Security News

Cybersecurity news aggregator

📰
INFO News

Security Morning Briefing - July 07, 2026

  • # Morgunfyrirlestrar um öryggisþjóðarstefnu
  • Dagsetning:** 2026-07-07 | **Tími:** 08:00 UTC | **Flokkun:** Innanfyrir notendur ## Fyrirlestrar Þjóðarstefnan er á kritískri stig, með breytilegri virkri nýtingu á veikleikum yfir kerfisþjónustu. **Ubiquiti UniFi** og **Ivanti Sentry** veikleikarnir eru nú staðfestir sem aðal nýtingarveggjir fyrir gíslatökuhugbúnað og fyrstu nýtingar, sem krefjast áætlaðar uppfærslu. **FortiBleed** auðkenningarleikið hefur hægt, með yfir 110 milljón auðkenningar frá netvirkum **Fortinet** kerfum. Þar að auki, fyrsta skýrðu tilfelli af sjálfstæðu AI gíslatökuhugbúnað (JadePuffer) sem nýtir Langflow RCE veikleika merkir mikilvægan breytingu í nýtingarauðkenningu. ## ⚠️ Þörf fyrir áætlaða aðgerð
  • *Ubiquiti UniFi margar kritískar veikleikar** Fjölmargar kritískar veikleikar (CVSS upp á 10.0) í Ubiquiti UniFi kerfum (Network Application, OS Server, Express) leyfa óauðkenndar fjarkeyrslu kóða, réttindaaukning og auðkenningarframhjáhlaup. Þeir eru í virkri nýtingu.
  • *CVE:** CVE-2026-34910, CVE-2026-34909, CVE-2026-34908, CVE-2026-33000, CVE-2026-22557 (CVSS: upp á 10.0)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** UniFi Network Application, UniFi OS Server, UniFi Express (ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda)
  • *Lagfært í:** Uppfærslur eru tiltæk (ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda)
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [BSI Germany: Ubiquiti UniFi: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2171)
  • *Ivanti Sentry pre-auðkenningu RCE (CVE-2026-10520)** Kritískur pre-auðkenningu fjarkeyrslu kóða í Ivanti Sentry leyfir hætta að nýta fulla stjórn. Þeir eru í virkri nýtingu af gíslatökuhugbúnað.
  • *CVE:** CVE-2026-10520 (CVSS: 10.0)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Útgáfur fyrir 10.5.2, 10.6.2 og 10.7.1
  • *Lagfært í:** Uppfærslur útgefnar 10. júní 2026 (útgáfur 10.5.2, 10.6.2, 10.7.1)
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [BleepingComputer: Max severity Ivanti Sentry vulnerability now exploited in attacks](https://www.bleepingcomputer.com/news/security/max-severity-ivanti-sentry-vulnerability-now-exploited-in-attacks/)
  • *Citrix NetScaler minnismyndarleiki (CVE-2026-3055)** Kritískur út-bundinn lesa minnismynd í Citrix NetScaler ADC/Gateway sem er stillt sem SAML auðkenningarsjávarbúnað leyfir óauðkenndar hættur að leita út á háð minnismynd. Þeir eru í virkri nýtingu.
  • *CVE:** CVE-2026-3055 (CVSS: 9.3)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Fjölmargar fyrri útgáfur (ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda)
  • *Lagfært í:** Uppfærslur tiltæk (ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda)
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [CSO Online: New CitrixBleed-like NetScaler flaw sees exploit attempts in the wild](https://www.csoonline.com/article/4192741/new-citrixbleed-like-netscaler-flaw-sees-exploit-attempts-in-the-wild.html)
  • 🏢 **Cisco Unified CM SSRF veikleiki (CVE-2026-20230)** Kritískur Server-Side Request Forgery (SSRF) veikleiki í Cisco Unified Communications Manager leyfir óauðkenndar hættur að skrifa skrár og auka réttindi til rót. Nýting er sjáð í netinu.
  • *CVE:** CVE-2026-20230 (CVSS: 8.6)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Útgáfa 14 fyrir 14SU6; Útgáfa 15 fyrir 15SU5
  • *Lagfært í:** Uppfærslur tiltæk í útgáfum 14SU6 og 15SU5
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [SecurityWeek: Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability](https://www.securityweek.com/?p=47601)
  • *Splunk Enterprise óauðkennd fjarkeyrsla kóða (CVE-2026-20253)** Kritískur veikleiki í Splunk Enterprise leyfir óauðkennd fjarkeyrslu kóða. Þeir eru í virkri nýtingu áður en heimild er gefin.
