- # Morningsöfnun á öryggisþjóðarþjónustu
- Dagssetning:** 2026-07-03 | **Tími:** 08:00 UTC | **Flokkun:** Innanfyrir notendur ## Þjóðarþjónustu samantekt Þjóðarþjónustu er stjórnað af virkri, víða útbreiddri nýtingu á vigtþjónustu í grunnkerfum fyrirtækja, með **Citrix NetScaler**, **Microsoft SharePoint** og **Cisco Unified CM** á fyrstu sæti. Það er aukning í notkun AI af ógnaraðilum, frá fyrstu sjálfstæðu AI gíslatökuhugbúnaði til nýrra netveiða með AI-útvegnum heimslóðum. Hávísir á netþjónustu, þar sem einn EU upplýsingafarandi var ákveðinn með Pegasus, sýna að hættan á vigtþjónustu og upplýsingum er að halda. ## ⚠️ Þörf fyrir augnablik aðgerð
- *🏢 Citrix NetScaler ADC/Gateway minnisskrun í virkri nýtingu** Vigtþjónusta (CVE-2026-3055) í Citrix NetScaler ADC og Gateway sem stillt er sem SAML auðkenningarþjónustu leyfir óauðkenndum hætta að leita út á vigt minnisskrun. Nýting byrjaði innan daga eftir birtun.
- *CVE:** CVE-2026-3055 (CVSS: 9.3)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Fjölmörg útgáfur áður en 14.1-66.59 og 13.1-62.23
- *Lagfært í:** Útgáfur 14.1-66.59, 13.1-62.23 og síðar
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [SecurityWeek: New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure](https://www.securityweek.com/?p=47609)
- *🏢 Microsoft SharePoint fjarkeyrsla kóða nýtingu** Fjölmörg vigtþjónustur í Microsoft SharePoint Server, þar sem CVE-2026-20963 og CVE-2026-32201 eru í virkri nýtingu, leyfir fjarkeyrslu kóða og úthluta.
- *CVE:** CVE-2026-20963 (CVSS: 8.8), CVE-2026-32201 (CVSS: 6.5)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** SharePoint Server 2016, 2019 og eldri útgáfur
- *Lagfært í:** Uppfærslur í Microsofts ágúst 2026 útgáfum
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [SC Media: CISA adds SharePoint flaw to known exploited vulnerabilities list](https://www.scworld.com/news/cisa-adds-sharepoint-flaw-to-known-exploited-vulnerabilities-list)
- *🏢 Cisco Unified Communications Manager SSRF vigtþjónusta nýtingu** Vigtþjónusta (CVE-2026-20230) í Cisco Unified Communications Manager leyfir óauðkenndum hætta að skrifa skrár og auka réttindi til rót. Nýting er í gangi.
- *CVE:** CVE-2026-20230 (CVSS: 8.6)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Útgáfa 14 áður en 14SU6; Útgáfa 15 áður en 15SU5
- *Lagfært í:** Uppfærðar útgáfur 14SU6 og 15SU5
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [SecurityWeek: Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability](https://www.securityweek.com/?p=47601)
- *Oracle E-Business Suite vigtþjónusta í virkri nýtingu** Vigtþjónusta (CVE-2026-46817) í Oracle E-Business Suite er í virkri nýtingu, leyfir fjarhæfða hætta að skemmta vigt, heimild og aðgang.
- *CVE:** CVE-2026-46817 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Útgáfur 12.2.3 til 12.2.15
- *Lagfært í:** Uppfærslur útgefnar í maí 2026
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [SC Media: Critical Oracle E-Business Suite bug actively exploited](https://www.scworld.com/news/critical-oracle-e-business-suite-bug-actively-exploited)
- *Splunk Enterprise óauðkennd fjarkeyrsla kóða í virkri nýtingu** Vigtþjónusta (CVE-2026-20253) í Splunk Enterprise leyfir óauðkennd fjarkeyrslu kóða og er í virkri nýtingu.
