Security News

Cybersecurity news aggregator

📰
INFO News

Security Morning Briefing - July 02, 2026

  • # Morningsöfnun á öryggisþjóðarstjórn
  • Dagsetning:** 2026-07-02 | **Tími:** 08:00 UTC | **Flokkun:** Innanfyrir notendur ## Útsýni fyrir stjórnendur Þjóðarstjórnarumhverfið er skilgreint með útbreiddri nýtingu á kritískum vandamálum í vinnubúnaði og flóknunum, áhættuþjónustuþjónustu. Í virkri nýtingu á kritískum vandamálum í **Oracle E-Business Suite** og **Splunk Enterprise** er staðfest, sem býður á umhverfið á óuppfærðum kerfum. Þjónustuþjónustuþjónustu sem á að taka við **Fortinet** tækjum ("FortiBleed") er aukast, sem gefur hættulegum aðgang að kerfisbúnaði. Þar að auki eru nýjar hættuþjónustuþjónustur sem notast við SEO-veið, hættaþjónustuþjónustu og AI-gerðum gíslatökuhugbúnaði, sem vísar til þörfar um sterkar endapunkta- og notendaveitni. ## ⚠️ Þarf að gera áður en næst
  • *Oracle E-Business Suite fjarkeyrsla kóða** Fjölmörg kritísk vandamál, þar með talið CVE-2026-46817, leyfa óauðkenndum hættulegum að nýta Oracle E-Business Suite. Í virkri nýtingu er staðfest, sem á að nýta modúla eins og Oracle Payments.
  • *CVE:** CVE-2026-46817 (CVSS: 9.8-9.9)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Útgáfur 12.2.3 til 12.2.15
  • *Lagfært í:** Uppfærslur útgefnar maí 2026. Útfæra kritískar uppfærslur.
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [SC Media](https://www.scworld.com/news/critical-oracle-e-business-suite-bug-actively-exploited)
  • *Splunk Enterprise óauðkennd fjarkeyrsla kóða** Kritísk vandamál (CVE-2026-20253) í Splunk Enterprise og Cloud Platform leyfir óauðkennd fjarkeyrslu kóða og er í virkri nýtingu.
  • *CVE:** CVE-2026-20253 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Splunk Enterprise 10.0.0 til 10.2.3 og fleiri
  • *Lagfært í:** Útfæra uppfærslur í Splunk Enterprise útgáfur 10.2.4, 10.1.9, 10.0.14, eða nýrra.
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [Help Net Security](https://www.helpnetsecurity.com/?p=375286)
  • *Citrix NetScaler ADC/Gateway minnisskrun (CVE-2026-3055)** Kritísk vandamál í Citrix NetScaler ADC og Gateway sem stillt er sem SAML auðkenningarsjávar leyfir óauðkenndum hættulegum að nýta háþrýða minnisskrun.
  • *CVE:** CVE-2026-3055 (CVSS: 9.3)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Fjölmörg útgáfur áður en 14.1-66.59 og 13.1-62.23
  • *Lagfært í:** Útfæra uppfærslur í útgáfur 14.1-66.59, 13.1-62.23, eða nýrra.
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [BSI Germany](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2147)
  • *SimpleHelp RMM auðkenningarframhjáhlaup (CVE-2026-48558)** Kritísk vandamál (CVSS 10.0) í SimpleHelp Remote Monitoring and Management (RMM) vinnubúnaði er í nýtingu til að setja Djinn Stealer, sem samlagði skyndi og AI auðkenningar.
  • *CVE:** CVE-2026-48558 (CVSS: 10.0)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
  • *Lagfært í:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [SC Media](https://www.scworld.com/news/attack-exploiting-simplehelp-vulnerability-deploys-novel-loader-infostealer)
  • *Apache ActiveMQ Classic fjarkeyrsla kóða (CVE-2026-34197)** Kritísk vandamál leyfir auðkenndum hættulegum að keyra óvæðar kóða með Jolokia API. Yfir 6.400 vélir eru enn óuppfærðar og í vörn.
  • *CVE:** CVE-2026-34197 (CVSS: 8.8)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** ActiveMQ Classic áður en 5.19.4 og 6.0.0–6.2.2
  • *Lagfært í:** Uppfærðu ActiveMQ Classic 5.19.4, 6.2.3, eða nýrra.
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [SC Media](https://www.scworld.com/brief/over-6400-apache-activemq-servers-at-risk-of-ongoing-attacks) ## 🔍 Þjónustuþjónustu
