~/greenteam/nerd

Thursday, June 25, 2026

Daily digest

Cisco Catalyst SD-WAN CVE-2026-20245 dominates today — Mandiant confirmed zero-day exploitation two months before public disclosure, with a second Cisco flaw (CVE-2026-20230) also now under active exploitation. If Cisco SD-WAN is anywhere in your network edge or supply chain, treat this as urgent.

cybersec BleepingComputer

Mandiant Reveals How Cisco SD-WAN Zero-Day Attacks Gained Root Access (CVE-2026-20245)

Mandiant confirmed that threat actors exploited CVE-2026-20245 (CVSS 7.8) in Cisco Catalyst SD-WAN at least two months before public disclosure. Attackers used rogue peering to connect to victim SD-WAN devices, then created unauthorized root accounts. A second flaw, CVE-2026-20230, is also now under active exploitation according to The Register's concurrent coverage.

Why it matters: If Cisco Catalyst SD-WAN is used at your network edge or by any DIB partners you connect to, root-level compromise via rogue peering is a CUI exfiltration risk — patch immediately and audit SD-WAN peering configurations and admin account logs for anomalies going back at least 60 days.

cybersec The Hacker News

CISA Warns of Actively Exploited Critical Lantronix EDS5000 Flaw (CVE-2025-67038, CVSS 9.8)

CISA added CVE-2025-67038, a critical code-injection vulnerability in Lantronix EDS5000 Series serial-to-ethernet devices, to its Known Exploited Vulnerabilities catalog. FCEB agencies have a patch deadline of June 26, 2026. CISA simultaneously warned of active exploitation of max-severity flaws in Ubiquiti UniFi OS devices.

Why it matters: Lantronix serial-to-ethernet converters are common in OT/lab environments and legacy server rooms — inventory your environment for EDS5000 devices now. Ubiquiti UniFi is widely used for facility and guest Wi-Fi; exploitation of those flaws could provide a lateral movement foothold into managed network segments.

cybersec The Hacker News

Amadey and StealC Infrastructure Dismantled, 27M Stolen Credentials Recovered

In an Operation Endgame follow-on action, Europol, Microsoft's Digital Crimes Unit, Bitdefender, ESET, and others took down 200+ C2 servers supporting the Amadey and StealC infostealer operations. Approximately 27 million stolen credentials were recovered. StealC is a credential-harvesting tool widely used as a precursor to ransomware deployment.

Why it matters: StealC has been used to harvest credentials from managed Windows endpoints — check your threat intelligence feeds and Microsoft Defender telemetry for any prior StealC indicators, and verify whether any harvested credentials may have included M365 GCC High accounts.

cybersec The Hacker News

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

Researchers at Novee Security disclosed a class of CI/CD workflow vulnerability dubbed Cordyceps that allows attackers to hijack GitHub Actions workflows and gain full control of affected repositories. Over 300 repositories at major organizations — including Microsoft, Google, and Apache — were found to contain the exploitable pattern. The flaw stems from improper handling of user-controlled input in workflow triggers.

Why it matters: If your Ansible playbooks, container image builds, or infrastructure-as-code pipelines pull from any GitHub-hosted upstream dependencies, a compromised repository in your dependency chain could inject malicious code into your environment — audit GitHub Actions workflow permissions and pin dependency versions with verified checksums.

cybersec The Hacker News

New Gaslight macOS Malware Uses Prompt Injection to Defeat AI-Assisted Malware Analysis

Researchers identified a Rust-based macOS implant and infostealer named Gaslight that embeds prompt injection payloads designed to cause AI-assisted analysis tools to abort or refuse to analyze the sample. The malware is assessed with high confidence to be an offensive tool rather than commodity malware. A related Schneier on Security post documents a separate technique where malware embeds policy-triggering text (e.g., WMD references) in comments to confuse automated AI scanners.

Why it matters: If your SOC or IR process uses AI-assisted triage tools (e.g., Copilot for Security, third-party LLM-based sandboxes) as a first-pass filter, adversaries are now actively engineering malware to blind those tools — samples that your AI tools flag as benign or refuse to analyze should be escalated, not dismissed.

cybersec BleepingComputer

Malicious Edge Extension 'Edgecution' Abuses Native Messaging to Deploy Ransomware

A malicious Microsoft Edge browser extension named Edgecution was used in a ransomware attack to escape the browser sandbox via the Native Messaging API, then deploy a Python-based backdoor. The attack chain leverages a legitimate browser feature to bridge from a compromised extension to host-level code execution.

