~/greenteam/nerd

Friday, June 5, 2026

Daily digest

Two Cisco vulnerabilities dominate today — an unpatched SD-WAN zero-day under active exploitation and a critical Unified CM flaw with public PoC code. If Cisco gear touches your network perimeter or UC stack, treat both as urgent.

cybersec BleepingComputer

Cisco warns of unpatched SD-WAN zero-day exploited in attacks

Cisco disclosed CVE-2026-20245, a high-severity zero-day in Catalyst SD-WAN Manager that is actively being exploited to achieve root privilege escalation — with no patch currently available. Organizations relying on Cisco SD-WAN for network segmentation or remote connectivity should review Cisco's mitigation guidance immediately and monitor for indicators of compromise. No fix is available yet, making this the most urgent item of the day.

cybersec BleepingComputer

Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

Cisco patched a critical server-side request forgery bug in Unified Communications Manager (CVE-2026-20230) that allows an unauthenticated network attacker to write arbitrary files and escalate to root. Public proof-of-concept exploit code is already circulating, dramatically shortening the window before exploitation becomes widespread. Patch immediately if Unified CM is in your environment.

cybersec The Hacker News

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

Threat actor PCPJack compromised over 230 business cloud servers across AWS, Azure, and Google Cloud and repurposed them as covert SMTP relay proxies, syncing the network to downstream consumers every five minutes. The campaign targeted misconfigured or vulnerable cloud workloads across the US, Europe, and Asia, with victim infrastructure silently weaponized for spam and phishing operations. AWS GovCloud tenants should audit outbound SMTP traffic and review IAM permissions for unusual activity.

cybersec BleepingComputer

New IronWorm malware hits 36 packages in npm supply-chain attack

A Rust-written infostealer called IronWorm was injected into 36 npm packages in a supply-chain attack targeting developers, stealing credentials and using them to propagate further through the software supply chain. Any organization with CI/CD pipelines consuming npm packages — including Ansible roles or automation tooling with Node.js dependencies — should audit recently updated packages. This is a direct threat to software build integrity in environments subject to CMMC supply chain requirements.

cybersec The Hacker News

China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa

Chinese cybercrime group TA4922 has significantly expanded its phishing operations beyond East Asia, now targeting organizations in the UK, Germany, Italy, and South Africa using ValleyRAT and Atlas RAT malware. The group operates at a rapid tempo with a constantly evolving malware arsenal, making detection and signature-based defenses difficult. Defense contractors and government suppliers with European business ties should treat this as an elevated threat to CUI-handling systems.

cybersec The Hacker News

Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months

Unknown attackers maintained persistent access to a senior executive's Outlook mailbox for at least five months, exfiltrating email in small batches routed through Dropbox and OneDrive to blend with normal cloud traffic. Symantec assessed the campaign as espionage-motivated, with the low-and-slow exfiltration technique specifically designed to evade detection. This is a direct reminder to audit OAuth app permissions, Outlook audit logs, and anomalous OneDrive/Dropbox egress in M365 GCC High environments.

cybersec The Register

Five Eyes: Watch out for odd LinkedIn connection requests, China's back on the hunt for state secrets

Five Eyes intelligence agencies issued a joint warning about China's continued use of LinkedIn and social media to recruit insiders with access to classified or sensitive government information. The tradecraft involves fake personas offering financial incentives for information, a tactic that has persisted for years with demonstrated success. Personnel in cleared contractor environments handling CUI should receive refreshed insider threat and social engineering awareness briefings.

cybersec The Register

Pink threat group uses fake helpdesk calls to steal credentials

A threat group dubbed 'Pink' is executing vishing campaigns using fake IT helpdesk calls to steal employee credentials, echoing the social engineering playbook popularized by Lapsus$. The technique bypasses technical controls entirely by targeting users directly, making it effective even against well-hardened environments. CMMC Level 2 environments should ensure helpdesk identity verification procedures are enforced and that MFA cannot be social-engineered away through reset flows.

cmmc Federal News Network

CISA close to issuing new cyber AI directive

CISA is finalizing a new directive that will establish a platform to help federal agencies leverage AI for defensive cybersecurity purposes. The directive is expected to shape how agencies integrate AI into SOC operations and threat detection, with downstream implications for contractors operating under government cybersecurity frameworks. Watch for this to influence future CMMC and NIST guidance on acceptable AI use in security operations.

cmmc FedScoop

Bipartisan 'Great American AI Act' draft proposes new federal AI governance framework

A bipartisan House discussion draft would authorize $100 million annually for a Center for AI Standards and Innovation and establish federal oversight mechanisms for government AI adoption. The proposal would also preempt state AI laws for three years, creating a single federal compliance lane for contractors deploying AI tools across government engagements. Organizations using AI in government-adjacent workflows should track this closely as it could directly affect compliance obligations.

infrastructure BleepingComputer

Microsoft blames unexpected Windows driver updates on caching issue

Microsoft identified and fixed a bug that caused Windows devices to install driver updates without user or policy consent, bypassing configurations meant to block automatic driver updates. For environments using Intune or Group Policy to control driver deployment — particularly those maintaining validated hardware configurations for compliance — this represents an uncontrolled change risk. Verify driver inventory on managed endpoints for unexpected changes during the affected window.

infrastructure AWS Security Blog

Gain visibility into DDoS attacks with flow logs in AWS Shield Advanced

AWS Shield Advanced now supports attack flow logs that capture traffic metadata during active DDoS events, publishing logs to S3 for integration with existing SIEM and analysis pipelines. This eliminates the previous requirement to reconstruct attack traffic post-incident from disparate sources, enabling faster mitigation verification. GovCloud tenants using Shield Advanced should enable flow logs and route them into their SOC tooling for improved DDoS observability.