The Lyceum: Cyber Intelligence Daily — Jun 30, 2026
Photo: lyceumnews.com
Tuesday, June 30, 2026
Morning Command Brief
- Patch Oracle EBS now: CVE-2026-46817, an unauthenticated remote takeover of Oracle Payments fixed in the May CSPU, went live over the weekend with 450+ exposed instances online and no public PoC — meaning attackers built private tooling.
- Assume PeopleSoft compromise: Nissan confirmed an employee-data breach via CVE-2026-35273, the same Oracle zero-day ShinyHunters is running across unpatched orgs in higher education, insurance, and now automotive.
- Update every Apple device today: Apple shipped iOS 26.5.2/macOS Tahoe 26.5.2 fixing 30+ flaws — including no-interaction WebKit bugs, some found by AI tooling.
What Changed Overnight
Oracle EBS CVE-2026-46817 went from ignored to actively exploited
Live attack traffic was captured on June 27–28 hitting the /OA_HTML/ibytransmit endpoint with crafted XML, setting FULL_FILE_PATH to /etc/passwd from a French IP. The patch has been available since the May 2026 CSPU — over a month — so the unapplied fix is the entire story. Anyone running Oracle E-Business Suite for payments or accounting should patch immediately; recall CVE-2025-61882 in the same product became a Cl0p ransomware entry point late last year.
ShinyHunters' PeopleSoft campaign claims Nissan
Attackers exploited CVE-2026-35273 (missing authentication, on CISA KEV at maturity 3) to expose personal, financial, tax, and national ID data for Nissan employees across the US, Canada, Mexico, and Brazil. The same flaw hit the National Association of Insurance Commissioners, which said only public data was taken. If you run PeopleSoft and skipped the June 2026 CSPU fix, assume you're on the target list — exfiltrate-then-extort is the playbook.
APT28 weaponizes a five-month-old Office patch
Russia's GRU-linked APT28 (UAC-0001) reverse-engineered the January fix for CVE-2026-21509 (CVSS 7.8), now hitting orgs that never applied it. Exploitation was confirmed before public disclosure — a true zero-day initially used against high-value targets, now likely delivered via spear-phishing with malicious documents. Any org on Office 2016/2019 missing the January update is inside an active GRU campaign.
SimpleHelp KEV deadline hits Thursday
CISA added CVE-2026-48558, an OIDC authentication bypass, to KEV on June 29 with a July 2 deadline. Attackers are deploying Djinn Stealer, a previously undocumented cross-platform infostealer hunting cloud and AI credentials across Windows, macOS, and Linux. If you run SimpleHelp for remote IT support, the clock expires Thursday.
Watch Next
- If CISA adds CVE-2026-46817 to KEV this week, it means exploitation has moved past honeypots to confirmed victims — and federal agencies inherit a mandatory remediation deadline.
- If the ShinyHunters PeopleSoft victim list expands into healthcare or finance, it means CVE-2026-35273 has graduated from a sector campaign into a general-purpose enterprise intrusion tool, with every unpatched instance on a countdown.
- If CVE-2026-21509 picks up a CISA KEV addition, it means exploitation has been confirmed against US government or critical-infrastructure targets, triggering BOD 26-04's three-day federal patch clock.
Also tracking: Aflac Life Insurance Japan disclosed a breach affecting 4.38 million customers, with 230,000 having payment account details exposed (separate from the 2025 US Aflac incident; no actor identified). The State Department is offering $10 million for information on Russia-linked UNC5792 and UNC4221, which compromise Signal and WhatsApp accounts via device-linking tricks targeting officials, journalists, and activists — audit your linked devices. Delta Electronics DVP12SE PLCs have two unauthenticated flaws (CVE-2026-12818, CVE-2026-12819) over Modbus TCP with no fix listed — isolate from internet-accessible segments now. libssh2 ≤1.11.1 (CVE-2026-55200) now has public PoC for pre-auth memory corruption triggered by a malicious SSH server.