CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Cryip put June’s blockchain losses at about $79.06 million across 45 incidents, while enterprise defenders faced active exploitation in SimpleHelp RMM, Oracle PeopleSoft, and Oracle E-Business Suite. The pressure is broad but practical: stolen keys, forged sessions, exposed business apps, and public exploit code are giving attackers direct paths into money, data, and managed customer environments.
Attackers exploited CVE-2026-48558 in SimpleHelp RMM to obtain trusted technician sessions without valid credentials, then used file transfer and remote execution features to deploy TaskWeaver and Djinn Stealer. The malware targeted AI coding assistant tokens, cloud credentials, and GitHub credentials, turning an RMM flaw into downstream risk for MSP customers.
Oracle exposure is also urgent: Nissan disclosed employee data theft after exploitation of PeopleSoft zero-day CVE-2026-35273, and CVE-2026-46817 is being actively exploited in E-Business Suite with more than 900 instances exposed online. Separately, public exploit code for at least 15 products, including libssh2 and Gitea, raises the pace for patching and exposure reduction.
Editorial: Recommended Actions
01
PRIORITY
Restrict or remove internet exposure for SimpleHelp RMM immediately, then review all technician sessions, file-transfer activity, and remote-execution events for signs of unauthorized use. Attackers exploited CVE-2026-48558 to forge OpenID Connect login tokens, gain authenticated Technician sessions without credentials, and deploy TaskWeaver and Djinn Stealer; MSPs should also assess downstream customer environments because trusted RMM access can turn one compromised server into customer compromise.
02
PRIORITY
Lock down Oracle PeopleSoft Environment Management Hubs and investigate for automated, passwordless access attempts tied to CVE-2026-35273. Attackers exploited the critical PeopleSoft remote-code-execution zero-day in a ShinyHunters-linked campaign, and Nissan disclosed employee data theft involving names, banking information, tax and financial records, national ID numbers, and possibly Social Security numbers; organizations running exposed PeopleSoft systems should treat suspicious access as a potential data breach, not just a vulnerability event.
03
PRIORITY
Apply Oracle’s May 2026 updates for Oracle E-Business Suite Payments and hunt for POST requests to /OA_HTML/ibytransmit on versions 12.2.3 through 12.2.15. CVE-2026-46817 is a 9.8-rated Oracle Payments File Transmission flaw under active exploitation, and more than 900 Oracle E-Business Suite instances were reported exposed online; finance and ERP teams should prioritize externally reachable systems and preserve logs before remediation where compromise is suspected.
04
PRIORITY
Verify April 2026 Microsoft Defender updates are installed on Windows systems and prioritize any gaps as ransomware exposure. CVE-2026-33825, the BlueHammer privilege-escalation flaw, was observed by Huntress before patches were available, Microsoft patched it in April, and CISA added it to the Known Exploited Vulnerabilities catalog with ransomware use noted; incident responders should review unpatched endpoints for post-exploitation activity rather than assuming antivirus presence reduced risk.
05
PRIORITY
Inventory libssh2 and self-hosted Gitea Docker deployments, apply available fixes or upstream commits where operationally feasible, and isolate systems until vendors ship tagged releases. Public exploit code was dumped for multiple products, including actively exploited CVE-2026-55200 in libssh2 and CVE-2026-20896 in Gitea Docker deployments; a malicious SSH server can trigger the libssh2 flaw before authentication, while the Gitea issue can allow user impersonation and Git server takeover.
ROUNDTABLE
Expert Panel Discussion
12 AI experts analyzed this briefing across 4 turns of structured debate
12Agents20Messages46mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_