  • *🏢 FortiBleed auðkenningar samlagðar aukast:** Þá áður skýrða **FortiBleed** þjónustuþjónustu hefur breyst, með því að þjónustuþjónustu er nú skýrt að hafa samlagð yfir 110 milljónar auðkenningar og SSL VPN auðkenningar frá yfir 70.000 internetbundnum Fortinet tækjum. Þetta gefur hættulegum aðgang að kerfisbúnaði með óauðkenndum kerfisbúnaði.
  • *SEO-veiðar síður setja AsyncRAT:** Þjónustuþjónustu notast við leitarþjónustu (SEO) til að bæta við hættaþjónustuþjónustu sem skýra vinsæla vinnubúnaði. Þessar síður setja AsyncRAT með ScreenConnect, með DLL side-loading og PowerShell skrifum fyrir aðgerð og fjárþjónustu.
  • *Ousaban bankaþjónustuþjónustu á að taka við Iberisku hálföldin:** Ousaban bankaþjónustuþjónustu er í raun nýtingu á notendum í Spanverjum og Portúgál með netveiðar PDF með geofencing. Það notast við steganografi til að fela vörn og veikja uppgjöf með breytilegum stjórn- og boðmiðlun til að samlaga auðkenningar og taka kerfi.
  • *Azure CLI lykilorðsýnd:** Þjónustuþjónustu hefur áður áhrif á að minnst 78 Microsoft notendur með lykilorðsýnd sem á að taka við áður en notendur notuðu Resource Owner Password Credentials (ROPC) OAuth flæði í Azure CLI, sem hækkar MFA. Vandanum er skilgreint sem CVE-2026-20245.
  • *Hættaþjónustuþjónustu í vafra:** Tvö mikilvæg þjónustuþjónustur taka við vafra notendur. **Microsoft hafði fjarlægt 119 hættaþjónustuþjónustu Edge** (StegoAd þjónustuþjónustu) sem notast við steganografi til að fela vörn. Þar að auki, ein hættaþjónustuþjónustu **Chrome vafra sem skýra Perplexity AI** hefur hægt að taka vefþjónustu og senda notendagögn í aðgangsþjónustu. ## 📋 Uppfærslur og uppfærslur
  • *IBM WebSphere Application Server:** Fjölmörg kritísk vandamál leyfir öryggisbrot, óvæðar kóða og þjónustuneitun. Uppfærslur eru til í útgáfum áður en 9.0.5.29 og 8.5.5.31.
  • *Apple iOS/iPadOS:** Apple hefur útgefið uppfærslur fyrir fjölmörg kritísk vandamál í iOS og iPadOS sem leyfir fjarkeyrslu kóða og réttindaaukning. Uppfærðu í nýjasta útgáfurnar.
  • *Apache Tomcat:** Fjölmörg hávæð vandamál leyfir fjarkeyrslu kóða, þjónustuneitun og upplýsingar útgefnar. Þau eru aðgengileg í útgáfum eins og 11.x, 10.1.x, 9.0.x og eldri.
  • *Redis:** Fjölmörg kritísk vandamál í Redis (CVE-2026-23479, CVE-2026-25243) leyfir fjarkeyrslu kóða og eru aðgengileg í uppfærslum, eins og Redis 8.6.3 og viðkomandi Red Hat Enterprise Linux uppfærslur. ## Daglegar áherslur 1. **Uppfærðu Oracle E-Business Suite og Splunk Enterprise á einhverju.** Staðfestu nýtingu á CVE-2026-46817 og CVE-2026-20253 og útfæra uppfærslur frá framleiðandann sem fyrst. 2. **Athugaðu auðkenningar á Fortinet tækjum.** Í ljósi FortiBleed þjónustuþjónustu, skoðaðu og breytu öll auðkenningar og SSL VPN auðkenningar á internetbundnum Fortinet tækjum. Skoðaðu eftir tekinum aðgerðum. 3. **Athugaðu og takðu vafraþjónustu.** Þýðu reglur til að banna óþýða vafraþjónustu og athugaðu innsetta vafraþjónustu á móti þekktum hættaþjónustuþjónustum frá StegoAd og Perplexity AI þjónustuþjónustum. 4. **Athugaðu útbreidda aðgang á Citrix NetScaler og Apache ActiveMQ.** Staðfestu uppfærsluástand fyrir CVE-2026-3055 (Citrix) og CVE-2026-34197 (ActiveMQ), með fokus á internetbundnar tilfelli. ## 🔗 Heimildir - [SC Media: Kritísk vandamál í Oracle E-Business Suite í nýtingu](https://www.scworld.com/news/critical-oracle-e-business-suite-bug-actively-exploited) - [Help Net Security: Óauðkennd fjarkeyrsla kóða í Splunk Enterprise í nýtingu (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286) - [The Hacker News: FortiBleed á að taka við FortiGate vörn í 110 milljónar auðkenningar samlagðar](https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html) - [BSI Germany: [NEU] [hoch] Citrix Systems NetScaler ADC und Gateway: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2147) - [The Hacker News: SEO-veiðar vinnubúnaðar síður notast við ScreenConnect til að setja AsyncRAT](https://thehackernews.com/2026/07/seo-poisoned-software-sites-abuse.html)
Read Full Article →

