<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>ctipilot.ch · Weekly (Switzerland, Europe &amp; Public Sector)</title><link>https://ctipilot.ch/</link><atom:link href="https://ctipilot.ch/feed-weekly.xml" rel="self" type="application/rss+xml"/><description>Weekly cyber threat intelligence summaries: multi-day campaigns, sector patterns, policy horizon.</description><language>en</language><lastBuildDate>Sun, 12 Jul 2026 23:56:00 +0000</lastBuildDate><item><title>CTI Weekly Summary · 2026-W28</title><link>https://ctipilot.ch/weekly/2026-W28/</link><guid isPermaLink="true">https://ctipilot.ch/weekly/2026-W28/</guid><pubDate>Sun, 12 Jul 2026 23:56:00 +0000</pubDate><dc:date>2026-07-12T23:56:00Z</dc:date><description><![CDATA[<ul><li><strong>CH/EU government under broad attack this week — Latvia forestry ransomware, Swiss cantonal mailbox compromise, e-gov watering-hole, Ghostwriter phishing.</strong> The constituency&#39;s core sector was hit from several directions in 2026-W28: a ransomware crew breached Latvia&#39;s state forestry operator LVM via a two-year-unpatched service (CERT.LV, an EU/NATO-shared-threat framing); Psychiatrische Dienste Aargau (a Swiss cantonal health authority) had email accounts phished and abused as a spam relay; espionage actors weaponised a citizen-facing e-government complaint portal as a watering hole; Armored Likho hit government and electric-power targets with an AI-generated loader; and UNC1151/Ghostwriter ran real-time 2FA-relay Gmail phishing against officials (CERT Polska). The common thread is not one actor but the breadth of pressure on public-sector identity, exposed services and citizen-facing web. <a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-government-public-admin-targeting/">→</a></li><li><strong>M365 identity attacks converged this week — device-code, AiTM PhaaS, ROPC spray and vishing all bypass MFA/Conditional Access by sidestepping it.</strong> Four independent 2026-W28 disclosures describe the same M365 account-takeover pattern from different angles: Huntress&#39; root-cause comparison of the Railway (device-code) and LSHIY (ROPC spray) campaigns, where 55 of 78 LSHIY-compromised accounts had CA policies requiring MFA that failed on scoping gaps; the Forg365 AiTM phishing-as-a-service kit; and the Helix data-extortion cluster pairing manager-impersonation vishing with device-code phishing. None defeats MFA cryptographically — each exploits an auth flow (device-code, ROPC/legacy, token replay) that a typical Conditional Access policy does not gate. Every M365 tenant should block device-code and ROPC where unused and confirm CA covers all cloud apps and client-app types. <a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-m365-identity-attack-convergence/">→</a></li><li><strong>Exposed enterprise software under active attack this week — ColdFusion (KEV), CitrixBleed 2 → DragonForce, Gitea escalated to actively-exploited.</strong> Three separate internet-facing enterprise products crossed into confirmed exploitation in 2026-W28: Adobe ColdFusion CVE-2026-48282 (one of the 1 July CVSS 10.0 RCEs) was exploited within two hours of public detail and added to CISA KEV; Citrix NetScaler&#39;s CitrixBleed 2 (CVE-2025-5777) was reconstructed by Huntress into a repeatable initial-access-broker kill chain ending in DragonForce ransomware, where stolen session tokens survive patching; and NCSC-CH escalated the Gitea Docker reverse-proxy auth bypass (CVE-2026-20896) to actively exploited. The operational reality: any exposed unpatched instance of these should be treated as compromised, not merely vulnerable — and for CitrixBleed 2, patching alone is insufficient. <a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-exploited-edge-enterprise-software/">→</a></li><li><strong>Joomla third-party-extension file-upload RCE wave — four unauthenticated flaws this week, several exploited as zero-days, KEV within days.</strong> A sustained mySites.guru disclosure wave hit four Joomla third-party extensions across 2026-W28 — SP Page Builder (CVE-2026-48908) and a second page-builder (CVE-2026-56290), Balbooa Forms (CVE-2026-56291), iCagenda (CVE-2026-48939) and RSFiles!/Phoca Download (CVE-2026-57827/57828) — every one an arbitrary-file-upload-to-RCE (CWE-434). Several were exploited in the wild as zero-days before a fix existed and reached CISA KEV within days, with the observed payload planting a hidden Super Administrator account. Any Swiss or European municipal / public-sector Joomla site running these extensions should treat an unpatched instance as a compromise event, not merely a risk, and hunt for web shells and rogue admin accounts. <a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-joomla-file-upload-rce-wave/">→</a></li></ul>]]></description><content:encoded><![CDATA[<div class="tldr"><span class="eyebrow eyebrow--muted">Week at a glance</span><ol><li><span class="num">01</span><span><b>CH/EU government under broad attack this week — Latvia forestry ransomware, Swiss cantonal mailbox compromise, e-gov watering-hole, Ghostwriter phishing.</b> The constituency&#39;s core sector was hit from several directions in 2026-W28: a ransomware crew breached Latvia&#39;s state forestry operator LVM via a two-year-unpatched service (CERT.LV, an EU/NATO-shared-threat framing); Psychiatrische Dienste Aargau (a Swiss cantonal health authority) had email accounts phished and abused as a spam relay; espionage actors weaponised a citizen-facing e-government complaint portal as a watering hole; Armored Likho hit government and electric-power targets with an AI-generated loader; and UNC1151/Ghostwriter ran real-time 2FA-relay Gmail phishing against officials (CERT Polska). The common thread is not one actor but the breadth of pressure on public-sector identity, exposed services and citizen-facing web. <a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-government-public-admin-targeting/">→</a></span></li><li><span class="num">02</span><span><b>M365 identity attacks converged this week — device-code, AiTM PhaaS, ROPC spray and vishing all bypass MFA/Conditional Access by sidestepping it.</b> Four independent 2026-W28 disclosures describe the same M365 account-takeover pattern from different angles: Huntress&#39; root-cause comparison of the Railway (device-code) and LSHIY (ROPC spray) campaigns, where 55 of 78 LSHIY-compromised accounts had CA policies requiring MFA that failed on scoping gaps; the Forg365 AiTM phishing-as-a-service kit; and the Helix data-extortion cluster pairing manager-impersonation vishing with device-code phishing. None defeats MFA cryptographically — each exploits an auth flow (device-code, ROPC/legacy, token replay) that a typical Conditional Access policy does not gate. Every M365 tenant should block device-code and ROPC where unused and confirm CA covers all cloud apps and client-app types. <a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-m365-identity-attack-convergence/">→</a></span></li><li><span class="num">03</span><span><b>Exposed enterprise software under active attack this week — ColdFusion (KEV), CitrixBleed 2 → DragonForce, Gitea escalated to actively-exploited.</b> Three separate internet-facing enterprise products crossed into confirmed exploitation in 2026-W28: Adobe ColdFusion CVE-2026-48282 (one of the 1 July CVSS 10.0 RCEs) was exploited within two hours of public detail and added to CISA KEV; Citrix NetScaler&#39;s CitrixBleed 2 (CVE-2025-5777) was reconstructed by Huntress into a repeatable initial-access-broker kill chain ending in DragonForce ransomware, where stolen session tokens survive patching; and NCSC-CH escalated the Gitea Docker reverse-proxy auth bypass (CVE-2026-20896) to actively exploited. The operational reality: any exposed unpatched instance of these should be treated as compromised, not merely vulnerable — and for CitrixBleed 2, patching alone is insufficient. <a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-exploited-edge-enterprise-software/">→</a></span></li><li><span class="num">04</span><span><b>Joomla third-party-extension file-upload RCE wave — four unauthenticated flaws this week, several exploited as zero-days, KEV within days.</b> A sustained mySites.guru disclosure wave hit four Joomla third-party extensions across 2026-W28 — SP Page Builder (CVE-2026-48908) and a second page-builder (CVE-2026-56290), Balbooa Forms (CVE-2026-56291), iCagenda (CVE-2026-48939) and RSFiles!/Phoca Download (CVE-2026-57827/57828) — every one an arbitrary-file-upload-to-RCE (CWE-434). Several were exploited in the wild as zero-days before a fix existed and reached CISA KEV within days, with the observed payload planting a hidden Super Administrator account. Any Swiss or European municipal / public-sector Joomla site running these extensions should treat an unpatched instance as a compromise event, not merely a risk, and hunt for web shells and rogue admin accounts. <a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-joomla-file-upload-rce-wave/">→</a></span></li></ol></div><nav class="secnav" aria-label="Sections"><a class="secnav-chip" href="#highest-impact-events-what-s-on-fire-if-no-one-acted">Highest-impact events · what&#39;s on fire if no one acted <span class="secnav-n">2</span></a><a class="secnav-chip" href="#multi-day-campaigns-and-chains">Multi-day campaigns and chains <span class="secnav-n">1</span></a><a class="secnav-chip" href="#vulnerability-roll-up">Vulnerability roll-up <span class="secnav-n">1</span></a><a class="secnav-chip" href="#sector-victim-patterns">Sector &amp; victim patterns <span class="secnav-n">2</span></a><a class="secnav-chip" href="#incidents-disclosures-recap">Incidents &amp; disclosures recap <span class="secnav-n">1</span></a><a class="secnav-chip" href="#research-threat-actor-developments">Research &amp; threat-actor developments <span class="secnav-n">3</span></a><a class="secnav-chip" href="#long-running-campaigns-status-update">Long-running campaigns · status update <span class="secnav-n">2</span></a><a class="secnav-chip" href="#policy-regulatory-horizon">Policy &amp; regulatory horizon <span class="secnav-n">2</span></a><a class="secnav-chip" href="#looking-ahead-what-to-watch-next-week">Looking ahead · what to watch next week <span class="secnav-n">1</span></a></nav><div class="sect" id="highest-impact-events-what-s-on-fire-if-no-one-acted"><span class="n">01</span><span class="t">Highest-impact events · what&#39;s on fire if no one acted</span><span class="c">2 items</span></div><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-exploited-edge-enterprise-software" data-tags="vulnerabilities actively-exploited pre-auth rce ransomware cisa-kev" data-regions="switzerland europe global" data-kind="synthesis" data-priority="high" data-discovered="2026-07-12T23:22:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-exploited-edge-enterprise-software"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-exploited-edge-enterprise-software/">Confirmed in-the-wild exploitation of internet-facing enterprise software converged this week — ColdFusion, Citrix NetScaler and Gitea all moved from &#39;at risk&#39; to &#39;under attack&#39;</a></h3><p><strong>If you did nothing this week:</strong> three classes of internet-facing enterprise software you likely have somewhere in the estate moved from theoretical risk to confirmed exploitation. An unpatched, exposed ColdFusion, Citrix NetScaler Gateway or Gitea instance should be handled as an incident, not a maintenance ticket — and for NetScaler, applying the patch does not evict an attacker who already has your session tokens.</p>
<p>The week&#39;s exploitation signal converged on the perimeter. <strong>Adobe ColdFusion</strong> CVE-2026-48282 — one of the six unauthenticated CVSS 10.0 RCEs Adobe patched on 1 July, and exactly the item last week&#39;s outlook flagged as awaiting weaponisation — was confirmed exploited in the wild and added to CISA KEV on 7 July; KEVIntel reported catching exploitation &quot;within under two hours of CVE-2026-48282 public details being released&quot; against its honeypots (<a href="https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-08</a>). <strong>Citrix NetScaler</strong> saw the most operationally consequential development: Huntress reconstructed a mechanically identical intrusion chain across at least six unrelated organisations, run by an initial-access broker (Sophos: STAC3725) that steals pre-auth session tokens via CitrixBleed 2 (CVE-2025-5777) — &quot;sift[ing] through the heap fragments for valid session tokens of someone who is currently logged in&quot; (<a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-10</a>) — then escalating via a registry-symlink privilege-escalation tool to SYSTEM, persisting with ScreenConnect/Zoho Assist, and in the most progressed case deploying DragonForce ransomware. Because the stolen tokens survive patching, remediation requires terminating live sessions as well. Finally, <strong>NCSC-CH</strong> escalated the Gitea Docker reverse-proxy authentication bypass (CVE-2026-20896) — full unauthenticated admin control &quot;via a single custom HTTP header&quot; — to &quot;Actively Exploited, Proof of Concept Available&quot; (<a href="https://security-hub.ncsc.admin.ch/#/posts/12755" target="_blank" rel="noopener noreferrer">NCSC-CH Cyber Security Hub, 2026-07-10</a>). A fourth strand — Langflow&#39;s cross-tenant IDOR (CVE-2026-55255) chained with pre-auth RCE, first exploited 25 June and now KEV-listed (<a href="https://www.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited" target="_blank" rel="noopener noreferrer">Sysdig, 2026-07-08</a>) — reinforces the same lesson: exploitation, not CVSS, is what set this week&#39;s priorities.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">exposure plus a confirmed exploitation record is the trigger, and for token-theft classes (CitrixBleed 2) the post-patch step — session termination and a hunt for broker-stage persistence (ScreenConnect/Zoho Assist installs, registry-symlink LPE artifacts) — is what actually closes the door. <strong>Triage:</strong> for NetScaler, benign session activity originates from expected client IP ranges and device postures; the broker signal is a burst of malformed pre-auth requests to the vulnerable endpoint followed by authenticated actions from a session whose token was never issued to that source, then a remote-support agent install under an anomalous parent.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Within under two hours of CVE-2026-48282 public details being released, KEVIntel captured in-the-wild exploitation within our global honeypot network.</p><figcaption class="entry-cite__attr">KEVIntel, via BleepingComputer</figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">By spraying enough of those requests, an adversary can then sift through the heap fragments for valid session tokens of someone who is currently logged in.</p><figcaption class="entry-cite__attr"><a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Current exploitation status: Actively Exploited, Proof of Concept Available</p><figcaption class="entry-cite__attr"><a href="https://security-hub.ncsc.admin.ch/#/posts/12755" target="_blank" rel="noopener noreferrer">NCSC-CH Cyber Security Hub</a></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/cve-2026-48282-adobe-coldfusion-actively-exploited-kev/">2026-07-08/cve-2026-48282-adobe-coldfusion-actively-exploited-kev</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/">2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/gitea-cve-2026-20896-ncsc-ch-actively-exploited-update/">2026-07-10/gitea-cve-2026-20896-ncsc-ch-actively-exploited-update</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/cve-2026-55255-langflow-idor-kev-chained-with-rce/">2026-07-08/cve-2026-55255-langflow-idor-kev-chained-with-rce</a></p><div class="prov"><span>synthesis</span><span>12 Jul 23:22Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-exploited-edge-enterprise-software/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12755" target="_blank" rel="noopener noreferrer">NCSC-CH Cyber Security Hub</a> · <a href="https://www.sysdig.com/blog/understanding-langflow-cve-2026-55255-and-why-higher-cvss-vulnerabilities-arent-always-the-most-exploited" target="_blank" rel="noopener noreferrer">Sysdig Threat Research Team</a></div></article><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-joomla-file-upload-rce-wave" data-tags="vulnerabilities actively-exploited pre-auth rce zero-day cisa-kev" data-regions="switzerland europe global" data-kind="synthesis" data-priority="high" data-discovered="2026-07-12T23:20:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-joomla-file-upload-rce-wave"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-joomla-file-upload-rce-wave/">A researcher-driven Joomla extension file-upload wave produced four unauthenticated RCE disclosures this week — several exploited as zero-days before a patch existed</a></h3><p><strong>If you did nothing this week:</strong> any internet-facing Joomla site your constituency runs with SP Page Builder, Balbooa Forms, iCagenda, RSFiles! or Phoca Download installed should now be treated as potentially compromised — several of these flaws were exploited in the wild before a patch shipped, and the observed payload gives the attacker a hidden Joomla super-admin.</p>
<p>Across 2026-W28 the specialist Joomla-security researcher mySites.guru disclosed the same bug class — CWE-434 arbitrary file upload leading to remote code execution — in four separate third-party extensions in quick succession, and CISA moved several onto the Known Exploited Vulnerabilities catalog within days. The mechanism is consistent: an upload handler that fails to enforce a server-side extension allow-list, does not block <code>.php</code>, and does not verify the declared content type, letting an attacker write an executable script into a web-reachable directory. In SP Page Builder the exploited path was <code>index.php?option=com_sppagebuilder&amp;task=asset.uploadCustomIcon</code>, driven by an HTTP POST (<a href="https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-08</a>); the researcher observed that &quot;the payload plants a hidden Super Administrator account, usually with an @secure.local email&quot; (<a href="https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/" target="_blank" rel="noopener noreferrer">mySites.guru, 2026-07-08</a>). Balbooa Forms (CVE-2026-56291) was likewise found under live exploitation before any fix existed — &quot;it was already being exploited in the wild when we found it, before any patch existed&quot; (<a href="https://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/" target="_blank" rel="noopener noreferrer">mySites.guru, 2026-07-09</a>) — and iCagenda (CVE-2026-48939) reached KEV as an unauthenticated file-upload-to-RCE (<a href="https://mysites.guru/blog/icagenda-zero-day-file-upload-rce/" target="_blank" rel="noopener noreferrer">mySites.guru, 2026-07-10</a>). The week closed with two more from the same wave: RSFiles! (CVE-2026-57827, unauthenticated, CVSS 4.0 10.0, fixed 1.17.12) and Phoca Download (CVE-2026-57828, member-authenticated allow-list bypass, fixed 6.1.3), with no confirmed exploitation of that pair yet (<a href="https://mysites.guru/blog/rsfiles-unauthenticated-file-upload-rce/" target="_blank" rel="noopener noreferrer">mySites.guru, 2026-07-11</a>).</p>
<p><strong>Why this is the week&#39;s operational reality for the constituency:</strong> Joomla is disproportionately common on cantonal, communal and small-agency public-sector sites across Switzerland and the EU, and the ecosystem&#39;s risk lives in its third-party extensions, not the core. A wave of unauthenticated, pre-auth-exploited RCEs against exactly that surface, several with a public exploitation record and a self-installing super-admin payload, is a patch-and-hunt priority the normal monthly cadence does not cover.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">treat the extension inventory — not the Joomla core version — as the exposure surface; update or remove every affected component now, and because at least three of these were exploited pre-patch, assume any lagging instance may already carry a web shell or rogue admin. <strong>Triage:</strong> a legitimate Joomla file-upload writes into a media/asset path an authenticated editor triggered; the wave&#39;s signal is a <code>.php</code> (or double-extension) file appearing in an extension&#39;s upload/download folder from an unauthenticated request, frequently followed by the creation of a Super Administrator account with a synthetic domain such as <code>@secure.local</code>.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">CVE-2026-48908, on the other hand, is said to have been exploited as a zero-day to upload a PHP file by means of an HTTP POST request to the &#39;index.php?option=com_sppagebuilder&amp;task=asset.uploadCustomIcon&#39; endpoint.</p><figcaption class="entry-cite__attr"><a href="https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Already exploited in the wild. The payload plants a hidden Super Administrator account, usually with an @secure.local email.</p><p class="entry-cite__quote">This was a zero-day: it was already being exploited in the wild when we found it, before any patch existed, and those attacks are still going on now against sites that have not updated.</p><figcaption class="entry-cite__attr"><a href="https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/" target="_blank" rel="noopener noreferrer">mySites.guru</a></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/joomla-page-builder-cve-2026-48908-56290-kev-zerodays/">2026-07-08/joomla-page-builder-cve-2026-48908-56290-kev-zerodays</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/cve-2026-56291-balbooa-forms-joomla-unauth-file-upload-rce/">2026-07-09/cve-2026-56291-balbooa-forms-joomla-unauth-file-upload-rce</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/cve-2026-48939-icagenda-joomla-unauth-file-upload-rce-kev/">2026-07-10/cve-2026-48939-icagenda-joomla-unauth-file-upload-rce-kev</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/joomla-rsfiles-phoca-file-upload-rce-cve-2026-57827-57828/">2026-07-11/joomla-rsfiles-phoca-file-upload-rce-cve-2026-57827-57828</a></p><div class="prov"><span>synthesis</span><span>12 Jul 23:20Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-joomla-file-upload-rce-wave/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://mysites.guru/blog/sp-page-builder-zero-day-uploadcustomicon-rce/" target="_blank" rel="noopener noreferrer">mySites.guru</a> · <a href="https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article><div class="sect" id="multi-day-campaigns-and-chains"><span class="n">02</span><span class="t">Multi-day campaigns and chains</span><span class="c">1 item</span></div><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-m365-identity-attack-convergence" data-tags="identity phishing cloud auth-bypass data-breach" data-regions="switzerland europe global" data-kind="synthesis" data-priority="high" data-discovered="2026-07-12T23:24:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-m365-identity-attack-convergence"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-m365-identity-attack-convergence/">Microsoft 365 account-takeover tradecraft converged this week on auth flows Conditional Access rarely covers — device-code, AiTM, ROPC and manager-impersonation vishing all beat MFA without breaking it</a></h3><p>Four separate 2026-W28 disclosures describe one problem: Microsoft 365 account takeover is increasingly achieved not by defeating multi-factor authentication but by choosing an authentication path that Conditional Access commonly fails to gate. Huntress&#39; comparative root-cause analysis of two campaigns made the mechanism explicit — &quot;device code phishing is effective because it doesn&#39;t try to beat MFA. It sidesteps it,&quot; and in the ROPC-based LSHIY campaign &quot;of the 78 compromised accounts, 55 had active Conditional Access policies requiring MFA&quot; that still failed, because legacy/ROPC authentication through the <code>/token</code> endpoint never reaches the authorization endpoint where CA is enforced (<a href="https://www.huntress.com/blog/conditional-access-misconfigurations" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-10</a>). The same week, ZeroBEC documented <strong>Forg365</strong>, a Telegram-distributed adversary-in-the-middle phishing-as-a-service kit purpose-built to relay M365 auth and steal session cookies (<a href="https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas" target="_blank" rel="noopener noreferrer">ZeroBEC, 2026-07-10</a>), and ReliaQuest profiled the <strong>Helix</strong> data-extortion cluster pairing manager-impersonation vishing with device-code phishing before SharePoint exfiltration (<a href="https://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem" target="_blank" rel="noopener noreferrer">ReliaQuest, 2026-07-10</a>). Read together with the week&#39;s ShinyHunters/Odido vishing attribution, the through-line is a maturing, commoditised identity-attack economy targeting the same tenant surface.</p>
<p><strong>Why this is a cross-day pattern, not four items:</strong> device-code phishing, AiTM cookie theft, ROPC spraying and impersonation vishing are distinct techniques, but they exploit the <em>same</em> structural gap — a Conditional Access posture that assumes MFA coverage it does not actually enforce across every flow, client-app type and cloud app. A tenant that hardened against one of these this week is not hardened against the others.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">treat Conditional Access coverage completeness — not the presence of an MFA requirement — as the control to audit; block device-code and ROPC/legacy auth for populations that do not need them, and verify no cloud app or client-app type is exempt. <strong>Triage:</strong> a legitimate device-code grant comes from a genuine input-constrained device enrolment the user initiated; the attack signature is a device-code grant to an unmanaged/unexpected device shortly after a phishing lure, or successful authentication via ROPC/<code>/token</code> against Azure CLI from an account and location with no history of CLI use.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Device code phishing is effective because it doesn&#39;t try to beat MFA. It sidesteps it.</p><p class="entry-cite__quote">Of the 78 compromised accounts, 55 had active Conditional Access policies requiring MFA.</p><figcaption class="entry-cite__attr"><a href="https://www.huntress.com/blog/conditional-access-misconfigurations" target="_blank" rel="noopener noreferrer">Huntress</a></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns/">2026-07-10/m365-conditional-access-gaps-railway-lshiy-campaigns</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie/">2026-07-10/forg365-m365-phaas-aitm-devicecode-forgcookie</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil/">2026-07-10/helix-data-extortion-devicecode-vishing-sharepoint-exfil</a></p><div class="prov"><span>synthesis</span><span>12 Jul 23:24Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-m365-identity-attack-convergence/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.huntress.com/blog/conditional-access-misconfigurations" target="_blank" rel="noopener noreferrer">Huntress</a> · <a href="https://zerobec.com/blog/inside-forg365-telegram-distributed-sneaky2fa-style-phaas" target="_blank" rel="noopener noreferrer">ZeroBEC</a> · <a href="https://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem" target="_blank" rel="noopener noreferrer">ReliaQuest</a></div></article><div class="sect" id="vulnerability-roll-up"><span class="n">03</span><span class="t">Vulnerability roll-up</span><span class="c">1 item</span></div><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-vuln-status-rollup" data-tags="vulnerabilities actively-exploited cisa-kev rce priv-esc ot-ics" data-regions="switzerland europe global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-07-12T23:26:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-vuln-status-rollup"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-vuln-status-rollup/">Vulnerability status roll-up — 2026-W28: what moved into exploitation, what reached KEV, and what to patch out-of-band</a></h3><p>This roll-up consolidates the 2026-W28 vulnerabilities that cross the out-of-band-action bar — actively exploited, at imminent mass exploitation, or otherwise demanding a response the routine monthly cycle does not give. Per-CVE facts, CVSS, and affected/fixed versions live in the linked operational entries; this entry is the status trajectory a reader uses to sequence the week&#39;s patching.</p>
<p><strong>Confirmed exploited / on CISA KEV this week.</strong> <em>Adobe ColdFusion</em> CVE-2026-48282 (one of the 1 July CVSS 10.0 unauthenticated RCEs) — exploited within two hours of public detail, KEV-listed 7 July (<a href="https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-08</a>). <em>Citrix NetScaler</em> CitrixBleed 2 CVE-2025-5777 — weaponised into a repeatable initial-access-broker kill chain ending in DragonForce ransomware; patch plus session termination required. <em>Gitea</em> CVE-2026-20896 — NCSC-CH escalated to &quot;Actively Exploited, Proof of Concept Available&quot; (<a href="https://security-hub.ncsc.admin.ch/#/posts/12755" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-07-10</a>). <em>Langflow</em> CVE-2026-55255 — cross-tenant IDOR chained with pre-auth RCE, first exploited 25 June, now KEV. <em>Joomla extension file-upload wave</em> — CVE-2026-48908 / 56290 / 56291 / 48939 exploited as zero-days (see the dedicated top-story), CVE-2026-57827/57828 patched without confirmed exploitation yet.</p>
<p><strong>Urgency raised by public exploit or full mechanics, no confirmed ITW use.</strong> <em>GhostLock</em> CVE-2026-43499 — Linux kernel rtmutex use-after-free with a public ~97%-reliable local-privilege-escalation exploit. <em>Windows HTTP.sys</em> CVE-2026-47291 (pre-auth RCE, CVSS 9.8) — ZDI published full exploitation mechanics for the June Patch Tuesday flaw, collapsing the reverse-engineering barrier. <em>Linux KVM/x86 &#39;Januscape&#39;</em> CVE-2026-53359 — shadow-MMU use-after-free enabling guest-to-host VM escape, relevant to multi-tenant virtualisation. <em>BeyondTrust Remote Support / Privileged Remote Access</em> — the CVE-2026-40138 pre-auth bypass cluster on a remote-access product class that is itself a high-value target.</p>
<p><strong>OT / critical-infrastructure note.</strong> <em>Siemens SICAM 8</em> grid RTUs (A8000/EGS/S8000) — a firmware-signature-validation bypass (CVE-2026-54798-801) on devices deployed in European energy grids; slow patch cycles make network isolation and OT-segment monitoring the near-term control. <em>Progress MOVEit Transfer</em> — pre-auth SFTP DoS (CVE-2026-10699) plus admin scope-bypass fixes, notable given MOVEit&#39;s history as a mass-exfiltration target.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">sequence by exploitation evidence, then exposure — the KEV/exploited set above is this week&#39;s out-of-band queue; the public-exploit set is next in line before it is weaponised; the OT items are isolate-and-monitor where an immediate patch is impractical.</div></aside><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/cve-2026-48282-adobe-coldfusion-actively-exploited-kev/">2026-07-08/cve-2026-48282-adobe-coldfusion-actively-exploited-kev</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725/">2026-07-10/citrixbleed-2-dragonforce-iab-kill-chain-stac3725</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/gitea-cve-2026-20896-ncsc-ch-actively-exploited-update/">2026-07-10/gitea-cve-2026-20896-ncsc-ch-actively-exploited-update</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/cve-2026-55255-langflow-idor-kev-chained-with-rce/">2026-07-08/cve-2026-55255-langflow-idor-kev-chained-with-rce</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/ghostlock-cve-2026-43499-linux-kernel-rtmutex-uaf-lpe/">2026-07-08/ghostlock-cve-2026-43499-linux-kernel-rtmutex-uaf-lpe</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics/">2026-07-11/cve-2026-47291-httpsys-zdi-exploitation-mechanics</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape/">2026-07-09/cve-2026-53359-januscape-kvm-x86-guest-to-host-vm-escape</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/beyondtrust-rs-pra-preauth-bypass-cve-2026-40138-cluster/">2026-07-08/beyondtrust-rs-pra-preauth-bypass-cve-2026-40138-cluster</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass/">2026-07-10/siemens-sicam-8-ssa-229470-firmware-signing-bypass</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903/">2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903</a></p><div class="prov"><span>vulnerability</span><span>12 Jul 23:26Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-vuln-status-rollup/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/max-severity-adobe-coldfusion-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12755" target="_blank" rel="noopener noreferrer">NCSC-CH Cyber Security Hub</a></div></article><div class="sect" id="sector-victim-patterns"><span class="n">04</span><span class="t">Sector &amp; victim patterns</span><span class="c">2 items</span></div><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-government-public-admin-targeting" data-tags="data-breach espionage ransomware phishing" data-regions="switzerland europe" data-kind="synthesis" data-priority="high" data-discovered="2026-07-12T23:30:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-government-public-admin-targeting"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-government-public-admin-targeting/">Government and public administration across Switzerland and Europe took a broad spread of attacks this week — ransomware, espionage watering-holes, AI-tooled APTs and credential-phishing</a></h3><p>Government and public administration — the profiled constituency&#39;s core — absorbed an unusually broad spread of activity in 2026-W28, notable less for any single incident than for how many different attack classes landed on the sector in one week.</p>
<p>On the <strong>ransomware</strong> front, CERT.LV disclosed that a crew breached Latvijas Valsts Meži (LVM), Latvia&#39;s state forestry operator, through a service left unpatched for roughly two years, and framed it explicitly as an EU/NATO-shared-threat matter for a state-owned critical operator (<a href="https://cert.lv/lv/2026/06/as-latvijas-valsts-mezi-kiberdrosibas-incidents-aktuala-informacija" target="_blank" rel="noopener noreferrer">CERT.LV, 2026-06</a>). In Switzerland, <strong>Psychiatrische Dienste Aargau (PDAG)</strong>, a cantonal health authority, had staff email accounts compromised via phishing and abused to relay spam — a low-sophistication but high-frequency pattern against public-sector mailboxes (<a href="https://www.swisscybersecurity.net/news/2026-07-09/psychiatrische-dienste-aargau-werden-opfer-eines-phishing-angriffs" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net, 2026-07-09</a>). On the <strong>espionage</strong> axis, SentinelLabs documented converging China- and India-nexus operations weaponising a citizen-facing e-government complaint portal as a watering hole with a CMS implant (<a href="https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/" target="_blank" rel="noopener noreferrer">SentinelLabs, 2026-07-10</a>); Kaspersky profiled <strong>Armored Likho</strong> hitting government and electric-power targets with an AI-generated loader and the BusySnake stealer (<a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-07-11</a>); and CERT Polska tracked <strong>UNC1151/Ghostwriter</strong> moving to Gmail with real-time 2FA-relay phishing against officials (<a href="https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/" target="_blank" rel="noopener noreferrer">CERT Polska, 2026-06</a>).</p>
<p><strong>Why this is a sector pattern for the constituency:</strong> two of the five strands carry a direct home-region or EU-critical-operator nexus (a Swiss cantonal authority and a Latvian state operator); the e-government watering-hole targeted a Pakistani law-enforcement programme (EU-funded but with no direct European victim nexus) and is carried for its transferable technique, while the remaining two are actors whose targeting profile — government and energy — matches the constituency. The exposed surfaces recur: unpatched internet-facing services, public-sector email identity, and citizen-facing web applications.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the week&#39;s public-sector lesson is coverage of the unglamorous basics — an authoritative patch SLA for internet-facing services (the LVM two-year gap is the cautionary case), phishing-resistant MFA on staff mail to break both spam-relay abuse and 2FA-relay phishing, and integrity monitoring on citizen-facing CMS platforms that make natural watering holes. <strong>Triage:</strong> a compromised public-sector mailbox used as a relay shows a sudden outbound-volume spike and sends to external recipients with no prior correspondence; a watering-hole CMS implant shows unexpected file writes to web-root and template/plugin directories outside a deployment window.</div></aside><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat/">2026-07-10/cert-lv-lvm-olpha-ransomware-eu-nato-shared-threat</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/pdag-aargau-email-account-compromise-spam-relay/">2026-07-09/pdag-aargau-email-account-compromise-spam-relay</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/e-government-portal-watering-hole-cms-implant-espionage/">2026-07-10/e-government-portal-watering-hole-cms-implant-espionage</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer/">2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing/">2026-07-09/unc1151-ghostwriter-gmail-realtime-2fa-phishing</a></p><div class="prov"><span>synthesis</span><span>12 Jul 23:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-government-public-admin-targeting/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cert.lv/lv/2026/06/as-latvijas-valsts-mezi-kiberdrosibas-incidents-aktuala-informacija" target="_blank" rel="noopener noreferrer">CERT.LV</a> · <a href="https://www.swisscybersecurity.net/news/2026-07-09/psychiatrische-dienste-aargau-werden-opfer-eines-phishing-angriffs" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net</a> · <a href="https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/" target="_blank" rel="noopener noreferrer">SentinelLabs</a> · <a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist</a> · <a href="https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/" target="_blank" rel="noopener noreferrer">CERT Polska</a></div></article><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-healthcare-targeting" data-tags="data-breach ransomware phishing insider-threat" data-regions="switzerland europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-07-12T23:32:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-healthcare-targeting"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-healthcare-targeting/">Healthcare across Switzerland and the UK saw ransomware confirmation, mailbox compromise and an insider-access clampdown this week</a></h3><p>Healthcare surfaced three ways this week, and the value of reading them together is that they cover the sector&#39;s external, identity and internal threat surfaces in a single window.</p>
<p>Externally, <strong>Groupe 3R</strong> — the Réseau Radiologique Romand, a Western-Swiss radiology network — confirmed in its own forensic report that the Akira ransomware operation was responsible for the intrusion that had twice disrupted it, and that stolen data had been published on Akira&#39;s darknet leak site (<a href="https://www.swisscybersecurity.net/news/2026-05-07/cyberangriff-legt-westschweizer-radiologie-netzwerk-erneut-lahm" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net, 2026-05-07</a>). On the <strong>identity</strong> surface, <strong>Psychiatrische Dienste Aargau (PDAG)</strong>, a cantonal psychiatric authority, had email accounts phished and abused as a spam relay (<a href="https://www.swisscybersecurity.net/news/2026-07-09/psychiatrische-dienste-aargau-werden-opfer-eines-phishing-angriffs" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net, 2026-07-09</a>). Internally, <strong>NHS England</strong> issued new controls after staff were found inappropriately accessing high-profile patients&#39; records, tying repeat &quot;snooping&quot; to dismissal and potential prosecution (<a href="https://www.england.nhs.uk/2026/07/snooping-staff-face-sack-prison-inappropriate-access-patient-data/" target="_blank" rel="noopener noreferrer">NHS England, 2026-07-11</a>).</p>
<p><strong>Why this belongs to the constituency&#39;s healthcare lens:</strong> two of the three are Swiss (a Romand radiology provider and an Aargau cantonal authority), and the third is a transferable governance lesson for any large healthcare data controller. Healthcare&#39;s threat model is not just ransomware on clinical systems — it is equally the mailbox identity that attackers abuse and the legitimate-but-excessive internal access that no perimeter control addresses.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">healthcare defenders should read the week as a reminder that record confidentiality fails from three directions — external encryption/leak (Akira), compromised staff identity (PDAG), and authorised-but-inappropriate access (NHS) — and that the last requires access-logging and least-privilege on clinical record systems, not network controls. <strong>Triage:</strong> insider misuse looks like legitimate authenticated access, so the discriminator is behavioural — a clinician account reading records outside its care relationship, department or normal caseload volume — surfaced from record-access audit logs, not endpoint or network telemetry.</div></aside><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/groupe-3r-akira-forensic-confirmation-darknet-publication/">2026-07-09/groupe-3r-akira-forensic-confirmation-darknet-publication</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/nhs-england-insider-patient-record-access-controls/">2026-07-11/nhs-england-insider-patient-record-access-controls</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/pdag-aargau-email-account-compromise-spam-relay/">2026-07-09/pdag-aargau-email-account-compromise-spam-relay</a></p><div class="prov"><span>synthesis</span><span>12 Jul 23:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-healthcare-targeting/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.swisscybersecurity.net/news/2026-05-07/cyberangriff-legt-westschweizer-radiologie-netzwerk-erneut-lahm" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net</a> · <a href="https://www.england.nhs.uk/2026/07/snooping-staff-face-sack-prison-inappropriate-access-patient-data/" target="_blank" rel="noopener noreferrer">NHS England</a></div></article><div class="sect" id="incidents-disclosures-recap"><span class="n">05</span><span class="t">Incidents &amp; disclosures recap</span><span class="c">1 item</span></div><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-third-party-cloud-account-exposure" data-tags="data-breach supply-chain cloud organized-crime" data-regions="switzerland europe global" data-kind="incident" data-priority="notable" data-discovered="2026-07-12T23:34:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-third-party-cloud-account-exposure"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-third-party-cloud-account-exposure/">This week&#39;s disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim</a></h3><p>Read as a set, the week&#39;s confirmed incidents point away from the classic perimeter-RCE story and toward exposure that lives in someone else&#39;s account, platform or supply chain.</p>
<p>The <strong>third-party / vendor</strong> strand: Accenture confirmed a data-theft incident after the handle &quot;888&quot; advertised roughly 35 GB of internal source code (<a href="https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-08</a>); Deutsche Bank disclosed a third-party-vendor incident after the &quot;Unsafe&quot; ransomware group posted claims (<a href="https://www.computing.co.uk/news/2026/security/deutsche-bank-probes-supplier-cyber-incident-after-ransomware-gang-claims-breach" target="_blank" rel="noopener noreferrer">Computing, 2026-07-09</a>); and KDDI named a zero-day in third-party email-platform software as the root cause of a breach affecting about 12 million people (<a href="https://www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-09</a>). The <strong>cloud-account</strong> strand: Nayax, a Bank-of-Lithuania-licensed EEA payment institution, disclosed a cloud-account incident (claimed by &quot;The Syndicate&quot;) in its own SEC Form 6-K (<a href="https://www.sec.gov/Archives/edgar/data/1901279/000117891326003440/zk2635660.htm" target="_blank" rel="noopener noreferrer">Nayax, 2026-07-09</a>); ShinyHunters&#39; Odido (Netherlands telecom) breach drew a Dutch-national-involvement assessment from police voice analysis (<a href="https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html" target="_blank" rel="noopener noreferrer">Politie, 2026-07-08</a>); and Nextcloud GmbH&#39;s own hosting infrastructure exposed roughly 367,000 internal records through a misconfigured public Elasticsearch (<a href="https://cybernews.com/security/nextcloud-cloud-provider-data-leak/" target="_blank" rel="noopener noreferrer">Cybernews, 2026-07-10</a>).</p>
<p><strong>Why the pattern matters for the constituency:</strong> several victims are directly relevant classes — an EEA-licensed payment institution, an EU telecom, a European cloud vendor — and the shared root cause is exactly the exposure a Swiss/EU public-sector or CI organisation inherits through its suppliers and cloud tenancy. The transferable lesson is that a mature internal patch posture does not cover a vendor&#39;s zero-day, a supplier&#39;s compromised account, or a misconfigured datastore in your own cloud footprint.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">treat third-party and cloud-account exposure as first-class incident surface — maintain a supplier inventory with incident-notification clauses, apply the same internet-exposure and misconfiguration scanning to cloud-hosted datastores as to on-prem, and monitor cloud-account sign-in anomalies with the same rigour as endpoint alerts. <strong>Triage:</strong> a supplier-origin compromise typically first surfaces as anomalous data access via a legitimate integration or service account rather than a malware alert — the discriminator is access volume and pattern on that account against its baseline, and exfiltration to an unexpected destination class.</div></aside><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim/">2026-07-08/accenture-confirms-data-theft-888-azure-devops-claim</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident/">2026-07-09/deutsche-bank-unsafe-ransomware-third-party-vendor-incident</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update/">2026-07-09/kddi-isp-email-breach-zero-day-root-cause-update</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/nayax-cloud-account-incident-the-syndicate-claim/">2026-07-09/nayax-cloud-account-incident-the-syndicate-claim</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution/">2026-07-10/odido-shinyhunters-vishing-dutch-police-attribution</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/nextcloud-gmbh-elasticsearch-exposure-msb-nrw/">2026-07-10/nextcloud-gmbh-elasticsearch-exposure-msb-nrw</a></p><div class="prov"><span>incident</span><span>12 Jul 23:34Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-third-party-cloud-account-exposure/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-after-hacker-offers-stolen-data-for-sale/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.sec.gov/Archives/edgar/data/1901279/000117891326003440/zk2635660.htm" target="_blank" rel="noopener noreferrer">Nayax Ltd. — SEC Form 6-K</a> · <a href="https://www.politie.nl/nieuws/2026/juli/8/onderzoek-naar-hack-odido-wijst-op-mogelijke-betrokkenheid-nederlanders.html" target="_blank" rel="noopener noreferrer">Politie (Dutch National Police)</a> · <a href="https://www.computing.co.uk/news/2026/security/deutsche-bank-probes-supplier-cyber-incident-after-ransomware-gang-claims-breach" target="_blank" rel="noopener noreferrer">Computing (UK)</a> · <a href="https://cybernews.com/security/nextcloud-cloud-provider-data-leak/" target="_blank" rel="noopener noreferrer">Cybernews</a></div></article><div class="sect" id="research-threat-actor-developments"><span class="n">06</span><span class="t">Research &amp; threat-actor developments</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-threat-actor-developments" data-tags="espionage phishing" data-regions="global europe" data-kind="research" data-priority="notable" data-discovered="2026-07-12T23:43:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="weekly-w28-threat-actor-developments"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-threat-actor-developments/">Threat-actor developments this week: Group-IB reframes Scattered Spider as a decentralised collective, and China- and Iran-nexus edge/ORB tradecraft advances</a></h3><p>The week&#39;s actor reporting split between a model-changing reframing of a well-known financially-motivated collective and a set of state-nexus tradecraft advances.</p>
<p><strong>Scattered Spider — a model change, not an incident.</strong> Group-IB argues the actor &quot;cannot be considered or analyzed as a single organized &#39;group&#39; with its own hierarchy or organigram [but is] more accurately described as a decentralised cybercrime collective&quot; of independent subclusters, typically 3-5 people, unified by shared tradecraft and community learning rather than command structure, and states &quot;we can consider 0ktapus as a subcluster of Scattered Spider&quot; — explicitly mapping Microsoft&#39;s Octo Tempest, Mandiant&#39;s UNC3944 and Palo Alto&#39;s Muddled Libra as overlapping labels for subclusters of the same movement (<a href="https://www.group-ib.com/blog/connecting-scattered-spider/" target="_blank" rel="noopener noreferrer">Group-IB, 2026-07-07</a>). The documented playbook is squarely relevant to the constituency&#39;s help desks: vishing/smishing with Okta/Microsoft/Citrix/Google SSO-lookalike pages staged minutes before a call, SIM-swaps via coercion or carrier-staff social engineering, and help-desk impersonation using OSINT from already-compromised systems, monetised through BlackCat/ALPHV and DragonForce ransomware. The practical consequence Group-IB draws: because resilience comes from decentralisation, individual arrests do not blunt the collective, so defenders should treat each attributed intrusion as one small ad-hoc crew rather than evidence of a persistent central adversary.</p>
<p><strong>State-nexus edge and C2 tradecraft.</strong> Talos detailed China-nexus <strong>UAT-7810</strong> expanding its operational relay-box (ORB) network with the LONGLEASH/DOGLEASH/JARLEASH suite (<a href="https://blog.talosintelligence.com/uat-7810/" target="_blank" rel="noopener noreferrer">Cisco Talos, 2026-07-08</a>); Proofpoint&#39;s <strong>UNK_MassTraction</strong>, a suspected China-aligned actor, exploited Roundcube webmail as an edge device (<a href="https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation" target="_blank" rel="noopener noreferrer">Proofpoint, 2026-07-09</a>); and Check Point exposed Iran MOIS-linked <strong>Cavern Manticore</strong>&#39;s modular .NET command-and-control framework with layered anti-analysis (<a href="https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/" target="_blank" rel="noopener noreferrer">Check Point Research, 2026-07-09</a>).</p>
<p><strong>Why grouped here:</strong> these are actor-model and capability developments — the lens the weekly owns — rather than new operational incidents. Scattered Spider&#39;s decentralisation and the state actors&#39; edge/ORB focus both change how a SOC should scope attribution and where to look (help-desk identity workflows; internet-facing webmail and edge appliances as relay infrastructure).</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">operationalise the Scattered Spider model by hardening the help-desk identity-verification workflow (out-of-band verification for password/MFA resets, no reset on voice alone) rather than hunting a single signature set; for the state-nexus edge tradecraft, treat internet-facing webmail (Roundcube) and edge appliances as compromise-and-relay targets subject to the same egress monitoring as any C2 channel. <strong>Triage:</strong> Scattered Spider social engineering surfaces at the help desk as a caller pressing for an urgent MFA/password reset with convincing but externally-sourced personal detail; ORB/edge abuse surfaces as an appliance initiating outbound sessions to unrelated third parties it has no functional reason to contact.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Scattered Spider cannot be considered or analyzed as a single organized &#39;group&#39; with its own hierarchy or organigram. Instead, it can be more accurately described as a decentralised cybercrime collective.</p><p class="entry-cite__quote">we can consider 0ktapus as a subcluster of Scattered Spider</p><figcaption class="entry-cite__attr"><a href="https://www.group-ib.com/blog/connecting-scattered-spider/" target="_blank" rel="noopener noreferrer">Group-IB</a></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash/">2026-07-08/talos-uat-7810-china-nexus-orb-network-longleash</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/unk-masstraction-roundcube-edge-exploitation/">2026-07-09/unk-masstraction-roundcube-edge-exploitation</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/cavern-manticore-iran-mois-modular-net-c2-anti-analysis/">2026-07-09/cavern-manticore-iran-mois-modular-net-c2-anti-analysis</a></p><div class="prov"><span>research</span><span>12 Jul 23:43Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-threat-actor-developments/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.group-ib.com/blog/connecting-scattered-spider/" target="_blank" rel="noopener noreferrer">Group-IB</a> · <a href="https://blog.talosintelligence.com/uat-7810/" target="_blank" rel="noopener noreferrer">Cisco Talos</a> · <a href="https://www.proofpoint.com/us/blog/threat-insight/one-email-closer-edge-unkmasstraction-physics-exploitation" target="_blank" rel="noopener noreferrer">Proofpoint Threat Research</a> · <a href="https://research.checkpoint.com/2026/cavern-manticore-exposing-iran-linked-modular-c2-framework/" target="_blank" rel="noopener noreferrer">Check Point Research</a></div></article><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-identity-trust-primitive-forgery" data-tags="identity supply-chain" data-regions="global europe" data-kind="research" data-priority="notable" data-discovered="2026-07-12T23:40:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-identity-trust-primitive-forgery"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-identity-trust-primitive-forgery/">Trust-primitive forgery was a research theme this week: recovering live ADFS signing keys, and minting a second &#39;Verified&#39; GitHub commit</a></h3><p>Two of the week&#39;s research findings share an underappreciated theme: they forge a trust primitive that downstream systems and humans treat as authoritative, rather than exploiting a memory-corruption bug.</p>
<p>The heavier of the two, for the constituency, is Mandiant/GTIG&#39;s <strong>ADFS token-signing-key recovery</strong>. ADFS stores its certificate private keys under Machine DPAPI, so any SYSTEM-level process on the ADFS host can recover them independently of the live service or LSASS; when <code>AutoCertificateRollover</code> is disabled and an admin rotates a signing certificate manually without a matching WID update, the database retains a &quot;ghost&quot; record while the real signing key stays live in the machine key store. With that key, an attacker forges arbitrary SAML assertions to impersonate any federated user — Global Administrators included — against every SAML-federated app including Microsoft 365 and Entra ID, &quot;bypassing multifactor authentication (MFA), conditional access, and all identity-based controls,&quot; and deliberately avoids the LSASS/live-ADFS surfaces defenders usually watch (<a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant, 2026-07-09</a>). The detectable side-effect is Event ID 385 (certificate-rollover mismatch), and Mandiant&#39;s guidance is to treat ADFS as Tier-0, move to HSM-backed keys, validate rotations with <code>Set-AdfsCertificate</code>, and SACL-audit the MachineKeys directory (Event ID 4663). The second finding, <strong>Git commit-signature malleability</strong>, lets an attacker produce a second commit with a different hash that still renders GitHub&#39;s &quot;Verified&quot; badge — collapsing the assumption that a verified-signed commit uniquely identifies its content (<a href="https://thehackernews.com/2026/07/github-verified-commits-can-be.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-09</a>).</p>
<p><strong>Why this belongs in the week&#39;s research lens:</strong> both extend a running arc — after last week&#39;s Keycloak JWT-forgery and OAuth-abuse research, this week&#39;s items give the on-premises-AD equivalent (ADFS) and a code-supply-chain equivalent (signed commits), each with a concrete detection surface the earlier work lacked.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">for identity teams, ADFS belongs in the Tier-0 monitoring and hardening tier alongside domain controllers — the actionable, low-cost step is enabling SACL auditing on the MachineKeys directory and alerting on Event IDs 385 and 4663, since the technique is invisible to LSASS-focused tooling. For build-pipeline owners, a &quot;Verified&quot; badge is no longer sufficient provenance — pin and verify commit hashes, not just signature status. <strong>Triage:</strong> ADFS key theft produces no failed logon and no LSASS access; the honest signals are the certificate-rollover mismatch event and any non-service SYSTEM process reading the MachineKeys path, distinguished from legitimate ADFS operation by process lineage.</div></aside><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery/">2026-07-09/mandiant-adfs-machine-dpapi-golden-saml-key-recovery</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/git-signature-malleability-github-verified-commit-ghost-twin/">2026-07-09/git-signature-malleability-github-verified-commit-ghost-twin</a></p><div class="prov"><span>research</span><span>12 Jul 23:40Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-identity-trust-primitive-forgery/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/recovering-active-adfs-signing-keys-machine-dpapi" target="_blank" rel="noopener noreferrer">Mandiant (Google Cloud / GTIG)</a> · <a href="https://thehackernews.com/2026/07/github-verified-commits-can-be.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-ai-operationalized" data-tags="ai-abuse cloud phishing supply-chain" data-regions="global europe" data-kind="research" data-priority="notable" data-discovered="2026-07-12T23:38:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="weekly-w28-ai-operationalized"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-ai-operationalized/">AI as operator, not target: this week&#39;s research showed adversaries using AI to run attacks faster, evade AI defences, and generate tooling</a></h3><p>Last week&#39;s weekly framed AI as having &quot;crossed from attack target to attack operator.&quot; This week&#39;s research does not repeat that thesis — it fills it in with concrete, independent data points that sharpen what defenders should change.</p>
<p>The clearest is <strong>operational tempo</strong>. Sygnia&#39;s incident responders documented a single actor going from an internet-facing-app foothold to broad compromise of AWS, CI/CD and source control in roughly 72 hours using no novel malware and no zero-day — every technique long-tracked, but chained and parallelised at a speed Sygnia attributes to AI/agentic assistance (four distinct IAM access keys used from one source in a single observed second) (<a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia, 2026-07-08</a>). The second is <strong>AI as attack surface turned back on defenders</strong>: the &quot;Friendly Fire&quot; brief showed prompt injection hijacking defensive AI code-review agents into remote code execution (<a href="https://ainowinstitute.org/publications/friendly-fire-exploit-brief" target="_blank" rel="noopener noreferrer">AI Now Institute, 2026-07-11</a>), and PraisonAI&#39;s agentic framework carried unsandboxed-LLM-code-execution and tool-call-RCE CVEs (<a href="https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2xv2-w8cq-5gxw" target="_blank" rel="noopener noreferrer">PraisonAI GHSA, 2026-07-11</a>). The third is <strong>AI in tooling and evasion</strong>: Kaspersky&#39;s Armored Likho APT shipped an AI-generated loader with the BusySnake stealer (<a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-07-11</a>), and SANS documented &quot;comment stuffing&quot; — padding HTML phishing attachments to dilute or exhaust AI/NLP email scanners (<a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS ISC, 2026-07-10</a>). This week&#39;s ESET Threat Report H1 2026, covered separately, independently records the first Android malware using generative AI at runtime.</p>
<p><strong>Why this is a strategic-shift item, not a re-list:</strong> each finding is a distinct new-this-week research publication, and together they change a defender obligation rather than restate awareness — when access-to-impact compresses to hours and defensive AI itself becomes an exploitation target, detection can no longer wait for full visibility.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">for cloud estates, tune detections toward early, partial-signal indicators that survive tempo compression — simultaneous multi-key use from one source, anomalous IAM-user/access-key creation velocity, and short-window RDS query spikes across many databases (Sygnia&#39;s hunt set) — and treat any AI agent with tool-execution or code-review privileges as an execution surface that needs sandboxing and untrusted-input isolation, not a passive assistant. <strong>Triage:</strong> AI-assisted operations still emit ordinary cloud-audit telemetry; the discriminator is rate and concurrency — human operators do not use four separate credentials in the same second, and defensive-agent RCE surfaces as the agent process spawning an interpreter or network egress it never makes during normal review.</div></aside><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h/">2026-07-09/sygnia-ai-orchestrated-aws-cloud-intrusion-72h</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/friendly-fire-prompt-injection-rce-defensive-ai-agents/">2026-07-11/friendly-fire-prompt-injection-rce-defensive-ai-agents</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer/">2026-07-11/armored-likho-busysnake-ai-generated-loader-python-stealer</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion/">2026-07-10/comment-stuffing-html-phishing-ai-email-scanner-evasion</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-11/praisonai-agentic-framework-three-cves-code-exec-rce-ddli/">2026-07-11/praisonai-agentic-framework-three-cves-code-exec-rce-ddli</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-09/eset-threat-report-h1-2026/">2026-07-09/eset-threat-report-h1-2026</a></p><div class="prov"><span>research</span><span>12 Jul 23:38Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-ai-operationalized/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/" target="_blank" rel="noopener noreferrer">Sygnia</a> · <a href="https://ainowinstitute.org/publications/friendly-fire-exploit-brief" target="_blank" rel="noopener noreferrer">AI Now Institute</a> · <a href="https://securelist.com/tr/armored-likho-apt-with-busysnake-stealer/120292/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist</a> · <a href="https://isc.sans.edu/diary/33144" target="_blank" rel="noopener noreferrer">SANS Internet Storm Center</a> · <a href="https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2xv2-w8cq-5gxw" target="_blank" rel="noopener noreferrer">PraisonAI (GitHub Security Advisory)</a></div></article><div class="sect" id="long-running-campaigns-status-update"><span class="n">07</span><span class="t">Long-running campaigns · status update</span><span class="c">2 items</span></div><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-the-gentlemen-status" data-tags="ransomware" data-regions="global europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-07-12T23:46:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="weekly-w28-the-gentlemen-status"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-the-gentlemen-status/">The Gentlemen (Storm-2697) status update — Unit 42&#39;s full profile: 580 victims, a Qilin-affiliate lineage, and a suspected EDR-disable zero-day</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered 2026-06-29/the-gentlemen <span class="mono muted">(2026-06-29)</span></p><p>Palo Alto Unit 42 published the first full technical profile of The Gentlemen (Microsoft: Storm-2697; also Phantom Mantis), consolidating and extending the picture this pipeline built from ESET&#39;s GentleKiller research and the FortiBleed nexus. The delta worth carrying: Unit 42 counts 580 claimed victims across 77 countries through 3 July 2026 (103 in manufacturing) and a &quot;slightly more than 6x&quot; victim increase from H2 2025 to H1 2026, and assesses the ~20 operators &quot;likely morphed from a private entity into a RaaS model on or about September 2025,&quot; previously operating as &quot;ArmCorp,&quot; an affiliate of Qilin, now offering an &quot;unprecedented 90% payout&quot; versus the typical 70-80% (<a href="https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-07-10</a>). Two operationally relevant additions: the initial-access set now explicitly names Erlang/OTP SSH-server and Windows SMB-client flaws alongside the already-tracked FortiOS/FortiProxy edge path, and Unit 42 cites Expel describing a <em>suspected zero-day the group uses specifically to disable target EDR agents</em> — distinct from the BYOVD-based GentleKiller framework and not previously in this pipeline&#39;s coverage. The Go/C dual-language encryptor and Curve25519/XChaCha20 per-file key scheme are unchanged.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the actionable change since June is the broadened initial-access surface — organisations exposing Erlang/OTP SSH or reachable SMB now share the same entry-point risk previously framed mainly around FortiGate edge, so prioritise those alongside the Fortinet patch posture; the reported EDR-disable zero-day means tamper-protection and EDR-health monitoring (agent-stop/uninstall alerting) are worth confirming as a hunt, though the specific mechanism awaits Expel&#39;s own write-up.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The operators (roughly 20 of them) likely morphed from a private entity into a RaaS model on or about September 2025. While traditional RaaS models typically offer affiliates a 70% to 80% cut of paid ransoms, The Gentlemen offer an unprecedented 90% payout.</p><p class="entry-cite__quote">When comparing the last six months of 2025 to the first six months of 2026, the number of victims claimed by The Gentlemen increased by slightly more than 6x.</p><figcaption class="entry-cite__attr"><a href="https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/" target="_blank" rel="noopener noreferrer">Palo Alto Networks Unit 42</a></figcaption></figure></div><div class="prov"><span>synthesis</span><span>12 Jul 23:46Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-the-gentlemen-status/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/" target="_blank" rel="noopener noreferrer">Palo Alto Networks Unit 42</a></div></article><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-npm-supply-chain-wave" data-tags="supply-chain data-breach infostealer cloud" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-07-12T23:48:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w28-npm-supply-chain-wave"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-npm-supply-chain-wave/">npm supply-chain wave status: jscrambler package compromised this week, extending the install-hook-evasion pattern seen in the injectivelabs SDK</a></h3><p>The software-supply-chain pressure on the npm ecosystem that this pipeline has tracked as a sustained wave continued this week, with a fresh compromise that sharpens the evasion trend rather than repeating it.</p>
<p>On 2026-07-11 the <strong>jscrambler</strong> npm package — a code-protection/obfuscation build tool — was compromised via what Socket assesses as a stolen publishing credential or compromised build pipeline: a malicious v8.14.0 pushed directly to npm, bypassing the project&#39;s normal release flow, adding an undocumented <code>preinstall</code> hook that unpacks and detached-spawns a platform-specific Rust infostealer on <code>npm install</code> alone. The stealer targets cloud metadata-endpoint credentials, Kubernetes configs, browser secrets, crypto-wallet seeds, AI coding-tool configs and messaging tokens. The notable evolution: over roughly three hours the actor pushed four more malicious releases and, &quot;starting with 8.18.0 the install hook is gone entirely—the identical dropper is instead injected as a self-executing function at the top of dist/index.js&quot; — moving execution out of the very hook that install-script scanners watch (<a href="https://socket.dev/blog/jscrambler-supply-chain-attack" target="_blank" rel="noopener noreferrer">Socket, 2026-07-11</a>). Socket &quot;detected the compromised package 6 minutes after publication&quot;; v8.22.0 is confirmed clean (<a href="https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-07-11</a>). This is the same install-hook-evasion arc as this week&#39;s injectivelabs SDK compromise, though — unlike the Shai-Hulud worm strain — jscrambler has not been shown to self-propagate to other maintainers.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the wave&#39;s shared lesson for any org with a CI/CD JS build chain is that install-hook scanning is now routinely bypassed, so provenance controls (pinned versions/lockfile integrity, short-lived scoped CI credentials, egress control from build runners) matter more than install-time script inspection; a runner that installed an affected jscrambler build should be treated as a credential-exposure event. <strong>Triage:</strong> a compromised build package shows up as a build/CI process making unexpected outbound connections or reading cloud-metadata and secret paths during <code>install</code>/<code>build</code> — behaviour a legitimate obfuscation tool has no reason to exhibit.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Starting with 8.18.0 the install hook is gone entirely—the identical dropper is instead injected as a self-executing function at the top of dist/index.js.</p><p class="entry-cite__quote">Socket detected the compromised package 6 minutes after publication.</p><figcaption class="entry-cite__attr"><a href="https://socket.dev/blog/jscrambler-supply-chain-attack" target="_blank" rel="noopener noreferrer">Socket</a></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-10/injectivelabs-npm-runtime-keyhook-supply-chain-evasion/">2026-07-10/injectivelabs-npm-runtime-keyhook-supply-chain-evasion</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-29/npm-supply-chain-worms-a-sustained-wave-across-the-week/">2026-06-29/npm-supply-chain-worms-a-sustained-wave-across-the-week</a></p><div class="prov"><span>synthesis</span><span>12 Jul 23:48Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-npm-supply-chain-wave/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://socket.dev/blog/jscrambler-supply-chain-attack" target="_blank" rel="noopener noreferrer">Socket</a> · <a href="https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article><div class="sect" id="policy-regulatory-horizon"><span class="n">08</span><span class="t">Policy &amp; regulatory horizon</span><span class="c">2 items</span></div><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-finma-post-quantum-guidance" data-tags="law-enforcement" data-regions="switzerland europe" data-kind="policy" data-priority="notable" data-discovered="2026-07-12T23:54:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="weekly-w28-finma-post-quantum-guidance"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-finma-post-quantum-guidance/">FINMA sets post-quantum crypto expectations for the Swiss financial sector — Aufsichtsmitteilung 05/2026 flags &#39;harvest now, decrypt later&#39; and a missing migration roadmap</a></h3><p>FINMA published <strong>Aufsichtsmitteilung (supervisory communication) 05/2026</strong> on 9 July 2026, presenting the results of a November 2025–January 2026 survey of 60 Swiss financial institutions on cryptographically-relevant quantum computing (CRQC) risk. Its core finding: institutions are aware of the threat but &quot;meist fehlt aber eine klare Roadmap und eine ausreichend vorausschauende Planung für die Migration zu quantensicherer Verschlüsselung&quot; — most lack a clear roadmap and sufficiently forward-looking planning for the migration to quantum-safe encryption (<a href="https://www.finma.ch/news/2026/07/20260709-mm-am-05-26/" target="_blank" rel="noopener noreferrer">FINMA, 2026-07-09</a>). FINMA explicitly names <strong>&quot;harvest now, decrypt later&quot;</strong> — capture-and-store-for-future-decryption of today&#39;s encrypted traffic and data — as the operative near-term threat model, and sets, under existing operational-risk-and-resilience supervisory expectations rather than a new binding circular, that institutions should produce a PQC migration strategy and roadmap, run an institution-specific risk analysis, &quot;die Erstellung eines kryptographischen Inventars&quot; (build a cryptographic inventory), adopt crypto-agility, and extend the planning to outsourced service providers. No mandatory deadline accompanies the communication (<a href="https://www.swissinfo.ch/eng/various/finma-to-banks-further-measures-are-needed-to-tackle-quantum-computers/91726878" target="_blank" rel="noopener noreferrer">swissinfo.ch, 2026-07-10</a>).</p>
<p><strong>Why this belongs in the strategic view:</strong> it is the home financial-sector regulator setting a direction of travel that a Swiss/EU public-sector or CI reader will encounter next as a compliance expectation, and it reframes post-quantum readiness as a near-term data-protection issue, not a distant cryptographic curiosity — because the &quot;harvest now, decrypt later&quot; risk accrues from <em>today&#39;s</em> captured traffic regardless of when a CRQC actually arrives.</p>
<aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the defensible near-term action for finance-sector (and CI) readers is to start the cryptographic inventory now — enumerate which systems, protocols (TLS/VPN/at-rest) and applications use which algorithms and key lengths — because that inventory is the prerequisite for any migration and the only way to reason about HNDL exposure; watch for whether FINMA converts this into a binding circular and whether NCSC-CH or ENISA issue parallel public-sector PQC guidance.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Die Institute sind sich der Cyberrisiken von kryptografisch relevanten Quantum Computern bewusst. Meist fehlt aber eine klare Roadmap und eine ausreichend vorausschauende Planung für die Migration zu quantensicherer Verschlüsselung.</p><p class="entry-cite__quote">Dazu gehört eine klare Strategie und Roadmap für die Migration zu quantensicheren Verschlüsselungen, eine institutsspezifische Risikoanalyse, die Erstellung eines kryptographischen Inventars, der Schutz kritischer Daten vor &#39;harvest now, decrypt later&#39; Angriffen.</p><figcaption class="entry-cite__attr">FINMA</figcaption></figure></div><div class="prov"><span>policy</span><span>12 Jul 23:54Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-finma-post-quantum-guidance/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.finma.ch/news/2026/07/20260709-mm-am-05-26/" target="_blank" rel="noopener noreferrer">FINMA (Swiss Financial Market Supervisory Authority)</a> · <a href="https://www.swissinfo.ch/eng/various/finma-to-banks-further-measures-are-needed-to-tackle-quantum-computers/91726878" target="_blank" rel="noopener noreferrer">SWI swissinfo.ch</a></div></article><article class="finding entry-card" data-entry-id="2026-07-12/weekly-w28-netherlands-nis2-in-force" data-tags="law-enforcement" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-07-12T23:52:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 1: Confirmed"><span class="k">NATO</span>A1</span></div><h3 class="f-h" id="weekly-w28-netherlands-nis2-in-force"><a href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/">Netherlands NIS2 transposition confirmed: the Senate passed the Cyberbeveiligingswet on 7 July, fixing entry into force at 15 August 2026</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered 2026-07-05/weekly-w27-netherlands-nis2-slip <span class="mono muted">(2026-07-05)</span></p><p>the Dutch NIS2 transposition status this pipeline tracked as &quot;slipped past its 1 July target, Senate vote set for 7 July&quot; has resolved. On 7 July 2026 the Eerste Kamer (First Chamber) passed both the <strong>Cyberbeveiligingswet</strong> (Cbw, the NIS2 transposition) and the companion <strong>Wet weerbaarheid kritieke entiteiten</strong> (Wwke, the CER-directive transposition) — the Tweede Kamer had passed them on 15 April — and &quot;de wetten treden op 15 augustus 2026 in werking&quot; (&quot;the laws enter into force on 15 August 2026&quot;) (<a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl, 2026-07-07</a>). The parliamentary vote record confirms broad cross-party support (<a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer, 2026-07-07</a>). The Cbw covers roughly 8,000 organisations across 18 designated essential/important sectors and imposes a cybersecurity duty of care (including supply-chain risk management), mandatory registration in the NCSC entity register, significant-incident reporting to the relevant CSIRT, and board-level accountability with director training (<a href="https://www.ncsc.nl/nieuws/de-cyberbeveiligingswet-in-laatste-fase-van-vaststelling" target="_blank" rel="noopener noreferrer">NCSC-NL</a>).</p>
<p><strong>Why this matters to the constituency:</strong> beyond direct applicability to any covered Dutch entity, this is a concrete datapoint for the deployment&#39;s standing EU NIS2-transposition watch — a member state moving from indefinite slip to a fixed enforcement date. For Swiss-domiciled organisations with Dutch subsidiaries, NL-incorporated critical suppliers, or cross-border NIS2-equivalent reporting relationships, 15 August 2026 is the operative clock, five weeks out from this brief. The next checkpoint is confirmation the NCSC-NL entity register is live and accepting registrations ahead of the date.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">De wetten treden op 15 augustus 2026 in werking.</p><figcaption class="entry-cite__attr"><a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl (Dutch national government)</a></figcaption></figure></div><div class="prov"><span>policy</span><span>12 Jul 23:52Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl (Dutch national government)</a> · <a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal</a> · <a href="https://www.ncsc.nl/nieuws/de-cyberbeveiligingswet-in-laatste-fase-van-vaststelling" target="_blank" rel="noopener noreferrer">NCSC-NL</a></div></article><div class="sect" id="looking-ahead-what-to-watch-next-week"><span class="n">09</span><span class="t">Looking ahead · what to watch next week</span><span class="c">1 item</span></div><article class="finding entry-card" data-entry-id="2026-07-12/looking-ahead-2026-w28" data-tags="vulnerabilities law-enforcement ransomware" data-regions="switzerland europe global" data-kind="outlook" data-priority="notable" data-discovered="2026-07-12T23:56:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="looking-ahead-2026-w28"><a href="https://ctipilot.ch/entries/2026-07-12/looking-ahead-2026-w28/">Looking ahead — 2026-W28</a></h3><p>Items already in motion for the coming weeks — each with a dated source or an in-week entry, none a prediction:</p>
<ul><li><strong>EU regulatory clocks.</strong> The Dutch NIS2 <strong>Cyberbeveiligingswet</strong> enters into force <strong>15 August 2026</strong> — now a fixed date after the 7 July Senate passage (<a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl, 2026-07-07</a>). The <strong>EU Cyber Resilience Act</strong> vulnerability/incident-reporting obligation lands <strong>11 September 2026</strong>, roughly 60 days out and previously covered in this store — the reporting-platform readiness is the item to watch next.</li><li><strong>FINMA post-quantum guidance may harden.</strong> FINMA&#39;s Aufsichtsmitteilung 05/2026 is supervisory expectation-setting, not yet a binding circular; the open question is whether it converts into a Rundschreiben revision (<a href="https://www.finma.ch/news/2026/07/20260709-mm-am-05-26/" target="_blank" rel="noopener noreferrer">FINMA, 2026-07-09</a>).</li><li><strong>Joomla file-upload wave — the newest members await exploitation.</strong> RSFiles! and Phoca Download are patched but not yet exploited, whereas earlier members of the same CWE-434 wave reached CISA KEV within days (<a href="https://mysites.guru/blog/rsfiles-unauthenticated-file-upload-rce/" target="_blank" rel="noopener noreferrer">mySites.guru, 2026-07-11</a>) — treat these as likely-imminent-KEV, not resolved.</li><li><strong>The Gentlemen EDR-disable zero-day.</strong> Unit 42 references an Expel analysis of a suspected zero-day the group uses to disable EDR, distinct from the GentleKiller BYOVD framework; that write-up had not published at the time of Unit 42&#39;s report (<a href="https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-07-10</a>).</li><li><strong>CitrixBleed 2 broker activity continues.</strong> Huntress&#39; STAC3725 reconstruction shows an initial-access broker actively weaponising CVE-2025-5777; organisations that patched but did not terminate live sessions remain exposed to token replay and downstream DragonForce deployment (<a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress, 2026-07-10</a>).</li></ul><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-netherlands-nis2-in-force/">2026-07-12/weekly-w28-netherlands-nis2-in-force</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-finma-post-quantum-guidance/">2026-07-12/weekly-w28-finma-post-quantum-guidance</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-joomla-file-upload-rce-wave/">2026-07-12/weekly-w28-joomla-file-upload-rce-wave</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-the-gentlemen-status/">2026-07-12/weekly-w28-the-gentlemen-status</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-12/weekly-w28-exploited-edge-enterprise-software/">2026-07-12/weekly-w28-exploited-edge-enterprise-software</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-29/eu-cyber-resilience-act-75-days-to-the-11-september-vulnerab/">2026-06-29/eu-cyber-resilience-act-75-days-to-the-11-september-vulnerab</a></p><div class="prov"><span>outlook</span><span>12 Jul 23:56Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-12/looking-ahead-2026-w28/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/07/07/cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten-vanaf-15-augustus-2026-van-kracht" target="_blank" rel="noopener noreferrer">Rijksoverheid.nl (Dutch national government)</a> · <a href="https://www.finma.ch/news/2026/07/20260709-mm-am-05-26/" target="_blank" rel="noopener noreferrer">FINMA</a> · <a href="https://mysites.guru/blog/rsfiles-unauthenticated-file-upload-rce/" target="_blank" rel="noopener noreferrer">mySites.guru</a> · <a href="https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/" target="_blank" rel="noopener noreferrer">Palo Alto Networks Unit 42</a> · <a href="https://www.huntress.com/blog/citrixbleed-2-dragonforce-ransomware" target="_blank" rel="noopener noreferrer">Huntress</a></div></article><details class="verif"><summary class="vh">About this weekly<span class="verif-count">1 run</span><svg class="verif-chev" viewBox="0 0 24 24" width="12" height="12" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" aria-hidden="true"><path d="M6 9l6 6 6-6"></path></svg></summary><div class="verif-body"><div class="run-note" data-run-id="2026-07-12T2309Z-weekly"><h3 class="run-note__head"><span class="mono">2026-07-12T2309Z-weekly</span> <span class="muted">· weekly · Claude Opus 4.8 · 15 entries published</span></h3><div class="run-note__body"><h1 id="weekly-strategic-run-2026-w28-2026-07-06-2026-07-12">Weekly strategic run — 2026-W28 (2026-07-06 – 2026-07-12)</h1>
<h2 id="att-ck-pin-freshness">ATT&amp;CK pin freshness</h2>
<p><code>tools/attack_data.py --check</code>: up to date — local v19.1 == upstream latest v19.1. No update required this run. Two operational-entry technique ids composed this week were mapped to their v19 survivors after the pin check (T1562.001 → T1685 &quot;Disable or Modify Tools&quot;; T1656 → T1684.001 &quot;Impersonation&quot;).</p>
<h2 id="week-in-review-phase-1">Week in review (Phase 1)</h2>
<p>57 operational entries across the ISO week (07-08: 11, 07-09: 21, 07-10: 16, 07-11: 9; 07-06/07-07/07-12 quiet), 13 high-priority, no critical. Working lists persisted to <code>work/&lt;run-id&gt;/week-review.json</code>. Duplicate-week guard: prior <code>-weekly</code> record (2026-07-05) covered W27; W28 not previously covered — cleared.</p>
<h2 id="strategic-output-15-entries">Strategic output (15 entries)</h2>
