The Lyceum: Cyber Intelligence Daily — Jun 26, 2026
Photo: lyceumnews.com
Friday, June 26, 2026
Morning Command Brief
- Patch today or accept exploitation: CISA's three-day clock expires now on actively exploited Lantronix EDS5000 (CVSS 9.8) and three CVSS 10.0 Ubiquiti UniFi OS flaws with public PoC chaining to full device takeover.
- Assume your perimeter trust is the breach vector: Polymarket lost ~$3 million Thursday via a third-party vendor that injected malicious JavaScript into users' browsers — on-chain contracts worked perfectly; the plumbing didn't.
- Treat Cloudflare-whitelisted traffic as hostile: Russia's FSB-linked Turla (STOCKSTAY) and Gamaredon are now hiding inside trusted cloud and signed traffic, targeting Ukrainian defense and foreign-policy networks.
What Changed Overnight
Google Exposes Turla's STOCKSTAY Backdoor Targeting Ukraine
Google's Threat Intelligence Group detailed STOCKSTAY, a previously undocumented .NET backdoor deployed by FSB-linked Turla (Secret Blizzard / UAC-0194) since at least December 2022 against Ukrainian government and military targets, plus entities tied to Italian foreign policy. It shares significant code with KAZUAR, communicates over WebSocket to blend as encrypted web traffic, and was delivered via WinRAR flaw CVE-2025-8088 using drone-themed military lures. In one 2023 incident, Turla pushed STOCKSTAY, WILDDAY, DIAMONDBACK, and KAZUAR via malicious Group Policy from a compromised domain controller. Defense and foreign-policy orgs should hunt for signature-evading WebSocket C2; a CERT-UA cross-reference makes IOCs operationally urgent.
CISA's Three-Day Clock Expires — Four Device Flaws Under Attack
CVE-2025-67038, a CVSS 9.8 code-injection flaw in Lantronix EDS5000 serial-to-IP converters, is actively exploited; the device bridges PLCs, RTUs, and sensors to IP networks, so compromise sits directly on the OT/IT boundary. Per Forescout, attackers hit a Lantronix honeypot as early as April 5, likely reverse-engineering the February patch. Three CVSS 10.0 Ubiquiti UniFi OS flaws (CVE-2026-34908/-34909/-34910) are also exploited, with Bishop Fox PoC chaining them to full control and Defused reporting malware distribution. Patch now to Lantronix firmware 2.2.0.0R1 and UniFi OS Server 5.0.8+ — no waiting for a maintenance window.
Polymarket Loses $3M to a Frontend Vendor Compromise
Polymarket confirmed hackers stole funds after a third-party vendor compromise let them inject malicious code into the site "for some users." This was not a smart-contract exploit — the frontend script tricked connected wallets into approving draining transactions, pulling ~$3 million in PUSD from 11+ wallets, bridged to ~1,893 ETH. Any web app loading third-party JavaScript — analytics, ad networks, support widgets, payment processors — carries this surface; the company says it has contained the incident and is refunding victims fully. Watch for the vendor name to gauge shared-dependency exposure.
Gamaredon Overhauls Evasion With Cloud Tunnels and Dead Drops
ESET documented FSB group Gamaredon (UAC-0010) — responsible for thousands of simultaneous Ukraine infections — now leaning on Cloudflare Tunnels, Cloudflare Workers, and dead drops inside Telegram and Telegra.ph to hide C2 in whitelisted IP ranges. ESET also notes deepening Turla collaboration: Gamaredon breaches, Turla persists quietly. Blocking known Gamaredon domains is no longer enough — defenders need egress inspection of "normal" cloud traffic or they go blind.
Coverage Notes
- Coverage note: CVE-2026-21509: Actively Exploited Microsoft Office Zero-Day Forces Emergency Patch — This is a required major-headline item for reader awareness; monitor vendor guidance, exploitation reports, and any emergency patch timeline. Key terms: Microsoft Office, zero-day, actively exploited, emergency patch, CVE-2026-21509. Source: SOC Prime.
Watch Next
- If CERT-UA publishes an advisory cross-referencing Google's STOCKSTAY disclosure, it means the backdoor is confirmed live in Ukrainian government networks and the IOC set becomes immediately actionable for defense and foreign-policy teams.
- If GreyNoise shows a UniFi or Cisco SD-WAN scanning spike after today's deadlines pass, it means exploitation has shifted from targeted to opportunistic mass-scanning and the quiet-patching window has closed.
- If Polymarket names the compromised vendor and that vendor's JavaScript loads on other financial or Web3 platforms, it means the malicious dependency may still be running live elsewhere.