The Lyceum: Cyber Intelligence Daily — Jun 25, 2026
Photo: lyceumnews.com
Thursday, June 25, 2026
Morning Command Brief
- Patch your edge gear by tonight: CISA's KEV deadline for actively-exploited Ubiquiti UniFi OS and Lantronix EDS5000 flaws expires tomorrow, June 26.
- Assume compromise, not just exposure, on Cisco SD-WAN: Mandiant's overnight post-mortem shows attackers held root for two months pre-disclosure and deleted their tracks — patching alone won't tell you if you were breached.
- Go check Have I Been Pwned: Operation Endgame recovered up to 27 million stolen credentials, and SocGholish-related data is already being loaded into HIBP.
What Changed Overnight
Cisco SD-WAN's seventh 2026 zero-day — attackers inside for two months
Mandiant published a post-mortem on CVE-2026-20245, the seventh actively-exploited SD-WAN flaw this year. Attackers used earlier auth-bypass bugs to establish rogue peering on a service provider from March 2026, then uploaded a malicious "evil_tenant.csv" via the CLI tenant-upload feature to execute as root, creating a "troot" account before restoring configs and deleting traces. Anyone running Cisco Catalyst SD-WAN Manager is exposed; fixes ship in 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, and 26.1.1.2. Patch, then open a Cisco TAC case and upload admin-tech bundles for compromise review — upgrading doesn't reveal prior intrusion.
CISA KEV deadline tomorrow: four exploited Ubiquiti and Lantronix flaws
CISA added three UniFi OS flaws (CVE-2026-34908/-34909/-34910 — improper access control, path traversal, input validation) and one Lantronix EDS5000 bug (CVE-2025-67038, CVSS 9.8) to the KEV catalog, all due June 26. Bishop Fox showed the UniFi trio chains to unauthenticated RCE with elevated privileges and has published a detection script; the Lantronix flaw injects OS commands via the HTTP log username field for root. Small-business and enterprise UniFi operators plus industrial Lantronix users are exposed. Update UniFi OS to 5.0.8+ and Lantronix to firmware 2.2.0.0R1 — if you can't patch tonight, pull management interfaces off internet-facing networks and confine to a trusted VLAN.
Operation Endgame dismantles the ransomware supply chain
Between June 15-19, authorities from eight countries took down the infrastructure behind StealC and Amadey — subscription malware linked to over 140,000 infected machines in early May alone. Proofpoint and IBM X-Force exploited a bug in StealC's C2 panel to build a tracking emulator. The result: 326 servers and 142 domains dismantled, over $47 million in crypto restricted, and up to 27 million credentials recovered. Recovered credentials are being loaded into Have I Been Pwned — check haveibeenpwned.com and rotate before attackers monetize them via VPN and SaaS credential-stuffing.
Edgecution: malicious Edge extension escapes the browser sandbox
BleepingComputer documents "Edgecution," a malicious Microsoft Edge extension used in a ransomware attack to break the browser sandbox and deploy a Python backdoor. The technique abuses Native Messaging — a legitimate Windows feature bridging extensions to desktop apps — to run code on the underlying system. Browser extensions are a largely unmonitored attack surface that most security teams never audit. Review installed extensions now and restrict installs to an approved allowlist.
Coverage Notes
- Coverage note: CVE-2026-21509: Actively Exploited Microsoft Office Zero-Day Forces Emergency Patch — Research inputs treated this as prior or recirculated context rather than a fresh standalone development; monitor for a new vendor advisory, KEV deadline, or active-exploitation escalation. Key terms: Microsoft Office, zero-day, actively exploited, emergency patch, CVE-2026-21509. Source: SOC Prime.
Watch Next
- If Cisco or Mandiant names the SD-WAN actor, the "restore configs, delete traces" tradecraft will likely confirm nation-state espionage — meaning your management plane is a deliberate objective, not collateral.
- If the 27 million Endgame credentials land in HIBP, it means a narrow window to rotate ahead of credential-stuffing against VPNs and SaaS — organizations that miss it will see attacks within weeks.
- If StealC and Amadey operators reappear on fresh infrastructure within 60 days, it means Endgame was tactical theater rather than structural disruption.