<ul><li><strong>top-stories (2):</strong> Joomla third-party-extension file-upload RCE wave (on-fire, CH/EU public-sector, several exploited zero-days + KEV); confirmed ITW exploitation of exposed enterprise/edge software (ColdFusion KEV, CitrixBleed 2 → DragonForce IAB, Gitea escalated by NCSC-CH).</li><li><strong>multi-day (1):</strong> M365 identity-attack convergence — device-code / AiTM PhaaS / ROPC spray / manager-impersonation vishing all sidestepping MFA + Conditional Access.</li><li><strong>vuln-rollup (1):</strong> W28 CVE status trajectory (exploited/KEV set + public-exploit set + OT note); <code>cves: []</code> by design — every CVE fully sourced in its referenced operational entry, so the roll-up avoids the cross-run CVE-dedup FAIL.</li><li><strong>sector-patterns (2):</strong> government &amp; public administration (CH/EU) targeting cluster (high); healthcare (CH nexus).</li><li><strong>incidents-recap (1):</strong> third-party / cloud-account / vendor exposure drove the week&#39;s disclosures.</li><li><strong>research (3):</strong> AI operationalised (from target to operator, deepening); identity &amp; trust-primitive forgery (ADFS Machine DPAPI key recovery + Git signature malleability); threat-actor developments (Scattered Spider reclustering + China/Iran state-nexus edge/ORB/C2 tradecraft).</li><li><strong>long-running (2):</strong> The Gentlemen (Storm-2697) status update (update_of W26); npm supply-chain wave status (jscrambler + injectivelabs).</li><li><strong>policy (2):</strong> Netherlands NIS2 Senate passage → 15 Aug 2026 in force (update_of W27 slip story); FINMA post-quantum crypto guidance AM 05/2026.</li><li><strong>looking-ahead (1):</strong> 2026-W28 outlook — items already in motion.</li></ul>
<p>Priority calibration: <code>high</code> reserved for the four genuinely week-defining items (Joomla wave, exploited edge/enterprise, M365 identity convergence, CH/EU government targeting); no <code>critical</code> — no single stop-and-act weekly item this week, bar unchanged.</p>
<h2 id="verification-coverage-notes">Verification &amp; coverage notes</h2>
<ul><li><strong>Weekly dedup (replaces PD-8).</strong> Dedup ran against W27 (2026-07-05) and W26 (2026-06-29) strategic entries. Items already consolidated returned only as fresh deltas: Netherlands NIS2 as <code>update_of</code> the W27 slip entry (Senate now passed, hard date fixed); The Gentlemen as <code>update_of</code> the W26 long-running entry (Unit 42 full profile). The AI-as-operator arc (W27 multi-day) returns only as new-this-week specific research (Sygnia, Friendly Fire, Armored Likho, PraisonAI, comment-stuffing), not a re-list. W1 found no qualifying new movement on ShinyHunters/UNC6240, FortiBleed, DragonForce/CitrixBleed (beyond dailies) or Operation Endgame — checked, not padded.</li><li><strong>Already-operational, referenced not re-summarised.</strong> W1 surfaced the Mandiant ADFS and Sygnia AWS items as fresh, but both were already published operationally on 07-09; they are synthesised into the research entries by reference (with new lens), never re-summarised. The ESET Threat Report H1 2026 (07-09 annual-report) is referenced once, not re-summarised.</li><li><strong>Single-source items.</strong> The Scattered Spider reclustering rests on a single primary (Group-IB) with no independent second source yet — carried as <code>single-source</code>, attributed to Group-IB as an analytical model, not settled fact. The Gentlemen status delta is single-source (Unit 42); the cited Expel EDR-disable zero-day is a third-party claim relayed by Unit 42, not independently confirmed (flagged in the entry and the outlook).</li><li><strong>Coverage gaps.</strong> <code>jina</code> universal-reader (tools/fetch_source.py jina) returned HTTP 402 &quot;JINA_API_KEY balance exhausted&quot; on every call across BOTH sub-agents this run — a system-wide outage, not a per-source failure. Every source whose recipe leans on the jina fallback rung (e.g. coe.int, cisa-directives direct-403 hosts) was degraded to direct-fetch/WebSearch only. W2 covered the affected policy questions via WebSearch with no material item lost; Council of Europe Second Additional Protocol status unchanged (2 of 5 ratifications). W1 listed recordedfuture-insikt (JS-shell landing page, needs a bridge/RSS recipe) and sekoia (301 → sekoia.com/blog, url needs updating) as reachable-but-degraded — deferred to a daily run rather than edited this run to avoid sources.json churn during the jina outage. <strong>Operator action: the jina API key needs a top-up or rotation (https://jina.ai/api-dashboard/) — until then, every jina-fallback source is degraded across all routines.</strong></li><li><strong>Source health.</strong> <code>tools/source_health.py</code> probed 157/157 sources (95 ok, 56 bridge-ok, 3 bridge-blocked). Three UNSOLVED <code>needs-demote</code> flags — <code>ccn-cert-es</code>, <code>reliaquest</code>, <code>mysites-guru</code> — are all attributable to the same jina-402 outage above, not to dead recipes: <code>mysites.guru</code> and <code>reliaquest</code> both fetched successfully as <em>primary</em> sources in this week&#39;s daily entries (the Joomla wave and Helix entries cite them), so their content is demonstrably reachable and the failure is the jina fallback rung being balance-exhausted this run. Demoting healthy sources on a transient key-balance outage would violate the standing &quot;a transport/anti-bot block never demotes&quot; rule, so <strong>no demotion was applied</strong>; the operator-side jina key top-up clears all three. <code>sources_changed: []</code>.</li><li><code>check_run.py</code> <code>--pre-verify</code> and the Phase 5.7 verifier loop results are recorded in the verification block above once run.</li></ul></div></div></div></details>]]></content:encoded></item><item><title>CTI Weekly Summary · 2026-W27</title><link>https://ctipilot.ch/weekly/2026-W27/</link><guid isPermaLink="true">https://ctipilot.ch/weekly/2026-W27/</guid><pubDate>Sun, 05 Jul 2026 23:43:00 +0000</pubDate><dc:date>2026-07-05T23:43:00Z</dc:date><category>CVE-2025-67038</category><category>CVE-2026-10735</category><category>CVE-2026-11800</category><category>CVE-2026-12569</category><category>CVE-2026-20230</category><category>CVE-2026-20245</category><category>CVE-2026-34908</category><category>CVE-2026-34909</category><description><![CDATA[<ul><li><strong>Public-administration targeting this week — Canton Zürich leak claim, Pegasus-infected MEP, DHS HSIN breach.</strong> Three separate government-targeting events landed this week with direct Swiss/EU relevance: MedusaLocker listed the Canton of Zürich&#39;s Baudirektion (bd.zh.ch) on its leak site (unconfirmed); Citizen Lab forensically confirmed Pegasus twice infected a European Parliament PEGA-committee MEP via the zero-click PWNYOURHOME chain; and DHS confirmed a breach of its Homeland Security Information Network. The common thread is not a shared CVE but the target class — public institutions attacked through leak-site extortion, mercenary mobile spyware, and cross-org collaboration-platform trust boundaries. <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-government-targeting-ch-eu/">→</a></li><li><strong>Vuln status roll-up 2026-W27 — exploited, KEV-listed, working-exploit, and weaponisation-likely items.</strong> The week&#39;s vulnerability status at a glance for a public-sector estate: newly exploited/KEV (SimpleHelp CVE-2026-48558, Oracle EBS CVE-2026-46817, SharePoint CVE-2026-45659, Kemp LoadMaster CVE-2026-8037); working-exploit or PoC (DirtyClone Linux LPE CVE-2026-43503, libssh2 CVE-2026-55200, Citrix NetScaler CVE-2026-8451); and weaponisation-likely-but-not-yet-exploited (six CVSS 10.0 Adobe ColdFusion RCEs, Control Web Panel CVE-2026-57517, Coolify CVE-2026-34038). <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-vuln-status-rollup/">→</a></li><li><strong>Edge/VPN appliances: three pre-auth flaws in one week — Citrix NetScaler, WatchGuard Firebox, Kemp LoadMaster.</strong> Three internet-facing edge appliances disclosed pre-authentication memory-safety flaws across the week: Citrix NetScaler CVE-2026-8451 (CitrixBleed-lineage SAML overread, public susceptibility tool), WatchGuard Firebox CVE-2026-13368 (IKEv2 use-after-free RCE, CVSS 9.2), and Progress Kemp LoadMaster CVE-2026-8037 (uninitialized-heap pre-auth RCE, CVSS 9.8) — the last already seeing exploitation attempts the day its PoC dropped. The pattern, not any single CVE, is the signal: pre-auth edge RCE reliably attracts fast-follow mass exploitation. <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-edge-vpn-pre-auth-rce-cluster/">→</a></li><li><strong>Two internet-facing Oracle enterprise product lines under active exploitation this week — EBS RCE + PeopleSoft.</strong> Oracle E-Business Suite CVE-2026-46817 (pre-auth RCE in the Payments File Transmission servlet, CVSS 9.8) saw its first confirmed in-the-wild exploitation this week, landing while the separate ShinyHunters Oracle PeopleSoft campaign (CVE-2026-35273) kept acquiring named victims. The operational reality for a public-sector or higher-education estate: treat every internet-reachable Oracle application tier — EBS, PeopleSoft, and their web front ends — as a priority patch-and-isolate target, not just the specific CVE. <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-oracle-ebs-and-peoplesoft-exploited/">→</a></li><li><strong>Netherlands NIS2 (Cyberbeveiligingswet) clears the lower house — entry into force targeted for 1 July 2026.</strong> Policy: the Netherlands&#39; NIS2 law cleared its lower house (entry into force targeted for 1 July); the EU CRA reporting obligation is ~75 days out (11 September) — enforceable Dutch notification clocks are imminent and CRA SRP onboarding should start. (NL Digital Government, ENISA SRP) <a href="https://ctipilot.ch/entries/2026-06-29/netherlands-nis2-cyberbeveiligingswet-clears-the-lower-house/">→</a></li><li><strong>The Gentlemen.</strong> The Gentlemen ransomware makes Switzerland the second-most-targeted European country, claims 478 victims and adds worm propagation — ESET&#39;s leaked-data deep-dive shows victims are chosen on FortiGate misconfiguration, tying the pipeline to FortiBleed reconnaissance. (daily 06-27, inside-it.ch) <a href="https://ctipilot.ch/entries/2026-06-29/the-gentlemen/">→</a></li><li><strong>FortiBleed.</strong> FortiBleed escalates from credential exposure to confirmed AD domain takeover at a NATO-aligned defence contractor — patch level is irrelevant; rotate any FortiGate credential active May–June and hunt AD persistence. (daily 06-24, CISA) <a href="https://ctipilot.ch/entries/2026-06-29/fortibleed/">→</a></li><li><strong>Threat-actor developments: Russia-nexus espionage broadens; new China-nexus and DPRK clusters.</strong> Turla&#39;s new STOCKSTAY backdoor (GTIG) broadens Russia-nexus espionage toward Western-European foreign-policy targets — delivered via WinRAR CVE-2025-8088 and malicious RDP files; relevant to Swiss/EU governmental entities with Ukraine-adjacent policy work. (daily 06-26, Google GTIG) <a href="https://ctipilot.ch/entries/2026-06-29/threat-actor-developments-russia-nexus-espionage-broadens-ne/">→</a></li><li><strong>Research: the trust chain, not the perimeter, was the week&#39;s attack surface.</strong> The week&#39;s research converges on the trust chain, not the perimeter — a &quot;Developer Credential Economy&quot; feeding npm worms into AI-coding-agent session hooks, OAuth-grant abuse, and a Browser-in-the-Middle PhaaS (Bluekit) that defeats Device Bound Session Credentials. (daily 06-28, Tenable) <a href="https://ctipilot.ch/entries/2026-06-29/research-the-trust-chain-not-the-perimeter-was-the-week-s-at/">→</a></li><li><strong>Klue / Icarus Salesforce OAuth-integration breach — from nine named victims to ~24, then the attacker gets hacked.</strong> The Klue/Icarus Salesforce OAuth breach widened to ~24 named firms, then the attacker was itself hacked and a second extortion group emerged listing ~195 organisations — one dormant integration token cascading into multi-tenant CRM theft. (daily 06-27, SecurityWeek) <a href="https://ctipilot.ch/entries/2026-06-29/klue-icarus-salesforce-oauth-integration-breach-from-nine-na/">→</a></li><li><strong>ShapedPlugin&#39;s official update channel shipped backdoored WordPress Pro plugins — credential, 2FA-secret and web-shell theft.</strong> ShapedPlugin&#39;s official WordPress update channel shipped backdoored Pro plugins — credential, 2FA-secret and web-shell theft straight from the trusted pipeline. (daily 06-23, Wordfence) <a href="https://ctipilot.ch/entries/2026-06-29/shapedplugin-s-official-update-channel-shipped-backdoored-wo/">→</a></li><li><strong>NAIC breached through an Oracle PeopleSoft zero-day; ShinyHunters dumps 3.1 TB and US rating-agency feeds stall.</strong> NAIC breached through an Oracle PeopleSoft zero-day (CVE-2026-35273); ShinyHunters dumps 3.1 TB and US rating-agency feeds stall — the same UNC6240 campaign GTIG has tracked against ~100 orgs (68% higher education) is still acquiring victims; treat internet-reachable PeopleSoft as assume-compromise. (daily 06-28, NAIC) <a href="https://ctipilot.ch/entries/2026-06-29/naic-breached-through-an-oracle-peoplesoft-zero-day-shinyhun/">→</a></li><li><strong>AI crossed from target to operator this week — agentic ransomware, coerced coding agents, LLM-output poisoning.</strong> Four independent research disclosures across the week mark a shift in how AI figures in the threat model: Sysdig&#39;s JADEPUFFER is assessed as the first end-to-end LLM-driven ransomware run; Mozilla 0DIN coerced AI coding agents into a reverse shell with no malicious code in the repo; Unit 42&#39;s Phantom Squatting poisons LLM-recommended URLs at the delivery layer; and Kaspersky shows a community AI-agent skill marketplace still shipping malicious skills. The prior weekly framed AI as a target; this week it is the operator and the delivery channel. <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-ai-moved-from-target-to-operator/">→</a></li><li><strong>SimpleHelp RMM auth bypass (CVE-2026-48558) actively exploited this week — an RMM supply-chain foothold.</strong> The week&#39;s most acute exploited flaw is an OIDC signature-verification bypass in SimpleHelp RMM (CVE-2026-48558, CVSS 10.0), now on CISA KEV and used to deploy the new Djinn infostealer. An RMM server is a supply-chain multiplier — one compromise reaches every managed endpoint downstream — so any internet-exposed SimpleHelp instance with OIDC group-auth enabled is an assume-compromise target until patched to v5.5.16/v6.0 RC2. <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-simplehelp-rmm-auth-bypass-actively-exploited/">→</a></li></ul>]]></description><content:encoded><![CDATA[<div class="tldr"><span class="eyebrow eyebrow--muted">Week at a glance</span><ol><li><span class="num">01</span><span><b>Public-administration targeting this week — Canton Zürich leak claim, Pegasus-infected MEP, DHS HSIN breach.</b> Three separate government-targeting events landed this week with direct Swiss/EU relevance: MedusaLocker listed the Canton of Zürich&#39;s Baudirektion (bd.zh.ch) on its leak site (unconfirmed); Citizen Lab forensically confirmed Pegasus twice infected a European Parliament PEGA-committee MEP via the zero-click PWNYOURHOME chain; and DHS confirmed a breach of its Homeland Security Information Network. The common thread is not a shared CVE but the target class — public institutions attacked through leak-site extortion, mercenary mobile spyware, and cross-org collaboration-platform trust boundaries. <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-government-targeting-ch-eu/">→</a></span></li><li><span class="num">02</span><span><b>Vuln status roll-up 2026-W27 — exploited, KEV-listed, working-exploit, and weaponisation-likely items.</b> The week&#39;s vulnerability status at a glance for a public-sector estate: newly exploited/KEV (SimpleHelp CVE-2026-48558, Oracle EBS CVE-2026-46817, SharePoint CVE-2026-45659, Kemp LoadMaster CVE-2026-8037); working-exploit or PoC (DirtyClone Linux LPE CVE-2026-43503, libssh2 CVE-2026-55200, Citrix NetScaler CVE-2026-8451); and weaponisation-likely-but-not-yet-exploited (six CVSS 10.0 Adobe ColdFusion RCEs, Control Web Panel CVE-2026-57517, Coolify CVE-2026-34038). <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-vuln-status-rollup/">→</a></span></li><li><span class="num">03</span><span><b>Edge/VPN appliances: three pre-auth flaws in one week — Citrix NetScaler, WatchGuard Firebox, Kemp LoadMaster.</b> Three internet-facing edge appliances disclosed pre-authentication memory-safety flaws across the week: Citrix NetScaler CVE-2026-8451 (CitrixBleed-lineage SAML overread, public susceptibility tool), WatchGuard Firebox CVE-2026-13368 (IKEv2 use-after-free RCE, CVSS 9.2), and Progress Kemp LoadMaster CVE-2026-8037 (uninitialized-heap pre-auth RCE, CVSS 9.8) — the last already seeing exploitation attempts the day its PoC dropped. The pattern, not any single CVE, is the signal: pre-auth edge RCE reliably attracts fast-follow mass exploitation. <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-edge-vpn-pre-auth-rce-cluster/">→</a></span></li><li><span class="num">04</span><span><b>Two internet-facing Oracle enterprise product lines under active exploitation this week — EBS RCE + PeopleSoft.</b> Oracle E-Business Suite CVE-2026-46817 (pre-auth RCE in the Payments File Transmission servlet, CVSS 9.8) saw its first confirmed in-the-wild exploitation this week, landing while the separate ShinyHunters Oracle PeopleSoft campaign (CVE-2026-35273) kept acquiring named victims. The operational reality for a public-sector or higher-education estate: treat every internet-reachable Oracle application tier — EBS, PeopleSoft, and their web front ends — as a priority patch-and-isolate target, not just the specific CVE. <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-oracle-ebs-and-peoplesoft-exploited/">→</a></span></li><li><span class="num">05</span><span><b>Netherlands NIS2 (Cyberbeveiligingswet) clears the lower house — entry into force targeted for 1 July 2026.</b> Policy: the Netherlands&#39; NIS2 law cleared its lower house (entry into force targeted for 1 July); the EU CRA reporting obligation is ~75 days out (11 September) — enforceable Dutch notification clocks are imminent and CRA SRP onboarding should start. (NL Digital Government, ENISA SRP) <a href="https://ctipilot.ch/entries/2026-06-29/netherlands-nis2-cyberbeveiligingswet-clears-the-lower-house/">→</a></span></li><li><span class="num">06</span><span><b>The Gentlemen.</b> The Gentlemen ransomware makes Switzerland the second-most-targeted European country, claims 478 victims and adds worm propagation — ESET&#39;s leaked-data deep-dive shows victims are chosen on FortiGate misconfiguration, tying the pipeline to FortiBleed reconnaissance. (daily 06-27, inside-it.ch) <a href="https://ctipilot.ch/entries/2026-06-29/the-gentlemen/">→</a></span></li><li><span class="num">07</span><span><b>FortiBleed.</b> FortiBleed escalates from credential exposure to confirmed AD domain takeover at a NATO-aligned defence contractor — patch level is irrelevant; rotate any FortiGate credential active May–June and hunt AD persistence. (daily 06-24, CISA) <a href="https://ctipilot.ch/entries/2026-06-29/fortibleed/">→</a></span></li><li><span class="num">08</span><span><b>Threat-actor developments: Russia-nexus espionage broadens; new China-nexus and DPRK clusters.</b> Turla&#39;s new STOCKSTAY backdoor (GTIG) broadens Russia-nexus espionage toward Western-European foreign-policy targets — delivered via WinRAR CVE-2025-8088 and malicious RDP files; relevant to Swiss/EU governmental entities with Ukraine-adjacent policy work. (daily 06-26, Google GTIG) <a href="https://ctipilot.ch/entries/2026-06-29/threat-actor-developments-russia-nexus-espionage-broadens-ne/">→</a></span></li><li><span class="num">09</span><span><b>Research: the trust chain, not the perimeter, was the week&#39;s attack surface.</b> The week&#39;s research converges on the trust chain, not the perimeter — a &quot;Developer Credential Economy&quot; feeding npm worms into AI-coding-agent session hooks, OAuth-grant abuse, and a Browser-in-the-Middle PhaaS (Bluekit) that defeats Device Bound Session Credentials. (daily 06-28, Tenable) <a href="https://ctipilot.ch/entries/2026-06-29/research-the-trust-chain-not-the-perimeter-was-the-week-s-at/">→</a></span></li><li><span class="num">10</span><span><b>Klue / Icarus Salesforce OAuth-integration breach — from nine named victims to ~24, then the attacker gets hacked.</b> The Klue/Icarus Salesforce OAuth breach widened to ~24 named firms, then the attacker was itself hacked and a second extortion group emerged listing ~195 organisations — one dormant integration token cascading into multi-tenant CRM theft. (daily 06-27, SecurityWeek) <a href="https://ctipilot.ch/entries/2026-06-29/klue-icarus-salesforce-oauth-integration-breach-from-nine-na/">→</a></span></li><li><span class="num">11</span><span><b>ShapedPlugin&#39;s official update channel shipped backdoored WordPress Pro plugins — credential, 2FA-secret and web-shell theft.</b> ShapedPlugin&#39;s official WordPress update channel shipped backdoored Pro plugins — credential, 2FA-secret and web-shell theft straight from the trusted pipeline. (daily 06-23, Wordfence) <a href="https://ctipilot.ch/entries/2026-06-29/shapedplugin-s-official-update-channel-shipped-backdoored-wo/">→</a></span></li><li><span class="num">12</span><span><b>NAIC breached through an Oracle PeopleSoft zero-day; ShinyHunters dumps 3.1 TB and US rating-agency feeds stall.</b> NAIC breached through an Oracle PeopleSoft zero-day (CVE-2026-35273); ShinyHunters dumps 3.1 TB and US rating-agency feeds stall — the same UNC6240 campaign GTIG has tracked against ~100 orgs (68% higher education) is still acquiring victims; treat internet-reachable PeopleSoft as assume-compromise. (daily 06-28, NAIC) <a href="https://ctipilot.ch/entries/2026-06-29/naic-breached-through-an-oracle-peoplesoft-zero-day-shinyhun/">→</a></span></li><li><span class="num">13</span><span><b>AI crossed from target to operator this week — agentic ransomware, coerced coding agents, LLM-output poisoning.</b> Four independent research disclosures across the week mark a shift in how AI figures in the threat model: Sysdig&#39;s JADEPUFFER is assessed as the first end-to-end LLM-driven ransomware run; Mozilla 0DIN coerced AI coding agents into a reverse shell with no malicious code in the repo; Unit 42&#39;s Phantom Squatting poisons LLM-recommended URLs at the delivery layer; and Kaspersky shows a community AI-agent skill marketplace still shipping malicious skills. The prior weekly framed AI as a target; this week it is the operator and the delivery channel. <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-ai-moved-from-target-to-operator/">→</a></span></li><li><span class="num">14</span><span><b>SimpleHelp RMM auth bypass (CVE-2026-48558) actively exploited this week — an RMM supply-chain foothold.</b> The week&#39;s most acute exploited flaw is an OIDC signature-verification bypass in SimpleHelp RMM (CVE-2026-48558, CVSS 10.0), now on CISA KEV and used to deploy the new Djinn infostealer. An RMM server is a supply-chain multiplier — one compromise reaches every managed endpoint downstream — so any internet-exposed SimpleHelp instance with OIDC group-auth enabled is an assume-compromise target until patched to v5.5.16/v6.0 RC2. <a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-simplehelp-rmm-auth-bypass-actively-exploited/">→</a></span></li></ol></div><nav class="secnav" aria-label="Sections"><a class="secnav-chip" href="#highest-impact-events-what-s-on-fire-if-no-one-acted">Highest-impact events · what&#39;s on fire if no one acted <span class="secnav-n">4</span></a><a class="secnav-chip" href="#multi-day-campaigns-and-chains">Multi-day campaigns and chains <span class="secnav-n">5</span></a><a class="secnav-chip" href="#vulnerability-roll-up">Vulnerability roll-up <span class="secnav-n">10</span></a><a class="secnav-chip" href="#sector-victim-patterns">Sector &amp; victim patterns <span class="secnav-n">5</span></a><a class="secnav-chip" href="#incidents-disclosures-recap">Incidents &amp; disclosures recap <span class="secnav-n">5</span></a><a class="secnav-chip" href="#research-threat-actor-developments">Research &amp; threat-actor developments <span class="secnav-n">3</span></a><a class="secnav-chip" href="#annual-periodic-threat-reports">Annual / periodic threat reports <span class="secnav-n">3</span></a><a class="secnav-chip" href="#long-running-campaigns-status-update">Long-running campaigns · status update <span class="secnav-n">6</span></a><a class="secnav-chip" href="#policy-regulatory-horizon">Policy &amp; regulatory horizon <span class="secnav-n">4</span></a><a class="secnav-chip" href="#looking-ahead-what-to-watch-next-week">Looking ahead · what to watch next week <span class="secnav-n">2</span></a></nav><div class="sect" id="highest-impact-events-what-s-on-fire-if-no-one-acted"><span class="n">01</span><span class="t">Highest-impact events · what&#39;s on fire if no one acted</span><span class="c">4 items</span></div><article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-oracle-ebs-and-peoplesoft-exploited" data-tags="vulnerabilities actively-exploited pre-auth rce data-breach" data-regions="global europe" data-kind="synthesis" data-priority="high" data-discovered="2026-07-05T23:25:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="weekly-w27-oracle-ebs-and-peoplesoft-exploited"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-oracle-ebs-and-peoplesoft-exploited/">Two internet-facing Oracle enterprise product lines were under active exploitation this week — E-Business Suite RCE joins the PeopleSoft campaign</a></h3><p><strong>If you did nothing this week:</strong> any internet-reachable Oracle enterprise application tier is a live pre-auth target. Two distinct Oracle product lines were being exploited in the same window, so the defender decision is not &quot;patch this CVE&quot; but &quot;get every Oracle application front end off the public internet and onto the exploited-flaw patch clock.&quot;</p>
<p>The new fact this week is <strong>CVE-2026-46817</strong> (CVSS 9.8), an unauthenticated RCE in the <em>File Transmission</em> component of Oracle Payments within Oracle E-Business Suite (EBS 12.2.3–12.2.15), fixed in the May 2026 Critical Patch Update. Threat-intel firm Defused reported the first confirmed in-the-wild exploitation against its EBS honeypots over the weekend of 27–28 June — roughly six weeks after the patch and with &quot;no known previous exploitation and no public POC code&quot; until that point (<a href="https://www.bleepingcomputer.com/news/security/new-oracle-e-business-suite-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-29</a>; <a href="https://securityaffairs.com/194463/security/attackers-actively-exploit-the-oracle-e-business-suite-flaw-cve-2026-46817.html" target="_blank" rel="noopener noreferrer">SecurityAffairs, 2026-06-30</a>). That &quot;patched-but-now-exploited, no-PoC&quot; pattern is exactly what turns unpatched internet-facing estates into targets fastest. Shadowserver tracks 450+ internet-exposed EBS instances, ~200 in the US and Europe, and EBS Payments/financial modules sit in government, higher-education and large-enterprise finance back offices — high-value data behind an internet-reachable app tier (<a href="https://www.bleepingcomputer.com/news/security/new-oracle-e-business-suite-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-29</a>).</p>
<p>This lands alongside — but is distinct from — the ShinyHunters/UNC6240 Oracle <strong>PeopleSoft</strong> zero-day campaign (CVE-2026-35273) that GTIG/Mandiant attributes and that added Nissan as its largest named victim this week (<a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit" target="_blank" rel="noopener noreferrer">Google GTIG</a>; campaign arc consolidated separately in this week&#39;s long-running status entry). No public reporting ties the EBS exploitation to ShinyHunters — the EBS activity is unattributed — so the weekly signal is not a single actor but a <strong>product-family exposure</strong>: two Oracle enterprise application lines under active exploitation at once. Detail on each: EBS deep dive and the Nissan disclosure (§ references).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Threat-intel firm Defused reported the first confirmed in-the-wild exploitation against its Oracle EBS honeypots, with the first attempts observed over the weekend of 27–28 June 2026</p><figcaption class="entry-cite__attr">BleepingComputer (paraphrase of Defused telemetry)</figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Shadowserver tracks over 450 internet-exposed Oracle EBS instances, with nearly 200 across the United States and Europe</p><figcaption class="entry-cite__attr"><a href="https://www.bleepingcomputer.com/news/security/new-oracle-e-business-suite-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/oracle-e-business-suite-cve-2026-46817-pre-auth-rce-in-the-p/">2026-07-01/oracle-e-business-suite-cve-2026-46817-pre-auth-rce-in-the-p</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o/">2026-07-01/nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o</a></p><div class="prov"><span>synthesis</span><span>05 Jul 23:25Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-oracle-ebs-and-peoplesoft-exploited/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/new-oracle-e-business-suite-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://securityaffairs.com/194463/security/attackers-actively-exploit-the-oracle-e-business-suite-flaw-cve-2026-46817.html" target="_blank" rel="noopener noreferrer">SecurityAffairs</a> · <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit" target="_blank" rel="noopener noreferrer">Google GTIG / Mandiant</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/shapedplugin-s-official-update-channel-shipped-backdoored-wo" data-tags="supply-chain data-breach actively-exploited patch-available" data-regions="global europe" data-kind="synthesis" data-priority="high" data-discovered="2026-06-29T00:20:54Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-10735/">CVE-2026-10735</a><span class="b exp">exploited</span></div><h3 class="f-h" id="shapedplugin-s-official-update-channel-shipped-backdoored-wo"><a href="https://ctipilot.ch/entries/2026-06-29/shapedplugin-s-official-update-channel-shipped-backdoored-wo/">ShapedPlugin&#39;s official update channel shipped backdoored WordPress Pro plugins — credential, 2FA-secret and web-shell theft</a></h3><p><strong>If you did nothing this week:</strong> any site running the ShapedPlugin Pro plugins that auto-updated through the licensed channel pulled backdoor code straight from the vendor — patch level was no defence, because the trusted distribution pipeline itself was the attacker. The malicious <code>LicenseLoader.php</code> loads inside the WordPress admin panel, fetches a second stage, installs it as a fake plugin and self-deletes to frustrate forensics.</p>
<p>Wordfence <a href="https://www.wordfence.com/blog/2026/06/psa-supply-chain-compromise-targets-shapedplugin-backdoored-pro-plugins-distributed-via-official-channels/" target="_blank" rel="noopener noreferrer">disclosed on 2026-06-22</a> that an attacker breached ShapedPlugin&#39;s build and Easy Digital Downloads distribution pipeline and injected backdoor code into the Pro (paid) releases of three plugins, served through official update channels. The implant harvests credentials and 2FA secrets and drops a web shell (<a href="https://www.bleepingcomputer.com/news/security/shapedplugin-update-flow-hacked-to-infect-wordpress-sites/" target="_blank" rel="noopener noreferrer">BleepingComputer</a>). For a public-sector or education estate that runs WordPress behind a CMS team, the hunt is for the fake-plugin artefact and unexpected <code>LicenseLoader.php</code> execution in the admin context, plus credential/2FA rotation for any admin who logged in during the exposure window — not merely &quot;update the plugin.&quot; (<a href="https://ctipilot.ch/briefs/2026-06-23/" target="_blank" rel="noopener noreferrer">daily 06-23</a>)</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Attackers compromised the vendor&#39;s build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels</p><figcaption class="entry-cite__attr"><a href="https://www.wordfence.com/blog/2026/06/psa-supply-chain-compromise-targets-shapedplugin-backdoored-pro-plugins-distributed-via-official-channels/" target="_blank" rel="noopener noreferrer">Wordfence</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">The malicious packages contained a file named LicenseLoader.php, which was loaded automatically within the WordPress admin panel ... downloaded a second-stage payload, installed it as a fake plugin ... and then deleted itself to hinder forensic analysis</p><figcaption class="entry-cite__attr"><a href="https://www.bleepingcomputer.com/news/security/shapedplugin-update-flow-hacked-to-infect-wordpress-sites/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></figcaption></figure></div><div class="prov"><span>synthesis</span><span>29 Jun 00:20Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/shapedplugin-s-official-update-channel-shipped-backdoored-wo/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.wordfence.com/blog/2026/06/psa-supply-chain-compromise-targets-shapedplugin-backdoored-pro-plugins-distributed-via-official-channels/" target="_blank" rel="noopener noreferrer">Wordfence</a> · <a href="https://www.bleepingcomputer.com/news/security/shapedplugin-update-flow-hacked-to-infect-wordpress-sites/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/naic-breached-through-an-oracle-peoplesoft-zero-day-shinyhun" data-tags="data-breach zero-day actively-exploited organized-crime" data-regions="us europe" data-kind="synthesis" data-priority="high" data-discovered="2026-06-29T00:20:53Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-35273/">CVE-2026-35273</a><span class="b exp">exploited</span></div><h3 class="f-h" id="naic-breached-through-an-oracle-peoplesoft-zero-day-shinyhun"><a href="https://ctipilot.ch/entries/2026-06-29/naic-breached-through-an-oracle-peoplesoft-zero-day-shinyhun/">NAIC breached through an Oracle PeopleSoft zero-day; ShinyHunters dumps 3.1 TB and US rating-agency feeds stall</a></h3><p><strong>If you did nothing this week:</strong> any internet-reachable Oracle PeopleSoft instance is a live pre-auth foothold — the same zero-day path that put the US National Association of Insurance Commissioners into ShinyHunters&#39; hands, and PeopleSoft is widely deployed across European public administration, higher education and HR/finance back offices. The W25 looking-ahead flagged that ShinyHunters PeopleSoft notifications were still landing and that EU universities were a probable next-named class; NAIC is the fresh high-profile confirmation that the campaign is still acquiring victims.</p>
<p>NAIC — the standard-setting body for all 50 US state insurance regulators — <a href="https://content.naic.org/about/security-update" target="_blank" rel="noopener noreferrer">confirmed on 2026-06-26</a> that an unauthorised party reached its environment on June 11 via an Oracle PeopleSoft vulnerability, then pivoted from PeopleSoft to temporary access to data-storage areas. ShinyHunters claims 3.1 TB exfiltrated (<a href="https://www.techradar.com/pro/security/naic-confirms-data-breach-with-shinyhunters-claiming-3-1tb-of-data-stolen-in-oracle-zero-day-attack" target="_blank" rel="noopener noreferrer">TechRadar</a>, <a href="https://www.insurancejournal.com/news/national/2026/06/25/875334.htm" target="_blank" rel="noopener noreferrer">Insurance Journal</a>). The operational tell is the downstream impact NAIC itself disclosed: credit-rating agencies paused their data feeds and NAIC suspended assigning designations to insurer investments — a regulatory-process outage, not just a data-confidentiality event. This is the same PeopleSoft exploitation wave (CVE-2026-35273, the unauthenticated RCE in PeopleTools Environment Management) Google GTIG attributes to UNC6240/ShinyHunters and has been tracking against the education sector — 68% of identified targets were higher-education institutions; Treat any externally-reachable PeopleSoft portal (<code>/PSEMHUB/</code>, <code>/PSIGW/HttpListeningConnector</code>) as a hunt target, not a patch-later item. (<a href="https://ctipilot.ch/briefs/2026-06-28/" target="_blank" rel="noopener noreferrer">daily 06-28</a>)</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Unauthorized access to a portion of the NAIC&#39;s environment was identified on June 11 via an Oracle PeopleSoft vulnerability. While in PeopleSoft, the unauthorized party was able to obtain information needed to gain temporary access to certain data storage areas.</p><p class="entry-cite__quote">Due to the incident, certain credit rating agencies have paused their data feeds and consequently, the NAIC has temporarily suspended assigning designations to insurer investments.</p><figcaption class="entry-cite__attr">NAIC</figcaption></figure></div><div class="prov"><span>synthesis</span><span>29 Jun 00:20Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/naic-breached-through-an-oracle-peoplesoft-zero-day-shinyhun/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://content.naic.org/about/security-update" target="_blank" rel="noopener noreferrer">NAIC security update</a> · <a href="https://www.insurancejournal.com/news/national/2026/06/25/875334.htm" target="_blank" rel="noopener noreferrer">Insurance Journal</a> · <a href="https://www.techradar.com/pro/security/naic-confirms-data-breach-with-shinyhunters-claiming-3-1tb-of-data-stolen-in-oracle-zero-day-attack" target="_blank" rel="noopener noreferrer">TechRadar</a></div></article><article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-simplehelp-rmm-auth-bypass-actively-exploited" data-tags="vulnerabilities actively-exploited auth-bypass cisa-kev infostealer" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-07-05T23:24:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w27-simplehelp-rmm-auth-bypass-actively-exploited"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-simplehelp-rmm-auth-bypass-actively-exploited/">SimpleHelp RMM auth bypass (CVE-2026-48558) went from disclosure to in-the-wild exploitation this week — an RMM supply-chain foothold</a></h3><p><strong>If you did nothing this week:</strong> an internet-exposed SimpleHelp RMM server running OIDC single-sign-on is a full-takeover foothold — and because remote-monitoring-and-management servers push commands to every endpoint they manage, one compromised instance is a supply-chain pivot into an entire managed estate, the same blast-radius pattern that made Kaseya and ConnectWise ScreenConnect priority targets.</p>
<p>CVE-2026-48558 (CVSS 10.0) is an OIDC SSO authentication bypass in SimpleHelp: the OIDC callback handler accepts an identity token without verifying its cryptographic signature (CWE-347), so an attacker forges an arbitrary token, obtains a full Technician-level session, and bypasses MFA on first OIDC login (<a href="https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/" target="_blank" rel="noopener noreferrer">Horizon3.ai, 2026-06-12</a>). The prerequisite is a configured OIDC provider with a TechnicianGroup bound and &quot;Allow group authenticated logins&quot; enabled; Horizon3.ai measured ~14,000 internet-exposed servers, ~7.2% (~1,000) in a vulnerable OIDC configuration. This week&#39;s shift is from disclosure to exploitation: CISA added the CVE to KEV on 2026-06-29 — jurisdiction-agnostic confirmation of in-the-wild abuse — and observed follow-on is deployment of the new cross-platform <strong>Djinn</strong> infostealer through a &quot;TaskWeaver&quot; loader persisting via scheduled tasks and launchd plists (<a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-simplehelp-flaw-deploy-new-djinn-infostealer-taskweaver-malware/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-29</a>; <a href="https://ccb.belgium.be/advisories/warning-simplehelp-patched-cve-2026-48558-critical-authentication-bypass-vulnerability" target="_blank" rel="noopener noreferrer">Centre for Cybersecurity Belgium, 2026-06</a>). The weekly lens for a public-sector reader: RMM and remote-support tooling is a recurring first-party supply-chain surface — treat the management plane of any remote-support product as tier-0, patch it on the exploited-flaw clock rather than the monthly cycle, and confirm no support vendor in your own supply chain is running an exposed, unpatched instance. First covered operationally on 2026-06-30 (§ references).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Hackers exploit critical SimpleHelp flaw to deploy new Djinn infostealer and TaskWeaver malware</p><figcaption class="entry-cite__attr"><a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-simplehelp-flaw-deploy-new-djinn-infostealer-taskweaver-malware/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">nearly 14,000 SimpleHelp servers exposed, with roughly 7.2% configured to use the vulnerable OIDC authentication method</p><figcaption class="entry-cite__attr"><a href="https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/" target="_blank" rel="noopener noreferrer">Horizon3.ai</a></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/cve-2026-48558-simplehelp-rmm-oidc-sso-authentication-bypass/">2026-06-30/cve-2026-48558-simplehelp-rmm-oidc-sso-authentication-bypass</a></p><div class="prov"><span>synthesis</span><span>05 Jul 23:24Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-simplehelp-rmm-auth-bypass-actively-exploited/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://horizon3.ai/attack-research/disclosures/cve-2026-48558-simplehelp-authentication-bypass-iocs/" target="_blank" rel="noopener noreferrer">Horizon3.ai</a> · <a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-simplehelp-flaw-deploy-new-djinn-infostealer-taskweaver-malware/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://ccb.belgium.be/advisories/warning-simplehelp-patched-cve-2026-48558-critical-authentication-bypass-vulnerability" target="_blank" rel="noopener noreferrer">Centre for Cybersecurity Belgium</a></div></article><div class="sect" id="multi-day-campaigns-and-chains"><span class="n">02</span><span class="t">Multi-day campaigns and chains</span><span class="c">5 items</span></div><article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-edge-vpn-pre-auth-rce-cluster" data-tags="vulnerabilities pre-auth rce actively-exploited poc-public patch-available" data-regions="global europe" data-kind="synthesis" data-priority="high" data-discovered="2026-07-05T23:26:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w27-edge-vpn-pre-auth-rce-cluster"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-edge-vpn-pre-auth-rce-cluster/">Edge and VPN appliances took three pre-auth RCE/overread disclosures in one week — Citrix NetScaler, WatchGuard Firebox, Kemp LoadMaster</a></h3><p>The through-line across three otherwise unrelated vendors this week is that the network edge kept producing the exact bug class — pre-authentication memory corruption / overread in an internet-reachable appliance — that the Fortinet/Ivanti/Citrix history shows reliably becomes a mass-exploitation target once detail surfaces.</p>
<p><strong>Kemp LoadMaster — CVE-2026-8037</strong> (CVSS 9.8): watchTowr published full mechanics of an uninitialized-<code>malloc()</code> heap corruption in the <code>escape_quotes()</code> path of the <code>access</code> executable, reached by a sprayed JSON payload to <code>/accessv2</code>, yielding code execution as root with no authentication (<a href="https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadmaster-uninitialized-heap-to-pre-auth-rce-cve-2026-8037/" target="_blank" rel="noopener noreferrer">watchTowr, 2026-06-29</a>). eSentire&#39;s TRU reported in-the-wild exploitation attempts beginning <strong>the same day the PoC dropped</strong> (observed attempts failed) — the fastest disclosure-to-attempt turn of the three (first covered 06-30, exploitation confirmed 07-02; § references).</p>
<p><strong>Citrix NetScaler ADC/Gateway — CVE-2026-8451</strong> (CVSS 8.8): a pre-auth out-of-bounds read in the hand-rolled XML attribute parser behind <code>/saml/login</code>, reachable only when the appliance is a SAML IdP, leaking adjacent process memory in the <code>NSC_TASS</code> response cookie — the fourth CitrixBleed-class memory-safety defect watchTowr has documented in NetScaler auth paths. watchTowr shipped a public &quot;Detection Artefact Generator&quot; so operators can test exposure; no in-the-wild exploitation was confirmed at disclosure, but CitrixBleed-lineage siblings have been exploited within days (<a href="https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/" target="_blank" rel="noopener noreferrer">watchTowr, 2026-06-30</a>; NCSC-NL advisory NCSC-2026-0216).</p>
<p><strong>WatchGuard Firebox — CVE-2026-13368</strong> (CVSS 9.2): a use-after-free race in the <code>iked</code> IKEv2 daemon reachable during LDAP authentication for Mobile VPN with IKEv2; a remote unauthenticated attacker winning the race executes code in the <code>iked</code> context (<a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023" target="_blank" rel="noopener noreferrer">WatchGuard PSIRT, 2026-07-02</a>; BSI CERT-Bund WID-SEC-2026-2193). The 12.5.x branch had no fix at publication and 11.x is EOL.</p>
<p><strong>Weekly takeaway for defenders:</strong> the recurring exposure is not a product, it is the <em>class</em> — internet-terminated VPN/UTM/load-balancer appliances with pre-auth memory-corruption primitives. Where a fix does not yet exist for your build (Firebox 12.5.x), the correct move is to remove the vulnerable auth path, not wait; and detection for all three realistically lives in appliance crash telemetry and the backing auth server&#39;s logs, because the exploit fires before any session is established. Per-appliance detail in § references.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">A remote unauthenticated attacker could exploit this vulnerability to execute arbitrary code in the context of the iked process on Fireboxes that have a Mobile VPN with IKEv2 configured to use an external LDAP authentication server.</p><figcaption class="entry-cite__attr"><a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023" target="_blank" rel="noopener noreferrer">WatchGuard PSIRT (WGSA-2026-00023)</a></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem/">2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-03/cve-2026-13368-watchguard-fireware-iked-pre-auth-rce/">2026-07-03/cve-2026-13368-watchguard-fireware-iked-pre-auth-rce</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/cve-2026-8037-progress-kemp-loadmaster-pre-auth-rce-via-unin/">2026-06-30/cve-2026-8037-progress-kemp-loadmaster-pre-auth-rce-via-unin</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/kemp-loadmaster-cve-2026-8037-exploitation-attempts-confirme/">2026-07-02/kemp-loadmaster-cve-2026-8037-exploitation-attempts-confirme</a></p><div class="prov"><span>synthesis</span><span>05 Jul 23:26Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-edge-vpn-pre-auth-rce-cluster/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netscaler-pre-auth-memory-overread-cve-2026-8451/" target="_blank" rel="noopener noreferrer">watchTowr Labs</a> · <a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023" target="_blank" rel="noopener noreferrer">WatchGuard PSIRT (WGSA-2026-00023)</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/klue-icarus-salesforce-oauth-integration-breach-from-nine-na" data-tags="data-breach supply-chain identity cloud organized-crime" data-regions="global europe" data-kind="synthesis" data-priority="high" data-discovered="2026-06-29T00:20:55Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="klue-icarus-salesforce-oauth-integration-breach-from-nine-na"><a href="https://ctipilot.ch/entries/2026-06-29/klue-icarus-salesforce-oauth-integration-breach-from-nine-na/">Klue / Icarus Salesforce OAuth-integration breach — from nine named victims to ~24, then the attacker gets hacked</a></h3><p>This is the W25 multi-day item, but the in-window deltas re-shape it materially. At the start of the week the named-victim list stood at nine, mostly cybersecurity vendors (HackerOne, Huntress, Jamf, OneTrust and others, <a href="https://www.securityweek.com/more-cybersecurity-firms-disclose-impact-from-klue-hack/" target="_blank" rel="noopener noreferrer">SecurityWeek 06-23</a>). It then accreted through the week: 8x8 <a href="https://www.sec.gov/Archives/edgar/data/0001023731/000102373126000084/eght-20260617.htm" target="_blank" rel="noopener noreferrer">filed an SEC 8-K Item 1.05 on 06-23</a> confirming Salesforce exfiltration; <a href="https://www.securityweek.com/beyondtrust-lastpass-impacted-by-klue-salesforce-incident/" target="_blank" rel="noopener noreferrer">BeyondTrust and LastPass disclosed</a> business-contact and sales data theft on 06-25; by 06-27 <a href="https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/" target="_blank" rel="noopener noreferrer">roughly two dozen firms</a> had notified, and in a twist the Icarus attacker was itself hacked, with a second extortion actor now threatening the stolen data. Salesforce disabled the Klue connected app.</p>
<p>The new lens the dailies could not assemble: this is a single dormant OAuth integration credential at one SaaS vendor cascading into multi-tenant CRM theft across that vendor&#39;s entire customer base — the exact failure mode ReliaQuest framed as &quot;integration abused in CRM data theft&quot; in W25. For a Swiss/EU SOC the takeaway is an OAuth-grant inventory exercise: enumerate third-party connected apps with API scopes into your CRM/identity tenants, revoke dormant grants, and alert on bulk REST/Bulk-API reads from integration principals — patching nothing here helps, because no software was vulnerable; a delegated token was. (<a href="https://ctipilot.ch/briefs/2026-06-23/" target="_blank" rel="noopener noreferrer">daily 06-23</a>, <a href="https://ctipilot.ch/briefs/2026-06-25/" target="_blank" rel="noopener noreferrer">daily 06-25</a>, <a href="https://ctipilot.ch/briefs/2026-06-27/" target="_blank" rel="noopener noreferrer">daily 06-27</a>)</p><div class="prov"><span>synthesis</span><span>29 Jun 00:20Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/klue-icarus-salesforce-oauth-integration-breach-from-nine-na/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/" target="_blank" rel="noopener noreferrer">SecurityWeek — victims identified, hackers hacked</a> · <a href="https://www.sec.gov/Archives/edgar/data/0001023731/000102373126000084/eght-20260617.htm" target="_blank" rel="noopener noreferrer">SEC EDGAR — 8x8 Form 8-K</a> · <a href="https://www.securityweek.com/beyondtrust-lastpass-impacted-by-klue-salesforce-incident/" target="_blank" rel="noopener noreferrer">SecurityWeek — BeyondTrust/LastPass</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/shinyhunters-unc6240-one-cluster-multiple-reported-tradecraf" data-tags="organized-crime data-breach identity phishing" data-regions="uk us europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-29T00:20:56Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="shinyhunters-unc6240-one-cluster-multiple-reported-tradecraf"><a href="https://ctipilot.ch/entries/2026-06-29/shinyhunters-unc6240-one-cluster-multiple-reported-tradecraf/">ShinyHunters (UNC6240) — one cluster, multiple reported tradecraft paths in one week</a></h3><p>The week is a compact case study in how a single extortion cluster&#39;s <em>reported</em> activity spans very different initial-access tradecraft. The two firmly UNC6240-attributed events are the Oracle PeopleSoft zero-day behind the NAIC breach (GTIG/Mandiant attribution, § 1) and the April 2026 Instructure Canvas LMS breach, whose UK Cyber Monitoring Centre <a href="https://www.computerweekly.com/news/366645159/Canvas-breach-hit-160-UK-unis-but-caused-limited-damage" target="_blank" rel="noopener noreferrer">sector review</a> landed 06-27 (160 UK universities, extortion, ransom paid). Alongside them, <a href="https://www.404media.co/how-hackers-broke-into-madison-square-garden/" target="_blank" rel="noopener noreferrer">404 Media&#39;s reconstruction</a> (06-26) showed the Madison Square Garden intrusion began with a single vishing call into the company&#39;s identity platform — the operator phoned a low-level employee and talked them through authorising access; the 404 Media account documents the technique but names no actor, and the ShinyHunters link rests on the operators&#39; own claims and the SSO-vishing TTP overlap <a href="https://abnormal.ai/blog/shinyhunters-sso-social-engineering-mfa-identity-compromise" target="_blank" rel="noopener noreferrer">Abnormal Security</a> attributes to the cluster.</p>
<p>The cross-day pattern matters more than any single victim: a server-side zero-day, a SaaS-platform compromise and SSO-targeting vishing all appear under (or adjacent to) one extortion banner in one week, so defending against this cluster is not a single control. It is externally-reachable enterprise-app patching/hunting, third-party SaaS exposure management, and help-desk/identity-platform vishing resistance (callback verification, no MFA-reset-on-call) — all at once. (<a href="https://ctipilot.ch/briefs/2026-06-26/" target="_blank" rel="noopener noreferrer">daily 06-26</a>, <a href="https://ctipilot.ch/briefs/2026-06-27/" target="_blank" rel="noopener noreferrer">daily 06-27</a>, <a href="https://ctipilot.ch/briefs/2026-06-28/" target="_blank" rel="noopener noreferrer">daily 06-28</a>)</p><div class="prov"><span>synthesis</span><span>29 Jun 00:20Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/shinyhunters-unc6240-one-cluster-multiple-reported-tradecraf/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.computerweekly.com/news/366645159/Canvas-breach-hit-160-UK-unis-but-caused-limited-damage" target="_blank" rel="noopener noreferrer">Computer Weekly — Canvas/CMC review</a> · <a href="https://www.404media.co/how-hackers-broke-into-madison-square-garden/" target="_blank" rel="noopener noreferrer">404 Media — MSG vishing</a> · <a href="https://abnormal.ai/blog/shinyhunters-sso-social-engineering-mfa-identity-compromise" target="_blank" rel="noopener noreferrer">Abnormal Security — ShinyHunters SSO vishing TTP</a></div></article><article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-ai-moved-from-target-to-operator" data-tags="ai-abuse supply-chain ransomware phishing" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-07-05T23:27:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="weekly-w27-ai-moved-from-target-to-operator"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-ai-moved-from-target-to-operator/">This week AI crossed from attack target to attack operator — agentic ransomware, coerced coding agents, and LLM-output poisoning</a></h3><p>The prior weekly&#39;s research lens was &quot;the AI agent and toolchain control plane became a <em>target</em>.&quot; Four independent disclosures this week move the frame: AI is now showing up as the <strong>operator</strong> of an intrusion and as the <strong>delivery channel</strong> for one, not just the thing being attacked.</p>
<p><strong>AI as operator.</strong> Sysdig documented <strong>JADEPUFFER</strong>, which it assesses to be the first end-to-end ransomware operation driven by an LLM rather than a human — entering through an unpatched, internet-exposed Langflow (CVE-2025-3248, on CISA KEV since May 2025), then autonomously sweeping credentials, forging a Nacos JWT from a documented default signing key, probing for container escape, and encrypting 1,342 Nacos config items with a never-persisted key (<a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion" target="_blank" rel="noopener noreferrer">Sysdig, 2026-07-01</a>). Sysdig&#39;s own framing is that the novelty is the operator, not the vulnerabilities — every step exploited a known, patchable exposure, but agentic tooling collapsed the skill floor to chain recon-through-destruction into one automated run (§ references, covered operationally 07-04).</p>
<p><strong>AI as the thing attackers subvert to reach you.</strong> Mozilla 0DIN showed a &quot;clean&quot; GitHub repo — no malicious code to flag on static analysis — coercing an AI coding agent into a reverse shell through three levels of indirection (error message → DNS TXT lookup → shell execution), so the agent &quot;never decided to open a shell; it decided to fix an error&quot; (<a href="https://0din.ai/blog/clone-this-repo-and-i-own-your-machine" target="_blank" rel="noopener noreferrer">Mozilla 0DIN, 2026-06-25</a>).</p>
<p><strong>AI as the delivery layer.</strong> Unit 42&#39;s <strong>Phantom Squatting</strong> pre-registers the specific domains a production LLM hallucinates when asked for URLs, so later users or agent-browsers are handed attacker infrastructure with zero reputation history to flag (<a href="https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-07-01</a>). And Kaspersky&#39;s June telemetry shows a community AI-agent &quot;skill&quot; marketplace still distributing malicious <code>SKILL.md</code> files that run with the tokens and file-system access of whatever they touch (<a href="https://securelist.com/openclaw-security/120484/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-07-01</a>).</p>
<p><strong>Weekly takeaway:</strong> for a SOC that increasingly runs AI coding agents in CI/CD and developer workstations and is beginning to field agentic tooling, the strategic obligation is to treat every agent capability — shell, repo access, browsing, third-party skills — as a privilege scope that needs an explicit grant and human-in-the-loop gating, and to recognise that none of these attacks needed a novel software bug: they exploited agent autonomy plus the same neglected, internet-exposed infrastructure defenders already owe a patch. Per-technique detail and detection concepts in § references.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The Sysdig Threat Research Team (TRT) has captured what we assess to be the first documented case of agentic ransomware: a complete extortion operation driven end-to-end by a large language model (LLM).</p><figcaption class="entry-cite__attr"><a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion" target="_blank" rel="noopener noreferrer">Sysdig Threat Research Team</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">Claude Code never decided to open a shell. It decided to fix an error. The reverse shell is three indirection steps away from anything Claude Code actually evaluated</p><figcaption class="entry-cite__attr"><a href="https://0din.ai/blog/clone-this-repo-and-i-own-your-machine" target="_blank" rel="noopener noreferrer">Mozilla 0DIN</a></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-04/jadepuffer-agentic-llm-ransomware-langflow-rce/">2026-07-04/jadepuffer-agentic-llm-ransomware-langflow-rce</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-29/mozilla-0din-a-clean-github-repo-coerces-ai-coding-agents-in/">2026-06-29/mozilla-0din-a-clean-github-repo-coerces-ai-coding-agents-in</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/unit-42-phantom-squatting-registering-ai-hallucinated-domain/">2026-07-01/unit-42-phantom-squatting-registering-ai-hallucinated-domain</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/kaspersky-community-ai-agent-skills-are-an-emerging-supply-c/">2026-07-02/kaspersky-community-ai-agent-skills-are-an-emerging-supply-c</a></p><div class="prov"><span>synthesis</span><span>05 Jul 23:27Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-ai-moved-from-target-to-operator/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion" target="_blank" rel="noopener noreferrer">Sysdig Threat Research Team</a> · <a href="https://0din.ai/blog/clone-this-repo-and-i-own-your-machine" target="_blank" rel="noopener noreferrer">Mozilla 0DIN</a> · <a href="https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/" target="_blank" rel="noopener noreferrer">Palo Alto Networks Unit 42</a> · <a href="https://securelist.com/openclaw-security/120484/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/npm-supply-chain-worms-a-sustained-wave-across-the-week" data-tags="supply-chain infostealer north-korea-nexus organized-crime" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-29T00:20:57Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="npm-supply-chain-worms-a-sustained-wave-across-the-week"><a href="https://ctipilot.ch/entries/2026-06-29/npm-supply-chain-worms-a-sustained-wave-across-the-week/">npm supply-chain worms — a sustained wave across the week</a></h3><p>Three separate npm-ecosystem supply-chain events were in play across the window, and the pattern is the story. Microsoft attributed the <a href="https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/" target="_blank" rel="noopener noreferrer">Mastra scope compromise</a> (140+ <code>@mastra</code> packages, <code>postinstall</code> dropper) to North Korea&#39;s Sapphire Sleet (covered in the daily on 06-21). JFrog documented <a href="https://research.jfrog.com/post/from-postcss-typosquat-to-windows-rat/" target="_blank" rel="noopener noreferrer">PostCSS typosquats</a> from the <code>abdrizak</code> account delivering a Nuitka-compiled Python RAT with Chrome DPAPI credential theft. And on 2026-06-25 Socket reported a <a href="https://socket.dev/blog/miasma-mini-shai-hulud-hits-leoplatform-npm-packages-go-ecosystem" target="_blank" rel="noopener noreferrer">fresh Miasma / &quot;Mini Shai-Hulud&quot; worm wave</a> across LeoPlatform/RStreams packages (carried in the daily 06-27), the self-propagating supply-chain worm last seen backdooring <code>@redhat-cloud-services</code>.</p>
<p>The synthesis: the npm registry is under continuous, parallel pressure from a state actor (DPRK), commodity typosquat crews and a self-replicating worm — three different operators, one ecosystem. The common control is the same one npm v12 is about to enforce by default: disable install scripts (<code>--ignore-scripts</code>), pin and review dependencies, and treat CI build-time package resolution as an attack surface. (<a href="https://ctipilot.ch/briefs/2026-06-21/" target="_blank" rel="noopener noreferrer">daily 06-21</a>, <a href="https://ctipilot.ch/briefs/2026-06-24/" target="_blank" rel="noopener noreferrer">daily 06-24</a>, <a href="https://ctipilot.ch/briefs/2026-06-27/" target="_blank" rel="noopener noreferrer">daily 06-27</a>)</p><div class="prov"><span>synthesis</span><span>29 Jun 00:20Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/npm-supply-chain-worms-a-sustained-wave-across-the-week/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://socket.dev/blog/miasma-mini-shai-hulud-hits-leoplatform-npm-packages-go-ecosystem" target="_blank" rel="noopener noreferrer">Socket Security — Miasma</a> · <a href="https://research.jfrog.com/post/from-postcss-typosquat-to-windows-rat/" target="_blank" rel="noopener noreferrer">JFrog — PostCSS RAT</a> · <a href="https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/" target="_blank" rel="noopener noreferrer">Microsoft — Mastra</a></div></article><div class="sect" id="vulnerability-roll-up"><span class="n">03</span><span class="t">Vulnerability roll-up</span><span class="c">10 items</span></div><article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-vuln-status-rollup" data-tags="vulnerabilities actively-exploited cisa-kev rce patch-available" data-regions="global europe" data-kind="vulnerability" data-priority="high" data-discovered="2026-07-05T23:30:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="weekly-w27-vuln-status-rollup"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-vuln-status-rollup/">Vulnerability status roll-up — 2026-W27: what moved, what to patch on the exploited-flaw clock vs the monthly cycle</a></h3><p>This is the week&#39;s vulnerability state as a single scannable view — the CVE detail and full sourcing live in the operational entries that first covered each item (§ references); the value here is the current status and the patch-priority framing.</p>
<p><strong>Newly exploited / KEV-listed this week (assume-compromise if exposed and unpatched).</strong> SimpleHelp RMM <strong>CVE-2026-48558</strong> (CVSS 10.0 OIDC auth bypass) moved to active exploitation + CISA KEV, deploying the Djinn infostealer (this week&#39;s top story). Oracle E-Business Suite <strong>CVE-2026-46817</strong> (pre-auth RCE) saw its first in-the-wild exploitation. Microsoft SharePoint Server <strong>CVE-2026-45659</strong> (CWE-502 deserialization, Site-Member RCE) was added to CISA KEV on 2026-07-01 — the first public confirmation of exploitation, and notable because Microsoft&#39;s own advisory still rates it &quot;Exploitation Less Likely,&quot; a contradiction defenders should resolve toward the exploitation evidence (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45659" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a>; <a href="https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json" target="_blank" rel="noopener noreferrer">CISA KEV feed, 2026-07-01</a>). Progress Kemp LoadMaster <strong>CVE-2026-8037</strong> (pre-auth RCE) drew exploitation attempts the day its PoC dropped (covered in this week&#39;s edge-appliance entry).</p>
<p><strong>Working exploit or public PoC (patch on emergency cadence).</strong> DirtyClone Linux-kernel LPE <strong>CVE-2026-43503</strong> now has a confirmed working exploit on default Debian/Fedora; the libssh2 pre-auth heap write <strong>CVE-2026-55200</strong> has a public PoC; Citrix NetScaler <strong>CVE-2026-8451</strong> has a public susceptibility-testing artefact.</p>
<p><strong>Weaponisation-likely, not yet exploited (patch before the PoC lands).</strong> Adobe&#39;s APSB26-68 fixed <strong>six CVSS 10.0</strong> unauthenticated RCE paths in ColdFusion 2025/2023 — two unrestricted-file-upload, three input-validation, one path-traversal — all Adobe Priority 1 (&quot;high risk of being targeted&quot;), with Adobe stating no known in-the-wild exploits yet; ColdFusion&#39;s history of rapid weaponisation of unauth file-upload primitives makes this a same-week patch priority for any internet-facing instance (<a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html" target="_blank" rel="noopener noreferrer">Adobe PSIRT APSB26-68, 2026-06-30</a>). Control Web Panel <strong>CVE-2026-57517</strong> (pre-auth SQLi→RCE) and Coolify <strong>CVE-2026-34038</strong> (authenticated command injection, CVSS 9.9) round out the high-impact patch set.</p>
<p><strong>Also patched this week (standard cycle, no exploitation):</strong> Gogs <strong>CVE-2026-52806</strong> (now abused for cryptojacking), the SzafirHost e-signature client JAR parser-confusion RCE <strong>CVE-2026-13165</strong> (CERT Polska — EU public-sector e-signature relevance), Altium Enterprise Server <strong>CVE-2026-14439</strong>, and cve-search <strong>CVE-2026-59509</strong>. Full per-CVE detail in § references.</p><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/cve-2026-48558-simplehelp-rmm-oidc-sso-authentication-bypass/">2026-06-30/cve-2026-48558-simplehelp-rmm-oidc-sso-authentication-bypass</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/oracle-e-business-suite-cve-2026-46817-pre-auth-rce-in-the-p/">2026-07-01/oracle-e-business-suite-cve-2026-46817-pre-auth-rce-in-the-p</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/cve-2026-45659-microsoft-sharepoint-server-authenticated-des/">2026-07-02/cve-2026-45659-microsoft-sharepoint-server-authenticated-des</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/kemp-loadmaster-cve-2026-8037-exploitation-attempts-confirme/">2026-07-02/kemp-loadmaster-cve-2026-8037-exploitation-attempts-confirme</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/dirtyclone-linux-kernel-lpe-cve-2026-43503-now-has-a-confirm/">2026-06-30/dirtyclone-linux-kernel-lpe-cve-2026-43503-now-has-a-confirm</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/public-poc-released-for-the-libssh2-pre-auth-heap-write-cve/">2026-06-30/public-poc-released-for-the-libssh2-pre-auth-heap-write-cve</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem/">2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/cve-2026-48276-48277-48281-48282-48283-48316-adobe-coldfusio/">2026-07-02/cve-2026-48276-48277-48281-48282-48283-48316-adobe-coldfusio</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-03/cve-2026-57517-control-web-panel-pre-auth-sqli-to-rce/">2026-07-03/cve-2026-57517-control-web-panel-pre-auth-sqli-to-rce</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-03/cve-2026-34038-coolify-authenticated-command-injection-to-rc/">2026-07-03/cve-2026-34038-coolify-authenticated-command-injection-to-rc</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a/">2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/cert-polska-discloses-a-jar-parser-confusion-rce-in-the-szaf/">2026-06-30/cert-polska-discloses-a-jar-parser-confusion-rce-in-the-szaf</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic/">2026-07-02/cve-2026-14439-altium-enterprise-server-altium-365-authentic</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-05/cve-2026-59509-cve-search-fetch-cve-data-nosql/">2026-07-05/cve-2026-59509-cve-search-fetch-cve-data-nosql</a></p><div class="prov"><span>vulnerability</span><span>05 Jul 23:30Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-vuln-status-rollup/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html" target="_blank" rel="noopener noreferrer">Adobe PSIRT (APSB26-68)</a> · <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45659" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a> · <a href="https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json" target="_blank" rel="noopener noreferrer">CISA KEV feed</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/cve-2026-11800-jwt-algorithm-confusion-and-cve-2026-9800-pol" data-tags="vulnerabilities auth-bypass identity patch-available" data-regions="europe switzerland global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:21:05Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-11800/">CVE-2026-11800 +1</a></div><h3 class="f-h" id="cve-2026-11800-jwt-algorithm-confusion-and-cve-2026-9800-pol"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2026-11800-jwt-algorithm-confusion-and-cve-2026-9800-pol/">CVE-2026-11800 (JWT algorithm-confusion) and CVE-2026-9800 (policy-enforcer authz bypass) — Keycloak identity-plane fixes</a></h3><p>Keycloak 26.6.4 <a href="https://www.keycloak.org/2026/06/keycloak-2664-released" target="_blank" rel="noopener noreferrer">fixed eight CVEs</a>. The headline flaw is CVE-2026-11800, a JWT algorithm-confusion that lets an attacker with valid client credentials forge an assertion, bypass signature verification and impersonate any federated user behind the affected identity provider (<a href="https://github.com/advisories/GHSA-gqj5-2xp5-3qmp" target="_blank" rel="noopener noreferrer">GHSA-gqj5-2xp5-3qmp</a>, <a href="https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2093" target="_blank" rel="noopener noreferrer">BSI WID-SEC-2026-2093</a>); the bundled CVE-2026-9800 is a separate policy-enforcer authorization bypass via incorrect URI comparison. Keycloak is the IdP of choice across European public-sector, healthcare and finance deployments — these are identity-plane breaks, not app bugs. Patch to 26.6.4.</p><div class="prov"><span>vulnerability</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2026-11800-jwt-algorithm-confusion-and-cve-2026-9800-pol/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.keycloak.org/2026/06/keycloak-2664-released" target="_blank" rel="noopener noreferrer">Keycloak Project release notes</a> · <a href="https://github.com/advisories/GHSA-gqj5-2xp5-3qmp" target="_blank" rel="noopener noreferrer">GitHub Advisory GHSA-gqj5-2xp5-3qmp</a> · <a href="https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2093" target="_blank" rel="noopener noreferrer">BSI WID-SEC-2026-2093</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/cve-2026-58053-gitea-act-runner-docker-backend-container-har" data-tags="vulnerabilities poc-public priv-esc rce enisa-critical" data-regions="global europe switzerland" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:21:04Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-58053/">CVE-2026-58053</a></div><h3 class="f-h" id="cve-2026-58053-gitea-act-runner-docker-backend-container-har"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2026-58053-gitea-act-runner-docker-backend-container-har/">CVE-2026-58053 — Gitea act_runner Docker backend: container-hardening bypass to host escape (public PoC, ENISA-critical)</a></h3><p>Gitea <code>act_runner</code> through 0.262.0 passes a workflow-defined <code>container.options</code> string straight into Docker&#39;s <code>HostConfig</code>, forcing only <code>Privileged=false</code> while merging <code>--pid=host</code>, <code>--cap-add</code> and <code>--security-opt</code> unchanged — a malicious workflow escapes the job container to the host (<a href="https://www.vulncheck.com/advisories/gitea-act-runner-container-hardening-bypass-via-workflow-container-options" target="_blank" rel="noopener noreferrer">VulnCheck</a>). Public PoC, CVSS 9.4, mitigation-only this week. Self-hosted Gitea CI is common in DACH developer shops and universities; restrict who can define workflow container options. The companion Gitea-core auth bypass via <code>X-WEBAUTH-USER</code> (CVE-2026-20896, <a href="https://blog.gitea.com/release-of-1.26.3-and-1.26.4" target="_blank" rel="noopener noreferrer">fixed in 1.26.3/1.26.4</a>) remains worth patching on the same estate.</p><div class="prov"><span>vulnerability</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2026-58053-gitea-act-runner-docker-backend-container-har/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.vulncheck.com/advisories/gitea-act-runner-container-hardening-bypass-via-workflow-container-options" target="_blank" rel="noopener noreferrer">VulnCheck advisory</a> · <a href="https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-58053" target="_blank" rel="noopener noreferrer">ENISA EUVD EUVD-2026-58053</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/cve-2026-34908-cve-2026-34909-cve-2026-34910-ubiquiti-unifi" data-tags="vulnerabilities actively-exploited cisa-kev pre-auth rce auth-bypass patch-available" data-regions="global europe dach" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:21:01Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-34908/">CVE-2026-34908 +2</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-34908-cve-2026-34909-cve-2026-34910-ubiquiti-unifi"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2026-34908-cve-2026-34909-cve-2026-34910-ubiquiti-unifi/">CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 — Ubiquiti UniFi OS Server: pre-auth RCE chain, exploited (CISA KEV)</a></h3><p>Three max-severity (CVSS 10.0) flaws in UniFi OS Server — improper access control and path traversal that bypass authentication and reach an unauthenticated RCE endpoint — were <a href="https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-unifi-os-vulnerabilities/" target="_blank" rel="noopener noreferrer">patched and KEV-listed</a> with confirmed exploitation. UniFi controllers are common in DACH SME, education and public-sector branch networks; the management plane is frequently exposed. Patch and audit controller-account integrity.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Three max-severity (CVSS 10.0) flaws in UniFi OS Server — improper access control and path traversal that bypass authentication and reach an unauthenticated RCE endpoint — were patched and KEV-listed with confirmed exploitation.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2026-34908-cve-2026-34909-cve-2026-34910-ubiquiti-unifi/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-unifi-os-vulnerabilities/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.scworld.com/brief/ubiquiti-unifi-os-server-vulnerabilities-allow-unauthenticated-remote-code-execution" target="_blank" rel="noopener noreferrer">SC Media</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una" data-tags="vulnerabilities actively-exploited cisa-kev pre-auth rce ot-ics patch-available" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:21:00Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-67038/">CVE-2025-67038</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una/">CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converters: unauthenticated command injection to root (BRIDGE:BREAK, CISA KEV)</a></h3><p>Forescout Vedere Labs&#39; <a href="https://www.forescout.com/blog/exploiting-serial-to-ethernet-converters-in-critical-infrastructure/" target="_blank" rel="noopener noreferrer">BRIDGE:BREAK research</a> documented an unauthenticated OS command-injection flaw in Lantronix EDS5000-series device servers — the HTTP management interface concatenates unsanitised input into a shell call. The in-window development is its CISA KEV listing on 2026-06-23 with confirmed in-the-wild exploitation (covered in <a href="https://ctipilot.ch/briefs/2026-06-24/" target="_blank" rel="noopener noreferrer">daily 06-24</a>) — the first BRIDGE:BREAK flaw to flip from research to active abuse. Serial-to-IP converters sit in front of OT, building-management and medical serial devices; firmware 2.0.0R1 closes it. This is an energy/water/healthcare exposure, not an IT one.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Forescout Vedere Labs&#39; BRIDGE:BREAK research documented an unauthenticated OS command-injection flaw in Lantronix EDS5000-series device servers — the HTTP management interface concatenates unsanitised input into a shell call.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2025-67038-lantronix-eds5000-serial-to-ip-converters-una/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.forescout.com/blog/exploiting-serial-to-ethernet-converters-in-critical-infrastructure/" target="_blank" rel="noopener noreferrer">Forescout Vedere Labs — BRIDGE:BREAK</a> · <a href="https://www.securityweek.com/serial-to-ip-converter-flaws-expose-ot-and-healthcare-systems-to-hacking/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/cve-2026-20245-cisco-catalyst-sd-wan-manager-mandiant-recons" data-tags="vulnerabilities actively-exploited priv-esc rce patch-available" data-regions="global switzerland" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:20:59Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20245/">CVE-2026-20245</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-20245-cisco-catalyst-sd-wan-manager-mandiant-recons"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2026-20245-cisco-catalyst-sd-wan-manager-mandiant-recons/">CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: Mandiant reconstructs the full zero-day chain</a></h3><p>Mandiant (GTIG) <a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager" target="_blank" rel="noopener noreferrer">published the first complete TTP chain</a> on 06-24 for the Catalyst SD-WAN Manager zero-day activity, observed at a service provider: a peering/authentication bypass (CVE-2026-20127, CVE-2026-20182) leading to credential manipulation, then local privilege escalation to root via a malicious CSV upload (CVE-2026-20245) to plant a root backdoor. NCSC-CH <a href="https://security-hub.ncsc.admin.ch/#/posts/12579" target="_blank" rel="noopener noreferrer">posted on it</a>, giving it direct Swiss relevance. Telco and public-sector SD-WAN operators should hunt for unexpected file writes under the web-UI service account and root-owned artefacts post-dating the patch.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Mandiant (GTIG) published the first complete TTP chain on 06-24 for the Catalyst SD-WAN Manager zero-day activity, observed at a service provider: a peering/authentication bypass (CVE-2026-20127, CVE-2026-20182) leading to credential manipulation, then local privilege escalation to root via a …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>29 Jun 00:20Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2026-20245-cisco-catalyst-sd-wan-manager-mandiant-recons/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/zero-day-exploitation-cisco-catalyst-sd-wan-manager" target="_blank" rel="noopener noreferrer">Google Mandiant (GTIG)</a> · <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio" data-tags="vulnerabilities actively-exploited rce pre-auth cisa-kev" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:20:58Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-12569/">CVE-2026-12569</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/">CVE-2026-12569 — PTC Windchill / FlexPLM: pre-auth deserialization RCE, now confirmed exploited with JSP web shells (CISA KEV)</a></h3><p>When first covered (06-20) and in the W25 weekly this was a pre-auth deserialization flaw with BSI escalating to admins out-of-hours. The in-window delta: CISA <a href="https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html" target="_blank" rel="noopener noreferrer">added it to KEV on 06-25</a> and JSP web-shell deployment against the login interface is now confirmed in the wild. Any internet-reachable Windchill PDMLink or FlexPLM instance should be treated as assume-compromise — manufacturing and defence-supplier PLM is exactly the externally-reachable engineering surface a Swiss/EU industrial estate forgets to inventory.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">When first covered (06-20) and in the W25 weekly this was a pre-auth deserialization flaw with BSI escalating to admins out-of-hours.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>29 Jun 00:20Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/06/cisa-adds-exploited-ptc-windchill-rce.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-37831" target="_blank" rel="noopener noreferrer">ENISA EUVD EUVD-2026-37831</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/cve-2026-55200-cve-2026-55199-libssh2-heap-out-of-bounds-wri" data-tags="vulnerabilities poc-public rce dos" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:21:06Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-55200/">CVE-2026-55200 +1</a></div><h3 class="f-h" id="cve-2026-55200-cve-2026-55199-libssh2-heap-out-of-bounds-wri"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2026-55200-cve-2026-55199-libssh2-heap-out-of-bounds-wri/">CVE-2026-55200 / CVE-2026-55199 — libssh2 heap out-of-bounds write with public PoC</a></h3><p>The GitHub Security Advisory <a href="https://github.com/advisories/GHSA-r8mh-x5qv-7gg2" target="_blank" rel="noopener noreferrer">GHSA-r8mh-x5qv-7gg2</a> describes a heap out-of-bounds write in libssh2&#39;s <code>ssh2_transport_read()</code> that fails to enforce an upper bound on the <code>packet_length</code> field (CVSS 9.2), with a companion pre-auth DoS (CVE-2026-55199) corroborated by <a href="https://advisories.ncsc.nl/2026/ncsc-2026-0210.html" target="_blank" rel="noopener noreferrer">NCSC-NL NCSC-2026-0210</a>; public PoC code was reported within the window (see <a href="https://ctipilot.ch/briefs/2026-06-28/" target="_blank" rel="noopener noreferrer">daily 06-28</a>). An upstream fix has landed (the GHSA references the fix commit), but tagged-release availability still varies across the binding and appliance ecosystem — so the operational task is SBOM exposure tracking and chasing each embedding vendor&#39;s release, not a single library bump (. libssh2 is embedded in a long tail of management tooling, appliances and language bindings.</p><div class="prov"><span>vulnerability</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2026-55200-cve-2026-55199-libssh2-heap-out-of-bounds-wri/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://github.com/advisories/GHSA-r8mh-x5qv-7gg2" target="_blank" rel="noopener noreferrer">GitHub Advisory GHSA-r8mh-x5qv-7gg2</a> · <a href="https://advisories.ncsc.nl/2026/ncsc-2026-0210.html" target="_blank" rel="noopener noreferrer">NCSC-NL NCSC-2026-0210</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/cve-2026-43503-dirtyclone-and-cve-2026-46331-pedit-cow-linux" data-tags="vulnerabilities lpe priv-esc poc-public patch-available" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:21:03Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-43503/">CVE-2026-43503 +1</a></div><h3 class="f-h" id="cve-2026-43503-dirtyclone-and-cve-2026-46331-pedit-cow-linux"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2026-43503-dirtyclone-and-cve-2026-46331-pedit-cow-linux/">CVE-2026-43503 (DirtyClone) and CVE-2026-46331 (pedit COW) — Linux kernel LPE with public weaponised PoCs</a></h3><p>Two page-cache-corruption local-privilege-escalation flaws drew working exploits within the window. JFrog <a href="https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/" target="_blank" rel="noopener noreferrer">published a full DirtyClone walkthrough</a> (XFRM/IPsec skb cloning) on 06-25; a companion <code>tc act_pedit</code> out-of-bounds write (<code>pedit COW</code>) gained a <a href="https://thehackernews.com/2026/06/new-linux-pedit-cow-exploit-enables.html" target="_blank" rel="noopener noreferrer">weaponised PoC</a> within a day of assignment. Both are post-auth root escalation on patched-but-unrebooted hosts — prioritise kernel updates on multi-tenant and internet-exposed Linux where an initial foothold is plausible.</p><div class="prov"><span>vulnerability</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2026-43503-dirtyclone-and-cve-2026-46331-pedit-cow-linux/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://research.jfrog.com/post/dissecting-and-exploiting-linux-lpe-variant-dirtyclone-cve-2026-43503/" target="_blank" rel="noopener noreferrer">JFrog Security Research</a> · <a href="https://access.redhat.com/security/vulnerabilities/RHSB-2026-008" target="_blank" rel="noopener noreferrer">Red Hat RHSB-2026-008</a> · <a href="https://thehackernews.com/2026/06/new-linux-pedit-cow-exploit-enables.html" target="_blank" rel="noopener noreferrer">The Hacker News — pedit COW</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/cve-2026-20230-cisco-unified-cm-webdialer-pre-auth-ssrf-to-a" data-tags="vulnerabilities actively-exploited pre-auth poc-public patch-available rce" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-29T00:21:02Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20230/">CVE-2026-20230</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-20230-cisco-unified-cm-webdialer-pre-auth-ssrf-to-a"><a href="https://ctipilot.ch/entries/2026-06-29/cve-2026-20230-cisco-unified-cm-webdialer-pre-auth-ssrf-to-a/">CVE-2026-20230 — Cisco Unified CM WebDialer: pre-auth SSRF to arbitrary root file write, reconnaissance-stage scanning observed</a></h3><p>Cisco PSIRT&#39;s advisory describes an SSRF in the WebDialer service of Unified CM 14/15 that lets an unauthenticated attacker write files to the OS and later escalate to root. The in-window signal: <a href="https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">exploitation moved to reconnaissance stage</a>, with a PoC that fingerprints vulnerable devices. Unified CM is core telephony for many cantonal and hospital networks — patch before the scanning becomes exploitation.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Cisco PSIRT&#39;s advisory describes an SSRF in the WebDialer service of Unified CM 14/15 that lets an unauthenticated attacker write files to the OS and later escalate to root.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/cve-2026-20230-cisco-unified-cm-webdialer-pre-auth-ssrf-to-a/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW" target="_blank" rel="noopener noreferrer">Cisco PSIRT advisory cisco-sa-cucm-ssrf-cXPnHcW</a> · <a href="https://www.bleepingcomputer.com/news/security/cisco-unified-cm-sme-flaw-cve-2026-20230-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article><div class="sect" id="sector-victim-patterns"><span class="n">04</span><span class="t">Sector &amp; victim patterns</span><span class="c">5 items</span></div><article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-government-targeting-ch-eu" data-tags="data-breach espionage mobile ransomware" data-regions="switzerland europe us" data-kind="synthesis" data-priority="high" data-discovered="2026-07-05T23:31:00Z"><div class="badges"><span class="b pri">HIGH</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="weekly-w27-government-targeting-ch-eu"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-government-targeting-ch-eu/">Government and public administration took three distinct hits this week — a Swiss cantonal leak-site claim, a Pegasus-infected MEP, and a US federal info-sharing breach</a></h3><p>Three unrelated events this week share one thing: the victim is a public institution, and each demonstrates a different way government is reached — extortion branding, mercenary spyware, and inter-agency trust boundaries. For a Swiss federal SOC the value is the pattern across the target class, not any single incident.</p>
