Cisco Unified CM veikleiki er í virkri nýtingu til að setja webshells (CVE-2026-20230)](https://www.helpnetsecurity.com/?p=375890) - [The Hacker News: FortiBleed áhrif á FortiGate tækin í 110 milljón auðkenni úthluta](https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html) - [CyberScoop: ‘Mini Shai-Hulud’ gíslatökuhugbúnaður áhrif á hundruð af opnum kóða](https://cyberscoop.com/?p=88980) - [Rapid7 Research: Virk nýting á Oracle PeopleSoft Zero-Day (CVE-2026-35273)](https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273) - [Help Net Security: Óauðkennd RCE í Splunk Enterprise í virkri nýtingu (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286)
# Morning Executive Briefing **Date:** 2026-06-25 | **Time:** 08:00 UTC **Audience:** Enterprise Security Administrators & CISOs
## Executive Summary The threat landscape remains highly active with **multiple critical vulnerabilities under active exploitation**, requiring immediate patching cycles. **Cisco** is a primary target, with new reports of webshell deployment via the Unified CM SSRF flaw (CVE-2026-20230) and continued exploitation of SD-WAN authentication bypass (CVE-2026-20127). The **FortiBleed** credential leak has expanded, now reportedly involving 110 million credentials from over 86,000 devices. Additionally, a significant **supply chain attack** has compromised 42 TanStack npm packages via stolen OIDC tokens, demonstrating a sophisticated attack vector against developer ecosystems. Law enforcement's **Operation Endgame** has disrupted major malware families, but the underlying vulnerabilities they exploited remain a risk.
## ⚠️ Immediate Action Required * **Cisco Unified Communications Manager SSRF Exploited for Webshells** A critical Server-Side Request Forgery (SSRF) vulnerability is being actively exploited to write arbitrary files and escalate privileges to root on Cisco Unified Communications Manager (Unified CM) appliances. * **CVE:** CVE-2026-20230 (CVSS: 8.6) * **Status:** Active exploitation detected * **Vulnerable:** Versions 14 prior to 14SU6, versions 15 prior to 15SU5 * **Fixed:** Patched in versions 14SU6 and 15SU5 * **Workaround:** None mentioned in source * **Reference:** Help Net Security ([Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)](https://www.helpnetsecurity.com/?p=375890))
* **Cisco Catalyst SD-WAN Manager Authentication Bypass** An authentication bypass flaw (CVSS 10.0) allows unauthenticated attackers to gain administrative access to Cisco Catalyst SD-WAN Manager and Controller. This vulnerability is on CISA's KEV catalog and is actively exploited. * **CVE:** CVE-2026-20127 (CVSS: 10.0) * **Status:** Active exploitation detected * **Vulnerable:** Multiple releases prior to 20.9.8.2 * **Fixed:** Patched in version 20.9.8.2 * **Workaround:** None mentioned in source * **Reference:** The Hacker News ([Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access](https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-zero-day-cve-2026.html))
* **Oracle PeopleSoft Zero-Day Remote Code Execution** A critical zero-day vulnerability in Oracle PeopleSoft is being actively exploited by the ShinyHunters threat group for unauthenticated remote code execution and data theft. * **CVE:** CVE-2026-35273 (CVSS: 9.8) * **Status:** Active exploitation detected * **Vulnerable:** PeopleTools 8.61 and 8.62 * **Fixed:** Mitigations released; full patches pending * **Workaround:** None mentioned in source * **Reference:** Rapid7 Research ([Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)](https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273))
* **Splunk Enterprise Unauthenticated Remote Code Execution** A critical vulnerability in Splunk Enterprise allows unauthenticated remote code execution and is under active attack shortly after disclosure. * **CVE:** CVE-2026-20253 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Splunk Enterprise 10.0.0 through 10.2.3 and earlier * **Fixed:** Patched in recent updates * **Workaround:** None mentioned in source * **Reference:** Help Net Security ([Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286))