Why it matters: Your Intune-managed Windows 11 fleet almost certainly runs Edge as the default browser — review your Intune/Defender for Endpoint policies to restrict unapproved browser extension installation and consider blocking or auditing Native Messaging host registrations, which are frequently overlooked in endpoint hardening.

infrastructure AWS Security Blog

AWS Announces Network-Based Restrictions for Management Console Sign-In via Resource Control Policies

AWS published guidance on using newly supported resource-based policies and Resource Control Policies (RCPs) for AWS Sign-In to restrict Management Console and AWS CLI login sessions to specific approved networks, including on-premises data centers and VPCs. The controls allow organizations to enforce that console access only originates from expected IP ranges, regardless of valid credentials.

Why it matters: For your AWS GovCloud environment, implementing sign-in RCPs to restrict console access to your corporate egress IPs or VPN ranges directly supports NIST 800-171 AC.3.017 (least privilege) and AC.3.012 (remote access controls) — this is a low-effort, high-value control worth implementing in the near term.

cmmc NextGov

DOD Releases Post-Quantum Cryptography Strategy

Pentagon CIO Kirsten Davies described the DOD's newly published post-quantum cryptography strategy as 'a first step' in preparing department operations for the quantum threat era. The strategy is framed as one component of a broader readiness posture rather than a comprehensive solution. Separately, a Senate NDAA amendment to reauthorize the National Quantum Initiative is also advancing.

Why it matters: DIB contractors handling CUI should begin tracking NIST post-quantum cryptography standards (FIPS 203/204/205) now — CMMC assessments in the next revision cycle are expected to reference PQC migration readiness, and early inventory of cryptographic dependencies in your M365 GCC High and AWS GovCloud integrations will reduce future remediation costs.

cmmc Federal News Network

Anthropic's Mythos AI Model Found Vulnerabilities in Classified US Government Systems

A U.S. government official disclosed that Anthropic's Mythos model identified vulnerabilities in classified government systems during an evaluation. Anthropic has separately raised concerns about how the U.S. military intends to use its AI, and the administration has restricted use of some Anthropic models in certain contexts.

cybersec NextGov

Residential Proxy Networks Turning Home IPs Into Hacker Cover — 'Blood Diamonds of the Digital Age'

Researchers traced millions of household IP addresses being sold through illicit residential proxy networks, which allow attackers to route malicious traffic through legitimate consumer ISP addresses to evade geo-blocking and IP reputation filters. The scale of these networks undermines IP-based access controls and threat intelligence feeds that rely on IP reputation.

Why it matters: IP allowlisting and geo-restriction controls on your M365 GCC High tenant and AWS GovCloud console are weaker mitigations than they appear if adversaries are sourcing traffic from residential US IPs — this reinforces the case for conditional access policies based on device compliance and identity rather than network location alone.

infrastructure HashiCorp Blog

HCP Vault Dedicated Introduces Cluster-Level Disaster Recovery (Public Preview)

HashiCorp announced public preview of cluster disaster recovery for HCP Vault Dedicated, enabling teams to simulate full cluster failures and test failover readiness at the cluster level rather than just data replication. The feature is intended to support DR drills without impacting production workloads.

Why it matters: If Vault is part of your secrets management or PKI infrastructure — common in Ansible automation and Kubernetes/container environments — cluster DR capability directly supports NIST 800-171 CP requirements for contingency planning and recovery testing. Worth evaluating if you've deferred Vault DR implementation.

cmmc FedScoop

FedScoop: 'Just Having a Human in the Loop' Is Not AI Governance

A FedScoop analysis argues that federal agencies are deploying AI systems with nominal human oversight checkpoints but without the underlying governance structures — policies, accountability chains, training, and audit mechanisms — needed for those checkpoints to be meaningful. The piece calls out the gap between compliance theater and substantive AI risk management.

Why it matters: As DIB contractors increasingly deploy AI tools in workflows that touch CUI — including AI-assisted ticket triage, document summarization, or code generation — auditors and assessors are beginning to scrutinize AI governance as a component of overall system security plans; documented policies and review procedures will matter.