<p><strong>A Swiss cantonal department on a leak site (unconfirmed).</strong> MedusaLocker listed a victim &quot;Bd&quot; with domain <strong>bd.zh.ch</strong> — the Baudirektion of the Canton of Zürich — on 2026-07-01, claiming 772 extracted emails, as part of a batch-style posting wave that also listed a French municipality and other European entities in immediate succession (<a href="https://www.ransomware.live/id/QmRAbWVkdXNhbG9ja2Vy" target="_blank" rel="noopener noreferrer">Ransomware.live, 2026-07-01</a>). This is a dark-web claim only: no cantonal statement, no NCSC.ch (BACS) advisory, no independent Swiss press coverage exists in-window. It is a situational-awareness signal for cantonal-government readers, not a confirmed breach — but batch-listing of European public bodies is itself the operational note (§ references).</p>
<p><strong>A Pegasus-infected European Parliament oversight member.</strong> Citizen Lab confirmed with high confidence that the iPhone of former MEP Stelios Kouloglou — who sat on the Parliament&#39;s PEGA committee investigating commercial-spyware abuse — was infected with NSO Group&#39;s Pegasus twice (Oct 2022 and Mar 2023) via the zero-click PWNYOURHOME chain (a crafted <code>NSKeyedArchive</code> landing in the HomeKit daemon, then malicious content in <code>MessagesBlastDoorService</code>) (<a href="https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/" target="_blank" rel="noopener noreferrer">Citizen Lab, 2026-07-03</a>). The targeting infrastructure overlaps a Pegasus operator also hitting Russian/Belarusian-speaking exiles in Europe. Infecting the person scrutinising spyware abuse is an EU parliamentary-privilege concern, and the defensive surface for high-risk officials is proactive mobile forensics plus enforced Lockdown Mode — not endpoint alerting.</p>
<p><strong>A US federal information-sharing platform.</strong> DHS confirmed a breach of the Homeland Security Information Network — the platform federal/state/local/international/private-sector partners use to exchange sensitive-but-unclassified information — with intrusion believed to be late-May–early-June and a SharePoint collaboration system implicated; DHS says no classified networks were impacted (<a href="https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-01</a>). Both this and HSIN&#39;s 2023 incident trace to collaboration-platform trust boundaries rather than perimeter exploitation.</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">government cross-org information-sharing portals are a recurring soft target — the transferable lesson for European public-sector SOCs running equivalent partner portals is to audit standing access and download-anomaly alerting on those platforms specifically. Detail on each event in § references.</div></aside><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/medusalocker-leak-site-lists-the-canton-of-z-rich-s-baudirek/">2026-07-02/medusalocker-leak-site-lists-the-canton-of-z-rich-s-baudirek</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-03/citizen-lab-pega-committee-mep-infected-with-pegasus/">2026-07-03/citizen-lab-pega-committee-mep-infected-with-pegasus</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/dhs-confirms-a-breach-of-the-homeland-security-information-n/">2026-07-02/dhs-confirms-a-breach-of-the-homeland-security-information-n</a></p><div class="prov"><span>synthesis</span><span>05 Jul 23:31Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-government-targeting-ch-eu/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/" target="_blank" rel="noopener noreferrer">Citizen Lab</a> · <a href="https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.ransomware.live/id/QmRAbWVkdXNhbG9ja2Vy" target="_blank" rel="noopener noreferrer">Ransomware.live</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/technology-saas-supply-chain-the-week-s-busiest-victim-class" data-tags="supply-chain data-breach identity" data-regions="global europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-29T00:21:10Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="technology-saas-supply-chain-the-week-s-busiest-victim-class"><a href="https://ctipilot.ch/entries/2026-06-29/technology-saas-supply-chain-the-week-s-busiest-victim-class/">Technology &amp; SaaS supply chain — the week&#39;s busiest victim class</a></h3><p>The dominant pattern of the week was the third party as entry vector: Klue/Icarus (Salesforce OAuth, ~24 firms), ShapedPlugin (WordPress build pipeline), the npm worm wave, 8x8&#39;s SEC-disclosed Salesforce theft, and the BadBlocker Chrome extension (§ 6). In nearly every case the victim organisation patched nothing wrong of its own — the compromise rode in through a trusted vendor, integration token, package or browser extension.</p><div class="prov"><span>synthesis</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/technology-saas-supply-chain-the-week-s-busiest-victim-class/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/" target="_blank" rel="noopener noreferrer">SecurityWeek — Klue victims</a> · <a href="https://www.wordfence.com/blog/2026/06/psa-supply-chain-compromise-targets-shapedplugin-backdoored-pro-plugins-distributed-via-official-channels/" target="_blank" rel="noopener noreferrer">Wordfence — ShapedPlugin</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/education" data-tags="data-breach vulnerabilities sqli" data-regions="uk dach europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-29T00:21:09Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="education"><a href="https://ctipilot.ch/entries/2026-06-29/education/">Education</a></h3><p>Education was a structural victim class. The ShinyHunters Canvas/Instructure breach <a href="https://www.computerweekly.com/news/366645159/Canvas-breach-hit-160-UK-unis-but-caused-limited-damage" target="_blank" rel="noopener noreferrer">hit 160 UK universities</a> per the UK CMC sector review (ransom paid, limited downstream damage). The unpatched ILIAS 11.0 SQL-injection (<a href="https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2016" target="_blank" rel="noopener noreferrer">CVE-2026-12789</a>, PoC-public, no patch) directly exposes the DACH learning-management estate, and self-hosted Gitea CI (§ 3) is concentrated in universities. The common thread: education runs exposed CMS/LMS/forum and developer stacks with thin operational security.</p><div class="prov"><span>synthesis</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/education/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.computerweekly.com/news/366645159/Canvas-breach-hit-160-UK-unis-but-caused-limited-damage" target="_blank" rel="noopener noreferrer">Computer Weekly — Canvas</a> · <a href="https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2016" target="_blank" rel="noopener noreferrer">BSI WID-SEC-2026-2016 — ILIAS</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/healthcare" data-tags="data-breach ransomware supply-chain" data-regions="us uk europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-29T00:21:08Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="healthcare"><a href="https://ctipilot.ch/entries/2026-06-29/healthcare/">Healthcare</a></h3><p>Third-party processors drove the week&#39;s healthcare exposure. <a href="https://www.hipaajournal.com/xsolis-data-breach/" target="_blank" rel="noopener noreferrer">Xsolis</a>, a healthcare-AI utilization-management vendor, disclosed a phishing-driven breach affecting 1,396,519 patients across seven US health systems — the data sat at the processor, not the hospitals. The UK&#39;s HCRG Care Group <a href="https://hipaapulse.com/uk-more-than-one-year-later-hcrg-is-first-notifying-patients-of-33ec763c" target="_blank" rel="noopener noreferrer">began notifying patients</a> of a February 2025 Medusa ransomware attack — a 16-month notification lag. The Lantronix BRIDGE:BREAK flaw (§ 3) additionally exposes serial-attached medical devices.</p><div class="prov"><span>synthesis</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/healthcare/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.hipaajournal.com/xsolis-data-breach/" target="_blank" rel="noopener noreferrer">HIPAA Journal — Xsolis</a> · <a href="https://hipaapulse.com/uk-more-than-one-year-later-hcrg-is-first-notifying-patients-of-33ec763c" target="_blank" rel="noopener noreferrer">HIPAA Pulse — HCRG</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/public-administration-government" data-tags="phishing hacktivism data-breach" data-regions="switzerland europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-29T00:21:07Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="public-administration-government"><a href="https://ctipilot.ch/entries/2026-06-29/public-administration-government/">Public administration &amp; government</a></h3><p>The week&#39;s public-sector signal is heavily Swiss/European. NCSC-CH reported an <a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/wochenrueckblick_25.html" target="_blank" rel="noopener noreferrer">active Microsoft 365 &quot;voicemail&quot; phishing wave</a> in Switzerland delivering infostealers and harvesting M365 credentials, with chain-phishing onward from compromised mailboxes. The <a href="https://www.swisscybersecurity.net/news/2026-06-19/neue-cyberaufsicht-kaempft-mit-anlaufschwierigkeiten" target="_blank" rel="noopener noreferrer">Swiss Federal Audit Office reported</a> that the two-year-old split of federal cyber-governance leaves strategic oversight without a complete incident picture — a structural finding for any federated public administration. Further afield, Ukraine&#39;s postal operator Ukrposhta had <a href="https://therecord.media/ukraine-state-postal-operator-reports-disruption" target="_blank" rel="noopener noreferrer">digital services disrupted</a> by an overnight attack, and Brazil&#39;s national Cell Broadcast alert platform was <a href="https://thenextweb.com/news/brazil-civil-defense-alert-hack-misanthropy-cell-broadcast" target="_blank" rel="noopener noreferrer">hijacked to push fake emergency messages</a> to ~30M phones — a reminder that government alerting infrastructure is itself a target.</p><div class="prov"><span>synthesis</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/public-administration-government/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/wochenrueckblick_25.html" target="_blank" rel="noopener noreferrer">NCSC-CH Wochenrückblick Week 25</a> · <a href="https://www.swisscybersecurity.net/news/2026-06-19/neue-cyberaufsicht-kaempft-mit-anlaufschwierigkeiten" target="_blank" rel="noopener noreferrer">SwissCybersecurity.net — EFK audit</a> · <a href="https://therecord.media/ukraine-state-postal-operator-reports-disruption" target="_blank" rel="noopener noreferrer">The Record — Ukrposhta</a></div></article><div class="sect" id="incidents-disclosures-recap"><span class="n">05</span><span class="t">Incidents &amp; disclosures recap</span><span class="c">5 items</span></div><article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-extortion-without-encryption" data-tags="ransomware data-breach organized-crime" data-regions="global us switzerland" data-kind="incident" data-priority="notable" data-discovered="2026-07-05T23:32:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="weekly-w27-extortion-without-encryption"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-extortion-without-encryption/">Data-theft extortion without an encryptor keeps maturing — a US county paid ~$1M to Kairos with no encryptor recovered</a></h3><p>The week&#39;s incident cases reinforce a shift that has been building through 2026: extortion is decoupling from encryption. The concrete anchor is Kairos.</p>
<p>Ransom-ISAC published a case study of a US county government that paid roughly <strong>$1 million</strong> to the data-theft extortion actor <strong>Kairos</strong> after an intrusion in which <strong>no encryptor was recovered</strong> — Ransom-ISAC obtained no locker binary and notes the actor&#39;s &quot;ransomware group&quot; status remains unverified, so the leverage was the threat to publish exfiltrated county data rather than encryption (<a href="https://ransom-isac.org/blog/kairos-ransomware-data-extortion-case-study/" target="_blank" rel="noopener noreferrer">Ransom-ISAC, 2026-07-03</a>). The intrusion itself is a 2025 case (demand mid-May, payment mid-June 2025) published as a retrospective this window, not a this-week breach. This is the pure form of a model that also showed up elsewhere in the week: MedusaLocker&#39;s leak-site listings (including the unconfirmed Canton of Zürich claim) trade on data-disclosure threat rather than demonstrated encryption, and the ShinyHunters cluster consolidated separately in this week&#39;s long-running status entry continues to extort on exfiltration alone, without a locker.</p>
<p><strong>Why it is strategic, not just another incident:</strong> for a decade the standard ransomware-resilience answer has been tested, offline, immutable backups — a posture that bounds the <em>availability</em> impact of encryption. Encryption-less data-theft extortion routes around that entirely: if the leverage is disclosure of citizen or employee PII, restoring from backup does not reduce the harm or the notification obligation. The defender consequence for a public-sector SOC is a re-weighting: exfiltration detection (anomalous large outbound transfers, cloud/SFTP staging), data minimisation on sensitive stores, and clear pre-agreed non-payment / notification playbooks matter as much as recovery engineering. The Kairos county case is a single-source 2025 retrospective case study (§ references) — treat the dollar figure as illustrative and the &quot;no encryptor&quot; as evidentiary absence, not proven — but the encryption-less-extortion pattern across this week&#39;s cases is the durable signal.</p><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout/">2026-07-05/kairos-data-theft-extortion-case-us-county-govt-1m-payout</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/medusalocker-leak-site-lists-the-canton-of-z-rich-s-baudirek/">2026-07-02/medusalocker-leak-site-lists-the-canton-of-z-rich-s-baudirek</a></p><div class="prov"><span>incident</span><span>05 Jul 23:32Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-extortion-without-encryption/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://ransom-isac.org/blog/kairos-ransomware-data-extortion-case-study/" target="_blank" rel="noopener noreferrer">Ransom-ISAC</a> · <a href="https://www.ransomware.live/id/QmRAbWVkdXNhbG9ja2Vy" target="_blank" rel="noopener noreferrer">Ransomware.live</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/attribution-and-accountability-jaguar-land-rover-and-scatter" data-tags="ransomware organized-crime law-enforcement russia-nexus" data-regions="uk europe" data-kind="incident" data-priority="notable" data-discovered="2026-06-29T00:21:13Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="attribution-and-accountability-jaguar-land-rover-and-scatter"><a href="https://ctipilot.ch/entries/2026-06-29/attribution-and-accountability-jaguar-land-rover-and-scatter/">Attribution and accountability: Jaguar Land Rover and Scattered Spider</a></h3><p>Two disclosures closed loops opened months ago. A <a href="https://techcrunch.com/2026/06/26/russian-hackers-were-behind-2-5-billion-hack-of-jaguar-land-rover-report/" target="_blank" rel="noopener noreferrer">New York Times investigation</a> gave the first named attribution for the 2025 Jaguar Land Rover ransomware attack — a Russian state-linked criminal group — though investigators have not determined whether the operators worked for, independently of, or with the tacit approval of the Russian government. And two Scattered Spider members <a href="https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted" target="_blank" rel="noopener noreferrer">pleaded guilty</a> over the 2024 Transport for London intrusion. Both reinforce that the dominant English-speaking extortion ecosystems are being mapped to named individuals and state-linked clusters.</p><div class="prov"><span>incident</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/attribution-and-accountability-jaguar-land-rover-and-scatter/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://techcrunch.com/2026/06/26/russian-hackers-were-behind-2-5-billion-hack-of-jaguar-land-rover-report/" target="_blank" rel="noopener noreferrer">TechCrunch — JLR/NYT</a> · <a href="https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted" target="_blank" rel="noopener noreferrer">UK National Crime Agency — TfL</a></div></article><article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-law-enforcement-momentum" data-tags="law-enforcement botnet organized-crime" data-regions="global" data-kind="incident" data-priority="notable" data-discovered="2026-07-05T23:33:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w27-law-enforcement-momentum"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-law-enforcement-momentum/">Law-enforcement and platform-disruption momentum this week — NetNut/Popa proxy botnet dismantled, StegoAd extension cluster killed, $10M bounty on Russia-nexus crews</a></h3><p>Three disruption actions this week are worth consolidating not as wins to celebrate but for what each says about the durability of the abused technique.</p>
<p><strong>NetNut (Popa) residential-proxy botnet dismantled.</strong> The FBI — with Google, Lumen and Shadowserver — seized NetNut/Popa infrastructure on 2026-07-02; Google disabled the Google accounts used for C2 and updated Play Protect to block apps bundling the malicious SDKs, while the FBI seized <code>netnut.com</code> (<a href="https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks" target="_blank" rel="noopener noreferrer">Google GTIG, 2026-07-02</a>; <a href="https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/" target="_blank" rel="noopener noreferrer">Krebs on Security, 2026-07-02</a>). The strategic figure GTIG surfaces is that in a single June week it observed <strong>316 distinct threat clusters</strong> — criminal and suspected-espionage — routing traffic through suspected NetNut exit nodes to mask origin IPs during password-spray, credential-stuffing and infrastructure access. That confirms residential-proxy relay as shared criminal/state infrastructure, and Google&#39;s own caution is the key defender note: degraded operators buy capacity from rivals, so proxy-based anonymisation volumes shift providers rather than dropping (§ references, operational coverage 07-04).</p>
<p><strong>StegoAd extension cluster.</strong> Microsoft disrupted StegoAd — 119 Edge extensions that hid payloads inside image and font files via steganography (<code>campaign:stegoad-darkspectre-119-edge-extensions-steganography</code>) — reinforcing browser-extension marketplaces as a recurring, disruptable delivery surface (this week&#39;s operational coverage, § references).</p>
<p><strong>$10M bounty on Russia-nexus crews.</strong> The US added a $10M bounty on the Russia-nexus Signal/WhatsApp phishing crews and folded Signal Backup-Recovery-Key theft into the advisory (this week&#39;s operational coverage, § references).</p>
<p><strong>Weekly takeaway:</strong> all three targets abuse infrastructure that is cheap to re-provision — residential proxies, browser extensions, messaging-app social engineering — so the correct posture for a SOC is to keep the <em>behavioural</em> detections (implausible residential-ASN auth sequences, extension-install governance, Signal backup-key hygiene for high-risk staff) running past the headlines, because the operators displaced this week reappear behind new providers. This week&#39;s Mustang Panda dead-drop-C2-via-Zoho-WorkDrive case (§ references) is the same lesson from the offensive side: abuse of legitimate, hard-to-block infrastructure is the through-line.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups.</p><p class="entry-cite__quote">Google Threat Intelligence Group (GTIG) estimates the size of the NetNut network to be at least 2 million devices, distributed across the world.</p><figcaption class="entry-cite__attr"><a href="https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks" target="_blank" rel="noopener noreferrer">Google Cloud (GTIG)</a></figcaption></figure></div><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-04/netnut-popa-residential-proxy-botnet-disrupted-by-google-fbi/">2026-07-04/netnut-popa-residential-proxy-botnet-disrupted-by-google-fbi</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/microsoft-disrupts-stegoad-119-edge-extensions-hid-payloads/">2026-06-30/microsoft-disrupts-stegoad-119-edge-extensions-hid-payloads</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/us-posts-10m-bounty-on-the-russia-nexus-signal-whatsapp-crew/">2026-06-30/us-posts-10m-bounty-on-the-russia-nexus-signal-whatsapp-crew</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe/">2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe</a></p><div class="prov"><span>incident</span><span>05 Jul 23:33Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-law-enforcement-momentum/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks" target="_blank" rel="noopener noreferrer">Google Cloud (GTIG)</a> · <a href="https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/" target="_blank" rel="noopener noreferrer">Krebs on Security</a> · <a href="https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/mass-third-party-exposures-xsolis-texas-parks-wildlife-canva" data-tags="data-breach supply-chain" data-regions="us uk" data-kind="incident" data-priority="notable" data-discovered="2026-06-29T00:21:12Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="mass-third-party-exposures-xsolis-texas-parks-wildlife-canva"><a href="https://ctipilot.ch/entries/2026-06-29/mass-third-party-exposures-xsolis-texas-parks-wildlife-canva/">Mass third-party exposures: Xsolis, Texas Parks &amp; Wildlife, Canvas</a></h3><p>Three large data exposures all traced to a third party rather than the named organisation: <a href="https://www.hipaajournal.com/xsolis-data-breach/" target="_blank" rel="noopener noreferrer">Xsolis</a> (1.4M patients via a healthcare-AI processor), <a href="https://www.bleepingcomputer.com/news/security/texas-govt-data-breach-exposes-over-3-million-drivers-licenses/" target="_blank" rel="noopener noreferrer">Texas Parks &amp; Wildlife</a> (3.08M licence holders via an unnamed licence-sales vendor, with a public-vs-AG-filing SSN contradiction noted in § 11), and the Canvas/Instructure LMS breach (160 UK universities). The recurring control gap is vendor data-minimisation and breach-notification SLAs.</p><div class="prov"><span>incident</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/mass-third-party-exposures-xsolis-texas-parks-wildlife-canva/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.hipaajournal.com/xsolis-data-breach/" target="_blank" rel="noopener noreferrer">HIPAA Journal — Xsolis</a> · <a href="https://www.bleepingcomputer.com/news/security/texas-govt-data-breach-exposes-over-3-million-drivers-licenses/" target="_blank" rel="noopener noreferrer">BleepingComputer — Texas</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/social-engineering-and-sso-abuse-opened-the-highest-profile" data-tags="phishing identity data-breach organized-crime" data-regions="us global" data-kind="incident" data-priority="notable" data-discovered="2026-06-29T00:21:11Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="social-engineering-and-sso-abuse-opened-the-highest-profile"><a href="https://ctipilot.ch/entries/2026-06-29/social-engineering-and-sso-abuse-opened-the-highest-profile/">Social engineering and SSO abuse opened the highest-profile intrusions</a></h3><p>Madison Square Garden was breached by <a href="https://www.404media.co/how-hackers-broke-into-madison-square-garden/" target="_blank" rel="noopener noreferrer">a single vishing call</a> into its identity platform; the operators talked a low-level employee into authorising access. This is the same human-layer entry that has driven the year&#39;s most damaging extortion. The defensive lesson is process, not product: callback verification on help-desk identity changes, no MFA reset on an inbound call, and alerting on anomalous SSO grants from new devices.</p><div class="prov"><span>incident</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/social-engineering-and-sso-abuse-opened-the-highest-profile/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.404media.co/how-hackers-broke-into-madison-square-garden/" target="_blank" rel="noopener noreferrer">404 Media</a> · <a href="https://abnormal.ai/blog/shinyhunters-sso-social-engineering-mfa-identity-compromise" target="_blank" rel="noopener noreferrer">Abnormal Security</a></div></article><div class="sect" id="research-threat-actor-developments"><span class="n">06</span><span class="t">Research &amp; threat-actor developments</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-06-29/threat-actor-developments-russia-nexus-espionage-broadens-ne" data-tags="nation-state espionage russia-nexus china-nexus north-korea-nexus" data-regions="europe switzerland apac global" data-kind="research" data-priority="high" data-discovered="2026-06-29T00:21:15Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="threat-actor-developments-russia-nexus-espionage-broadens-ne"><a href="https://ctipilot.ch/entries/2026-06-29/threat-actor-developments-russia-nexus-espionage-broadens-ne/">Threat-actor developments: Russia-nexus espionage broadens; new China-nexus and DPRK clusters</a></h3><p>The most significant new actor finding the dailies did not carry is Turla&#39;s <strong>STOCKSTAY</strong> — Google GTIG <a href="https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering" target="_blank" rel="noopener noreferrer">characterised</a> a multi-component .NET/Windows Forms backdoor that communicates C2 over secure WebSocket and shares significant code overlap with Kazuar (Turla&#39;s staple implant since 2017). Delivery used malicious RDP files by phishing and, as recently as November 2025, RAR archives exploiting WinRAR&#39;s CVE-2025-8088 (a flaw also abused by Sandworm, Gamaredon and RomCom). Current targeting is Ukrainian government and military, but earlier victims had Italian, Dutch, Polish and German foreign-policy interest — a direct read-across for Swiss federal and European governmental entities with Ukraine-adjacent policy work (<a href="https://thehackernews.com/2026/06/google-details-turlas-new-stockstay.html" target="_blank" rel="noopener noreferrer">The Hacker News</a>). This sits alongside the week&#39;s other Russia-nexus signal: FBI/CISA escalated their warning that Russian intelligence (tracked as UNC5792) is now <a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank" rel="noopener noreferrer">phishing Signal Backup Recovery Keys</a> for persistent account takeover, and ESET&#39;s Gamaredon retrospective (§ 7) shows the FSB-linked group moving exfil and C2 wholesale onto trusted cloud services.</p>
<p>Two non-Russian clusters round out the picture. Unit 42 documented <strong>CL-STA-1062</strong>, a Chinese-speaking cluster (overlapping Talos&#39;s UAT-7237) deploying the new TinyRCT .NET backdoor via AppDomainManager injection against Southeast-Asian government and state-owned energy targets (<a href="https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/" target="_blank" rel="noopener noreferrer">Unit 42</a>); Kaspersky GReAT analysed the <strong>StrikeShark</strong> cluster&#39;s SharkLoader deploying Cobalt Strike via &quot;Perfect DLL Hijacking&quot; against government targets (<a href="https://securelist.com/strikeshark-campaign/120326/" target="_blank" rel="noopener noreferrer">Securelist</a>). And SentinelLABS&#39; <strong>macOS.Gaslight</strong>, a DPRK-aligned Rust backdoor, notably turns prompt injection on the LLM-assisted analyst rather than the sandbox (<a href="https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/" target="_blank" rel="noopener noreferrer">SentinelLABS</a>) — an early instance of tradecraft built specifically to poison AI-assisted triage. Attribute the claim to the research outfit, not the state, where the source itself hedges.</p><div class="prov"><span>research</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/threat-actor-developments-russia-nexus-espionage-broadens-ne/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/stockstay-turla-intelligence-gathering" target="_blank" rel="noopener noreferrer">Google GTIG — STOCKSTAY</a> · <a href="https://www.ic3.gov/PSA/2026/PSA260626" target="_blank" rel="noopener noreferrer">FBI IC3 PSA I-062626-PSA</a> · <a href="https://unit42.paloaltonetworks.com/cl-sta-1062-tinyrct-backdoor/" target="_blank" rel="noopener noreferrer">Unit 42 — CL-STA-1062</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/research-the-trust-chain-not-the-perimeter-was-the-week-s-at" data-tags="supply-chain identity ai-abuse cloud" data-regions="global europe" data-kind="research" data-priority="high" data-discovered="2026-06-29T00:21:14Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="research-the-trust-chain-not-the-perimeter-was-the-week-s-at"><a href="https://ctipilot.ch/entries/2026-06-29/research-the-trust-chain-not-the-perimeter-was-the-week-s-at/">Research: the trust chain, not the perimeter, was the week&#39;s attack surface</a></h3><p>The week&#39;s research converges on one structural shift: the productive attack surface in 2026 is the set of trust relationships connecting developer tools, CI/CD pipelines, SaaS integrations, AI coding agents and the browser — not the network perimeter. Tenable&#39;s analysis of the Miasma worm frames it as a <a href="https://www.tenable.com/blog/what-the-miasma-campaign-reveals-about-the-new-supply-chain-threat-model-and-the-underground" target="_blank" rel="noopener noreferrer"><strong>&quot;Developer Credential Economy&quot;</strong></a>: an infostealer harvests a developer credential (a Red Hat GitHub token sat in infostealer logs ~7 weeks before weaponisation), it is brokered underground, then weaponised through npm and — the novel capability — injected into the <code>SessionStart</code> hooks of AI coding tools so it runs when a developer opens a repo (Socket enumerates at least five affected tools — Claude Code, GitHub Copilot, Gemini CLI, Cursor, VS Code). The entire kill chain carries no CVE, and SLSA provenance attestations passed registry checks — provenance without content scanning is no defence (<a href="https://socket.dev/blog/miasma-mini-shai-hulud-hits-leoplatform-npm-packages-go-ecosystem" target="_blank" rel="noopener noreferrer">Socket</a>).</p>
<p>The same trust-boundary theme runs through the week&#39;s other primary research: the Klue/Icarus cascade (a 2022 OAuth grant, § 2); Cordyceps, which found 300+ exploitable <code>pull_request_target</code> GitHub Actions misconfigurations leaking main-branch secrets (<a href="https://novee.security/blog/cordyceps/" target="_blank" rel="noopener noreferrer">Novee Security</a>); Unit 42&#39;s malicious-skill payloads bypassing the OpenClaw agent sandbox (<a href="https://unit42.paloaltonetworks.com/openclaw-ai-supply-chain-risk/" target="_blank" rel="noopener noreferrer">Unit 42</a>); and Island&#39;s &quot;BadBlocker&quot;, an 11M-install Chrome ad-blocker one server-side config change away from arbitrary JavaScript on any site, with no extension update or store review (<a href="https://www.island.io/blog/badblocker-11-million-users-one-server-call-away-from-compromise" target="_blank" rel="noopener noreferrer">Island</a>). On the identity plane, Netcraft documented Bluekit, a Browser-in-the-Middle phishing-as-a-service platform that authenticates the victim into the <em>attacker&#39;s</em> browser session, defeating Device Bound Session Credentials (<a href="https://www.netcraft.com/blog/bluekit-phishing-as-a-service-threat" target="_blank" rel="noopener noreferrer">Netcraft</a>) — a reminder that session-binding controls like DBSC do not stop a browser-in-the-middle relaying the live authenticated session. Cisco Talos&#39;s <a href="https://blog.talosintelligence.com/introduction-to-com-usage-by-windows-threats/" target="_blank" rel="noopener noreferrer">field guide to Windows COM abuse</a> (ITaskService, BITS, WMI, DCOM as EDR-evasion primitives) closes the loop on detection: indirect vtable calls hide activity behind legitimate service call stacks. The defender takeaway is uniform — audit OAuth grants and integration service accounts older than 12 months, restrict AI-agent hook configuration to read-only paths, treat CI/CD token scope as a reviewed principal, and don&#39;t assume FIDO2 closes the phishing path.</p><div class="prov"><span>research</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/research-the-trust-chain-not-the-perimeter-was-the-week-s-at/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.tenable.com/blog/what-the-miasma-campaign-reveals-about-the-new-supply-chain-threat-model-and-the-underground" target="_blank" rel="noopener noreferrer">Tenable — Developer Credential Economy</a> · <a href="https://www.netcraft.com/blog/bluekit-phishing-as-a-service-threat" target="_blank" rel="noopener noreferrer">Netcraft — Bluekit BitM</a> · <a href="https://www.island.io/blog/badblocker-11-million-users-one-server-call-away-from-compromise" target="_blank" rel="noopener noreferrer">Island — BadBlocker</a></div></article><article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-tradecraft-trusted-primitives" data-tags="identity espionage infostealer phishing" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-07-05T23:34:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="weekly-w27-tradecraft-trusted-primitives"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-tradecraft-trusted-primitives/">The week&#39;s tradecraft converged on abusing trusted primitives — OAuth tokens, signed binaries, native auth APIs and legitimate SaaS</a></h3><p>Five otherwise-unrelated research disclosures this week point the same direction: capable actors — from a Chinese APT to commodity BEC and ransomware crews — are increasingly operating <em>through</em> trusted, native mechanisms rather than dropping signatureable custom malware. For a detection-engineering audience, that is the strategic note, because it tells you where the hunt surface is moving.</p>
<p><strong>OAuth tokens as the target.</strong> Kaspersky GReAT documented <strong>Umbrij</strong>, a .NET tool the ToddyCat APT uses to automate theft of Google Workspace OAuth tokens via a technique GReAT calls Shadow Token via Remote Debug (STRD) — driving Chromium&#39;s remote-debugging interface to lift live tokens (<a href="https://securelist.com/toddycat-apt-umbrij-tool-and-oauth/120251/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist, 2026-06-30</a>). Cisco Talos exposed <strong>ARToken</strong>, an EvilTokens-lineage BEC-as-a-service panel (80+ API endpoints) automating Microsoft 365 device-code phishing, Primary-Refresh-Token persistence that survives password resets, and mailbox/SharePoint exfiltration (<a href="https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/" target="_blank" rel="noopener noreferrer">Cisco Talos</a>). Both defeat password-centric defences: the credential is no longer the secret worth stealing, the token is.</p>
<p><strong>Signed binaries and native APIs as the execution and validation layer.</strong> Blackpoint&#39;s <strong>Avalon</strong> framework chains a signed-binary MSBuild loader with ETW/AMSI patching (in-process telemetry tampering) and the CrownX ransomware payload (<a href="https://blackpointcyber.com/blog/avalons-path-from-legal-lure-to-crownx-ransom-capabilities/" target="_blank" rel="noopener noreferrer">Blackpoint Cyber</a>); Jamf&#39;s <strong>PamStealer</strong> impersonates the Maccy clipboard app and confirms a stolen macOS password through the native <code>pam_authenticate</code> API before exfiltrating it (<a href="https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/" target="_blank" rel="noopener noreferrer">Jamf Threat Labs</a>) — using the OS&#39;s own auth path to guarantee the loot is valid.</p>
<p><strong>Legitimate SaaS as C2.</strong> Mustang Panda (TA416 / HIVE0154) used <strong>Zoho WorkDrive</strong> as a dead-drop C2 channel (ZOHOMURK) against government and energy targets (<a href="https://www.acronis.com/en/tru/posts/mustang-panda-targets-indias-government-and-energy-sectors/" target="_blank" rel="noopener noreferrer">Acronis TRU, 2026-06-29</a>) — command traffic riding a trusted, hard-to-block SaaS host.</p>
<p><strong>Weekly takeaway:</strong> the common defensive failure mode across all five is reliance on signatures and on the password as the crown jewel. The hunt has to move to <em>anomalous use of the trusted mechanism</em> — remote-debugging flags on browser processes, token issuance/reuse surviving resets, signed LOLBins loading unexpected code, ETW/AMSI tampering, native auth-API calls from non-auth processes, and server egress to consumer SaaS storage. Per-tool detail and detection concepts in § references.</p><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace/">2026-07-01/kaspersky-great-toddycat-s-umbrij-automates-gmail-workspace</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/cisco-talos-artoken-exposes-a-full-bec-as-a-service-toolkit/">2026-07-02/cisco-talos-artoken-exposes-a-full-bec-as-a-service-toolkit</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware/">2026-07-04/avalon-framework-msbuild-etw-loader-crownx-ransomware</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation/">2026-07-04/pamstealer-macos-infostealer-pam-api-password-validation</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe/">2026-06-30/mustang-panda-abuses-zoho-workdrive-as-a-dead-drop-c2-channe</a></p><div class="prov"><span>research</span><span>05 Jul 23:34Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-tradecraft-trusted-primitives/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securelist.com/toddycat-apt-umbrij-tool-and-oauth/120251/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist (GReAT)</a> · <a href="https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/" target="_blank" rel="noopener noreferrer">Cisco Talos</a> · <a href="https://blackpointcyber.com/blog/avalons-path-from-legal-lure-to-crownx-ransom-capabilities/" target="_blank" rel="noopener noreferrer">Blackpoint Cyber</a> · <a href="https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/" target="_blank" rel="noopener noreferrer">Jamf Threat Labs</a></div></article><div class="sect" id="annual-periodic-threat-reports"><span class="n">07</span><span class="t">Annual / periodic threat reports</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-06-29/eset-gamaredon-2025-annual-actor-retrospective" data-tags="nation-state espionage russia-nexus" data-regions="europe" data-kind="annual-report" data-priority="notable" data-discovered="2026-06-29T00:21:18Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eset-gamaredon-2025-annual-actor-retrospective"><a href="https://ctipilot.ch/entries/2026-06-29/eset-gamaredon-2025-annual-actor-retrospective/">ESET Gamaredon 2025 — annual actor retrospective</a></h3><p><strong>Background.</strong> Gamaredon (FSB-linked, Russia-nexus) has been ESET&#39;s most-tracked Ukraine-focused operator for years; its prior annual papers documented a high-tempo, PowerShell-heavy toolset and aggressive infrastructure churn.</p>
<p>ESET&#39;s <a href="https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/" target="_blank" rel="noopener noreferrer">2025 Gamaredon paper</a> (covered 06-26) documents six new PowerShell tools and the wholesale migration of exfiltration and C2 onto trusted cloud services, tunnels and &quot;workers&quot; — the horizon implication for European public-sector defenders is detection-oriented: Gamaredon-class C2 increasingly hides inside legitimate cloud-service traffic (Cloudflare workers, Telegram, dead-drop resolvers), so network-indicator blocking degrades and behavioural detection on the endpoint and on anomalous cloud-service egress becomes the durable control.</p><div class="prov"><span>annual-report</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/eset-gamaredon-2025-annual-actor-retrospective/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a> · <a href="https://www.sekoia.com/blog/fsbs-matryoshka-3-3-gamaredons-gifts-that-keeps-unpacking-gammasteel" target="_blank" rel="noopener noreferrer">Sekoia</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo" data-tags="ransomware organized-crime russia-nexus" data-regions="global europe switzerland" data-kind="annual-report" data-priority="notable" data-discovered="2026-06-29T00:21:17Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo"><a href="https://ctipilot.ch/entries/2026-06-29/eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo/">ESET &quot;Killing me gently&quot; — a de-facto mid-year RaaS-tooling report</a></h3><p><strong>Background.</strong> The Gentlemen emerged in late 2025 as a RaaS operation founded by &quot;hastalamuerte&quot; (a former Qilin affiliate per Group-IB, previously affiliated with Embargo, LockBit, Medusa and BlackLock per PRODAFT). ESET first hypothesised an in-house EDR-killer in February 2026; Group-IB and Check Point independently corroborated before the gang&#39;s own internal data leaked. By April 2026 the group accounted for ~10% of global ransomware activity, and Krebs (06-10) linked the alias to a named individual in Izhevsk, Russia.</p>
<p>ESET&#39;s 06-26 deep-dive into the leaked internal data is the most substantive published-in-window documentation of RaaS tooling structure, and reads as a mid-year complement to the W25 Check Point State of Ransomware Q1 2026. Three structural findings a detection engineer should register: (1) GentleKiller is a modular in-house framework with at least eight BYOVD variants, each impersonating a different vendor and abusing a different kernel driver — driver allow-listing alone is insufficient without process-injection-chain detection; (2) the group integrates <em>rival gangs&#39;</em> EDR killers (HexKiller from Warlock, ThrottleBlood shared with MedusaLocker/DragonForce, HavocKiller), so tooling overlap no longer implies operational overlap; (3) victims are selected centrally on FortiGate misconfiguration rather than geography, tying the Gentlemen victim pipeline directly to FortiBleed-style reconnaissance (§ 8). New BYOVD PoCs are operationalised within days of public release. (<a href="https://ctipilot.ch/briefs/2026-06-27/" target="_blank" rel="noopener noreferrer">daily 06-27</a>)</p><div class="prov"><span>annual-report</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/eset-killing-me-gently-a-de-facto-mid-year-raas-tooling-repo/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a> · <a href="https://www.eset.com/us/about/newsroom/research/eset-research-gentlemen-ransomware-gang-edr-killers/" target="_blank" rel="noopener noreferrer">ESET Newsroom</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/swiss-post-cybersecurity-inaugural-swiss-threat-landscape-re" data-tags="phishing identity ai-abuse" data-regions="switzerland" data-kind="annual-report" data-priority="notable" data-discovered="2026-06-29T00:21:16Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="swiss-post-cybersecurity-inaugural-swiss-threat-landscape-re"><a href="https://ctipilot.ch/entries/2026-06-29/swiss-post-cybersecurity-inaugural-swiss-threat-landscape-re/">Swiss Post Cybersecurity — inaugural Swiss Threat Landscape Report</a></h3><p>Swiss Post Cybersecurity <a href="https://www.swisspost-cybersecurity.ch/news/swiss-threat-landscape-report" target="_blank" rel="noopener noreferrer">published its first Swiss Threat Landscape Report</a> at its Hack&#39;Events conference (06-23), drawing on its own SOC, IR and offensive-security practice. For a Swiss public-sector SOC this is the most locally-grounded threat baseline of the week; the synthesis worth carrying beyond the daily&#39;s recap is that the report&#39;s emphasis on phishing, identity compromise and AI-abuse maps precisely onto the week&#39;s operational signal — the NCSC-CH M365 voicemail-phishing wave (§ 4), the Bluekit BitM and Klue OAuth identity attacks (§§ 2, 6), and AI-agent supply-chain abuse (§ 6). The local-vendor view and the week&#39;s incidents agree on where Swiss defenders should spend marginal effort: identity and the human layer, not perimeter CVEs alone.</p><div class="prov"><span>annual-report</span><span>29 Jun 00:21Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/swiss-post-cybersecurity-inaugural-swiss-threat-landscape-re/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.swisspost-cybersecurity.ch/news/swiss-threat-landscape-report" target="_blank" rel="noopener noreferrer">Swiss Post Cybersecurity</a></div></article><div class="sect" id="long-running-campaigns-status-update"><span class="n">08</span><span class="t">Long-running campaigns · status update</span><span class="c">6 items</span></div><article class="finding entry-card" data-entry-id="2026-06-29/the-gentlemen" data-tags="ransomware organized-crime russia-nexus" data-regions="switzerland dach europe" data-kind="synthesis" data-priority="high" data-discovered="2026-06-29T00:21:21Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="the-gentlemen"><a href="https://ctipilot.ch/entries/2026-06-29/the-gentlemen/">The Gentlemen</a></h3><p>The W25 multi-day item now has primary-evidence depth (the ESET deep-dive, § 7) and a sharp Swiss angle: Check Point data, reported by Swiss tech press, makes <a href="https://www.inside-it.ch/aufstrebende-ransomware-bande-findet-mehr-schweizer-opfer-20260626" target="_blank" rel="noopener noreferrer">Switzerland the second-most-targeted European country</a> for the operation, which now claims 478 victims and has added worm propagation. The operationally important link is that victim selection runs on FortiGate misconfiguration scanning — so a Swiss organisation&#39;s FortiBleed exposure (above) is also its Gentlemen-victim-selection exposure. Outstanding for defenders: the same FortiGate hardening that closes FortiBleed reduces Gentlemen targeting, and EDR-tamper-protection plus driver-blocklist enforcement is the GentleKiller counter.</p><div class="prov"><span>synthesis</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/the-gentlemen/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.inside-it.ch/aufstrebende-ransomware-bande-findet-mehr-schweizer-opfer-20260626" target="_blank" rel="noopener noreferrer">inside-it.ch</a> · <a href="https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/fortibleed" data-tags="actively-exploited data-breach identity russia-nexus" data-regions="global europe switzerland" data-kind="synthesis" data-priority="high" data-discovered="2026-06-29T00:21:19Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="fortibleed"><a href="https://ctipilot.ch/entries/2026-06-29/fortibleed/">FortiBleed</a></h3><p>The W25 top story continued without a scale revision — the device count holds at the 86,644 figure the dailies reported — but the in-window development is the clearest state-interest signal yet: CISA <a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-of-credential-exposure" target="_blank" rel="noopener noreferrer">updated its hardening alert on 06-22</a> to link Fortinet&#39;s revised guidance, and reporting now confirms that on in mid-June the Russian-speaking operator completed offline Kerberos-hash cracking from captured FortiGate configs and immediately exfiltrated DFS backup data from a NATO-aligned defence contractor — a full AD domain takeover (<a href="https://securityaffairs.com/194004/hacking/fortibleed-the-most-detailed-breakdown-yet-of-an-active-russian-credential-harvesting-operation.html" target="_blank" rel="noopener noreferrer">Security Affairs</a>). Outstanding for defenders: treat any FortiGate admin/VPN credential active May–June 2026 as compromised, rotate, then hunt AD for pass-the-hash, DCSync and DFS-backup exfiltration (Kerberos ticket anomalies, LSASS access, <code>ntdsutil</code>/impacket artefacts). Patch level is irrelevant — this is credential reuse, not a new CVE.</p><div class="prov"><span>synthesis</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/fortibleed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-of-credential-exposure" target="_blank" rel="noopener noreferrer">CISA alert</a> · <a href="https://securityaffairs.com/194004/hacking/fortibleed-the-most-detailed-breakdown-yet-of-an-active-russian-credential-harvesting-operation.html" target="_blank" rel="noopener noreferrer">Security Affairs</a></div></article><article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution" data-tags="ransomware data-breach organized-crime identity" data-regions="global europe dach" data-kind="synthesis" data-priority="notable" data-discovered="2026-07-05T23:41:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="weekly-w27-fortibleed-inc-lynx-attribution"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/">FortiBleed status update — the FortiGate credential-theft campaign is now attributed to INC Ransom / Lynx, with a scaled-up victim count and an unconfirmed Nextcloud zero-day claim</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-29/fortibleed/">FortiBleed</a> <span class="mono muted">(2026-06-29)</span></p><p>FortiBleed — the FortiGate credential-exposure campaign the prior two weeklies tracked from disclosure (86,644+ then 73,932+ exposed credentials) through the Golang &quot;FortigateSniffer&quot; tool (abusing FortiOS&#39;s native <code>diagnose sniffer packet</code>) and an AD-domain-takeover at a NATO-aligned defence contractor — gained a ransomware attribution and a scale revision this week.</p>
<p><strong>Attribution to INC Ransom / Lynx.</strong> SOCRadar&#39;s Threat Research Unit published evidence tying FortiBleed&#39;s infrastructure directly to two active ransomware operations: an operator with access to FortiBleed infrastructure was found logged into the negotiation panels of both <strong>INC Ransom</strong> and <strong>Lynx</strong> (which SOCRadar assesses, per other researchers, to be an INC rebrand rather than a distinct group), and FortiBleed victim data overlaps victims on INC Ransom&#39;s leak site — the first direct evidence linking the mass FortiGate credential theft to a specific ransomware-deployment pipeline (<a href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/" target="_blank" rel="noopener noreferrer">SOCRadar STRU, 2026-07-01</a>; <a href="https://www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-01</a>). STRU characterises the operation as an ~20-person Initial Access Broker business with a tiered internal structure exposed via an opsec lapse.</p>
<p><strong>Scale revision.</strong> STRU reports scanning against ~11,250 FortiGate portals across 150+ countries, admin-level access confirmed on 409 targets, full domain compromise on 354, and at least 12 confirmed ransomware deployments to date — sharpening the risk picture from &quot;credential exposure&quot; to &quot;credential exposure feeding an active RaaS deployment pipeline.&quot;</p>
<p><strong>Unconfirmed Nextcloud zero-day (track, do not action).</strong> STRU further states the group possesses at least one undisclosed Nextcloud zero-day, with SOCRadar coordinating responsible disclosure. This is a single-source claim pending vendor confirmation and carries no CVE — but given Nextcloud&#39;s data-sovereignty-driven prevalence in Swiss and German public-sector and SME estates, it belongs on the watch list for an immediate patch once Nextcloud publishes. The durable defender action is unchanged: treat any FortiGate exposed in the May–June window as having leaked credentials, rotate, and hunt the sniffer technique. New registry entity this run: <code>actor:inc-ransom</code> (aliases INC Ransomware, Lynx).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Scanning activity against roughly 11,250 FortiGate portals in more than 150 countries, with admin-level access confirmed on 409 targets</p><figcaption class="entry-cite__attr"><a href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/" target="_blank" rel="noopener noreferrer">SOCRadar (STRU)</a></figcaption></figure><figure class="entry-cite"><p class="entry-cite__quote">During the investigation of that server, analysis of the collected artifacts revealed that the threat actor had accessed the ransomware negotiation panels of both the Lynx / INC ransomware group.</p><figcaption class="entry-cite__attr">BleepingComputer (citing SOCRadar)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>05 Jul 23:41Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-fortibleed-inc-lynx-attribution/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/" target="_blank" rel="noopener noreferrer">SOCRadar (STRU)</a> · <a href="https://www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article><article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-shinyhunters-oracle-campaign-status" data-tags="data-breach actively-exploited organized-crime zero-day" data-regions="global europe us" data-kind="synthesis" data-priority="notable" data-discovered="2026-07-05T23:40:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 1: Confirmed"><span class="k">NATO</span>B1</span></div><h3 class="f-h" id="weekly-w27-shinyhunters-oracle-campaign-status"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-shinyhunters-oracle-campaign-status/">ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfaces</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-29/shinyhunters-unc6240-oracle-peoplesoft-campaign/">ShinyHunters / UNC6240 Oracle PeopleSoft campaign</a> <span class="mono muted">(2026-06-29)</span></p><p>the ShinyHunters/UNC6240 Oracle PeopleSoft campaign (CVE-2026-35273, unauthenticated RCE in PeopleTools Environment Management) kept acquiring named victims this week — the delta since the prior weekly&#39;s status.</p>
<p><strong>Nissan is the largest named victim yet.</strong> SecurityWeek reported Nissan disclosed a breach tied to the Oracle PeopleSoft attacks, exposing current and former employee HR/payroll PII across four countries — a different exposure profile than the NAIC breach the W26 weekly led with (<a href="https://www.securityweek.com/nissan-employee-data-breached-in-oracle-peoplesoft-hack/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-30</a>; § references). It confirms the &quot;still acquiring victims&quot; throughline the W26 looking-ahead flagged, and that named victims now span beyond the education sector GTIG originally emphasised.</p>
<p><strong>A separate Medtronic claim — attribution precision matters.</strong> Medtronic is notifying ~9 million people of a ShinyHunters-<em>claimed</em> breach of corporate IT systems from April 2026 (names, DOB, SSNs, health data), with medical devices reported unaffected (<a href="https://www.bleepingcomputer.com/news/security/medtronic-notifies-customers-impacted-by-shinyhunters-data-breach/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-07-02</a>; § references). This is a <em>distinct</em> incident from the PeopleSoft campaign — a corporate-IT breach the brand claimed, not tied to the Oracle zero-day path — and the weekly notes it to keep the ShinyHunters cluster&#39;s several concurrent operations from being conflated: the PeopleSoft ERP zero-day campaign is one line of effort; opportunistic corporate-IT data extortion under the same brand is another.</p>
<p><strong>Status:</strong> GTIG&#39;s ~100-organisation notification set (68% higher education) is still landing, so more European education and public-finance victims are likely in the un-notified tail (<a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit" target="_blank" rel="noopener noreferrer">Google GTIG</a>). The separate, unattributed Oracle E-Business Suite RCE now exploited in the wild (this week&#39;s Oracle top story) compounds the message: internet-facing Oracle application tiers are a priority patch-and-isolate class regardless of which actor is behind any single CVE.</p><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o/">2026-07-01/nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-03/medtronic-notifies-9-million-people-of-a-shinyhunters-claime/">2026-07-03/medtronic-notifies-9-million-people-of-a-shinyhunters-claime</a></p><div class="prov"><span>synthesis</span><span>05 Jul 23:40Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-shinyhunters-oracle-campaign-status/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.securityweek.com/nissan-employee-data-breached-in-oracle-peoplesoft-hack/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://www.bleepingcomputer.com/news/security/medtronic-notifies-customers-impacted-by-shinyhunters-data-breach/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit" target="_blank" rel="noopener noreferrer">Google GTIG / Mandiant</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/operation-endgame" data-tags="law-enforcement infostealer botnet organized-crime" data-regions="europe global" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-29T00:21:22Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="operation-endgame"><a href="https://ctipilot.ch/entries/2026-06-29/operation-endgame/">Operation Endgame</a></h3><p>Europol&#39;s law-enforcement campaign extended its reach this week: the 06-24/25 Amadey and StealC takedown actioned 326 servers and 142 domains and recovered approximately 27 million stolen credentials from over 385,000 compromised systems (<a href="https://www.bleepingcomputer.com/news/security/amadey-stealc-malware-operations-disrupted-in-operation-endgame-action/" target="_blank" rel="noopener noreferrer">BleepingComputer</a>), with Microsoft providing the Amadey/StealC infrastructure analysis (<a href="https://www.microsoft.com/en-us/security/blog/2026/06/24/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-that-deliver-them/" target="_blank" rel="noopener noreferrer">Microsoft</a>). Combined with the W25 SocGholish/TA569 seizure (106 servers), Endgame has now dismantled three commodity delivery-and-theft networks in quick succession. The defender gap: no arrests were announced for this phase, so infrastructure can reconstitute — cross-reference the recovered 27M credentials against your identity-store canaries and hunt Amadey persistence (<code>HKCU</code> run-key, <code>rundll32</code>/<code>regsvr32</code> side-loads, short-lived child processes under <code>%AppData%\Roaming</code>).</p><div class="prov"><span>synthesis</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/operation-endgame/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/amadey-stealc-malware-operations-disrupted-in-operation-endgame-action/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.microsoft.com/en-us/security/blog/2026/06/24/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-that-deliver-them/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence</a> · <a href="https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks" target="_blank" rel="noopener noreferrer">Europol newsroom</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/shinyhunters-unc6240-oracle-peoplesoft-campaign" data-tags="data-breach zero-day actively-exploited organized-crime" data-regions="global us europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-29T00:21:20Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-35273/">CVE-2026-35273</a><span class="b exp">exploited</span></div><h3 class="f-h" id="shinyhunters-unc6240-oracle-peoplesoft-campaign"><a href="https://ctipilot.ch/entries/2026-06-29/shinyhunters-unc6240-oracle-peoplesoft-campaign/">ShinyHunters / UNC6240 Oracle PeopleSoft campaign</a></h3><p>The campaign behind the § 1 NAIC breach. GTIG/Mandiant attributes to UNC6240 an active zero-day exploitation of Oracle PeopleSoft (CVE-2026-35273) between May 27 and June 9, predating Oracle&#39;s advisory; staging environments deployed customised MeshCentral agents masquerading as cloud endpoints, then ran a per-victim <code>[victim]_fanout.sh</code> lateral-movement-and-defacement script (<a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit" target="_blank" rel="noopener noreferrer">Google GTIG</a>). ~300 PeopleSoft instances compromised, ~100 organisations notified, 68% higher education, with the University of Nottingham among the first named public victims (<a href="https://www.securityweek.com/google-confirms-exploitation-of-oracle-peoplesoft-zero-day-by-shinyhunters/" target="_blank" rel="noopener noreferrer">SecurityWeek</a>). The status this week: NAIC confirmed (§ 1), and notifications are still landing, so more European education and public-finance victims are likely. The weekly lens: this is ShinyHunters operating as a zero-day-capable ERP attacker — a capability shift from the brand&#39;s 2021–2024 credential-stuffing persona. Outstanding question: which EU universities running PeopleSoft are in the un-notified tail.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The campaign behind the § 1 NAIC breach.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/shinyhunters-unc6240-oracle-peoplesoft-campaign/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit" target="_blank" rel="noopener noreferrer">Google GTIG / Mandiant</a> · <a href="https://www.securityweek.com/google-confirms-exploitation-of-oracle-peoplesoft-zero-day-by-shinyhunters/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article><div class="sect" id="policy-regulatory-horizon"><span class="n">09</span><span class="t">Policy &amp; regulatory horizon</span><span class="c">4 items</span></div><article class="finding entry-card" data-entry-id="2026-06-29/netherlands-nis2-cyberbeveiligingswet-clears-the-lower-house" data-tags="law-enforcement eu-nexus" data-regions="europe" data-kind="policy" data-priority="high" data-discovered="2026-06-29T00:21:23Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="netherlands-nis2-cyberbeveiligingswet-clears-the-lower-house"><a href="https://ctipilot.ch/entries/2026-06-29/netherlands-nis2-cyberbeveiligingswet-clears-the-lower-house/">Netherlands NIS2 (Cyberbeveiligingswet) clears the lower house — entry into force targeted for 1 July 2026</a></h3><p>The Dutch transposition is in its final step: the Tweede Kamer (lower house) approved the Cyberbeveiligingswet on 15 April 2026 (<a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/04/15/tweede-kamer-stemt-in-met-wetsvoorstellen-cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten" target="_blank" rel="noopener noreferrer">Rijksoverheid</a>), with the Eerste Kamer (upper-house) ratification vote still pending in late June and the government targeting 1 July 2026 for entry into force. NCSC-NL is the designated supervisor; the regime runs a three-step 24h / 72h / one-month incident-notification protocol, essential-entity penalties up to €10M or 2% of turnover, and personal board liability for security-measure oversight (<a href="https://www.nldigitalgovernment.nl/nis2-directive-cyberbeveiligingswet-cbw/" target="_blank" rel="noopener noreferrer">NL Digital Government</a>). This is the fresh delta on the W25 NIS2-transposition item, which listed the Netherlands as pending; France, Ireland, Luxembourg and Spain remain non-transposed. What changes for defenders: any essential/important entity with Dutch operations or Dutch counterparties is about to face an enforceable notification clock and a named supervisor — wire NCSC-NL&#39;s 24/72-hour flow into the incident-response runbook now, and re-check which group entities fall in scope.</p><div class="prov"><span>policy</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/netherlands-nis2-cyberbeveiligingswet-clears-the-lower-house/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/04/15/tweede-kamer-stemt-in-met-wetsvoorstellen-cyberbeveiligingswet-en-wet-weerbaarheid-kritieke-entiteiten" target="_blank" rel="noopener noreferrer">Rijksoverheid — Tweede Kamer vote</a> · <a href="https://www.nldigitalgovernment.nl/nis2-directive-cyberbeveiligingswet-cbw/" target="_blank" rel="noopener noreferrer">NL Digital Government — Cyberbeveiligingswet</a> · <a href="https://ucomply.cloud/en/blog/cyberbeveiligingswet-1-juli-2026-wat-moet-u-nu-regelen/" target="_blank" rel="noopener noreferrer">uComply advisory</a></div></article><article class="finding entry-card" data-entry-id="2026-07-05/weekly-w27-netherlands-nis2-slip" data-tags="law-enforcement" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-07-05T23:42:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b upd">update</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability A: Completely reliable · information credibility 2: Probably true"><span class="k">NATO</span>A2</span></div><h3 class="f-h" id="weekly-w27-netherlands-nis2-slip"><a href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/">Netherlands NIS2 transposition slips past its 1 July target — Senate vote set for 7 July, entry into force now 15 August 2026</a></h3><p class="update-lead"><strong>UPDATE</strong> · originally covered <a href="https://ctipilot.ch/entries/2026-06-29/netherlands-nis2-cyberbeveiligingswet-clears-the-lower-house/">Netherlands NIS2 (Cyberbeveiligingswet) clears the lower house — entry into force targeted for 1 July 2026</a> <span class="mono muted">(2026-06-29)</span></p><p>the Dutch NIS2 transposition — the Cyberbeveiligingswet (Cbw) plus the companion Wet weerbaarheid kritieke entiteiten — has missed the 1 July 2026 entry-into-force target the prior weekly reported as the government&#39;s goal.</p>
<p>The Eerste Kamer (Senate) tabled its government response to the second committee report (&quot;nota naar aanleiding van het tweede verslag&quot;) on 29 June 2026 — the last written-preparation step before plenary debate — and the Senate&#39;s own bill-tracking page now states the floor vote will take place on <strong>7 July 2026</strong>, noting the bill was adopted by the Tweede Kamer on 15 April 2026 (<a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer, bill 36764</a>). iBestuur reports the government&#39;s revised entry-into-force target is now <strong>15 August 2026</strong>, roughly six weeks later than previously communicated (<a href="https://ibestuur.nl/digitale-weerbaarheid/digitale-veiligheid/eerste-kamer-stemt-7-juli-over-cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">iBestuur, 2026-07-01</a>).</p>
<p>The substantive scope is unchanged from prior coverage: NCSC-NL as designated supervisor, a three-step 24h/72h/one-month incident-notification protocol, essential-entity fines up to EUR 10M or 2% of global turnover, personal board liability for security-measure oversight, and an expansion of in-scope Dutch entities from roughly 1,000 to roughly 8,000. This is the fourth documented slip in the Dutch NIS2 timetable (originally targeted Q3 2025).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">the only action for a Swiss/EU reader is administrative — re-anchor readiness milestones and contractual compliance-date references onto 15 August 2026 for any Dutch group entities, hosting, or counterparties. No technical control change follows from the date shift itself.</div></aside><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">De stemming in de Eerste Kamer vindt plaats op 7 juli 2026.</p><p class="entry-cite__quote">Het voorstel (EK, A) is op 15 april 2026 aangenomen door de Tweede Kamer.</p><figcaption class="entry-cite__attr"><a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal (official bill page)</a></figcaption></figure></div><div class="prov"><span>policy</span><span>05 Jul 23:42Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/weekly-w27-netherlands-nis2-slip/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal (official bill page)</a> · <a href="https://ibestuur.nl/digitale-weerbaarheid/digitale-veiligheid/eerste-kamer-stemt-7-juli-over-cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">iBestuur</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/eu-cyber-resilience-act-75-days-to-the-11-september-vulnerab" data-tags="law-enforcement eu-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-06-29T00:21:25Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eu-cyber-resilience-act-75-days-to-the-11-september-vulnerab"><a href="https://ctipilot.ch/entries/2026-06-29/eu-cyber-resilience-act-75-days-to-the-11-september-vulnerab/">EU Cyber Resilience Act — 75 days to the 11 September vulnerability/incident-reporting obligation</a></h3><p>CRA Article 28 (conformity-body notification) entered force on 11 June 2026; the next binding milestone — mandatory vulnerability/incident reporting by manufacturers to ENISA&#39;s Single Reporting Platform — activates 11 September 2026, now ~75 days out (<a href="https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp" target="_blank" rel="noopener noreferrer">ENISA SRP</a>). ENISA has not yet published a dry-run schedule, stating guidance is due June–August (<a href="https://www.crowell.com/en/insights/client-alerts/eu-cyber-resilience-act-countdown-11-september-2026-incidentvulnerability-reporting-deadline-is-less-than-100-days-away" target="_blank" rel="noopener noreferrer">Crowell &amp; Moring</a>). For Swiss readers the practical action is procurement-side: Swiss manufacturers selling digital products into the EU fall in scope, and Swiss public-sector procurement teams should add CRA compliance attestations to vendor specs and confirm in-scope suppliers can meet the 24/72-hour SRP reporting flow before it binds.</p><div class="prov"><span>policy</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/eu-cyber-resilience-act-75-days-to-the-11-september-vulnerab/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp" target="_blank" rel="noopener noreferrer">ENISA Single Reporting Platform</a> · <a href="https://www.crowell.com/en/insights/client-alerts/eu-cyber-resilience-act-countdown-11-september-2026-incidentvulnerability-reporting-deadline-is-less-than-100-days-away" target="_blank" rel="noopener noreferrer">Crowell &amp; Moring advisory</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/eu-commission-proposes-a-major-europol-eurojust-mandate-expa" data-tags="law-enforcement eu-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-06-29T00:21:24Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eu-commission-proposes-a-major-europol-eurojust-mandate-expa"><a href="https://ctipilot.ch/entries/2026-06-29/eu-commission-proposes-a-major-europol-eurojust-mandate-expa/">EU Commission proposes a major Europol / Eurojust mandate expansion</a></h3><p>On 24 June the Commission tabled COM(2026) 580 proposing to expand Europol and Eurojust: automated, near-real-time national-police-to-Europol data upload via a new &quot;Police Shared Data Space&quot; cloud, Europol Support Offices embedded in Member-State agencies, an explicit Eurojust cybercrime mandate, and a roughly doubled (~€3bn) budget, with cybercrime and AI-accelerated threats cited as primary drivers (<a href="https://commission.europa.eu/news-and-media/news/commission-proposes-new-measures-better-tackle-cross-border-crime-and-terrorism-2026-06-24_en" target="_blank" rel="noopener noreferrer">European Commission</a>). The Protect Not Surveil coalition <a href="https://protectnotsurveil.eu/resources/press-release-europol-mandate-overhault-2026/" target="_blank" rel="noopener noreferrer">warns</a> of systematic data ingestion without categorisation safeguards. This is co-decision and unlikely to bind before 2027+, but public-sector CISOs in EU Member States should track it now: it reshapes how incident and victim data may flow to Europol, with data-protection and onward-sharing implications for breach reporting.</p><div class="prov"><span>policy</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/eu-commission-proposes-a-major-europol-eurojust-mandate-expa/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://commission.europa.eu/news-and-media/news/commission-proposes-new-measures-better-tackle-cross-border-crime-and-terrorism-2026-06-24_en" target="_blank" rel="noopener noreferrer">European Commission</a> · <a href="https://protectnotsurveil.eu/resources/press-release-europol-mandate-overhault-2026/" target="_blank" rel="noopener noreferrer">Protect Not Surveil</a></div></article><div class="sect" id="looking-ahead-what-to-watch-next-week"><span class="n">10</span><span class="t">Looking ahead · what to watch next week</span><span class="c">2 items</span></div><article class="finding entry-card" data-entry-id="2026-07-05/looking-ahead-2026-w27" data-tags="vulnerabilities law-enforcement" data-regions="global europe" data-kind="outlook" data-priority="notable" data-discovered="2026-07-05T23:43:00Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b cls cls-high" title="NATO Admiralty code · source reliability B: Usually reliable · information credibility 2: Probably true"><span class="k">NATO</span>B2</span></div><h3 class="f-h" id="looking-ahead-2026-w27"><a href="https://ctipilot.ch/entries/2026-07-05/looking-ahead-2026-w27/">Looking ahead — 2026-W27</a></h3><p>Items <strong>already in motion</strong> — sourced developments a defender should expect to act on in the coming weeks, not forecasts:</p>
<ul><li><strong>Adobe ColdFusion — six CVSS 10.0 unauth RCEs awaiting weaponisation.</strong> APSB26-68 fixed six maximum-severity RCE paths (file-upload, input-validation, path-traversal), all Adobe Priority 1, with no known exploitation yet (<a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html" target="_blank" rel="noopener noreferrer">Adobe PSIRT, 2026-06-30</a>). ColdFusion&#39;s history is rapid weaponisation of unauth file-upload primitives — patch internet-facing instances before a PoC lands (§ references).</li><li><strong>Citrix NetScaler CVE-2026-8451 — public test artefact, siblings exploited within days.</strong> A &quot;Detection Artefact Generator&quot; is public and CitrixBleed-lineage siblings have been exploited within days of disclosure; treat exploitation as a matter of time (§ references).</li><li><strong>WatchGuard Firebox 12.5.x — fix still pending.</strong> The pre-auth <code>iked</code> RCE (CVE-2026-13368) has no fix for the 12.5.x branch and 11.x is EOL; a build is expected — until it ships, the LDAP-backed IKEv2 path must be removed, not waited on (<a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023" target="_blank" rel="noopener noreferrer">WatchGuard PSIRT, 2026-07-02</a>).</li><li><strong>Dutch NIS2 — Senate vote 7 July, entry into force 15 August 2026.</strong> The Eerste Kamer floor vote is scheduled for 7 July with a revised entry-into-force target of 15 August (<a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer, bill 36764</a>); organisations with Dutch nexus should re-anchor readiness milestones (this week&#39;s policy entry).</li><li><strong>ShinyHunters Oracle PeopleSoft — un-notified victim tail.</strong> GTIG&#39;s ~100-organisation notification set is still landing (68% higher education); more European education and public-finance named victims are likely (this week&#39;s long-running status; § references).</li><li><strong>FortiBleed-actor Nextcloud zero-day — pending vendor disclosure.</strong> SOCRadar states the INC/Lynx-linked FortiBleed operator holds an undisclosed Nextcloud zero-day, coordination in progress. Single-source and unconfirmed — but given Nextcloud&#39;s Swiss/German public-sector prevalence, be ready to prioritise a patch the moment Nextcloud publishes (this week&#39;s FortiBleed status entry).</li></ul><p class="entry-references"><strong>Builds on:</strong> <a class="mono" href="https://ctipilot.ch/entries/2026-07-02/cve-2026-48276-48277-48281-48282-48283-48316-adobe-coldfusio/">2026-07-02/cve-2026-48276-48277-48281-48282-48283-48316-adobe-coldfusio</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem/">2026-07-01/cve-2026-8451-citrix-netscaler-adc-gateway-pre-auth-saml-mem</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-03/cve-2026-13368-watchguard-fireware-iked-pre-auth-rce/">2026-07-03/cve-2026-13368-watchguard-fireware-iked-pre-auth-rce</a> · <a class="mono" href="https://ctipilot.ch/entries/2026-07-01/nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o/">2026-07-01/nissan-is-the-largest-named-victim-yet-in-the-shinyhunters-o</a></p><div class="prov"><span>outlook</span><span>05 Jul 23:43Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-07-05/looking-ahead-2026-w27/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://helpx.adobe.com/security/products/coldfusion/apsb26-68.html" target="_blank" rel="noopener noreferrer">Adobe PSIRT (APSB26-68)</a> · <a href="https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00023" target="_blank" rel="noopener noreferrer">WatchGuard PSIRT (WGSA-2026-00023)</a> · <a href="https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet" target="_blank" rel="noopener noreferrer">Eerste Kamer der Staten-Generaal</a></div></article><article class="finding entry-card" data-entry-id="2026-06-29/looking-ahead-2026-w26" data-tags="cloud" data-regions="global" data-kind="outlook" data-priority="notable" data-discovered="2026-06-29T00:21:26Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="looking-ahead-2026-w26"><a href="https://ctipilot.ch/entries/2026-06-29/looking-ahead-2026-w26/">Looking ahead — 2026-W26</a></h3><p>A focused, justified list — items already in motion, not predictions.</p>
<ul><li><strong>ShinyHunters PeopleSoft notifications are still landing — expect more named European education and public-finance victims.</strong> GTIG has notified ~100 organisations (68% higher education) and NAIC is the fresh high-profile case; patch internet-reachable PeopleSoft and hunt <code>/PSEMHUB/</code> and <code>/PSIGW/HttpListeningConnector</code>. (<a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit" target="_blank" rel="noopener noreferrer">Google GTIG</a>; <a href="https://ctipilot.ch/briefs/2026-06-28/" target="_blank" rel="noopener noreferrer">daily 06-28</a>)</li><li><strong>FortiBleed is not a one-and-done credential reset — full AD domain takeover is now confirmed at a NATO-aligned contractor.</strong> Finish session termination and credential rotation, then hunt for post-compromise AD persistence (Kerberos abuse, DCSync, DFS-backup exfiltration) rather than assuming the reset closed it. (<a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-of-credential-exposure" target="_blank" rel="noopener noreferrer">CISA</a>; <a href="https://ctipilot.ch/briefs/2026-06-24/" target="_blank" rel="noopener noreferrer">daily 06-24</a>)</li><li><strong>The Klue/Icarus extortion surface is multiplying after the &quot;resolution&quot; — a second group is now extorting ~195 listed organisations.</strong> Any firm with a Klue/Salesforce integration should expect renewed extortion contact regardless of Icarus&#39;s stated data deletion; complete OAuth-grant revocation and CRM-egress monitoring. (<a href="https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/" target="_blank" rel="noopener noreferrer">SecurityWeek</a>; <a href="https://ctipilot.ch/briefs/2026-06-27/" target="_blank" rel="noopener noreferrer">daily 06-27</a>)</li><li><strong>CRA Single Reporting Platform go-live is ~75 days out (11 September); ENISA&#39;s dry-run schedule is due now.</strong> In-scope manufacturers — including Swiss exporters to the EU — should register and wire the 24/72-hour reporting flow into their PSIRT process before the obligation binds. (<a href="https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp" target="_blank" rel="noopener noreferrer">ENISA SRP</a>)</li><li><strong>EDPB Article 33 harmonised breach-notification template consultation closes 5 August.</strong> Still open with no in-window change; multi-jurisdiction breach-response owners have a closing window to comment before the EDPB sets a mandatory-adoption timeline. (<a href="https://www.edpb.europa.eu/news/edpb-meets-with-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification-template_en" target="_blank" rel="noopener noreferrer">EDPB</a>)</li><li><strong>npm v12 will disable install scripts by default — the week&#39;s Miasma worm wave is the reminder to audit CI now.</strong> Miasma&#39;s <code>postinstall</code>-and-<code>SessionStart</code>-hook propagation is exactly the kill chain <code>--ignore-scripts</code> / npm v12 defaults neutralise; inventory pipelines and AI-coding-tool hook configs that rely on build scripts. (<a href="https://socket.dev/blog/miasma-mini-shai-hulud-hits-leoplatform-npm-packages-go-ecosystem" target="_blank" rel="noopener noreferrer">Socket</a>; <a href="https://ctipilot.ch/briefs/2026-06-27/" target="_blank" rel="noopener noreferrer">daily 06-27</a>)</li><li><strong>libssh2 CVE-2026-55200 has a public PoC and an upstream fix commit, but tagged releases lag across the binding ecosystem — track the embedded-dependency fix pipeline.</strong> Inventory appliances, tooling and language bindings that ship libssh2 and chase each vendor&#39;s release rather than assuming a single library bump closes it. (<a href="https://advisories.ncsc.nl/2026/ncsc-2026-0210.html" target="_blank" rel="noopener noreferrer">NCSC-NL</a>; <a href="https://ctipilot.ch/briefs/2026-06-28/" target="_blank" rel="noopener noreferrer">daily 06-28</a>)</li><li><strong>Scattered Spider TfL sentencing is set for 16 July.</strong> First UK court outcome on the campaign; the vishing/social-engineering TTP precedent is directly relevant to European transport and public-sector identity-desk hardening. (<a href="https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted" target="_blank" rel="noopener noreferrer">UK NCA</a>; <a href="https://ctipilot.ch/briefs/2026-06-23/" target="_blank" rel="noopener noreferrer">daily 06-23</a>)</li></ul><div class="prov"><span>outlook</span><span>29 Jun 00:21Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-29/looking-ahead-2026-w26/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit" target="_blank" rel="noopener noreferrer">Google GTIG</a> · <a href="https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-of-credential-exposure" target="_blank" rel="noopener noreferrer">CISA</a> · <a href="https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp" target="_blank" rel="noopener noreferrer">ENISA SRP</a> · <a href="https://www.edpb.europa.eu/news/edpb-meets-with-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification-template_en" target="_blank" rel="noopener noreferrer">EDPB</a> · <a href="https://socket.dev/blog/miasma-mini-shai-hulud-hits-leoplatform-npm-packages-go-ecosystem" target="_blank" rel="noopener noreferrer">Socket</a> · <a href="https://advisories.ncsc.nl/2026/ncsc-2026-0210.html" target="_blank" rel="noopener noreferrer">NCSC-NL</a> · <a href="https://www.nationalcrimeagency.gov.uk/news/cyber-criminals-who-hacked-into-transport-for-londons-computer-network-are-convicted" target="_blank" rel="noopener noreferrer">UK NCA</a></div></article><details class="verif"><summary class="vh">About this weekly<span class="verif-count">1 run</span><svg class="verif-chev" viewBox="0 0 24 24" width="12" height="12" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" aria-hidden="true"><path d="M6 9l6 6 6-6"></path></svg></summary><div class="verif-body"><div class="run-note" data-run-id="2026-07-05T2305Z-weekly"><h3 class="run-note__head"><span class="mono">2026-07-05T2305Z-weekly</span> <span class="muted">· weekly · Claude Opus 4.8 (1M context) · 13 entries published</span></h3><div class="run-note__body"><h1 id="weekly-strategic-run-2026-w27-2026-06-29-2026-07-05">Weekly strategic run — 2026-W27 (2026-06-29 → 2026-07-05)</h1>
<h2 id="verification-coverage-notes">Verification &amp; coverage notes</h2>
<p>Weekly strategic fire for ISO week <strong>2026-W27</strong> (Mon 2026-06-29 00:00 UTC → Sun 2026-07-05 24:00 UTC). Prior weekly: <strong>2026-W26</strong> (run <code>2026-06-29</code>, entry run_id <code>2026-W26-b78503e7</code>); <code>window_days=7</code> (gap 6 days since the prior weekly, no missed week). <strong>Duplicate-week guard: PASS</strong> — no prior <code>-weekly</code> record covers 2026-W27.</p>
