Friday, June 5, 2026
Daily digest
Two Cisco vulnerabilities dominate today — an unpatched SD-WAN zero-day under active exploitation and a critical Unified CM flaw with public PoC code. If Cisco gear touches your network perimeter or UC stack, treat both as urgent.
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
Cisco disclosed CVE-2026-20245, a high-severity zero-day in Catalyst SD-WAN Manager that is actively being exploited to achieve root privilege escalation — with no patch currently available. Organizations relying on Cisco SD-WAN for network segmentation or remote connectivity should review Cisco's mitigation guidance immediately and monitor for indicators of compromise. No fix is available yet, making this the most urgent item of the day.
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Cisco patched a critical server-side request forgery bug in Unified Communications Manager (CVE-2026-20230) that allows an unauthenticated network attacker to write arbitrary files and escalate to root. Public proof-of-concept exploit code is already circulating, dramatically shortening the window before exploitation becomes widespread. Patch immediately if Unified CM is in your environment.
PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network
Threat actor PCPJack compromised over 230 business cloud servers across AWS, Azure, and Google Cloud and repurposed them as covert SMTP relay proxies, syncing the network to downstream consumers every five minutes. The campaign targeted misconfigured or vulnerable cloud workloads across the US, Europe, and Asia, with victim infrastructure silently weaponized for spam and phishing operations. AWS GovCloud tenants should audit outbound SMTP traffic and review IAM permissions for unusual activity.
New IronWorm malware hits 36 packages in npm supply-chain attack
A Rust-written infostealer called IronWorm was injected into 36 npm packages in a supply-chain attack targeting developers, stealing credentials and using them to propagate further through the software supply chain. Any organization with CI/CD pipelines consuming npm packages — including Ansible roles or automation tooling with Node.js dependencies — should audit recently updated packages. This is a direct threat to software build integrity in environments subject to CMMC supply chain requirements.
China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa
Chinese cybercrime group TA4922 has significantly expanded its phishing operations beyond East Asia, now targeting organizations in the UK, Germany, Italy, and South Africa using ValleyRAT and Atlas RAT malware. The group operates at a rapid tempo with a constantly evolving malware arsenal, making detection and signature-based defenses difficult. Defense contractors and government suppliers with European business ties should treat this as an elevated threat to CUI-handling systems.
Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
Unknown attackers maintained persistent access to a senior executive's Outlook mailbox for at least five months, exfiltrating email in small batches routed through Dropbox and OneDrive to blend with normal cloud traffic. Symantec assessed the campaign as espionage-motivated, with the low-and-slow exfiltration technique specifically designed to evade detection. This is a direct reminder to audit OAuth app permissions, Outlook audit logs, and anomalous OneDrive/Dropbox egress in M365 GCC High environments.
Five Eyes: Watch out for odd LinkedIn connection requests, China's back on the hunt for state secrets
Five Eyes intelligence agencies issued a joint warning about China's continued use of LinkedIn and social media to recruit insiders with access to classified or sensitive government information. The tradecraft involves fake personas offering financial incentives for information, a tactic that has persisted for years with demonstrated success. Personnel in cleared contractor environments handling CUI should receive refreshed insider threat and social engineering awareness briefings.
Pink threat group uses fake helpdesk calls to steal credentials
A threat group dubbed 'Pink' is executing vishing campaigns using fake IT helpdesk calls to steal employee credentials, echoing the social engineering playbook popularized by Lapsus$. The technique bypasses technical controls entirely by targeting users directly, making it effective even against well-hardened environments. CMMC Level 2 environments should ensure helpdesk identity verification procedures are enforced and that MFA cannot be social-engineered away through reset flows.
CISA close to issuing new cyber AI directive
CISA is finalizing a new directive that will establish a platform to help federal agencies leverage AI for defensive cybersecurity purposes. The directive is expected to shape how agencies integrate AI into SOC operations and threat detection, with downstream implications for contractors operating under government cybersecurity frameworks. Watch for this to influence future CMMC and NIST guidance on acceptable AI use in security operations.
Bipartisan 'Great American AI Act' draft proposes new federal AI governance framework
A bipartisan House discussion draft would authorize $100 million annually for a Center for AI Standards and Innovation and establish federal oversight mechanisms for government AI adoption. The proposal would also preempt state AI laws for three years, creating a single federal compliance lane for contractors deploying AI tools across government engagements. Organizations using AI in government-adjacent workflows should track this closely as it could directly affect compliance obligations.
Microsoft blames unexpected Windows driver updates on caching issue
Microsoft identified and fixed a bug that caused Windows devices to install driver updates without user or policy consent, bypassing configurations meant to block automatic driver updates. For environments using Intune or Group Policy to control driver deployment — particularly those maintaining validated hardware configurations for compliance — this represents an uncontrolled change risk. Verify driver inventory on managed endpoints for unexpected changes during the affected window.
Gain visibility into DDoS attacks with flow logs in AWS Shield Advanced
AWS Shield Advanced now supports attack flow logs that capture traffic metadata during active DDoS events, publishing logs to S3 for integration with existing SIEM and analysis pipelines. This eliminates the previous requirement to reconstruct attack traffic post-incident from disparate sources, enabling faster mitigation verification. GovCloud tenants using Shield Advanced should enable flow logs and route them into their SOC tooling for improved DDoS observability.