# Morning Executive Threat Intelligence Digest **Date:** 2026-07-02 | **Time:** 08:00 UTC | **Classification:** Internal Use

## Executive Summary The threat landscape is characterized by widespread exploitation of critical enterprise software vulnerabilities and sophisticated, targeted malware campaigns. **Active exploitation** of critical flaws in **Oracle E-Business Suite** and **Splunk Enterprise** is confirmed, posing an immediate risk to unpatched systems. A massive credential leak targeting **Fortinet** devices ("FortiBleed") continues to escalate, providing attackers with keys to corporate perimeters. Additionally, novel malware campaigns are leveraging SEO poisoning, malicious browser extensions, and AI-generated ransomware, highlighting the need for robust endpoint and user awareness controls.

## ⚠️ Immediate Action Required

* **Oracle E-Business Suite Remote Code Execution** Multiple critical vulnerabilities, including CVE-2026-46817, allow unauthenticated attackers to compromise Oracle E-Business Suite. Active exploitation is confirmed, targeting modules like Oracle Payments. * **CVE:** CVE-2026-46817 (CVSS: 9.8-9.9) * **Status:** Active exploitation detected * **Vulnerable:** Versions 12.2.3 through 12.2.15 * **Fixed:** Patches released May 2026. Apply Critical Patch Update. * **Workaround:** None mentioned in source * **Reference:** [SC Media](https://www.scworld.com/news/critical-oracle-e-business-suite-bug-actively-exploited)

* **Splunk Enterprise Unauthenticated Remote Code Execution** A critical vulnerability (CVE-2026-20253) in Splunk Enterprise and Cloud Platform allows unauthenticated remote code execution and is being actively exploited. * **CVE:** CVE-2026-20253 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Splunk Enterprise 10.0.0 through 10.2.3 and others * **Fixed:** Apply updates to Splunk Enterprise versions 10.2.4, 10.1.9, 10.0.14, or later. * **Workaround:** None mentioned in source * **Reference:** [Help Net Security](https://www.helpnetsecurity.com/?p=375286)

* **Citrix NetScaler ADC/Gateway Memory Leak (CVE-2026-3055)** A critical out-of-bounds read vulnerability in Citrix NetScaler ADC and Gateway configured as a SAML Identity Provider allows unauthenticated attackers to leak sensitive memory data. * **CVE:** CVE-2026-3055 (CVSS: 9.3) * **Status:** Active exploitation detected * **Vulnerable:** Multiple versions prior to 14.1-66.59 and 13.1-62.23 * **Fixed:** Apply patches to versions 14.1-66.59, 13.1-62.23, or later. * **Workaround:** None mentioned in source * **Reference:** [BSI Germany](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2147)

* **SimpleHelp RMM Authentication Bypass (CVE-2026-48558)** A critical authentication bypass vulnerability (CVSS 10.0) in SimpleHelp Remote Monitoring and Management (RMM) software is being exploited to deploy Djinn Stealer, which harvests cloud and AI credentials. * **CVE:** CVE-2026-48558 (CVSS: 10.0) * **Status:** Active exploitation detected * **Vulnerable:** Not specified in source — check vendor advisory * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [SC Media](https://www.scworld.com/news/attack-exploiting-simplehelp-vulnerability-deploys-novel-loader-infostealer)