<p><strong>Phase 1 (week in review, local only):</strong> built seven working lists from the 45 in-window <strong>operational</strong> entries (9 incident · 12 research · 17 vulnerability · 7 threat) in <code>work/&lt;run-id&gt;/week-review.json</code>. Dedup target: the 75 prior-weekly <code>horizon: strategic</code> entries (W25 2026-06-22 + W26 2026-06-29) loaded from <code>prior_coverage.json</code>.</p>
<p><strong>Phase 2 (horizon research):</strong> W1 (threat-actor/campaign/report) and W2 (strategic/policy) spawned in parallel, both <strong>Sonnet 5</strong>, both returned within the 30-min cap. Main agent did no source fetching while they ran (W-INV-3).</p>
<p><strong>Strategic entries published (13):</strong></p>
<ul><li><code>weekly-top-stories</code> (2): SimpleHelp RMM CVE-2026-48558 (actively-exploited RMM supply-chain foothold); two Oracle enterprise product lines under active exploitation (EBS CVE-2026-46817 first ITW + the PeopleSoft campaign).</li><li><code>weekly-multi-day</code> (2): the week&#39;s edge/VPN pre-auth RCE cluster (Citrix NetScaler / WatchGuard Firebox / Kemp LoadMaster); <strong>AI crossed from target to operator</strong> (JADEPUFFER agentic ransomware, 0DIN coding-agent coercion, Phantom Squatting LLM-output poisoning, OpenClaw malicious skills) — the deliberately-new lens vs W26&#39;s &quot;AI as target.&quot;</li><li><code>weekly-vuln-rollup</code> (1): consolidated CVE status roll-up (exploited/KEV/working-exploit/weaponisation-likely) with <code>references</code> to the operational entries.</li><li><code>weekly-sector-patterns</code> (1): government/public-administration targeting (Canton Zürich MedusaLocker leak claim [unconfirmed], Pegasus-infected PEGA-committee MEP, DHS HSIN breach) — Swiss/EU home-region nexus.</li><li><code>weekly-incidents-recap</code> (2): data-theft extortion decoupling from encryption (Kairos county $1M, no encryptor); law-enforcement/platform-disruption momentum (NetNut/Popa botnet, StegoAd, $10M bounty).</li><li><code>weekly-research</code> (1): tradecraft convergence on abusing trusted primitives (ToddyCat Umbrij OAuth-token theft, Talos ARToken, Avalon signed-MSBuild loader, PamStealer, Mustang Panda SaaS dead-drop C2).</li><li><code>weekly-long-running</code> (2): ShinyHunters/UNC6240 Oracle campaign status (<code>update_of</code> W26; Nissan + separate Medtronic claim); FortiBleed → INC Ransom/Lynx attribution (<code>update_of</code> W26; new entity <code>actor:inc-ransom</code>).</li><li><code>weekly-policy</code> (1): Netherlands NIS2 transposition slip (<code>update_of</code> W26; Senate vote 7 July, entry-into-force 15 Aug).</li><li><code>weekly-looking-ahead</code> (1): one <code>outlook</code> entry of items already in motion (ColdFusion CVSS-10 set, NetScaler exploitation fast-follow, WatchGuard 12.5.x pending, Dutch NIS2 vote, ShinyHunters un-notified tail, unconfirmed Nextcloud zero-day claim).</li></ul>
<p>Empty sections: <code>weekly-annual-reports</code> — W1 confirmed no periodic report landed in-window (CrowdStrike/PwC/WEF/Check Point/Huntress items in search results are earlier-2026 recirculations). Legitimately rendered empty.</p>
<p><strong>Dedup polarity (W-PD-8):</strong> every strategic entry re-frames operational entries via <code>references</code> or is an <code>update_of</code> a prior weekly&#39;s strategic entry; frontmatter <code>cves[]</code> on the non-update synthesis entries is intentionally empty (the operational entries own the CVE index — this satisfies the cross-run CVE-dedup gate, which FAILs a non-update entry re-declaring an in-window operational CVE). Entity-key overlaps with operational entries are the expected synthesis WARNs, not defects.</p>
<p><strong>Single-source / carve-out items:</strong></p>
<ul><li>Canton Zürich Baudirektion (MedusaLocker) — uncorroborated leak-site claim; carried only as a monitored situational-awareness signal inside the government-targeting synthesis, framed unconfirmed, no defender action recommended.</li><li>Kairos US-county $1M case — single-source Ransom-ISAC case study; the encryption-less-extortion <em>pattern</em> is corroborated across ShinyHunters + MedusaLocker, so the entry is <code>multi-source</code> with the single-source anchor flagged.</li><li>FortiBleed Nextcloud zero-day — single-source SOCRadar claim, no CVE, pending vendor disclosure; carried as track-do-not-action, not a fact.</li></ul>
<p><strong>Source-discipline catch:</strong> W2 ruled out a WebSearch-surfaced &quot;2 July 2026 OFAC LockBit/Khoroshev sanction&quot; after fetching the OFAC recent-actions primary page directly (no such in-window designation — a hallucination conflating the real 2024 Khoroshev sanction with a fabricated 2026 date). Correctly excluded (PD-1).</p>
<p><strong>Coverage gaps (rotation candidates for next weekly):</strong> W1 — cert-pl, anssi-fr, ncsc-uk not fetched (time budget prioritised the two campaigns with genuine movement). W2 — cert-fr feed stale, ncsc-ch-incidents empty bridge body, bakom-ofcom 404 (URL moved), finma news page menu-only. <code>source_health.py</code> recipe fixes for bakom-ofcom (404, URL moved) and cert-fr (stale feed cache) recommended for a follow-up run. The <code>source_health.py</code> full-store probe was started this run but did not complete within the run budget (slow all-source probe); <code>state/source_health.json</code> retains the prior snapshot. Not blocking — the specific in-window gaps are documented above.</p>
<p><strong>Watchlist:</strong> no products/suppliers configured — sweep is a no-op (W1 duty products+suppliers, W2 none).</p>
<p><strong>Closed-source intake:</strong> none (no in-window <code>intel/</code> drops).</p>
<p><strong>Verification (Phase 5.7):</strong> 2 iterations, model rotation (iter1 Opus <code>cti-verification</code> → NEEDS_FIXES truth=1/editorial=1/advisory=3; iter2 Sonnet <code>cti-verification-alt</code> → CLEAN). All five iteration-1 findings remediated (F3 truth-softening on the Kairos &quot;no encryptor&quot; absolute; F5 added StegoAd + $10M-bounty operational entries to references; three F11 advisories: bounty formatting, Kairos date/event_date, NL NIS2 unsourced date range) and re-verified CLEAN by the alternate model. <code>verification_residual_count = 0</code>. No entries dropped by verification.</p></div></div></div></details>]]></content:encoded></item><item><title>CTI Weekly Summary · 2026-W26</title><link>https://ctipilot.ch/weekly/2026-W26/</link><guid isPermaLink="true">https://ctipilot.ch/weekly/2026-W26/</guid><pubDate>Mon, 22 Jun 2026 00:15:12 +0000</pubDate><dc:date>2026-06-22T00:15:12Z</dc:date><category>CVE-2025-13036</category><category>CVE-2026-0257</category><category>CVE-2026-0646</category><category>CVE-2026-0647</category><category>CVE-2026-11317</category><category>CVE-2026-12569</category><category>CVE-2026-20181</category><category>CVE-2026-20190</category><description><![CDATA[<ul><li><strong>G7 Évian cybersecurity declaration calls PQC an &quot;urgent priority&quot; — and the expected hacktivist DDoS materialised on day one.</strong> Policy: the G7 called PQC an &quot;urgent priority&quot; and the predicted NoName057(16) DDoS hit Swiss-border Haute-Savoie sites; the CRA&#39;s first reporting obligation lands 11 September. (ANSSI, Cyberattaque.org) <a href="https://ctipilot.ch/entries/2026-06-22/g7-vian-cybersecurity-declaration-calls-pqc-an-urgent-priori/">→</a></li><li><strong>ShinyHunters extortion brand — Council of Europe named, Kodak and One Medical added to the leak-site pressure.</strong> ShinyHunters named the Council of Europe in the Oracle PeopleSoft campaign — a European institution of which Switzerland is a member — while adding Kodak and One Medical to its leak-site pressure. (daily 06-16, SecurityWeek) <a href="https://ctipilot.ch/entries/2026-06-22/shinyhunters-extortion-brand-council-of-europe-named-kodak-a/">→</a></li><li><strong>CVE-2026-12569 — PTC Windchill / FlexPLM pre-auth deserialization RCE, exploited, BSI calling admins at 02:30.</strong> PTC Windchill CVE-2026-12569 — pre-auth deserialization RCE (CVSS 10.0) exploited; BSI phoned operators at 02:30 — a DACH manufacturing/defence emergency. (daily 06-20, Heise) <a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/">→</a></li><li><strong>CVE-2026-20253 — Splunk Enterprise pre-auth RCE flips to confirmed exploitation and CISA KEV.</strong> Splunk CVE-2026-20253 flipped to confirmed exploitation and CISA KEV — a pre-auth RCE on the SIEM backbone many CH/EU SOCs run; patch on emergency cadence. (daily 06-20, Splunk PSIRT) <a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-20253-splunk-enterprise-pre-auth-rce-flips-to-confi/">→</a></li><li><strong>FortiBleed — Russian-speaking operator cracking 86,644 FortiGate credentials into Active Directory.</strong> FortiBleed is the Monday-morning escalation — 86,644 FortiGate credentials validated and a Russian-speaking operator pivoting into Active Directory; CISA issued emergency hardening. Treat any exposed FortiGate&#39;s secrets as compromised regardless of patch level. (daily 06-20, SecurityWeek) <a href="https://ctipilot.ch/entries/2026-06-22/fortibleed-russian-speaking-operator-cracking-86-644-fortiga/">→</a></li><li><strong>Research: the AI agent and toolchain control plane became a concrete attack-surface class this week.</strong> The AI agent/toolchain control plane became a concrete attack surface — Microsoft&#39;s AutoJack (web page → host RCE via an agent&#39;s MCP socket) capped a week of LiteLLM, Copilot SearchLeak, Vertex AI and JetBrains-plugin disclosures. (daily 06-20, Microsoft) <a href="https://ctipilot.ch/entries/2026-06-22/research-the-ai-agent-and-toolchain-control-plane-became-a-c/">→</a></li><li><strong>The Gentlemen — EDR-killer framework documented, OT-adjacent victim claimed, operator named.</strong> The Gentlemen RaaS grew +315% in Q1 and impacted OT — ESET exposed its centrally-built GentleKiller EDR-killer; the gang halted milling at Mackay Sugar. (daily 06-19, ESET) <a href="https://ctipilot.ch/entries/2026-06-22/the-gentlemen-edr-killer-framework-documented-ot-adjacent-vi/">→</a></li></ul>]]></description><content:encoded><![CDATA[<div class="tldr"><span class="eyebrow eyebrow--muted">Week at a glance</span><ol><li><span class="num">01</span><span><b>G7 Évian cybersecurity declaration calls PQC an &quot;urgent priority&quot; — and the expected hacktivist DDoS materialised on day one.</b> Policy: the G7 called PQC an &quot;urgent priority&quot; and the predicted NoName057(16) DDoS hit Swiss-border Haute-Savoie sites; the CRA&#39;s first reporting obligation lands 11 September. (ANSSI, Cyberattaque.org) <a href="https://ctipilot.ch/entries/2026-06-22/g7-vian-cybersecurity-declaration-calls-pqc-an-urgent-priori/">→</a></span></li><li><span class="num">02</span><span><b>ShinyHunters extortion brand — Council of Europe named, Kodak and One Medical added to the leak-site pressure.</b> ShinyHunters named the Council of Europe in the Oracle PeopleSoft campaign — a European institution of which Switzerland is a member — while adding Kodak and One Medical to its leak-site pressure. (daily 06-16, SecurityWeek) <a href="https://ctipilot.ch/entries/2026-06-22/shinyhunters-extortion-brand-council-of-europe-named-kodak-a/">→</a></span></li><li><span class="num">03</span><span><b>CVE-2026-12569 — PTC Windchill / FlexPLM pre-auth deserialization RCE, exploited, BSI calling admins at 02:30.</b> PTC Windchill CVE-2026-12569 — pre-auth deserialization RCE (CVSS 10.0) exploited; BSI phoned operators at 02:30 — a DACH manufacturing/defence emergency. (daily 06-20, Heise) <a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/">→</a></span></li><li><span class="num">04</span><span><b>CVE-2026-20253 — Splunk Enterprise pre-auth RCE flips to confirmed exploitation and CISA KEV.</b> Splunk CVE-2026-20253 flipped to confirmed exploitation and CISA KEV — a pre-auth RCE on the SIEM backbone many CH/EU SOCs run; patch on emergency cadence. (daily 06-20, Splunk PSIRT) <a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-20253-splunk-enterprise-pre-auth-rce-flips-to-confi/">→</a></span></li><li><span class="num">05</span><span><b>FortiBleed — Russian-speaking operator cracking 86,644 FortiGate credentials into Active Directory.</b> FortiBleed is the Monday-morning escalation — 86,644 FortiGate credentials validated and a Russian-speaking operator pivoting into Active Directory; CISA issued emergency hardening. Treat any exposed FortiGate&#39;s secrets as compromised regardless of patch level. (daily 06-20, SecurityWeek) <a href="https://ctipilot.ch/entries/2026-06-22/fortibleed-russian-speaking-operator-cracking-86-644-fortiga/">→</a></span></li><li><span class="num">06</span><span><b>Research: the AI agent and toolchain control plane became a concrete attack-surface class this week.</b> The AI agent/toolchain control plane became a concrete attack surface — Microsoft&#39;s AutoJack (web page → host RCE via an agent&#39;s MCP socket) capped a week of LiteLLM, Copilot SearchLeak, Vertex AI and JetBrains-plugin disclosures. (daily 06-20, Microsoft) <a href="https://ctipilot.ch/entries/2026-06-22/research-the-ai-agent-and-toolchain-control-plane-became-a-c/">→</a></span></li><li><span class="num">07</span><span><b>The Gentlemen — EDR-killer framework documented, OT-adjacent victim claimed, operator named.</b> The Gentlemen RaaS grew +315% in Q1 and impacted OT — ESET exposed its centrally-built GentleKiller EDR-killer; the gang halted milling at Mackay Sugar. (daily 06-19, ESET) <a href="https://ctipilot.ch/entries/2026-06-22/the-gentlemen-edr-killer-framework-documented-ot-adjacent-vi/">→</a></span></li></ol></div><nav class="secnav" aria-label="Sections"><a class="secnav-chip" href="#highest-impact-events-what-s-on-fire-if-no-one-acted">Highest-impact events · what&#39;s on fire if no one acted <span class="secnav-n">3</span></a><a class="secnav-chip" href="#multi-day-campaigns-and-chains">Multi-day campaigns and chains <span class="secnav-n">2</span></a><a class="secnav-chip" href="#vulnerability-roll-up">Vulnerability roll-up <span class="secnav-n">11</span></a><a class="secnav-chip" href="#sector-victim-patterns">Sector &amp; victim patterns <span class="secnav-n">5</span></a><a class="secnav-chip" href="#incidents-disclosures-recap">Incidents &amp; disclosures recap <span class="secnav-n">3</span></a><a class="secnav-chip" href="#research-threat-actor-developments">Research &amp; threat-actor developments <span class="secnav-n">6</span></a><a class="secnav-chip" href="#annual-periodic-threat-reports">Annual / periodic threat reports <span class="secnav-n">2</span></a><a class="secnav-chip" href="#long-running-campaigns-status-update">Long-running campaigns · status update <span class="secnav-n">2</span></a><a class="secnav-chip" href="#policy-regulatory-horizon">Policy &amp; regulatory horizon <span class="secnav-n">6</span></a><a class="secnav-chip" href="#looking-ahead-what-to-watch-next-week">Looking ahead · what to watch next week <span class="secnav-n">1</span></a></nav><div class="sect" id="highest-impact-events-what-s-on-fire-if-no-one-acted"><span class="n">01</span><span class="t">Highest-impact events · what&#39;s on fire if no one acted</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio" data-tags="vulnerabilities actively-exploited pre-auth rce" data-regions="europe dach switzerland" data-kind="synthesis" data-priority="high" data-discovered="2026-06-22T00:14:33Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-12569/">CVE-2026-12569</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/">CVE-2026-12569 — PTC Windchill / FlexPLM pre-auth deserialization RCE, exploited, BSI calling admins at 02:30</a></h3><p><strong>If you did nothing this week:</strong> if you run an internet-reachable PTC Windchill or FlexPLM instance, assume compromise — a pre-auth deserialization flaw on the login interface is being exploited to drop backdoors, and the German BSI considered it urgent enough to phone operators in the middle of the night.</p>
<p>CVE-2026-12569 (CVSS 3.1 10.0; CVSS 4.0 9.3) is an unsafe deserialization of untrusted data reachable on the web-based Windchill/FlexPLM login interface <em>before</em> authentication — no credentials, no prior foothold, no user interaction (<a href="https://security-hub.ncsc.admin.ch/#/posts/12713" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub, 2026-06-19</a>; <a href="https://ctipilot.ch/briefs/2026-06-20/" target="_blank" rel="noopener noreferrer">daily 06-20 deep dive</a>). PTC shipped fixes on 2026-06-15 and auto-patched cloud tenants; affected on-premises builds span the 11.x, 12.0.x, 12.1.x, 13.0.x and 13.1.0.0–13.1.3.0 lines as well as releases prior to 11.0 M030 (<a href="https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability" target="_blank" rel="noopener noreferrer">PTC PSIRT</a>). Both BSI and NCSC-CH treat it as actively exploited, with Heise reporting backdoor deployment on vulnerable servers and the BSI escalating to direct after-hours phone calls — a step reserved for its highest-urgency advisories (<a href="https://www.heise.de/en/news/PTC-Windchill-BSI-calls-admins-at-night-due-to-critical-security-vulnerability-11338329.html" target="_blank" rel="noopener noreferrer">Heise Security, 2026-06-19</a>).</p>
<p>Windchill and FlexPLM are the product-lifecycle-management backbone across DACH manufacturing, aerospace, automotive and the defence-industrial base, holding engineering crown jewels (CAD, BOMs, supplier data) behind increasingly internet-reachable supplier portals — which is exactly why the BSI mobilised. Patch every on-premises instance, confirm cloud tenants were auto-patched, and until then pull the login interface off the internet behind a VPN or authenticating reverse proxy. Hunt for Java deserialization exception bursts on the login path and for the Windchill application-server process (JBoss/WildFly/WebLogic) spawning shells or scripting interpreters (<code>T1190</code> → <code>T1505.003</code>).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Attacks on the deserialization vulnerability are apparently already underway to place backdoors on vulnerable servers.</p><p class="entry-cite__quote">At 2:30 AM, a BSI employee called the company, reported a new zero-day vulnerability, and urged immediate patches.</p><figcaption class="entry-cite__attr"><a href="https://www.heise.de/en/news/PTC-Windchill-BSI-calls-admins-at-night-due-to-critical-security-vulnerability-11338329.html" target="_blank" rel="noopener noreferrer">Heise Security</a></figcaption></figure></div><div class="prov"><span>synthesis</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-12569-ptc-windchill-flexplm-pre-auth-deserializatio/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability" target="_blank" rel="noopener noreferrer">PTC PSIRT advisory</a> · <a href="https://www.heise.de/en/news/PTC-Windchill-BSI-calls-admins-at-night-due-to-critical-security-vulnerability-11338329.html" target="_blank" rel="noopener noreferrer">Heise Security</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12713" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-20253-splunk-enterprise-pre-auth-rce-flips-to-confi" data-tags="vulnerabilities actively-exploited pre-auth rce cisa-kev" data-regions="global europe" data-kind="synthesis" data-priority="high" data-discovered="2026-06-22T00:14:32Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20253/">CVE-2026-20253</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-20253-splunk-enterprise-pre-auth-rce-flips-to-confi"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-20253-splunk-enterprise-pre-auth-rce-flips-to-confi/">CVE-2026-20253 — Splunk Enterprise pre-auth RCE flips to confirmed exploitation and CISA KEV</a></h3><p><strong>If you did nothing this week:</strong> if you run an internet-reachable Splunk Enterprise search head on 10.0.x or 10.2.x, you are now exposed to an unauthenticated remote-code-execution path that is being exploited in the wild — and a compromised search head sits at the centre of your detection and log visibility.</p>
<p>When CVE-2026-20253 (CVSS 9.8, CWE-306) was first covered on 2026-06-14 it was a disclosure-plus-patch story. This week Splunk PSIRT confirmed limited exploitation, CISA added it to the KEV catalog on 2026-06-18, and NCSC-NL corroborated (<a href="https://advisory.splunk.com/advisories/SVD-2026-0603" target="_blank" rel="noopener noreferrer">Splunk PSIRT SVD-2026-0603</a>; <a href="https://www.securityweek.com/splunk-enterprise-vulnerability-exploited-in-attacks-days-after-disclosure/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-19</a>; <a href="https://ctipilot.ch/briefs/2026-06-20/" target="_blank" rel="noopener noreferrer">daily 06-20</a>). The flaw is an unauthenticated arbitrary file-creation/truncation primitive reachable through a PostgreSQL sidecar service endpoint that lacks authentication controls, chaining to RCE. It affects Splunk Enterprise 10.0 below 10.0.7 and 10.2 below 10.2.4; fixes (10.4.0 / 10.2.4 / 10.0.7) have been available since 2026-06-14.</p>
<p>The operational weight here is the platform, not the CVSS: Splunk is a standard SIEM backbone inside CH/EU public-sector SOCs, and an attacker who lands pre-auth code execution on the search-head tier owns the analytics plane that defenders rely on. Patch on emergency cadence, restrict search-job submission to authorised analyst accounts, and verify indexer/search-head network segmentation so the PostgreSQL sidecar is not network-reachable from untrusted zones.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">In June 2026, the Splunk Product Security Incident Response Team (PSIRT) became aware of limited exploitation of this vulnerability.</p><p class="entry-cite__quote">an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint</p><figcaption class="entry-cite__attr">Splunk PSIRT</figcaption></figure></div><div class="prov"><span>synthesis</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-20253-splunk-enterprise-pre-auth-rce-flips-to-confi/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://advisory.splunk.com/advisories/SVD-2026-0603" target="_blank" rel="noopener noreferrer">Splunk PSIRT SVD-2026-0603</a> · <a href="https://www.securityweek.com/splunk-enterprise-vulnerability-exploited-in-attacks-days-after-disclosure/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/fortibleed-russian-speaking-operator-cracking-86-644-fortiga" data-tags="actively-exploited data-breach identity russia-nexus" data-regions="global europe" data-kind="synthesis" data-priority="high" data-discovered="2026-06-22T00:14:31Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="fortibleed-russian-speaking-operator-cracking-86-644-fortiga"><a href="https://ctipilot.ch/entries/2026-06-22/fortibleed-russian-speaking-operator-cracking-86-644-fortiga/">FortiBleed — Russian-speaking operator cracking 86,644 FortiGate credentials into Active Directory</a></h3><p><strong>If you did nothing this week:</strong> any internet-facing FortiGate whose admin or SSL VPN credentials are in the &quot;FortiBleed&quot; corpus is a live initial-access foothold right now — patch level is irrelevant, because the leaked credential is the weapon, and the operator is already pivoting from validated VPN logins into internal Active Directory.</p>
<p>The FortiBleed dataset surfaced on 2026-06-17 as 73,932 unique FortiGate management URLs (~75,000 devices across 194 countries) paired with valid VPN and administrative credentials (<a href="https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-17</a>; <a href="https://ctipilot.ch/briefs/2026-06-18/" target="_blank" rel="noopener noreferrer">daily 06-18</a>). By 2026-06-19 the verified count had grown to 86,644 confirmed working credentials and CISA had issued an emergency hardening advisory (<a href="https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-19</a>; <a href="https://ctipilot.ch/briefs/2026-06-20/" target="_blank" rel="noopener noreferrer">daily 06-20</a>). Fortinet&#39;s PSIRT confirmed the campaign ties to previously disclosed incidents (FG-IR-26-060 / FG-IR-25-647) and that the credentials originated from exported device configurations — its position is that this is <strong>not a new CVE</strong>, the corpus being a reshare of prior-incident data combined with large-scale brute-forcing (<a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices" target="_blank" rel="noopener noreferrer">Fortinet PSIRT, 2026-06-19</a>) — but that distinction is cold comfort operationally: the credentials validate. The methodology that emerged this week is the load-bearing detail. A Russian-speaking actor intercepts SSL VPN authentication, cracks the captured hashes on a 45-GPU Hashtopolis cluster, and then uses the recovered service and admin accounts to move laterally into internal Active Directory (<code>T1078</code> valid accounts following <code>T1110</code> credential cracking).</p>
<p>The escalation that makes this § 1 rather than a routine credential-leak note is the AD pivot plus CISA&#39;s mandated response: terminate all SSL VPN sessions, reset every credential, migrate admin-hash storage from the older MD5-crypt scheme to PBKDF2, and enforce phishing-resistant MFA on all remote access. FortiGate is ubiquitous on Swiss and EU public-sector and telco perimeters, so treat any exposed device&#39;s local admin and VPN secrets as potentially in the corpus regardless of firmware version. Hunt for sequential VPN authentication failures from rotating residential IP ranges followed by a success and immediate internal RDP/SMB/LDAP reconnaissance, and cross-reference SSL VPN session logs against the Shadowserver notification feed.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Discovered in June 2026, the operation has produced a verified database of over 86,644 confirmed working credentials across 194 countries</p><p class="entry-cite__quote">They intercept SSL VPN authentication, crack hashes on a 45-GPU cluster managed via Hashtopolis, and pivot into internal Active Directory environments</p><figcaption class="entry-cite__attr"><a href="https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></figcaption></figure></div><div class="prov"><span>synthesis</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/fortibleed-russian-speaking-operator-cracking-86-644-fortiga/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices" target="_blank" rel="noopener noreferrer">Fortinet PSIRT</a> · <a href="https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/" target="_blank" rel="noopener noreferrer">BleepingComputer — first coverage</a></div></article><div class="sect" id="multi-day-campaigns-and-chains"><span class="n">02</span><span class="t">Multi-day campaigns and chains</span><span class="c">2 items</span></div><article class="finding entry-card" data-entry-id="2026-06-22/shinyhunters-extortion-brand-council-of-europe-named-kodak-a" data-tags="data-breach organized-crime espionage" data-regions="global europe" data-kind="synthesis" data-priority="high" data-discovered="2026-06-22T00:14:34Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="shinyhunters-extortion-brand-council-of-europe-named-kodak-a"><a href="https://ctipilot.ch/entries/2026-06-22/shinyhunters-extortion-brand-council-of-europe-named-kodak-a/">ShinyHunters extortion brand — Council of Europe named, Kodak and One Medical added to the leak-site pressure</a></h3><p>The ShinyHunters extortion brand (the data-theft cluster Google tracks as UNC6240) ran on two fronts this week. The technical core remains the Oracle PeopleSoft zero-day campaign (CVE-2026-35273) consolidated in the W24 weekly, and Google&#39;s Threat Intelligence Group sharpened it this week: GTIG&#39;s analysis confirms UNC6240 exploited the flaw between 27 May and 9 June as a zero-day, has notified 100+ organisations (68% in higher education), and documented the TTPs — JSP shell implant, a customised MeshCentral agent masquerading as Azure cloud endpoints, <code>[victim]_fanout.sh</code> SSH credential-spraying and <code>zstd</code>-compressed exfiltration (<a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit" target="_blank" rel="noopener noreferrer">Google GTIG</a>). On 2026-06-16 ShinyHunters listed the <strong>Council of Europe</strong> — the 46-member Strasbourg human-rights body of which Switzerland is a member — claiming roughly 297 GB exfiltrated; per W1&#39;s assessment it is the only named European-institution victim in the campaign to date (<a href="https://www.securityweek.com/shinyhunters-claims-council-of-europe-hack/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-16</a>; <a href="https://ctipilot.ch/briefs/2026-06-16/" target="_blank" rel="noopener noreferrer">daily 06-16</a>). In parallel the brand expanded its leak-site extortion pressure beyond PeopleSoft: Eastman Kodak confirmed on 2026-06-17 that &quot;an unauthorized third party illegally gained access to a limited amount of company data&quot; after a ShinyHunters listing (<a href="https://www.securityweek.com/kodak-admits-data-breach-after-shinyhunters-hack-claims/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-19</a>; <a href="https://ctipilot.ch/briefs/2026-06-20/" target="_blank" rel="noopener noreferrer">daily 06-20</a>), and Amazon&#39;s One Medical confirmed a legacy third-party file-storage breach while ShinyHunters&#39; unverified 8.8 TB claim ran a deadline that expired 2026-06-21 (<a href="https://www.bankinfosecurity.com/shinyhunters-threatens-to-leak-amazon-one-medical-records-a-32027" target="_blank" rel="noopener noreferrer">BankInfoSecurity, 2026-06-20</a>; <a href="https://ctipilot.ch/briefs/2026-06-21/" target="_blank" rel="noopener noreferrer">daily 06-21</a>).</p>
<p>The cross-day pattern for a CH/EU SOC: the same brand is simultaneously running a confirmed enterprise-SaaS zero-day (PeopleSoft, vendor-confirmed) and a higher-noise leak-site operation where claims (Kodak data volume, the One Medical 8.8 TB figure) are attacker-asserted and partly unverified. Triage the two differently — the PeopleSoft exposure is a patch-and-hunt emergency for internet-reachable instances; the leak-site listings warrant victim-notification monitoring but the headline data volumes should be treated as unconfirmed until the victim corroborates.</p><div class="prov"><span>synthesis</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/shinyhunters-extortion-brand-council-of-europe-named-kodak-a/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit" target="_blank" rel="noopener noreferrer">Google GTIG</a> · <a href="https://www.securityweek.com/shinyhunters-claims-council-of-europe-hack/" target="_blank" rel="noopener noreferrer">SecurityWeek — Council of Europe</a> · <a href="https://www.securityweek.com/kodak-admits-data-breach-after-shinyhunters-hack-claims/" target="_blank" rel="noopener noreferrer">SecurityWeek — Kodak</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/the-gentlemen-edr-killer-framework-documented-ot-adjacent-vi" data-tags="ransomware organized-crime russia-nexus ot-ics" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-06-22T00:14:35Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="the-gentlemen-edr-killer-framework-documented-ot-adjacent-vi"><a href="https://ctipilot.ch/entries/2026-06-22/the-gentlemen-edr-killer-framework-documented-ot-adjacent-vi/">The Gentlemen — EDR-killer framework documented, OT-adjacent victim claimed, operator named</a></h3><p>The Gentlemen RaaS operation moved from tooling disclosure to victim impact to attribution across three days. On 2026-06-18 ESET published a months-long investigation showing the gang <strong>centrally builds and maintains its affiliates&#39; GentleKiller EDR-killer framework</strong> — a structural departure from the affiliate norm in which each affiliate sources its own evasion tooling (<a href="https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/" target="_blank" rel="noopener noreferrer">ESET, 2026-06-19</a>; <a href="https://ctipilot.ch/briefs/2026-06-19/" target="_blank" rel="noopener noreferrer">daily 06-19</a>). On 2026-06-18 Mackay Sugar — Australia&#39;s second-largest sugar producer — confirmed an intrusion around 10 June that halted milling at two of three mills, an OT-adjacent impact the group later claimed (<a href="https://therecord.media/mackay-sugar-cyberattack-claimed-gentlemen" target="_blank" rel="noopener noreferrer">The Record, 2026-06-18</a>; <a href="https://ctipilot.ch/briefs/2026-06-20/" target="_blank" rel="noopener noreferrer">daily 06-20</a>). Separately, KrebsOnSecurity published OSINT attribution identifying the group&#39;s administrator (&quot;Hastalamuerte&quot; / &quot;Zeta88&quot;) as a 36-year-old from Izhevsk, Russia, who reportedly uses AI tooling to develop ransomware and assist post-exploitation (<a href="https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/" target="_blank" rel="noopener noreferrer">KrebsOnSecurity, 2026-06-10</a>).</p>
<p>The defender signal is the centralised EDR-killer model: because the BYOVD evasion tooling is built once and pushed to all affiliates, detection content that catches GentleKiller&#39;s driver-load and EDR-tamper behaviour generalises across every affiliate intrusion rather than needing per-affiliate tuning. The Krebs attribution is an analytical claim, not an indictment — treat it as context, not actionable IOC.</p><div class="prov"><span>synthesis</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/the-gentlemen-edr-killer-framework-documented-ot-adjacent-vi/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a> · <a href="https://therecord.media/mackay-sugar-cyberattack-claimed-gentlemen" target="_blank" rel="noopener noreferrer">The Record</a></div></article><div class="sect" id="vulnerability-roll-up"><span class="n">03</span><span class="t">Vulnerability roll-up</span><span class="c">11 items</span></div><article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-55803-cve-2026-55804-drupal-core-php-object-injecti" data-tags="vulnerabilities rce patch-available eu-nexus" data-regions="europe global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:47Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-55803/">CVE-2026-55803 +1</a></div><h3 class="f-h" id="cve-2026-55803-cve-2026-55804-drupal-core-php-object-injecti"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-55803-cve-2026-55804-drupal-core-php-object-injecti/">CVE-2026-55803 / CVE-2026-55804 — Drupal core: PHP object-injection chain in JSON:API, BSI-rated critical</a></h3><p>The Drupal Security Team published six advisories on 2026-06-17 (fixed in 10.5.12, 10.6.11, 11.2.14, 11.3.12); BSI escalated the aggregate to <em>kritisch</em> (<a href="https://www.drupal.org/sa-core-2026-005" target="_blank" rel="noopener noreferrer">Drupal SA-CORE-2026-005</a>; <a href="https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2002" target="_blank" rel="noopener noreferrer">BSI CERT-Bund</a>; <a href="https://ctipilot.ch/briefs/2026-06-19/" target="_blank" rel="noopener noreferrer">daily 06-19</a>). Drupal runs a large share of European government and university sites, making this a public-sector CMS patch priority. Update core immediately.</p><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-55803-cve-2026-55804-drupal-core-php-object-injecti/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.drupal.org/sa-core-2026-005" target="_blank" rel="noopener noreferrer">Drupal SA-CORE-2026-005</a> · <a href="https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2002" target="_blank" rel="noopener noreferrer">BSI CERT-Bund WID-SEC-2026-2002</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic" data-tags="vulnerabilities ot-ics auth-bypass dos pre-auth" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:46Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-0647/">CVE-2026-0647 +3</a></div><h3 class="f-h" id="cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic/">CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (9.4) and Logix CIP DoS, flagged by NCSC-CH</a></h3><p>Rockwell disclosed five ICS CVEs on 2026-06-16, consolidated by NCSC-CH on 2026-06-17 and CISA ICS-CERT, headlined by an unauthenticated FLEX I/O password reset (CVE-2026-0647, 9.4) and Logix CIP denial-of-service flaws (<a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05" target="_blank" rel="noopener noreferrer">CISA ICS-CERT ICSA-26-167-05</a>; <a href="https://security-hub.ncsc.admin.ch/#/posts/12639" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub</a>; <a href="https://ctipilot.ch/briefs/2026-06-18/" target="_blank" rel="noopener noreferrer">daily 06-18</a>). Directly relevant to Swiss/EU energy, water and manufacturing OT operators. Patch on the OT change-management cycle and verify these controllers are not reachable from IT networks.</p><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-0647-et-al-rockwell-automation-flex-i-o-unauthentic/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05" target="_blank" rel="noopener noreferrer">CISA ICS-CERT ICSA-26-167-05</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12639" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-20181-cve-2026-20190-cisco-identity-services-engine" data-tags="vulnerabilities rce priv-esc auth-bypass info-disclosure" data-regions="global europe switzerland" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:45Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20181/">CVE-2026-20181 +1</a></div><h3 class="f-h" id="cve-2026-20181-cve-2026-20190-cisco-identity-services-engine"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-20181-cve-2026-20190-cisco-identity-services-engine/">CVE-2026-20181 / CVE-2026-20190 — Cisco Identity Services Engine: unauthenticated credential read chaining to root command execution</a></h3><p>Two flaws in Cisco ISE and the ISE Passive Identity Connector let an unauthenticated attacker read credentials (CVE-2026-20181, 9.1) that chain to authenticated root command execution (CVE-2026-20190, 7.5); BSI flagged the pair for DACH operators (<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a>; <a href="https://ctipilot.ch/briefs/2026-06-19/" target="_blank" rel="noopener noreferrer">daily 06-19</a>). ISE is the network-access-control and policy backbone in many enterprise and public-sector networks — a rooted ISE undermines NAC posture wholesale. Patch promptly.</p><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-20181-cve-2026-20190-cisco-identity-services-engine/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a> · <a href="https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1989" target="_blank" rel="noopener noreferrer">BSI CERT-Bund WID-SEC-2026-1989</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen" data-tags="vulnerabilities auth-bypass poc-public" data-regions="europe global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:43Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-50751/">CVE-2026-50751</a></div><h3 class="f-h" id="cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen/">CVE-2026-50751 — Check Point Security Gateway IKEv1 VPN authentication bypass: public PoC, Qilin affiliate use</a></h3><p>Status update on the W24 § 1 item: NCSC-NL updated its advisory on 2026-06-16 to note public proof-of-concept code is now available for the IKEv1 VPN authentication bypass, which a Qilin ransomware affiliate has used for initial access (<a href="https://www.helpnetsecurity.com/2026/06/12/cve-2026-50751-poc-exploit/" target="_blank" rel="noopener noreferrer">Help Net Security</a>; <a href="https://advisories.ncsc.nl/advisory?id=NCSC-2026-0179" target="_blank" rel="noopener noreferrer">NCSC-NL NCSC-2026-0179</a>; <a href="https://ctipilot.ch/briefs/2026-06-17/" target="_blank" rel="noopener noreferrer">daily 06-17</a>). A Remote Access VPN gateway still running the deprecated IKEv1 path is an active ransomware entry point. Apply the Check Point hotfix and disable IKEv1 where IKEv2 can replace it.</p><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.helpnetsecurity.com/2026/06/12/cve-2026-50751-poc-exploit/" target="_blank" rel="noopener noreferrer">Help Net Security</a> · <a href="https://advisories.ncsc.nl/advisory?id=NCSC-2026-0179" target="_blank" rel="noopener noreferrer">NCSC-NL advisory NCSC-2026-0179</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-0257-palo-alto-networks-pan-os-globalprotect-authen" data-tags="vulnerabilities actively-exploited auth-bypass cisa-kev" data-regions="europe global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:37Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-0257/">CVE-2026-0257</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-0257-palo-alto-networks-pan-os-globalprotect-authen"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-0257-palo-alto-networks-pan-os-globalprotect-authen/">CVE-2026-0257 — Palo Alto Networks PAN-OS GlobalProtect: authentication bypass under active exploitation</a></h3><p>First disclosed in May and KEV-listed on 2026-05-29, the GlobalProtect portal/gateway authentication bypass moved into a confirmed exploitation wave this week. Unit 42 observed active exploitation by an unidentified actor attempting to access GlobalProtect, with Arctic Wolf reporting increasing exploitation volume and NCSC-CH refreshing its advisory on 2026-06-16 (<a href="https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/" target="_blank" rel="noopener noreferrer">Unit 42</a>; <a href="https://ctipilot.ch/briefs/2026-06-17/" target="_blank" rel="noopener noreferrer">daily 06-17</a>). Notably, Unit 42 states no post-access lateral movement had been identified as of its analysis — so the current operational signal is unauthorised VPN session establishment, not yet confirmed downstream compromise. Patch to the fixed PAN-OS trains, and hunt GlobalProtect logs for authentications that bypass the expected portal flow.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Palo Alto Networks Unit 42 has observed active exploitation of PAN-OS vulnerability CVE-2026-0257 by an unidentified threat actor attempting to access GlobalProtect.</p><p class="entry-cite__quote">No post-access behavior or lateral movement has been identified as of this time.</p><figcaption class="entry-cite__attr"><a href="https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/" target="_blank" rel="noopener noreferrer">Unit 42</a></figcaption></figure></div><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-0257-palo-alto-networks-pan-os-globalprotect-authen/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/" target="_blank" rel="noopener noreferrer">Unit 42</a> · <a href="https://security.paloaltonetworks.com/CVE-2026-0257" target="_blank" rel="noopener noreferrer">Palo Alto Networks PSIRT</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12605" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-46978-cve-2026-35278-oracle-june-2026-cspu-unauthen" data-tags="vulnerabilities rce pre-auth patch-available" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:44Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-46978/">CVE-2026-46978 +1</a></div><h3 class="f-h" id="cve-2026-46978-cve-2026-35278-oracle-june-2026-cspu-unauthen"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-46978-cve-2026-35278-oracle-june-2026-cspu-unauthen/">CVE-2026-46978 / CVE-2026-35278 — Oracle June 2026 CSPU: unauthenticated Solaris RAD flaw (10.0) and PeopleSoft RCE (9.8)</a></h3><p>Oracle&#39;s June Critical Security Patch Update shipped 245 fixes on 2026-06-17, around 100 remotely exploitable without authentication, headlined by an unauthenticated Solaris Remote Administration Daemon flaw (CVE-2026-46978, CVSS 10.0) and a PeopleSoft RCE (CVE-2026-35278, 9.8) (<a href="https://www.oracle.com/security-alerts/cspujun2026.html" target="_blank" rel="noopener noreferrer">Oracle CSPU</a>; <a href="https://ctipilot.ch/briefs/2026-06-18/" target="_blank" rel="noopener noreferrer">daily 06-18</a>). The PeopleSoft fix lands in the middle of the ShinyHunters PeopleSoft campaign (§ 2) — prioritise PeopleSoft and any internet-reachable Solaris RAD instances.</p><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-46978-cve-2026-35278-oracle-june-2026-cspu-unauthen/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.oracle.com/security-alerts/cspujun2026.html" target="_blank" rel="noopener noreferrer">Oracle CSPU advisory</a> · <a href="https://www.securityweek.com/oracles-second-monthly-security-updates-deliver-245-patches/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-4020-gravity-smtp-wordpress-plugin-unauthenticated" data-tags="vulnerabilities actively-exploited info-disclosure pre-auth" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:42Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-4020/">CVE-2026-4020</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-4020-gravity-smtp-wordpress-plugin-unauthenticated"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-4020-gravity-smtp-wordpress-plugin-unauthenticated/">CVE-2026-4020 — Gravity SMTP WordPress plugin: unauthenticated credential dump, mass-exploited</a></h3><p>An unauthenticated information-disclosure flaw in the Gravity SMTP plugin (all versions through 2.1.4) lets an attacker dump the configured email-connector credentials (SMTP, SendGrid, Mailgun and similar API keys), and it is being mass-exploited (<a href="https://github.com/advisories/GHSA-jxfc-8wcq-xxcg" target="_blank" rel="noopener noreferrer">GitHub Advisory GHSA-jxfc-8wcq-xxcg</a>; <a href="https://ctipilot.ch/briefs/2026-06-21/" target="_blank" rel="noopener noreferrer">daily 06-21</a>). Stolen mail-sending credentials enable downstream phishing from a trusted domain. Update the plugin and rotate every credential stored in it.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">An unauthenticated information-disclosure flaw in the Gravity SMTP plugin (all versions through 2.1.4) lets an attacker dump the configured email-connector credentials (SMTP, SendGrid, Mailgun and similar API keys), and it is being mass-exploited (GitHub Advisory GHSA-jxfc-8wcq-xxcg; daily 06-21).</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-4020-gravity-smtp-wordpress-plugin-unauthenticated/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://github.com/advisories/GHSA-jxfc-8wcq-xxcg" target="_blank" rel="noopener noreferrer">GitHub Advisory GHSA-jxfc-8wcq-xxcg</a> · <a href="https://thenextweb.com/news/gravity-smtp-wordpress-plugin-vulnerability-cve-2026-4020-api-keys-exploit" target="_blank" rel="noopener noreferrer">The Next Web</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-25089-cve-2026-39808-cve-2026-39813-fortisandbox-th" data-tags="vulnerabilities actively-exploited pre-auth rce auth-bypass" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:41Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-39808/">CVE-2026-39808 +2</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-25089-cve-2026-39808-cve-2026-39813-fortisandbox-th"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-25089-cve-2026-39808-cve-2026-39813-fortisandbox-th/">CVE-2026-25089 / CVE-2026-39808 / CVE-2026-39813 — FortiSandbox: three critical flaws exploited in one 24-hour window</a></h3><p>What was disclosure-only on 06-12 became active exploitation this week: Defused Cyber reported three FortiSandbox flaws exploited within a single 24-hour window — a JRPC OS command injection (CVE-2026-39808, 9.8), a JRPC path-traversal/auth-bypass (CVE-2026-39813, 9.1), and the web-UI command injection (CVE-2026-25089, 9.8) (<a href="https://securityaffairs.com/193709/ai/fortinet-warned-as-three-critical-fortisandbox-bugs-come-under-attack.html" target="_blank" rel="noopener noreferrer">Security Affairs</a>; <a href="https://ctipilot.ch/briefs/2026-06-17/" target="_blank" rel="noopener noreferrer">daily 06-17</a>). FortiSandbox supplies the verdicts FortiGate, FortiMail, FortiProxy and FortiClient consume, so a compromised sandbox can suppress detection across the dependent Fortinet stack. The CVE-2026-25089 in-the-wild exploit appears AI-generated and faulty yet still finds traction against unpatched interfaces; Fortinet has not officially confirmed exploitation. Patch all three and restrict management-interface exposure.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">What was disclosure-only on 06-12 became active exploitation this week: Defused Cyber reported three FortiSandbox flaws exploited within a single 24-hour window — a JRPC OS command injection (CVE-2026-39808, 9.8), a JRPC path-traversal/auth-bypass (CVE-2026-39813, 9.1), and the web-UI command …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-25089-cve-2026-39808-cve-2026-39813-fortisandbox-th/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securityaffairs.com/193709/ai/fortinet-warned-as-three-critical-fortisandbox-bugs-come-under-attack.html" target="_blank" rel="noopener noreferrer">Security Affairs</a> · <a href="https://www.helpnetsecurity.com/2026/06/16/fortisandbox-vulnerabilities-cve-2026-39813-cve-2026-39808-cve-2026-25089/" target="_blank" rel="noopener noreferrer">Help Net Security</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-54420-litespeed-cpanel-whm-plugin-symlink-following" data-tags="vulnerabilities actively-exploited priv-esc cisa-kev" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:40Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-54420/">CVE-2026-54420</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-54420-litespeed-cpanel-whm-plugin-symlink-following"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-54420-litespeed-cpanel-whm-plugin-symlink-following/">CVE-2026-54420 — LiteSpeed cPanel/WHM plugin: symlink-following on shared hosting, exploited (CISA KEV)</a></h3><p>The LiteSpeed cPanel plugin before 2.4.8 mishandles user-supplied symlinks on CloudLinux/CageFS shared hosting, letting a user with FTP or web-shell access escalate; it is exploited in the wild and KEV-listed (<a href="https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/" target="_blank" rel="noopener noreferrer">LiteSpeed</a>; <a href="https://ctipilot.ch/briefs/2026-06-16/" target="_blank" rel="noopener noreferrer">daily 06-16</a>). Relevant to any public-sector or education entity running shared cPanel hosting. Update to the LiteSpeed WHM PlugIn version 5.3.2.1.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">The LiteSpeed cPanel plugin before 2.4.8 mishandles user-supplied symlinks on CloudLinux/CageFS shared hosting, letting a user with FTP or web-shell access escalate; it is exploited in the wild and KEV-listed (LiteSpeed; daily 06-16).</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-54420-litespeed-cpanel-whm-plugin-symlink-following/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.litespeedtech.com/2026/06/01/security-update-for-litespeed-cpanel-plugin-2/" target="_blank" rel="noopener noreferrer">LiteSpeed security update</a> · <a href="https://www.cisa.gov/news-events/alerts/2026/06/15/cisa-adds-two-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer">CISA KEV alert</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-48907-joomla-content-editor-jce-unauthenticated-pro" data-tags="vulnerabilities actively-exploited pre-auth rce cisa-kev" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:39Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-48907/">CVE-2026-48907</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-48907-joomla-content-editor-jce-unauthenticated-pro"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-48907-joomla-content-editor-jce-unauthenticated-pro/">CVE-2026-48907 — Joomla Content Editor (JCE): unauthenticated profile-import to PHP RCE (CVSS 4.0 10.0, CISA KEV)</a></h3><p>JCE is one of the most widely installed Joomla editors across European universities, municipalities and community portals. CVE-2026-48907 chains weaknesses in the profile-import workflow into unauthenticated PHP remote code execution, is rated CVSS 4.0 10.0, and was KEV-listed on 2026-06-16 (<a href="https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites" target="_blank" rel="noopener noreferrer">Widget Factory / JCE</a>; <a href="https://www.yeswehack.com/news/rce-joomla-content-editor-extension" target="_blank" rel="noopener noreferrer">YesWeHack</a>; <a href="https://ctipilot.ch/briefs/2026-06-17/" target="_blank" rel="noopener noreferrer">daily 06-17</a>). Update to JCE 2.9.99.5 or later; the vendor also shipped a free patch for older sites.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">JCE is one of the most widely installed Joomla editors across European universities, municipalities and community portals.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-48907-joomla-content-editor-jce-unauthenticated-pro/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites" target="_blank" rel="noopener noreferrer">Widget Factory / JCE security update</a> · <a href="https://www.yeswehack.com/news/rce-joomla-content-editor-extension" target="_blank" rel="noopener noreferrer">YesWeHack technical write-up</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/cve-2026-20262-cisco-catalyst-sd-wan-manager-authenticated-a" data-tags="vulnerabilities actively-exploited rce path-traversal cisa-kev" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-22T00:14:38Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20262/">CVE-2026-20262</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-20262-cisco-catalyst-sd-wan-manager-authenticated-a"><a href="https://ctipilot.ch/entries/2026-06-22/cve-2026-20262-cisco-catalyst-sd-wan-manager-authenticated-a/">CVE-2026-20262 — Cisco Catalyst SD-WAN Manager: authenticated arbitrary file write to root, exploited as a zero-day (CISA KEV)</a></h3><p>A path-traversal weakness in the web UI of Cisco Catalyst SD-WAN Manager (formerly vManage) lets an authenticated remote attacker create or overwrite any file on the underlying OS and escalate to root code execution; Cisco patched it after zero-day exploitation and CISA added it to KEV (<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a>; <a href="https://ctipilot.ch/briefs/2026-06-16/" target="_blank" rel="noopener noreferrer">daily 06-16</a>). SD-WAN Manager is the centralised control plane for an entire SD-WAN fabric, so a rooted controller is a fabric-wide compromise. Patch on emergency cadence and restrict management-plane access to a dedicated administrative network.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">A path-traversal weakness in the web UI of Cisco Catalyst SD-WAN Manager (formerly vManage) lets an authenticated remote attacker create or overwrite any file on the underlying OS and escalate to root code execution; Cisco patched it after zero-day exploitation and CISA added it to KEV (Cisco …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cve-2026-20262-cisco-catalyst-sd-wan-manager-authenticated-a/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a> · <a href="https://www.theregister.com/patches/2026/06/15/cisco-sd-wan-make-me-root-bug-under-attack/5255916" target="_blank" rel="noopener noreferrer">The Register</a></div></article><div class="sect" id="sector-victim-patterns"><span class="n">04</span><span class="t">Sector &amp; victim patterns</span><span class="c">5 items</span></div><article class="finding entry-card" data-entry-id="2026-06-22/education-exposed-cms-and-forum-software-stack-a-structural" data-tags="vulnerabilities data-breach" data-regions="europe global" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-22T00:14:49Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="education-exposed-cms-and-forum-software-stack-a-structural"><a href="https://ctipilot.ch/entries/2026-06-22/education-exposed-cms-and-forum-software-stack-a-structural/">Education — exposed CMS and forum software stack a structural risk</a></h3><p>Education entities sat under two pressures this week: the continuing ShinyHunters PeopleSoft campaign that W24 documented landing disproportionately on universities, and a cluster of critical web-application CVEs in software ubiquitous across European universities and student communities — JCE for Joomla (CVE-2026-48907, exploited), phpBB (CVE-2026-48611), Drupal core (CVE-2026-55803, BSI critical) and LiteSpeed shared-hosting (CVE-2026-54420, exploited), all in § 3. The pattern is not a single incident but an attack-surface concentration: the open-source CMS/forum/hosting stack that the education sector runs widely all took critical, partly-exploited disclosures in one week.</p><div class="prov"><span>synthesis</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/education-exposed-cms-and-forum-software-stack-a-structural/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.joomlacontenteditor.net/news/jce-security-update-and-a-free-patch-for-older-sites" target="_blank" rel="noopener noreferrer">Widget Factory / JCE</a> · <a href="https://www.drupal.org/sa-core-2026-005" target="_blank" rel="noopener noreferrer">Drupal SA-CORE-2026-005</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/public-administration-named-european-institutions-and-govern" data-tags="data-breach hacktivism iran-nexus" data-regions="us europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-22T00:14:48Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="public-administration-named-european-institutions-and-govern"><a href="https://ctipilot.ch/entries/2026-06-22/public-administration-named-european-institutions-and-govern/">Public administration — named European institutions and government data in the firing line</a></h3><p>The public sector again carried high-severity activity on multiple vectors. The Council of Europe — a Strasbourg human-rights body of which Switzerland is a member — was named in the ShinyHunters PeopleSoft campaign (§ 2). Iran-aligned Handala breached California Water Service through an internet-exposed RTKBase GNSS platform, leaking billing PII for ~2M customers though without OT access (<a href="https://www.securityweek.com/iranian-cyber-group-handala-claims-cal-water-hack/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-06-14</a>; <a href="https://ctipilot.ch/briefs/2026-06-15/" target="_blank" rel="noopener noreferrer">daily 06-15</a>). Texas Parks &amp; Wildlife disclosed a third-party-vendor breach exposing 3.08M licence holders&#39; names and driver&#39;s-licence numbers (<a href="https://www.bleepingcomputer.com/news/security/texas-govt-data-breach-exposes-over-3-million-drivers-licenses/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-18</a>; <a href="https://ctipilot.ch/briefs/2026-06-21/" target="_blank" rel="noopener noreferrer">daily 06-21</a>). And the recurring lesson for CH/EU administration is the PTC Windchill emergency (§ 1), where the BSI&#39;s after-hours calls underline how government CERTs are now treating internet-exposed public-sector and industrial software.</p><div class="prov"><span>synthesis</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/public-administration-named-european-institutions-and-govern/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.securityweek.com/iranian-cyber-group-handala-claims-cal-water-hack/" target="_blank" rel="noopener noreferrer">SecurityWeek — Cal Water</a> · <a href="https://www.bleepingcomputer.com/news/security/texas-govt-data-breach-exposes-over-3-million-drivers-licenses/" target="_blank" rel="noopener noreferrer">BleepingComputer — Texas Parks</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/technology-saas-supply-chain-the-week-s-busiest-victim-class" data-tags="supply-chain data-breach north-korea-nexus" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-22T00:14:52Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="technology-saas-supply-chain-the-week-s-busiest-victim-class"><a href="https://ctipilot.ch/entries/2026-06-22/technology-saas-supply-chain-the-week-s-busiest-victim-class/">Technology &amp; SaaS supply chain — the week&#39;s busiest victim class</a></h3><p>The most active victim class was technology and SaaS, reflecting the week&#39;s supply-chain theme (§ 6). Klue/Icarus (§ 2) cascaded through a SaaS integrator&#39;s customer base; Nintendo employee data was stolen from third-party HR-survey SaaS TinyPulse, not Nintendo&#39;s own systems (<a href="https://www.bleepingcomputer.com/news/security/nintendo-confirms-data-stolen-in-webmd-subsidiary-cyberattack/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-20</a>; <a href="https://ctipilot.ch/briefs/2026-06-20/" target="_blank" rel="noopener noreferrer">daily 06-20</a>); a WordPress supply-chain compromise via Awesome Motive&#39;s CDN backdoored ~1.2M sites (<a href="https://sansec.io/research/optinmonster-supply-chain-attack" target="_blank" rel="noopener noreferrer">Sansec, 2026-06-16</a>; <a href="https://ctipilot.ch/briefs/2026-06-16/" target="_blank" rel="noopener noreferrer">daily 06-16</a>); and the Mastra npm scope compromise was attributed to North Korea (§ 6). The cross-cutting lesson: the breach increasingly enters through a vendor&#39;s plumbing, not the victim&#39;s perimeter.</p><div class="prov"><span>synthesis</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/technology-saas-supply-chain-the-week-s-busiest-victim-class/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://sansec.io/research/optinmonster-supply-chain-attack" target="_blank" rel="noopener noreferrer">Sansec — OptinMonster</a> · <a href="https://www.bleepingcomputer.com/news/security/nintendo-confirms-data-stolen-in-webmd-subsidiary-cyberattack/" target="_blank" rel="noopener noreferrer">BleepingComputer — Nintendo/TinyPulse</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/energy-water-ot-perimeter-and-process-failures-with-an-ot-ad" data-tags="data-breach ot-ics" data-regions="apac global" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-22T00:14:51Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="energy-water-ot-perimeter-and-process-failures-with-an-ot-ad"><a href="https://ctipilot.ch/entries/2026-06-22/energy-water-ot-perimeter-and-process-failures-with-an-ot-ad/">Energy, water &amp; OT — perimeter and process failures, with an OT-adjacent halt</a></h3><p>Critical-infrastructure exposure ran from cyber intrusion to physical mishandling. Handala&#39;s Cal Water breach (above) and the Rockwell ICS advisory batch (§ 3) bracket the cyber end; at the process end, a Kyushu Electric subsidiary lost an unencrypted portable SSD holding ~10.9M customer records — reportedly Japan&#39;s largest personal-data breach (<a href="https://www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-14</a>; <a href="https://ctipilot.ch/briefs/2026-06-14/" target="_blank" rel="noopener noreferrer">daily 06-14</a>). The Gentlemen&#39;s Mackay Sugar claim (§ 2) halted milling at two of three mills — an OT-adjacent production impact even without confirmed OT-network compromise.</p><div class="prov"><span>synthesis</span><span>22 Jun 00:14Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/energy-water-ot-perimeter-and-process-failures-with-an-ot-ad/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/" target="_blank" rel="noopener noreferrer">BleepingComputer — Kyushu Electric</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/healthcare-third-party-exposure-and-a-16-month-notification" data-tags="data-breach ransomware" data-regions="uk us" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-22T00:14:50Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="healthcare-third-party-exposure-and-a-16-month-notification"><a href="https://ctipilot.ch/entries/2026-06-22/healthcare-third-party-exposure-and-a-16-month-notification/">Healthcare — third-party exposure and a 16-month notification gap</a></h3><p>Healthcare breaches this week were dominated by third-party and disclosure-timing failures rather than direct perimeter compromise. iRhythm filed an SEC 8-K reporting data theft via social engineering of a third-party-hosted application (<a href="https://www.sec.gov/Archives/edgar/data/0001388658/000138865826000055/irtc-20260610.htm" target="_blank" rel="noopener noreferrer">SEC 8-K, 2026-06-15</a>; <a href="https://ctipilot.ch/briefs/2026-06-16/" target="_blank" rel="noopener noreferrer">daily 06-16</a>). HCRG Care Group began notifying patients in June 2026 of a Medusa ransomware attack that occurred in <strong>February 2025</strong> — a 16-month gap between incident and notification (<a href="https://hipaapulse.com/uk-more-than-one-year-later-hcrg-is-first-notifying-patients-of-33ec763c" target="_blank" rel="noopener noreferrer">HIPAA Pulse, 2026-06-20</a>; <a href="https://ctipilot.ch/briefs/2026-06-21/" target="_blank" rel="noopener noreferrer">daily 06-21</a>). Amazon&#39;s One Medical confirmed a legacy-storage breach (§ 2). The defender takeaway: most healthcare exposure this week entered through suppliers and legacy systems, not the front door.</p><div class="prov"><span>synthesis</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/healthcare-third-party-exposure-and-a-16-month-notification/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sec.gov/Archives/edgar/data/0001388658/000138865826000055/irtc-20260610.htm" target="_blank" rel="noopener noreferrer">iRhythm SEC 8-K</a> · <a href="https://hipaapulse.com/uk-more-than-one-year-later-hcrg-is-first-notifying-patients-of-33ec763c" target="_blank" rel="noopener noreferrer">HIPAA Pulse — HCRG</a></div></article><div class="sect" id="incidents-disclosures-recap"><span class="n">05</span><span class="t">Incidents &amp; disclosures recap</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-06-22/insider-and-process-failures-munich-school-data-a-lost-ssd-a" data-tags="insider-threat data-breach" data-regions="dach uk" data-kind="incident" data-priority="notable" data-discovered="2026-06-22T00:14:54Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="insider-and-process-failures-munich-school-data-a-lost-ssd-a"><a href="https://ctipilot.ch/entries/2026-06-22/insider-and-process-failures-munich-school-data-a-lost-ssd-a/">Insider and process failures — Munich school data, a lost SSD, and an NHS records caution</a></h3><p>Several of the week&#39;s incidents were not external intrusions at all. Munich&#39;s municipal IT subsidiary is investigating ~120,000 student records suspected on the darknet, with a terminated employee under investigation (<a href="https://www.heise.de/news/Datenschutzvorfall-in-Muenchen-120-000-sensible-Schuldaten-im-Darknet-11333920.html" target="_blank" rel="noopener noreferrer">Heise, 2026-06-17</a>; <a href="https://ctipilot.ch/briefs/2026-06-17/" target="_blank" rel="noopener noreferrer">daily 06-17</a>). The Kyushu Electric SSD loss (§ 4) was a physical-custody failure. And the UK ICO closed a two-year criminal investigation into deliberate misuse of Catherine, Princess of Wales&#39; medical records at The London Clinic with a formal caution (<a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/06/ico-statement-conclusion-of-criminal-investigation/" target="_blank" rel="noopener noreferrer">ICO, 2026-06-19</a>; <a href="https://ctipilot.ch/briefs/2026-06-19/" target="_blank" rel="noopener noreferrer">daily 06-19</a>). The common thread: privileged-insider and data-custody controls — offboarding, removable-media encryption, and access auditing on sensitive records — are as consequential as perimeter defence.</p><div class="prov"><span>incident</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/insider-and-process-failures-munich-school-data-a-lost-ssd-a/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.heise.de/news/Datenschutzvorfall-in-Muenchen-120-000-sensible-Schuldaten-im-Darknet-11333920.html" target="_blank" rel="noopener noreferrer">Heise — Munich</a> · <a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/06/ico-statement-conclusion-of-criminal-investigation/" target="_blank" rel="noopener noreferrer">ICO statement</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/law-enforcement-momentum-operation-endgame-expands-silver-fo" data-tags="law-enforcement organized-crime botnet" data-regions="europe apac global" data-kind="incident" data-priority="notable" data-discovered="2026-06-22T00:14:53Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="law-enforcement-momentum-operation-endgame-expands-silver-fo"><a href="https://ctipilot.ch/entries/2026-06-22/law-enforcement-momentum-operation-endgame-expands-silver-fo/">Law-enforcement momentum — Operation Endgame expands, Silver Fox mass-arrest, Conti loader plea</a></h3><p>The week was unusually strong on enforcement follow-through. A coordinated international action on 2026-06-18 expanded Operation Endgame to SocGholish/TA569, dismantling 106 C2 servers and stripping the FakeUpdates loader from 14,971 WordPress sites (<a href="https://www.politie.nl/en/news/2026/juni/18/11-international-law-enforcement-initiate-hunt-on-malware-group-socgholish.html" target="_blank" rel="noopener noreferrer">Politie, 2026-06-18</a>; <a href="https://ctipilot.ch/briefs/2026-06-19/" target="_blank" rel="noopener noreferrer">daily 06-19</a>). Chinese police arrested 67 members of the Silver Fox (Winos/ValleyRAT) cybercrime network across five provinces (<a href="https://news.risky.biz/risky-bulletin-china-arrests-members-of-silver-fox-cybercrime-group/" target="_blank" rel="noopener noreferrer">Risky Business, 2026-06-18</a>; <a href="https://ctipilot.ch/briefs/2026-06-18/" target="_blank" rel="noopener noreferrer">daily 06-18</a>), and Conti loader developer Oleksii Lytvynenko pleaded guilty in US federal court after extradition from Ireland (<a href="https://www.globalsecurity.org/security/library/news/2026/06/sec-260612-doj01.htm" target="_blank" rel="noopener noreferrer">Global Security, 2026-06-12</a>; <a href="https://ctipilot.ch/briefs/2026-06-14/" target="_blank" rel="noopener noreferrer">daily 06-14</a>). For defenders, the Endgame action is the operationally useful one: SocGholish/FakeUpdates is a standard initial-access broker for ransomware, so the takedown measurably degrades a common entry path — though TA569&#39;s history of rebuilding means the relief is likely temporary.</p><div class="prov"><span>incident</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/law-enforcement-momentum-operation-endgame-expands-silver-fo/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.politie.nl/en/news/2026/juni/18/11-international-law-enforcement-initiate-hunt-on-malware-group-socgholish.html" target="_blank" rel="noopener noreferrer">Politie (NL)</a> · <a href="https://news.risky.biz/risky-bulletin-china-arrests-members-of-silver-fox-cybercrime-group/" target="_blank" rel="noopener noreferrer">Risky Business</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/the-third-party-breach-as-the-week-s-dominant-entry-vector" data-tags="supply-chain data-breach identity" data-regions="global" data-kind="incident" data-priority="notable" data-discovered="2026-06-22T00:14:55Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="the-third-party-breach-as-the-week-s-dominant-entry-vector"><a href="https://ctipilot.ch/entries/2026-06-22/the-third-party-breach-as-the-week-s-dominant-entry-vector/">The third-party breach as the week&#39;s dominant entry vector</a></h3><p>The clearest cross-cutting theme of the week&#39;s incidents is that the breach increasingly entered through someone else&#39;s systems. iRhythm (social-engineered third-party app), Nintendo (TinyPulse HR SaaS), Texas Parks &amp; Wildlife (unnamed licensing vendor) and the Klue/Icarus cascade (§ 2) all share the same root pattern: the victim&#39;s own perimeter held, but a supplier&#39;s did not. This is the operational case for extending vendor-access governance — OAuth-grant inventory, supplier breach-notification SLAs, and least-privilege on integration credentials — into the same tier as perimeter hardening, because that is where this week&#39;s data actually left.</p><div class="prov"><span>incident</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/the-third-party-breach-as-the-week-s-dominant-entry-vector/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sec.gov/Archives/edgar/data/0001388658/000138865826000055/irtc-20260610.htm" target="_blank" rel="noopener noreferrer">SEC 8-K — iRhythm</a> · <a href="https://www.bleepingcomputer.com/news/security/texas-govt-data-breach-exposes-over-3-million-drivers-licenses/" target="_blank" rel="noopener noreferrer">BleepingComputer — Texas Parks</a></div></article><div class="sect" id="research-threat-actor-developments"><span class="n">06</span><span class="t">Research &amp; threat-actor developments</span><span class="c">6 items</span></div><article class="finding entry-card" data-entry-id="2026-06-22/threat-actor-fishmonger-i-soon-ports-sprysocks-to-windows-wi" data-tags="nation-state espionage china-nexus" data-regions="global europe" data-kind="research" data-priority="notable" data-discovered="2026-06-22T00:14:59Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="threat-actor-fishmonger-i-soon-ports-sprysocks-to-windows-wi"><a href="https://ctipilot.ch/entries/2026-06-22/threat-actor-fishmonger-i-soon-ports-sprysocks-to-windows-wi/">Threat actor: FishMonger (I-SOON) ports SprySOCKS to Windows with a kernel-mode rootkit</a></h3><p>ESET&#39;s full research paper detailed two previously undocumented Windows variants of the SprySOCKS backdoor attributed to <strong>FishMonger</strong> (Earth Lusca / Aquatic Panda — the Winnti-contractor tracked as I-SOON), centred on a <code>RawWNPF.sys</code> kernel driver that hides processes (<code>NtQuerySystemInformation</code> hook), network connections (<code>nsiproxy.sys</code> IOCTL interception), files (minifilter callbacks) and persistence registry keys, and redirects crafted TCP packets to a hidden backdoor port via the Windows Filtering Platform (<a href="https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/" target="_blank" rel="noopener noreferrer">ESET, 2026-06-16</a>; <a href="https://ctipilot.ch/briefs/2026-06-17/" target="_blank" rel="noopener noreferrer">daily 06-17</a>). <strong>Background:</strong> FishMonger has been publicly tracked since the 2024 I-SOON contractor-leak exposed its government-espionage-for-hire model; ESET&#39;s earlier work documented the Linux SprySOCKS lineage, and this report extends the toolkit to a Windows kernel rootkit with a possible UEFI-bootkit component (leveraging the patched BlackLotus Secure Boot bypass, CVE-2023-24932). Confirmed victims are government organisations in Honduras, Taiwan, Thailand and Pakistan; the targeting class — government and defence — keeps EU government networks in scope. Enable the vulnerable-driver blocklist, hunt for the named driver and for process/network-hiding behaviours, and verify Secure Boot is at current patch level.</p><div class="prov"><span>research</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/threat-actor-fishmonger-i-soon-ports-sprysocks-to-windows-wi/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a> · <a href="https://thehackernews.com/2026/06/china-linked-sprysocks-backdoor-expands.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/research-the-ai-agent-and-toolchain-control-plane-became-a-c" data-tags="ai-abuse cloud vulnerabilities supply-chain" data-regions="global" data-kind="research" data-priority="high" data-discovered="2026-06-22T00:14:56Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="research-the-ai-agent-and-toolchain-control-plane-became-a-c"><a href="https://ctipilot.ch/entries/2026-06-22/research-the-ai-agent-and-toolchain-control-plane-became-a-c/">Research: the AI agent and toolchain control plane became a concrete attack-surface class this week</a></h3><p>The week&#39;s single most important research synthesis is that the AI developer toolchain — gateways, agents, IDE plugins and the Model Context Protocol — stopped being a theoretical risk and accumulated a cluster of working exploit chains. Microsoft&#39;s <strong>AutoJack</strong> showed a single malicious web page can drive host-level RCE through an AI browsing agent&#39;s local MCP WebSocket: a three-flaw chain in AutoGen Studio (origin-allowlist bypass, missing auth on <code>/api/mcp/*</code>, and OS command injection via <code>StdioServerParams</code>) lets an attacker-steered agent reach a privileged localhost socket and execute arbitrary host processes (<a href="https://www.microsoft.com/en-us/security/blog/2026/06/18/autojack-single-page-rce-host-running-ai-agent/" target="_blank" rel="noopener noreferrer">Microsoft Security, 2026-06-18</a>; <a href="https://ctipilot.ch/briefs/2026-06-20/" target="_blank" rel="noopener noreferrer">daily 06-20</a>). That sits alongside the week&#39;s other AI-surface disclosures: Obsidian Security&#39;s three-CVE LiteLLM chain turning any gateway user into root (<a href="https://www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce" target="_blank" rel="noopener noreferrer">Obsidian, 2026-06-16</a>; <a href="https://ctipilot.ch/briefs/2026-06-16/" target="_blank" rel="noopener noreferrer">daily 06-16</a>), Varonis &quot;SearchLeak&quot; one-click M365 Copilot data exfiltration (CVE-2026-42824) (<a href="https://www.varonis.com/blog/searchleak" target="_blank" rel="noopener noreferrer">Varonis</a>; <a href="https://ctipilot.ch/briefs/2026-06-16/" target="_blank" rel="noopener noreferrer">daily 06-16</a>), Unit 42&#39;s &quot;Pickle in the Middle&quot; cross-tenant code execution in Google Vertex AI (CVE-2026-2473) (<a href="https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/" target="_blank" rel="noopener noreferrer">Unit 42</a>; <a href="https://ctipilot.ch/briefs/2026-06-17/" target="_blank" rel="noopener noreferrer">daily 06-17</a>), and 15 malicious JetBrains Marketplace plugins exfiltrating AI-provider API keys (<a href="https://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys" target="_blank" rel="noopener noreferrer">Aikido</a>; <a href="https://ctipilot.ch/briefs/2026-06-18/" target="_blank" rel="noopener noreferrer">daily 06-18</a>). Sophos X-Ops&#39; underground-AI report (<a href="https://ctipilot.ch/briefs/2026-06-19/" target="_blank" rel="noopener noreferrer">daily 06-19</a>) confirms criminal interest in exactly these agent frameworks. The defender takeaway for CH/EU public-sector teams adopting AI tooling: treat self-hosted AI gateways and agent frameworks as internet-adjacent application servers — bind MCP/agent sockets to loopback behind a host firewall, run them under low-privilege isolated accounts, never on shared or production hosts, and rotate the API keys and cloud credentials these tools concentrate.</p><div class="prov"><span>research</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/research-the-ai-agent-and-toolchain-control-plane-became-a-c/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/06/18/autojack-single-page-rce-host-running-ai-agent/" target="_blank" rel="noopener noreferrer">Microsoft Security — AutoJack</a> · <a href="https://www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce" target="_blank" rel="noopener noreferrer">Obsidian — LiteLLM</a> · <a href="https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/" target="_blank" rel="noopener noreferrer">Unit 42 — Vertex AI</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/research-usbliter8-an-unpatchable-securerom-boot-chain-explo" data-tags="mobile vulnerabilities no-patch" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-06-22T00:15:01Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="research-usbliter8-an-unpatchable-securerom-boot-chain-explo"><a href="https://ctipilot.ch/entries/2026-06-22/research-usbliter8-an-unpatchable-securerom-boot-chain-explo/">Research: usbliter8 — an unpatchable SecureROM boot-chain exploit for Apple A12/A13 silicon</a></h3><p>Paradigm Shift published <strong>usbliter8</strong>, a working SecureROM (burned-in, unpatchable boot code) exploit for Apple A12 and A13 SoCs via a hardware-level USB DMA buffer underflow combined with a firmware configuration flaw, achieving pre-boot arbitrary code execution in under two seconds (<a href="https://9to5mac.com/2026/06/18/new-unpatchable-exploit-targets-apple-devices-with-a12-and-a13-chips/" target="_blank" rel="noopener noreferrer">9to5Mac, 2026-06-18</a>; <a href="https://ctipilot.ch/briefs/2026-06-20/" target="_blank" rel="noopener noreferrer">daily 06-20</a>). It requires physical possession in DFU mode with a dedicated RP2350 board; the Secure Enclave is not compromised, so passcodes and encrypted user data remain protected — the risk class is forensic/intelligence-collection on seized devices, not remote exploitation. For CH/EU public-sector MDM/BYOD fleets the operational consequence is a hardware-refresh planning input: affected devices (iPhone XR/XS/11 generations, several iPads, older Apple Watches and HomePod mini) cannot be patched, so high-sensitivity-role devices on A12/A13 silicon should be prioritised for replacement and protected with physical-custody controls.</p><div class="prov"><span>research</span><span>22 Jun 00:15Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/research-usbliter8-an-unpatchable-securerom-boot-chain-explo/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://9to5mac.com/2026/06/18/new-unpatchable-exploit-targets-apple-devices-with-a12-and-a13-chips/" target="_blank" rel="noopener noreferrer">9to5Mac</a> · <a href="https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/threat-actor-inc-ransomware-s-rust-rewrite-and-byovd-evoluti" data-tags="ransomware organized-crime" data-regions="global us" data-kind="research" data-priority="notable" data-discovered="2026-06-22T00:15:00Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="threat-actor-inc-ransomware-s-rust-rewrite-and-byovd-evoluti"><a href="https://ctipilot.ch/entries/2026-06-22/threat-actor-inc-ransomware-s-rust-rewrite-and-byovd-evoluti/">Threat actor: INC ransomware&#39;s Rust rewrite and BYOVD evolution</a></h3><p>Acronis and The Hacker News documented the evolution of <strong>INC ransomware</strong> into a top-tier RaaS — 830+ victims since 2023, fourth in Q1 2026 — with a Rust rewrite of its Windows and Linux/ESXi encryptors, BYOVD EDR-termination using the drivers <code>filwfp.sys</code> / <code>filnk.sys</code> / <code>fildds.sys</code> (the same set seen in earlier Vanilla Tempest campaigns), a Veeam credential dumper for backup infrastructure, and two source-code-leak-derived variants (Lynx, Sinobi) (<a href="https://www.acronis.com/en/tru/posts/from-emerging-threat-to-top-tier-ransomware-as-a-service-the-evolution-of-inc-ransomware/" target="_blank" rel="noopener noreferrer">Acronis TRU, 2026-06-18</a>; <a href="https://thehackernews.com/2026/06/inc-ransomware-claims-830-victims-since.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-19</a>). The geography is incidental for a CH/EU SOC — the cited reporting puts the majority of INC&#39;s victims in the US — but the tradecraft is not: the three BYOVD drivers (shared with earlier Vanilla Tempest campaigns), the Veeam backup-credential dumper, and the cross-platform Rust encryptor are detection content that generalises to any victim. Detect the three BYOVD drivers via driver-load events with a hash blocklist, alert on Veeam process-memory access from unexpected parents, and keep backup systems MFA-protected and network-isolated.</p><div class="prov"><span>research</span><span>22 Jun 00:15Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/threat-actor-inc-ransomware-s-rust-rewrite-and-byovd-evoluti/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.acronis.com/en/tru/posts/from-emerging-threat-to-top-tier-ransomware-as-a-service-the-evolution-of-inc-ransomware/" target="_blank" rel="noopener noreferrer">Acronis TRU</a> · <a href="https://thehackernews.com/2026/06/inc-ransomware-claims-830-victims-since.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/threat-actor-dprk-sapphire-sleet-escalates-npm-supply-chain" data-tags="supply-chain nation-state north-korea-nexus infostealer" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-06-22T00:14:58Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="threat-actor-dprk-sapphire-sleet-escalates-npm-supply-chain"><a href="https://ctipilot.ch/entries/2026-06-22/threat-actor-dprk-sapphire-sleet-escalates-npm-supply-chain/">Threat actor: DPRK Sapphire Sleet escalates npm supply-chain attacks with the Mastra compromise</a></h3><p>Microsoft attributed the Mastra npm scope compromise — first covered as an unattributed supply-chain event on 2026-06-18 — to <strong>Sapphire Sleet</strong> (BlueNoroff / UNC1069), making it the actor&#39;s second major npm strike of 2026 after the April Axios attack (<a href="https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/" target="_blank" rel="noopener noreferrer">Microsoft Security, 2026-06-17</a>; <a href="https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-18</a>; <a href="https://ctipilot.ch/briefs/2026-06-21/" target="_blank" rel="noopener noreferrer">daily 06-21</a>). The operators compromised a maintainer account whose scope access was never revoked and published 140+ malicious <code>@mastra</code> packages within a ~20-minute window, using an <code>easy-day-js</code> typosquat of <code>dayjs</code> to run a <code>postinstall</code> dropper with cross-platform persistence (Registry Run key, macOS LaunchAgent, Linux systemd unit) that exfiltrated browser-wallet extensions, cloud credentials, LLM API keys, CI/CD tokens and SSH keys. The recurrence establishes a clear DPRK pattern of targeting the <strong>AI developer toolchain&#39;s</strong> supply chain specifically — the same surface § 6&#39;s first item flags. Run <code>npm install --ignore-scripts</code> in CI, pin lockfile versions, and rotate credentials on any host that pulled <code>@mastra</code> packages in the days before the 17 June disclosure.