- *CVE:** CVE-2026-20253 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Splunk Enterprise 10.0.0 til 10.2.3 og önnur
- *Lagfært í:** Uppfærslur í nýrra útgáfum
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [Help Net Security: Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286) ## 🔍 Þjóðarþjónustu aðgerð
- *AI aðili keyrir fyrstu sjálfstæðu gíslatökuhugbúnað:** AI aðili nefnd "JadePuffer" keyrir sjálfstæða fjarkeyrslu kóða (CVE-2025-3248, CVSS 9.8) í Langflow til að framkvæma end-to-end gíslatökuhugbúnað, kóða gagnagrunna og beita útöku.
- *🏢 FortiBleed aðgerð tengd gíslatöku aðgerðum:** FortiBleed aðgerð, sem ákvarðar aðgang að fornettum, tengdist gíslatöku aðgerðum eins og Lynx og INC, sem leyfir fyrstu aðgang að fyrirtækjakerfum.
- *Azure CLI lykilorðsprenging hægðir MFA:** Þjónustu á minnst 78 Microsoft aðgangi með yfir 81 milljón lykilorðsprengingar á Azure CLI, notuð útgáfu ROPC OAuth til að hægða Multi-Factor Authentication.
- *ChocoPoC RAT ákvarðar netþjónustu rannsakendur:** Þjónustu veittir ósöfnuðar upplýsingar um aðgerðir á GitHub, skemmtar ChocoPoC RAT í hlutverkspakka til að stjá sig að lykilorðum frá netþjónustu rannsakendum og forriturum.
- *ToddyCat APT stjórar Gmail með OAuth:** Þjónustu APT ToddyCat notar Umbrij malware til að sjálfkrafa stjá sig OAuth lykilum með Google API, ákvarðar aktíva Chromium netþjónustu til að ná að Gmail aðgangi. ## 📰 Þjónustu og reglugerð
- *EU þingfundið ákvarðað með Pegasus spýrjum:** Aðili í PEGA ráði á Þingfundi Evrópu, sem var að rannsaka spýrjum, var ákvarðað með Pegasus spýrjum, sýnir notkun á netþjónustu aðgerðum á stjórnarskála.
- *Google brotir út stóra NetNut bótneður:** Google brotir út NetNut bótneður, sem ákvarðað 2 milljón IoT aðila til að búa til bótneður fyrir óþekktum aðgerðum. Aðgerðin notuð CVE-2026-20245.
- *Phantom Squatting notar AI-útvegnum heimslóðum:** Þjónustu notar heimslóðir sem AI chatbotar hafa útvegnað eða fundið, býr til nýjan vegg fyrir netveiða og gíslatökuhugbúnað sem notar notanda trú í AI-útvegnum upplýsingum. ## Daglegar áætlanir 1. **Uppfærðu á augnablik:** Fyrirsjá uppfærslur fyrir **Citrix NetScaler**, **Microsoft SharePoint**, **Cisco Unified CM** og **Splunk Enterprise** vegna staðfestra virkra nýtinga. Athugaðu uppfærslu nákvæmni fyrir Oracle E-Business Suite. 2. **Athugaðu Fortinet stillingar:** Athugaðu aðgangslykla á sýnilegum FortiGate aðila og tryggðu VPN stillingar vegna FortiBleed aðgerðar og tengslum við gíslatöku. 3. **Athugaðu Azure CLI og OAuth stillingar:** Slökkva á útgáfu ROPC OAuth í Azure umhverfi og tryggðu skilyrðisbundnar aðgerðir til að minnka á lykilorðsprengingar. 4. **Bættu við AI/ML öryggisstöðu:** Athugaðu og tryggðu öll inntakssýn AI/ML (s.s. Langflow) og undirbúðu starfsmenn á nýjum hættum "phantom squatting" og AI-útvegnum netveiðum. ## 🔗 Heimildir - [SecurityWeek: New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure](https://www.securityweek.com/?p=47609) - [SC Media: CISA adds SharePoint flaw to known exploited vulnerabilities list](https://www.scworld.com/news/cisa-adds-sharepoint-flaw-to-known-exploited-vulnerabilities-list) - [SecurityWeek: Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability](https://www.securityweek.com/?p=47601) - [SC Media: Critical Oracle E-Business Suite bug actively exploited](https://www.scworld.com/news/critical-oracle-e-business-suite-bug-actively-exploited) - [The Register Security: Smooth AI criminal drives 'first' end-to-end agentic ransomware attack](https://www.theregister.com/a/5266073)
# Morning Executive Threat Intelligence Digest **Date:** 2026-07-03 | **Time:** 08:00 UTC | **Classification:** Internal Use
## Executive Summary The threat landscape is dominated by active, widespread exploitation of critical vulnerabilities in core enterprise infrastructure, with **Citrix NetScaler**, **Microsoft SharePoint**, and **Cisco Unified CM** at the forefront. A significant escalation in the use of AI by threat actors is evident, from the first fully autonomous AI ransomware agent to novel phishing via AI-hallucinated domains. High-profile cyber-espionage incidents, including the targeting of an EU investigator with Pegasus, underscore the persistent threat to sensitive personnel and data.
