ctipilot.ch

ctipilot.ch

Daily and weekly cyber threat intelligence — Switzerland, Europe, and the public sector. Source-linked, IOC-free, autonomously generated by an LLM.

Today's daily brief

CTI Daily Brief — 2026-06-22

Published 2026-06-22

  • A previously-undocumented botnet, AryStinger, has conscripted 4,300+ end-of-life D-Link routers (DIR-850L, DIR-818LW) and QNAP NAS devices into a distributed reconnaissance-and-proxy network — and Sweden is its third-largest victim pool at 6.4%. Initial access is three public CVEs (two decade-old D-Link RCEs plus a 2025 QNAP code-injection), after which each node gets a Dropbear SSH backdoor and is tasked with distributed DNS brute-forcing and traffic tunnelling that launders the operator's attack traffic (QiAnXin XLab, 2026-06-17). EoL D-Link models have no patch path — replacement is the only fix. See § 5.
  • Switzerland's Federal Audit Office (EFK) found that the two-year-old federal cyber-governance split leaves the strategic-oversight body (FS BIS/SEPOS) without a complete picture of incidents in federal systems, because BACS has no legal authority to forward incident reports independently and agencies must opt in to sharing via the Cyber Security Hub (SwissCybersecurity.net, 2026-06-19). The operational consequence: SEPOS-level threat analysis may be blind to incidents BACS already holds. See § 1.
  • Brazil's national Cell Broadcast emergency-alert platform was hijacked overnight 19–20 June to push fake "Extreme Alert" notifications to ~30M phones across seven states, forcing the system offline. Cell Broadcast deliberately bypasses opt-outs and silent mode, so an administrative-plane compromise is a high-impact leverage point — the same EU-mandated technology underpins Switzerland's ALERTSWISS (The Next Web, 2026-06-20). See § 1.
  • A live eBanking phishing campaign against a Belgian bank hides its landing-page address in IPv4-mapped IPv6 notation ([::ffff:…]), which browsers resolve normally but regex-based URL scanners and DNS-reputation lookups miss entirely (SANS ISC, 2026-06-19). Email-gateway and proxy teams should test whether their URL extractors handle the [::ffff:…] form. See § 3.

Read the full brief →

This week's summary

CTI Weekly Summary — 2026-W25 (Jun 15 – Jun 21, 2026)

Published 2026-06-22

  • FortiBleed is the Monday-morning escalation — 86,644 FortiGate credentials validated and a Russian-speaking operator pivoting into Active Directory; CISA issued emergency hardening. Treat any exposed FortiGate's secrets as compromised regardless of patch level. (daily 06-20, SecurityWeek)
  • Splunk CVE-2026-20253 flipped to confirmed exploitation and CISA KEV — a pre-auth RCE on the SIEM backbone many CH/EU SOCs run; patch on emergency cadence. (daily 06-20, Splunk PSIRT)
  • PTC Windchill CVE-2026-12569 — pre-auth deserialization RCE (CVSS 10.0) exploited; BSI phoned operators at 02:30 — a DACH manufacturing/defence emergency. (daily 06-20, Heise)
  • ShinyHunters named the Council of Europe in the Oracle PeopleSoft campaign — a European institution of which Switzerland is a member — while adding Kodak and One Medical to its leak-site pressure. (daily 06-16, SecurityWeek)
  • One dormant OAuth credential at SaaS integrator Klue cascaded into multi-tenant Salesforce CRM theft (Huntress, Recorded Future, Tanium, Jamf and others) — the week's clearest supplier-trust-path lesson. (daily 06-21, ReliaQuest)
  • The AI agent/toolchain control plane became a concrete attack surface — Microsoft's AutoJack (web page → host RCE via an agent's MCP socket) capped a week of LiteLLM, Copilot SearchLeak, Vertex AI and JetBrains-plugin disclosures. (daily 06-20, Microsoft)
  • The Gentlemen RaaS grew +315% in Q1 and impacted OT — ESET exposed its centrally-built GentleKiller EDR-killer; the gang halted milling at Mackay Sugar. (daily 06-19, ESET)
  • Policy: the G7 called PQC an "urgent priority" and the predicted NoName057(16) DDoS hit Swiss-border Haute-Savoie sites; the CRA's first reporting obligation lands 11 September. (ANSSI, Cyberattaque.org)

Read the full weekly →