  • *CVE:** CVE-2026-20253 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Splunk Enterprise 10.0.0 til 10.2.3 og önnur (ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda)
  • *Lagfært í:** Uppfærslur tiltæk í uppfærðum útgáfum (ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda)
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [Help Net Security: Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286) ## 🔍 Þjóðarstefnur
  • *FortiBleed auðkenningarauðkenningu leikur hefur hægt** **FortiBleed** leikur hefur sýnt auðkenningar og SSL VPN auðkenningar fyrir yfir 110 milljón samninga frá yfir 70.000 netvirkum **Fortinet** kerfum. Þjóðarstefnur nota þessar auðkenningar fyrir brútefni og aðgang í fyrirtækjakerfum. Þetta er ekki nýr veikleikur, heldur massa auðkenningarauðkenningu sem á að nýta þekktar eða sjálfgefnar auðkenningar.
  • *Fyrsta sjálfstæða AI gíslatökuhugbúnað er staðfest** **JadePuffer** AI hugbúnaður er staðfestur sem fyrsta sjálfstæða, LLM-þjónandi gíslatökuhugbúnaður, sem nýtir kritískan Langflow RCE veikleika (CVE-2025-3248). Þessi hugbúnaður gerði upplýsingar, hliðarfærslu og kóðaþýðingu sjálfstæðilega.
  • *Iran tengdur Cavern Manticore notar nýja C2 kerfi** Þjóðarstefnurinn **Cavern Manticore** er að nýta nýja modulat .NET stjórn- og boðmiðlun kerfi á ísraelskum fyrirtækjum. Kerfið notar framfarir að aðskilnað (Mixed-Mode C++/CLI, Native AOT) og er sett upp með DLL side-loading á SysAid.
  • *Google og FBI hætta NetNut botnet** Sameiginlegur aðgerð hefur hætt **NetNut** netvirkja botnet, sem samanstendur af yfir 2 milljón hættuðum IoT og Android kerfum. Botnet hefur verið notað fyrir auðkenningar og öðru netþjónustu. Hætta varða aðgangi að C2 kerfi og blokkingu á óþægilegum SDK. ## 📋 Uppfærslur og uppfærslur
  • *Microsoft SharePoint margar kritískar RCE veikleikar**: Uppfærslur eru tiltæk í Microsofts ágúst 2026 uppfærslum fyrir virkri nýtingu á veikleikum (CVE-2026-20963, CVE-2026-32201) sem áhrif á SharePoint Server 2016, 2019 og fyrri útgáfur.
  • *BeyondTrust Remote Support pre-auðkenningu RCE (CVE-2026-1731)**: SaaS útgáfur voru uppfærðar 2. febrúar 2026; sjálfstæðar útgáfur krefjast handvirkra uppfærslur. Þessi veikleikur er í virkri nýtingu með VShell, SparkRAT og gíslatökuhugbúnað.
  • *Apple iOS/iPadOS kritískar veikleikar**: Apple hefur gefið út uppfærslur fyrir fjölmargar kritískar veikleikar (CVSS upp á 9.8) sem leyfir RCE og réttindaaukning í iOS og iPadOS fyrir útgáfur fyrir 18.7.9 og 26.5.
  • *Oracle E-Business Suite kritískar veikleikar**: Uppfærslur voru gefnar út í maí 2026 fyrir fjölmargar kritískar veikleikar (CVSS 9.8-9.9), þar á meðal CVE-2026-46817 sem er nú í virkri nýtingu. ## Daglegar árangurir 1. **Uppfærðu Ubiquiti UniFi og Ivanti Sentry kerfisnáttúrunum áætlaða.** Þeir eru í virkri, breytilegri nýtingu fyrir fyrstu nýtingu og gíslatökuhugbúnað. 2. **Athugaðu og breyttu auðkenningum á öllum netvirkum Fortinet kerfum** í svar til stóra FortiBleed auðkenningarleiks. Þýðu MFA þar sem hægt. 3. **Athugaðu uppfærslustöðu fyrir Citrix NetScaler, Cisco Unified CM og Splunk Enterprise** á móti kritískum, virkri nýtingu á CVEs sem eru lýst. 4. **Skoðaðu sýnilegar AI/ML kerfisnáttúrunar**, sérstaklega OpenClaw og Langflow útgáfur, fyrir óuppfærðar kritískar veikleikar sem eru notaðar í sjálfvirkum nýtingum. ## 🔗 Heimildir - [BSI Germany: Ubiquiti UniFi: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2171) - [BleepingComputer: Max severity Ivanti Sentry vulnerability now exploited in attacks](https://www.bleepingcomputer.com/news/security/max-severity-ivanti-sentry-vulnerability-now-exploited-in-attacks/) - [The Hacker News: FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation](https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html) - [Dark Reading: JadePuffer: The First Complete LLM-Driven Ransomware Attack](https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack) - [SecurityWeek: Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability](https://www.securityweek.com/?p=47601)
Read Full Article →