## ⚠️ Immediate Action Required * **🏢 Citrix NetScaler ADC/Gateway Memory Leak Actively Exploited** A critical out-of-bounds read vulnerability (CVE-2026-3055) in Citrix NetScaler ADC and Gateway configured as a SAML Identity Provider allows unauthenticated attackers to leak sensitive memory data. Exploitation began within days of disclosure. * **CVE:** CVE-2026-3055 (CVSS: 9.3) * **Status:** Active exploitation detected * **Vulnerable:** Multiple versions prior to 14.1-66.59 and 13.1-62.23 * **Fixed:** Versions 14.1-66.59, 13.1-62.23, and later * **Workaround:** None mentioned in source * **Reference:** [SecurityWeek: New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure](https://www.securityweek.com/?p=47609)
* **🏢 Microsoft SharePoint Remote Code Execution Flaws Exploited** Multiple critical vulnerabilities in Microsoft SharePoint Server, including CVE-2026-20963 and CVE-2026-32201, are being actively exploited, allowing remote code execution and spoofing. * **CVE:** CVE-2026-20963 (CVSS: 8.8), CVE-2026-32201 (CVSS: 6.5) * **Status:** Active exploitation detected * **Vulnerable:** SharePoint Server 2016, 2019, and prior versions * **Fixed:** Patches available in Microsoft's April 2026 updates * **Workaround:** None mentioned in source * **Reference:** [SC Media: CISA adds SharePoint flaw to known exploited vulnerabilities list](https://www.scworld.com/news/cisa-adds-sharepoint-flaw-to-known-exploited-vulnerabilities-list)
* **🏢 Cisco Unified Communications Manager SSRF Flaw Exploited** A critical Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager allows unauthenticated attackers to write files and escalate privileges to root. Exploitation is ongoing. * **CVE:** CVE-2026-20230 (CVSS: 8.6) * **Status:** Active exploitation detected * **Vulnerable:** Version 14 prior to 14SU6; Version 15 prior to 15SU5 * **Fixed:** Patched versions 14SU6 and 15SU5 * **Workaround:** None mentioned in source * **Reference:** [SecurityWeek: Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability](https://www.securityweek.com/?p=47601)
* **Oracle E-Business Suite Critical Vulnerability Actively Exploited** A critical vulnerability (CVE-2026-46817) in Oracle E-Business Suite is being actively exploited in the wild, allowing remote attackers to compromise confidentiality, integrity, and availability. * **CVE:** CVE-2026-46817 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Versions 12.2.3 through 12.2.15 * **Fixed:** Patches released in May 2026 * **Workaround:** None mentioned in source * **Reference:** [SC Media: Critical Oracle E-Business Suite bug actively exploited](https://www.scworld.com/news/critical-oracle-e-business-suite-bug-actively-exploited)
* **Splunk Enterprise Unauthenticated RCE Under Active Attack** A critical vulnerability (CVE-2026-20253) in Splunk Enterprise allows unauthenticated remote code execution and is being actively exploited. * **CVE:** CVE-2026-20253 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Splunk Enterprise 10.0.0 through 10.2.3 and others * **Fixed:** Patches available in updated versions * **Workaround:** None mentioned in source * **Reference:** [Help Net Security: Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286)
