THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

4 min read

AI-assisted briefingHow we put it together ↗
Operation Endgame: Law enforcement disrupts StealC and Amadey “assembly line” infrastructure

International law enforcement and partners, including Microsoft and other private-sector security firms, targeted the infrastructure behind StealC and Amadey—malware families used together to compromise victims and steal data for fraud and ransomware workflows. The takedowns disrupted key “service” components and recovered millions in stolen credentials, underscoring how much modern cybercrime depends on shared back-end infrastructure. For defenders, the takeaway is to treat cybercrime operations as ecosystems: credential theft pipelines and monetization layers are often as important to detect and dismantle as the initial malware drop.

Source: Help Net Security


Cisco Unified CM (CVE-2026-20230) actively exploited: attackers move from SSRF to webshell-style control

Security reporting indicates CVE-2026-20230—a Cisco Unified Communications Manager issue—has been actively exploited in the wild to enable server-side request forgery (SSRF) chains that culminate in remote code execution capabilities such as webshell deployment. Observed activity includes automated sweeps that leverage anonymity infrastructure (e.g., Tor) and attempt reliable deployment on exposed systems. The key action item for security teams is to prioritize asset identification for Unified CM and confirm patch status and compensating controls immediately, then hunt for webshell indicators and suspicious outbound/internal request patterns.

Source: Help Net Security


Cisco Catalyst SD-WAN zero-day chain: CVE-2026-20245 exploited to escalate to root (with anti-forensics)

Mandiant and Cisco have detailed a compromise path against Cisco Catalyst SD-WAN Manager where attackers exploited CVE-2026-20245 to gain root-level control via a malicious tenant-list upload (including attempts to modify /etc/passwd and /etc/shadow). The report also describes extensive anti-forensic behavior—deleting or reverting artifacts to reduce detection—and shows how attackers use stealthy authentication and configuration rollback tactics to hide changes. For defenders, the most important insight is that SD-WAN control planes are high-value targets: they demand rapid patching, privileged access monitoring, and targeted threat hunts that look beyond “alerts” to the exact administrative actions attackers manipulate.

Source: Google Cloud Threat Intelligence


FortiBleed: credential access-brokering exposes valid logins for ~73,000 Fortinet firewalls

A widespread operation dubbed “FortiBleed” is reported to have exposed valid credentials for tens of thousands of Fortinet firewall devices, enabling attackers to pivot through legitimate remote access paths. The “broker” model turns exposed management access into a scalable product, lowering friction for follow-on intrusions across many organizations. Defenders should treat any sign of exposed administrative interfaces as an incident trigger: rotate credentials, restrict management-plane access, verify exposure of diagnostic utilities, and validate whether attackers used the credentials before remediation.

Source: Security Affairs


Klue supply-chain incident expands: OAuth token compromise exposed customer Salesforce data (LastPass also affected)

Multiple reports tie the Klue incident to stolen OAuth tokens used to access customer data stored in Salesforce environments, implying that attackers succeeded in compromising a trusted third-party integration. LastPass disclosed that attackers leveraged compromised OAuth tokens from Klue to reach data in its Salesforce environment, highlighting the downstream risk of “legitimate” access paths. The security lesson is clear: focus on identity and token posture (scopes, lifetimes, audience restrictions), validate third-party integrations, and consider token revocation and integration auditing as core incident-response steps—not optional follow-ups.

Source: Help Net Security


New scam playbooks: sextortion and renewal-impersonation campaigns continue to scale via social engineering

Security-focused coverage highlights continued growth in sextortion lures claiming device control and in “renewal” scams impersonating well-known brands (including Malwarebytes) to trick users into fraudulent actions. These campaigns rely on convincing narrative hooks, urgency, and brand familiarity rather than technical exploitation—meaning they succeed even when patching is strong. For teams, the practical guidance is to tighten user-facing controls (email filtering/verification, safe-browsing prompts), reinforce reporting workflows, and ensure support desks have current scripts for verifying legitimate account and subscription events.

Source: Malwarebytes


AI security shift: “prompt testing” is no longer enough—enterprises need AI red teaming across workflows

Check Point argues that enterprise AI systems are not isolated chat interfaces; they include policies, retrieval pipelines, APIs/tools, permissions, and evolving models—so testing must expand beyond prompt refusals. The move to AI red teaming at enterprise scale focuses on how failures and abuse can propagate through workflows (data access, tool invocation, and decision logic), where real-world risk lives. This is a governance and engineering requirement, not just a research exercise: organizations should map end-to-end AI execution paths and test authorization boundaries and tool outputs just as rigorously as model behavior.

Source: Checkpoint Blog


You May Also Be Interested In...
Cisco SD-WAN Zero-Day Exploited Months Before Patching
Google Workspace expands password reset alerts to all admins
What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime
Cybersecurity — June 25, 2026 | Briefing24