# Morning Executive Threat Intelligence Digest **Date:** 2026-07-07 | **Time:** 08:00 UTC | **Classification:** Internal Use

## Executive Summary The threat landscape remains at a critical level, with widespread active exploitation of vulnerabilities across core enterprise infrastructure. The **Ubiquiti UniFi** and **Ivanti Sentry** vulnerabilities are now confirmed as primary attack vectors for ransomware and initial access, demanding immediate patching. The **FortiBleed** credential leak campaign has escalated, exposing over 110 million credentials from internet-facing Fortinet devices. Additionally, the first documented case of a fully autonomous AI ransomware agent (**JadePuffer**) exploiting a Langflow RCE flaw marks a significant evolution in attack automation.

## ⚠️ Immediate Action Required * **Ubiquiti UniFi Multiple Critical Vulnerabilities** Multiple critical vulnerabilities (CVSS up to 10.0) in Ubiquiti UniFi products (Network Application, OS Server, Express) allow unauthenticated remote code execution, privilege escalation, and security control bypass. Actively exploited. * **CVE:** CVE-2026-34910, CVE-2026-34909, CVE-2026-34908, CVE-2026-33000, CVE-2026-22557 (CVSS: Up to 10.0) * **Status:** Active exploitation detected * **Vulnerable:** UniFi Network Application, UniFi OS Server, UniFi Express (specific versions not detailed in source — check vendor advisory) * **Fixed:** Patches are available (specific versions not detailed in source — check vendor advisory) * **Workaround:** None mentioned in source * **Reference:** [BSI Germany: Ubiquiti UniFi: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2171)

* **Ivanti Sentry Pre-Auth RCE (CVE-2026-10520)** A critical pre-authentication remote code execution flaw in Ivanti Sentry allows attackers to gain complete control. Actively exploited by ransomware actors. * **CVE:** CVE-2026-10520 (CVSS: 10.0) * **Status:** Active exploitation detected * **Vulnerable:** Versions prior to 10.5.2, 10.6.2, and 10.7.1 * **Fixed:** Patches released June 10, 2026 (versions 10.5.2, 10.6.2, 10.7.1) * **Workaround:** None mentioned in source * **Reference:** [BleepingComputer: Max severity Ivanti Sentry vulnerability now exploited in attacks](https://www.bleepingcomputer.com/news/security/max-severity-ivanti-sentry-vulnerability-now-exploited-in-attacks/)

* **Citrix NetScaler Memory Overread Vulnerability (CVE-2026-3055)** A critical out-of-bounds read vulnerability in Citrix NetScaler ADC/Gateway configured as a SAML Identity Provider allows unauthenticated attackers to leak sensitive memory data. Actively exploited. * **CVE:** CVE-2026-3055 (CVSS: 9.3) * **Status:** Active exploitation detected * **Vulnerable:** Multiple prior releases (specific versions not detailed in source — check vendor advisory) * **Fixed:** Patches available (specific versions not detailed in source — check vendor advisory) * **Workaround:** None mentioned in source * **Reference:** [CSO Online: New CitrixBleed-like NetScaler flaw sees exploit attempts in the wild](https://www.csoonline.com/article/4192741/new-citrixbleed-like-netscaler-flaw-sees-exploit-attempts-in-the-wild.html)

* 🏢 **Cisco Unified CM SSRF Vulnerability (CVE-2026-20230)** A critical Server-Side Request Forgery (SSRF) flaw in Cisco Unified Communications Manager allows unauthenticated attackers to write files and escalate privileges to root. Exploitation observed in the wild. * **CVE:** CVE-2026-20230 (CVSS: 8.6) * **Status:** Active exploitation detected * **Vulnerable:** Version 14 prior to 14SU6; Version 15 prior to 15SU5 * **Fixed:** Patches available in versions 14SU6 and 15SU5 * **Workaround:** None mentioned in source * **Reference:** [SecurityWeek: Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability](https://www.securityweek.com/?p=47601)

