THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
China-linked UNC6508 abused REDCap servers and Google Workspace rules to siphon research and defense emails

Google’s Threat Intelligence Group exposed a long-running PRC-nexus campaign that breached vulnerable REDCap servers at North American medical, academic, and military research organizations. Attackers deployed a bespoke backdoor (INFINITERED) to harvest credentials, then covertly exfiltrated sensitive emails by abusing domain content compliance rules that silently BCC-forwarded messages to an attacker-controlled Gmail account. The operation persisted for over a year with strong OPSEC. Defenders should urgently patch/remove legacy REDCap versions, enable phishing-resistant 2SV for admins, audit Workspace compliance rules, and hunt for INFINITERED IOCs.

Source: GoogleCloud TI


Cisco SD-WAN zero-day (CVE-2026-20262) actively exploited; patch now

Cisco released fixes for a Catalyst SD-WAN Manager flaw that allows authenticated attackers to write arbitrary files via the web UI—an issue now under active exploitation. Successful abuse can lead to code execution and full system compromise. Organizations should apply the update immediately, restrict SD-WAN Manager exposure, and monitor for suspicious admin actions or unexpected file writes.

Source: TheHackerNews


Palo Alto PAN‑OS GlobalProtect auth bypass (CVE-2026-0257) exploited in the wild; added to CISA KEV

An authentication bypass impacting GlobalProtect portals/gateways is being actively abused to establish unauthorized VPN sessions. Despite patches being available since May, exploitation continues and CISA has added the bug to its Known Exploited Vulnerabilities list. Patch affected PAN‑OS versions, comb VPN logs for anomalous connections, revoke rogue sessions/creds, and consider geo/IP restrictions where feasible.

Source: SCMagazine


One‑click Microsoft 365 Copilot data theft via “SearchLeak” chaining (CVE-2026-42824) — now patched

Varonis researchers chained three issues to turn a single trusted microsoft.com link into a powerful exfiltration vector against Copilot Enterprise Search, exposing emails, calendar details, indexed files—even MFA codes. Microsoft has addressed the issue, but the case underscores the blast radius of over-permissive enterprise search and assistants. Limit Copilot entitlements and indexing scope, enable detailed audit logging, and review tenant-wide app and link trust policies.

Source: Varonis


Velvet Ant: China-linked spies backdoored an organization’s authentication stack to hide for years

Sygnia detailed an APT dubbed Velvet Ant that maintained nearly decade-long persistence inside a target network by compromising identity infrastructure. By backdooring the full authentication stack and rotating tactics, the group evaded detection and proved difficult to evict. Identity systems remain prime targets—validate trust anchors, audit SSO/MFA provider configurations, monitor for golden ticket/Golden SAML–style abuse, and be prepared for staged identity rebuilds during eviction.

Source: Help Net Security


Supply-chain attack on popular WordPress plugins via Awesome Motive CDN tampering

Attackers modified trusted JavaScript delivered to sites running OptinMonster, TrustPulse, and PushEngage, turning legitimate assets into a backdoor. When an admin loaded the tainted script, it could create a rogue admin account and install a hidden plugin for persistence. Site owners should verify plugin asset integrity, rotate admin credentials, remove unknown admins/plugins, and consider enforcing Subresource Integrity (SRI) and CSP where possible.

Source: TheHackerNews


FBI and Google dismantle “Outsider Enterprise” phishing service tied to 9,000 sites and $1.9B in losses

Law enforcement took down a prolific phishing platform that operated thousands of sites, stole nearly 4 million credit cards, and inflicted an estimated $1.9 billion in damages. The service industrialized credential theft at scale, underscoring how PhaaS lowers barriers for less-skilled criminals. Security teams should update blocklists, review detections for Outsider-related IOCs, and reinforce MFA and anti-phishing controls.

Source: SecurityWeek


You May Also Be Interested In...

Anthropic says US government forced it to disable cybersecurity AI models
CISA flags actively exploited LiteSpeed cPanel plugin flaw for root escalation
Arch Linux locks down AUR signups after wave of malicious commits

Cybersecurity — June 16, 2026 | Briefing24