CYBER_THREATCAST
$ briefing --date=

CYBER THREATCAST

CYBER THREAT INTELLIGENCE BRIEFING

Thursday, June 25, 2026|MORNING EDITION|09:10 TR (06:10 UTC)|316 Signals|15 Sectors
ROUNDTABLE ACTIVE5 agents · 18 messages · 24mView →
Cisco Unified Communications Manager tops a day dominated by active exploitation and identity-driven intrusion. Attackers are abusing CVE-2026-20230 to deploy webshells and reach remote code execution on underlying servers, while Storm-2603 is hitting unpatched on-premises Microsoft SharePoint flaws with ransomware and custom backdoors. At the same time, phishing and access-broker activity is leaning on legitimate platforms and trust signals: EvilTokens abuses Microsoft 365 device-code flows, Edgecution starts with Microsoft Teams lures and a fake Outlook update portal, and FortiBleed reportedly harvested credentials from more than 430,000 FortiGate firewalls.
The Cisco case stands out because the chain is already moving past initial access into deeper compromise. Reporting says attackers are using public exploit code, automated Tor-routed scans, and multi-stage webshells against internet-facing Unified CM, and one service provider victim saw escalation from a compromised admin account to root. Cisco administrators have a short list of immediate options in the reporting: upgrade or disable WebDialer.
Identity and administration paths keep resurfacing as the pressure points. SharePoint attackers combined CVE-2025-49706 and CVE-2025-49704 with ransomware, custom backdoors, and bring-your-own-vulnerable-driver tactics; EvilTokens is stealing valid Microsoft 365 access tokens through legitimate authentication; and FortiBleed shows how post-access traffic capture can turn edge infrastructure into a credential collection point. The common lesson is blunt: exposed collaboration, identity, and management systems are still giving attackers both entry and leverage.

Editorial: Recommended Actions

01
PRIORITY
Patch Cisco Unified Communications Manager immediately and disable WebDialer where you cannot upgrade at once. Attackers are actively exploiting CVE-2026-20230 with public exploit code, using an unauthenticated SSRF chain to drop multi-stage webshells and reach remote code execution on underlying servers. Reported activity includes automated Tor-routed scanning and a service-provider compromise that escalated from an admin account to root, so internet-facing Cisco Unified CM deployments should be treated as exposed until verified otherwise.
02
PRIORITY
Patch on-premises Microsoft SharePoint Server now and hunt for post-exploitation activity on any unpatched systems. Storm-2603 and a second unrelated threat actor are reportedly exploiting CVE-2025-49706 and CVE-2025-49704, with probing linked to CVE-2025-11371, to deploy ransomware, custom backdoors, and BYOVD-based defense evasion. Organizations running exposed SharePoint servers should assume that delay raises the risk of simultaneous actor access, weakened endpoint defenses, and fast progression from initial access to destructive impact.
03
PRIORITY
Update Ubiquiti UniFi OS to the patched release, including UniFi OS Server 5.0.8 where applicable, and prioritize any internet-exposed management instances. CISA says attackers are actively exploiting CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, which can be chained from authentication bypass to command injection for possible unauthenticated remote code execution and rogue admin account creation. Any organization relying on UniFi OS for network administration should verify that no unauthorized administrator accounts were introduced during the exposure window.
04
PRIORITY
Tighten Microsoft 365 phishing defenses around device code flows and train users to treat unsolicited authentication prompts, QR codes, and sign-in requests as hostile unless validated out of band. EvilTokens is reportedly abusing legitimate Microsoft 365 authentication, AI-generated lures, and Cloudflare Workers-hosted landing pages to steal valid access tokens that can enable business email compromise. Organizations with heavy Microsoft 365 dependence should review detections for token theft and suspicious sign-in activity because this tradecraft bypasses simple password-focused defenses by capturing real session access.
05
PRIORITY
Review FortiGate access, administrative activity, and live-traffic exposure immediately, especially on FortiOS SSL-VPN systems. Researchers say the FortiBleed campaign has compromised more than 430,000 FortiGate firewalls by abusing the FortiOS diagnostic packet-sniffing command to harvest credentials from traffic, then using stolen plaintext passwords, tokens, mass scanning, credential stuffing, and brute force to expand access. Organizations operating FortiGate firewalls should treat them as potential credential-collection points and reset exposed credentials if there is any sign that sniffer-based collection occurred.
ROUNDTABLE
Expert Panel Discussion
5 AI experts analyzed this briefing across 3 turns of structured debate
5Agents18Messages24mDuration

Field Signals

Real-time intelligence from X/Twitter
$ scanning feeds_

Sector Intelligence

Cyber Threatcast is generated by an autonomous AI intelligence pipeline. All assessments are algorithmically derived.

Published by halilozturkci.com