## 🔍 Threat Activity * **🏢 FortiBleed Credential Leak Escalates:** The FortiBleed campaign has reportedly exposed credentials for over **86,000 Fortinet devices**, with threat actors harvesting **110 million credentials**. The leak involves administrative and SSL VPN credentials from internet-facing FortiGate firewalls, enabling network infiltration via credential stuffing. Immediate credential rotation and review of VPN/FortiGate logs for anomalous access is critical. Reference: The Hacker News ([FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation](https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html)) * **Sophisticated npm Supply Chain Attack:** The **TeamPCP** threat actor compromised 42 TanStack npm packages by exploiting GitHub Actions to steal OIDC tokens, publishing malicious versions with valid SLSA provenance. The malware steals credentials and establishes persistence, affecting projects like Mistral AI and UiPath. Reference: CyberScoop ([‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawl](https://cyberscoop.com/?p=88980)) * **Operation Endgame Disrupts Malware Infrastructure:** An international law enforcement operation led by Europol has disrupted the infrastructure for the **Amadey** and **StealC** malware families, which had infected over 140,000 devices and stolen 27 million credentials. While this disrupts criminal operations, enterprises should remain vigilant for infections using these now-orphaned malware strains. Reference: The Hacker News ([Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered](https://thehackernews.com/2026/06/amadey-and-stealc-malware-network.html)) * **AryStinger Botnet Targets Legacy Routers:** The AryStinger botnet has infected thousands of end-of-life **D-Link routers** (e.g., DIR-850L) using known vulnerabilities (CVE-2025-11837, CVE-2016-5681), turning them into a distributed proxy network for reconnaissance, traffic tunneling, and DNS hijacking. Reference: The Hacker News ([AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network](https://thehackernews.com/2026/06/arystinger-malware-infects-4300-legacy.html))
## 📋 Patches & Updates * **🏢 Multiple nginx Critical Vulnerabilities:** Red Hat and Ubuntu have released patches for multiple critical vulnerabilities in nginx, including CVE-2026-42945, which allow arbitrary code execution and denial of service. Affected systems include RHEL 8, 9, 10, and Ubuntu. Reference: Red Hat Errata ([RHSA-2026:19374: Critical: nginx security update](https://access.redhat.com/errata/RHSA-2026:19374)) * **FFmpeg PixelSmash RCE Vulnerability (CVE-2026-8461):** A critical heap out-of-bounds write vulnerability in FFmpeg's MagicYUV decoder (CVSS 8.8) allows remote code execution or denial-of-service via crafted video files (AVI, MKV, MOV). Patches are available. Reference: Malwarebytes Labs ([PixelSmash flaw turns video files into attack tools](https://www.malwarebytes.com/blog/news/2026/06/pixelsmash-flaw-turns-video-files-into-attack-tools)) * **Google Chrome Zero-Day Patched:** Google has released an emergency update for Chrome (version 145) to patch a critical zero-day vulnerability (CVE-2026-2441) that is being actively exploited in the wild. Reference: SC Media ([Google releases emergency update for fifth Chrome zero-day exploited in the wild](https://www.scworld.com/brief/google-releases-emergency-update-for-fifth-chrome-zero-day-exploited-in-the-wild-this-year))
## Today's Priorities 1. **Patch Exploited Cisco & Oracle Systems:** Immediately apply patches for Cisco Unified CM (CVE-2026-20230), Cisco SD-WAN Manager (CVE-2026-20127), and review Oracle PeopleSoft deployments for available mitigations against CVE-2026-35273. 2. **Rotate Fortinet Credentials & Audit Access:** Assume compromise of internet-facing FortiGate devices. Force credential rotation for all administrative and VPN accounts and conduct forensic analysis for signs of lateral movement. 3. **Audit CI/CD Pipelines & npm Dependencies:** Review GitHub Actions configurations for OIDC token misuse and scan for compromised TanStack npm packages (@tanstack/*). Update FFmpeg libraries used in media processing applications. 4. **Review CISA KEV Catalog:** Ensure all systems are patched against vulnerabilities recently added to CISA's Known Exploited Vulnerabilities catalog, including those for Splunk (CVE-2026-20253) and others.
## 🔗 References
- [Help Net Security: Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)](https://www.helpnetsecurity.com/?p=375890)
- [The Hacker News: FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation](https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html)
- [CyberScoop: ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawl](https://cyberscoop.com/?p=88980)
- [Rapid7 Research: Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)](https://www.rapid7.com/blog/post/etr-active-exploitation-of-oracle-peoplesoft-zero-day-cve-2026-35273)
- [Help Net Security: Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286)