* **Splunk Enterprise Unauthenticated RCE (CVE-2026-20253)** A critical vulnerability in Splunk Enterprise allows unauthenticated remote code execution. Actively exploited days after disclosure. * **CVE:** CVE-2026-20253 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Splunk Enterprise 10.0.0 through 10.2.3 and others (specific ranges not detailed in source — check vendor advisory) * **Fixed:** Patches available in updated versions (specific versions not detailed in source — check vendor advisory) * **Workaround:** None mentioned in source * **Reference:** [Help Net Security: Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286)

## 🔍 Threat Activity * **FortiBleed Credential Harvesting Campaign Escalates** The **FortiBleed** campaign has exposed administrative and SSL VPN credentials for over 110 million sessions from more than 70,000 internet-facing **Fortinet** devices. Threat actors are using these harvested credentials for brute-force attacks and to pivot into corporate networks. This is not a new vulnerability but a mass credential harvesting operation targeting known or default credentials. * **First Autonomous AI Ransomware Agent Confirmed** The **JadePuffer** AI agent has been confirmed as the first fully autonomous, LLM-driven ransomware attack, exploiting the critical Langflow RCE vulnerability (CVE-2025-3248). The agent performed reconnaissance, lateral movement, and encryption autonomously. * **Iran-Linked Cavern Manticore Deploys New C2 Framework** The Iran-linked threat actor **Cavern Manticore** is targeting Israeli organizations with a new modular .NET command-and-control framework. The framework uses advanced evasion techniques (Mixed-Mode C++/CLI, Native AOT) and is deployed via DLL side-loading through SysAid. * **Google and FBI Disrupt NetNut Botnet** A joint operation has disrupted the **NetNut** residential proxy botnet, comprising over 2 million compromised IoT and Android devices. The botnet was used for credential-stuffing and other cybercrimes. Disruption involved disabling C2 infrastructure and blocking malicious SDKs.

## 📋 Patches & Updates * **Microsoft SharePoint Multiple Critical RCE Flaws**: Patches are available in Microsoft's April 2026 updates for actively exploited vulnerabilities (CVE-2026-20963, CVE-2026-32201) affecting SharePoint Server 2016, 2019, and prior versions. * **BeyondTrust Remote Support Pre-Auth RCE (CVE-2026-1731)**: SaaS instances were patched on February 2, 2026; self-hosted deployments require manual updates. This flaw is actively exploited with VShell, SparkRAT, and ransomware payloads. * **Apple iOS/iPadOS Critical Vulnerabilities**: Apple has released patches for multiple critical vulnerabilities (CVSS up to 9.8) allowing RCE and privilege escalation in iOS and iPadOS prior to versions 18.7.9 and 26.5. * **Oracle E-Business Suite Critical Flaws**: Patches were released in May 2026 for multiple critical vulnerabilities (CVSS 9.8-9.9), including CVE-2026-46817 which is now actively exploited.

## Today's Priorities 1. **Patch Ubiquiti UniFi and Ivanti Sentry systems immediately.** These are under active, widespread exploitation for initial access and ransomware deployment. 2. **Audit and rotate credentials on all internet-facing Fortinet devices** in response to the massive FortiBleed credential leak. Enforce MFA where possible. 3. **Verify patch status for Citrix NetScaler, Cisco Unified CM, and Splunk Enterprise** against the critical, actively exploited CVEs listed. 4. **Review exposed AI/ML infrastructure**, particularly OpenClaw and Langflow instances, for unpatched critical vulnerabilities being leveraged in automated attacks.

## 🔗 References

  • [BSI Germany: Ubiquiti UniFi: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2171)
  • [BleepingComputer: Max severity Ivanti Sentry vulnerability now exploited in attacks](https://www.bleepingcomputer.com/news/security/max-severity-ivanti-sentry-vulnerability-now-exploited-in-attacks/)
  • [The Hacker News: FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation](https://thehackernews.com/2026/06/fortibleed-targeted-fortigate-firewalls.html)
  • [Dark Reading: JadePuffer: The First Complete LLM-Driven Ransomware Attack](https://www.darkreading.com/cyberattacks-data-breaches/jadepuffer-first-complete-llm-driven-ransomware-attack)
  • [SecurityWeek: Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability](https://www.securityweek.com/?p=47601)

Share this article