</p><div class="prov"><span>research</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/threat-actor-dprk-sapphire-sleet-escalates-npm-supply-chain/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/" target="_blank" rel="noopener noreferrer">Microsoft Security — Mastra</a> · <a href="https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/research-clickfix-matured-into-a-productised-malware-as-a-se" data-tags="phishing infostealer organized-crime" data-regions="global" data-kind="research" data-priority="notable" data-discovered="2026-06-22T00:14:57Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="research-clickfix-matured-into-a-productised-malware-as-a-se"><a href="https://ctipilot.ch/entries/2026-06-22/research-clickfix-matured-into-a-productised-malware-as-a-se/">Research: ClickFix matured into a productised malware-as-a-service supply chain</a></h3><p>A second cross-day research thread: the ClickFix technique — fake browser/update dialogues that trick users into pasting attacker PowerShell — has industrialised. Sekoia documented <strong>ErrTraffic</strong>, a ClickFix Malware-as-a-Service framework that resolves its C2 through the Polygon blockchain (<a href="https://blog.sekoia.io/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework/" target="_blank" rel="noopener noreferrer">Sekoia, 2026-06-17</a>; <a href="https://ctipilot.ch/briefs/2026-06-17/" target="_blank" rel="noopener noreferrer">daily 06-17</a>), and Huntress detailed the <strong>Potemkin</strong> loader delivering RMMProject RAT through a ClickFix chain that also bypasses Chromium App-Bound Encryption (<a href="https://www.huntress.com/blog/potemkin-loader-rmmproject-clickfix-attack" target="_blank" rel="noopener noreferrer">Huntress, 2026-06-17</a>; <a href="https://ctipilot.ch/briefs/2026-06-17/" target="_blank" rel="noopener noreferrer">daily 06-17</a>). ErrTraffic also surfaced as one of the SocGholish-adjacent clusters still operating after the Operation Endgame takedown (§ 8). The pattern for defenders: ClickFix is now a delivery channel with multiple competing operators and resilient C2, so user-paste-to-PowerShell detection (clipboard-sourced <code>powershell.exe</code>/<code>mshta.exe</code> invocations, <code>RunMRU</code> artefacts) is worth promoting from awareness training to a standing hunt.</p><div class="prov"><span>research</span><span>22 Jun 00:14Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/research-clickfix-matured-into-a-productised-malware-as-a-se/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.sekoia.io/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework/" target="_blank" rel="noopener noreferrer">Sekoia — ErrTraffic</a> · <a href="https://www.huntress.com/blog/potemkin-loader-rmmproject-clickfix-attack" target="_blank" rel="noopener noreferrer">Huntress — Potemkin</a></div></article><div class="sect" id="annual-periodic-threat-reports"><span class="n">07</span><span class="t">Annual / periodic threat reports</span><span class="c">2 items</span></div><article class="finding entry-card" data-entry-id="2026-06-22/check-point-state-of-ransomware-q1-2026-ecosystem-consolidat" data-tags="ransomware organized-crime" data-regions="switzerland europe global" data-kind="annual-report" data-priority="notable" data-discovered="2026-06-22T00:15:03Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="check-point-state-of-ransomware-q1-2026-ecosystem-consolidat"><a href="https://ctipilot.ch/entries/2026-06-22/check-point-state-of-ransomware-q1-2026-ecosystem-consolidat/">Check Point State of Ransomware Q1 2026 — ecosystem consolidation, with Switzerland and Germany named</a></h3><p>Surfaced this week for its CH/EU-specific findings, Check Point&#39;s Q1 2026 ransomware report (published 11 May, not covered in the dailies) documents a structural consolidation: the top 10 groups now hold <strong>71.1% of all leak-site victims</strong>, the highest concentration since early 2024 and a reversal of two years of fragmentation — meaning defenders face fewer but more professionalised adversaries (<a href="https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/" target="_blank" rel="noopener noreferrer">Check Point Research</a>; corroborated by <a href="https://www.emsisoft.com/en/blog/47562/the-state-of-ransomware-in-q1-2026/" target="_blank" rel="noopener noreferrer">Emsisoft</a>). The Gentlemen grew +315% quarter-on-quarter (explaining this week&#39;s Mackay Sugar and GentleKiller coverage in § 2) and LockBit 5.0 resurged +106% on a Rust rewrite. The geography is the operative detail for this audience: <strong>Switzerland — Check Point notes Akira accounts for roughly 31% of Swiss ransomware victims</strong>, and Germany is the #2 country globally for ransomware victims (Emsisoft). The synthesis a Swiss SOC should take: Akira is the dominant ransomware threat to model against domestically, and the consolidation trend favours investing detection effort against a smaller set of high-capability operators (Qilin, Akira, The Gentlemen, LockBit 5.0).</p><div class="prov"><span>annual-report</span><span>22 Jun 00:15Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/check-point-state-of-ransomware-q1-2026-ecosystem-consolidat/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/" target="_blank" rel="noopener noreferrer">Check Point Research — State of Ransomware Q1 2026</a> · <a href="https://www.emsisoft.com/en/blog/47562/the-state-of-ransomware-in-q1-2026/" target="_blank" rel="noopener noreferrer">Emsisoft</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/dora-year-1-the-esas-first-annual-ict-incident-report-3-383" data-tags="supply-chain eu-nexus" data-regions="europe" data-kind="annual-report" data-priority="notable" data-discovered="2026-06-22T00:15:02Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="dora-year-1-the-esas-first-annual-ict-incident-report-3-383"><a href="https://ctipilot.ch/entries/2026-06-22/dora-year-1-the-esas-first-annual-ict-incident-report-3-383/">DORA Year 1 — the ESAs&#39; first annual ICT-incident report: 3,383 major incidents, a third cross-border, only ~10% cyber</a></h3><p>The European Supervisory Authorities (EBA, EIOPA, ESMA) published their first annual overview of major ICT-related incidents reported under DORA, covering 2025 (<a href="https://www.eba.europa.eu/publications-and-media/press-releases/esas-publish-first-report-dora-major-ict-related-incidents" target="_blank" rel="noopener noreferrer">EBA, 2026-06-03</a>; <a href="https://www.eiopa.europa.eu/esas-publish-first-report-dora-major-ict-related-incidents-2026-06-03_en" target="_blank" rel="noopener noreferrer">EIOPA, 2026-06-03</a>). The findings most useful to a defender: 3,383 major incidents across EU financial sectors; roughly <strong>one-third had cross-border impact</strong> — the borderless-interconnection risk the DORA reporting regime exists to surface, with the ESAs stating &quot;ICT risks are increasingly borderless and interconnected&quot;; and cybersecurity incidents made up only ~10% of the total, with system failures and operational events dominating. The ESAs explicitly flag AI-driven attack tooling as an emerging multiplier that could shift that baseline rapidly. For Swiss financial entities under FINMA — not bound by DORA but operating to comparable operational-resilience expectations — the report is a useful peer benchmark for what a European incident profile looks like under comparable obligations.</p><div class="prov"><span>annual-report</span><span>22 Jun 00:15Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/dora-year-1-the-esas-first-annual-ict-incident-report-3-383/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.eba.europa.eu/publications-and-media/press-releases/esas-publish-first-report-dora-major-ict-related-incidents" target="_blank" rel="noopener noreferrer">EBA joint ESA press release</a> · <a href="https://www.eiopa.europa.eu/esas-publish-first-report-dora-major-ict-related-incidents-2026-06-03_en" target="_blank" rel="noopener noreferrer">EIOPA</a></div></article><div class="sect" id="long-running-campaigns-status-update"><span class="n">08</span><span class="t">Long-running campaigns · status update</span><span class="c">2 items</span></div><article class="finding entry-card" data-entry-id="2026-06-22/socgholish-ta569-operation-endgame-seized-106-servers-but-se" data-tags="organized-crime law-enforcement supply-chain" data-regions="europe global" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-22T00:15:05Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="socgholish-ta569-operation-endgame-seized-106-servers-but-se"><a href="https://ctipilot.ch/entries/2026-06-22/socgholish-ta569-operation-endgame-seized-106-servers-but-se/">SocGholish / TA569 — Operation Endgame seized 106 servers, but seven delivery clusters remain operational</a></h3><p><code>key: item:operation-endgame-expands-to-socgholish-ta569-106-c2-servers</code>. The Operation Endgame takedown (§ 5) was the headline; Proofpoint&#39;s post-action analysis is the status update that matters for the longer arc. TA569 served for years as a primary distribution layer for WastedLocker (Evil Corp), LockBit and RansomHub, and while law enforcement seized over 100 servers and 14,971 WordPress sites were remediated, <strong>seven FakeUpdates-style clusters remain operational</strong> — TA2726, TA2727, ZPHP, ErrTraffic (the ClickFix MaaS in § 6), LandUpdate808/KongTuke, GeoTDS and tdsshop (<a href="https://www.proofpoint.com/us/blog/threat-insight/sayonara-socgholish-operation-endgame-disrupts-major-cybercrime-operation" target="_blank" rel="noopener noreferrer">Proofpoint, 2026-06-18</a>; <a href="https://ctipilot.ch/briefs/2026-06-19/" target="_blank" rel="noopener noreferrer">daily 06-19</a>). Proofpoint also notes WordPress sites frequently reinfect because the underlying credential compromise outlives CMS-level cleanup. The defender consequence: the fake-update initial-access vector is degraded, not closed — keep GPO restrictions on JScript/WSH execution from user-writable paths, browser isolation for email links, and (for WordPress operators) full credential rotation plus FIM after any cleanup, because removing the loader without rotating credentials invites reinfection.</p><div class="prov"><span>synthesis</span><span>22 Jun 00:15Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/socgholish-ta569-operation-endgame-seized-106-servers-but-se/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.proofpoint.com/us/blog/threat-insight/sayonara-socgholish-operation-endgame-disrupts-major-cybercrime-operation" target="_blank" rel="noopener noreferrer">Proofpoint</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/chaotic-eclipse-nightmare-eclipse-zero-day-wave-rogueplanet" data-tags="vulnerabilities zero-day lpe poc-public no-patch" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-22T00:15:04Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-50656/">CVE-2026-50656</a></div><h3 class="f-h" id="chaotic-eclipse-nightmare-eclipse-zero-day-wave-rogueplanet"><a href="https://ctipilot.ch/entries/2026-06-22/chaotic-eclipse-nightmare-eclipse-zero-day-wave-rogueplanet/">Chaotic Eclipse / Nightmare Eclipse zero-day wave — RoguePlanet (CVE-2026-50656) still unpatched, PoC works on June builds</a></h3><p><code>key: item:nightmare-chaotic-eclipse-zero-day-wave-the-defender-lpe-now</code>. The serialised Windows zero-day campaign the W24 weekly consolidated has a worsening status. As of 2026-06-21, <strong>CVE-2026-50656 (RoguePlanet) remains unpatched.</strong> The exploit abuses a Time-of-Check-to-Time-of-Use race in Microsoft Defender&#39;s file-processing workflow (CWE-59): Defender checks a file path under SYSTEM, then reopens it, and the exploit swaps the file in the gap to get SYSTEM-level execution (<a href="https://www.helpnetsecurity.com/2026/06/17/rogueplanet-zero-day-cve-2026-50656/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-06-17</a>; <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">MSRC</a>; <a href="https://ctipilot.ch/briefs/2026-06-19/" target="_blank" rel="noopener noreferrer">daily 06-19</a>). The PoC is validated against fully-patched Windows 10 and 11 including the June 2026 Patch Tuesday build, Real-Time Protection status is irrelevant, and the researcher states small PoC changes defeat mitigations — &quot;the only thing you can realistically do is wait for a patch.&quot; Microsoft confirms a fix is in development with no timeline. This is post-initial-access privilege escalation (local auth required), so it compounds rather than initiates a breach; until a patch ships, the realistic controls are application allowlisting to constrain post-exploitation and hunting for <code>MsMpEng.exe</code> spawning unexpected children or temp-directory symlink manipulation timed to scans. Outstanding question to watch: whether Microsoft ships an out-of-band fix or holds it to July Patch Tuesday.</p><div class="prov"><span>synthesis</span><span>22 Jun 00:15Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/chaotic-eclipse-nightmare-eclipse-zero-day-wave-rogueplanet/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.helpnetsecurity.com/2026/06/17/rogueplanet-zero-day-cve-2026-50656/" target="_blank" rel="noopener noreferrer">Help Net Security</a> · <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a></div></article><div class="sect" id="policy-regulatory-horizon"><span class="n">09</span><span class="t">Policy &amp; regulatory horizon</span><span class="c">6 items</span></div><article class="finding entry-card" data-entry-id="2026-06-22/g7-vian-cybersecurity-declaration-calls-pqc-an-urgent-priori" data-tags="ddos hacktivism eu-nexus russia-nexus" data-regions="europe switzerland" data-kind="policy" data-priority="high" data-discovered="2026-06-22T00:15:09Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="g7-vian-cybersecurity-declaration-calls-pqc-an-urgent-priori"><a href="https://ctipilot.ch/entries/2026-06-22/g7-vian-cybersecurity-declaration-calls-pqc-an-urgent-priori/">G7 Évian cybersecurity declaration calls PQC an &quot;urgent priority&quot; — and the expected hacktivist DDoS materialised on day one</a></h3><p>The G7 Cybersecurity Working Group declaration, adopted around the Évian summit (15–17 June), names post-quantum cryptography an &quot;urgent priority&quot; with a call for coordinated industry-government migration, alongside AI-cyber dual-use risk, telecom resilience and SME cybersecurity; the European Commission issued a welcome statement linking it to the NIS2/CRA stack (<a href="https://cyber.gouv.fr/en/publications/jointly-led-international-publications/declaration-of-the-g7-cybersecurity-working-group/" target="_blank" rel="noopener noreferrer">ANSSI</a>; <a href="https://digital-strategy.ec.europa.eu/en/news/european-commission-welcomes-g7-cybersecurity-declaration-strengthen-global-digital-resilience" target="_blank" rel="noopener noreferrer">European Commission, 2026-06-17</a>). The PQC-urgency framing aligns with Swiss federal cryptographic-migration planning. Resolving the W24 looking-ahead watch item: the NCSC-CH-predicted hacktivist DDoS did materialise — NoName057(16) ran layer-7 DDoS on 15 June against public-sector and tourism sites in the Swiss-bordering Haute-Savoie department (Évian-les-Bains, Thonon-les-Bains, Saint-Gingolph municipalities, the EVA&#39;D transport portal), causing temporary outages with no data compromise (<a href="https://www.cyberattaque.org/g7-devian-plusieurs-sites-publics-de-haute-savoie-cibles-par-des-cyberattaques/" target="_blank" rel="noopener noreferrer">Cyberattaque.org, 2026-06-16</a>; <a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/massnahmen-grossanlaesse-konferenzen-g7.html" target="_blank" rel="noopener noreferrer">NCSC-CH pre-event advisory</a>). Attribution rests on the group&#39;s Telegram self-claim; no Swiss federal sites were reported hit. The lesson reconfirmed: NCSC-CH&#39;s pre-event DDoS guidance for summit-adjacent organisations was correctly calibrated, and the NoName057(16) pattern around Swiss-adjacent summits (cf. Bürgenstock 2024) holds.</p><div class="prov"><span>policy</span><span>22 Jun 00:15Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/g7-vian-cybersecurity-declaration-calls-pqc-an-urgent-priori/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cyber.gouv.fr/en/publications/jointly-led-international-publications/declaration-of-the-g7-cybersecurity-working-group/" target="_blank" rel="noopener noreferrer">ANSSI — G7 CWG Declaration</a> · <a href="https://www.cyberattaque.org/g7-devian-plusieurs-sites-publics-de-haute-savoie-cibles-par-des-cyberattaques/" target="_blank" rel="noopener noreferrer">Cyberattaque.org — Haute-Savoie DDoS</a> · <a href="https://digital-strategy.ec.europa.eu/en/news/european-commission-welcomes-g7-cybersecurity-declaration-strengthen-global-digital-resilience" target="_blank" rel="noopener noreferrer">European Commission</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/ncsc-ch-fake-swiss-post-avis-de-passage-qr-code-phishing-in" data-tags="phishing" data-regions="switzerland" data-kind="policy" data-priority="notable" data-discovered="2026-06-22T00:15:11Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="ncsc-ch-fake-swiss-post-avis-de-passage-qr-code-phishing-in"><a href="https://ctipilot.ch/entries/2026-06-22/ncsc-ch-fake-swiss-post-avis-de-passage-qr-code-phishing-in/">NCSC-CH — fake Swiss Post &quot;Avis de passage&quot; QR-code phishing in French-speaking Switzerland</a></h3><p>NCSC-CH&#39;s Week 24 Wochenrückblick flagged a hybrid physical-plus-digital social-engineering campaign in French-speaking Switzerland: attackers drop fake Swiss Post collection-notice (&quot;Avis de passage&quot;) letters into letterboxes, closely mimicking official branding, with a QR code leading to a phishing site that harvests identity and credit-card data (<a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/wochenrueckblick_24.html" target="_blank" rel="noopener noreferrer">NCSC-CH, 2026-06-16</a>). The physical-delivery vector defeats email-gateway controls entirely. Public-sector organisations in French-speaking cantons should brief staff on the physical-QR lure, since the Swiss Post brand is frequently abused and a letterbox-delivered QR bypasses every email-based phishing control.</p><div class="prov"><span>policy</span><span>22 Jun 00:15Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/ncsc-ch-fake-swiss-post-avis-de-passage-qr-code-phishing-in/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/wochenrueckblick_24.html" target="_blank" rel="noopener noreferrer">NCSC-CH Week 24 Wochenrückblick</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/nis2-transposition-remains-incomplete-france-and-spain-still" data-tags="eu-nexus law-enforcement" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-06-22T00:15:08Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="nis2-transposition-remains-incomplete-france-and-spain-still"><a href="https://ctipilot.ch/entries/2026-06-22/nis2-transposition-remains-incomplete-france-and-spain-still/">NIS2 transposition remains incomplete — France and Spain still among the laggards</a></h3><p>NIS2 transposition is still incomplete across several Member States more than 18 months after the October 2024 deadline, with most of the EU now compliant but a minority — France and Spain among them — still lagging (<a href="https://digital-strategy.ec.europa.eu/en/policies/nis-transposition" target="_blank" rel="noopener noreferrer">EC Digital Strategy — NIS transposition tracker</a>; <a href="https://viktoria-compliance.eu/en/blog/nis2-transposition-status-eu-2026" target="_blank" rel="noopener noreferrer">Viktoria Compliance NIS2 tracker</a>). France in particular has not yet enacted its NIS2 transposition vehicle, which means the national authority cannot formally designate in-scope entities or apply sanctions there — and NIS2-derived incident-notification obligations on French entities are therefore not yet enforceable. The operational consequence for Swiss organisations with French or Spanish supply-chain or data-processing counterparts: do not assume NIS2 notification and security obligations are operative in those jurisdictions yet, and confirm the contractual basis for any incident-notification flow rather than relying on a not-yet-transposed statutory one.</p><div class="prov"><span>policy</span><span>22 Jun 00:15Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/nis2-transposition-remains-incomplete-france-and-spain-still/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://digital-strategy.ec.europa.eu/en/policies/nis-transposition" target="_blank" rel="noopener noreferrer">European Commission — NIS transposition tracker</a> · <a href="https://viktoria-compliance.eu/en/blog/nis2-transposition-status-eu-2026" target="_blank" rel="noopener noreferrer">Viktoria Compliance NIS2 tracker</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/cra-reporting-obligation-lands-11-september-enisa-single-rep" data-tags="vulnerabilities eu-nexus supply-chain" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-06-22T00:15:07Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="cra-reporting-obligation-lands-11-september-enisa-single-rep"><a href="https://ctipilot.ch/entries/2026-06-22/cra-reporting-obligation-lands-11-september-enisa-single-rep/">CRA reporting obligation lands 11 September — ENISA Single Reporting Platform access manual due, dry-runs before go-live</a></h3><p>The first Cyber Resilience Act obligation to bind, from 11 September 2026, requires manufacturers of products with digital elements to report actively exploited vulnerabilities (24-hour early warning + 72-hour notification + final report) and severe incidents through ENISA&#39;s Single Reporting Platform (<a href="https://digital-strategy.ec.europa.eu/en/policies/cra-reporting" target="_blank" rel="noopener noreferrer">EC Digital Strategy</a>; <a href="https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp" target="_blank" rel="noopener noreferrer">ENISA SRP</a>). ENISA committed to publishing access manuals and registration instructions during June 2026 with a dry-run period before go-live. Swiss companies exporting products with digital elements to the EU are directly in scope, with NCSC/GovCERT.ch as the designated national-CSIRT counterpart for the simultaneous-notification routing. With the deadline ~82 days out, in-scope manufacturers should begin SRP registration preparation and build the 24/72-hour reporting workflow into their PSIRT process now.</p><div class="prov"><span>policy</span><span>22 Jun 00:15Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/cra-reporting-obligation-lands-11-september-enisa-single-rep/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://digital-strategy.ec.europa.eu/en/policies/cra-reporting" target="_blank" rel="noopener noreferrer">European Commission — CRA reporting</a> · <a href="https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp" target="_blank" rel="noopener noreferrer">ENISA Single Reporting Platform</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/edpb-adopts-a-harmonised-gdpr-article-33-breach-notification" data-tags="data-breach eu-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-06-22T00:15:06Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="edpb-adopts-a-harmonised-gdpr-article-33-breach-notification"><a href="https://ctipilot.ch/entries/2026-06-22/edpb-adopts-a-harmonised-gdpr-article-33-breach-notification/">EDPB adopts a harmonised GDPR Article 33 breach-notification template — consultation open to 5 August</a></h3><p>The EDPB adopted a draft common EU/EEA personal-data-breach notification template at its June plenary and opened public consultation until 5 August 2026 (<a href="https://www.edpb.europa.eu/news/news/2026/edpb-meets-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification_en" target="_blank" rel="noopener noreferrer">EDPB, 2026-06-10</a>). The template is a structured common form with predefined answer options and fill-in guidance, designed to replace the current patchwork in which each national DPA maintains its own notification form. After 5 August the EDPB will publish a timeline for mandatory adoption by all DPAs — the point at which it becomes the channel. What defenders should do differently: breach-response process owners with multi-jurisdiction obligations should review the draft now and begin aligning their incident-response notification playbooks to the common template. Swiss organisations under the nFADP have no direct EDPB obligation but need aligned preparation for any EU-nexus incident notifiable to an EU DPA.</p><div class="prov"><span>policy</span><span>22 Jun 00:15Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/edpb-adopts-a-harmonised-gdpr-article-33-breach-notification/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.edpb.europa.eu/news/news/2026/edpb-meets-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification_en" target="_blank" rel="noopener noreferrer">EDPB</a></div></article><article class="finding entry-card" data-entry-id="2026-06-22/uk-ico-left-leaderless-mid-restructure-commissioner-resigns" data-tags="data-breach" data-regions="uk" data-kind="policy" data-priority="notable" data-discovered="2026-06-22T00:15:10Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="uk-ico-left-leaderless-mid-restructure-commissioner-resigns"><a href="https://ctipilot.ch/entries/2026-06-22/uk-ico-left-leaderless-mid-restructure-commissioner-resigns/">UK ICO left leaderless mid-restructure — Commissioner resigns with immediate effect</a></h3><p>UK Information Commissioner John Edwards resigned with immediate effect on 19 June after an independent workplace investigation found &quot;a case to answer&quot; over his conduct; Chief Executive Paul Arnold now holds Commissioner responsibilities under a scheme of delegation while a DSIT/parliament appointment process expected to take months runs its course (<a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/06/ico-confirms-john-edwards-resignation/" target="_blank" rel="noopener noreferrer">ICO, 2026-06-19</a>; <a href="https://www.computerweekly.com/news/366644976/UK-information-commissioner-John-Edwards-resigns-after-HR-investigation" target="_blank" rel="noopener noreferrer">Computer Weekly, 2026-06-19</a>; <a href="https://ctipilot.ch/briefs/2026-06-21/" target="_blank" rel="noopener noreferrer">daily 06-21</a>). This is a regulatory-capacity story for any Swiss or EU organisation with UK operations: the ICO&#39;s enforcement posture under Edwards (high-profile fines, age-assurance actions) is not guaranteed to continue unchanged under interim leadership, and the regulator is short its top accountability anchor at a time it is also mid-restructure. Defenders should not read the vacuum as reduced obligation — UK GDPR duties are unchanged — but enforcement timing and priorities may shift during the interregnum.</p><div class="prov"><span>policy</span><span>22 Jun 00:15Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/uk-ico-left-leaderless-mid-restructure-commissioner-resigns/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/06/ico-confirms-john-edwards-resignation/" target="_blank" rel="noopener noreferrer">ICO confirmation</a> · <a href="https://www.computerweekly.com/news/366644976/UK-information-commissioner-John-Edwards-resigns-after-HR-investigation" target="_blank" rel="noopener noreferrer">Computer Weekly</a></div></article><div class="sect" id="looking-ahead-what-to-watch-next-week"><span class="n">10</span><span class="t">Looking ahead · what to watch next week</span><span class="c">1 item</span></div><article class="finding entry-card" data-entry-id="2026-06-22/looking-ahead-2026-w25" data-tags="vulnerabilities" data-regions="global" data-kind="outlook" data-priority="notable" data-discovered="2026-06-22T00:15:12Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="looking-ahead-2026-w25"><a href="https://ctipilot.ch/entries/2026-06-22/looking-ahead-2026-w25/">Looking ahead — 2026-W25</a></h3><p>A focused, justified list — items already in motion, not predictions.</p>
<ul><li><strong>RoguePlanet (CVE-2026-50656) has no patch and a PoC that works on June builds — watch MSRC for an out-of-band fix.</strong> Microsoft says a fix is &quot;in development&quot; with no timeline; the researcher warns mitigations are not reliable. Decide now whether to hold for July Patch Tuesday or push application allowlisting as an interim control. (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">MSRC</a>; <a href="https://ctipilot.ch/briefs/2026-06-19/" target="_blank" rel="noopener noreferrer">daily 06-19</a>)</li><li><strong>FortiBleed credential resets are not a one-and-done — expect more named victims and AD-persistence findings.</strong> CISA confirmed full AD domain takeover at multiple organisations; finish session termination, credential rotation and PBKDF2 migration, then hunt for post-compromise persistence rather than assuming the reset closed it. (<a href="https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/" target="_blank" rel="noopener noreferrer">SecurityWeek</a>; <a href="https://ctipilot.ch/briefs/2026-06-20/" target="_blank" rel="noopener noreferrer">daily 06-20</a>)</li><li><strong>ShinyHunters PeopleSoft notifications are still landing — more European victims are likely.</strong> Google GTIG has notified 100+ organisations (68% higher education); EU universities are a probable next-named class. Patch internet-reachable PeopleSoft and hunt the <code>/PSEMHUB/</code> and <code>/PSIGW/HttpListeningConnector</code> paths. (<a href="https://ctipilot.ch/briefs/2026-06-16/" target="_blank" rel="noopener noreferrer">daily 06-16</a>)</li><li><strong>CRA Single Reporting Platform go-live is ~82 days out (11 September).</strong> ENISA&#39;s access manual and a dry-run window are due now; in-scope manufacturers (including Swiss exporters to the EU) should register and wire the 24/72-hour reporting flow into their PSIRT process before the obligation binds. (<a href="https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp" target="_blank" rel="noopener noreferrer">ENISA SRP</a>)</li><li><strong>EDPB Article 33 harmonised-template consultation closes 5 August.</strong> Multi-jurisdiction breach-response owners have a window to review and comment before the EDPB sets a mandatory-adoption timeline. (<a href="https://www.edpb.europa.eu/news/news/2026/edpb-meets-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification_en" target="_blank" rel="noopener noreferrer">EDPB</a>)</li><li><strong>npm v12 will disable install scripts by default — the Mastra compromise is this week&#39;s reminder to audit CI before the change.</strong> Sapphire Sleet&#39;s <code>postinstall</code> dropper is exactly the kill chain <code>--ignore-scripts</code> / npm v12 defaults neutralise; inventory pipelines that rely on build scripts now. (<a href="https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/" target="_blank" rel="noopener noreferrer">Microsoft</a>; <a href="https://ctipilot.ch/briefs/2026-06-21/" target="_blank" rel="noopener noreferrer">daily 06-21</a>)</li><li><strong>France&#39;s NIS2 transposition remains unresolved into late 2026.</strong> Organisations with French counterparts should track the next parliamentary session; NIS2-derived notification flows from French partners are not yet enforceable. (<a href="https://viktoria-compliance.eu/en/blog/nis2-transposition-status-eu-2026" target="_blank" rel="noopener noreferrer">Viktoria Compliance</a>)</li></ul><div class="prov"><span>outlook</span><span>22 Jun 00:15Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-22/looking-ahead-2026-w25/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656" target="_blank" rel="noopener noreferrer">MSRC</a> · <a href="https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp" target="_blank" rel="noopener noreferrer">ENISA SRP</a> · <a href="https://www.edpb.europa.eu/news/news/2026/edpb-meets-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification_en" target="_blank" rel="noopener noreferrer">EDPB</a> · <a href="https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/" target="_blank" rel="noopener noreferrer">Microsoft</a> · <a href="https://viktoria-compliance.eu/en/blog/nis2-transposition-status-eu-2026" target="_blank" rel="noopener noreferrer">Viktoria Compliance</a></div></article><details class="verif"><summary class="vh">About this weekly<span class="verif-count">2 runs</span><svg class="verif-chev" viewBox="0 0 24 24" width="12" height="12" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" aria-hidden="true"><path d="M6 9l6 6 6-6"></path></svg></summary><div class="verif-body"><div class="run-note" data-run-id="2026-W26-b78503e7"><h3 class="run-note__head"><span class="mono">2026-W26-b78503e7</span> <span class="muted">· weekly · Anthropic Claude (specific model not determined) · 34 entries published</span></h3><div class="run-note__body"><ul><li><strong>Single-source / attributed claims.</strong> The &quot;second extortion group&quot; in the Klue/Icarus item (§ 2) and its claim of ~195 listed organisations rest on a single primary (The Next Web, relaying a private Klue customer update obtained by TechCrunch); the allegation that Klue paid the original Icarus operator is unverified and is attributed as a claim, not stated as fact. The NAIC 3.1 TB figure is ShinyHunters&#39; own claim relayed by tech press; NAIC confirms the breach and the rating-feed pause but not the volume. The &quot;Switzerland is the second-most-targeted European country&quot; ranking for The Gentlemen (§§ 0, 8) rests on a single source (inside-it.ch relaying Check Point data); the co-cited ESET paper does not state a European country ranking, and inside-it.ch returns 403 to the routine&#39;s fetcher, so the specific ranking could not be independently re-verified this run — it is attributed, not asserted as established fact.</li><li><strong>Unresolved contradiction.</strong> Texas Parks &amp; Wildlife (§ 5): the daily flagged a discrepancy between the public statement and the state AG filing over whether SSNs were exposed; unresolved this week, carried as a confidence caveat.</li><li><strong>Items considered and dropped (may resurface).</strong> RoguePlanet (CVE-2026-50656) — carried in the W25 looking-ahead but no fresh in-window source on a Microsoft fix, so dropped rather than re-asserted stale. eBanking IPv4-mapped-IPv6 phishing (06-22), the Brazil Cell Broadcast hijack (single-source, beyond audience nexus beyond the § 4 mention), Arystinger botnet (06-22), Prinz Eugen ransomware (06-21) and Payouts King/Edgecution (06-25) did not clear W-PD-1 (inaction-=-incident / cross-day pattern / strategic horizon) and were left to the dailies. The MISP 2.5.42 CVEs (06-25) and ILIAS SQLi (06-23) are folded into §§ 3–4 rather than given standalone roll-up entries.</li><li><strong>Reduced confidence.</strong> StrikeShark China-nexus attribution is Kaspersky&#39;s <em>low-confidence</em> assessment and is reported as such (§ 6).</li><li><strong>libssh2 patch-status caveat (§ 3).</strong> The GHSA references an upstream fix commit and NCSC-NL NCSC-2026-0210 is titled as a fix advisory, so the item is marked <code>patch-available</code>; however, tagged-release availability lags across the binding/appliance ecosystem, so a given deployment may still be effectively unpatched pending its embedding vendor&#39;s release. Treat <code>patch-available</code> as &quot;fix exists upstream,&quot; not &quot;your appliance is fixed.&quot;</li><li><strong>Sub-agents.</strong> Both horizon sub-agents (W1 threat-actor/campaign/research; W2 strategic/policy) returned within cap. No coverage axis was abandoned.</li><li><strong>Verification iterations:</strong> 5 · residuals: 0 — verdict CLEAN on iteration 5, with model rotation across iterations (opus on 1/3/5, sonnet on 2/4). Iterations 1–4 remediated ~21 findings (URL corrections, an MSG→ShinyHunters attribution overclaim, a Miasma quantifier inflation, a Netherlands NIS2 &quot;transposition done&quot; factual overclaim, and several date/citation-anchor gaps); iteration 5 found no truth or editorial defects.</li><li>Coverage gaps: databreaches-net (transport-403, 3rd consecutive run — content reached via GTIG/SecurityWeek primaries instead); mandiant-gtig (RSS feed returned IncompleteRead, content obtained via WebSearch + the GTIG blog directly); inside-it-ch (Cloudflare-challenged for the W2 sub-agent UA, but the 06-26 Gentlemen article was reachable and is cited). W2 &quot;outside-window&quot; sources (cert-eu, edpb, bsi-de, enisa-nis360, cisa-directives) were quiet in-window, not failed fetches. The end-of-run <code>tools/source_health.py</code> accessibility probe did not complete inside its budget in this container (slow under the egress proxy) and was stopped so it would not block publish; the prior committed snapshot (from the 2026-06-28 daily run) stands and the next run re-probes.</li></ul>
<p><em>Migrated from briefs/weekly/2026-W26.md (v2).</em></p></div></div><div class="run-note" data-run-id="2026-W25-0aacfe65"><h3 class="run-note__head"><span class="mono">2026-W25-0aacfe65</span> <span class="muted">· weekly · Claude Opus 4.8 · 42 entries published</span></h3><div class="run-note__body"><ul><li><strong>Items flagged <code>[SINGLE-SOURCE]</code> this week:</strong> HCRG Care Group breach (§ 4; single HIPAA-focused outlet, no independent corroboration in-window); Amazon One Medical ShinyHunters 8.8 TB claim (§ 2; victim confirmed a legacy-storage breach but the data-volume figure is attacker-asserted and unverified). National-authority single sources covered by the verification carve-out: EDPB Article 33 template (§ 9; EDPB primary), CRA SRP reporting (EC Digital Strategy / ENISA primaries), NCSC-CH Week 24 Wochenrückblick (NCSC-CH primary), G7 CWG declaration (ANSSI host primary). Check Point State of Ransomware Q1 2026 (§ 7) is vendor telemetry, corroborated by Emsisoft. <strong>Tolerated single/aggregator-source items (<code>check_brief.py</code> WARNs, accepted):</strong> the § 8 SocGholish status-update rests on a single Proofpoint research-lab primary (acceptable — Proofpoint is the disclosing analyst); the § 3 FortiSandbox status-update is corroborated only by two aggregators (Security Affairs, Help Net Security) reflecting the still-unconfirmed-by-Fortinet exploitation report (reduced confidence on the exploitation claim accordingly).</li><li><strong>Contradiction (resolved in favour of the primary):</strong> the 06-17 daily framed PAN-OS CVE-2026-0257 as an &quot;exploitation wave with Impacket post-compromise,&quot; but the cited Unit 42 primary states &quot;No post-access behavior or lateral movement has been identified as of this time.&quot; The weekly uses Unit 42&#39;s wording in § 3 — active exploitation confirmed, downstream lateral movement not yet observed by the primary. The Impacket detail may originate from a secondary (Rapid7/Arctic Wolf) report not re-verified this run.</li><li><strong>Items dropped from this week&#39;s roll-up:</strong> VerdantBamboo / UNC5221 BRICKSTORM (Volexity 2026-06-04, out of the 8-day window and already consolidated in the W24 weekly — no fresh in-window delta); Velvet Ant &quot;Operation Highland&quot; (Sygnia 2026-06-11; already consolidated in the W24 weekly § long-running, no fresh delta this week beyond what W24 carried); Prinz Eugen ransomware (06-19 daily deep-dive; new Go family with a French public-sector victim but a single-day item with no cross-day weekly delta — may resurface if it acquires more EU victims); single-day daily items not meeting W-PD-1 (Rokarolla Android banker, the crypto clipboard-hijacker VirusTotal-reputation abuse, the Microsoft USB-LNK Tor worm, UpdraftPlus/phpBB/Zammad patch-only items beyond the § 3 roundup line).</li><li><strong>Reduced-confidence items:</strong> the NoName057(16) G7/Haute-Savoie DDoS attribution (§ 9) rests on the group&#39;s Telegram self-claim with no independent technical corroboration in-window (W2 assessed MEDIUM); the Kodak and One Medical breach-volume figures are attacker-asserted.</li><li><strong>Sub-agents:</strong> both W1 (threat-actor/research/report horizon) and W2 (policy horizon) returned within budget; both ran on Claude Sonnet 4.6. <strong>Timestamp anomaly:</strong> W1&#39;s return-line and <code>findings.W1.yaml</code> report <code>ended_at=2026-06-21T23:52:00Z</code> / <code>duration_seconds=2694</code>, which disagrees with W1&#39;s on-disk <code>.ended_at</code> checkpoint (23:17:59Z) and the wall-clock observed by the main agent (both W-checkpoints present by ~23:18Z). The checkpoint/observed time was used for the run log; the self-reported 45-minute duration is implausible against the observed ~11-minute run.</li><li><strong>Verification:</strong> 4 iterations, model-rotated (iter 1 Claude Opus 4.8 → NEEDS_FIXES truth=5; iter 2 Claude Sonnet 4.6 → NEEDS_FIXES truth=5, all 7 iter-1 remediations confirmed; iter 3 Claude Opus 4.8 → NEEDS_FIXES truth=3; iter 4 Claude Sonnet 4.6 → CLEAN). All findings were truth-class accuracy corrections — sub-agent-asserted specifics that did not trace to the cited primaries on independent re-fetch — and every one was remediated before publish: DORA &quot;one-third&quot; reframed from third-party to cross-border impact; Check Point EU-% figure removed (it was healthcare-sector, not EU-wide); INC ransomware victim geography corrected (majority-US, not non-US) and unverifiable NHS victim names dropped; SocGholish figures aligned to Proofpoint (over 100 servers / 14,971 sites / seven residual clusters); EDPB template structural specifics and the NCSC-CH e-vignette claim removed as unsourced; Mastra publish-window and Klue victim-list corrected; the NIS2/CER item stripped to source-supportable claims. Residual count: 0 (clean publish at iteration 4).</li><li><strong>Coverage gaps:</strong> databreaches-net (persistent HTTP 403, rotation-priority); inside-it-ch (Cloudflare 403, persistent); finma-ch (no in-window guidance — quiet); ofcom-bakom (no in-window publication — quiet); ncsc-ch-week-25 (Week 25 Wochenrückblick not yet published, HTTP 404 as of run end); acronis-tru (HTTP 403, content recovered via The Hacker News); bleepingcomputer (HTTP 403 on two articles, recovered via secondary sourcing).</li></ul>
<p>— <em>Source: run state · Tags: verification-notes · Region: global</em></p>
<p><em>Migrated from briefs/weekly/2026-W25.md (v2).</em></p></div></div></div></details>]]></content:encoded></item><item><title>CTI Weekly Summary · 2026-W24</title><link>https://ctipilot.ch/weekly/2026-W24/</link><guid isPermaLink="true">https://ctipilot.ch/weekly/2026-W24/</guid><pubDate>Sun, 14 Jun 2026 23:57:43 +0000</pubDate><dc:date>2026-06-14T23:57:43Z</dc:date><category>CVE-2025-8088</category><category>CVE-2026-20253</category><category>CVE-2026-44748</category><category>CVE-2026-49261</category><description><![CDATA[<ul><li><strong>European Commission refers France and Spain to the CJEU over NIS2 non-transposition.</strong> The European Commission referred France and Spain to the CJEU over NIS2 non-transposition, 19+ months past the deadline — financial penalties now in play and a signal to the five remaining non-transposers. (Brussels Signal) <a href="https://ctipilot.ch/entries/2026-06-14/european-commission-refers-france-and-spain-to-the-cjeu-over/">→</a></li><li><strong>France&#39;s Tchap government messenger — account-takeover scrapes 73,467 civil servants&#39; metadata.</strong> France&#39;s sovereign Tchap government messenger was breached — account-takeover scraped metadata on 73,467 civil servants, ANSSI detected it and DINUM disclosed; the largest public-sector incident of the week. (daily 06-10, DINUM) <a href="https://ctipilot.ch/entries/2026-06-14/france-s-tchap-government-messenger-account-takeover-scrapes/">→</a></li><li><strong>CVE-2026-41089 — Windows Netlogon: pre-auth SYSTEM RCE on domain controllers, confirmed exploited in the EU.</strong> Windows Netlogon CVE-2026-41089 is now confirmed exploited inside the EU. CERT-EU advisory 2026-007 confirmed in-the-wild abuse of a pre-auth SYSTEM RCE on unpatched domain controllers — patch every DC in the forest if you have not. (daily 06-11, CERT-EU 2026-007) <a href="https://ctipilot.ch/entries/2026-06-14/cve-2026-41089-windows-netlogon-pre-auth-system-rce-on-domai/">→</a></li><li><strong>Chaotic Eclipse / Nightmare Eclipse Windows zero-day wave — three long-tracked bugs patched, a fourth still open.</strong> June Patch Tuesday was the largest ever (198 CVEs) and finally closed the long-tracked Chaotic Eclipse zero-days (YellowKey, GreenPlasma, MiniPlasma) — but a fourth, GreatXML, remains unpatched, and an HTTP.sys pre-auth RCE (CVE-2026-47291, CVSS 9.8) headlines the release. (daily 06-10, daily 06-12, BleepingComputer) <a href="https://ctipilot.ch/entries/2026-06-14/chaotic-eclipse-nightmare-eclipse-windows-zero-day-wave-thre/">→</a></li><li><strong>CVE-2026-35273 — Oracle PeopleSoft: confirmed zero-day exploited by ShinyHunters (UNC6240), education sector hit hardest.</strong> ShinyHunters&#39; Oracle PeopleSoft campaign was vendor-confirmed as a zero-day and attributed to UNC6240, with education hit hardest. Oracle shipped an out-of-band fix for CVE-2026-35273; the University of Nottingham quantified 455,000 records; Mandiant/GTIG put 100+ organisations in scope. (daily 06-12, daily 06-13, Google GTIG) <a href="https://ctipilot.ch/entries/2026-06-14/cve-2026-35273-oracle-peoplesoft-confirmed-zero-day-exploite/">→</a></li><li><strong>CVE-2026-10520 / CVE-2026-10523 — Ivanti Sentry: pre-auth command injection to root, now confirmed exploited and gateways backdoored.</strong> Ivanti Sentry pre-auth RCE went from PoC to backdoored gateways in four days. CVE-2026-10520 (CVSS 10.0) was an advisory-plus-public-PoC story on Tuesday; by week-end the unauthenticated MICS command injection was confirmed exploited in the wild with attacker implants on internet-facing Sentry gateways. (daily 06-10, daily 06-14, watchTowr Labs) <a href="https://ctipilot.ch/entries/2026-06-14/cve-2026-10520-cve-2026-10523-ivanti-sentry-pre-auth-command/">→</a></li></ul>]]></description><content:encoded><![CDATA[<div class="tldr"><span class="eyebrow eyebrow--muted">Week at a glance</span><ol><li><span class="num">01</span><span><b>European Commission refers France and Spain to the CJEU over NIS2 non-transposition.</b> The European Commission referred France and Spain to the CJEU over NIS2 non-transposition, 19+ months past the deadline — financial penalties now in play and a signal to the five remaining non-transposers. (Brussels Signal) <a href="https://ctipilot.ch/entries/2026-06-14/european-commission-refers-france-and-spain-to-the-cjeu-over/">→</a></span></li><li><span class="num">02</span><span><b>France&#39;s Tchap government messenger — account-takeover scrapes 73,467 civil servants&#39; metadata.</b> France&#39;s sovereign Tchap government messenger was breached — account-takeover scraped metadata on 73,467 civil servants, ANSSI detected it and DINUM disclosed; the largest public-sector incident of the week. (daily 06-10, DINUM) <a href="https://ctipilot.ch/entries/2026-06-14/france-s-tchap-government-messenger-account-takeover-scrapes/">→</a></span></li><li><span class="num">03</span><span><b>CVE-2026-41089 — Windows Netlogon: pre-auth SYSTEM RCE on domain controllers, confirmed exploited in the EU.</b> Windows Netlogon CVE-2026-41089 is now confirmed exploited inside the EU. CERT-EU advisory 2026-007 confirmed in-the-wild abuse of a pre-auth SYSTEM RCE on unpatched domain controllers — patch every DC in the forest if you have not. (daily 06-11, CERT-EU 2026-007) <a href="https://ctipilot.ch/entries/2026-06-14/cve-2026-41089-windows-netlogon-pre-auth-system-rce-on-domai/">→</a></span></li><li><span class="num">04</span><span><b>Chaotic Eclipse / Nightmare Eclipse Windows zero-day wave — three long-tracked bugs patched, a fourth still open.</b> June Patch Tuesday was the largest ever (198 CVEs) and finally closed the long-tracked Chaotic Eclipse zero-days (YellowKey, GreenPlasma, MiniPlasma) — but a fourth, GreatXML, remains unpatched, and an HTTP.sys pre-auth RCE (CVE-2026-47291, CVSS 9.8) headlines the release. (daily 06-10, daily 06-12, BleepingComputer) <a href="https://ctipilot.ch/entries/2026-06-14/chaotic-eclipse-nightmare-eclipse-windows-zero-day-wave-thre/">→</a></span></li><li><span class="num">05</span><span><b>CVE-2026-35273 — Oracle PeopleSoft: confirmed zero-day exploited by ShinyHunters (UNC6240), education sector hit hardest.</b> ShinyHunters&#39; Oracle PeopleSoft campaign was vendor-confirmed as a zero-day and attributed to UNC6240, with education hit hardest. Oracle shipped an out-of-band fix for CVE-2026-35273; the University of Nottingham quantified 455,000 records; Mandiant/GTIG put 100+ organisations in scope. (daily 06-12, daily 06-13, Google GTIG) <a href="https://ctipilot.ch/entries/2026-06-14/cve-2026-35273-oracle-peoplesoft-confirmed-zero-day-exploite/">→</a></span></li><li><span class="num">06</span><span><b>CVE-2026-10520 / CVE-2026-10523 — Ivanti Sentry: pre-auth command injection to root, now confirmed exploited and gateways backdoored.</b> Ivanti Sentry pre-auth RCE went from PoC to backdoored gateways in four days. CVE-2026-10520 (CVSS 10.0) was an advisory-plus-public-PoC story on Tuesday; by week-end the unauthenticated MICS command injection was confirmed exploited in the wild with attacker implants on internet-facing Sentry gateways. (daily 06-10, daily 06-14, watchTowr Labs) <a href="https://ctipilot.ch/entries/2026-06-14/cve-2026-10520-cve-2026-10523-ivanti-sentry-pre-auth-command/">→</a></span></li></ol></div><nav class="secnav" aria-label="Sections"><a class="secnav-chip" href="#highest-impact-events-what-s-on-fire-if-no-one-acted">Highest-impact events · what&#39;s on fire if no one acted <span class="secnav-n">4</span></a><a class="secnav-chip" href="#multi-day-campaigns-and-chains">Multi-day campaigns and chains <span class="secnav-n">3</span></a><a class="secnav-chip" href="#vulnerability-roll-up">Vulnerability roll-up <span class="secnav-n">4</span></a><a class="secnav-chip" href="#sector-victim-patterns">Sector &amp; victim patterns <span class="secnav-n">3</span></a><a class="secnav-chip" href="#incidents-disclosures-recap">Incidents &amp; disclosures recap <span class="secnav-n">4</span></a><a class="secnav-chip" href="#annual-periodic-threat-reports">Annual / periodic threat reports <span class="secnav-n">1</span></a><a class="secnav-chip" href="#long-running-campaigns-status-update">Long-running campaigns · status update <span class="secnav-n">3</span></a><a class="secnav-chip" href="#policy-regulatory-horizon">Policy &amp; regulatory horizon <span class="secnav-n">5</span></a><a class="secnav-chip" href="#looking-ahead-what-to-watch-next-week">Looking ahead · what to watch next week <span class="secnav-n">1</span></a></nav><div class="sect" id="highest-impact-events-what-s-on-fire-if-no-one-acted"><span class="n">01</span><span class="t">Highest-impact events · what&#39;s on fire if no one acted</span><span class="c">4 items</span></div><article class="finding entry-card" data-entry-id="2026-06-14/cve-2026-41089-windows-netlogon-pre-auth-system-rce-on-domai" data-tags="vulnerabilities actively-exploited pre-auth rce" data-regions="europe" data-kind="synthesis" data-priority="high" data-discovered="2026-06-14T23:57:17Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-41089-windows-netlogon-pre-auth-system-rce-on-domai"><a href="https://ctipilot.ch/entries/2026-06-14/cve-2026-41089-windows-netlogon-pre-auth-system-rce-on-domai/">CVE-2026-41089 — Windows Netlogon: pre-auth SYSTEM RCE on domain controllers, confirmed exploited in the EU</a></h3><p><strong>If you did nothing this week:</strong> every unpatched domain controller in your forest is a pre-auth remote-code-execution target as SYSTEM, and the exploitation is no longer hypothetical — CERT-EU confirmed in-the-wild abuse in its jurisdiction this week.</p>
<p>CVE-2026-41089 is a CVSS 9.8 stack-based buffer overflow (CWE-121) in the Windows Netlogon RPC service. It was disclosed and patched in the May/June cycle and tracked in the W23 weekly as a disclosure-and-patch story. This week CERT-EU published advisory 2026-007 (10 June) confirming active exploitation against unpatched DCs in the EU (<a href="https://cert.europa.eu/publications/security-advisories/2026-007/" target="_blank" rel="noopener noreferrer">CERT-EU 2026-007</a>; <a href="https://ctipilot.ch/briefs/2026-06-11/" target="_blank" rel="noopener noreferrer">daily 06-11</a>). A domain controller compromise is full-domain compromise: the entire identity plane is in scope.</p>
<p>Patch every domain controller now — DCs are the one asset class where &quot;patch window&quot; is not a negotiation. Where patching lags, restrict Netlogon RPC exposure at the network layer and hunt for anomalous pre-authentication RPC traffic to DCs and for new SYSTEM-context processes on those hosts.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/cve-2026-41089-windows-netlogon-pre-auth-system-rce-on-domai/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cert.europa.eu/publications/security-advisories/2026-007/" target="_blank" rel="noopener noreferrer">CERT-EU advisory 2026-007</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/cve-2026-35273-oracle-peoplesoft-confirmed-zero-day-exploite" data-tags="vulnerabilities actively-exploited zero-day data-breach" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-06-14T23:57:18Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-35273-oracle-peoplesoft-confirmed-zero-day-exploite"><a href="https://ctipilot.ch/entries/2026-06-14/cve-2026-35273-oracle-peoplesoft-confirmed-zero-day-exploite/">CVE-2026-35273 — Oracle PeopleSoft: confirmed zero-day exploited by ShinyHunters (UNC6240), education sector hit hardest</a></h3><p><strong>If you did nothing this week:</strong> if you run internet-reachable Oracle PeopleSoft, assume data-theft exposure — the initial-access vector that was merely attacker-asserted last week is now vendor-confirmed as a zero-day, with 100+ organisations already breached.</p>
<p>What was a claim-only story on 11 June became vendor-confirmed within 48 hours. Oracle assigned CVE-2026-35273 (CVSS 9.8), an unauthenticated flaw in the PeopleSoft Environment Management Hub, and shipped an out-of-band patch (<a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html" target="_blank" rel="noopener noreferrer">Oracle security alert</a>; <a href="https://ctipilot.ch/briefs/2026-06-12/" target="_blank" rel="noopener noreferrer">daily 06-12</a>). Mandiant and Google GTIG then formally attributed the campaign to UNC6240 (ShinyHunters) and confirmed active exploitation against 100+ organisations, with the education sector disproportionately represented; the University of Nottingham quantified roughly 455,000 affected records (<a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/" target="_blank" rel="noopener noreferrer">Google GTIG</a>; <a href="https://ctipilot.ch/briefs/2026-06-13/" target="_blank" rel="noopener noreferrer">daily 06-13</a>).</p>
<p>This is a direct hit on a sector dense with European public-sector entities — universities and research institutions running PeopleSoft for HR and campus systems. Apply Oracle&#39;s out-of-band fix, then assume data exfiltration on any instance that was internet-reachable before patching: review Environment Management Hub access logs, rotate exposed credentials, and prepare for extortion contact, which is ShinyHunters&#39; standard follow-through.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/cve-2026-35273-oracle-peoplesoft-confirmed-zero-day-exploite/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.oracle.com/security-alerts/alert-cve-2026-35273.html" target="_blank" rel="noopener noreferrer">Oracle security alert</a> · <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/" target="_blank" rel="noopener noreferrer">Google GTIG</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/cve-2026-10520-cve-2026-10523-ivanti-sentry-pre-auth-command" data-tags="vulnerabilities actively-exploited pre-auth rce cisa-kev" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-06-14T23:57:16Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-10520-cve-2026-10523-ivanti-sentry-pre-auth-command"><a href="https://ctipilot.ch/entries/2026-06-14/cve-2026-10520-cve-2026-10523-ivanti-sentry-pre-auth-command/">CVE-2026-10520 / CVE-2026-10523 — Ivanti Sentry: pre-auth command injection to root, now confirmed exploited and gateways backdoored</a></h3><p><strong>If you did nothing this week:</strong> any internet-facing Ivanti Sentry gateway you run is likely already compromised. The flaw moved from &quot;advisory plus public PoC&quot; on 10 June to confirmed in-the-wild exploitation with persistent implants by 14 June.</p>
<p>CVE-2026-10520 (CVSS 10.0) is an unauthenticated OS command injection in the MICS (Mobile Iron Configuration Service) administrative interface of Ivanti Sentry — the EMM/MDM enforcement gateway that proxies email and applications to managed mobile devices and is frequently exposed to the internet. watchTowr Labs published the technical analysis and a working proof-of-concept on 10 June (<a href="https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/" target="_blank" rel="noopener noreferrer">watchTowr Labs</a>; <a href="https://ctipilot.ch/briefs/2026-06-10/" target="_blank" rel="noopener noreferrer">daily 06-10</a>), and a paired path (CVE-2026-10523) compounds the exposure. By 14 June SecurityAffairs and others reported that gateways were being compromised shortly after patch release, with attacker-established footholds on exposed systems (<a href="https://ctipilot.ch/briefs/2026-06-14/" target="_blank" rel="noopener noreferrer">daily 06-14</a>, <a href="https://securityaffairs.com/193530/hacking/cve-2026-10520-exploited-ivanti-sentry-gateways-compromised-shortly-after-patch-release.html" target="_blank" rel="noopener noreferrer">SecurityAffairs</a>).</p>
<p>Because the injection is pre-auth and on the management interface, the only safe assumption for an exposed, unpatched Sentry is that it has been touched. Patch to the fixed Sentry release immediately, then treat the appliance as suspect: review for unexpected child processes spawned by the Sentry service account, unexplained outbound connections, and modified web-tier files. Restrict the MICS interface to management networks — it should never have been internet-reachable.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/cve-2026-10520-cve-2026-10523-ivanti-sentry-pre-auth-command/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/" target="_blank" rel="noopener noreferrer">watchTowr Labs</a> · <a href="https://securityaffairs.com/193530/hacking/cve-2026-10520-exploited-ivanti-sentry-gateways-compromised-shortly-after-patch-release.html" target="_blank" rel="noopener noreferrer">SecurityAffairs</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen" data-tags="vulnerabilities actively-exploited auth-bypass ransomware" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-14T23:57:19Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen"><a href="https://ctipilot.ch/entries/2026-06-14/cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen/">CVE-2026-50751 — Check Point Security Gateway: IKEv1 VPN authentication bypass exploited by a Qilin affiliate</a></h3><p><strong>If you did nothing this week:</strong> a Remote Access VPN gateway running the deprecated IKEv1 path is an active ransomware entry point — a Qilin affiliate is using this bypass for initial access.</p>
<p>Check Point disclosed and patched CVE-2026-50751 (CVSS 9.3) on 8 June — a certificate-validation logic flaw in the deprecated IKEv1 key exchange affecting Remote Access VPN and Mobile Access on Security Gateway (<a href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/" target="_blank" rel="noopener noreferrer">Check Point</a>; <a href="https://ctipilot.ch/briefs/2026-06-09/" target="_blank" rel="noopener noreferrer">daily 06-09</a>). The disclosure noted exploitation by a Qilin ransomware affiliate, which puts this firmly in the inaction-equals-incident column: VPN gateways are the front door, and a ransomware crew is already through it on unpatched IKEv1 deployments.</p>
<p>Apply the hotfix and, where operationally possible, disable IKEv1 entirely in favour of IKEv2 — the flaw lives in a protocol path most estates no longer need. Hunt for anomalous VPN session establishment without corresponding successful certificate validation and for new Remote Access sessions from unexpected geographies.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/cve-2026-50751-check-point-security-gateway-ikev1-vpn-authen/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/" target="_blank" rel="noopener noreferrer">Check Point advisory</a></div></article><div class="sect" id="multi-day-campaigns-and-chains"><span class="n">02</span><span class="t">Multi-day campaigns and chains</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-06-14/chaotic-eclipse-nightmare-eclipse-windows-zero-day-wave-thre" data-tags="vulnerabilities zero-day lpe poc-public" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-06-14T23:57:20Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="chaotic-eclipse-nightmare-eclipse-windows-zero-day-wave-thre"><a href="https://ctipilot.ch/entries/2026-06-14/chaotic-eclipse-nightmare-eclipse-windows-zero-day-wave-thre/">Chaotic Eclipse / Nightmare Eclipse Windows zero-day wave — three long-tracked bugs patched, a fourth still open</a></h3><p>This researcher&#39;s serialised zero-day disclosures have run across four weekly cycles, and this week brought both resolution and a fresh open wound. June Patch Tuesday (9 June) finally closed the three bugs the W20–W22 weeklies tracked as &quot;expected fix in June&quot;: <strong>YellowKey</strong> (CVE-2026-45585, BitLocker bypass via the Windows Recovery Environment, physical access required), <strong>GreenPlasma</strong> (CVE-2026-45586, CTFMON elevation to SYSTEM), and <strong>MiniPlasma</strong> (a re-opened regression of CVE-2020-17103 in the Cloud Filter driver <code>cldflt.sys</code>), per the patch-day round-ups (<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws/" target="_blank" rel="noopener noreferrer">BleepingComputer</a>; <a href="https://www.tenable.com/blog/microsofts-june-2026-patch-tuesday-addresses-198-cves-cve-2026-49160-cve-2026-50507" target="_blank" rel="noopener noreferrer">Tenable</a>).</p>
<p>But the cadence continued the same day. On 9 June the researcher published <strong>RoguePlanet</strong>, a TOCTOU race in the Microsoft Defender scan engine yielding a SYSTEM shell — hours after the patches landed, with no CVE and no fix (<a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/" target="_blank" rel="noopener noreferrer">BleepingComputer</a>; <a href="https://ctipilot.ch/briefs/2026-06-11/" target="_blank" rel="noopener noreferrer">daily 06-11</a>). Two days later came <strong>GreatXML</strong>, a BitLocker bypass via crafted XML on the recovery partition — PoC public, practical severity contested, still unpatched (<a href="https://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/" target="_blank" rel="noopener noreferrer">SecurityWeek</a>; <a href="https://ctipilot.ch/briefs/2026-06-12/" target="_blank" rel="noopener noreferrer">daily 06-12</a>). The trajectory: deploy the June cumulative update to close the three patched bugs, retain BitLocker PIN/TPM policy regardless, and keep monitoring MSRC — the fourth disclosure is the pattern, not the exception.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/chaotic-eclipse-nightmare-eclipse-windows-zero-day-wave-thre/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws/" target="_blank" rel="noopener noreferrer">BleepingComputer — June Patch Tuesday</a> · <a href="https://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/" target="_blank" rel="noopener noreferrer">SecurityWeek — GreatXML</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/maine-breach-notification-portal-hoax-fraudulent-filings-aga" data-tags="disinformation data-breach" data-regions="us" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-14T23:57:22Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="maine-breach-notification-portal-hoax-fraudulent-filings-aga"><a href="https://ctipilot.ch/entries/2026-06-14/maine-breach-notification-portal-hoax-fraudulent-filings-aga/">Maine breach-notification portal hoax — fraudulent filings against VRChat and Discord, then the portal goes dark</a></h3><p>A two-day arc that doubles as a fake-news cautionary tale. On 12 June, Maine&#39;s Attorney-General breach-notification portal published two fraudulent filings — one claiming a 2.4-million-user VRChat compromise, another a 10-million-user Discord breach — because the portal accepted submissions without verifying the submitter; both companies denied any breach (<a href="https://www.bleepingcomputer.com/news/security/maine-breach-portal-abused-to-publish-fake-data-breach-disclosures/" target="_blank" rel="noopener noreferrer">BleepingComputer</a>; <a href="https://ctipilot.ch/briefs/2026-06-12/" target="_blank" rel="noopener noreferrer">daily 06-12</a>). On 12 June the Maine AG issued a formal statement confirming the filings were a hoax and took the portal offline (<a href="https://www.maine.gov/ag/news-and-library/press-releases/statement-office-maine-attorney-general-abuse-data-breach-reporting" target="_blank" rel="noopener noreferrer">Maine AG</a>; <a href="https://ctipilot.ch/briefs/2026-06-13/" target="_blank" rel="noopener noreferrer">daily 06-13</a>). The defender lesson is sourcing discipline: a government breach-notification portal is normally a high-reliability primary, but an unauthenticated submission path turned it into a vector for fabricated breach claims. Treat single-portal breach assertions as claim-only until the named victim confirms.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/maine-breach-notification-portal-hoax-fraudulent-filings-aga/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/maine-breach-portal-abused-to-publish-fake-data-breach-disclosures/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.maine.gov/ag/news-and-library/press-releases/statement-office-maine-attorney-general-abuse-data-breach-reporting" target="_blank" rel="noopener noreferrer">Maine AG statement</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/shai-hulud-miasma-supply-chain-worm-lineage-open-sourced-por" data-tags="supply-chain infostealer botnet" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-14T23:57:21Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="shai-hulud-miasma-supply-chain-worm-lineage-open-sourced-por"><a href="https://ctipilot.ch/entries/2026-06-14/shai-hulud-miasma-supply-chain-worm-lineage-open-sourced-por/">Shai-Hulud / Miasma supply-chain worm lineage — open-sourced, ported to PyPI, and a 1,500-package AUR wave</a></h3><p>The supply-chain-worm family the W23 weekly consolidated under the Miasma/IronWorm banner spent this week proliferating across ecosystems and operators. On 9 June a SANS ISC handler tracked TeamPCP open-sourcing its Mini Shai-Hulud framework, immediately spawning a &quot;Phantom Gyp&quot; derivative (<a href="https://isc.sans.edu/diary/33060" target="_blank" rel="noopener noreferrer">SANS ISC</a>; <a href="https://ctipilot.ch/briefs/2026-06-09/" target="_blank" rel="noopener noreferrer">daily 06-09</a>). On 10 June the lineage opened a PyPI front dubbed &quot;Hades&quot; — 37 malicious wheels across 19 packages (<a href="https://thehackernews.com/2026/06/hades-pypi-attack-19-packages-poisoned.html" target="_blank" rel="noopener noreferrer">The Hacker News</a>; <a href="https://ctipilot.ch/briefs/2026-06-10/" target="_blank" rel="noopener noreferrer">daily 06-10</a>).</p>
<p>The week&#39;s largest wave hit the Arch User Repository. &quot;Atomic Arch&quot; began with roughly 400 orphaned AUR packages adopted and re-pointed to a Rust credential-stealer plus eBPF rootkit (<a href="https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html" target="_blank" rel="noopener noreferrer">The Hacker News</a>; <a href="https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency" target="_blank" rel="noopener noreferrer">Sonatype</a>; <a href="https://ctipilot.ch/briefs/2026-06-13/" target="_blank" rel="noopener noreferrer">daily 06-13</a>); a second wave around 12 June expanded the count further (tracker estimates range from the 400+ in primary reporting to ~1,500) and swapped some PKGBUILD delivery from npm dependency injection to <code>bun install js-digest</code> — active operator iteration against detection. The npm delivery mechanism has been linked by SANS ISC and subsequent reporting to the broader Shai-Hulud supply-chain family. Official Arch core/extra repositories were not affected; only adopted AUR packages. For defenders the through-line is constant: install-time script execution is the kill chain, and <code>npm</code>/<code>bun</code>/AUR build steps need to be treated as untrusted code execution in CI/CD.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/shai-hulud-miasma-supply-chain-worm-lineage-open-sourced-por/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency" target="_blank" rel="noopener noreferrer">Sonatype — Atomic Arch</a> · <a href="https://thehackernews.com/2026/06/over-400-arch-linux-aur-packages.html" target="_blank" rel="noopener noreferrer">The Hacker News — AUR wave</a></div></article><div class="sect" id="vulnerability-roll-up"><span class="n">03</span><span class="t">Vulnerability roll-up</span><span class="c">4 items</span></div><article class="finding entry-card" data-entry-id="2026-06-14/cve-2025-8088-winrar-path-traversal-still-fuelling-ukraine-i" data-tags="vulnerabilities actively-exploited nation-state path-traversal russia-nexus" data-regions="europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-14T23:57:26Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2025-8088/">CVE-2025-8088</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2025-8088-winrar-path-traversal-still-fuelling-ukraine-i"><a href="https://ctipilot.ch/entries/2026-06-14/cve-2025-8088-winrar-path-traversal-still-fuelling-ukraine-i/">CVE-2025-8088 — WinRAR path traversal: still fuelling Ukraine intrusions a year after the fix</a></h3><p>A reminder that &quot;patched&quot; is not &quot;remediated&quot; where users don&#39;t update. Trend Micro documented two Russia-aligned campaigns still exploiting CVE-2025-8088 — a path traversal via NTFS Alternate Data Streams in WinRAR patched in July 2025 — nearly a year on: GIFTEDCROOK delivery via UAC-0226 and an Earth Dahu chain (<a href="https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html" target="_blank" rel="noopener noreferrer">Trend Micro</a>; <a href="https://ctipilot.ch/briefs/2026-06-10/" target="_blank" rel="noopener noreferrer">daily 06-10</a>). The operational takeaway for any estate with desktop WinRAR: inventory and force-update, because the archived-fix assumption is exactly what these operators rely on.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">A reminder that &quot;patched&quot; is not &quot;remediated&quot; where users don&#39;t update.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/cve-2025-8088-winrar-path-traversal-still-fuelling-ukraine-i/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html" target="_blank" rel="noopener noreferrer">Trend Micro</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/cve-2026-44748-sap-netweaver-as-abap-saml-xml-signature-wrap" data-tags="vulnerabilities auth-bypass pre-auth" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-14T23:57:25Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-44748/">CVE-2026-44748</a></div><h3 class="f-h" id="cve-2026-44748-sap-netweaver-as-abap-saml-xml-signature-wrap"><a href="https://ctipilot.ch/entries/2026-06-14/cve-2026-44748-sap-netweaver-as-abap-saml-xml-signature-wrap/">CVE-2026-44748 — SAP NetWeaver AS ABAP: SAML XML Signature Wrapping (CVSS 9.9)</a></h3><p>SAP&#39;s June Patch Day (9 June) shipped multiple HotNews notes; the most severe affect NetWeaver AS ABAP and the ABAP Platform — the ERP backbone across Swiss federal/cantonal administration and EU public-sector finance. CVE-2026-44748 (CVSS 9.9) is a SAML XML Signature Wrapping flaw, paired with an unauthenticated RFC kernel memory-corruption bug (CVSS 9.8) (<a href="https://onapsis.com/blog/sap-security-patch-day-june-2026" target="_blank" rel="noopener noreferrer">Onapsis</a>; <a href="https://ctipilot.ch/briefs/2026-06-10/" target="_blank" rel="noopener noreferrer">daily 06-10</a>). Signature-wrapping bugs let an attacker forge an assertion that passes signature validation while carrying attacker-chosen identity content — an authentication bypass against SAML-federated logins. Apply the June HotNews notes; for SAML federation, verify the patched NetWeaver enforces strict assertion-to-signature binding, and hunt for logons with valid-but-anomalous assertion structure.</p><div class="prov"><span>vulnerability</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/cve-2026-44748-sap-netweaver-as-abap-saml-xml-signature-wrap/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://onapsis.com/blog/sap-security-patch-day-june-2026" target="_blank" rel="noopener noreferrer">Onapsis</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/cve-2026-49261-mariadb-galera-cluster-pre-auth-lateral-rce-v" data-tags="vulnerabilities pre-auth rce" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-14T23:57:24Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-49261/">CVE-2026-49261</a></div><h3 class="f-h" id="cve-2026-49261-mariadb-galera-cluster-pre-auth-lateral-rce-v"><a href="https://ctipilot.ch/entries/2026-06-14/cve-2026-49261-mariadb-galera-cluster-pre-auth-lateral-rce-v/">CVE-2026-49261 — MariaDB Galera cluster: pre-auth lateral RCE via wsrep_notify_cmd</a></h3><p>NCSC-CH&#39;s Security Hub flagged a CVSS 10.0 OS command injection (post 12627, 11 June) that did not surface in the daily briefs. When MariaDB Community or Enterprise Server runs in a Galera cluster with <code>wsrep_notify_cmd</code> configured, the notification command is built by interpolating peer-supplied <code>wsrep_node_name</code> and <code>wsrep_node_incoming_address</code> fields directly into a string passed to <code>sh -c</code> — without escaping (<a href="https://security-hub.ncsc.admin.ch/#/posts/12627" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub</a>; <a href="https://mariadb.com/docs/server/security/cve/community-server" target="_blank" rel="noopener noreferrer">MariaDB CVE list</a>). A malicious or compromised cluster peer that announces a node name containing shell metacharacters achieves arbitrary command execution on every cluster member with a notify command configured, at the privilege of the database process — lateral RCE across the whole cluster, DB authentication bypassed. Fixed in Community 10.6.27 / 10.11.18 / 11.4.12 / 11.8.8 / 12.3.2 and the corresponding Enterprise builds. This matters for European public-sector estates because MariaDB underpins a great deal of self-hosted open-source tooling (Nextcloud, Moodle, GLPI). Patch immediately; if Galera notifications are required, restrict cluster-join initiation to trusted internal nodes at the network layer (Galera ports 4567/4568) and disable <code>wsrep_notify_cmd</code> where it is not strictly needed.</p><div class="prov"><span>vulnerability</span><span>14 Jun 23:57Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/cve-2026-49261-mariadb-galera-cluster-pre-auth-lateral-rce-v/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://security-hub.ncsc.admin.ch/#/posts/12627" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub post 12627</a> · <a href="https://mariadb.com/docs/server/security/cve/community-server" target="_blank" rel="noopener noreferrer">MariaDB CVE list</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/cve-2026-20253-splunk-enterprise-unauthenticated-arbitrary-f" data-tags="vulnerabilities pre-auth" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-14T23:57:23Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20253/">CVE-2026-20253</a></div><h3 class="f-h" id="cve-2026-20253-splunk-enterprise-unauthenticated-arbitrary-f"><a href="https://ctipilot.ch/entries/2026-06-14/cve-2026-20253-splunk-enterprise-unauthenticated-arbitrary-f/">CVE-2026-20253 — Splunk Enterprise: unauthenticated arbitrary file creation/truncation via the PostgreSQL sidecar proxy</a></h3><p>Disclosed this week and not yet seen exploited, but it belongs in the operationally-critical tier because Splunk is the SIEM/log-analytics backbone in many SOCs — including public-sector ones — and an unauthenticated flaw on your detection platform is a defender&#39;s worst-case blind spot. Per Splunk&#39;s advisory, CVE-2026-20253 (CVSS 9.8, CWE-306 Missing Authentication for Critical Function) lets an unauthenticated actor create or truncate arbitrary files via the bundled PostgreSQL sidecar proxy in Splunk Enterprise 10.0.0–10.0.6 and 10.2.0–10.2.3 — a primitive that can be chained toward code execution but which the advisory itself scopes as file creation/truncation rather than direct RCE (<a href="https://advisory.splunk.com/advisories/SVD-2026-0603" target="_blank" rel="noopener noreferrer">Splunk SVD-2026-0603</a>; <a href="https://ctipilot.ch/briefs/2026-06-14/" target="_blank" rel="noopener noreferrer">daily 06-14</a>). Patch to the fixed maintenance releases; where the Splunk web/API tier is internet-reachable, restrict it now — a compromised SIEM lets an attacker both pivot and rewrite the evidence.</p><div class="prov"><span>vulnerability</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/cve-2026-20253-splunk-enterprise-unauthenticated-arbitrary-f/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://advisory.splunk.com/advisories/SVD-2026-0603" target="_blank" rel="noopener noreferrer">Splunk SVD-2026-0603</a></div></article><div class="sect" id="sector-victim-patterns"><span class="n">04</span><span class="t">Sector &amp; victim patterns</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-06-14/education-shinyhunters-peoplesoft-campaign-lands-disproporti" data-tags="data-breach supply-chain" data-regions="uk europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-14T23:57:28Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="education-shinyhunters-peoplesoft-campaign-lands-disproporti"><a href="https://ctipilot.ch/entries/2026-06-14/education-shinyhunters-peoplesoft-campaign-lands-disproporti/">Education — ShinyHunters&#39; PeopleSoft campaign lands disproportionately on universities</a></h3><p>The week&#39;s clearest sectoral concentration. Mandiant/GTIG&#39;s attribution of the Oracle PeopleSoft zero-day campaign (§ 1) explicitly noted that the education sector was hit hardest, with the University of Nottingham confirming ~455,000 affected records (<a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/" target="_blank" rel="noopener noreferrer">Google GTIG</a>; <a href="https://ctipilot.ch/briefs/2026-06-13/" target="_blank" rel="noopener noreferrer">daily 06-13</a>). It rhymes with the earlier Oxford University CareerConnect breach, where third-party provider Group GTI&#39;s compromise exposed students across multiple UK universities (<a href="https://www.careers.ox.ac.uk/article/careerconnect-secured-and-safe-to-use-following-data-security-incident" target="_blank" rel="noopener noreferrer">Oxford</a>; <a href="https://ctipilot.ch/briefs/2026-06-09/" target="_blank" rel="noopener noreferrer">daily 06-09</a>). European higher-education ICT teams running PeopleSoft or relying on shared careers/HR SaaS should treat both as direct warnings.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/education-shinyhunters-peoplesoft-campaign-lands-disproporti/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/" target="_blank" rel="noopener noreferrer">Google GTIG</a> · <a href="https://www.careers.ox.ac.uk/article/careerconnect-secured-and-safe-to-use-following-data-security-incident" target="_blank" rel="noopener noreferrer">Oxford University</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/public-administration-the-week-s-centre-of-gravity" data-tags="phishing identity nation-state" data-regions="switzerland europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-14T23:57:27Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="public-administration-the-week-s-centre-of-gravity"><a href="https://ctipilot.ch/entries/2026-06-14/public-administration-the-week-s-centre-of-gravity/">Public administration — the week&#39;s centre of gravity</a></h3><p>The public sector again carried the highest concentration of operationally severe items. France&#39;s sovereign Tchap messenger breach (§ 5) struck the French civil service directly; NCSC-CH&#39;s Week 23 report documented a coordinated surge in job-seeker targeting against Swiss residents — fake interviews, reshipping identity theft, and LinkedIn-to-GitHub infostealer delivery (<a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/wochenrueckblick_23.html" target="_blank" rel="noopener noreferrer">NCSC-CH</a>; <a href="https://ctipilot.ch/briefs/2026-06-10/" target="_blank" rel="noopener noreferrer">daily 06-10</a>); and ENISA ran its biennial Cyber Europe 2026 exercise (10–11 June), testing the revised EU Cyber Blueprint and triggering the first live activation of the EU Cybersecurity Reserve (<a href="https://www.enisa.europa.eu/news/cyber-europe-2026-all-eyes-on-the-eus-collective-response-and-resilience" target="_blank" rel="noopener noreferrer">ENISA</a>; <a href="https://ctipilot.ch/briefs/2026-06-14/" target="_blank" rel="noopener noreferrer">daily 06-14</a>). The pattern for a Swiss/EU public-sector SOC: the threats are arriving through identity and through suppliers, and the EU&#39;s collective-response machinery is being stress-tested precisely because that is where the pressure is.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/public-administration-the-week-s-centre-of-gravity/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/wochenrueckblick_23.html" target="_blank" rel="noopener noreferrer">NCSC-CH Week 23</a> · <a href="https://www.enisa.europa.eu/news/cyber-europe-2026-all-eyes-on-the-eus-collective-response-and-resilience" target="_blank" rel="noopener noreferrer">ENISA Cyber Europe 2026</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/healthcare-energy-large-scale-personal-data-exposure-from-th" data-tags="data-breach" data-regions="apac" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-14T23:57:29Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="healthcare-energy-large-scale-personal-data-exposure-from-th"><a href="https://ctipilot.ch/entries/2026-06-14/healthcare-energy-large-scale-personal-data-exposure-from-th/">Healthcare &amp; energy — large-scale personal-data exposure from theft and from mishandling</a></h3><p>Two contrasting root causes in one week. Novo Nordisk disclosed the theft of non-public data including personal data after an external party accessed internal systems (§ 5) — a deliberate intrusion against pharma. At the other end, Kyushu Electric&#39;s transmission/distribution subsidiary lost an <strong>unencrypted</strong> portable SSD holding personal records for roughly 10.9 million customers — reportedly Japan&#39;s largest personal-data breach, and an entirely preventable one (<a href="https://www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/" target="_blank" rel="noopener noreferrer">BleepingComputer</a>; <a href="https://ctipilot.ch/briefs/2026-06-14/" target="_blank" rel="noopener noreferrer">daily 06-14</a>). For utilities and healthcare data custodians the joint lesson is unglamorous: full-disk encryption on removable media is still the control that turns a lost-device headline into a non-event.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/healthcare-energy-large-scale-personal-data-exposure-from-th/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/japanese-energy-firm-loses-drive-with-data-of-109-million-clients/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article><div class="sect" id="incidents-disclosures-recap"><span class="n">05</span><span class="t">Incidents &amp; disclosures recap</span><span class="c">4 items</span></div><article class="finding entry-card" data-entry-id="2026-06-14/france-s-tchap-government-messenger-account-takeover-scrapes" data-tags="data-breach identity" data-regions="europe" data-kind="incident" data-priority="high" data-discovered="2026-06-14T23:57:30Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="france-s-tchap-government-messenger-account-takeover-scrapes"><a href="https://ctipilot.ch/entries/2026-06-14/france-s-tchap-government-messenger-account-takeover-scrapes/">France&#39;s Tchap government messenger — account-takeover scrapes 73,467 civil servants&#39; metadata</a></h3><p>The most consequential public-sector incident of the week. On 7 June ANSSI detected a compromise of Tchap, the French state&#39;s sovereign Matrix-based encrypted messenger used by ~825,000 civil servants across all ministries; DINUM published the disclosure (<a href="https://www.numerique.gouv.fr/sinformer/espace-presse/incident-tchap/" target="_blank" rel="noopener noreferrer">DINUM</a>; <a href="https://ctipilot.ch/briefs/2026-06-10/" target="_blank" rel="noopener noreferrer">daily 06-10</a>). The attacker used account takeover to scrape directory metadata on 73,467 users; message content, protected by end-to-end encryption, was not exposed, and CNIL was notified. The defender takeaway is that &quot;sovereign and E2E-encrypted&quot; still leaves a metadata-harvesting surface at the account/identity layer — the directory is a target even when the message body is not.</p><div class="prov"><span>incident</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/france-s-tchap-government-messenger-account-takeover-scrapes/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.numerique.gouv.fr/sinformer/espace-presse/incident-tchap/" target="_blank" rel="noopener noreferrer">DINUM incident page</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/law-enforcement-follow-through-conti-loader-developer-pleads" data-tags="law-enforcement ransomware cryptocrime" data-regions="us europe" data-kind="incident" data-priority="notable" data-discovered="2026-06-14T23:57:32Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="law-enforcement-follow-through-conti-loader-developer-pleads"><a href="https://ctipilot.ch/entries/2026-06-14/law-enforcement-follow-through-conti-loader-developer-pleads/">Law-enforcement follow-through — Conti loader developer pleads guilty, AudiA6 laundering service dismantled</a></h3><p>Two enforcement wins with a Swiss touchpoint. Ukrainian national Oleksii Lytvynenko pleaded guilty on 12 June in US federal court (Middle District of Tennessee) to conspiracy to commit wire fraud for his role developing loaders for the Conti ransomware operation, after extradition from Ireland (<a href="https://www.globalsecurity.org/security/library/news/2026/06/sec-260612-doj01.htm" target="_blank" rel="noopener noreferrer">DOJ via GlobalSecurity</a>; <a href="https://ctipilot.ch/briefs/2026-06-14/" target="_blank" rel="noopener noreferrer">daily 06-14</a>). Separately, a US-Secret-Service-led operation with Europol, Eurojust and ten countries — <strong>Switzerland among the participants</strong> — dismantled the AudiA6 cryptocurrency money-laundering service and charged two individuals (<a href="https://www.secretservice.gov/newsroom/releases/2026/06/two-charged-connection-cryptocurrency-money-laundering-service-allegedly" target="_blank" rel="noopener noreferrer">US Secret Service</a>; <a href="https://ctipilot.ch/briefs/2026-06-12/" target="_blank" rel="noopener noreferrer">daily 06-12</a>). The cumulative signal: the affiliate-and-launderer layer of the ransomware economy continues to be peeled back through international cooperation, with Swiss authorities now routinely in the coalition.