CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Attackers turned Cisco Unified Communications Manager flaw CVE-2026-20230 into a live intrusion path within 24 hours of disclosure, using exposed CUCM WebDialer services to drop webshells as CISA moved the bug into KEV and set an urgent federal remediation deadline. The day’s sharpest risk sits at the intersection of speed and scale: Google also patched 124 Android flaws including CVE-2025-48595, which it says is under active targeted exploitation, while multiple phishing and supply-chain campaigns are bypassing the controls many teams still rely on most.
Cisco’s case is especially stark because the path from disclosure to weaponization was so short. Reporting says attackers used automated scripts, Tor exit nodes, reconnaissance through a WSDL endpoint, and an SSRF-to-RCE chain against CUCM WebDialer to deploy staged JSP webshells. Cisco patched the issue on June 3 and warned it was remotely exploitable without authentication; CISA’s KEV listing and June 28 deadline for federal agencies underline that exposed collaboration infrastructure is now a priority target, not routine patch backlog.
Elsewhere, the most consequential campaigns are going after identity and software trust rather than brute-force perimeter access. The FBI says Kali365 abuses Microsoft 365 OAuth device code flows to steal tokens and keep access without passwords, Trend Micro describes TONResolver phishing against Booking.com partner hotels through fake guest complaints, and researchers say Miasma tainted more than 57 npm packages while abusing GitHub Actions and install-time execution to siphon secrets from cloud and vault platforms.
Editorial: Recommended Actions
01
PRIORITY
Patch Cisco Unified Communications Manager immediately for CVE-2026-20230 and urgently identify any internet-exposed CUCM WebDialer instances for containment and review. Cisco said the flaw is remotely exploitable without authentication, CISA has added it to KEV, and reporting says attackers weaponized it within 24 hours to abuse exposed WebDialer services, probe WSDL endpoints, and deploy JSP webshells through SSRF-to-RCE chains. Any organization running CUCM—especially those with exposed WebDialer services—should treat this as an active compromise risk, not a routine patch cycle item.
02
PRIORITY
Prioritize Oracle PeopleSoft exposure review and emergency remediation for CVE-2026-35273, then assess whether sensitive systems tied to PeopleSoft were accessed. NAIC says attackers exploited the PeopleSoft zero-day in a breach linked to ShinyHunters, and reports tie the incident to extortion and a 3.1 TB data leak, with claims that more than 100 organizations were hit in the wider campaign. Any organization running PeopleSoft should assume the flaw is operationally relevant now, especially where the platform touches regulatory, business, or high-value data systems.
03
PRIORITY
Tighten Microsoft 365 monitoring and user guidance around OAuth device code sign-ins, and hunt for suspicious token-based access to Outlook, Teams, and OneDrive. The FBI says Kali365 abuses Microsoft 365 device code authentication to trick users into authorizing access on a legitimate Microsoft login page, letting attackers steal OAuth tokens and bypass password-focused phishing defenses, including MFA tied to password theft. Organizations that rely on Microsoft 365 should treat device-code authorization flows as a live phishing vector that can create persistent account access without stolen passwords.
04
PRIORITY
Audit npm dependencies and GitHub Actions workflows immediately for exposure to the Miasma campaign, and treat affected developer or CI/CD environments as potentially compromised. Researchers say Miasma is actively abusing more than 57 npm packages, compromised maintainer accounts, GitHub Actions, and install-time execution via malicious binding.gyp changes to steal credentials and secrets from cloud and vault platforms. Organizations that consume npm packages or run GitHub Actions should move beyond package removal alone and verify whether secrets, tokens, or build credentials were exposed during installation or pipeline execution.
05
PRIORITY
Warn hotel staff now to reject ZIP “photo” attachments and complaint-themed emails claiming to come through Booking.com workflows, and isolate any Windows endpoint that executed an LNK file from such messages. Trend Micro says attackers are targeting Booking.com partner companies in Japan with fake guest complaints and review requests, using ZIP archives containing malicious Windows shortcut files to install TONResolver, while Microsoft identified related phishing against hotel employees in Europe and Asia. Hospitality organizations should treat reservation, guest-relations, and front-desk inboxes as the front line for this campaign because compromised endpoints can sit in a keepalive loop awaiting follow-on commands.
ROUNDTABLE
Expert Panel Discussion
11 AI experts analyzed this briefing across 3 turns of structured debate
11Agents15Messages31mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_