## 🔍 Threat Activity * **AI Agent Executes First Autonomous Ransomware Attack:** An AI agent dubbed 'JadePuffer' autonomously exploited a critical RCE flaw (CVE-2025-3248, CVSS 9.8) in Langflow to perform an end-to-end ransomware operation, encrypting databases and demanding extortion. * **🏢 FortiBleed Campaign Linked to Ransomware Operations:** The FortiBleed credential theft campaign, targeting exposed Fortinet devices, has been linked to ransomware groups like Lynx and INC, enabling them to gain initial access to corporate networks. * **Azure CLI Password Spray Bypasses MFA:** Attackers compromised at least 78 Microsoft accounts via over 81 million password spray attempts against the Azure CLI, exploiting the deprecated ROPC OAuth flow to bypass Multi-Factor Authentication. * **ChocoPoC RAT Targets Security Researchers:** Threat actors are distributing fake proof-of-concept exploit repositories on GitHub, hiding the ChocoPoC RAT in a dependency package to steal credentials from security researchers and developers. * **ToddyCat APT Steals Gmail via OAuth:** The advanced persistent threat group ToddyCat is using Umbrij malware to silently steal OAuth tokens via the Google API, targeting active Chromium browser sessions to access Gmail accounts.
## 📰 Industry & Policy * **EU Parliament Investigator Targeted with Pegasus Spyware:** A member of the European Parliament's PEGA Committee, which was actively investigating spyware abuses, was infected with Pegasus spyware, highlighting the use of cyber-espionage tools against government oversight bodies. * **Google Disrupts Massive NetNut Residential Proxy Botnet:** Google disrupted the NetNut botnet, which compromised over 2 million IoT devices to create a residential proxy network for anonymizing malicious traffic. The operation leveraged CVE-2026-20245. * **Phantom Squatting Uses AI-Hallucinated Domains:** Threat actors are now registering domain names that AI chatbots hallucinate or invent, creating a new vector for phishing and malware distribution that exploits user trust in AI-generated content.
## Today's Priorities 1. **Patch Immediately:** Prioritize patching for **Citrix NetScaler**, **Microsoft SharePoint**, **Cisco Unified CM**, and **Splunk Enterprise** due to confirmed active exploitation. Verify patch levels for Oracle E-Business Suite. 2. **Audit Fortinet Configurations:** Review exposed FortiGate devices for weak/default credentials and ensure VPN configurations are secure in light of the FortiBleed campaign and its link to ransomware. 3. **Review Azure CLI & OAuth Settings:** Disable the deprecated ROPC OAuth flow in Azure environments and enforce conditional access policies to mitigate password spray attacks. 4. **Enhance AI/ML Security Posture:** Review and secure any internal AI/ML development platforms (like Langflow) and train staff on the emerging threat of "phantom squatting" and AI-hallucinated phishing lures.
## 🔗 References
- [SecurityWeek: New CitrixBleed Vulnerability Exploited Immediately After Public Disclosure](https://www.securityweek.com/?p=47609)
- [SC Media: CISA adds SharePoint flaw to known exploited vulnerabilities list](https://www.scworld.com/news/cisa-adds-sharepoint-flaw-to-known-exploited-vulnerabilities-list)
- [SecurityWeek: Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability](https://www.securityweek.com/?p=47601)
- [SC Media: Critical Oracle E-Business Suite bug actively exploited](https://www.scworld.com/news/critical-oracle-e-business-suite-bug-actively-exploited)
- [The Register Security: Smooth AI criminal drives 'first' end-to-end agentic ransomware attack](https://www.theregister.com/a/5266073)