</p><div class="prov"><span>incident</span><span>14 Jun 23:57Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/law-enforcement-follow-through-conti-loader-developer-pleads/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.secretservice.gov/newsroom/releases/2026/06/two-charged-connection-cryptocurrency-money-laundering-service-allegedly" target="_blank" rel="noopener noreferrer">US Secret Service</a> · <a href="https://www.globalsecurity.org/security/library/news/2026/06/sec-260612-doj01.htm" target="_blank" rel="noopener noreferrer">DOJ via GlobalSecurity</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/novo-nordisk-theft-of-non-public-data-including-personal-dat" data-tags="data-breach" data-regions="europe" data-kind="incident" data-priority="notable" data-discovered="2026-06-14T23:57:31Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="novo-nordisk-theft-of-non-public-data-including-personal-dat"><a href="https://ctipilot.ch/entries/2026-06-14/novo-nordisk-theft-of-non-public-data-including-personal-dat/">Novo Nordisk — theft of non-public data including personal data</a></h3><p>Danish pharmaceutical maker Novo Nordisk disclosed on 11 June that an external party gained unauthorised access to a limited number of internal IT systems and copied non-public data, including personal data (<a href="https://www.novonordisk.com/news-and-media/news-and-ir-materials/news-details.html?id=916571" target="_blank" rel="noopener noreferrer">Novo Nordisk</a>; <a href="https://ctipilot.ch/briefs/2026-06-13/" target="_blank" rel="noopener noreferrer">daily 06-13</a>). The company&#39;s statement does not itemise the data categories beyond &quot;personal data&quot;; pharma and life-sciences SOCs should nonetheless treat research-data and personal-data repositories as crown-jewel assets, given their value for both espionage and extortion.</p><div class="prov"><span>incident</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/novo-nordisk-theft-of-non-public-data-including-personal-dat/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.novonordisk.com/news-and-media/news-and-ir-materials/news-details.html?id=916571" target="_blank" rel="noopener noreferrer">Novo Nordisk disclosure</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/south-korea-fines-coupang-a-record-624-7-bn-over-an-unrevoke" data-tags="data-breach insider-threat" data-regions="apac" data-kind="incident" data-priority="notable" data-discovered="2026-06-14T23:57:33Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="south-korea-fines-coupang-a-record-624-7-bn-over-an-unrevoke"><a href="https://ctipilot.ch/entries/2026-06-14/south-korea-fines-coupang-a-record-624-7-bn-over-an-unrevoke/">South Korea fines Coupang a record ₩624.7 bn over an unrevoked signing key</a></h3><p>A regulatory follow-up worth a defender&#39;s attention because the root cause is mundane and universal. South Korea&#39;s Personal Information Protection Commission issued its largest-ever penalty against e-commerce platform Coupang, attributing a breach of tens of millions of customer records to a signing key that a former employee had stolen before departing and then used to harvest customer data undetected for months (<a href="https://therecord.media/south-korea-data-breach-record-fine-coupang" target="_blank" rel="noopener noreferrer">The Record</a>; <a href="https://ctipilot.ch/briefs/2026-06-13/" target="_blank" rel="noopener noreferrer">daily 06-13</a>). Key custody and anomaly detection on signing-key use are the controls that failed — and the months of undetected access is the part that turned an insider theft into a record fine.</p><div class="prov"><span>incident</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/south-korea-fines-coupang-a-record-624-7-bn-over-an-unrevoke/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://therecord.media/south-korea-data-breach-record-fine-coupang" target="_blank" rel="noopener noreferrer">The Record</a></div></article><div class="sect" id="annual-periodic-threat-reports"><span class="n">06</span><span class="t">Annual / periodic threat reports</span><span class="c">1 item</span></div><article class="finding entry-card" data-entry-id="2026-06-14/crowdstrike-2026-technology-threat-landscape-report-technolo" data-tags="supply-chain nation-state" data-regions="global" data-kind="annual-report" data-priority="notable" data-discovered="2026-06-14T23:57:34Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="crowdstrike-2026-technology-threat-landscape-report-technolo"><a href="https://ctipilot.ch/entries/2026-06-14/crowdstrike-2026-technology-threat-landscape-report-technolo/">CrowdStrike 2026 Technology Threat Landscape Report — &quot;technology = most-targeted&quot; reads as prophecy against this week&#39;s incidents</a></h3><p>CrowdStrike&#39;s report (published 9 June, distilled in the <a href="https://ctipilot.ch/briefs/2026-06-11/" target="_blank" rel="noopener noreferrer">06-11 daily</a>) found technology to be the most-targeted sector. Rather than re-recap it, the weekly&#39;s lens is corroboration: this very week supplied the evidence. The Shai-Hulud/Atomic Arch supply-chain wave (§ 2), the ShinyHunters PeopleSoft zero-day (§ 1), and the run of AI-developer-platform flaws (Langflow, LangGraph, LiteLLM in § 3) are all attacks <em>on</em> the technology supply chain and the developer toolchain rather than merely <em>through</em> it. For a public-sector SOC the implication is that the technology vendors and open-source components in your stack are themselves now the front line — SBOM-driven component inventory ( is the prerequisite for reasoning about it.</p><div class="prov"><span>annual-report</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/crowdstrike-2026-technology-threat-landscape-report-technolo/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-technology-threat-landscape-report/" target="_blank" rel="noopener noreferrer">CrowdStrike 2026 Technology Threat Landscape Report</a></div></article><div class="sect" id="long-running-campaigns-status-update"><span class="n">07</span><span class="t">Long-running campaigns · status update</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-06-14/apt28-gru-unit-26165-sekoia-documents-a-shift-to-llm-generat" data-tags="nation-state espionage russia-nexus ai-abuse" data-regions="europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-14T23:57:37Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="apt28-gru-unit-26165-sekoia-documents-a-shift-to-llm-generat"><a href="https://ctipilot.ch/entries/2026-06-14/apt28-gru-unit-26165-sekoia-documents-a-shift-to-llm-generat/">APT28 (GRU Unit 26165) — Sekoia documents a shift to LLM-generated payloads and cloud-native C2</a></h3><p><code>key: campaign:apt28-tradecraft-evolution-2026</code>. Sekoia&#39;s tradecraft-evolution retrospective (covered in the <a href="https://ctipilot.ch/briefs/2026-06-14/" target="_blank" rel="noopener noreferrer">06-14 daily</a>) is worth tracking as a forward indicator rather than a single incident: the 2025–2026 tooling shows LLM-generated payloads (the LameHug stealer), cloud-native command-and-control (BeardShell), and router DNS-hijack persistence (FrostArmada) (<a href="https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/" target="_blank" rel="noopener noreferrer">Sekoia</a>). The status-update value is the direction of travel: a top-tier Russian state operator is now industrialising LLM-assisted payload generation, which raises the baseline volume and variability of what defenders will see. Single-source (Sekoia TDR) and reported as the actor&#39;s TTPs, not new incidents — track it as a capability trend, not an active breach.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/apt28-gru-unit-26165-sekoia-documents-a-shift-to-llm-generat/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/" target="_blank" rel="noopener noreferrer">Sekoia</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/velvet-ant-operation-highland-sygnia-documents-decade-long-l" data-tags="nation-state espionage china-nexus identity" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-14T23:57:36Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="velvet-ant-operation-highland-sygnia-documents-decade-long-l"><a href="https://ctipilot.ch/entries/2026-06-14/velvet-ant-operation-highland-sygnia-documents-decade-long-l/">Velvet Ant &quot;Operation Highland&quot; — Sygnia documents decade-long Linux PAM/sshd subversion</a></h3><p><code>key: campaign:velvet-ant-operation-highland-2026</code>. Sygnia&#39;s &quot;Operation Highland&quot; report, relayed in detail by The Hacker News on 12 June and deep-dived in the <a href="https://ctipilot.ch/briefs/2026-06-13/" target="_blank" rel="noopener noreferrer">06-13 daily</a>, documents a China-nexus intrusion set that held covert access to an air-gapped network for nearly a decade (earliest traces ~2016) by subverting the Linux authentication stack: nine distinct backdoored <code>pam_unix.so</code> variants and credential-logging <code>sshd</code>/<code>ssh</code> binaries that suppress their own logging during operator sessions (<a href="https://thehackernews.com/2026/06/china-linked-hackers-backdoored-linux.html" target="_blank" rel="noopener noreferrer">The Hacker News</a>; <a href="https://www.sygnia.co/blog/operation-highland-velvet-ant/" target="_blank" rel="noopener noreferrer">Sygnia — Operation Highland</a>). The horizon framing the dailies could not give: this is the same tradecraft class as VerdantBamboo&#39;s edge-appliance persistence — long-dwell, identity/auth-layer implants on systems outside EDR coverage. The two together describe a sustained China-nexus investment in living below the endpoint-detection line. Defender watch-item: integrity-monitor PAM modules and <code>sshd</code>/<code>ssh</code> binaries against package checksums (<code>rpm -V</code> / <code>dpkg --verify</code>, AIDE/Tripwire), and treat air-gap as a latency control, not an isolation guarantee.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/velvet-ant-operation-highland-sygnia-documents-decade-long-l/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/06/china-linked-hackers-backdoored-linux.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://www.sygnia.co/blog/operation-highland-velvet-ant/" target="_blank" rel="noopener noreferrer">Sygnia — Operation Highland</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/verdantbamboo-unc5221-warp-panda-bsd-compiled-brickstorm-con" data-tags="nation-state espionage china-nexus" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-14T23:57:35Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="verdantbamboo-unc5221-warp-panda-bsd-compiled-brickstorm-con"><a href="https://ctipilot.ch/entries/2026-06-14/verdantbamboo-unc5221-warp-panda-bsd-compiled-brickstorm-con/">VerdantBamboo (UNC5221 / WARP PANDA) — BSD-compiled BRICKSTORM confirmed on pfSense, plus a new PLENET backdoor</a></h3><p><code>key: actor:VerdantBamboo</code>. The W23 weekly first carried Volexity&#39;s IR disclosure of this China-nexus operator; follow-up reporting this week fills in the technical chain. Volexity&#39;s case describes a BSD-compiled variant of the BRICKSTORM Golang backdoor on an MSP customer&#39;s pfSense firewall, reached after compromising an Egnyte Storage Sync appliance (local privilege escalation via default <code>egnyteservice</code> sudo permissions, fixed in Storage Sync v13.13), plus a previously-undocumented .NET Native AOT backdoor named <strong>PLENET</strong> on a Synology NAS and an AGENTPSD dropper (<a href="https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/" target="_blank" rel="noopener noreferrer">Volexity</a>; <a href="https://thehackernews.com/2026/06/verdantbamboo-deploys-bsd-variant-of.html" target="_blank" rel="noopener noreferrer">The Hacker News</a>). The BSD variant is the status-changing detail: it confirms VerdantBamboo can operate on FreeBSD-based appliances, beyond the Linux-only model where enterprise EDR is already blind. The intrusion ran ~18 months undetected and was used to proxy through the MSP into customer Microsoft 365 tenants via Conditional Access bypass. Outstanding question for defenders: edge appliances (firewalls, NAS, sync gateways) remain the EDR dead zone — the hunt has to move to network-flow anomalies and appliance-integrity baselining, not endpoint telemetry.</p><div class="prov"><span>synthesis</span><span>14 Jun 23:57Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/verdantbamboo-unc5221-warp-panda-bsd-compiled-brickstorm-con/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/" target="_blank" rel="noopener noreferrer">Volexity</a> · <a href="https://thehackernews.com/2026/06/verdantbamboo-deploys-bsd-variant-of.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article><div class="sect" id="policy-regulatory-horizon"><span class="n">08</span><span class="t">Policy &amp; regulatory horizon</span><span class="c">5 items</span></div><article class="finding entry-card" data-entry-id="2026-06-14/european-commission-refers-france-and-spain-to-the-cjeu-over" data-tags="law-enforcement eu-nexus" data-regions="europe" data-kind="policy" data-priority="high" data-discovered="2026-06-14T23:57:38Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="european-commission-refers-france-and-spain-to-the-cjeu-over"><a href="https://ctipilot.ch/entries/2026-06-14/european-commission-refers-france-and-spain-to-the-cjeu-over/">European Commission refers France and Spain to the CJEU over NIS2 non-transposition</a></h3><p>The week&#39;s most consequential regulatory move. The Commission referred France and Spain to the Court of Justice of the EU on ~9 June — the third and final stage of the infringement procedure — for failing to transpose NIS2 (Directive 2022/2555) more than 19 months past the October 2024 deadline (<a href="https://brusselssignal.eu/2026/06/eu-takes-france-and-spain-to-court-over-cybersecurity-law-delay/" target="_blank" rel="noopener noreferrer">Brussels Signal</a>). The CJEU can impose lump-sum fines and daily penalties until transposition completes. <strong>What defenders need to do differently:</strong> entities in non-transposed states operate in a legal grey zone — NIS2&#39;s substantive Article 21 security measures and Article 23 reporting windows apply as the floor even where the national implementing law and its competent authority do not yet exist. Swiss federal agencies and cantonal governments with regulated counterparts or outsourced providers in France or Spain should treat NIS2 Article 21 as the baseline regardless of national enforcement status, and watch the remaining non-transposers for the same escalation.</p><div class="prov"><span>policy</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/european-commission-refers-france-and-spain-to-the-cjeu-over/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://brusselssignal.eu/2026/06/eu-takes-france-and-spain-to-court-over-cybersecurity-law-delay/" target="_blank" rel="noopener noreferrer">Brussels Signal</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/edpb-adopts-a-harmonised-gdpr-article-33-breach-notification" data-tags="data-breach eu-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-06-14T23:57:41Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="edpb-adopts-a-harmonised-gdpr-article-33-breach-notification"><a href="https://ctipilot.ch/entries/2026-06-14/edpb-adopts-a-harmonised-gdpr-article-33-breach-notification/">EDPB adopts a harmonised GDPR Article 33 breach-notification template</a></h3><p>The European Data Protection Board adopted a common EU/EEA personal-data-breach notification template under GDPR Article 33 at its 10 June plenary, opening it for public consultation until 5 August (<a href="https://www.edpb.europa.eu/news/news/2026/edpb-meets-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification_en" target="_blank" rel="noopener noreferrer">EDPB</a>; <a href="https://ctipilot.ch/briefs/2026-06-11/" target="_blank" rel="noopener noreferrer">daily 06-11</a>). <strong>What to do differently:</strong> breach-response runbooks that currently target per-DPA notification formats should be reviewed against the harmonised template during the consultation window — a single common format reduces the cross-border friction that has historically slowed multi-jurisdiction breach reporting, but only if your incident-response process pre-maps its fields.</p><div class="prov"><span>policy</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/edpb-adopts-a-harmonised-gdpr-article-33-breach-notification/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.edpb.europa.eu/news/news/2026/edpb-meets-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification_en" target="_blank" rel="noopener noreferrer">EDPB</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/enisa-publishes-the-first-eu-wide-sbom-adoption-state-of-pla" data-tags="supply-chain eu-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-06-14T23:57:40Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="enisa-publishes-the-first-eu-wide-sbom-adoption-state-of-pla"><a href="https://ctipilot.ch/entries/2026-06-14/enisa-publishes-the-first-eu-wide-sbom-adoption-state-of-pla/">ENISA publishes the first EU-wide SBOM Adoption State of Play — consumption lags generation</a></h3><p>ENISA released its end-2025 SBOM adoption survey on 9 June — the first EU-wide empirical baseline (<a href="https://www.enisa.europa.eu/publications/sbom-adoption-state-of-play-2026" target="_blank" rel="noopener noreferrer">ENISA</a>). The report confirms the CRA is the primary accelerant of SBOM adoption and that organisations are investing in SBOM <em>generation</em> and SDLC/CI-CD integration. The practical gap this creates — generation capability advancing faster than operational <em>consumption</em> (ingesting a vendor&#39;s SBOM into your own vulnerability-management workflow) — is the operational challenge it implies for Swiss/EU procurers; that framing is this brief&#39;s inference, not a stated headline of the report. It lands 94 days before the CRA&#39;s 11 September reporting-platform milestone. <strong>What to do differently:</strong> for public-sector procurement, demand SBOM deliverables in tenders now and verify your own consuming capability — generating SBOMs satisfies a producer obligation, but the defensive value (correlating known-bad components against CVE feeds) only materialises if you can ingest supplier SBOMs before the reporting obligation begins. This connects directly to § 6&#39;s &quot;technology is the front line&quot; synthesis.</p><div class="prov"><span>policy</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/enisa-publishes-the-first-eu-wide-sbom-adoption-state-of-pla/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.enisa.europa.eu/publications/sbom-adoption-state-of-play-2026" target="_blank" rel="noopener noreferrer">ENISA — SBOM Adoption State of Play 2026</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/germany-s-bundestag-opens-first-reading-of-the-cra-domestic" data-tags="eu-nexus" data-regions="dach europe" data-kind="policy" data-priority="notable" data-discovered="2026-06-14T23:57:39Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="germany-s-bundestag-opens-first-reading-of-the-cra-domestic"><a href="https://ctipilot.ch/entries/2026-06-14/germany-s-bundestag-opens-first-reading-of-the-cra-domestic/">Germany&#39;s Bundestag opens first reading of the CRA domestic-implementation bill</a></h3><p><code>Drucksache 21/6134</code> — &quot;zur Durchführung der Verordnung (EU) 2024/2847&quot; — had its first reading on 11 June, designating Germany&#39;s national CRA authorities, notified bodies and enforcement routes, with BSI the anticipated primary market-surveillance authority (<a href="https://www.bundestag.de/dokumente/textarchiv/2026/kw24-de-cyberresilienz-1181930" target="_blank" rel="noopener noreferrer">Deutscher Bundestag</a>). This is distinct from the general CRA notifying-authority deadline the W23 weekly tracked: it is the German <em>legislative</em> step starting the parliamentary clock (committee stage next, second/third readings and Bundesrat consent expected Q4 2026). The CRA&#39;s Chapter IV (notified bodies) entered force EU-wide the same day. <strong>What to do differently:</strong> Swiss ICT vendors exporting digital products to the German public sector, and German public-sector procurers, should track committee amendments now — the national authority designation determines who you report to and who surveils your products under the CRA.</p><div class="prov"><span>policy</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/germany-s-bundestag-opens-first-reading-of-the-cra-domestic/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bundestag.de/dokumente/textarchiv/2026/kw24-de-cyberresilienz-1181930" target="_blank" rel="noopener noreferrer">Deutscher Bundestag</a></div></article><article class="finding entry-card" data-entry-id="2026-06-14/cisa-replaces-the-flat-kev-14-day-rule-with-risk-tiered-reme" data-tags="vulnerabilities us-nexus" data-regions="us" data-kind="policy" data-priority="notable" data-discovered="2026-06-14T23:57:42Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="cisa-replaces-the-flat-kev-14-day-rule-with-risk-tiered-reme"><a href="https://ctipilot.ch/entries/2026-06-14/cisa-replaces-the-flat-kev-14-day-rule-with-risk-tiered-reme/">CISA replaces the flat KEV 14-day rule with risk-tiered remediation (BOD 26-04)</a></h3><p>CISA issued Binding Operational Directive 26-04 on 10 June, superseding BOD 19-02 and BOD 22-01 and replacing the flat 14-day KEV remediation rule with risk-tiered deadlines, including a 3-day class for the worst exposures (<a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" target="_blank" rel="noopener noreferrer">CISA</a>; <a href="https://ctipilot.ch/briefs/2026-06-12/" target="_blank" rel="noopener noreferrer">daily 06-12</a>). The deadlines bind only US Federal Civilian Executive Branch agencies and carry no compliance weight in CH/EU. <strong>What to do differently — and what not to:</strong> the useful signal for a Swiss/EU SOC is the <em>risk-tiering model</em> (exploitation status and exposure driving remediation urgency), not the deadlines themselves; the KEV listing flag remains jurisdiction-agnostic confirmation of in-the-wild exploitation, but a KEV deadline is never the reason an item is urgent for this audience.</p><div class="prov"><span>policy</span><span>14 Jun 23:57Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/cisa-replaces-the-flat-kev-14-day-rule-with-risk-tiered-reme/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk" target="_blank" rel="noopener noreferrer">CISA BOD 26-04</a></div></article><div class="sect" id="looking-ahead-what-to-watch-next-week"><span class="n">09</span><span class="t">Looking ahead · what to watch next week</span><span class="c">1 item</span></div><article class="finding entry-card" data-entry-id="2026-06-14/looking-ahead-2026-w24" data-tags="ddos" data-regions="global" data-kind="outlook" data-priority="notable" data-discovered="2026-06-14T23:57:43Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="looking-ahead-2026-w24"><a href="https://ctipilot.ch/entries/2026-06-14/looking-ahead-2026-w24/">Looking ahead — 2026-W24</a></h3><p>A focused, justified list — items already in motion, not predictions.</p>
<ul><li><strong>G7 Évian summit, 15–17 June — pre-stage DDoS mitigations now.</strong> NCSC-CH&#39;s advisory explicitly names Swiss organisations as the hacktivist-DDoS target pool for the summit window (Évian sits on the Swiss border), consistent with the NoName057(16) pattern around past Swiss-adjacent summits. Confirm upstream scrubbing burst capacity, test CDN/anycast failover, and pre-position out-of-band NOC comms before Monday. MITRE ATT&amp;CK T1498/T1499. (<a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/massnahmen-grossanlaesse-konferenzen-g7.html" target="_blank" rel="noopener noreferrer">NCSC-CH G7 advisory</a>)</li><li><strong>GreatXML and RoguePlanet remain unpatched — watch MSRC for an out-of-band response.</strong> Two Chaotic Eclipse disclosures (GreatXML BitLocker bypass, RoguePlanet Defender SYSTEM EoP) have public PoCs and no fix after June Patch Tuesday closed three siblings; the researcher&#39;s cadence suggests more. Retain BitLocker PIN/TPM policy and monitor MSRC. (<a href="https://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/" target="_blank" rel="noopener noreferrer">SecurityWeek — GreatXML</a>; <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/" target="_blank" rel="noopener noreferrer">BleepingComputer — RoguePlanet</a>; <a href="https://ctipilot.ch/briefs/2026-06-12/" target="_blank" rel="noopener noreferrer">daily 06-12</a>)</li><li><strong>CRA 11 September reporting-platform milestone is now ~90 days out.</strong> ENISA&#39;s SBOM survey shows generation outpacing consumption; the window to build SBOM-ingestion into your vulnerability-management workflow before the reporting obligation begins is closing. (<a href="https://www.enisa.europa.eu/publications/sbom-adoption-state-of-play-2026" target="_blank" rel="noopener noreferrer">ENISA SBOM</a>)</li><li><strong>npm v12 will disable install scripts by default — audit CI/CD before July.</strong> GitHub&#39;s announced breaking change (<code>preinstall</code>/<code>install</code>/<code>postinstall</code> off by default, <code>npm approve-builds</code> required) is the single most effective structural mitigation against the Shai-Hulud/Atomic Arch install-time-execution kill chain, but it will break pipelines that rely on build scripts. Inventory affected pipelines now. (<a href="https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/" target="_blank" rel="noopener noreferrer">GitHub changelog</a>; <a href="https://ctipilot.ch/briefs/2026-06-12/" target="_blank" rel="noopener noreferrer">daily 06-12</a>)</li><li><strong>Acer Wave-7 mesh-router maximum-severity zero-days (CVE-2026-49200/-49201) still await a fix targeted for end-June.</strong> Cleartext-credential logging plus a hardcoded backup key, CVSS 10.0, no patch yet — track the firmware release and treat exposed Wave-7 management as compromised in the interim. (<a href="https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/" target="_blank" rel="noopener noreferrer">BleepingComputer</a>; <a href="https://ctipilot.ch/briefs/2026-06-08/" target="_blank" rel="noopener noreferrer">daily 06-08</a>)</li><li><strong>EDPB Article 33 harmonised-template consultation closes 5 August.</strong> Breach-response process owners with multi-jurisdiction obligations have a window to review and comment. (<a href="https://www.edpb.europa.eu/news/news/2026/edpb-meets-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification_en" target="_blank" rel="noopener noreferrer">EDPB</a>)</li></ul><div class="prov"><span>outlook</span><span>14 Jun 23:57Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-14/looking-ahead-2026-w24/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/massnahmen-grossanlaesse-konferenzen-g7.html" target="_blank" rel="noopener noreferrer">NCSC-CH G7 advisory</a> · <a href="https://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/" target="_blank" rel="noopener noreferrer">SecurityWeek — GreatXML</a> · <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/" target="_blank" rel="noopener noreferrer">BleepingComputer — RoguePlanet</a> · <a href="https://www.enisa.europa.eu/publications/sbom-adoption-state-of-play-2026" target="_blank" rel="noopener noreferrer">ENISA SBOM</a> · <a href="https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/" target="_blank" rel="noopener noreferrer">GitHub changelog</a> · <a href="https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.edpb.europa.eu/news/news/2026/edpb-meets-eu-commissioner-mcgrath-and-adopts-common-data-breach-notification_en" target="_blank" rel="noopener noreferrer">EDPB</a></div></article><details class="verif"><summary class="vh">About this weekly<span class="verif-count">1 run</span><svg class="verif-chev" viewBox="0 0 24 24" width="12" height="12" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" aria-hidden="true"><path d="M6 9l6 6 6-6"></path></svg></summary><div class="verif-body"><div class="run-note" data-run-id="2026-W24-bd5a7519"><h3 class="run-note__head"><span class="mono">2026-W24-bd5a7519</span> <span class="muted">· weekly · Claude Opus 4.8 · 28 entries published</span></h3><div class="run-note__body"><ul><li><strong>Items flagged <code>[SINGLE-SOURCE]</code> this week:</strong> CrowdStrike 2026 Technology Threat Landscape Report (§ 6; vendor telemetry, directionally valid, no independent corroboration); APT28 tradecraft evolution (§ 7; Sekoia TDR sole source — reported as the actor&#39;s TTPs, attributed to the reporting, not asserted as new incidents); Check Point IKEv1 CVE-2026-50751 (§ 1; vendor PSIRT advisory is the canonical primary for the vendor&#39;s own product); Splunk CVE-2026-20253 (§ 3; Splunk advisory); SAP NetWeaver CVE-2026-44748 (§ 3; Onapsis analysis of SAP&#39;s HotNews note); WinRAR CVE-2025-8088 (§ 3; Trend Micro research). The § 8 Germany CRA bill (Bundestag), ENISA SBOM report, and EDPB Article 33 template are single-source from the disclosing government/EU body itself (carve-out applies). The § 2 Chaotic Eclipse Patch-Tuesday round-up is sourced to news aggregators (BleepingComputer, SecurityWeek) because patch-day reporting is inherently aggregator-led — reduced confidence on exact CVE-to-codename mapping, though the patched/unpatched split is corroborated across both. National-CERT / national-authority single sources covered by the verification carve-out: Germany CRA implementation bill (§ 8; Deutscher Bundestag primary), ENISA SBOM Adoption State of Play (§ 8; ENISA primary), NCSC-CH G7 Évian advisory (§ 8/§ 9; NCSC-CH primary), MariaDB CVE-2026-49261 (§ 3; NCSC-CH Security Hub primary, corroborated by MariaDB documentation). VerdantBamboo (§ 7) is now multi-source (Volexity primary + The Hacker News corroboration) and Velvet Ant (§ 7) leads with a verified-live The Hacker News relay because the Sygnia &quot;Operation Highland&quot; page returns automated-UA blocks (Imunify360/Cloudflare) — the page is likely reachable from a human browser.</li><li><strong>Items dropped from this week&#39;s roll-up:</strong> 2026-06-07 overlap-day items belonging to the W23 window (Chrome 149 / CVE-2026-10881, FFmpeg AI-found zero-days / CVE-2026-39210, polyfill[.]io reactivation, Stripe-API Magecart, WeTransfer steganographic loader) — covered in the W23 cycle, no new in-window development; FIFA World Cup 2026 / Ghost Stadium PhaaS (tournament kicked off 11 June, no new primary research and no confirmed infrastructure attack in-window); TA4922 and Gamaredon (no new in-window development beyond W23 coverage — W1); OceanLotus/APT32 FireAnt supply-chain, JDY botnet, The Gentlemen ransomware (fully resolved in dailies, no weekly-qualifying delta); single-day research items not meeting W-PD-1 (Teams external-chat phishing, AI-brand-impersonation malware delivery, cloud-logging defense-evasion, Entra Agent ID OBO abuse, Imperva/Varonis OpenClaw prompt-injection, Agentjacking, Google v. &quot;Outsider&quot; PhaaS) — these were operationally useful in the dailies but are not cross-day patterns or horizon shifts.</li><li><strong>Contradictions:</strong> none unresolved this run.</li><li><strong>Reduced-confidence items:</strong> Atomic Arch AUR compromised-package count (§ 2) — reporting ranges from 900 (PrivacyGuides) to ~1,500 (end-of-day 12 June); W1 assessed this MEDIUM confidence. The delivery-mechanism change (<code>bun install js-digest</code>) is the verified detail; the exact count is approximate.</li><li><strong>Sub-agents:</strong> both W1 (long-horizon) and W2 (policy) returned within budget. W1 reported its <code>findings.W1.yaml</code> ended-timestamp consistent with its return; W2&#39;s <code>findings.W2.yaml</code> carries an internal ended-timestamp that disagrees with its return-line timestamp — the authoritative <code>**Timestamps:**</code> return line (started 23:10:31Z, ended 23:20:13Z) was used for the run log.</li><li><strong>Verification:</strong> 2 iterations (iter 1 Claude Opus 4.8 → NEEDS_FIXES, truth=4 all remediated: Splunk RCE-overstatement, stale NIS2 corroborating link, Novo Nordisk data-category over-itemisation, Atomic Arch count/Shai-Hulud attribution; iter 2 Claude Sonnet 4.6 → NEEDS_FIXES, truth=2 both remediated: ENISA SBOM consumption-gap reframed as the brief&#39;s inference rather than the report&#39;s stated finding, Coupang root cause corrected to key <em>theft</em> by a former employee). <strong>Residuals:</strong> 2 — published via the low-defect early-exit path (iteration-2 truth+editorial ≤ 2 with no broken-URL/hallucination findings; both residual findings were nonetheless remediated before publish rather than carried).</li><li><strong>Coverage gaps:</strong> databreaches-net (persistent HTTP 403, rotation-priority); sophos-xops (HTTP 503, persistent); inside-it-ch (Cloudflare 403, persistent); finma (no in-window guidance — quiet); ofcom-bakom (no in-window cyber publication — quiet); us-treasury-ofac (no in-window cyber sanctions action — quiet); cnil-fr (no in-window enforcement — quiet); ico-uk (no new in-window action — quiet).</li></ul>
<p>— <em>Source: run state · Tags: verification-notes · Region: global</em></p>
<p><em>Migrated from briefs/weekly/2026-W24.md (v2).</em></p></div></div></div></details>]]></content:encoded></item><item><title>CTI Weekly Summary · 2026-W23</title><link>https://ctipilot.ch/weekly/2026-W23/</link><guid isPermaLink="true">https://ctipilot.ch/weekly/2026-W23/</guid><pubDate>Mon, 01 Jun 2026 05:00:25 +0000</pubDate><dc:date>2026-06-01T05:00:25Z</dc:date><category>CVE-2026-10868</category><category>CVE-2026-20127</category><category>CVE-2026-20182</category><category>CVE-2026-20245</category><category>CVE-2026-41089</category><category>CVE-2026-4874</category><category>CVE-2026-49975</category><category>CVE-2026-9704</category><description><![CDATA[<ul><li><strong>VerdantBamboo / UNC5221 / WARP PANDA — 18-month undetected China-nexus intrusion through MSP pfSense.</strong> VerdantBamboo (UNC5221 / WARP PANDA): 18-month undetected China-nexus espionage through an MSP&#39;s pfSense, living on EDR-blind edge appliances and proxying into M365 past Conditional Access. (daily, Volexity) <a href="https://ctipilot.ch/entries/2026-06-01/verdantbamboo-unc5221-warp-panda-18-month-undetected-china-n/">→</a></li><li><strong>ENISA NIS360 2026 (3rd edition) — seven sectors in the persistent risk zone where criticality outpaces maturity.</strong> NCSC-CH pre-event advisory: hacktivist DDoS against Swiss and event-linked infrastructure expected 15–17 June (G7 Évian). NoName057(16) Bürgenstock 2024 pattern; public-sector digital services at direct elevated risk — pre-stage mitigations now. (daily, NCSC-CH) <a href="https://ctipilot.ch/entries/2026-06-01/enisa-nis360-2026-3rd-edition-seven-sectors-in-the-persisten/">→</a></li><li><strong>Public sector — most-targeted sector this week by volume and by operational severity.</strong> ENISA NIS360 2026: public administration receives nearly 63% of all EU hacktivist attacks yet remains structurally under-mature relative to its criticality. Seven sectors in the persistent &quot;risk zone&quot; where criticality exceeds maturity. (ENISA) <a href="https://ctipilot.ch/entries/2026-06-01/public-sector-most-targeted-sector-this-week-by-volume-and-b/">→</a></li><li><strong>CVE-2026-41089 — Windows Netlogon: pre-auth SYSTEM RCE on domain controllers, actively exploited.</strong> On fire — Windows Netlogon CVE-2026-41089 (CVSS 9.8): pre-auth SYSTEM RCE on domain controllers, Belgium CCB confirms active exploitation. May Patch Tuesday fix has been available since 13 May; unpatched DCs are an active incident waiting to happen. (daily, Microsoft MSRC) <a href="https://ctipilot.ch/entries/2026-06-01/cve-2026-41089-windows-netlogon-pre-auth-system-rce-on-domai/">→</a></li><li><strong>Technology / software supply chain — four concurrent worm/supply-chain threats in one week.</strong> IronWorm: first eBPF-rootkit npm worm sweeps cloud/AI credentials from ~36 packages via Tor C2. Kernel-mode rootkit hides the implant from procfs and most EDR agents — user-space process hunting is insufficient. (daily, JFrog) <a href="https://ctipilot.ch/entries/2026-06-01/technology-software-supply-chain-four-concurrent-worm-supply/">→</a></li><li><strong>IronWorm + Miasma AI coding-agent injection: two supply-chain worms target cloud credentials and developer toolchains simultaneously.</strong> Miasma worm pivots to AI coding-agent config injection — 73 Microsoft GitHub repositories disabled in 105 seconds. Malicious commits wire execution to Claude Code / Cursor / Gemini CLI / VS Code workspace-config files, detonating on repo open rather than npm install; azure-functions-action CI/CD globally disrupted. (daily, StepSecurity) <a href="https://ctipilot.ch/entries/2026-06-01/ironworm-miasma-ai-coding-agent-injection-two-supply-chain-w/">→</a></li><li><strong>CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: no-patch zero-day chain confirmed to push malicious configs to edge devices.</strong> On fire — Cisco Catalyst SD-WAN CVE-2026-20245: no patch, actively exploited, edge-device config-push confirmed. The three-CVE chain (CVE-2026-20182 → CVE-2026-20127 → CVE-2026-20245) yields unauthenticated access, netadmin escalation, and root OS execution with downstream edge-device control; NCSC-CH updated its advisory on 5 June adding the forwarding-plane impact. (daily, NCSC-CH 12579) <a href="https://ctipilot.ch/entries/2026-06-01/cve-2026-20245-cisco-catalyst-sd-wan-manager-no-patch-zero-d/">→</a></li></ul>]]></description><content:encoded><![CDATA[<div class="tldr"><span class="eyebrow eyebrow--muted">Week at a glance</span><ol><li><span class="num">01</span><span><b>VerdantBamboo / UNC5221 / WARP PANDA — 18-month undetected China-nexus intrusion through MSP pfSense.</b> VerdantBamboo (UNC5221 / WARP PANDA): 18-month undetected China-nexus espionage through an MSP&#39;s pfSense, living on EDR-blind edge appliances and proxying into M365 past Conditional Access. (daily, Volexity) <a href="https://ctipilot.ch/entries/2026-06-01/verdantbamboo-unc5221-warp-panda-18-month-undetected-china-n/">→</a></span></li><li><span class="num">02</span><span><b>ENISA NIS360 2026 (3rd edition) — seven sectors in the persistent risk zone where criticality outpaces maturity.</b> NCSC-CH pre-event advisory: hacktivist DDoS against Swiss and event-linked infrastructure expected 15–17 June (G7 Évian). NoName057(16) Bürgenstock 2024 pattern; public-sector digital services at direct elevated risk — pre-stage mitigations now. (daily, NCSC-CH) <a href="https://ctipilot.ch/entries/2026-06-01/enisa-nis360-2026-3rd-edition-seven-sectors-in-the-persisten/">→</a></span></li><li><span class="num">03</span><span><b>Public sector — most-targeted sector this week by volume and by operational severity.</b> ENISA NIS360 2026: public administration receives nearly 63% of all EU hacktivist attacks yet remains structurally under-mature relative to its criticality. Seven sectors in the persistent &quot;risk zone&quot; where criticality exceeds maturity. (ENISA) <a href="https://ctipilot.ch/entries/2026-06-01/public-sector-most-targeted-sector-this-week-by-volume-and-b/">→</a></span></li><li><span class="num">04</span><span><b>CVE-2026-41089 — Windows Netlogon: pre-auth SYSTEM RCE on domain controllers, actively exploited.</b> On fire — Windows Netlogon CVE-2026-41089 (CVSS 9.8): pre-auth SYSTEM RCE on domain controllers, Belgium CCB confirms active exploitation. May Patch Tuesday fix has been available since 13 May; unpatched DCs are an active incident waiting to happen. (daily, Microsoft MSRC) <a href="https://ctipilot.ch/entries/2026-06-01/cve-2026-41089-windows-netlogon-pre-auth-system-rce-on-domai/">→</a></span></li><li><span class="num">05</span><span><b>Technology / software supply chain — four concurrent worm/supply-chain threats in one week.</b> IronWorm: first eBPF-rootkit npm worm sweeps cloud/AI credentials from ~36 packages via Tor C2. Kernel-mode rootkit hides the implant from procfs and most EDR agents — user-space process hunting is insufficient. (daily, JFrog) <a href="https://ctipilot.ch/entries/2026-06-01/technology-software-supply-chain-four-concurrent-worm-supply/">→</a></span></li><li><span class="num">06</span><span><b>IronWorm + Miasma AI coding-agent injection: two supply-chain worms target cloud credentials and developer toolchains simultaneously.</b> Miasma worm pivots to AI coding-agent config injection — 73 Microsoft GitHub repositories disabled in 105 seconds. Malicious commits wire execution to Claude Code / Cursor / Gemini CLI / VS Code workspace-config files, detonating on repo open rather than npm install; azure-functions-action CI/CD globally disrupted. (daily, StepSecurity) <a href="https://ctipilot.ch/entries/2026-06-01/ironworm-miasma-ai-coding-agent-injection-two-supply-chain-w/">→</a></span></li><li><span class="num">07</span><span><b>CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: no-patch zero-day chain confirmed to push malicious configs to edge devices.</b> On fire — Cisco Catalyst SD-WAN CVE-2026-20245: no patch, actively exploited, edge-device config-push confirmed. The three-CVE chain (CVE-2026-20182 → CVE-2026-20127 → CVE-2026-20245) yields unauthenticated access, netadmin escalation, and root OS execution with downstream edge-device control; NCSC-CH updated its advisory on 5 June adding the forwarding-plane impact. (daily, NCSC-CH 12579) <a href="https://ctipilot.ch/entries/2026-06-01/cve-2026-20245-cisco-catalyst-sd-wan-manager-no-patch-zero-d/">→</a></span></li></ol></div><nav class="secnav" aria-label="Sections"><a class="secnav-chip" href="#highest-impact-events-what-s-on-fire-if-no-one-acted">Highest-impact events · what&#39;s on fire if no one acted <span class="secnav-n">3</span></a><a class="secnav-chip" href="#multi-day-campaigns-and-chains">Multi-day campaigns and chains <span class="secnav-n">1</span></a><a class="secnav-chip" href="#vulnerability-roll-up">Vulnerability roll-up <span class="secnav-n">3</span></a><a class="secnav-chip" href="#sector-victim-patterns">Sector &amp; victim patterns <span class="secnav-n">4</span></a><a class="secnav-chip" href="#incidents-disclosures-recap">Incidents &amp; disclosures recap <span class="secnav-n">3</span></a><a class="secnav-chip" href="#annual-periodic-threat-reports">Annual / periodic threat reports <span class="secnav-n">2</span></a><a class="secnav-chip" href="#long-running-campaigns-status-update">Long-running campaigns · status update <span class="secnav-n">3</span></a><a class="secnav-chip" href="#policy-regulatory-horizon">Policy &amp; regulatory horizon <span class="secnav-n">4</span></a><a class="secnav-chip" href="#looking-ahead-what-to-watch-next-week">Looking ahead · what to watch next week <span class="secnav-n">1</span></a></nav><div class="sect" id="highest-impact-events-what-s-on-fire-if-no-one-acted"><span class="n">01</span><span class="t">Highest-impact events · what&#39;s on fire if no one acted</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-06-01/cve-2026-41089-windows-netlogon-pre-auth-system-rce-on-domai" data-tags="vulnerabilities actively-exploited pre-auth rce patch-available" data-regions="global europe" data-kind="synthesis" data-priority="high" data-discovered="2026-06-01T05:00:01Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-41089/">CVE-2026-41089</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-41089-windows-netlogon-pre-auth-system-rce-on-domai"><a href="https://ctipilot.ch/entries/2026-06-01/cve-2026-41089-windows-netlogon-pre-auth-system-rce-on-domai/">CVE-2026-41089 — Windows Netlogon: pre-auth SYSTEM RCE on domain controllers, actively exploited</a></h3><p><strong>If you did nothing this week:</strong> pre-auth remote-code execution as SYSTEM on every unpatched domain controller in your forest. Belgium&#39;s CCB confirmed active exploitation on 1 June. The May Patch Tuesday fix has been available since 13 May.</p>
<p>CVE-2026-41089 (CVSS 9.8) is a stack-based buffer overflow in the Windows Netlogon service (MS-NRPC), first covered as an emergency action on 2 June (<a href="https://ctipilot.ch/briefs/2026-06-02/" target="_blank" rel="noopener noreferrer">daily 2026-06-02</a>). A crafted NRPC request to a domain controller triggers a memory-corruption condition before any credential exchange, allowing an unauthenticated network attacker to execute code as SYSTEM (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41089" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a>; <a href="https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-01</a>). All currently supported Windows Server releases including Server 2025 are affected. Belgium&#39;s Centre for Cybersecurity (CCB) confirmed active exploitation; at the time of the daily brief Microsoft had not yet updated its advisory to reflect it.</p>
<p>The operational priority here is the target class — domain controllers — and the fact that Netlogon is necessarily reachable from every domain-joined machine in the estate. An attacker who has compromised any domain-joined workstation can move laterally to a DC without credentials if the patch has not been applied. Detection concepts: anomalous NRPC session counts from non-DC source addresses; Windows Security EID 4625 (authentication failures) spikes on DCs correlated with unexpected source IPs; network-layer alerts on NRPC/RPC-over-named-pipe from workstation segments. <strong>Patch immediately.</strong> If patching is delayed, restrict Netlogon/LDAP exposure to trusted hosts at the network layer.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: pre-auth remote-code execution as SYSTEM on every unpatched domain controller in your forest.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/cve-2026-41089-windows-netlogon-pre-auth-system-rce-on-domai/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41089" target="_blank" rel="noopener noreferrer">Microsoft MSRC CVE-2026-41089</a> · <a href="https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.helpnetsecurity.com/2026/06/01/windows-netlogon-rce-exploited-cve-2026-41089/" target="_blank" rel="noopener noreferrer">Help Net Security</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/ironworm-miasma-ai-coding-agent-injection-two-supply-chain-w" data-tags="supply-chain infostealer cloud actively-exploited" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-06-01T05:00:02Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="ironworm-miasma-ai-coding-agent-injection-two-supply-chain-w"><a href="https://ctipilot.ch/entries/2026-06-01/ironworm-miasma-ai-coding-agent-injection-two-supply-chain-w/">IronWorm + Miasma AI coding-agent injection: two supply-chain worms target cloud credentials and developer toolchains simultaneously</a></h3><p><strong>If you did nothing this week:</strong> any developer who cloned one of the 73 disabled Microsoft GitHub repositories and opened it in Claude Code, Cursor, Gemini CLI, or VS Code with AI extensions may have triggered malicious payload execution. Any CI/CD pipeline consuming azure-functions-action in the exposure window may have run attacker-controlled code. Any developer machine running npm packages from the affected @redhat-cloud-services or IronWorm-infected namespaces should be treated as credential-compromised.</p>
<p><strong>IronWorm</strong> (disclosed by JFrog on 2026-06-03; <a href="https://ctipilot.ch/briefs/2026-06-06/" target="_blank" rel="noopener noreferrer">daily 2026-06-06</a>) is a self-propagating npm worm distributed across ~36 packages from a compromised publisher account (<a href="https://research.jfrog.com/post/iron-worm-shai-hulud-rustier-cousin/" target="_blank" rel="noopener noreferrer">JFrog, 2026-06-03</a>). Unlike the JavaScript-stager Shai-Hulud lineage, IronWorm executes a Rust ELF payload through a <code>preinstall</code> lifecycle hook (<code>T1195.002</code>), then deploys an eBPF object providing kernel-level process, socket and anti-debug concealment — hiding the implant from procfs-based enumeration and most EDR agents that rely on user-space telemetry. The command channel runs over Tor. The credential sweep targets AWS, GCP, Azure, HashiCorp Vault, Kubernetes, Docker, GitHub and npm tokens, plus the 2026 generation of AI-provider API keys (Anthropic, OpenAI, Gemini). Self-propagation reuses stolen npm Trusted Publishing credentials. Detection: alert on <code>node</code>/<code>npm</code>/<code>npx</code> spawning <code>sh</code>/<code>bash</code> during <code>preinstall</code>/<code>postinstall</code>; audit <code>bpf()</code> syscalls from non-privileged processes via <code>auditd</code>; watch CI/CD egress for Tor bootstrap traffic. Hardening: run <code>npm install --ignore-scripts</code> in CI, pin lockfile integrity, scope/rotate npm publish tokens.</p>
<p><strong>Miasma&#39;s AI coding-agent injection</strong> (2026-06-05–06; <a href="https://ctipilot.ch/briefs/2026-06-06/" target="_blank" rel="noopener noreferrer">daily 2026-06-06</a>) planted a ~4.6 MB payload runner (4,643,745 bytes) in 73 Microsoft and Microsoft-adjacent GitHub repositories, wiring execution to workspace-config files — CLAUDE.md, <code>.claude/commands/</code>, <code>.gemini/</code>, <code>.cursor/rules</code>, <code>.vscode/settings.json</code> — so the trigger is a developer <strong>opening the repository in an AI-assisted IDE</strong>, not an <code>npm install</code> (<a href="https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents" target="_blank" rel="noopener noreferrer">StepSecurity</a>; <a href="https://thehackernews.com/2026/06/miasma-worm-hits-73-microsoft-github.html" target="_blank" rel="noopener noreferrer">The Hacker News</a>). GitHub disabled the affected repositories by June 6. StepSecurity forensics trace the entry-point account to the same contributor credentials compromised in the May 19 PyPI attack; full revocation was not confirmed (three hypotheses; non-revocation is the most parsimonious). Detection: treat workspace-config files from cloned repositories as untrusted data, not code, in CI/CD environments; monitor <code>.claude/commands/</code>, <code>.gemini/</code>, <code>.cursor/rules</code> for unexpected writes or outbound HTTP triggers; audit azure-functions-action workflows for execution in the exposure window.</p><div class="prov"><span>synthesis</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/ironworm-miasma-ai-coding-agent-injection-two-supply-chain-w/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://research.jfrog.com/post/iron-worm-shai-hulud-rustier-cousin/" target="_blank" rel="noopener noreferrer">JFrog Security Research — IronWorm</a> · <a href="https://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/" target="_blank" rel="noopener noreferrer">BleepingComputer — IronWorm</a> · <a href="https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents" target="_blank" rel="noopener noreferrer">StepSecurity — Miasma AI coding agent injection</a> · <a href="https://thehackernews.com/2026/06/miasma-worm-hits-73-microsoft-github.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/cve-2026-20245-cisco-catalyst-sd-wan-manager-no-patch-zero-d" data-tags="vulnerabilities actively-exploited rce priv-esc no-patch" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-06-01T05:00:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20245/">CVE-2026-20245 +2</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-20245-cisco-catalyst-sd-wan-manager-no-patch-zero-d"><a href="https://ctipilot.ch/entries/2026-06-01/cve-2026-20245-cisco-catalyst-sd-wan-manager-no-patch-zero-d/">CVE-2026-20245 — Cisco Catalyst SD-WAN Manager: no-patch zero-day chain confirmed to push malicious configs to edge devices</a></h3><p><strong>If you did nothing this week:</strong> attackers with netadmin access to your Catalyst SD-WAN Manager can execute arbitrary commands as root and, per NCSC-CH&#39;s 5 June advisory update, push malicious configurations to every downstream edge device. No patch exists.</p>
<p>CVE-2026-20245 is a command injection in SD-WAN Manager&#39;s CLI file-upload handler (<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a>; <a href="https://ctipilot.ch/briefs/2026-06-06/" target="_blank" rel="noopener noreferrer">daily 2026-06-06</a>). An authenticated attacker with netadmin privileges injects arbitrary OS commands that execute as root (<code>T1059.004</code>). In observed limited incidents, exploitation of CVE-2026-20245 resulted in <strong>malicious configurations pushed to downstream edge devices</strong> — extending attacker control from the management plane into the forwarding plane (<a href="https://security-hub.ncsc.admin.ch/#/posts/12579" target="_blank" rel="noopener noreferrer">NCSC-CH advisory 12579, updated 2026-06-05</a>). The realistic attack path is a three-CVE chain: CVE-2026-20182 provides unauthenticated management-interface access (<code>T1190</code>), CVE-2026-20127 escalates to netadmin (<code>T1078</code>), and CVE-2026-20245 executes OS commands as root. The first two CVEs are patched in post-14-May SD-WAN Manager builds; CVE-2026-20245 has no fix — Cisco&#39;s only guidance is management-plane access restriction.</p>
<p>The forwarding-plane impact is the operationally critical new fact from this week: in transit-mode SD-WAN deployments, attacker-controlled edge-device configurations can cascade into routing-table manipulation, traffic interception, and service disruption across every site managed from the compromised Manager instance. <strong>Defender actions:</strong> apply the post-14-May SD-WAN Manager builds (patches chain entry points CVE-2026-20182/20127); ACL the management interface to a dedicated management VLAN; enforce MFA for netadmin and rotate Manager credentials; hunt the CLI audit log for anomalous file-upload events; and treat any unscheduled edge-device config-push as a hunting trigger.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: attackers with netadmin access to your Catalyst SD-WAN Manager can execute arbitrary commands as root and, per NCSC-CH&#39;s 5 June advisory update, push malicious configurations to every downstream edge device.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/cve-2026-20245-cisco-catalyst-sd-wan-manager-no-patch-zero-d/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://security-hub.ncsc.admin.ch/#/posts/12579" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub advisory 12579</a> · <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx" target="_blank" rel="noopener noreferrer">Cisco PSIRT cisco-sa-sdwan-privesc-4uxFrdzx</a> · <a href="https://www.helpnetsecurity.com/2026/06/05/cisco-sd-wan-cve-2026-20245-0-day-exploited/" target="_blank" rel="noopener noreferrer">Help Net Security</a></div></article><div class="sect" id="multi-day-campaigns-and-chains"><span class="n">02</span><span class="t">Multi-day campaigns and chains</span><span class="c">1 item</span></div><article class="finding entry-card" data-entry-id="2026-06-01/gamaredon-gammaphish-gammaworm-ntfs-ads-usb-gammasteel-s3-ex" data-tags="nation-state espionage russia-nexus botnet" data-regions="europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-01T05:00:04Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="gamaredon-gammaphish-gammaworm-ntfs-ads-usb-gammasteel-s3-ex"><a href="https://ctipilot.ch/entries/2026-06-01/gamaredon-gammaphish-gammaworm-ntfs-ads-usb-gammasteel-s3-ex/">Gamaredon: GammaPhish → GammaWorm (NTFS ADS + USB) → GammaSteel (S3 exfil) — the week&#39;s most complete intrusion kill-chain disclosure</a></h3><p>Monday 2 June brought Sekoia&#39;s part-one Gamaredon series (<a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/" target="_blank" rel="noopener noreferrer">Sekoia TDR, 2026-06-01</a>), consolidating three capability clusters under unified naming: <strong>GammaPhish</strong> (the spearphishing-through-GammaLoad funnel), <strong>GammaWorm</strong> (the USB-and-network-propagation layer), and <strong>GammaSteel</strong> (the S3-exfiltration stealer confirmed in the same campaign arc via Sekoia TDR follow-up, <a href="https://ctipilot.ch/briefs/2026-06-03/" target="_blank" rel="noopener noreferrer">daily 2026-06-03</a>).</p>
<p><strong>Initial access (GammaPhish):</strong> weaponised xHTML files exploiting CVE-2025-8088 (the WinRAR path-traversal flaw, patched but widely unpatched) drop HTA payloads into Windows Startup directories via <code>mshta.exe</code>. <strong>Propagation (GammaWorm):</strong> a 20,000+-line obfuscated VBScript worm persists via scheduled tasks and <code>Run</code>/<code>RunOnce</code> registry keys, hides components in <strong>NTFS Alternate Data Streams</strong>, and spreads across USB drives and mapped network shares using Ukrainian-language lures (<code>T1025</code>, <code>T1091</code>). C2 resolves through dead-drop pages on Telegram, Telegra.ph, Teletype.in, Supabase and Cloudflare Workers — all platforms with high allow-list rates at enterprise egress proxies. <strong>Exfiltration (GammaSteel):</strong> the S3-exfiltration stealer stages and uploads collected data directly to attacker-controlled AWS S3 buckets.</p>
<p>The detection pattern across all three stages is highly transferable to non-Ukraine targets. Hunt for: <code>mshta.exe</code> spawning <code>wscript.exe</code>; large obfuscated VBScripts executing from <code>%APPDATA%</code>; scheduled tasks with randomised GUID names pointing into user-profile paths; NTFS ADS on <code>%TEMP%</code>/<code>%APPDATA%</code> files (<code>dir /r</code> or Sysmon EID 11 for streams); outbound HTTPS to Telegra.ph / Supabase / Workers from non-developer hosts; and anomalous S3-API calls from user endpoints.</p><div class="prov"><span>synthesis</span><span>01 Jun 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/gamaredon-gammaphish-gammaworm-ntfs-ads-usb-gammasteel-s3-ex/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/" target="_blank" rel="noopener noreferrer">Sekoia TDR — GammaPhish and GammaWorm</a></div></article><div class="sect" id="vulnerability-roll-up"><span class="n">03</span><span class="t">Vulnerability roll-up</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-06-01/cve-2026-10868-misp-mass-assignment-account-takeover-cvss-9" data-tags="vulnerabilities identity auth-bypass patch-available" data-regions="europe global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-01T05:00:07Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-10868/">CVE-2026-10868</a></div><h3 class="f-h" id="cve-2026-10868-misp-mass-assignment-account-takeover-cvss-9"><a href="https://ctipilot.ch/entries/2026-06-01/cve-2026-10868-misp-mass-assignment-account-takeover-cvss-9/">CVE-2026-10868 — MISP: mass-assignment account-takeover (CVSS 9.0) in the EU threat-sharing platform</a></h3><p>Patched 2026-06-04 (deep-dived 2026-06-06 daily). Insufficient field filtering in <code>UsersController::edit()</code> lets an authenticated user edit another account&#39;s record, enabling account-takeover and privilege manipulation in multi-organisation sharing hubs — the account-takeover combined with a companion cross-org event-template overwrite bug enables manipulation of the shared indicator pool itself (<a href="https://github.com/advisories/GHSA-h7wj-m45x-884x" target="_blank" rel="noopener noreferrer">GHSA-h7wj-m45x-884x</a>; <a href="https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1800" target="_blank" rel="noopener noreferrer">BSI WID-SEC-2026-1800</a>). MISP underpins CERT-EU, GovCERT.ch, CIRCL.lu and most EU national-CERT and ISAC sharing infrastructure — highest-priority patch for any multi-org sharing instance. Post-patch, audit user-account attribute changes in MISP&#39;s own event log for the pre-patch exposure window.</p><div class="prov"><span>vulnerability</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/cve-2026-10868-misp-mass-assignment-account-takeover-cvss-9/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://github.com/advisories/GHSA-h7wj-m45x-884x" target="_blank" rel="noopener noreferrer">GitHub Security Advisory GHSA-h7wj-m45x-884x</a> · <a href="https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1800" target="_blank" rel="noopener noreferrer">BSI CERT-Bund WID-SEC-2026-1800</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/keycloak-26-6-3-16-cves-in-the-eu-public-sector-s-reference" data-tags="vulnerabilities identity auth-bypass priv-esc patch-available" data-regions="global europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-01T05:00:06Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-9704/">CVE-2026-9704 +1</a></div><h3 class="f-h" id="keycloak-26-6-3-16-cves-in-the-eu-public-sector-s-reference"><a href="https://ctipilot.ch/entries/2026-06-01/keycloak-26-6-3-16-cves-in-the-eu-public-sector-s-reference/">Keycloak 26.6.3 — 16 CVEs in the EU public sector&#39;s reference IAM, led by token-exchange privilege escalation and SSRF</a></h3><p>Released 2026-06-04 (<a href="https://www.keycloak.org/2026/06/keycloak-2663-released" target="_blank" rel="noopener noreferrer">Keycloak</a>; deep-dived 2026-06-07 daily). <strong>CVE-2026-9704</strong> is a privilege escalation in OAuth 2.0 token exchange: a low-privilege client omits the <code>subject_token</code> parameter and Keycloak issues a token under the requesting client&#39;s identity rather than rejecting the malformed request, enabling lateral movement between service identities (<code>T1550.001</code>). <strong>CVE-2026-4874</strong> turns the OIDC token endpoint into an SSRF primitive, giving an attacker who can reach the endpoint a pivot into internal services Keycloak is permitted to contact. Additional CVEs of note: CVE-2026-8830 (missing server-side WebAuthn attestation validation — undermines phishing-resistant MFA enrolment assurance); CVE-2026-9802 (restart resets <code>startupTime</code>, allowing replay of rotated refresh tokens). No in-the-wild exploitation reported; patch-priority for any internet-reachable Keycloak underpinning e-government SSO or SAML federation. Detection: alert on <code>token_exchange</code> events in the Keycloak event log where <code>subject_token</code> is absent but a token is issued; watch for outbound connections from the Keycloak service host to non-allow-listed internal addresses correlated with token-endpoint requests.</p><div class="prov"><span>vulnerability</span><span>01 Jun 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/keycloak-26-6-3-16-cves-in-the-eu-public-sector-s-reference/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.keycloak.org/2026/06/keycloak-2663-released" target="_blank" rel="noopener noreferrer">Keycloak 26.6.3 release notes</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/cve-2026-49975-http-2-bomb-hpack-amplification-slowloris-cha" data-tags="cloud vulnerabilities dos pre-auth poc-public patch-available" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-06-01T05:00:05Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-49975/">CVE-2026-49975</a></div><h3 class="f-h" id="cve-2026-49975-http-2-bomb-hpack-amplification-slowloris-cha"><a href="https://ctipilot.ch/entries/2026-06-01/cve-2026-49975-http-2-bomb-hpack-amplification-slowloris-cha/">CVE-2026-49975 — HTTP/2 Bomb: HPACK amplification + Slowloris chains to single-connection RAM exhaustion, patch status split by server</a></h3><p>Disclosed 3 June via oss-security by researcher Calif, who discovered the bug using OpenAI&#39;s Codex (<a href="https://seclists.org/oss-sec/2026/q2/790" target="_blank" rel="noopener noreferrer">Calif/oss-security</a>; deep-dived 2026-06-04 daily; NCSC-CH advisory 12610). The attack combines two HTTP/2 protocol weaknesses: seeding the server&#39;s HPACK dynamic header-compression table with a large entry then sending thousands of single-byte back-references forces massive decoded-size reconstruction, while Slowloris-style connection holding prevents memory from being freed. Measured amplification ratios at 32 GB RAM: Envoy ~5,700:1 (exhausted in ~10 s), Apache httpd ~4,000:1, nginx ~70:1. PoC public. Patch status as of 7 June: <strong>nginx</strong> — fixed in 1.29.8 (<code>http2_max_field_size</code> directive); <strong>Apache mod_http2</strong> — fixed in standalone v2.0.41 but not yet bundled into an httpd 2.4.x release, requiring manual installation; <strong>Microsoft IIS, Envoy, Cloudflare Pingora</strong> — no patch. Researchers estimate over 880,000 public-facing servers exposed. No confirmed in-the-wild exploitation. For defenders: upgrade nginx ≥1.29.8; install standalone mod_http2 v2.0.41 on Apache until bundled; consider HTTP/2 disablement or WAF header-count limits for IIS and Envoy until patches ship.</p><div class="prov"><span>vulnerability</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/cve-2026-49975-http-2-bomb-hpack-amplification-slowloris-cha/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://seclists.org/oss-sec/2026/q2/790" target="_blank" rel="noopener noreferrer">oss-security / Calif</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12610" target="_blank" rel="noopener noreferrer">NCSC-CH advisory 12610</a> · <a href="https://www.securityweek.com/http-2-bomb-exploit-knocks-web-servers-offline-in-seconds/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article><div class="sect" id="sector-victim-patterns"><span class="n">04</span><span class="t">Sector &amp; victim patterns</span><span class="c">4 items</span></div><article class="finding entry-card" data-entry-id="2026-06-01/public-sector-most-targeted-sector-this-week-by-volume-and-b" data-tags="nation-state hacktivism vulnerabilities actively-exploited" data-regions="europe switzerland" data-kind="synthesis" data-priority="high" data-discovered="2026-06-01T05:00:08Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="public-sector-most-targeted-sector-this-week-by-volume-and-b"><a href="https://ctipilot.ch/entries/2026-06-01/public-sector-most-targeted-sector-this-week-by-volume-and-b/">Public sector — most-targeted sector this week by volume and by operational severity</a></h3><p>The public sector carried the highest concentration of critical items this week. CVE-2026-41089 (Netlogon SYSTEM RCE) and CVE-2026-20245 (Cisco SD-WAN no-patch zero-day) both have active exploitation with direct public-sector estate exposure. NCSC-CH&#39;s G7 Évian advisory is a direct Swiss federal / cantonal SOC priority for the coming week (. VerdantBamboo&#39;s intrusion entered through an MSP&#39;s pfSense — the precise threat model for any federation of public-sector organisations sharing managed-service relationships (§7). MISP CVE-2026-10868 patches EU CERT tooling directly used by the operators of this newsletter&#39;s primary audience. OP-512&#39;s China-linked IIS/.NET 4.0 cluster (<a href="https://ctipilot.ch/briefs/2026-06-06/" target="_blank" rel="noopener noreferrer">daily 2026-06-06</a>) targets the legacy web-server estate still common in cantonal and municipal government, with per-deployment cryptographic keying defeating signature-based detection entirely. ENISA NIS360 confirms public administration is the most consistently targeted EU sector by hacktivist activity, receiving nearly 63% of all EU hacktivist attacks, yet about a third of entities lack structured cybersecurity expertise at management level.</p><div class="prov"><span>synthesis</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/public-sector-most-targeted-sector-this-week-by-volume-and-b/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.enisa.europa.eu/enisa-nis360-2026" target="_blank" rel="noopener noreferrer">ENISA NIS360 2026</a> · <a href="https://securityaffairs.com/193002/reports/enisa-nis360-2026-progress-across-the-board-but-the-sectors-that-matter-most-are-still-falling-short.html" target="_blank" rel="noopener noreferrer">Security Affairs — NIS360</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/healthcare-hipaa-breach-healthcare-supply-chain-exposure" data-tags="data-breach organized-crime supply-chain" data-regions="us europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-01T05:00:09Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="healthcare-hipaa-breach-healthcare-supply-chain-exposure"><a href="https://ctipilot.ch/entries/2026-06-01/healthcare-hipaa-breach-healthcare-supply-chain-exposure/">Healthcare — HIPAA breach + healthcare supply-chain exposure</a></h3><p>ShinyHunters published the DentaQuest dataset this week: 234 GB, 2.6 million records in HIPAA-format ASC X12 claims interchange, including Medicaid IDs (<a href="https://www.bleepingcomputer.com/news/security/dentaquest-data-breach-exposed-info-of-26-million-accounts/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-04</a>). The DentaQuest extortion arc is the week&#39;s clearest demonstration that the ShinyHunters operation monetises pure data theft — no encryption, no backup-based leverage — placing the detection priority at bulk-export monitoring in claims and SaaS systems rather than backup integrity. Additionally, CVE-2026-42251 in KAMSOFT KS-SOMED (hardcoded FTP update-server credentials, allowing trojanised updates to any downstream Polish NHS deployment) underlines the supply-chain-through-update-mechanism risk in healthcare software.</p><div class="prov"><span>synthesis</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/healthcare-hipaa-breach-healthcare-supply-chain-exposure/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/dentaquest-data-breach-exposed-info-of-26-million-accounts/" target="_blank" rel="noopener noreferrer">BleepingComputer — DentaQuest</a> · <a href="https://www.bankinfosecurity.com/shinyhunters-leaks-234gb-dentaquest-data-trove-a-31883" target="_blank" rel="noopener noreferrer">BankInfoSecurity — DentaQuest</a> · <a href="https://cert.pl/en/posts/2026/06/CVE-2026-42251/" target="_blank" rel="noopener noreferrer">CERT Polska — CVE-2026-42251</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/technology-software-supply-chain-four-concurrent-worm-supply" data-tags="supply-chain infostealer cloud identity" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-06-01T05:00:11Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="technology-software-supply-chain-four-concurrent-worm-supply"><a href="https://ctipilot.ch/entries/2026-06-01/technology-software-supply-chain-four-concurrent-worm-supply/">Technology / software supply chain — four concurrent worm/supply-chain threats in one week</a></h3><p>Simultaneously active this week: Miasma npm credential collectors, IronWorm eBPF rootkit worm, two concurrent npm dependency confusion campaigns (Microsoft 45 packages + Sonatype 176 packages, <a href="https://ctipilot.ch/briefs/2026-06-01/" target="_blank" rel="noopener noreferrer">daily 2026-06-01</a>), the claude-code-action GitHub Actions flaw (arbitrary code execution from a single malicious issue, fixed in v1.0.94; <a href="https://ctipilot.ch/briefs/2026-06-05/" target="_blank" rel="noopener noreferrer">daily 2026-06-05</a>), and Polyfill.io domain reactivation surfacing native browser credential prompts on sites still loading the legacy CDN reference (<a href="https://ctipilot.ch/briefs/2026-06-07/" target="_blank" rel="noopener noreferrer">daily 2026-06-07</a>). The combined picture is a meaningful escalation of the npm/GitHub Actions attack surface: credential theft, kernel-rootkit persistence, and CI/CD pipeline compromise are now simultaneous, not sequential, threats in the software supply chain.</p><div class="prov"><span>synthesis</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/technology-software-supply-chain-four-concurrent-worm-supply/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://research.jfrog.com/post/iron-worm-shai-hulud-rustier-cousin/" target="_blank" rel="noopener noreferrer">JFrog — IronWorm</a> · <a href="https://flatt.tech/research/posts/poisoning-claude-code-one-github-issue-to-break-the-supply-chain/" target="_blank" rel="noopener noreferrer">GMO Flatt Security — claude-code-action</a> · <a href="https://www.bleepingcomputer.com/news/security/suspicious-polyfill-login-prompts-pop-up-on-toshiba-muji-websites/" target="_blank" rel="noopener noreferrer">BleepingComputer — Polyfill.io</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/finance-payments-stripe-abusing-magecart-and-ofac-iran-sanct" data-tags="organized-crime supply-chain data-breach law-enforcement iran-nexus cryptocrime" data-regions="global us" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-01T05:00:10Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="finance-payments-stripe-abusing-magecart-and-ofac-iran-sanct"><a href="https://ctipilot.ch/entries/2026-06-01/finance-payments-stripe-abusing-magecart-and-ofac-iran-sanct/">Finance / payments — Stripe-abusing Magecart and OFAC Iran sanctions</a></h3><p>A Magecart variant delivering its skimmer through Stripe customer metadata and exfiltrating stolen card data back through <code>api.stripe.com</code> as fake customer records was documented by Sansec this week (<a href="https://sansec.io/research/stripe-api-skimmer-infrastructure" target="_blank" rel="noopener noreferrer">Sansec, 2026-06-04</a>; <a href="https://ctipilot.ch/briefs/2026-06-07/" target="_blank" rel="noopener noreferrer">daily 2026-06-07</a>). Because both payload delivery and exfiltration transit a universally allow-listed domain, CSP <code>connect-src</code> controls and WAF egress rules built around blocking unknown domains are blind to this variant. Detection must move server-side: audit GTM container IDs, monitor Stripe customer-creation events for non-order-matched calls, and inspect customer-metadata fields for encoded JavaScript. Separately, OFAC designated Nobitex and three Iranian exchanges for IRGC-affiliated ransomware proceeds — confirmed wallet clusters now carry an OFAC sanctions-nexus consideration for any EU institution with US correspondent relationships.</p><div class="prov"><span>synthesis</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/finance-payments-stripe-abusing-magecart-and-ofac-iran-sanct/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://sansec.io/research/stripe-api-skimmer-infrastructure" target="_blank" rel="noopener noreferrer">Sansec — Stripe API skimmer</a> · <a href="https://home.treasury.gov/news/press-releases/sb0519" target="_blank" rel="noopener noreferrer">US Treasury OFAC</a></div></article><div class="sect" id="incidents-disclosures-recap"><span class="n">05</span><span class="t">Incidents &amp; disclosures recap</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-06-01/booking-com-whatsapp-phishing-upstream-hotel-saas-breach-rea" data-tags="data-breach phishing supply-chain" data-regions="europe switzerland" data-kind="incident" data-priority="notable" data-discovered="2026-06-01T05:00:14Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="booking-com-whatsapp-phishing-upstream-hotel-saas-breach-rea"><a href="https://ctipilot.ch/entries/2026-06-01/booking-com-whatsapp-phishing-upstream-hotel-saas-breach-rea/">Booking.com WhatsApp phishing + upstream hotel SaaS breach: real reservation data weaponised, 100+ properties affected, Dutch DPA opens investigation</a></h3><p>NCSC-CH&#39;s Week 22 report (4 June; <a href="https://ctipilot.ch/briefs/2026-06-04/" target="_blank" rel="noopener noreferrer">daily 2026-06-04</a>) documents two phishing variants exploiting real booking data leaked in the April 2026 Booking.com compromise: <strong>Variant 1</strong> — fake WhatsApp refund lure → TWINT/Swiss-bank-portal credential harvest; <strong>Variant 2</strong> — attackers using compromised hotel booking-system credentials to message guests <em>through the legitimate booking channel</em>, demanding urgent card re-verification. Variant 2 breaks user-awareness controls because the message originates from a trusted platform (<a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/wochenrueckblick_22.html" target="_blank" rel="noopener noreferrer">NCSC-CH</a>). In the same window, a separate upstream booking/channel-management SaaS layer breach exposed guest reservation records (names, contacts, arrival/departure dates) for guests at more than 100 Dutch, Belgian and Irish hotels; criminals are already sending contextually accurate &quot;confirm your reservation&quot; phishing referencing real upcoming stays (<a href="https://www.dutchnews.nl/2026/06/mass-data-breach-on-over-100-dutch-hotels-hits-guests/" target="_blank" rel="noopener noreferrer">DutchNews.nl</a>). The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has opened a GDPR investigation; Art. 33/34 notification clocks are running for each hotel as an independent controller.</p><div class="prov"><span>incident</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/booking-com-whatsapp-phishing-upstream-hotel-saas-breach-rea/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/wochenrueckblick_22.html" target="_blank" rel="noopener noreferrer">NCSC-CH Week 22 report</a> · <a href="https://www.dutchnews.nl/2026/06/mass-data-breach-on-over-100-dutch-hotels-hits-guests/" target="_blank" rel="noopener noreferrer">DutchNews.nl</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/shinyhunters-dentaquest-234-gb-hipaa-claims-data-published-a" data-tags="data-breach organized-crime" data-regions="us" data-kind="incident" data-priority="notable" data-discovered="2026-06-01T05:00:13Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="shinyhunters-dentaquest-234-gb-hipaa-claims-data-published-a"><a href="https://ctipilot.ch/entries/2026-06-01/shinyhunters-dentaquest-234-gb-hipaa-claims-data-published-a/">ShinyHunters — DentaQuest: 234 GB HIPAA claims data published after ransom refusal, 2.6 M Medicaid and dental-benefit records</a></h3><p>DentaQuest (Sun Life subsidiary, administering dental/vision benefits for ~35 M US Medicaid and Medicare members) confirmed on 1 June that ShinyHunters published 234 GB of stolen data after ransom negotiations broke down (<a href="https://www.bleepingcomputer.com/news/security/dentaquest-data-breach-exposed-info-of-26-million-accounts/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-04</a>; <a href="https://www.bankinfosecurity.com/shinyhunters-leaks-234gb-dentaquest-data-trove-a-31883" target="_blank" rel="noopener noreferrer">BankInfoSecurity</a>; <a href="https://ctipilot.ch/briefs/2026-06-05/" target="_blank" rel="noopener noreferrer">daily 2026-06-05</a>). The dataset — published by late May per BankInfoSecurity — is in HIPAA-format ASC X12 claims interchange; names, postal and email addresses, dates of birth, phone numbers, health-insurance details and Medicaid IDs across 2.6 million unique email addresses. DentaQuest has not confirmed the specific attack vector; the extortion pattern (no encryption, hard deadline, publish-on-refusal) is consistent with the broader ShinyHunters vishing-driven SaaS-access campaign that earlier claimed Charter, Carnival, 7-Eleven, Instructure and Wynn Resorts. The operational reminder: this actor has no backup-based leverage — detection must land at the bulk-export stage (anomalous off-hours claims-system bulk downloads; SaaS API token generation; volume spikes on outbound archive transfers).</p><div class="prov"><span>incident</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/shinyhunters-dentaquest-234-gb-hipaa-claims-data-published-a/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/dentaquest-data-breach-exposed-info-of-26-million-accounts/" target="_blank" rel="noopener noreferrer">BleepingComputer</a> · <a href="https://www.bankinfosecurity.com/shinyhunters-leaks-234gb-dentaquest-data-trove-a-31883" target="_blank" rel="noopener noreferrer">BankInfoSecurity</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/luna-moth-unc3753-vishing-to-physical-usb-data-theft-extorti" data-tags="organized-crime data-breach phishing" data-regions="us global" data-kind="incident" data-priority="notable" data-discovered="2026-06-01T05:00:12Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="luna-moth-unc3753-vishing-to-physical-usb-data-theft-extorti"><a href="https://ctipilot.ch/entries/2026-06-01/luna-moth-unc3753-vishing-to-physical-usb-data-theft-extorti/">Luna Moth / UNC3753: vishing-to-physical-USB data-theft extortion reaches ~$20 M suppression payment and DNS fast-flux C2</a></h3><p>Mandiant&#39;s comprehensive primary forensic analysis published 5 June (<a href="https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/" target="_blank" rel="noopener noreferrer">Mandiant</a>; deep-dived <a href="https://ctipilot.ch/briefs/2026-06-06/" target="_blank" rel="noopener noreferrer">daily 2026-06-06</a>) documents a January–May 2026 data-theft extortion campaign against US legal and professional-services organisations by UNC3753 (Luna Moth / Silent Ransom Group). The intrusion chain is entirely social-engineered: invoice/subscription pretext → vishing callback impersonating internal IT support → victim installs AnyDesk / Bomgar / Zoho Assist → actor enumerates file shares and document-management systems and exfiltrates in under an hour in several cases using portable WinSCP/Rclone. No ransomware, no encryption — leverage is the stolen data alone. Weil, Gotshal &amp; Manges reportedly paid an estimated ~$20 M suppression payment (<a href="https://www.legalcheek.com/2026/06/weil-reportedly-pays-up-to-20-million-after-hackers-steal-client-data/" target="_blank" rel="noopener noreferrer">Legal Cheek, 2026-06-03</a>). Two new in-window developments: (1) the FBI&#39;s 2026-05-26 Cyber FLASH and Mandiant both confirm operatives <strong>entering corporate offices to insert USB exfiltration devices</strong> when remote social engineering failed (<code>T1052.001</code>), bypassing every network-side control; (2) a 2026-06-05 report documents SRG migrating its C2 to <strong>DNS fast-flux</strong> infrastructure, hardening against takedown and static indicator blocking (<a href="https://securityaffairs.com/193215/cyber-crime/silent-ransom-group-srg-switching-to-dns-fast-flux-infrastructure.html" target="_blank" rel="noopener noreferrer">Security Affairs, 2026-06-05</a>). For Swiss and European legal and professional-services firms: the IT-helpdesk-impersonation vector is identical to social-engineering pressure documented across European corporate intrusions; the physical-USB escalation raises duty-of-care questions that require physical-security response, not just SOC playbooks.</p><div class="prov"><span>incident</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/luna-moth-unc3753-vishing-to-physical-usb-data-theft-extorti/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/" target="_blank" rel="noopener noreferrer">Mandiant / Google Cloud GTIG</a> · <a href="https://www.legalcheek.com/2026/06/weil-reportedly-pays-up-to-20-million-after-hackers-steal-client-data/" target="_blank" rel="noopener noreferrer">Legal Cheek, 2026-06-03</a> · <a href="https://securityaffairs.com/193215/cyber-crime/silent-ransom-group-srg-switching-to-dns-fast-flux-infrastructure.html" target="_blank" rel="noopener noreferrer">Security Affairs — DNS fast-flux</a></div></article><div class="sect" id="annual-periodic-threat-reports"><span class="n">06</span><span class="t">Annual / periodic threat reports</span><span class="c">2 items</span></div><article class="finding entry-card" data-entry-id="2026-06-01/enisa-nis360-2026-3rd-edition-seven-sectors-in-the-persisten" data-tags="hacktivism nation-state vulnerabilities" data-regions="europe" data-kind="annual-report" data-priority="high" data-discovered="2026-06-01T05:00:16Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="enisa-nis360-2026-3rd-edition-seven-sectors-in-the-persisten"><a href="https://ctipilot.ch/entries/2026-06-01/enisa-nis360-2026-3rd-edition-seven-sectors-in-the-persisten/">ENISA NIS360 2026 (3rd edition) — seven sectors in the persistent risk zone where criticality outpaces maturity</a></h3><p>Published 28 May 2026 (<a href="https://www.enisa.europa.eu/enisa-nis360-2026" target="_blank" rel="noopener noreferrer">ENISA</a>; follow-up coverage 2 June in <a href="https://securityaffairs.com/193002/reports/enisa-nis360-2026-progress-across-the-board-but-the-sectors-that-matter-most-are-still-falling-short.html" target="_blank" rel="noopener noreferrer">Security Affairs</a>). The headline finding is structural: a persistent &quot;risk zone&quot; where criticality exceeds maturity comprising public administration, health, railway, maritime, ICT service management, space, and drinking/waste water. Public administration receives <strong>nearly 63% of all EU hacktivist attacks</strong> and is the most consistently targeted sector, yet roughly one-third of entities lack structured cybersecurity expertise at management level and about half provide no cybersecurity training to management. Water sector: one in three entities has never conducted a risk assessment. The high-maturity sectors — banking, electricity, telecoms, trust services, aviation, financial market infrastructures — share a common driver: regulatory pressure backed by supervisory capacity with real enforcement. Only 16% of NIS2-affected entities consider themselves fully compliant; 41% face uncertainty about national obligations. For NIS2 national authorities: sectors without comparable oversight structures (ICT service management, space) lag structurally. For public-sector SOC managers specifically: the elevated hacktivist pressure confirmed by ENISA should cross-reference directly against current threat-model assumptions and DDoS mitigation capacity, particularly in the June 15–17 G7 Évian window.