* **Apache ActiveMQ Classic RCE (CVE-2026-34197)** A critical remote code execution vulnerability allows authenticated attackers to execute arbitrary commands via the Jolokia API. Over 6,400 servers remain unpatched and at risk. * **CVE:** CVE-2026-34197 (CVSS: 8.8) * **Status:** Active exploitation detected * **Vulnerable:** ActiveMQ Classic prior to 5.19.4 and 6.0.0–6.2.2 * **Fixed:** Update to ActiveMQ Classic 5.19.4, 6.2.3, or later. * **Workaround:** None mentioned in source * **Reference:** [SC Media](https://www.scworld.com/brief/over-6400-apache-activemq-servers-at-risk-of-ongoing-attacks)

## 🔍 Threat Activity

* **🏢 FortiBleed Credential Harvesting Campaign Escalates:** The previously reported **FortiBleed** campaign has expanded, with threat actors now reported to have harvested over 110 million administrative and SSL VPN credentials from more than 70,000 internet-facing Fortinet devices. This provides a direct path for attackers to infiltrate corporate networks via compromised perimeter security appliances. * **SEO-Poisoned Sites Deploy AsyncRAT:** Threat actors are using search engine optimization (SEO) to promote malicious websites spoofing popular software installers. These sites deploy AsyncRAT via ScreenConnect, using DLL side-loading and PowerShell scripts for persistence and remote control. * **Ousaban Banking Trojan Targets Iberian Peninsula:** The Ousaban banking trojan is actively targeting users in Spain and Portugal via phishing PDFs with geofencing. It uses steganography to hide payloads and evades detection with changing command-and-control domains to steal credentials and hijack sessions. * **Azure CLI Password Spray Campaign:** Attackers have compromised at least 78 Microsoft accounts via a password spray campaign targeting the deprecated Resource Owner Password Credentials (ROPC) OAuth flow in Azure CLI, bypassing MFA. The vulnerability is tracked as CVE-2026-20245. * **Malicious Browser Extensions:** Two significant campaigns target browser users. **Microsoft removed 119 malicious Edge extensions** (StegoAd campaign) that used steganography to hide malware. Separately, a malicious **Chrome extension impersonating Perplexity AI** hijacks search traffic and exfiltrates user data to attacker-controlled servers.

## 📋 Patches & Updates

* **IBM WebSphere Application Server:** Multiple critical vulnerabilities allow security bypass, arbitrary code execution, and denial of service. Patches are available for versions prior to 9.0.5.29 and 8.5.5.31. * **Apple iOS/iPadOS:** Apple has released patches for multiple critical vulnerabilities in iOS and iPadOS that allow remote code execution and privilege escalation. Update to the latest versions. * **Apache Tomcat:** Multiple high-severity vulnerabilities allowing RCE, DoS, and information disclosure have been patched. Affected versions include 11.x, 10.1.x, 9.0.x, and older. * **Redis:** Multiple critical Redis vulnerabilities (CVE-2026-23479, CVE-2026-25243) allowing remote code execution have been addressed in updates, including Redis 8.6.3 and relevant Red Hat Enterprise Linux patches.

## Today's Priorities 1. **Patch Oracle E-Business Suite and Splunk Enterprise immediately.** Confirm exploitation of CVE-2026-46817 and CVE-2026-20253 and apply vendor patches as a top priority. 2. **Audit Fortinet device credentials.** In light of the FortiBleed campaign, review and rotate all administrative and VPN credentials on internet-facing Fortinet appliances. Check for signs of compromise. 3. **Review and restrict browser extensions.** Enforce policies to block unauthorized browser extensions and audit installed extensions against known malicious lists from the StegoAd and Perplexity AI campaigns. 4. **Assess Citrix NetScaler and Apache ActiveMQ exposure.** Verify patch status for CVE-2026-3055 (Citrix) and CVE-2026-34197 (ActiveMQ), focusing on internet-facing instances.

## 🔗 References

  • [SC Media: Critical Oracle E-Business Suite bug actively exploited](https://www.scworld.com/news/critical-oracle-e-business-suite-bug-actively-exploited)
  • [Help Net Security: Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286)
  • [The Hacker News: FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation](https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html)
  • [BSI Germany: [NEU] [hoch] Citrix Systems NetScaler ADC und Gateway: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2147)
  • [The Hacker News: SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT](https://thehackernews.com/2026/07/seo-poisoned-software-sites-abuse.html)

Share this article