</p><div class="prov"><span>annual-report</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/enisa-nis360-2026-3rd-edition-seven-sectors-in-the-persisten/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.enisa.europa.eu/enisa-nis360-2026" target="_blank" rel="noopener noreferrer">ENISA NIS360 2026</a> · <a href="https://securityaffairs.com/193002/reports/enisa-nis360-2026-progress-across-the-board-but-the-sectors-that-matter-most-are-still-falling-short.html" target="_blank" rel="noopener noreferrer">Security Affairs</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/sophos-2026-active-adversary-report-identity-the-dominant-in" data-tags="ransomware identity organized-crime" data-regions="global" data-kind="annual-report" data-priority="notable" data-discovered="2026-06-01T05:00:17Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="sophos-2026-active-adversary-report-identity-the-dominant-in"><a href="https://ctipilot.ch/entries/2026-06-01/sophos-2026-active-adversary-report-identity-the-dominant-in/">Sophos 2026 Active Adversary Report — identity the dominant intrusion root cause; Impacket and AnyDesk most-observed post-exploitation</a></h3><p>Published 2 June (<a href="https://www.sophos.com/en-us/blog/2026-sophos-active-adversary-report" target="_blank" rel="noopener noreferrer">Sophos X-Ops</a>; drawing on 661 IR/MDR cases; <a href="https://ctipilot.ch/briefs/2026-06-03/" target="_blank" rel="noopener noreferrer">daily 2026-06-03</a>). The findings that directly shift defender priorities: identity-based compromise — stolen/valid credentials, brute force, phishing — is the <strong>leading intrusion root cause</strong>, with missing or misconfigured MFA present in a majority of incidents. Time from initial access to Active Directory compromise has compressed materially. <strong>Impacket</strong> is among the most frequently observed post-exploitation toolkits; <strong>AnyDesk</strong> is the most-abused legitimate remote-access tool, consistent with this week&#39;s Luna Moth tradecraft. The recurring telemetry blind spots are the load-bearing findings: firewall logs were missing in roughly <strong>half</strong> of ransomware cases, and a meaningful share of compromised Windows Servers were running end-of-life builds. Practical hunt targets: alert on Impacket artefacts (impacket-named tool processes, <code>secretsdump</code>-style NTDS access, <code>SMBExec</code>/<code>WMIExec</code> parent processes); instrument the initial-access-to-DC-compromise window; inventory EOL Windows Servers; verify firewall log retention is complete before an incident, not during one. This is a single-vendor IR report; treat findings as directionally correct rather than statistically definitive without independent corroboration. <code>[SINGLE-SOURCE]</code></p><div class="prov"><span>annual-report</span><span>01 Jun 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/sophos-2026-active-adversary-report-identity-the-dominant-in/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sophos.com/en-us/blog/2026-sophos-active-adversary-report" target="_blank" rel="noopener noreferrer">Sophos X-Ops 2026 Active Adversary Report</a></div></article><div class="sect" id="long-running-campaigns-status-update"><span class="n">07</span><span class="t">Long-running campaigns · status update</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-06-01/verdantbamboo-unc5221-warp-panda-18-month-undetected-china-n" data-tags="nation-state espionage supply-chain china-nexus" data-regions="europe" data-kind="synthesis" data-priority="high" data-discovered="2026-06-01T05:00:18Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="verdantbamboo-unc5221-warp-panda-18-month-undetected-china-n"><a href="https://ctipilot.ch/entries/2026-06-01/verdantbamboo-unc5221-warp-panda-18-month-undetected-china-n/">VerdantBamboo / UNC5221 / WARP PANDA — 18-month undetected China-nexus intrusion through MSP pfSense</a></h3><p>First disclosed this week by Volexity&#39;s incident-response case (<a href="https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/" target="_blank" rel="noopener noreferrer">Volexity, 2026-06-04</a>; <a href="https://ctipilot.ch/briefs/2026-06-05/" target="_blank" rel="noopener noreferrer">daily 2026-06-05</a>). VerdantBamboo — assessed with high confidence as UNC5221 (WARP PANDA) — entered a European organisation through its MSP&#39;s pfSense firewall with a BSD build of the BRICKSTORM Golang backdoor, then persisted across three appliances (pfSense, Synology NAS, Egnyte Storage Sync VM) that cannot run EDR by design. The M365 Conditional Access bypass — routing authentication through the Egnyte appliance&#39;s trusted egress IP — is the novel operational technique. Two previously undocumented implants: AGENTPSD (PyInstaller Python HTTPS reverse shell) and PLENET/GRIMBOLT (.NET Native AOT on Linux NAS). Outstanding question: Volexity found access dating at least 18 months back, raising the question of what else the actor collected during that window and whether the MSP has other affected European clients. The disclosure is Volexity primary IR only — no second corroborating source is available. <code>[SINGLE-SOURCE]</code></p><div class="prov"><span>synthesis</span><span>01 Jun 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/verdantbamboo-unc5221-warp-panda-18-month-undetected-china-n/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/" target="_blank" rel="noopener noreferrer">Volexity, 2026-06-04</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/gamaredon-gammaphish-gammaworm-gammasteel-russian-fsb-campai" data-tags="nation-state espionage russia-nexus botnet" data-regions="europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-01T05:00:20Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="gamaredon-gammaphish-gammaworm-gammasteel-russian-fsb-campai"><a href="https://ctipilot.ch/entries/2026-06-01/gamaredon-gammaphish-gammaworm-gammasteel-russian-fsb-campai/">Gamaredon — GammaPhish / GammaWorm / GammaSteel: Russian FSB campaign with USB worm and S3 exfiltration (Sekoia TDR part one)</a></h3><p>Sekoia&#39;s first part of the Gamaredon series disclosed a January 2026 campaign arc (<a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/" target="_blank" rel="noopener noreferrer">Sekoia TDR, 2026-06-01</a>; <a href="https://ctipilot.ch/briefs/2026-06-02/" target="_blank" rel="noopener noreferrer">daily 2026-06-02</a>; update <a href="https://ctipilot.ch/briefs/2026-06-03/" target="_blank" rel="noopener noreferrer">daily 2026-06-03</a>). Initial access via CVE-2025-8088 (WinRAR path-traversal, widely unpatched) drops HTA payloads from xHTML attachments. GammaWorm&#39;s NTFS-ADS concealment and USB-propagation pattern is the signature detection challenge: filesystem timestamps are useless (ADS hides the worm content), and the worm spreads to any mounted drive and mapped share, meaning air-gap-adjacent workstations remain in scope. GammaSteel exfiltrates collected data directly to S3. Part two of the Sekoia series is outstanding and expected to detail further tooling. Open question: has the campaign reached any EU public-sector estate beyond its primary Ukrainian targets? The USB-propagation vector is exactly the mechanism Luna Moth used this week for physical office intrusion — conceptually distinct actors, coincidentally parallel technique.</p><div class="prov"><span>synthesis</span><span>01 Jun 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/gamaredon-gammaphish-gammaworm-gammasteel-russian-fsb-campai/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/" target="_blank" rel="noopener noreferrer">Sekoia TDR</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/ta4922-china-nexus-cybercrime-cluster-expands-from-japan-int" data-tags="organized-crime phishing infostealer china-nexus" data-regions="europe dach uk" data-kind="synthesis" data-priority="notable" data-discovered="2026-06-01T05:00:19Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="ta4922-china-nexus-cybercrime-cluster-expands-from-japan-int"><a href="https://ctipilot.ch/entries/2026-06-01/ta4922-china-nexus-cybercrime-cluster-expands-from-japan-int/">TA4922 — China-nexus cybercrime cluster expands from Japan into Germany, UK and Italy with native-language lures and Atlas RAT</a></h3><p>Proofpoint reported this week that TA4922, a Chinese-speaking financially-motivated cluster running the highest campaign tempo of any cybercrime actor Proofpoint tracks, pivoted in March–April 2026 to localised campaigns against German, UK, Italian and South African organisations (<a href="https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-06-04</a>; <a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-use-new-atlas-rat-malware-in-european-cyberattacks/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-06-04</a>; <a href="https://ctipilot.ch/briefs/2026-06-05/" target="_blank" rel="noopener noreferrer">daily 2026-06-05</a>). Native-language tax-authority, HR/payroll and invoice lures now pair the known ValleyRAT (Winos 4.0) with newly observed Atlas RAT (C-based), RomulusLoader, and SilentRunLoader (Python infostealer targeting Chrome credentials). A notable TTP shift: conversations are moved to LINE, WhatsApp and Microsoft Teams before payload delivery, pulling targets off enterprise email controls. DACH public-sector and finance staff are in direct scope. Hunt for DLL side-loading chains where AnyDesk/SyncFuture load from unexpected user-profile paths, for Python processes reaching Chrome DPAPI, and for unsolicited inbound contact on Teams/WhatsApp that pivots to a &quot;document.&quot;</p><div class="prov"><span>synthesis</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/ta4922-china-nexus-cybercrime-cluster-expands-from-japan-int/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html" target="_blank" rel="noopener noreferrer">The Hacker News</a> · <a href="https://www.bleepingcomputer.com/news/security/chinese-hackers-use-new-atlas-rat-malware-in-european-cyberattacks/" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article><div class="sect" id="policy-regulatory-horizon"><span class="n">08</span><span class="t">Policy &amp; regulatory horizon</span><span class="c">4 items</span></div><article class="finding entry-card" data-entry-id="2026-06-01/eu-council-tte-june-9-csa2-high-risk-supplier-framework-nis2" data-tags="law-enforcement" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-06-01T05:00:24Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eu-council-tte-june-9-csa2-high-risk-supplier-framework-nis2"><a href="https://ctipilot.ch/entries/2026-06-01/eu-council-tte-june-9-csa2-high-risk-supplier-framework-nis2/">EU Council TTE June 9: CSA2 (high-risk supplier framework) + NIS2 simplification progress reports tabled; trilogue targeted early 2027</a></h3><p>The EU Transport, Telecommunications and Energy Council met on 9 June with the Presidency presenting progress reports on the Cybersecurity Act 2 (CSA2) and a targeted NIS2 simplification directive, both proposed by the Commission on 20 January 2026 (<a href="https://industrialcyber.co/regulation-standards-and-compliance/eu-council-to-examine-cybersecurity-package-focused-on-enisa-nis2-simplification-and-supply-chain-security/" target="_blank" rel="noopener noreferrer">Industrial Cyber, 2026-06-05</a>). CSA2 introduces a &quot;high-risk supplier&quot; designation mechanism targeting ICT vendors whose legal or geopolitical context creates cybersecurity risk to critical sectors, with consequences including exclusion from EU public procurement and penalties up to 7% of worldwide turnover. NIS2 simplification amendments clarify jurisdictional rules, add EU Digital Identity Wallet providers and submarine data-transmission infrastructure operators as new essential-entity categories, and streamline ransomware-attack data collection. Both proceed to trilogue; political agreement is targeted for early 2027. For Swiss ICT vendors and public-sector procurement teams: the CSA2 high-risk-supplier framework, once enacted, will reshape EU critical-sector supply-chain decisions and is expected to influence Swiss procurement policy given bilateral-track alignment pressure.</p><div class="prov"><span>policy</span><span>01 Jun 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/eu-council-tte-june-9-csa2-high-risk-supplier-framework-nis2/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://industrialcyber.co/regulation-standards-and-compliance/eu-council-to-examine-cybersecurity-package-focused-on-enisa-nis2-simplification-and-supply-chain-security/" target="_blank" rel="noopener noreferrer">Industrial Cyber</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/eu-20th-russia-sanctions-package-managed-security-services-p" data-tags="law-enforcement nation-state russia-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-06-01T05:00:23Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eu-20th-russia-sanctions-package-managed-security-services-p"><a href="https://ctipilot.ch/entries/2026-06-01/eu-20th-russia-sanctions-package-managed-security-services-p/">EU 20th Russia sanctions package: managed security services prohibition in force since 25 May; Commission interpretive guidance outstanding</a></h3><p>Since 25 May 2026, EU operators are prohibited from providing managed security services — incident response, penetration testing, security audits, consulting — to the Russian government and to entities established in Russia, under Council Regulation (EU) 2026/506 (20th sanctions package) (<a href="https://www.squirepattonboggs.com/insights/publications/the-20th-eu-sanctions-package-against-russia-scope-entry-into-force-and-compliance-implications-for-operators/" target="_blank" rel="noopener noreferrer">Squire Patton Boggs analysis</a>; <a href="https://www.gtlaw.com/en/insights/2026/5/eus-20th-russia-sanctions-package-key-changes-and-compliance-implications" target="_blank" rel="noopener noreferrer">Greenberg Traurig analysis</a>). Wind-down transactions must be completed before 24 October 2026. As of publication, interpretive guidance from the European Commission on the exact prohibition scope has not been issued. Swiss MSSPs are not directly subject to EU sanctions law but should note that EU-headquartered affiliates and any SWIFT/correspondent-banking touch points in EU create indirect exposure. For SOC procurement teams: this prohibition is now live compliance context when reviewing vendor contracts involving any Russian-entity counterparty.</p><div class="prov"><span>policy</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/eu-20th-russia-sanctions-package-managed-security-services-p/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.squirepattonboggs.com/insights/publications/the-20th-eu-sanctions-package-against-russia-scope-entry-into-force-and-compliance-implications-for-operators/" target="_blank" rel="noopener noreferrer">Squire Patton Boggs</a> · <a href="https://www.gtlaw.com/en/insights/2026/5/eus-20th-russia-sanctions-package-key-changes-and-compliance-implications" target="_blank" rel="noopener noreferrer">Greenberg Traurig</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/cra-june-11-notifying-authority-deadline-first-hard-cra-mile" data-tags="vulnerabilities law-enforcement" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-06-01T05:00:22Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="cra-june-11-notifying-authority-deadline-first-hard-cra-mile"><a href="https://ctipilot.ch/entries/2026-06-01/cra-june-11-notifying-authority-deadline-first-hard-cra-mile/">CRA June 11 notifying-authority deadline — first hard CRA milestone with ENISA SRP manual and Secure Update Mechanisms advisory published</a></h3><p>11 June is the Cyber Resilience Act&#39;s first mandatory milestone: EU member states must designate the national authority responsible for assessing and notifying conformity assessment bodies (CABs) for Important and Critical product classes (<a href="https://openssf.org/policy/2026/06/03/updates-from-europe-single-reporting-platform-public-consultations-new-publications/" target="_blank" rel="noopener noreferrer">OpenSSF policy blog, 2026-06-03</a>; <a href="https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp" target="_blank" rel="noopener noreferrer">ENISA SRP page</a>). Without designated notifying authorities, manufacturers of products such as operating systems, firewalls, smart cards, HSMs and smart meter gateways cannot obtain the third-party certificates needed by the December 2027 full-application date. In the same window ENISA published: (1) the access and registration manual for the CRA Single Reporting Platform (SRP) — the platform manufacturers must use from <strong>11 September 2026</strong> to report actively exploited vulnerabilities within 24 h (early warning) and 72 h (full notification); (2) a draft Technical Advisory on Secure Update Mechanisms for SME manufacturers (public consultation to 10 July). The 90-day window to SRP operational date is shorter than it appears: software vendors deploying into EU environments should validate their vulnerability-disclosure pipeline now, not in September.</p><div class="prov"><span>policy</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/cra-june-11-notifying-authority-deadline-first-hard-cra-mile/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://openssf.org/policy/2026/06/03/updates-from-europe-single-reporting-platform-public-consultations-new-publications/" target="_blank" rel="noopener noreferrer">OpenSSF policy blog</a> · <a href="https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp" target="_blank" rel="noopener noreferrer">ENISA CRA SRP</a></div></article><article class="finding entry-card" data-entry-id="2026-06-01/germany-s-gesetzentwurf-zur-st-rkung-der-cybersicherheit-cab" data-tags="law-enforcement nation-state" data-regions="europe dach" data-kind="policy" data-priority="notable" data-discovered="2026-06-01T05:00:21Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="germany-s-gesetzentwurf-zur-st-rkung-der-cybersicherheit-cab"><a href="https://ctipilot.ch/entries/2026-06-01/germany-s-gesetzentwurf-zur-st-rkung-der-cybersicherheit-cab/">Germany&#39;s Gesetzentwurf zur Stärkung der Cybersicherheit: cabinet-approved active-cyberdefence powers for BKA, Bundespolizei and BSI</a></h3><p>On 27 May 2026 the German Federal Cabinet adopted the Gesetzentwurf zur Stärkung der Cybersicherheit, now proceeding to Bundestag (<a href="https://www.bundesregierung.de/breg-en/news/strengthening-cyber-security-2433588" target="_blank" rel="noopener noreferrer">German Federal Government, 2026-05-27</a>; <a href="https://dig.watch/updates/germany-approves-draft-law-expanding-cyber-defense-powers-for-federal-authorities" target="_blank" rel="noopener noreferrer">Digital Watch Observatory, 2026-05-31</a>). The law grants: the BKA and Bundespolizei authority to shut down or disrupt attacker-controlled infrastructure including servers located outside Germany, reroute data traffic, and collect/modify/delete data on foreign systems; the BSI expanded authority to collect threat-preparation data and require telecoms and major platforms to relay BSI threat warnings to end users. Interior Minister Dobrindt: &quot;In future, we will target the attacker, their servers, their software and their strategy.&quot; Personnel implications: BKA +264, Bundespolizei +90, BSI +21 positions by 2030. Civil-society analysis flags constitutional concerns (Basic Law, cross-border state action, jurisdictional conflict with Länder). For DACH/EU defenders: (a) once enacted, telecoms/platform operators gain a new duty-to-relay obligation for BSI warnings; (b) the law sets a precedent for EU active-cyberdefence norms that Swiss forthcoming cyber-resilience legislation (draft expected autumn 2026) will need to address.</p><div class="prov"><span>policy</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/germany-s-gesetzentwurf-zur-st-rkung-der-cybersicherheit-cab/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bundesregierung.de/breg-en/news/strengthening-cyber-security-2433588" target="_blank" rel="noopener noreferrer">German Federal Government</a> · <a href="https://dig.watch/updates/germany-approves-draft-law-expanding-cyber-defense-powers-for-federal-authorities" target="_blank" rel="noopener noreferrer">Digital Watch Observatory</a></div></article><div class="sect" id="looking-ahead-what-to-watch-next-week"><span class="n">09</span><span class="t">Looking ahead · what to watch next week</span><span class="c">1 item</span></div><article class="finding entry-card" data-entry-id="2026-06-01/looking-ahead-2026-w23" data-tags="cloud lpe rce phishing identity ddos" data-regions="global" data-kind="outlook" data-priority="notable" data-discovered="2026-06-01T05:00:25Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="looking-ahead-2026-w23"><a href="https://ctipilot.ch/entries/2026-06-01/looking-ahead-2026-w23/">Looking ahead — 2026-W23</a></h3><p>A focused, justified list — not predictions, but items already in motion.</p>
<ul><li><strong>June 10 — Patch Tuesday: Chaotic Eclipse patches expected; researcher promises a &quot;big surprise&quot; the same day.</strong> YellowKey (CVE-2026-45585, BitLocker bypass via WinRE autofstx.exe), GreenPlasma (CTFMON SYSTEM escalation), and MiniPlasma (CVE-2020-17103, cldflt.sys Cloud Filter LPE) remain unpatched as of 7 June. Microsoft is expected to patch some or all in the June cumulative update. The Chaotic Eclipse researcher has explicitly promised a new disclosure to coincide with June Patch Tuesday — prepare for a simultaneous patch-and-new-zero-day drop. Pre-stage: verify YellowKey mitigation applied (WinRE autofstx.exe removal script or TPM+PIN BitLocker enforcement); monitor Microsoft MSRC on 10 June. (<a href="https://www.helpnetsecurity.com/2026/06/05/june-2026-patch-tuesday-forecast/" target="_blank" rel="noopener noreferrer">Help Net Security forecast</a>; <a href="https://www.cpomagazine.com/cyber-security/microsoft-doubles-down-on-opposition-to-public-disclosure-as-chaotic-eclipse-wave-of-zero-day-vulnerabilities-continues/" target="_blank" rel="noopener noreferrer">CPO Magazine</a>)</li></ul>
<ul><li><strong>June 11 — CRA notifying-authority deadline AND FIFA World Cup kickoff.</strong> The first hard CRA milestone (§8) and the peak Ghost Stadium PhaaS threat arrive simultaneously. Ghost Stadium — a Chinese-speaking PhaaS operation active across 4,300+ fraudulent FIFA domains — has already claimed an estimated 47,000 victims and up to $1 billion in losses ahead of the kickoff (<a href="https://www.bankinfosecurity.com/chinese-phishing-service-scams-thousands-fifa-world-cup-fans-a-31819" target="_blank" rel="noopener noreferrer">BankInfoSecurity, 2026-06-05</a>; <a href="https://www.ic3.gov/PSA/2026/PSA260527" target="_blank" rel="noopener noreferrer">FBI IC3 PSA260527</a>). The SSO-clone technique replicates PingIdentity login flows — corporate SSO credentials are at risk if employees mistake a sponsored-search-result phishing portal for an enterprise login. Defenders: add FIFA-themed domain alerts to email-gateway and DNS-filtering, block <code>fifa.com</code> typosquats at the proxy, and brief staff on avoiding paid/sponsored results for sports ticket purchases.</li></ul>
<ul><li><strong>June 15–17 — G7 Évian summit: pre-stage DDoS mitigations now.</strong> NCSC-CH expects hacktivist disruptive cyberspace operations on each summit day, following the NoName057(16) pattern from Bürgenstock 2024 (<a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/massnahmen-grossanlaesse-konferenzen-g7.html" target="_blank" rel="noopener noreferrer">NCSC-CH</a>). Organisations in the Geneva–Vaud corridor and Swiss federal/cantonal SOCs should verify DDoS mitigation playbooks, review MFA on customer-facing identity providers, and rotate administrative credentials before the event window.</li></ul>
<ul><li><strong>Gogs argument-injection RCE: still unpatched, Metasploit module public, 319 European instances exposed.</strong> The Rapid7-discovered pull-request-merge argument injection flaw remains unpatched; the Gogs maintainer has been silent since acknowledging receipt on 28 March. The Metasploit module availability means this will appear in opportunistic scan-and-exploit campaigns. Any internet-facing Gogs instance should have open registration disabled and the &quot;Rebase before merging&quot; strategy restricted to trusted owners. (<a href="https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/" target="_blank" rel="noopener noreferrer">Rapid7</a>)</li></ul>
<ul><li><strong>Keycloak 26.6.3 rollout: CVE-2026-9704 token-exchange priv-esc and CVE-2026-4874 SSRF are immediate patch priorities for internet-reachable instances.</strong> Any e-government SSO, SAML federation, or OIDC brokering service running Keycloak &lt; 26.6.3 should complete the upgrade before the G7 event window. (<a href="https://www.keycloak.org/2026/06/keycloak-2663-released" target="_blank" rel="noopener noreferrer">Keycloak</a>; <a href="https://ctipilot.ch/briefs/2026-06-07/" target="_blank" rel="noopener noreferrer">daily 2026-06-07</a>)</li></ul><div class="prov"><span>outlook</span><span>01 Jun 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-06-01/looking-ahead-2026-w23/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.helpnetsecurity.com/2026/06/05/june-2026-patch-tuesday-forecast/" target="_blank" rel="noopener noreferrer">Help Net Security forecast</a> · <a href="https://www.cpomagazine.com/cyber-security/microsoft-doubles-down-on-opposition-to-public-disclosure-as-chaotic-eclipse-wave-of-zero-day-vulnerabilities-continues/" target="_blank" rel="noopener noreferrer">CPO Magazine</a> · <a href="https://www.bankinfosecurity.com/chinese-phishing-service-scams-thousands-fifa-world-cup-fans-a-31819" target="_blank" rel="noopener noreferrer">BankInfoSecurity, 2026-06-05</a> · <a href="https://www.ic3.gov/PSA/2026/PSA260527" target="_blank" rel="noopener noreferrer">FBI IC3 PSA260527</a> · <a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/massnahmen-grossanlaesse-konferenzen-g7.html" target="_blank" rel="noopener noreferrer">NCSC-CH</a> · <a href="https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/" target="_blank" rel="noopener noreferrer">Rapid7</a> · <a href="https://www.keycloak.org/2026/06/keycloak-2663-released" target="_blank" rel="noopener noreferrer">Keycloak</a></div></article><details class="verif"><summary class="vh">About this weekly<span class="verif-count">1 run</span><svg class="verif-chev" viewBox="0 0 24 24" width="12" height="12" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" aria-hidden="true"><path d="M6 9l6 6 6-6"></path></svg></summary><div class="verif-body"><div class="run-note" data-run-id="2026-W23-9118e7bd"><h3 class="run-note__head"><span class="mono">2026-W23-9118e7bd</span> <span class="muted">· weekly · Claude Sonnet 4.6 · 26 entries published</span></h3><div class="run-note__body"><ul><li><strong>Items flagged <code>[SINGLE-SOURCE]</code> from this week:</strong> VerdantBamboo (§7; Volexity primary IR — no independent corroborating source); OP-512 (ReliaQuest primary disclosure, covered 2026-06-06 daily — carried into §4 as context, not a standalone section entry); Sophos 2026 Active Adversary Report (§6; vendor IR telemetry, directionally valid but no independent corroboration); WFP Gaza breach (UpGuard only); SVG phishing MIME evasion (SANS ISC only); SmartApeSG ClickFix chain (SANS ISC only); WeTransfer steganographic loader (SANS ISC only).</li><li><strong>Items dropped from weekly roll-up:</strong> <em>Operation Dragon Weave</em> (China-nexus Czech Republic; covered in detail <a href="https://ctipilot.ch/briefs/2026-06-02/" target="_blank" rel="noopener noreferrer">2026-06-02 daily</a> — no material new development this week); <em>CVE-2022-0492 Linux container escape</em> (KEV re-listing; low novelty for this window&#39;s threat picture); <em>CVE-2026-34906/34907 Wirtualna Uczelnia</em> (CERT-PL, no patch, no new development); <em>Dashlane TOTP brute-force</em> (fewer than 20 vault downloads, limited impact); <em>Operation XENOFISCAL (SideCopy/APT36 Afghan treasury)</em> (covered 2026-06-03 daily — South Asian focus, low direct CH/EU public-sector nexus); <em>Disig Web Signer CVE-2026-8931</em> (covered 2026-06-02 daily, no new development); <em>Apache Solr CVE-2026-44825</em> (covered 2026-06-02 daily, no new development).</li><li><strong>Contradictions:</strong> None unresolved this run.</li><li><strong>Reduced-confidence items:</strong> EU Council TTE June 9 — CSA2/NIS2 progress reports (§8): based on agenda reporting; the formal progress-report document and any Council outcome statement were not yet publicly available at sub-agent research time due to HTTP 403 on Consilium press releases.</li><li><strong>Candidate source from this run:</strong> <code>openssf-policy</code> (OpenSSF EU Policy blog — timely, technically-grounded EU cybersecurity regulatory updates; fills gap between ENISA official publications and practitioner briefings); added as <code>candidate</code> in sources/sources.json.</li><li><strong>Sub-agent models:</strong> W1: Claude Sonnet 4.6 (<code>claude-sonnet-4-6</code>) · W2: Claude Sonnet 4.6 (<code>claude-sonnet-4-6</code>)</li><li><strong>Verification iterations:</strong> 1 (pending at composition time) · <strong>Residuals:</strong> pending</li><li><strong>Coverage gaps:</strong> databreaches-net (persistent HTTP 403, 6+ consecutive runs); inside-it-ch (persistent HTTP 404, 6+ consecutive runs); sophos-xops (HTTP 503, 6+ consecutive runs); group-ib (Cloudflare-blocked); cert-fr-anssi (stale feed, last item October 2025); consilium-europa-eu (HTTP 403 on press-release pages); sec-disclosures-edgar (HTTP 500 on full-text search queries).</li></ul>
<p>— <em>Source: run state · Tags: verification-notes · Region: global</em></p>
<p><em>Migrated from briefs/weekly/2026-W23.md (v2).</em></p></div></div></div></details>]]></content:encoded></item><item><title>CTI Weekly Summary · 2026-W22</title><link>https://ctipilot.ch/weekly/2026-W22/</link><guid isPermaLink="true">https://ctipilot.ch/weekly/2026-W22/</guid><pubDate>Mon, 25 May 2026 05:00:31 +0000</pubDate><dc:date>2026-05-25T05:00:31Z</dc:date><category>CVE-2020-17103</category><category>CVE-2026-0257</category><category>CVE-2026-26980</category><category>CVE-2026-35616</category><category>CVE-2026-4408</category><category>CVE-2026-4480</category><category>CVE-2026-48710</category><category>CVE-2026-48842</category><description><![CDATA[<ul><li><strong>ENISA NIS360 2026 — public administration, health and water sit in the NIS2 &quot;risk zone&quot;.</strong> Strategic horizon — ENISA&#39;s NIS360 puts public administration, health and water in the NIS2 &quot;risk zone&quot;. The sectors a Swiss/EU public-sector SOC most often serves are the ones ENISA flags as under-mature relative to their criticality — a signal of where NIS2 supervisory pressure concentrates next. (ENISA) <a href="https://ctipilot.ch/entries/2026-05-25/enisa-nis360-2026-public-administration-health-and-water-sit/">→</a></li><li><strong>EU 20th-package managed-security-services ban in force from 25 May — Switzerland adopted listings only; MSS prohibition deferred.</strong> Policy — Germany cabinet-approves active-cyber-defence powers while the EU MSS ban goes live and Switzerland defers. The German hackback bill awaits Bundestag passage; the EU&#39;s managed-security-services prohibition is in force from 25 May, but Switzerland adopted listings only — a temporary CH/EU compliance asymmetry. (daily, Bundesregierung) <a href="https://ctipilot.ch/entries/2026-05-25/eu-20th-package-managed-security-services-ban-in-force-from/">→</a></li><li><strong>The Gentlemen / Storm-2697 — internal &quot;Rocket&quot; backend leaked by a rival; KELA and Check Point dissect the operator inner circle.</strong> Most active RaaS exposed — The Gentlemen&#39;s internal database leaked. A rival dumped the operation&#39;s &quot;Rocket&quot; backend; KELA and Check Point analysis exposes the operator inner circle and an initial-access playbook (Fortinet/Cisco edges, NTLM relay, GPO deployment) that maps straight to hunts. (daily, Check Point) <a href="https://ctipilot.ch/entries/2026-05-25/the-gentlemen-storm-2697-internal-rocket-backend-leaked-by-a/">→</a></li><li><strong>Mini Shai-Hulud / TrapDoor — the supply-chain worm goes cross-ecosystem, open-source and destructive.</strong> Supply-chain worm widens — Mini Shai-Hulud goes cross-ecosystem, open-source and destructive. TrapDoor spans npm/PyPI/crates, the framework was open-sourced with a wiper stage, and Maven Central poisoning via mvnpm is now confirmed — one of last week&#39;s two un-hit registries. (daily, Wiz) <a href="https://ctipilot.ch/entries/2026-05-25/mini-shai-hulud-trapdoor-the-supply-chain-worm-goes-cross-ec/">→</a></li><li><strong>CVE-2026-4408 / CVE-2026-4480 — Samba dual unauthenticated RCE (CVSS 10.0), patch window closed mid-week.</strong> On fire — Samba dual unauthenticated RCE (CVSS 10.0), patch window closed mid-week. No ITW confirmation yet, but two pre-auth 10.0 paths in ubiquitous file-sharing software make this the week&#39;s highest-severity race between patching and weaponisation. (daily, Samba) <a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-4408-cve-2026-4480-samba-dual-unauthenticated-rce-c/">→</a></li><li><strong>CVE-2026-35616 — Fortinet FortiClient EMS pre-auth bypass, exploited to push EKZ Infostealer down the management channel.</strong> On fire — FortiClient EMS bypass weaponises the management channel. CVE-2026-35616 is being exploited to push the EKZ Infostealer to managed endpoints disguised as a Fortinet patch — malware over the channel endpoints are built to trust. (daily, Arctic Wolf) <a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-35616-fortinet-forticlient-ems-pre-auth-bypass-expl/">→</a></li><li><strong>CVE-2026-0257 — Palo Alto PAN-OS GlobalProtect pre-auth authentication bypass, exploited in two waves by the same actor.</strong> On fire — PAN-OS GlobalProtect pre-auth bypass exploited in two waves. Palo Alto confirms in-the-wild exploitation of CVE-2026-0257 and Rapid7 ties a second 21 May wave to the same actor; unpatched edge VPNs are an active initial-access vector now. (daily, PAN PSIRT) <a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen/">→</a></li></ul>]]></description><content:encoded><![CDATA[<div class="tldr"><span class="eyebrow eyebrow--muted">Week at a glance</span><ol><li><span class="num">01</span><span><b>ENISA NIS360 2026 — public administration, health and water sit in the NIS2 &quot;risk zone&quot;.</b> Strategic horizon — ENISA&#39;s NIS360 puts public administration, health and water in the NIS2 &quot;risk zone&quot;. The sectors a Swiss/EU public-sector SOC most often serves are the ones ENISA flags as under-mature relative to their criticality — a signal of where NIS2 supervisory pressure concentrates next. (ENISA) <a href="https://ctipilot.ch/entries/2026-05-25/enisa-nis360-2026-public-administration-health-and-water-sit/">→</a></span></li><li><span class="num">02</span><span><b>EU 20th-package managed-security-services ban in force from 25 May — Switzerland adopted listings only; MSS prohibition deferred.</b> Policy — Germany cabinet-approves active-cyber-defence powers while the EU MSS ban goes live and Switzerland defers. The German hackback bill awaits Bundestag passage; the EU&#39;s managed-security-services prohibition is in force from 25 May, but Switzerland adopted listings only — a temporary CH/EU compliance asymmetry. (daily, Bundesregierung) <a href="https://ctipilot.ch/entries/2026-05-25/eu-20th-package-managed-security-services-ban-in-force-from/">→</a></span></li><li><span class="num">03</span><span><b>The Gentlemen / Storm-2697 — internal &quot;Rocket&quot; backend leaked by a rival; KELA and Check Point dissect the operator inner circle.</b> Most active RaaS exposed — The Gentlemen&#39;s internal database leaked. A rival dumped the operation&#39;s &quot;Rocket&quot; backend; KELA and Check Point analysis exposes the operator inner circle and an initial-access playbook (Fortinet/Cisco edges, NTLM relay, GPO deployment) that maps straight to hunts. (daily, Check Point) <a href="https://ctipilot.ch/entries/2026-05-25/the-gentlemen-storm-2697-internal-rocket-backend-leaked-by-a/">→</a></span></li><li><span class="num">04</span><span><b>Mini Shai-Hulud / TrapDoor — the supply-chain worm goes cross-ecosystem, open-source and destructive.</b> Supply-chain worm widens — Mini Shai-Hulud goes cross-ecosystem, open-source and destructive. TrapDoor spans npm/PyPI/crates, the framework was open-sourced with a wiper stage, and Maven Central poisoning via mvnpm is now confirmed — one of last week&#39;s two un-hit registries. (daily, Wiz) <a href="https://ctipilot.ch/entries/2026-05-25/mini-shai-hulud-trapdoor-the-supply-chain-worm-goes-cross-ec/">→</a></span></li><li><span class="num">05</span><span><b>CVE-2026-4408 / CVE-2026-4480 — Samba dual unauthenticated RCE (CVSS 10.0), patch window closed mid-week.</b> On fire — Samba dual unauthenticated RCE (CVSS 10.0), patch window closed mid-week. No ITW confirmation yet, but two pre-auth 10.0 paths in ubiquitous file-sharing software make this the week&#39;s highest-severity race between patching and weaponisation. (daily, Samba) <a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-4408-cve-2026-4480-samba-dual-unauthenticated-rce-c/">→</a></span></li><li><span class="num">06</span><span><b>CVE-2026-35616 — Fortinet FortiClient EMS pre-auth bypass, exploited to push EKZ Infostealer down the management channel.</b> On fire — FortiClient EMS bypass weaponises the management channel. CVE-2026-35616 is being exploited to push the EKZ Infostealer to managed endpoints disguised as a Fortinet patch — malware over the channel endpoints are built to trust. (daily, Arctic Wolf) <a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-35616-fortinet-forticlient-ems-pre-auth-bypass-expl/">→</a></span></li><li><span class="num">07</span><span><b>CVE-2026-0257 — Palo Alto PAN-OS GlobalProtect pre-auth authentication bypass, exploited in two waves by the same actor.</b> On fire — PAN-OS GlobalProtect pre-auth bypass exploited in two waves. Palo Alto confirms in-the-wild exploitation of CVE-2026-0257 and Rapid7 ties a second 21 May wave to the same actor; unpatched edge VPNs are an active initial-access vector now. (daily, PAN PSIRT) <a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen/">→</a></span></li></ol></div><nav class="secnav" aria-label="Sections"><a class="secnav-chip" href="#highest-impact-events-what-s-on-fire-if-no-one-acted">Highest-impact events · what&#39;s on fire if no one acted <span class="secnav-n">4</span></a><a class="secnav-chip" href="#multi-day-campaigns-and-chains">Multi-day campaigns and chains <span class="secnav-n">2</span></a><a class="secnav-chip" href="#vulnerability-roll-up">Vulnerability roll-up <span class="secnav-n">4</span></a><a class="secnav-chip" href="#sector-victim-patterns">Sector &amp; victim patterns <span class="secnav-n">4</span></a><a class="secnav-chip" href="#incidents-disclosures-recap">Incidents &amp; disclosures recap <span class="secnav-n">3</span></a><a class="secnav-chip" href="#annual-periodic-threat-reports">Annual / periodic threat reports <span class="secnav-n">2</span></a><a class="secnav-chip" href="#long-running-campaigns-status-update">Long-running campaigns · status update <span class="secnav-n">6</span></a><a class="secnav-chip" href="#policy-regulatory-horizon">Policy &amp; regulatory horizon <span class="secnav-n">5</span></a><a class="secnav-chip" href="#looking-ahead-what-to-watch-next-week">Looking ahead · what to watch next week <span class="secnav-n">1</span></a></nav><div class="sect" id="highest-impact-events-what-s-on-fire-if-no-one-acted"><span class="n">01</span><span class="t">Highest-impact events · what&#39;s on fire if no one acted</span><span class="c">4 items</span></div><article class="finding entry-card" data-entry-id="2026-05-25/cve-2026-4408-cve-2026-4480-samba-dual-unauthenticated-rce-c" data-tags="vulnerabilities rce pre-auth patch-available" data-regions="global europe switzerland" data-kind="synthesis" data-priority="high" data-discovered="2026-05-25T05:00:03Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-4408/">CVE-2026-4408 +1</a></div><h3 class="f-h" id="cve-2026-4408-cve-2026-4480-samba-dual-unauthenticated-rce-c"><a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-4408-cve-2026-4480-samba-dual-unauthenticated-rce-c/">CVE-2026-4408 / CVE-2026-4480 — Samba dual unauthenticated RCE (CVSS 10.0), patch window closed mid-week</a></h3><p><strong>If you did nothing this week:</strong> unpatched Samba servers expose two unauthenticated remote-code-execution paths rated CVSS <strong>10.0</strong>. There is no public confirmation of in-the-wild exploitation yet — but the disclosure-to-exploit interval on a pre-auth 10.0 in software this ubiquitous is the gap a SOC manager should assume is closing, not open.</p>
<p>The Samba project disclosed (2026-05-27, <a href="https://ctipilot.ch/briefs/2026-05-29/" target="_blank" rel="noopener noreferrer">covered 2026-05-29</a>) that a client-controlled username is passed to the &quot;check password script&quot; without escaping shell metacharacters (CVE-2026-4408) — <strong>this path is reachable only where a <code>check password script</code> (<code>%u</code>) is configured and <code>samba-dcerpcd</code> runs as a service, i.e. a non-default but common enterprise configuration</strong> — alongside a separate unauthenticated RCE in the printing subsystem (CVE-2026-4480), which is reachable where <code>%J</code> is used in the print command (CUPS/IPP backends are unaffected). Both 10.0 paths therefore depend on specific — non-default but common in enterprise estates — print and authentication configurations rather than affecting every install. CERT-FR issued CERTFR-2026-AVI-0651. Samba underpins a large share of public-sector, education and healthcare file-sharing and, in some estates, the AD domain controller. <strong>Patch to the fixed builds; where patching lags, disable the printing path, audit for the <code>check password script</code> setting, and restrict SMB reachability</strong> — this is the week&#39;s highest-severity item where the gap between exposure and compromise is whether the patch landed before someone weaponises a 10.0.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/cve-2026-4408-cve-2026-4480-samba-dual-unauthenticated-rce-c/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.samba.org/samba/security/CVE-2026-4408.html" target="_blank" rel="noopener noreferrer">Samba Project — CVE-2026-4408</a> · <a href="https://www.samba.org/samba/security/CVE-2026-4480.html" target="_blank" rel="noopener noreferrer">Samba Project — CVE-2026-4480</a> · <a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0651/" target="_blank" rel="noopener noreferrer">CERT-FR CERTFR-2026-AVI-0651</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/cve-2026-35616-fortinet-forticlient-ems-pre-auth-bypass-expl" data-tags="vulnerabilities actively-exploited pre-auth auth-bypass cisa-kev infostealer supply-chain" data-regions="europe switzerland global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-25T05:00:01Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-35616/">CVE-2026-35616</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-35616-fortinet-forticlient-ems-pre-auth-bypass-expl"><a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-35616-fortinet-forticlient-ems-pre-auth-bypass-expl/">CVE-2026-35616 — Fortinet FortiClient EMS pre-auth bypass, exploited to push EKZ Infostealer down the management channel</a></h3><p><strong>If you did nothing this week:</strong> an attacker with a working pre-auth bypass against your FortiClient EMS management API can — and per Arctic Wolf, is — modifying Remote Access Profile configurations and injecting malicious PowerShell into every managed endpoint, with the payload disguised as a legitimate Fortinet patch.</p>
<p>Arctic Wolf observed active exploitation of CVE-2026-35616 (CVSS 9.1, <a href="https://ctipilot.ch/briefs/2026-05-29/" target="_blank" rel="noopener noreferrer">first covered 2026-05-29</a>, Fortinet PSIRT FG-IR-26-099, now CISA KEV-listed) in which the EKZ Infostealer was distributed <em>through</em> the trusted endpoint-management plane. This is the operationally important framing for this audience: the malware arrives over the channel the endpoint is built to trust, so signature-trust and &quot;it came from EMS&quot; heuristics fail open. Any public-sector, finance, energy or telco estate running FortiClient EMS should patch, then hunt for unexpected Remote Access Profile changes and PowerShell pushed from the EMS server in the exposure window.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: an attacker with a working pre-auth bypass against your FortiClient EMS management API can — and per Arctic Wolf, is — modifying Remote Access Profile configurations and injecting malicious PowerShell into every managed endpoint, with the payload disguised as a …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/cve-2026-35616-fortinet-forticlient-ems-pre-auth-bypass-expl/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/" target="_blank" rel="noopener noreferrer">Arctic Wolf — EKZ Infostealer campaign</a> · <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099" target="_blank" rel="noopener noreferrer">Fortinet PSIRT FG-IR-26-099</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/cve-2026-26980-ghost-cms-unauthenticated-blind-sql-injection" data-tags="vulnerabilities actively-exploited pre-auth info-disclosure phishing" data-regions="global europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-25T05:00:02Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-26980/">CVE-2026-26980</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-26980-ghost-cms-unauthenticated-blind-sql-injection"><a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-26980-ghost-cms-unauthenticated-blind-sql-injection/">CVE-2026-26980 — Ghost CMS unauthenticated blind SQL injection, mass-exploited into a ClickFix infostealer chain</a></h3><p><strong>If you did nothing this week:</strong> self-hosted Ghost CMS instances are being mass-compromised through an unauthenticated blind SQL injection in the Content API <code>slug</code> filter, then weaponised as ClickFix social-engineering pages that serve infostealers to their own visitors.</p>
<p>XLab (Qianxin) and BleepingComputer document a large-scale campaign exploiting CVE-2026-26980 (CVSS 9.4, <a href="https://ctipilot.ch/briefs/2026-05-25/" target="_blank" rel="noopener noreferrer">first covered 2026-05-25</a>, GitHub advisory GHSA-w52v-v783-gw97). The dual-use is what makes this a §1 item rather than a routine SQLi: the same flaw both compromises the publishing platform and turns it into a watering hole. Public-sector, education and media organisations running self-hosted Ghost should patch to the fixed release and check for ClickFix-style injected content and unexpected database reads against the Content API.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: self-hosted Ghost CMS instances are being mass-compromised through an unauthenticated blind SQL injection in the Content API slug filter, then weaponised as ClickFix social-engineering pages that serve infostealers to their own visitors.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/cve-2026-26980-ghost-cms-unauthenticated-blind-sql-injection/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://github.com/advisories/GHSA-w52v-v783-gw97" target="_blank" rel="noopener noreferrer">GitHub Security Advisory GHSA-w52v-v783-gw97</a> · <a href="https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/" target="_blank" rel="noopener noreferrer">XLab Qianxin, 2026-05-21</a> · <a href="https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-05-24</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen" data-tags="vulnerabilities actively-exploited pre-auth auth-bypass cisa-kev patch-available" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-25T05:00:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-0257/">CVE-2026-0257</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen"><a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen/">CVE-2026-0257 — Palo Alto PAN-OS GlobalProtect pre-auth authentication bypass, exploited in two waves by the same actor</a></h3><p><strong>If you did nothing this week:</strong> internet-exposed PAN-OS GlobalProtect portals without the patch or mitigations applied are being authentication-bypassed now. Palo Alto&#39;s PSIRT confirms &quot;limited exploit attempts on unpatched PAN-OS devices,&quot; and Rapid7 MDR observed a <strong>second exploitation wave on 21 May</strong> that — on a consistent MAC address across both waves — it assesses to be the same threat actor.</p>
<p>The flaw is a pre-auth bypass via certificate reuse in the GlobalProtect authentication path (CVSS 7.8, <a href="https://ctipilot.ch/briefs/2026-05-30/" target="_blank" rel="noopener noreferrer">first covered 2026-05-30</a>). It is now on the CISA KEV catalogue. The CVSS understates the operational severity: a working pre-auth bypass on an edge VPN that fronts the whole estate is an initial-access primitive, and a second wave indicates the actor is iterating rather than spraying once. This item also closes the loop on last week&#39;s PAN-OS watch arc — W21 flagged the wave-2 PAN-OS patch builds as something to watch into this window. <strong>Patch immediately, and audit for attacker-created rogue administrator accounts <em>before</em> patching</strong> — the patch can wipe implant artefacts that would otherwise evidence a prior compromise.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: internet-exposed PAN-OS GlobalProtect portals without the patch or mitigations applied are being authentication-bypassed now.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/cve-2026-0257-palo-alto-pan-os-globalprotect-pre-auth-authen/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://security.paloaltonetworks.com/CVE-2026-0257" target="_blank" rel="noopener noreferrer">Palo Alto Networks PSIRT</a> · <a href="https://www.rapid7.com/blog/post/etr-rapid7-observed-exploitation-of-pan-os-globalprotect-authentication-bypass-vulnerability-cve-2026-0257/" target="_blank" rel="noopener noreferrer">Rapid7 ETR — observed exploitation</a></div></article><div class="sect" id="multi-day-campaigns-and-chains"><span class="n">02</span><span class="t">Multi-day campaigns and chains</span><span class="c">2 items</span></div><article class="finding entry-card" data-entry-id="2026-05-25/mini-shai-hulud-trapdoor-the-supply-chain-worm-goes-cross-ec" data-tags="supply-chain infostealer wiper ai-abuse cryptocrime" data-regions="global europe" data-kind="synthesis" data-priority="high" data-discovered="2026-05-25T05:00:05Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="mini-shai-hulud-trapdoor-the-supply-chain-worm-goes-cross-ec"><a href="https://ctipilot.ch/entries/2026-05-25/mini-shai-hulud-trapdoor-the-supply-chain-worm-goes-cross-ec/">Mini Shai-Hulud / TrapDoor — the supply-chain worm goes cross-ecosystem, open-source and destructive</a></h3><p>The npm-born self-propagating supply-chain worm widened on two axes this week. <strong>TrapDoor</strong> — a cross-ecosystem (npm / PyPI / crates) stealer campaign — was documented validating stolen tokens <em>before</em> exfiltration and poisoning AI-assistant configuration files to persist across developer sessions (<a href="https://ctipilot.ch/briefs/2026-05-26/" target="_blank" rel="noopener noreferrer">2026-05-26</a>). In parallel, the <strong>Mini Shai-Hulud / TeamPCP framework was open-sourced</strong>, a trojanised Microsoft PyPI SDK was shipped with a <strong>wiper stage</strong>, and the operators forged Sigstore provenance badges to launder trust (<a href="https://ctipilot.ch/briefs/2026-05-26/" target="_blank" rel="noopener noreferrer">2026-05-26 update</a>).</p>
<p>Read across the days, the trajectory is the story: the propagation primitive (OIDC-token reuse) is now commoditised, the blast radius spans three major registries, and the payload added a destructive option on top of credential theft. This connects directly to the W21 watch item flagging Cargo and Maven as the un-hit wave-6 candidate registries, and to the npm staged-publishing GA (§ 8) that is the first registry-level structural answer. Pre-stage Sigstore / provenance-anomaly hunts in Rust and Java dependency pipelines and gate internal publishing behind interactive promotion.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/mini-shai-hulud-trapdoor-the-supply-chain-worm-goes-cross-ec/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://socket.dev/blog/trapdoor-crypto-stealer-npm-pypi-crates" target="_blank" rel="noopener noreferrer">Socket — TrapDoor</a> · <a href="https://isc.sans.edu/diary/33016" target="_blank" rel="noopener noreferrer">SANS ISC diary 33016 — Mini Shai-Hulud framework / Microsoft SDK</a> · <a href="https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-05-25</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/ai-tooling-as-lure-attack-surface-and-force-multiplier-the-c" data-tags="ai-abuse phishing infostealer identity cloud" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-25T05:00:06Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="ai-tooling-as-lure-attack-surface-and-force-multiplier-the-c"><a href="https://ctipilot.ch/entries/2026-05-25/ai-tooling-as-lure-attack-surface-and-force-multiplier-the-c/">AI tooling as lure, attack surface and force-multiplier — the cross-day pattern no single daily framed whole</a></h3><p>Five separate daily items this week, each minor on its own, line up into the most important emerging pattern of the window: AI products are now simultaneously a <strong>lure brand</strong>, an <strong>attack surface</strong>, and an <strong>offensive force-multiplier</strong>. As a lure: ACR Stealer was distributed through counterfeit Claude AI download pages promoted by malicious search ads (<a href="https://ctipilot.ch/briefs/2026-05-26/" target="_blank" rel="noopener noreferrer">2026-05-26</a>), and a cryptojacking campaign used <strong>AI-chatbot search-result poisoning</strong> to steer victims to GPU-utility lookalikes that dropped ScreenConnect and process-hollowed miners under a signed Microsoft binary (<a href="https://ctipilot.ch/briefs/2026-05-28/" target="_blank" rel="noopener noreferrer">2026-05-28</a>). As an attack surface: <strong>LLMShare</strong> malvertising hid fake outage pages inside ChatGPT share links to serve infostealers (<a href="https://ctipilot.ch/briefs/2026-05-30/" target="_blank" rel="noopener noreferrer">2026-05-30</a>); <strong>ChatGPhish</strong> abused the ChatGPT Markdown renderer&#39;s trust of third-party image URLs and links for IP exfiltration and phishing from legitimate <code>chatgpt.com</code> (<a href="https://ctipilot.ch/briefs/2026-05-30/" target="_blank" rel="noopener noreferrer">2026-05-30</a>); and Red Canary detailed <strong>Entra Agent ID</strong> privilege escalation, injecting credentials into agent blueprints for tenant-wide lateral movement (<a href="https://ctipilot.ch/briefs/2026-05-30/" target="_blank" rel="noopener noreferrer">2026-05-30</a>). As a force-multiplier: Sysdig TRT documented the <strong>first observed LLM-agent-driven post-exploitation</strong>, moving from a Marimo-notebook RCE (CVE-2026-39987) to internal-database exfiltration in four pivots in under an hour (<a href="https://ctipilot.ch/briefs/2026-05-30/" target="_blank" rel="noopener noreferrer">2026-05-30</a>).</p>
<p>The synthesis for a public-sector SOC: treat AI-brand download and search results as a live malvertising vector (block lookalike domains, prefer vendor-canonical download paths); scope DLP and egress controls to LLM rendering and share endpoints; and govern non-human agent identities (Entra Agent IDs, service-principal-equivalent AI agents) with the same conditional-access and credential-hygiene controls applied to service principals.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/ai-tooling-as-lure-attack-surface-and-force-multiplier-the-c/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/" target="_blank" rel="noopener noreferrer">Microsoft Security Blog — search-poisoning cryptojacking</a> · <a href="https://pushsecurity.com/blog/llmshare-malvertising-campaign" target="_blank" rel="noopener noreferrer">Push Security — LLMShare</a> · <a href="https://permiso.io/blog/chatgpt-markdown-rendering-vulnerability" target="_blank" rel="noopener noreferrer">Permiso Security — ChatGPhish</a> · <a href="https://redcanary.com/blog/threat-detection/entra-id-ai-workflows/" target="_blank" rel="noopener noreferrer">Red Canary — Entra Agent ID</a> · <a href="https://www.sysdig.com/blog/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots" target="_blank" rel="noopener noreferrer">Sysdig TRT — LLM-agent post-exploitation</a></div></article><div class="sect" id="vulnerability-roll-up"><span class="n">03</span><span class="t">Vulnerability roll-up</span><span class="c">4 items</span></div><article class="finding entry-card" data-entry-id="2026-05-25/cve-2026-48842-roundcube-webmail-pre-authentication-sql-inje" data-tags="vulnerabilities pre-auth sqli info-disclosure patch-available" data-regions="europe global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-25T05:00:10Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-48842/">CVE-2026-48842</a></div><h3 class="f-h" id="cve-2026-48842-roundcube-webmail-pre-authentication-sql-inje"><a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-48842-roundcube-webmail-pre-authentication-sql-inje/">CVE-2026-48842 — Roundcube Webmail pre-authentication SQL injection</a></h3><p>Roundcube 1.6.16 / 1.7.1 fixed a pre-authentication SQL injection in the <code>virtuser_query</code> plugin path (CVE-2026-48842, CVSS 8.1, <a href="https://ctipilot.ch/briefs/2026-05-28/" target="_blank" rel="noopener noreferrer">first covered 2026-05-28</a>, with three further fixed CVEs in the same release); NCSC.ch carried it as Security Hub post 12596. Roundcube is the default webmail front-end for a large number of European public-sector, education and hosting deployments, and the pre-auth profile means an attacker needs no mailbox to reach the injection. Patch to the fixed branches and review web logs for anomalous query strings against the login and virtual-user endpoints.</p><div class="prov"><span>vulnerability</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/cve-2026-48842-roundcube-webmail-pre-authentication-sql-inje/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1" target="_blank" rel="noopener noreferrer">Roundcube Project</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12596" target="_blank" rel="noopener noreferrer">NCSC.ch Security Hub post 12596</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/cve-2026-9170-ibm-http-server-websphere-application-server-p" data-tags="vulnerabilities rce pre-auth patch-available" data-regions="europe switzerland global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-25T05:00:08Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-9170/">CVE-2026-9170</a></div><h3 class="f-h" id="cve-2026-9170-ibm-http-server-websphere-application-server-p"><a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-9170-ibm-http-server-websphere-application-server-p/">CVE-2026-9170 — IBM HTTP Server / WebSphere Application Server: pre-auth RCE (CVSS 9.8)</a></h3><p>IBM patched an improper-input-validation flaw in IBM HTTP Server / WebSphere Application Server that allows unauthenticated remote code execution and denial of service (CVSS 9.8, <a href="https://ctipilot.ch/briefs/2026-05-29/" target="_blank" rel="noopener noreferrer">first covered 2026-05-29</a>); NCSC.ch carried it as Security Hub post 12601. WebSphere fronts a large share of public-sector and financial back-office estates, where it is often internet-reachable through reverse proxies — the pre-auth, zero-interaction profile makes this a patch-now item for any CH/EU SOC with WebSphere in the asset inventory. Confirm fix-pack levels against IBM&#39;s bulletin and prioritise externally-reachable instances.</p><div class="prov"><span>vulnerability</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/cve-2026-9170-ibm-http-server-websphere-application-server-p/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ibm.com/support/pages/node/7274065" target="_blank" rel="noopener noreferrer">IBM Security Bulletin node/7274065</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12601" target="_blank" rel="noopener noreferrer">NCSC.ch Security Hub post 12601</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/cve-2026-48710-badhost-starlette-pre-auth-host-header-auth-b" data-tags="vulnerabilities pre-auth auth-bypass poc-public patch-available" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-25T05:00:09Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-48710/">CVE-2026-48710</a></div><h3 class="f-h" id="cve-2026-48710-badhost-starlette-pre-auth-host-header-auth-b"><a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-48710-badhost-starlette-pre-auth-host-header-auth-b/">CVE-2026-48710 &quot;BadHost&quot; — Starlette pre-auth host-header auth bypass across the Python AI/ASGI stack</a></h3><p>X41 D-Sec disclosed (via OSTIF) a pre-authentication authentication bypass in Starlette triggered by a malformed <code>Host</code> header (CVE-2026-48710, CVSS 6.5, <a href="https://ctipilot.ch/briefs/2026-05-30/" target="_blank" rel="noopener noreferrer">first covered 2026-05-30</a>; NCSC-NL NCSC-2026-0171). The reason it earns an H3 despite the medium CVSS is the dependency blast radius: Starlette is the ASGI core under <strong>FastAPI, vLLM, LiteLLM and the MCP Python SDK</strong>, so a single transitive dependency carries the flaw into a large slice of the Python AI-serving and agent tooling that public-sector teams are standing up this year. PoC is public. Pin Starlette to the fixed release across the dependency tree and front affected services with a proxy that normalises or rejects malformed <code>Host</code> headers.</p><div class="prov"><span>vulnerability</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/cve-2026-48710-badhost-starlette-pre-auth-host-header-auth-b/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette/" target="_blank" rel="noopener noreferrer">OSTIF — BadHost disclosure</a> · <a href="https://badhost.org/" target="_blank" rel="noopener noreferrer">X41 / badhost.org</a> · <a href="https://advisories.ncsc.nl/advisory?id=NCSC-2026-0171" target="_blank" rel="noopener noreferrer">NCSC-NL NCSC-2026-0171</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/cve-2026-5426-digital-knowledge-knowledgedeliver-lms-viewsta" data-tags="vulnerabilities actively-exploited rce pre-auth zero-day" data-regions="apac global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-25T05:00:07Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-5426/">CVE-2026-5426</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-5426-digital-knowledge-knowledgedeliver-lms-viewsta"><a href="https://ctipilot.ch/entries/2026-05-25/cve-2026-5426-digital-knowledge-knowledgedeliver-lms-viewsta/">CVE-2026-5426 — Digital Knowledge KnowledgeDeliver LMS: ViewState deserialization RCE exploited as a zero-day</a></h3><p>Google&#39;s Threat Intelligence Group documented active zero-day exploitation of a pre-shared ASP.NET <code>machineKey</code> in the KnowledgeDeliver LMS that enables ViewState deserialization to unauthenticated RCE (<a href="https://ctipilot.ch/briefs/2026-05-26/" target="_blank" rel="noopener noreferrer">first covered 2026-05-26</a>; Mandiant disclosure MNDT-2026-0009). The vulnerable-component lesson generalises well beyond this APAC-deployed product: any .NET web application shipping or reusing a static <code>machineKey</code> across deployments inherits the same ViewState-forgery-to-RCE path. Hunt for unexpected <code>__VIEWSTATE</code> POST bodies that fail MAC validation and for <code>w3wp.exe</code> spawning command interpreters; rotate <code>machineKey</code> values that were ever shared or committed to source.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Google&#39;s Threat Intelligence Group documented active zero-day exploitation of a pre-shared ASP.NET machineKey in the KnowledgeDeliver LMS that enables ViewState deserialization to unauthenticated RCE (first covered 2026-05-26; Mandiant disclosure MNDT-2026-0009).</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/cve-2026-5426-digital-knowledge-knowledgedeliver-lms-viewsta/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/" target="_blank" rel="noopener noreferrer">Google Threat Intelligence Group</a> · <a href="https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2026/MNDT-2026-0009.md" target="_blank" rel="noopener noreferrer">Mandiant Vulnerability Disclosures MNDT-2026-0009</a></div></article><div class="sect" id="sector-victim-patterns"><span class="n">04</span><span class="t">Sector &amp; victim patterns</span><span class="c">4 items</span></div><article class="finding entry-card" data-entry-id="2026-05-25/finance-iberian-retail-banking-pressure-from-grandoreiro-plu" data-tags="organized-crime mobile phishing infostealer" data-regions="europe latam" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-25T05:00:14Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="finance-iberian-retail-banking-pressure-from-grandoreiro-plu"><a href="https://ctipilot.ch/entries/2026-05-25/finance-iberian-retail-banking-pressure-from-grandoreiro-plu/">Finance — Iberian retail-banking pressure from Grandoreiro plus a parallel Android MaaS</a></h3><p>WatchGuard documented a <strong>Grandoreiro</strong> campaign abusing Delphi DLL side-loading across four different software packages, with WebSocket/STUN C2, against banks in Portugal and Spain; ESET mapped a parallel <strong>BTMOB</strong> Android RAT delivered as malware-as-a-service against the same Iberian banking customers via HTML injection and Accessibility Service abuse (<a href="https://ctipilot.ch/briefs/2026-05-29/" target="_blank" rel="noopener noreferrer">2026-05-29</a>). The pattern for EU financial-sector defenders is the desktop-plus-mobile pincer from LATAM-origin operators sustaining European targeting: DLL-side-loading detection on the endpoint and Accessibility-Service-abuse heuristics on managed mobile fleets address the two halves.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/finance-iberian-retail-banking-pressure-from-grandoreiro-plu/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.watchguard.com/wgrd-security-hub/secplicity-blog/grandoreiro-malware-campaign-targets-europe-and-latin-america" target="_blank" rel="noopener noreferrer">WatchGuard — Grandoreiro Europe/LatAm</a> · <a href="https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity — BTMOB</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/healthcare-administrative-and-imaging-intermediaries-remain" data-tags="vulnerabilities data-breach" data-regions="global europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-25T05:00:12Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="healthcare-administrative-and-imaging-intermediaries-remain"><a href="https://ctipilot.ch/entries/2026-05-25/healthcare-administrative-and-imaging-intermediaries-remain/">Healthcare — administrative and imaging intermediaries remain the soft surface</a></h3><p>Healthcare&#39;s exposure this week sat almost entirely in the administrative and imaging layers rather than clinical systems — the same structural lesson W21 drew from the Unimed billing-processor breach. Cisco Talos published a technical tour of the <strong>DICOM-format attack surface against Orthanc PACS</strong>, showing how network-ingested medical images become a heap out-of-bounds-write primitive precisely because PACS systems automatically ingest files received over the network (<a href="https://ctipilot.ch/briefs/2026-05-31/" target="_blank" rel="noopener noreferrer">2026-05-31</a>). France&#39;s <strong>CNIL fined IQVIA Operations France €5M</strong> for health-data-warehouse security failures — no MFA, no log monitoring, no network segmentation (<a href="https://ctipilot.ch/briefs/2026-05-30/" target="_blank" rel="noopener noreferrer">2026-05-30</a>) — a concrete regulatory marker of what &quot;inadequate&quot; looks like for a health-data processor. And California&#39;s AG sued the former <strong>23andMe</strong> over the 2023 genetic-data breach (bulk-enumeration coding error plus absent credential-stuffing defences) affecting ~6.9M customers (<a href="https://ctipilot.ch/briefs/2026-05-31/" target="_blank" rel="noopener noreferrer">2026-05-31</a>). For CH/EU healthcare SOCs: treat auto-ingesting imaging pipelines as an untrusted-input attack surface, and read the IQVIA fine as a checklist of the baseline controls a regulator now expects on a health-data store.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/healthcare-administrative-and-imaging-intermediaries-remain/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.talosintelligence.com/dicom-pydicom-gdcm-and-orthanc-a-technical-tour-of-what-really-happens-in-the-heap/" target="_blank" rel="noopener noreferrer">Cisco Talos — DICOM / Orthanc heap analysis</a> · <a href="https://www.cnil.fr/en/health-data-fine-5-million-euros-against-iqvia" target="_blank" rel="noopener noreferrer">CNIL — €5M IQVIA fine</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/public-administration-identity-ch-dach-lead-the-lms-sso-and" data-tags="vulnerabilities identity auth-bypass pre-auth" data-regions="switzerland dach europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-25T05:00:11Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="public-administration-identity-ch-dach-lead-the-lms-sso-and"><a href="https://ctipilot.ch/entries/2026-05-25/public-administration-identity-ch-dach-lead-the-lms-sso-and/">Public administration &amp; identity (CH / DACH lead) — the LMS, SSO and e-government estate under multi-product pressure</a></h3><p>The week put the public-sector identity and web estate under pressure from several directions at once, with a direct Swiss nexus. <strong>ILIAS LMS</strong> — the open-source learning platform deployed across German and Swiss public-sector and university estates — shipped nine fixes on 2026-05-27 including two critical access-control gaps (CVSS 9.8 and 9.3), with <strong>NCSC.ch flagging the SOAP interface as the primary unauthenticated attack surface</strong> (<a href="https://ctipilot.ch/briefs/2026-05-28/" target="_blank" rel="noopener noreferrer">2026-05-28</a>). In parallel, <strong>Apereo CAS</strong> patched an OIDC-provider flaw that was <strong>reported by Coop Switzerland</strong>, with CERT-FR issuing CERTFR-2026-AVI-0654 (<a href="https://ctipilot.ch/briefs/2026-05-29/" target="_blank" rel="noopener noreferrer">2026-05-29</a>) — relevant to any CH/EU entity running CAS as an OpenID Connect IdP. Further afield in the same estate class, <strong>Lithuania&#39;s Centre of Registers</strong> lost ~600,000 state-register records to abused institutional credentials with a foreign state suspected (<a href="https://ctipilot.ch/briefs/2026-05-27/" target="_blank" rel="noopener noreferrer">2026-05-27</a>), and Poland&#39;s <strong>Szafir SDK</strong> signature-verification bypass (CVE-2026-9058) struck e-government signing (<a href="https://ctipilot.ch/briefs/2026-05-26/" target="_blank" rel="noopener noreferrer">2026-05-26</a>). The cross-cutting takeaway: the contested surface for public administration this week was the <em>identity and document/learning-platform middleware</em> (SOAP endpoints, OIDC providers, signature SDKs), not the citizen-facing front ends.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/public-administration-identity-ch-dach-lead-the-lms-sso-and/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://docu.ilias.de/go/blog/15821" target="_blank" rel="noopener noreferrer">ILIAS Security Blog</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12599" target="_blank" rel="noopener noreferrer">NCSC.ch Security Hub post 12599</a> · <a href="https://apereo.github.io/2026/05/27/oidc-vuln/" target="_blank" rel="noopener noreferrer">Apereo CAS — OIDC disclosure</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/transport-iran-mois-destructive-breach-against-lacmta-with-d" data-tags="nation-state espionage wiper iran-nexus" data-regions="us middle-east" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-25T05:00:13Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="transport-iran-mois-destructive-breach-against-lacmta-with-d"><a href="https://ctipilot.ch/entries/2026-05-25/transport-iran-mois-destructive-breach-against-lacmta-with-d/">Transport — Iran-MOIS destructive breach against LACMTA with deliberate backup and VM destruction</a></h3><p>The window&#39;s standout transport-sector event was destructive, not extortive. Gambit Security attributed the <strong>LACMTA (Los Angeles Metro) breach</strong> to Iran&#39;s MOIS operating behind the &quot;Ababil of Minab&quot; hacktivist front, with ~700 GB exfiltrated and <strong>backups and virtual machines deliberately destroyed</strong> (<a href="https://ctipilot.ch/briefs/2026-05-28/" target="_blank" rel="noopener noreferrer">2026-05-28</a>). The relevance for European public-transit and public-sector defenders is the recovery-planning implication: where the adversary&#39;s objective is destruction rather than ransom, restoration assumes offline / immutable backups and rebuild-from-known-good capacity — controls that an extortion-only threat model under-provisions. The &quot;hacktivist front for state destruction&quot; pattern also complicates attribution and the public-comms response.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/transport-iran-mois-destructive-breach-against-lacmta-with-d/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://gambit.security/blog-posts/babil-of-minab-iran-mois-destruction-campaign" target="_blank" rel="noopener noreferrer">Gambit Security — Ababil of Minab / Iran MOIS</a> · <a href="https://therecord.media/iranian-intelligence-behind-hack-of-la-transit-system" target="_blank" rel="noopener noreferrer">The Record — Iranian intelligence behind LA transit hack</a></div></article><div class="sect" id="incidents-disclosures-recap"><span class="n">05</span><span class="t">Incidents &amp; disclosures recap</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-05-25/asocks-residential-proxy-botnet-dutch-police-ncsc-dismantle" data-tags="law-enforcement botnet organized-crime eu-nexus" data-regions="europe global" data-kind="incident" data-priority="notable" data-discovered="2026-05-25T05:00:17Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="asocks-residential-proxy-botnet-dutch-police-ncsc-dismantle"><a href="https://ctipilot.ch/entries/2026-05-25/asocks-residential-proxy-botnet-dutch-police-ncsc-dismantle/">Asocks residential-proxy botnet — Dutch Police + NCSC dismantle ~17M-device infrastructure hosted in the Netherlands</a></h3><p>The Cybercrime Team of the Police Unit The Hague, with the Dutch NCSC, dismantled a large residential-proxy botnet — at least 17 million compromised consumer devices worldwide, run through ~200 servers all physically hosted in the Netherlands (<a href="https://ctipilot.ch/briefs/2026-05-29/" target="_blank" rel="noopener noreferrer">2026-05-29</a>); NL Times and other reporting identify the service as <strong>Asocks</strong> (the politie.nl primary states the scale and the NL-hosted infrastructure but does not name it). The operationally relevant point is what was hit: residential-proxy services are the anonymisation plumbing that launders credential-stuffing, scraping and fraud traffic to look like ordinary consumer ISP connections, defeating IP-reputation controls. The takedown degrades that capability industry-wide for a period, but — consistent with the W21 takedown pattern — expect infrastructure churn rather than a durable drop; the demand for residential-proxy egress is undiminished.</p><div class="prov"><span>incident</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/asocks-residential-proxy-botnet-dutch-police-ncsc-dismantle/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.politie.nl/nieuws/2026/mei/28/06-politie-en-ncsc-halen-groot-botnetwerk-offline.html" target="_blank" rel="noopener noreferrer">Politie.nl — botnet takedown</a> · <a href="https://nltimes.nl/2026/05/28/ncsc-dutch-police-disrupt-global-botnet-controlled-via-netherlands-based-servers" target="_blank" rel="noopener noreferrer">NL Times</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/uk-visa-portal-100-000-passport-scans-and-selfies-on-a-publi" data-tags="data-breach cloud identity" data-regions="uk europe switzerland" data-kind="incident" data-priority="notable" data-discovered="2026-05-25T05:00:16Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="uk-visa-portal-100-000-passport-scans-and-selfies-on-a-publi"><a href="https://ctipilot.ch/entries/2026-05-25/uk-visa-portal-100-000-passport-scans-and-selfies-on-a-publi/">UK Visa Portal — ~100,000 passport scans and selfies on a public-read S3 bucket behind a government-lookalike site</a></h3><p>TechCrunch found ~100,000 passport scans and applicant selfies exposed on a <strong>public-read Amazon S3 bucket</strong> used by &quot;UK Visa Portal,&quot; a site not affiliated with the UK government that some applicants mistook for the official GOV.UK service; the leak was unfixed at time of reporting (<a href="https://ctipilot.ch/briefs/2026-05-29/" target="_blank" rel="noopener noreferrer">2026-05-29</a>). The defender double-lesson: the technical failure is the oldest cloud-storage misconfiguration in the book (object-level public read on a sensitive bucket), and the social failure is the government-service-lookalike that harvested real identity documents from people who believed they were on an official portal — a brand-protection and citizen-awareness problem for the genuine public-sector body whose service is being impersonated. CH/EU public bodies should monitor for lookalike service domains and re-confirm that no applicant-document storage is world-readable.</p><div class="prov"><span>incident</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/uk-visa-portal-100-000-passport-scans-and-selfies-on-a-publi/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://techcrunch.com/2026/05/27/uk-visa-portal-spilled-thousands-of-applicants-passports-and-selfies-online-and-hasnt-fixed-the-leak/" target="_blank" rel="noopener noreferrer">TechCrunch — UK Visa Portal leak</a> · <a href="https://www.techradar.com/pro/security/uk-visa-portal-website-leaks-thousands-of-user-passport-data-and-photos-online" target="_blank" rel="noopener noreferrer">TechRadar</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/afc-ajax-300-000-fan-accounts-exposed-via-misconfigured-api" data-tags="data-breach law-enforcement identity" data-regions="europe" data-kind="incident" data-priority="notable" data-discovered="2026-05-25T05:00:15Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="afc-ajax-300-000-fan-accounts-exposed-via-misconfigured-api"><a href="https://ctipilot.ch/entries/2026-05-25/afc-ajax-300-000-fan-accounts-exposed-via-misconfigured-api/">AFC Ajax — 300,000+ fan accounts exposed via misconfigured API access control; Dutch suspect arrested</a></h3><p>The Dutch National Police arrested a 35-year-old over the breach of AFC Ajax&#39;s fan app, in which <strong>misconfigured API access control and shared keys</strong> exposed 300,000+ accounts and 42,000 season-ticket records (<a href="https://ctipilot.ch/briefs/2026-05-28/" target="_blank" rel="noopener noreferrer">2026-05-28</a>). Two things make this instructive for this audience: the root cause is a textbook broken-object-level-authorization / over-shared-credential failure in a mobile-app back end — the class of defect that automated DAST and an API-inventory review catch cheaply — and the rapid arrest is a reminder that these cases do sometimes attribute to an individual rather than an organised crew. Re-audit API authorization on customer/citizen-facing apps for object-level checks, and retire shared API keys in favour of per-client credentials.</p><div class="prov"><span>incident</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/afc-ajax-300-000-fan-accounts-exposed-via-misconfigured-api/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/dutch-police-arrests-suspect-linked-to-ajax-football-club-hack/" target="_blank" rel="noopener noreferrer">BleepingComputer — Dutch police arrest</a> · <a href="https://therecord.media/dutch-police-arrest-man-over-cyber-breach-ajax-football" target="_blank" rel="noopener noreferrer">The Record</a> · <a href="https://english.ajax.nl/articles/information-about-data-breach-at-ajax/" target="_blank" rel="noopener noreferrer">AFC Ajax statement</a></div></article><div class="sect" id="annual-periodic-threat-reports"><span class="n">06</span><span class="t">Annual / periodic threat reports</span><span class="c">2 items</span></div><article class="finding entry-card" data-entry-id="2026-05-25/check-point-q1-2026-state-of-ransomware-ecosystem-reconsolid" data-tags="ransomware organized-crime" data-regions="global europe" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-25T05:00:19Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="check-point-q1-2026-state-of-ransomware-ecosystem-reconsolid"><a href="https://ctipilot.ch/entries/2026-05-25/check-point-q1-2026-state-of-ransomware-ecosystem-reconsolid/">Check Point Q1 2026 State of Ransomware — ecosystem reconsolidates; LockBit returns with a deliberate Europe pivot</a></h3><p>Horizon research surfaced a quarterly report the dailies did not cover: Check Point&#39;s Q1 2026 State of Ransomware (published 2026-05-11). The synthesis that matters for a CH/EU public-sector SOC is structural, not the leaderboard: after two years of fragmentation driven by law-enforcement pressure on LockBit, ALPHV/BlackCat and others, <strong>the ecosystem is reconsolidating — the top ten leak-site operations now account for roughly 71% of listed victims</strong>, with Qilin holding the top spot for a third straight quarter and <strong>The Gentlemen (§ 7) entering the top three</strong>. The single most defender-relevant finding is <strong>LockBit&#39;s comeback paired with a deliberate geographic shift toward European and Latin American targets</strong> — which moves the rebuilt operation directly into this audience&#39;s threat model rather than leaving it a US-centric concern. Read alongside the Gentlemen internal-leak intelligence in § 7, the picture is a smaller number of higher-capability operations with European intent; prioritise the edge-appliance and identity hardening those operators are documented to rely on.</p><div class="prov"><span>annual-report</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/check-point-q1-2026-state-of-ransomware-ecosystem-reconsolid/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/" target="_blank" rel="noopener noreferrer">Check Point Research — Q1 2026 State of Ransomware</a> · <a href="https://blog.checkpoint.com/research/q1-2026-ransomware-report-fewer-groups-higher-impact/" target="_blank" rel="noopener noreferrer">Check Point Blog — fewer groups, higher impact</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/eset-apt-activity-report-q4-2025-q1-2026-three-state-program" data-tags="nation-state espionage supply-chain russia-nexus north-korea-nexus china-nexus" data-regions="europe global" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-25T05:00:18Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eset-apt-activity-report-q4-2025-q1-2026-three-state-program"><a href="https://ctipilot.ch/entries/2026-05-25/eset-apt-activity-report-q4-2025-q1-2026-three-state-program/">ESET APT Activity Report Q4 2025–Q1 2026 — three state programmes converging on EU energy, defence and edge appliances</a></h3><p>ESET&#39;s APT Activity Report covering Q4 2025–Q1 2026 landed mid-window (<a href="https://ctipilot.ch/briefs/2026-05-30/" target="_blank" rel="noopener noreferrer">first covered 2026-05-30</a>). The daily recapped the headline findings — a rare out-of-Ukraine Sandworm destructive incident (a medium-confidence December 2025 attack on a single Polish energy company), Lazarus targeting the EU drone/defence sector, and UNC5221 pivoting to the Ivanti SPAWN toolset. The synthesis a daily reader could not see from those three bullets is that they are the <em>same story told by three different state programmes</em>: Russia-, North-Korea- and China-nexus operators are independently converging on (a) European energy and <strong>defence-industrial-base supply chains</strong> as the target set — Sandworm&#39;s move against a Polish energy target being notable precisely because the operator rarely acts destructively outside Ukraine — and (b) <strong>internet-facing edge appliances</strong> (Ivanti) as the entry vector. For a Swiss / European public-sector SOC the implication is a prioritisation argument rather than a new IOC list: edge-appliance patch SLAs and defence-supplier third-party-risk review are where all three programmes are applying pressure simultaneously, so they should outrank generic campaign awareness in the next planning cycle. The report reinforces, with cross-actor telemetry, the structural shift the W21 Verizon DBIR and Rapid7 reports flagged — exploitation of exposed software as the dominant access vector.</p><div class="prov"><span>annual-report</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/eset-apt-activity-report-q4-2025-q1-2026-three-state-program/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity — APT Activity Report Q4 2025–Q1 2026</a> · <a href="https://www.infosecurity-magazine.com/news/chinese-hackers-exploit-iran-war/" target="_blank" rel="noopener noreferrer">Infosecurity Magazine</a></div></article><div class="sect" id="long-running-campaigns-status-update"><span class="n">07</span><span class="t">Long-running campaigns · status update</span><span class="c">6 items</span></div><article class="finding entry-card" data-entry-id="2026-05-25/the-gentlemen-storm-2697-internal-rocket-backend-leaked-by-a" data-tags="ransomware organized-crime identity" data-regions="europe switzerland global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-25T05:00:20Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="the-gentlemen-storm-2697-internal-rocket-backend-leaked-by-a"><a href="https://ctipilot.ch/entries/2026-05-25/the-gentlemen-storm-2697-internal-rocket-backend-leaked-by-a/">The Gentlemen / Storm-2697 — internal &quot;Rocket&quot; backend leaked by a rival; KELA and Check Point dissect the operator inner circle</a></h3><p>The most consequential campaign development of the window is one no daily captured: on 2026-05-04 a rival actor leaked The Gentlemen&#39;s internal <strong>Rocket</strong> database backend on underground forums, and KELA (2026-05-20) and Check Point (&quot;Thus Spoke The Gentlemen&quot;, 2026-05-13) published deep analyses of the resulting six-month (Nov 2025 – Apr 2026) chat archive (<code>key: item:the-gentlemen-raas-czech-university-and-swiss-engineering-fi</code>). The leak exposes the inner circle (admin/infrastructure alias <strong>zeta88</strong>, also operating as <strong>hastalamuerte</strong>, alongside Wick, mAst3r, Kunder and others) and — far more useful to defenders — the operation&#39;s <strong>initial-access playbook</strong>: Fortinet and Cisco edge appliances, NTLM relay, harvested OWA / M365 credential logs, and <strong>GPO-based deployment</strong> of the encryptor. A linked affiliate runs a SystemBC SOCKS5 botnet of 1,570+ victims. This is an intelligence gift: every named access path maps to an existing hunt — prioritise edge-appliance patch state, NTLM-relay hardening (SMB/LDAP signing, channel binding) and anomalous-GPO-creation monitoring. Per Check Point&#39;s Q1 data the group sits at #3 globally (§ 6) — though its victims concentrate in Thailand, Brazil and India (US ~13%), so the European and Swiss listings carried over from W21 run <em>against</em> its centre of gravity, which is precisely what makes a CH/EU hit worth surfacing rather than treating as background.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/the-gentlemen-storm-2697-internal-rocket-backend-leaked-by-a/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/" target="_blank" rel="noopener noreferrer">Check Point Research — Thus Spoke The Gentlemen</a> · <a href="https://www.kelacyber.com/blog/the-gentlemen-ransomware-internal-chat-leak-analysis-2026/" target="_blank" rel="noopener noreferrer">KELA — internal chat-leak analysis</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/greyvibe-independent-corroboration-opsec-slips-enabled-attri" data-tags="nation-state espionage russia-nexus ai-abuse phishing" data-regions="europe russia-cis" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-25T05:00:25Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="greyvibe-independent-corroboration-opsec-slips-enabled-attri"><a href="https://ctipilot.ch/entries/2026-05-25/greyvibe-independent-corroboration-opsec-slips-enabled-attri/">GREYVIBE — independent corroboration; OPSEC slips enabled attribution; charity-front sub-campaign</a></h3><p>The Russia-nexus GREYVIBE cluster (2026-05-30 daily) gained independent in-window corroboration from SecurityWeek and Security Affairs of the original WithSecure Labs disclosure. The added detail: despite heavy AI integration in lure generation, the operators left <strong>Russian-language code comments and Moscow-timezone activity patterns</strong> that enabled attribution, and the <strong>PrincessClub</strong> sub-campaign masqueraded as Ukrainian-Armed-Forces charitable foundations (FPV-drone / UAV support) to harvest credentials. No expansion beyond Ukrainian targets was found. For CH/EU bodies with Ukraine-linked engagements, the relevant control is spear-phishing scrutiny on charity/fundraising lures referencing military support.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/greyvibe-independent-corroboration-opsec-slips-enabled-attri/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://labs.withsecure.com/publications/greyvibe" target="_blank" rel="noopener noreferrer">WithSecure Labs — GREYVIBE</a> · <a href="https://www.securityweek.com/russia-linked-greyvibe-attackers-use-ai-to-supercharge-cyberattacks/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/unc6671-blackfile-gtig-publishes-the-full-profile-group-anno" data-tags="organized-crime identity phishing" data-regions="global europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-25T05:00:24Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="unc6671-blackfile-gtig-publishes-the-full-profile-group-anno"><a href="https://ctipilot.ch/entries/2026-05-25/unc6671-blackfile-gtig-publishes-the-full-profile-group-anno/">UNC6671 / BlackFile — GTIG publishes the full profile; group announced shutdown &quot;under this name&quot;, rebrand probable</a></h3><p>Resolving a W21 carry-forward watch item: GTIG published a definitive <strong>UNC6671 / BlackFile</strong> profile in mid-May 2026, characterising the operation as an <strong>adversary-in-the-middle vishing specialist</strong> targeting Microsoft 365 and Okta SSO environments in retail and hospitality (vishing impersonating IT support → MFA-bypass / credential grant → AiTM session-token harvest → exfiltration → extortion over the Session messenger). The leak-site went offline in late April, briefly resumed on 2026-05-11 to announce &quot;BlackFile is shutting down… <strong>under this name</strong>,&quot; and went dark again — GTIG&#39;s phrasing and the qualifier point to a <strong>probable rebrand</strong> rather than a genuine exit. Defenders should keep the AiTM-vishing → rogue-MFA → SSO-token-theft TTP set on watch under any new brand; the tradecraft, not the name, is the durable indicator.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/unc6671-blackfile-gtig-publishes-the-full-profile-group-anno/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation" target="_blank" rel="noopener noreferrer">Google Cloud / GTIG — BlackFile vishing-extortion operation</a> · <a href="https://cyberscoop.com/blackfile-data-theft-extortion-retail-unit-42-rh-isac/" target="_blank" rel="noopener noreferrer">CyberScoop</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/shinyhunters-salesforce-campaign-40-listed-victims-canada-li" data-tags="data-breach organized-crime identity" data-regions="us uk europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-25T05:00:22Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="shinyhunters-salesforce-campaign-40-listed-victims-canada-li"><a href="https://ctipilot.ch/entries/2026-05-25/shinyhunters-salesforce-campaign-40-listed-victims-canada-li/">ShinyHunters Salesforce campaign — 40+ listed victims; Canada Life and Pitney Bowes confirm; the BreachForums extortion channel was previously seized</a></h3><p>Complementing the § 2 victim arc, horizon research confirms the campaign now lists <strong>40+ confirmed or claimed victims</strong> (<code>key: item:shinyhunters-salesforce-campaign-charter-and-7-eleven-both-c</code>), with <strong>Canada Life</strong> (insurance carrier, UK/Ireland) and <strong>Pitney Bowes</strong> confirming breaches in the window, and Canvas/Instructure reported to have paid ransom on 2026-05-12. The relevant law-enforcement context: the FBI and France&#39;s BL2C previously seized the ShinyHunters-operated BreachForums portal that served as the campaign&#39;s extortion channel (2025-10-10), which briefly interrupted operations before the group rebuilt — a reminder that channel seizures slow but do not stop a credential-extortion operation with this many active victims. No leadership arrests. The unchanged defender action is connected-app OAuth-scope and refresh-token review.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/shinyhunters-salesforce-campaign-40-listed-victims-canada-li/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/fbi-takes-down-breachforums-portal-used-for-salesforce-extortion/" target="_blank" rel="noopener noreferrer">BleepingComputer — FBI seizes BreachForums extortion portal</a> · <a href="https://www.scworld.com/brief/multiple-other-companies-purportedly-breached-by-shinyhunters-over-9m-record-leak-warned" target="_blank" rel="noopener noreferrer">SC Media — expanded victim list</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/mini-shai-hulud-teampcp-antv-npm-wave-and-confirmed-maven-ce" data-tags="supply-chain infostealer identity cloud" data-regions="global europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-25T05:00:21Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="mini-shai-hulud-teampcp-antv-npm-wave-and-confirmed-maven-ce"><a href="https://ctipilot.ch/entries/2026-05-25/mini-shai-hulud-teampcp-antv-npm-wave-and-confirmed-maven-ce/">Mini Shai-Hulud / TeamPCP — @antv npm wave and confirmed Maven Central poisoning; Cargo still un-hit</a></h3><p>Beyond the in-window TrapDoor and framework-open-sourcing covered in § 2, horizon research surfaced a development the dailies missed. Wiz documented a fresh wave (2026-05-19) in which TeamPCP hijacked a legitimate maintainer account to poison the <strong>@antv</strong> data-visualisation ecosystem on npm (@antv/g2, g6, x6, l7 and others, collectively millions of weekly downloads), running the standard Mini Shai-Hulud credential-harvest against GitHub/npm tokens and cloud keys across 80+ file paths. OX Security and Security Affairs documented copycat clones spreading after the source-code leak. On the W21 watch list of un-hit registries: npm remains the only ecosystem with a primary-confirmed poisoning this wave — horizon research flagged unverified secondary reporting of Maven Central exposure via the <code>mvnpm</code> npm-to-Maven bridge, but this run could not corroborate it against a primary source, so it is <strong>not asserted</strong> here, and Cargo / crates.io status is likewise unverified. No GovCERT.ch / NCSC.ch developer advisory was found. Keep the provenance-anomaly hunt centred on npm and treat the <code>mvnpm</code> bridge as a plausible next vector to watch.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/mini-shai-hulud-teampcp-antv-npm-wave-and-confirmed-maven-ce/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain" target="_blank" rel="noopener noreferrer">Wiz Research — Mini Shai-Hulud hits @antv</a> · <a href="https://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here/" target="_blank" rel="noopener noreferrer">OX Security — TeamPCP copycats</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/chaotic-eclipse-nightmare-eclipse-miniplasma-confirmed-syste" data-tags="vulnerabilities zero-day lpe no-patch poc-public" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-25T05:00:23Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2020-17103/">CVE-2020-17103</a></div><h3 class="f-h" id="chaotic-eclipse-nightmare-eclipse-miniplasma-confirmed-syste"><a href="https://ctipilot.ch/entries/2026-05-25/chaotic-eclipse-nightmare-eclipse-miniplasma-confirmed-syste/">Chaotic Eclipse / Nightmare Eclipse — MiniPlasma confirmed SYSTEM on a fully-patched Windows 11; sixth zero-day in six weeks</a></h3><p>The Windows zero-day cluster carried a material technical update beyond the 2026-05-30 daily. <strong>MiniPlasma</strong> — the sixth zero-day the &quot;Chaotic Eclipse&quot; researcher has dropped in six weeks — is a local privilege escalation in the Windows Cloud Filter driver (<code>cldflt.sys</code>) that reuses <strong>CVE-2020-17103</strong>, the researcher claiming the 2020 patch was incomplete or partially reverted. <strong>ThreatLocker independently confirmed MiniPlasma achieves SYSTEM on a fully-patched Windows 11 running the May 2026 cumulative update</strong> — i.e. there is no configuration that closes it today. Three earlier drops in the series (BlueHammer, RedSun, UnDefend) have been observed in real attacks. Microsoft&#39;s DCU has called the uncoordinated releases &quot;never justifiable&quot; but has shipped no out-of-band fix; <strong>June 10 Patch Tuesday is the first fix opportunity</strong> (. Until then, treat any <code>cldflt.sys</code>-adjacent LPE as live.</p><div class="prov"><span>synthesis</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/chaotic-eclipse-nightmare-eclipse-miniplasma-confirmed-syste/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/microsoft/new-windows-miniplasma-zero-day-exploit-gives-system-access-poc-released/" target="_blank" rel="noopener noreferrer">BleepingComputer — MiniPlasma zero-day PoC</a> · <a href="https://www.threatlocker.com/blog/miniplasma-windows-privilege-escalation-zero-day-affects-fully-patched-systems" target="_blank" rel="noopener noreferrer">ThreatLocker — exploitation on fully-patched systems</a></div></article><div class="sect" id="policy-regulatory-horizon"><span class="n">08</span><span class="t">Policy &amp; regulatory horizon</span><span class="c">5 items</span></div><article class="finding entry-card" data-entry-id="2026-05-25/enisa-nis360-2026-public-administration-health-and-water-sit" data-tags="eu-nexus" data-regions="europe" data-kind="policy" data-priority="high" data-discovered="2026-05-25T05:00:28Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="enisa-nis360-2026-public-administration-health-and-water-sit"><a href="https://ctipilot.ch/entries/2026-05-25/enisa-nis360-2026-public-administration-health-and-water-sit/">ENISA NIS360 2026 — public administration, health and water sit in the NIS2 &quot;risk zone&quot;</a></h3><p>ENISA published its third annual <strong>NIS360</strong> sectoral-maturity assessment on 2026-05-28, scoring all 18 NIS2 Annex I high-criticality sectors on legislation effectiveness, organisational preparedness, authority capacity and ecosystem maturity. The <strong>risk-zone</strong> sectors — criticality exceeding maturity — are <strong>health, railway (newly entered), maritime, ICT management services, space, public administrations, drinking water (newly entered) and wastewater (newly entered)</strong>; gas exited after targeted investment. Trust services, aviation and financial-market infrastructures sit in the higher-maturity band, while banking, electricity and telecom are scored among the most critical sectors. The defender-relevant read for this audience: the sectors a Swiss/EU public-sector SOC most often <em>is</em> or <em>serves</em> — public administration, health, water — are precisely the ones ENISA flags as under-resourced relative to their societal importance, which signals where NIS2 supervisory and investment pressure will concentrate next. Use the report as leverage for sector-specific funding and as a benchmark for the maturity axes your own programme is weakest on.</p><div class="prov"><span>policy</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/enisa-nis360-2026-public-administration-health-and-water-sit/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.enisa.europa.eu/news/nis360-the-bigger-picture-on-maturity-and-criticality-of-nis-critical-sectors" target="_blank" rel="noopener noreferrer">ENISA — NIS360 2026 analysis</a> · <a href="https://www.enisa.europa.eu/enisa-nis360-2026" target="_blank" rel="noopener noreferrer">ENISA — NIS360 2026 publication</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/eu-20th-package-managed-security-services-ban-in-force-from" data-tags="law-enforcement russia-nexus eu-nexus" data-regions="europe switzerland" data-kind="policy" data-priority="high" data-discovered="2026-05-25T05:00:27Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="eu-20th-package-managed-security-services-ban-in-force-from"><a href="https://ctipilot.ch/entries/2026-05-25/eu-20th-package-managed-security-services-ban-in-force-from/">EU 20th-package managed-security-services ban in force from 25 May — Switzerland adopted listings only; MSS prohibition deferred</a></h3><p>Resolving the open W21 compliance question. The EU&#39;s 20th Russia sanctions package introduced — <strong>effective 25 May 2026</strong> — a prohibition on providing <strong>managed security services</strong> (cybersecurity risk management, incident handling, penetration testing, security audits and related consulting) to the Russian government and Russian-established entities, extending to Russian subsidiaries of EU-incorporated companies absent a national-competent-authority licence. No European Commission interpretive guidance on the MSS scope had been published by end-May, so a conservative reading still applies. The Swiss answer is now confirmed: <strong>Switzerland&#39;s 22 May adoption covered the listings only — the substantive measures, including the MSS prohibition, were deferred</strong> (reporting points to a summer timeline). The practical consequence is a <strong>temporary CH/EU asymmetry</strong>: an EU-incorporated MSSP is already barred from servicing a Russian-established client, while the equivalent Swiss obligation is not yet in domestic force. Cross-border CH firms with EU entities should govern to the stricter EU line now rather than the Swiss timeline, and re-confirm no EDR/SIEM/connector service is operated under contract with a Russian-established entity.</p><div class="prov"><span>policy</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/eu-20th-package-managed-security-services-ban-in-force-from/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://sanctionsnews.bakermckenzie.com/swiss-government-partially-implements-the-20th-eu-sanctions-package/" target="_blank" rel="noopener noreferrer">Baker McKenzie — Switzerland partially implements the 20th EU package</a> · <a href="https://www.gtlaw.com/en/insights/2026/5/eus-20th-russia-sanctions-package-key-changes-and-compliance-implications" target="_blank" rel="noopener noreferrer">Greenberg Traurig — 20th package compliance implications</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/data-protection-enforcement-converges-on-a-health-data-contr" data-tags="data-breach law-enforcement" data-regions="europe us" data-kind="policy" data-priority="notable" data-discovered="2026-05-25T05:00:30Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="data-protection-enforcement-converges-on-a-health-data-contr"><a href="https://ctipilot.ch/entries/2026-05-25/data-protection-enforcement-converges-on-a-health-data-contr/">Data-protection enforcement converges on a health-data controls floor — CNIL fines IQVIA €5M; California AG sues over 23andMe</a></h3><p>Two enforcement actions in the window set the same baseline expectation for sensitive-data controllers. <strong>CNIL</strong> issued Délibération <strong>SAN-2026-008</strong> (26 May), fining <strong>IQVIA Operations France €5M</strong> for security failures across its two authorised health-data warehouses — <strong>no MFA on privileged access to the EMR warehouse, and no log monitoring to detect abnormal activity in either warehouse</strong>, both cited explicitly as GDPR Art. 32 failures — with a six-month injunction under a €10,000/day coercive penalty. In parallel, the <strong>California AG</strong> sued the former <strong>23andMe</strong> (28 May) over the 2023 genetic-data breach affecting ~6.9M people, alleging a bulk-enumeration coding error plus <strong>absent credential-stuffing defences and absent MFA</strong>. The convergence is the message: regulators on both sides of the Atlantic are now treating <strong>MFA on privileged access and active log monitoring as a non-negotiable floor</strong> for health and genomic data, and pricing their absence directly. CH/EU health-data controllers should read both as a concrete control checklist, not distant precedent.</p><div class="prov"><span>policy</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/data-protection-enforcement-converges-on-a-health-data-contr/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cnil.fr/en/health-data-fine-5-million-euros-against-iqvia" target="_blank" rel="noopener noreferrer">CNIL — €5M IQVIA fine</a> · <a href="https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000054136834" target="_blank" rel="noopener noreferrer">Légifrance — Délibération SAN-2026-008</a> · <a href="https://oag.ca.gov/news/press-releases/attorney-general-bonta-sues-chrome-holding-co-formerly-known-23andme-over-2023" target="_blank" rel="noopener noreferrer">California AG — Bonta sues Chrome Holding Co.</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/eu-cyber-resilience-act-11-june-notifying-authority-deadline" data-tags="eu-nexus vulnerabilities" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-25T05:00:29Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eu-cyber-resilience-act-11-june-notifying-authority-deadline"><a href="https://ctipilot.ch/entries/2026-05-25/eu-cyber-resilience-act-11-june-notifying-authority-deadline/">EU Cyber Resilience Act — 11 June notifying-authority deadline, then September reporting obligations</a></h3><p>The Cyber Resilience Act reaches its first hard operational milestones. <strong>By 11 June 2026</strong> (Chapter IV entry into application) member states must designate the national notifying authorities that assess and register conformity-assessment bodies for products with digital elements in the &quot;important&quot; and &quot;critical&quot; classes; until enough CABs are notified into NANDO (expected through December 2026), third-party conformity assessment cannot proceed at scale. <strong>From 11 September 2026</strong> the Article 14 reporting obligations begin — manufacturers must report actively-exploited vulnerabilities and severe incidents via the ENISA Single Reporting Platform. For public-sector procurement teams this is a near-term planning input: factor CRA conformity status into product-selection criteria now, because the certification pipeline it depends on is only just being stood up.</p><div class="prov"><span>policy</span><span>25 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/eu-cyber-resilience-act-11-june-notifying-authority-deadline/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://digital-strategy.ec.europa.eu/en/factpages/cyber-resilience-act-implementation" target="_blank" rel="noopener noreferrer">European Commission — CRA implementation factpage</a></div></article><article class="finding entry-card" data-entry-id="2026-05-25/germany-s-cybersicherheitsst-rkungsgesetz-federal-cabinet-ap" data-tags="law-enforcement eu-nexus" data-regions="dach europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-25T05:00:26Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="germany-s-cybersicherheitsst-rkungsgesetz-federal-cabinet-ap"><a href="https://ctipilot.ch/entries/2026-05-25/germany-s-cybersicherheitsst-rkungsgesetz-federal-cabinet-ap/">Germany&#39;s Cybersicherheitsstärkungsgesetz — federal cabinet approves active-cyber-defence powers; Bundestag passage still ahead</a></h3><p>The German federal cabinet approved the <strong>Cybersicherheitsstärkungsgesetz</strong> (Cyber Security Strengthening Act) on 2026-05-27 — the daily caught the Heise news hit; the primary government sources confirm the substance and, importantly, that it is <strong>a draft bill still requiring Bundestag passage and is not yet in force</strong>. Per the government&#39;s framing, it shifts the state from purely defending the target to acting directly against the attacker — &quot;their servers, their software and their strategy&quot; — with the <strong>BSI</strong>, <strong>BKA</strong> and <strong>Bundespolizei</strong> among the bodies gaining expanded authority to detect and counter large-scale, high-damage attacks (the announcement does not break the new powers down per agency in technical detail). For CH/EU defenders the watch item is the <strong>cross-border incident-response implication</strong>: once in force, German-authority active operations against infrastructure that may be hosted in or transit other jurisdictions raise coordination and deconfliction questions for any SOC running IR across the DACH region. Track the Bundestag passage; nothing changes operationally until it lands.</p><div class="prov"><span>policy</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/germany-s-cybersicherheitsst-rkungsgesetz-federal-cabinet-ap/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bundesregierung.de/breg-en/news/strengthening-cyber-security-2433588" target="_blank" rel="noopener noreferrer">Bundesregierung — Strengthening cyber security (EN)</a> · <a href="https://www.bundesregierung.de/breg-de/aktuelles/staerkung-cybersicherheit-2432588" target="_blank" rel="noopener noreferrer">Bundesregierung — Stärkung der Cybersicherheit (DE)</a></div></article><div class="sect" id="looking-ahead-what-to-watch-next-week"><span class="n">09</span><span class="t">Looking ahead · what to watch next week</span><span class="c">1 item</span></div><article class="finding entry-card" data-entry-id="2026-05-25/looking-ahead-2026-w22" data-tags="zero-day cloud rce phishing wiper" data-regions="global" data-kind="outlook" data-priority="notable" data-discovered="2026-05-25T05:00:31Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="looking-ahead-2026-w22"><a href="https://ctipilot.ch/entries/2026-05-25/looking-ahead-2026-w22/">Looking ahead — 2026-W22</a></h3><p>Items already in motion at the close of 2026-W22. Not predictions — each links to the in-motion reporting underneath.</p>
<ul><li><strong>Windows &quot;Chaotic Eclipse&quot; zero-day cluster — June 2026 Patch Tuesday (~2026-06-10) is the expected first fix, with a researcher drop announced for July 14.</strong> Microsoft&#39;s Digital Crimes Unit has threatened criminal action over the serial zero-day releases, but the cluster&#39;s escalation paths remain unpatched with public PoCs — <strong>YellowKey</strong> (CVE-2026-45585), <strong>GreenPlasma</strong>, and <strong>MiniPlasma</strong> (CVE-2020-17103, the <code>cldflt.sys</code> Cloud Filter driver, whose 2020 patch the researcher claims is incomplete) — and the researcher has announced more for <strong>July 14</strong>. Until a fix ships, BitLocker PIN / Network-Unlock GPOs and <code>ctfmon.exe</code>-injection WDAC rules are the available controls. (<a href="https://therecord.media/microsoft-calls-zero-day-releases-never-justifiable-as-researcher-threatens-more" target="_blank" rel="noopener noreferrer">The Record</a>; <a href="https://ctipilot.ch/briefs/2026-05-30/" target="_blank" rel="noopener noreferrer">Daily 2026-05-30</a>)</li><li><strong>Gogs argument-injection RCE remains unpatched with a public Metasploit module and a non-responsive maintainer.</strong> Rapid7 published the unfixed authenticated-RCE-via-argument-injection with exploit code; with no vendor fix in sight, the only mitigation is keeping Gogs off the public internet behind authenticated access and watching for the maintainer&#39;s response. (<a href="https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/" target="_blank" rel="noopener noreferrer">Rapid7</a>; <a href="https://ctipilot.ch/briefs/2026-05-29/" target="_blank" rel="noopener noreferrer">Daily 2026-05-29</a>)</li><li><strong>FIFA World Cup phishing ramps toward the June 11 kickoff — &quot;Ghost Stadium&quot; PhaaS.</strong> 300+ FIFA domain clones with multi-language fake SSO are already harvesting UK / Germany / Portugal / Spain fan credentials; the FBI IC3 PSA flags continued growth as the tournament approaches. Expect a volume spike in the next fortnight; brief staff and monitor for lookalike-domain credential-harvest landing pages. (<a href="https://www.ic3.gov/PSA/2026/PSA260527" target="_blank" rel="noopener noreferrer">FBI IC3 PSA260527</a>; <a href="https://ctipilot.ch/briefs/2026-05-30/" target="_blank" rel="noopener noreferrer">Daily 2026-05-30</a>)</li><li><strong>Delta Electronics DIAView SCADA CVE-2026-9642 has no patch — incomplete fix for prior unauthenticated remote database access.</strong> Tenable&#39;s disclosure shows the earlier CVE-2025-62582 fix was incomplete; watch for a complete vendor patch and keep DIAView off internet-reachable networks in the interim. (<a href="https://www.tenable.com/security/research/tra-2026-44" target="_blank" rel="noopener noreferrer">Tenable TRA-2026-44</a>; <a href="https://ctipilot.ch/briefs/2026-05-27/" target="_blank" rel="noopener noreferrer">Daily 2026-05-27</a>)</li><li><strong>Shai-Hulud wave-6 candidate registries — Cargo (Rust) and Maven (Java) remain the un-hit major ecosystems.</strong> With the worm framework now open-sourced and a wiper stage added (§ 2), the registry-agnostic OIDC-token-reuse primitive makes Cargo and Maven the next logical targets; pre-stage Sigstore / provenance-anomaly hunts in Rust and Java pipelines. (<a href="https://isc.sans.edu/diary/33016" target="_blank" rel="noopener noreferrer">SANS ISC diary 33016</a>; <a href="https://ctipilot.ch/briefs/2026-05-26/" target="_blank" rel="noopener noreferrer">Daily 2026-05-26</a>)</li></ul><div class="prov"><span>outlook</span><span>25 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-25/looking-ahead-2026-w22/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://therecord.media/microsoft-calls-zero-day-releases-never-justifiable-as-researcher-threatens-more" target="_blank" rel="noopener noreferrer">The Record</a> · <a href="https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/" target="_blank" rel="noopener noreferrer">Rapid7</a> · <a href="https://www.ic3.gov/PSA/2026/PSA260527" target="_blank" rel="noopener noreferrer">FBI IC3 PSA260527</a> · <a href="https://www.tenable.com/security/research/tra-2026-44" target="_blank" rel="noopener noreferrer">Tenable TRA-2026-44</a> · <a href="https://isc.sans.edu/diary/33016" target="_blank" rel="noopener noreferrer">SANS ISC diary 33016</a></div></article><details class="verif"><summary class="vh">About this weekly<span class="verif-count">1 run</span><svg class="verif-chev" viewBox="0 0 24 24" width="12" height="12" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" aria-hidden="true"><path d="M6 9l6 6 6-6"></path></svg></summary><div class="verif-body"><div class="run-note" data-run-id="2026-W22-da77963d"><h3 class="run-note__head"><span class="mono">2026-W22-da77963d</span> <span class="muted">· weekly · Claude Opus 4.8 · 32 entries published</span></h3><div class="run-note__body"><ul><li><strong><code>[SINGLE-SOURCE]</code> items carried into this summary:</strong> the Cisco Talos DICOM/Orthanc heap analysis (§ 4, single research-lab source — a technical study, not an incident claim); the Red Canary Entra Agent ID privilege-escalation detection (§ 2, single-vendor); Delta DIAView CVE-2026-9642 (§ 3 table / § 9, Tenable-only, no vendor patch). Each is attributed to its single source in place.</li><li><strong>Reduced confidence / single-primary:</strong> the EU CRA milestone item (§ 8) rests on the European Commission implementation factpage as a single primary — the dates are authoritative but uncorroborated by a second source this run. The Check Point Q1 2026 ransomware figures (§ 6) are single-vendor leak-site telemetry; group-share and victim-count numbers are treated as directional landscape signal, not precise measurement, and no vanity metrics were carried into the prose.</li><li><strong>Items dropped from this week&#39;s roll-up (cleared the daily bar, not the weekly W-PD-1 bar):</strong> the Underminr CDN domain-fronting research, Atos BYOVD-driver study, Google Cloud API-key deletion-latency, Tycoon 2FA AiTM detection-engineering, Lazarus RemotePE memory-only RAT, Wiz JINX-0164 crypto-targeting, and the SANS ISC Akira-from-syslog reconstruction were folded by reference or dropped — interesting in isolation but not inaction-=-incident / cross-day-pattern / strategic-horizon. The GitHub Enterprise SSRF (CVE-2026-9312) and the Rancher / Portainer / Veeam / GitLab patch clusters appear in the § 3 table without H3s (patched, no in-window exploitation). They may resurface if exploited.</li><li><strong>Carry-forwards resolved this week:</strong> the W21 watch on the UNC6671/BlackFile rebrand (GTIG profile + &quot;shutting down under this name&quot;, § 7), on Shai-Hulud wave-6 registries (npm @antv ecosystem confirmed hit; Maven Central exposure via <code>mvnpm</code> reported in secondary sourcing but <strong>not</strong> confirmed against a primary this run; Cargo status unverified, § 7), and on the SECO/MSS sanctions question (Switzerland deferred the MSS ban, § 8) are all closed. The GitHub internal-repo post-incident report remains outstanding and carries forward to W23.</li><li><strong>Contradictions / open items:</strong> none unresolved this run. No European Commission interpretive guidance on the EU MSS-prohibition scope has been published, so a conservative reading stands (§ 8).</li><li><strong>Sub-agents:</strong> both horizon sub-agents (W1 long-horizon, W2 policy) ran on Claude Sonnet 4.6 and returned within budget (W1 311s, W2 387s). Both were cut off at the very end of their runs before emitting their closing Markdown return; their findings were recovered intact from the committed <code>work/2026-W22-da77963d/findings.W1.yaml</code> / <code>findings.W2.yaml</code>, the agents&#39; completion summaries, and the <code>url-liveness.tsv</code> ledger (every cited primary verified 200 OK). No candidate sources surfaced this run.</li><li>Verification iterations: 3 — iter-1 (Opus) NEEDS_FIXES (truth=3, editorial=1, advisory=1); iter-2 (Sonnet) NEEDS_FIXES (truth=4, editorial=1, advisory=1); iter-3 (Opus) CLEAN. Model rotation applied across iterations. Residuals: 0. Remediated across the loop: an unverified Maven/Cargo &quot;confirmed&quot; claim (downgraded to unconfirmed), an ENISA maturity-band miscategorisation, the Asocks name-attribution, the Samba config-dependence of both 10.0 paths, a CVE mislabel (CVE-2026-45585 is YellowKey, not MiniPlasma; MiniPlasma is CVE-2020-17103), the German-hackback per-agency overstatement, and an ESET &quot;Sandworm vs NATO energy&quot; overstatement (one rare Polish-energy incident).</li><li>Coverage gaps: databreaches-net (403 — transport, bridge-routed); sophos-xops (503); inside-it-ch (Cloudflare 403); cert-fr-actu (feed stalled); ec-presscorner (SPA, no static content); bmi-bund-de (bridge returned empty); enisa-nis360-pdf (full PDF not fetched — analysis page used instead); GovCERT.ch (no Shai-Hulud developer advisory exists — confirmed absent, not a fetch failure).</li></ul>
<p><em>Migrated from briefs/weekly/2026-W22.md (v2).</em></p></div></div></div></details>]]></content:encoded></item><item><title>CTI Weekly Summary · 2026-W21</title><link>https://ctipilot.ch/weekly/2026-W21/</link><guid isPermaLink="true">https://ctipilot.ch/weekly/2026-W21/</guid><pubDate>Mon, 18 May 2026 05:00:39 +0000</pubDate><dc:date>2026-05-18T05:00:39Z</dc:date><category>CVE-2020-17103</category><category>CVE-2024-12802</category><category>CVE-2026-20223</category><category>CVE-2026-37979</category><category>CVE-2026-37982</category><category>CVE-2026-41091</category><category>CVE-2026-42096</category><category>CVE-2026-42097</category><description><![CDATA[<ul><li><strong>EU 20th Russia sanctions package — managed-security-services prohibition effective 25 May; Switzerland adopted most measures 22 May.</strong> EU 20th Russia sanctions package prohibits &quot;managed security services&quot; from 25 May; Switzerland adopted most measures 22 May — EU/CH MSSP, IR and pentest providers with Russian-entity clients must have wound those engagements down. (Greenberg Traurig; Swiss EAER) <a href="https://ctipilot.ch/entries/2026-05-18/eu-20th-russia-sanctions-package-managed-security-services-p/">→</a></li><li><strong>Midnight Blizzard and others operationalise ROADtools for Entra ID abuse.</strong> An unusually active espionage week — Webworm pivoted to EU government targets (Graph/OneDrive C2), Midnight Blizzard and others operationalised ROADtools against Entra ID, and Iran&#39;s Screening Serpens used AppDomainManager hijacking to blind ETW. (daily 2026-05-21; daily 2026-05-23) <a href="https://ctipilot.ch/entries/2026-05-18/midnight-blizzard-and-others-operationalise-roadtools-for-en/">→</a></li><li><strong>Healthcare (DACH) — the soft surface is the administrative intermediary, not the hospital.</strong> DACH healthcare hit through its administrative intermediaries — a single billing processor (Unimed) exposed patient records across at least six German university hospitals (The Record tallies ~96,600 across four named), and the ARWINI prescription-audit body lost a claimed ~70,000 Art. 9 records to Kairos. (daily 2026-05-24; The Record) <a href="https://ctipilot.ch/entries/2026-05-18/healthcare-dach-the-soft-surface-is-the-administrative-inter/">→</a></li><li><strong>Verizon 2026 DBIR — vulnerability exploitation is the #1 breach vector for the first time in 19 years; patching cadence regressed.</strong> Verizon&#39;s 2026 DBIR: vulnerability exploitation overtook credential theft as the #1 breach vector for the first time in 19 years — and Rapid7&#39;s Q1 report independently agrees; the patching cadence regressed (KEV remediation ~26%, down from ~38%). (Verizon; daily 2026-05-23) <a href="https://ctipilot.ch/entries/2026-05-18/verizon-2026-dbir-vulnerability-exploitation-is-the-1-breach/">→</a></li><li><strong>Technology / developer toolchain — CI/CD supply chain remains the week&#39;s highest-volume attack surface.</strong> The Shai-Hulud / Megalodon supply-chain worm went commodity — open-sourced 12 May, it escalated daily across the window: GitHub&#39;s own internal repos exfiltrated (~3,800), Microsoft&#39;s durabletask PyPI package weaponised, 5,561 repositories mass-poisoned in one ~6-hour Megalodon burst, and SLSA Build Level 3 attestation invalidated as an integrity gate. (daily 2026-05-21; CSA research note) <a href="https://ctipilot.ch/entries/2026-05-18/technology-developer-toolchain-ci-cd-supply-chain-remains-th/">→</a></li><li><strong>Two CISA KEV additions under active exploitation — Trend Micro Apex One and Langflow.</strong> CISA KEV double-add under active exploitation — Trend Micro Apex One (fleet-wide agent code push) and Langflow (Flodric botnet), plus SonicWall actors bypassing MFA on patched SSL-VPN firmware. (daily 2026-05-22; CISA KEV) <a href="https://ctipilot.ch/entries/2026-05-18/two-cisa-kev-additions-under-active-exploitation-trend-micro/">→</a></li><li><strong>Drupal core CVE-2026-9082 — pre-auth SQL injection, CISA KEV, active exploitation confirmed; NCSC.ch flipped to &quot;actively exploited&quot;.</strong> Drupal core CVE-2026-9082 went from pre-patch warning to KEV-confirmed exploitation in one week — NCSC Switzerland flipped its Cyber Security Hub post to &quot;Actively exploited&quot;; PostgreSQL-backed public-sector Drupal is the exposed estate. (daily 2026-05-23; Drupal SA-CORE-2026-004) <a href="https://ctipilot.ch/entries/2026-05-18/drupal-core-cve-2026-9082-pre-auth-sql-injection-cisa-kev-ac/">→</a></li><li><strong>Microsoft Defender Engine CVE-2026-41091 + CVE-2026-45498 — both confirmed exploited in the wild; out-of-band engine update is the fix.</strong> Microsoft Defender Engine CVE-2026-41091 + CVE-2026-45498 — both confirmed exploited in the wild, fixed by an out-of-band engine update; the AV engine itself was the foothold. (daily 2026-05-20; The Hacker News) <a href="https://ctipilot.ch/entries/2026-05-18/microsoft-defender-engine-cve-2026-41091-cve-2026-45498-both/">→</a></li></ul>]]></description><content:encoded><![CDATA[<div class="tldr"><span class="eyebrow eyebrow--muted">Week at a glance</span><ol><li><span class="num">01</span><span><b>EU 20th Russia sanctions package — managed-security-services prohibition effective 25 May; Switzerland adopted most measures 22 May.</b> EU 20th Russia sanctions package prohibits &quot;managed security services&quot; from 25 May; Switzerland adopted most measures 22 May — EU/CH MSSP, IR and pentest providers with Russian-entity clients must have wound those engagements down. (Greenberg Traurig; Swiss EAER) <a href="https://ctipilot.ch/entries/2026-05-18/eu-20th-russia-sanctions-package-managed-security-services-p/">→</a></span></li><li><span class="num">02</span><span><b>Midnight Blizzard and others operationalise ROADtools for Entra ID abuse.</b> An unusually active espionage week — Webworm pivoted to EU government targets (Graph/OneDrive C2), Midnight Blizzard and others operationalised ROADtools against Entra ID, and Iran&#39;s Screening Serpens used AppDomainManager hijacking to blind ETW. (daily 2026-05-21; daily 2026-05-23) <a href="https://ctipilot.ch/entries/2026-05-18/midnight-blizzard-and-others-operationalise-roadtools-for-en/">→</a></span></li><li><span class="num">03</span><span><b>Healthcare (DACH) — the soft surface is the administrative intermediary, not the hospital.</b> DACH healthcare hit through its administrative intermediaries — a single billing processor (Unimed) exposed patient records across at least six German university hospitals (The Record tallies ~96,600 across four named), and the ARWINI prescription-audit body lost a claimed ~70,000 Art. 9 records to Kairos. (daily 2026-05-24; The Record) <a href="https://ctipilot.ch/entries/2026-05-18/healthcare-dach-the-soft-surface-is-the-administrative-inter/">→</a></span></li><li><span class="num">04</span><span><b>Verizon 2026 DBIR — vulnerability exploitation is the #1 breach vector for the first time in 19 years; patching cadence regressed.</b> Verizon&#39;s 2026 DBIR: vulnerability exploitation overtook credential theft as the #1 breach vector for the first time in 19 years — and Rapid7&#39;s Q1 report independently agrees; the patching cadence regressed (KEV remediation ~26%, down from ~38%). (Verizon; daily 2026-05-23) <a href="https://ctipilot.ch/entries/2026-05-18/verizon-2026-dbir-vulnerability-exploitation-is-the-1-breach/">→</a></span></li><li><span class="num">05</span><span><b>Technology / developer toolchain — CI/CD supply chain remains the week&#39;s highest-volume attack surface.</b> The Shai-Hulud / Megalodon supply-chain worm went commodity — open-sourced 12 May, it escalated daily across the window: GitHub&#39;s own internal repos exfiltrated (~3,800), Microsoft&#39;s durabletask PyPI package weaponised, 5,561 repositories mass-poisoned in one ~6-hour Megalodon burst, and SLSA Build Level 3 attestation invalidated as an integrity gate. (daily 2026-05-21; CSA research note) <a href="https://ctipilot.ch/entries/2026-05-18/technology-developer-toolchain-ci-cd-supply-chain-remains-th/">→</a></span></li><li><span class="num">06</span><span><b>Two CISA KEV additions under active exploitation — Trend Micro Apex One and Langflow.</b> CISA KEV double-add under active exploitation — Trend Micro Apex One (fleet-wide agent code push) and Langflow (Flodric botnet), plus SonicWall actors bypassing MFA on patched SSL-VPN firmware. (daily 2026-05-22; CISA KEV) <a href="https://ctipilot.ch/entries/2026-05-18/two-cisa-kev-additions-under-active-exploitation-trend-micro/">→</a></span></li><li><span class="num">07</span><span><b>Drupal core CVE-2026-9082 — pre-auth SQL injection, CISA KEV, active exploitation confirmed; NCSC.ch flipped to &quot;actively exploited&quot;.</b> Drupal core CVE-2026-9082 went from pre-patch warning to KEV-confirmed exploitation in one week — NCSC Switzerland flipped its Cyber Security Hub post to &quot;Actively exploited&quot;; PostgreSQL-backed public-sector Drupal is the exposed estate. (daily 2026-05-23; Drupal SA-CORE-2026-004) <a href="https://ctipilot.ch/entries/2026-05-18/drupal-core-cve-2026-9082-pre-auth-sql-injection-cisa-kev-ac/">→</a></span></li><li><span class="num">08</span><span><b>Microsoft Defender Engine CVE-2026-41091 + CVE-2026-45498 — both confirmed exploited in the wild; out-of-band engine update is the fix.</b> Microsoft Defender Engine CVE-2026-41091 + CVE-2026-45498 — both confirmed exploited in the wild, fixed by an out-of-band engine update; the AV engine itself was the foothold. (daily 2026-05-20; The Hacker News) <a href="https://ctipilot.ch/entries/2026-05-18/microsoft-defender-engine-cve-2026-41091-cve-2026-45498-both/">→</a></span></li></ol></div><nav class="secnav" aria-label="Sections"><a class="secnav-chip" href="#highest-impact-events-what-s-on-fire-if-no-one-acted">Highest-impact events · what&#39;s on fire if no one acted <span class="secnav-n">4</span></a><a class="secnav-chip" href="#multi-day-campaigns-and-chains">Multi-day campaigns and chains <span class="secnav-n">3</span></a><a class="secnav-chip" href="#vulnerability-roll-up">Vulnerability roll-up <span class="secnav-n">6</span></a><a class="secnav-chip" href="#sector-victim-patterns">Sector &amp; victim patterns <span class="secnav-n">5</span></a><a class="secnav-chip" href="#incidents-disclosures-recap">Incidents &amp; disclosures recap <span class="secnav-n">7</span></a><a class="secnav-chip" href="#annual-periodic-threat-reports">Annual / periodic threat reports <span class="secnav-n">3</span></a><a class="secnav-chip" href="#long-running-campaigns-status-update">Long-running campaigns · status update <span class="secnav-n">7</span></a><a class="secnav-chip" href="#policy-regulatory-horizon">Policy &amp; regulatory horizon <span class="secnav-n">3</span></a><a class="secnav-chip" href="#looking-ahead-what-to-watch-next-week">Looking ahead · what to watch next week <span class="secnav-n">1</span></a></nav><div class="sect" id="highest-impact-events-what-s-on-fire-if-no-one-acted"><span class="n">01</span><span class="t">Highest-impact events · what&#39;s on fire if no one acted</span><span class="c">4 items</span></div><article class="finding entry-card" data-entry-id="2026-05-18/sonicwall-gen6-ssl-vpn-cve-2024-12802-akira-linked-actors-by" data-tags="ransomware vulnerabilities actively-exploited identity auth-bypass" data-regions="europe global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:03Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2024-12802/">CVE-2024-12802</a><span class="b exp">exploited</span></div><h3 class="f-h" id="sonicwall-gen6-ssl-vpn-cve-2024-12802-akira-linked-actors-by"><a href="https://ctipilot.ch/entries/2026-05-18/sonicwall-gen6-ssl-vpn-cve-2024-12802-akira-linked-actors-by/">SonicWall Gen6 SSL-VPN CVE-2024-12802 — Akira-linked actors bypassing MFA on *officially-patched* firmware</a></h3><p><strong>If you did nothing this week:</strong> patching alone did not close this. Actors whose TTPs match Akira ransomware successfully bypassed MFA on SonicWall Gen6 SSL-VPN appliances running officially-patched firmware between February and March 2026, by abusing a UPN/SAM account-name split in the authentication path — covered <a href="https://ctipilot.ch/briefs/2026-05-21/" target="_blank" rel="noopener noreferrer">2026-05-21</a>.</p>
<p>This is an incomplete-patch case (CVE-2024-12802, CVSS 9.1): the original fix did not fully remediate the MFA-bypass path, so a &quot;patched&quot; appliance can still be brute-forced through the account-name-split primitive. Swiss/EU public-sector and finance estates that treated the earlier SonicWall advisory as closed should re-open it: audit SSL-VPN authentication logs for UPN-vs-SAM mismatches and repeated MFA challenges, and confirm the appliance is on the firmware build that fully closes CVE-2024-12802 rather than the earlier partial fix.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: patching alone did not close this.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/sonicwall-gen6-ssl-vpn-cve-2024-12802-akira-linked-actors-by/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cybersecuritydive.com/news/patch-bypass-hackers-exploit-flaw-sonicwall/820600/" target="_blank" rel="noopener noreferrer">Cybersecurity Dive</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/two-cisa-kev-additions-under-active-exploitation-trend-micro" data-tags="vulnerabilities actively-exploited cisa-kev patch-available" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-18T05:00:04Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="two-cisa-kev-additions-under-active-exploitation-trend-micro"><a href="https://ctipilot.ch/entries/2026-05-18/two-cisa-kev-additions-under-active-exploitation-trend-micro/">Two CISA KEV additions under active exploitation — Trend Micro Apex One and Langflow</a></h3><p><strong>If you did nothing this week:</strong> if you run Apex One On-Premise, your endpoint-management server can push attacker code to every managed agent; if you run Langflow, a cross-origin request can steal a session. CISA added both to KEV on <a href="https://ctipilot.ch/briefs/2026-05-22/" target="_blank" rel="noopener noreferrer">2026-05-21</a> with confirmed in-the-wild exploitation.</p>
<p>CVE-2026-34926 (Apex One On-Premise, CVSS 6.7) is a post-auth relative-path-traversal flaw in builds below 17079 that lets an admin-credential holder inject code which the management server then deploys fleet-wide to all managed agents — turning the security console into a malware distribution point; JPCERT/CC issued at260014 corroborating. CVE-2025-34291 (Langflow ≤ 1.6.9, CVSS 9.4) is an overly-permissive CORS configuration combined with a <code>SameSite=None</code> refresh token that enables cross-origin token theft, exploited by the <em>Flodric</em> botnet. Patch both; for Apex One, restrict management-console access and audit agent-deployment jobs for unexpected packages.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/two-cisa-kev-additions-under-active-exploitation-trend-micro/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://success.trendmicro.com/en-US/solution/KA-0023430" target="_blank" rel="noopener noreferrer">Trend Micro KA-0023430</a> · <a href="https://www.jpcert.or.jp/english/at/2026/at260014.html" target="_blank" rel="noopener noreferrer">JPCERT/CC at260014</a> · <a href="https://www.cisa.gov/news-events/alerts/2026/05/21/cisa-adds-two-known-exploited-vulnerabilities-catalog" target="_blank" rel="noopener noreferrer">CISA KEV alert, 2026-05-21</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/drupal-core-cve-2026-9082-pre-auth-sql-injection-cisa-kev-ac" data-tags="vulnerabilities actively-exploited pre-auth cisa-kev patch-available" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-18T05:00:02Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-9082/">CVE-2026-9082</a><span class="b exp">exploited</span></div><h3 class="f-h" id="drupal-core-cve-2026-9082-pre-auth-sql-injection-cisa-kev-ac"><a href="https://ctipilot.ch/entries/2026-05-18/drupal-core-cve-2026-9082-pre-auth-sql-injection-cisa-kev-ac/">Drupal core CVE-2026-9082 — pre-auth SQL injection, CISA KEV, active exploitation confirmed; NCSC.ch flipped to &quot;actively exploited&quot;</a></h3><p><strong>If you did nothing this week:</strong> an internet-exposed Drupal site on PostgreSQL was anonymously SQL-injectable, and exploitation is now confirmed in the wild. Drupal pre-warned an emergency advisory via PSA-2026-05-18, shipped SA-CORE-2026-004 on <a href="https://ctipilot.ch/briefs/2026-05-21/" target="_blank" rel="noopener noreferrer">2026-05-21</a>, and by <a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">2026-05-23</a> the advisory was updated to confirm exploit attempts, CISA had KEV-listed it, and <strong>NCSC Switzerland flipped its Cyber Security Hub post 12584 to &quot;Actively exploited.&quot;</strong></p>
<p>CVE-2026-9082 is a &quot;highly critical&quot; pre-authentication SQL injection in the Drupal core database abstraction layer, exploitable only against PostgreSQL backends. Drupal is widely deployed across Swiss and EU public-administration web estates; the PostgreSQL-only condition narrows but does not eliminate exposure. Apply the SA-CORE-2026-004 fixed core release immediately; if you cannot patch a PostgreSQL-backed Drupal site, take it off the public internet until you can.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: an internet-exposed Drupal site on PostgreSQL was anonymously SQL-injectable, and exploitation is now confirmed in the wild.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/drupal-core-cve-2026-9082-pre-auth-sql-injection-cisa-kev-ac/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.drupal.org/sa-core-2026-004" target="_blank" rel="noopener noreferrer">Drupal Security Team — SA-CORE-2026-004</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/microsoft-defender-engine-cve-2026-41091-cve-2026-45498-both" data-tags="vulnerabilities actively-exploited lpe priv-esc patch-available" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-18T05:00:01Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-41091/">CVE-2026-41091 +1</a><span class="b exp">exploited</span></div><h3 class="f-h" id="microsoft-defender-engine-cve-2026-41091-cve-2026-45498-both"><a href="https://ctipilot.ch/entries/2026-05-18/microsoft-defender-engine-cve-2026-41091-cve-2026-45498-both/">Microsoft Defender Engine CVE-2026-41091 + CVE-2026-45498 — both confirmed exploited in the wild; out-of-band engine update is the fix</a></h3><p><strong>If you did nothing this week:</strong> the malware-protection engine on your Windows estate became the foothold. Microsoft confirmed both CVEs as actively exploited and shipped a combined out-of-band Defender Engine update (4.18.26040.7) — first disclosed <a href="https://ctipilot.ch/briefs/2026-05-20/" target="_blank" rel="noopener noreferrer">2026-05-20</a>, confirmed-exploited <a href="https://ctipilot.ch/briefs/2026-05-22/" target="_blank" rel="noopener noreferrer">2026-05-22</a>.</p>
<p>CVE-2026-41091 is a link-following elevation-of-privilege flaw in the Defender Engine (CVSS 7.8) flagged <code>exploited=Yes</code> and <code>publiclyDisclosed=Yes</code> in the MSRC update guide on 2026-05-19; CVE-2026-45498 was confirmed exploited alongside it. A third flaw disclosed the same day — CVE-2026-45584, a heap-based buffer overflow in the Defender Engine reachable over the network (AV:N) for unauthenticated code execution in the Defender process context (CVSS 8.1) — is patched by the same engine train but not confirmed exploited (§ 3). The engine auto-updates for most estates, but air-gapped, version-pinned, or managed-update environments must verify they are on engine ≥ 4.18.26040.7. Hunt for Defender engine-version regressions and anomalous <code>MpCmdRun.exe</code> activity.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: the malware-protection engine on your Windows estate became the foothold.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/microsoft-defender-engine-cve-2026-41091-cve-2026-45498-both/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41091" target="_blank" rel="noopener noreferrer">Microsoft MSRC — CVE-2026-41091</a> · <a href="https://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html" target="_blank" rel="noopener noreferrer">The Hacker News — two actively-exploited Defender flaws</a></div></article><div class="sect" id="multi-day-campaigns-and-chains"><span class="n">02</span><span class="t">Multi-day campaigns and chains</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-05-18/drupal-cve-2026-9082-disclosure-only-monday-to-kev-confirmed" data-tags="vulnerabilities actively-exploited pre-auth cisa-kev patch-available" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:07Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-9082/">CVE-2026-9082</a><span class="b exp">exploited</span></div><h3 class="f-h" id="drupal-cve-2026-9082-disclosure-only-monday-to-kev-confirmed"><a href="https://ctipilot.ch/entries/2026-05-18/drupal-cve-2026-9082-disclosure-only-monday-to-kev-confirmed/">Drupal CVE-2026-9082 — disclosure-only Monday to KEV-confirmed-exploited by Friday</a></h3><p>A textbook example of why the weekly lens matters: an item that was a pre-patch warning at the start of the week was confirmed exploited in the wild by its end. Drupal pre-announced an emergency advisory via PSA-2026-05-18 (<a href="https://ctipilot.ch/briefs/2026-05-20/" target="_blank" rel="noopener noreferrer">daily 2026-05-20</a>); SA-CORE-2026-004 shipped the &quot;highly critical&quot; pre-auth SQL injection fix on <a href="https://ctipilot.ch/briefs/2026-05-21/" target="_blank" rel="noopener noreferrer">2026-05-21</a>; and by <a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">2026-05-23</a> Drupal had updated the advisory to confirm exploit attempts, CISA had KEV-listed it, and NCSC Switzerland had flipped its Cyber Security Hub post 12584 to &quot;Actively exploited.&quot; See § 1 for the operational framing — the trajectory itself is the lesson: a PostgreSQL-backed public-sector Drupal site left unpatched across this one week moved from &quot;watch&quot; to &quot;presumed-targeted.&quot;</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">A textbook example of why the weekly lens matters: an item that was a pre-patch warning at the start of the week was confirmed exploited in the wild by its end.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/drupal-cve-2026-9082-disclosure-only-monday-to-kev-confirmed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.drupal.org/sa-core-2026-004" target="_blank" rel="noopener noreferrer">Drupal Security Team — SA-CORE-2026-004</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/windows-chaotic-eclipse-zero-day-proliferation-yellowkey-gre" data-tags="vulnerabilities lpe priv-esc poc-public no-patch" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:06Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-45585/">CVE-2026-45585 +1</a></div><h3 class="f-h" id="windows-chaotic-eclipse-zero-day-proliferation-yellowkey-gre"><a href="https://ctipilot.ch/entries/2026-05-18/windows-chaotic-eclipse-zero-day-proliferation-yellowkey-gre/">Windows &quot;Chaotic Eclipse&quot; zero-day proliferation — YellowKey, GreenPlasma, MiniPlasma</a></h3><p>The researcher cluster &quot;Chaotic Eclipse&quot; / &quot;Nightmare Eclipse&quot; continued releasing unpatched Windows LPE/bypass PoCs across the window. On <a href="https://ctipilot.ch/briefs/2026-05-19/" target="_blank" rel="noopener noreferrer">2026-05-19</a> a third PoC — <em>MiniPlasma</em> — landed, targeting the <code>cldflt.sys</code> <code>CfAbortHydration</code> path and claiming a re-exploitable regression of the 2020-era CVE-2020-17103. On <a href="https://ctipilot.ch/briefs/2026-05-20/" target="_blank" rel="noopener noreferrer">2026-05-20</a> Microsoft formally assigned <strong>CVE-2026-45585</strong> to the BitLocker/WinRE bypass (<em>YellowKey</em>) disclosed on 2026-05-12 and published a WinRE mitigation — but confirmed there is still no security update for the cluster; the earliest fix window remains the June 2026 Patch Tuesday. Three public PoCs (YellowKey, GreenPlasma, MiniPlasma) now exist against the Windows-centric desktop estates standard in CH/EU federal and cantonal administrations. Until a patch ships, enforce BitLocker PIN/Network-Unlock GPOs and AppLocker/WDAC rules on <code>ctfmon.exe</code> injection paths, and segregate privileged accounts from the workstation tier.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/windows-chaotic-eclipse-zero-day-proliferation-yellowkey-gre/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45585" target="_blank" rel="noopener noreferrer">MSRC — CVE-2026-45585</a> · <a href="https://www.bleepingcomputer.com/news/microsoft/new-windows-miniplasma-zero-day-exploit-gives-system-access-poc-released/" target="_blank" rel="noopener noreferrer">BleepingComputer — MiniPlasma PoC</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/teampcp-mini-shai-hulud-megalodon-the-open-sourced-supply-ch" data-tags="supply-chain actively-exploited infostealer cloud identity organized-crime" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:05Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span></div><h3 class="f-h" id="teampcp-mini-shai-hulud-megalodon-the-open-sourced-supply-ch"><a href="https://ctipilot.ch/entries/2026-05-18/teampcp-mini-shai-hulud-megalodon-the-open-sourced-supply-ch/">TeamPCP / Mini Shai-Hulud / Megalodon — the open-sourced supply-chain worm became commodity infrastructure this week</a></h3><p>This is the week&#39;s defining chain. After the worm framework was open-sourced on 2026-05-12, the window saw it move from a single operator&#39;s tool to commodity capability, escalating almost daily:</p>
<ul><li><strong>2026-05-18 → 19</strong> — First copycat wave: TeamPCP imitators deploy Phantom Bot plus SSH/cloud stealers, the Checkmarx Jenkins plugin is re-trojanised, and a rival &quot;PCPJack&quot; worm appears, per <a href="https://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here/" target="_blank" rel="noopener noreferrer">Ox Security</a> (<a href="https://ctipilot.ch/briefs/2026-05-19/" target="_blank" rel="noopener noreferrer">daily 2026-05-19</a>). Same window: the Nx Console VS Code extension (2.2M installs) is pushed malicious for an 11-minute window (12:36–12:47 UTC, 2026-05-18) via stolen publisher credentials, and all 53 tags of <code>actions-cool/issues-helper</code> are moved to an imposter commit reading <code>/proc/PID/mem</code> of the Runner.Worker (<a href="https://ctipilot.ch/briefs/2026-05-20/" target="_blank" rel="noopener noreferrer">daily 2026-05-20</a>).</li><li><strong>2026-05-21</strong> — Escalation to platform scale: GitHub itself is named in a breach claim, Microsoft&#39;s official <code>durabletask</code> PyPI package is weaponised (propagating via AWS SSM and <code>kubectl exec</code>), and Grafana confirms a missed-token-rotation root cause (<a href="https://thehackernews.com/2026/05/github-investigating-teampcp-claimed.html" target="_blank" rel="noopener noreferrer">The Hacker News</a>; <a href="https://ctipilot.ch/briefs/2026-05-21/" target="_blank" rel="noopener noreferrer">daily 2026-05-21</a>).</li><li><strong>2026-05-22</strong> — Unit 42 and StepSecurity publish concurrent analyses establishing that <strong>SLSA Build Level 3 provenance attestation is invalidated as an integrity gate</strong> for these waves — the malicious build step runs inside the legitimately-attested pipeline (<a href="https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/" target="_blank" rel="noopener noreferrer">Unit 42</a>; <a href="https://ctipilot.ch/briefs/2026-05-22/" target="_blank" rel="noopener noreferrer">daily 2026-05-22</a>).</li><li><strong>2026-05-23 (disclosure; event 2026-05-18)</strong> — SafeDep and OX Security disclose the <em>Megalodon</em> sub-campaign, which mass-poisoned 5,561 GitHub repositories in a ~6-hour window on 18 May using forged CI-bot identities and templated commit messages, harvesting cloud credentials and OIDC tokens (<a href="https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/" target="_blank" rel="noopener noreferrer">SafeDep</a>; <a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">daily 2026-05-23</a>). A further Packagist/Laravel-Lang compromise is reported the same day (<a href="https://ctipilot.ch/briefs/2026-05-24/" target="_blank" rel="noopener noreferrer">daily 2026-05-24</a>).</li></ul>
<p>Two in-window synthesis documents consolidate the picture. The <strong>Cloud Security Alliance</strong> research note (2026-05-22) frames the whole event as a two-wave attack: Wave 1 (Mini Shai-Hulud, 29 Apr – 12 May) hijacked TanStack&#39;s GitHub Actions runner via a <code>pull_request_target</code> trigger plus Actions cache poisoning, extracted a live OIDC token from runner process memory via <code>/proc/PID/mem</code>, obtained a Sigstore signing certificate from Fulcio, and produced <strong>SLSA BL3 provenance attestations for 404 malicious package versions across 172 packages</strong> (CVE-2026-45321, CVSS 9.6) — the first publicly-documented hijack of trusted build pipelines to generate attestation-bearing malicious artefacts. Wave 2 (Megalodon, from 18 May) pushed 5,718 commits to 5,561 repos in under six hours, harvesting AWS IAM, GCP/Azure IMDS, SSH, Docker auth, <code>.npmrc</code>, <code>.netrc</code>, Kubernetes configs, Vault tokens and Terraform state. Separately, <strong>GitHub&#39;s official post-incident blog</strong> (2026-05-20) confirmed an employee device was compromised via the poisoned Nx Console extension (GHSA-c9j4-9m59-847w) and ~3,800 GitHub-internal repositories were exfiltrated, with no customer-data impact found as of publication and a fuller report still outstanding.</p>
<p>Defender takeaways: set <code>permissions: id-token: none</code> on workflows that do not need OIDC; disable or isolate <code>pull_request_target</code> for fork PRs (<code>permissions: contents: read</code>); treat Git commit author/committer fields as unverified free text (use contributor allow-lists / push-rule bypass-actor audit events to catch Megalodon-style forged identities); audit Sigstore Rekor for unexpected signing events from your own pipeline identity; and do not accept SLSA BL3 attestation alone as a clean-package signal.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/teampcp-mini-shai-hulud-megalodon-the-open-sourced-supply-ch/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-shai-hulud-megalodon-supply-chain-cascade/" target="_blank" rel="noopener noreferrer">Cloud Security Alliance — Shai-Hulud/Megalodon research note</a> · <a href="https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/" target="_blank" rel="noopener noreferrer">GitHub Security Blog — internal-repo access</a></div></article><div class="sect" id="vulnerability-roll-up"><span class="n">03</span><span class="t">Vulnerability roll-up</span><span class="c">6 items</span></div><article class="finding entry-card" data-entry-id="2026-05-18/cve-2026-7507-15-keycloak-26-6-2-identity-provider-cluster-i" data-tags="vulnerabilities identity auth-bypass patch-available eu-nexus" data-regions="europe dach" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-18T05:00:13Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-7507/">CVE-2026-7507 +3</a></div><h3 class="f-h" id="cve-2026-7507-15-keycloak-26-6-2-identity-provider-cluster-i"><a href="https://ctipilot.ch/entries/2026-05-18/cve-2026-7507-15-keycloak-26-6-2-identity-provider-cluster-i/">CVE-2026-7507 (+15) — Keycloak 26.6.2: identity-provider cluster including OIDC session fixation and cross-realm IDOR</a></h3><p>Keycloak 26.6.2 fixed 16 CVEs across its identity, authentication and authorisation subsystems, including OIDC session fixation (CVE-2026-7507), WebAuthn execute-actions token replay (CVE-2026-37982), introspection audience bypass (CVE-2026-37979) and a cross-realm IDOR in Authorization Services (CVE-2026-4630); BSI CERT-Bund issued WID-SEC-2026-1612 at HIGH. Keycloak is the dominant open-source IAM in EU and Swiss public-sector and university SSO deployments — a session-fixation or cross-realm flaw in the IdP undermines every relying-party application behind it. Upgrade to 26.6.2; prioritise multi-realm deployments where the cross-realm IDOR has the widest blast radius.</p><div class="prov"><span>vulnerability</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/cve-2026-7507-15-keycloak-26-6-2-identity-provider-cluster-i/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.keycloak.org/2026/05/keycloak-2662-released" target="_blank" rel="noopener noreferrer">Keycloak Project</a> · <a href="https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1612" target="_blank" rel="noopener noreferrer">BSI CERT-Bund WID-SEC-2026-1612</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/cve-2026-42096-42100-sparx-enterprise-architect-pro-cloud-se" data-tags="vulnerabilities pre-auth rce auth-bypass poc-public no-patch" data-regions="switzerland europe global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-18T05:00:12Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-42096/">CVE-2026-42096 +4</a></div><h3 class="f-h" id="cve-2026-42096-42100-sparx-enterprise-architect-pro-cloud-se"><a href="https://ctipilot.ch/entries/2026-05-18/cve-2026-42096-42100-sparx-enterprise-architect-pro-cloud-se/">CVE-2026-42096 … -42100 — Sparx Enterprise Architect / Pro Cloud Server: five-CVE pre-auth chain, public PoC, no patch</a></h3><p>CERT Polska coordinated disclosure of five Sparx Systems vulnerabilities (CVE-2026-42096 … -42100), chaining pre-auth SQL injection with a WebEA race-condition to reach RCE; a researcher PoC is public and <strong>no vendor patch exists</strong>. Sparx EA / Pro Cloud Server is widely used as a modelling and enterprise-architecture repository in Swiss and EU public-administration and university environments, so the CH/education exposure is real. With no patch available, restrict Pro Cloud Server to authenticated VPN reach and monitor WebEA endpoints for the injection patterns CERT-PL documents.</p><div class="prov"><span>vulnerability</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/cve-2026-42096-42100-sparx-enterprise-architect-pro-cloud-se/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cert.pl/en/posts/2026/05/CVE-2026-42096/" target="_blank" rel="noopener noreferrer">CERT Polska</a> · <a href="https://sploit.tech/2026/05/19/Sparx-Enterprise-Architect-PCS.html" target="_blank" rel="noopener noreferrer">sploit.tech write-up</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/cve-2026-48172-litespeed-user-end-cpanel-plugin-authenticate" data-tags="vulnerabilities actively-exploited priv-esc patch-available" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-18T05:00:11Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-48172/">CVE-2026-48172</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-48172-litespeed-user-end-cpanel-plugin-authenticate"><a href="https://ctipilot.ch/entries/2026-05-18/cve-2026-48172-litespeed-user-end-cpanel-plugin-authenticate/">CVE-2026-48172 — LiteSpeed User-End cPanel plugin: authenticated cPanel user to root, actively exploited</a></h3><p>CVE-2026-48172 (CWE-266 incorrect privilege assignment, CVSS 10.0) in the LiteSpeed User-End cPanel plugin versions 2.3–2.4.4 lets an authenticated cPanel user escalate to root via the <code>lsws.redisAble</code> path, and is actively exploited. Shared-hosting and managed-WordPress estates running cPanel + LiteSpeed are the exposed population — a single low-privilege hosting account becomes root on the node. Patch to the vendor-recommended build (LiteSpeed advises 2.4.7 / WHM plugin 5.3.1.0) immediately and audit for unexpected root-level cron or service modifications on affected nodes.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">CVE-2026-48172 (CWE-266 incorrect privilege assignment, CVSS 10.0) in the LiteSpeed User-End cPanel plugin versions 2.3–2.4.4 lets an authenticated cPanel user escalate to root via the lsws.redisAble path, and is actively exploited.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/cve-2026-48172-litespeed-user-end-cpanel-plugin-authenticate/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.litespeedtech.com/2026/05/21/security-update-for-litespeed-cpanel-plugin/" target="_blank" rel="noopener noreferrer">LiteSpeed</a> · <a href="https://github.com/advisories/GHSA-fxrh-cwjh-m33v" target="_blank" rel="noopener noreferrer">GitHub Advisory GHSA-fxrh-cwjh-m33v</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/cve-2026-45829-chromadb-python-server-pre-auth-rce-before-th" data-tags="vulnerabilities rce pre-auth no-patch poc-public ai-abuse" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-18T05:00:10Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-45829/">CVE-2026-45829</a></div><h3 class="f-h" id="cve-2026-45829-chromadb-python-server-pre-auth-rce-before-th"><a href="https://ctipilot.ch/entries/2026-05-18/cve-2026-45829-chromadb-python-server-pre-auth-rce-before-th/">CVE-2026-45829 — ChromaDB Python server: pre-auth RCE before the auth check, still unpatched</a></h3><p>HiddenLayer / Hadrian researchers disclosed a CVSS 10.0 pre-authentication RCE in ChromaDB&#39;s Python FastAPI server (affected from v1.0.0): the embedding-function model is loaded before the authentication check runs, so an unauthenticated request reaches code execution &quot;before it asks who you are.&quot; Public PoC, <strong>still unpatched in v1.5.9</strong>. ChromaDB is a common vector-store backend for retrieval-augmented-generation stacks now appearing in public-sector AI pilots; any internet-reachable instance is exposed. Take ChromaDB off the public internet and front it with an authenticating reverse proxy until a fix ships.</p><div class="prov"><span>vulnerability</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/cve-2026-45829-chromadb-python-server-pre-auth-rce-before-th/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://hadrian.io/blog/cve-2026-45829----chromadb-python-server-hands-you-rce-before-it-asks-who-you-are" target="_blank" rel="noopener noreferrer">Hadrian Security</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/cve-2026-42822-azure-local-disconnected-operations-cvss-10-0" data-tags="vulnerabilities cloud auth-bypass priv-esc" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-18T05:00:09Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-42822/">CVE-2026-42822</a></div><h3 class="f-h" id="cve-2026-42822-azure-local-disconnected-operations-cvss-10-0"><a href="https://ctipilot.ch/entries/2026-05-18/cve-2026-42822-azure-local-disconnected-operations-cvss-10-0/">CVE-2026-42822 — Azure Local Disconnected Operations: CVSS 10.0 unauthenticated network elevation-of-privilege</a></h3><p>Microsoft assigned CVE-2026-42822 (CVSS 10.0, CWE-287 Improper Authentication, <code>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</code>) to an authentication-bypass flaw in Azure Local Disconnected Operations (ALDO), rated &quot;Exploitation More Likely.&quot; ALDO is the air-gapped/sovereign-cloud deployment mode that public-sector and regulated operators specifically choose for data-residency reasons — so this CVSS-10 bug lands squarely on the deployments most likely to hold sensitive workloads. No confirmed exploitation; treat as a high-priority patch given the &quot;More Likely&quot; rating and the sovereign-deployment exposure.</p><div class="prov"><span>vulnerability</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/cve-2026-42822-azure-local-disconnected-operations-cvss-10-0/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42822" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/cve-2026-20223-cisco-secure-workload-cvss-10-0-zero-auth-res" data-tags="vulnerabilities rce pre-auth" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-18T05:00:08Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20223/">CVE-2026-20223</a></div><h3 class="f-h" id="cve-2026-20223-cisco-secure-workload-cvss-10-0-zero-auth-res"><a href="https://ctipilot.ch/entries/2026-05-18/cve-2026-20223-cisco-secure-workload-cvss-10-0-zero-auth-res/">CVE-2026-20223 — Cisco Secure Workload: CVSS 10.0 zero-auth REST API grants Site Admin across all tenants, no workaround</a></h3><p>An access-validation failure in the internal REST API of Cisco Secure Workload (formerly Tetration), the enterprise micro-segmentation platform, lets an unauthenticated network attacker obtain Site Admin privileges across all tenants (CVSS 10.0, <code>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</code>). There is <strong>no workaround</strong> — patching is the only remediation. No confirmed exploitation yet, but a perfect-10 zero-auth admin bug on a segmentation controller is an attractive target: compromise of the micro-segmentation fabric undermines every downstream lateral-movement control. NCSC.ch carried it on the Cyber Security Hub (post 12588). Patch on the highest-priority schedule and restrict management-plane network reachability in the interim.</p><div class="prov"><span>vulnerability</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/cve-2026-20223-cisco-secure-workload-cvss-10-0-zero-auth-res/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy" target="_blank" rel="noopener noreferrer">Cisco PSIRT advisory</a> · <a href="https://www.theregister.com/security/2026/05/21/cisco-serves-up-yet-another-perfect-10-bug-with-secure-workload-admin-flaw/5244012" target="_blank" rel="noopener noreferrer">The Register</a></div></article><div class="sect" id="sector-victim-patterns"><span class="n">04</span><span class="t">Sector &amp; victim patterns</span><span class="c">5 items</span></div><article class="finding entry-card" data-entry-id="2026-05-18/healthcare-dach-the-soft-surface-is-the-administrative-inter" data-tags="ransomware data-breach supply-chain" data-regions="dach europe" data-kind="synthesis" data-priority="high" data-discovered="2026-05-18T05:00:14Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="healthcare-dach-the-soft-surface-is-the-administrative-inter"><a href="https://ctipilot.ch/entries/2026-05-18/healthcare-dach-the-soft-surface-is-the-administrative-inter/">Healthcare (DACH) — the soft surface is the administrative intermediary, not the hospital</a></h3><p>Two DACH healthcare data-theft events this window both hit <em>intermediaries</em> rather than clinical systems: the Unimed billing processor (exposing patient records across at least six German university hospitals) and ARWINI, the Lower Saxony prescription-audit body (Kairos claims 2.87 TB including ~70,000 Art. 9 records) — both detailed in § 5. The pattern for Swiss and German healthcare CISOs is concentration risk in the back-office tier: billing, audit, lab and imaging processors aggregate patient data from many providers and become a single high-value, lower-defended target. Inventory which processors hold your Art. 9 data and confirm each one&#39;s breach-notification SLA and security attestation.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/healthcare-dach-the-soft-surface-is-the-administrative-inter/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://therecord.media/hackers-steal-patient-billing-data-german-hospitals" target="_blank" rel="noopener noreferrer">The Record — German hospital billing breach</a> · <a href="https://www.aerzteblatt.de/news/hackerangriff-auf-rezeptprufer-c259a70c-595b-4770-9d84-87f6c8338c0c" target="_blank" rel="noopener noreferrer">Deutsches Ärzteblatt — ARWINI</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/education-virtual-classroom-platforms-and-edtech-saas-exposu" data-tags="vulnerabilities data-breach auth-bypass" data-regions="europe dach switzerland" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:17Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="education-virtual-classroom-platforms-and-edtech-saas-exposu"><a href="https://ctipilot.ch/entries/2026-05-18/education-virtual-classroom-platforms-and-edtech-saas-exposu/">Education — virtual-classroom platforms and EdTech SaaS exposure</a></h3><p>BigBlueButton — the open-source virtual-classroom platform deployed across German DFN, <strong>Swiss SWITCH</strong> and pan-European GÉANT academic networks, including cantonal school deployments — disclosed three flaws (weak session-token randomness, API checksum bypass, SSRF) in bbb-web &lt; 3.0.21 / &lt; 3.0.23 (<a href="https://ctipilot.ch/briefs/2026-05-19/" target="_blank" rel="noopener noreferrer">daily 2026-05-19</a>). In parallel, 7-Eleven became the latest named victim of the ShinyHunters Salesforce campaign that also claimed Instructure/Canvas (§ 5) — keeping EdTech SaaS supply-chain exposure live for the universities and cantonal education directorates that depend on these platforms. Patch BigBlueButton to the fixed branches and re-audit Canvas/Instructure-connected OAuth scopes.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/education-virtual-classroom-platforms-and-edtech-saas-exposu/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-7959-pf2v-xc4h" target="_blank" rel="noopener noreferrer">BigBlueButton — GHSA-7959-pf2v-xc4h</a> · <a href="https://www.securityweek.com/7-eleven-data-breach-confirmed-after-shinyhunters-ransom-demand/" target="_blank" rel="noopener noreferrer">SecurityWeek — 7-Eleven / ShinyHunters</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/telecom-sustained-pressure-from-espionage-tradecraft-and-fra" data-tags="nation-state espionage vulnerabilities china-nexus" data-regions="europe global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:16Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="telecom-sustained-pressure-from-espionage-tradecraft-and-fra"><a href="https://ctipilot.ch/entries/2026-05-18/telecom-sustained-pressure-from-espionage-tradecraft-and-fra/">Telecom — sustained pressure from espionage tradecraft and fragile carrier infrastructure</a></h3><p>Telecom was hit on two axes. Calypso/Red Lamassu&#39;s purpose-built Showboat/JFMBackdoor implant pair (§ 7) signals long-haul espionage intent against carriers, while Recorded Future&#39;s disclosure that a <strong>Huawei VRP enterprise-router zero-day</strong> caused the July 2025 POST Luxembourg nationwide telecom outage — with no CVE filed ten months later — exposes the fragility and disclosure-opacity of carrier-grade network gear (<a href="https://ctipilot.ch/briefs/2026-05-20/" target="_blank" rel="noopener noreferrer">daily 2026-05-20</a>, [SINGLE-SOURCE]). For CH/EU telecom and any public-sector operator depending on carrier uplinks, the combined lesson is that the network-infrastructure layer is both actively espionage-targeted and carries undisclosed vendor risk.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/telecom-sustained-pressure-from-espionage-tradecraft-and-fra/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.lumen.com/blog/en-us/introducing-showboat-a-new-malware-family-taunts-defenses-and-targets-international-telecom-firms" target="_blank" rel="noopener noreferrer">Lumen Black Lotus Labs — Showboat</a> · <a href="https://therecord.media/huawei-zero-day-behind-last-year-luxembourg-telecom-outage" target="_blank" rel="noopener noreferrer">The Record — Huawei VRP / POST Luxembourg</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/public-administration-web-cms-and-identity-estate-under-mult" data-tags="vulnerabilities nation-state data-breach" data-regions="europe switzerland" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:15Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="public-administration-web-cms-and-identity-estate-under-mult"><a href="https://ctipilot.ch/entries/2026-05-18/public-administration-web-cms-and-identity-estate-under-mult/">Public administration — web-CMS and identity estate under multi-vector pressure</a></h3><p>Public-sector web and identity infrastructure took hits from several directions this week: the actively-exploited Drupal pre-auth SQLi (§ 1), ANSSI/CERT-FR&#39;s CERTFR-2026-AVI-0635 on <strong>SPIP &lt; 4.4.15</strong> (the dominant French public-administration CMS), the unpatched Sparx Enterprise Architect chain and the Keycloak IAM cluster (§ 3), and Webworm&#39;s pivot to EU government targets (§ 7). Add the Krebs-reported CISA-contractor exposure of AWS GovCloud admin keys in a public GitHub repo for ~6 months (<a href="https://ctipilot.ch/briefs/2026-05-19/" target="_blank" rel="noopener noreferrer">daily 2026-05-19</a>) and the Rhysida Stuttgart claim (§ 5), and the week&#39;s signal is that the public-administration estate&#39;s CMS, IAM and cloud-credential surfaces are all live targets simultaneously. Prioritise the CMS/IAM patch SLAs and audit cloud-credential hygiene in contractor repositories.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/public-administration-web-cms-and-identity-estate-under-mult/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0635/" target="_blank" rel="noopener noreferrer">ANSSI / CERT-FR — CERTFR-2026-AVI-0635 (SPIP)</a> · <a href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/" target="_blank" rel="noopener noreferrer">Krebs on Security — CISA GovCloud keys</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/technology-developer-toolchain-ci-cd-supply-chain-remains-th" data-tags="supply-chain actively-exploited cloud identity" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-18T05:00:18Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="technology-developer-toolchain-ci-cd-supply-chain-remains-th"><a href="https://ctipilot.ch/entries/2026-05-18/technology-developer-toolchain-ci-cd-supply-chain-remains-th/">Technology / developer toolchain — CI/CD supply chain remains the week&#39;s highest-volume attack surface</a></h3><p>The Shai-Hulud/Megalodon waves (§ 2) made the developer toolchain the single most-targeted surface of the week by volume — 5,561 repositories mass-poisoned in one Megalodon burst, GitHub&#39;s own internal repos exfiltrated, and the SLSA BL3 trust model invalidated. The cross-cutting lesson for every sector running CI/CD (which is now every sector) is that build-time trust controls — OIDC token scoping, provenance attestation, registry publishing gates — are the contested ground, and the npm staged-publishing GA (§ 8) is the first registry-level structural response.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/technology-developer-toolchain-ci-cd-supply-chain-remains-th/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-shai-hulud-megalodon-supply-chain-cascade/" target="_blank" rel="noopener noreferrer">Cloud Security Alliance — Shai-Hulud/Megalodon research note</a> · <a href="https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/" target="_blank" rel="noopener noreferrer">SafeDep — Megalodon</a></div></article><div class="sect" id="incidents-disclosures-recap"><span class="n">05</span><span class="t">Incidents &amp; disclosures recap</span><span class="c">7 items</span></div><article class="finding entry-card" data-entry-id="2026-05-18/thorchain-11m-cross-chain-vault-drain-on-a-switzerland-based" data-tags="cryptocrime organized-crime" data-regions="switzerland global" data-kind="incident" data-priority="notable" data-discovered="2026-05-18T05:00:25Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="thorchain-11m-cross-chain-vault-drain-on-a-switzerland-based"><a href="https://ctipilot.ch/entries/2026-05-18/thorchain-11m-cross-chain-vault-drain-on-a-switzerland-based/">THORChain — ~$11M cross-chain vault drain on a Switzerland-based protocol</a></h3><p>A malicious validator node drained approximately $11M in protocol-owned funds from THORChain — a Switzerland-based decentralised cross-chain liquidity protocol — across nine chains on 2026-05-15, covered <a href="https://ctipilot.ch/briefs/2026-05-18/" target="_blank" rel="noopener noreferrer">2026-05-18</a>. Notable for this audience only as a Swiss-nexus financial-infrastructure incident; the root cause is a threshold-signature (GG20) vault-control failure rather than a defender-actionable enterprise TTP.</p><div class="prov"><span>incident</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/thorchain-11m-cross-chain-vault-drain-on-a-switzerland-based/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://therecord.media/more-than-10-million-stolen-crypto-platform-thorchain" target="_blank" rel="noopener noreferrer">The Record, 2026-05-15</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/rhysida-claims-stuttgart-municipal-data-city-denies-a-confir" data-tags="ransomware data-breach organized-crime" data-regions="europe dach" data-kind="incident" data-priority="notable" data-discovered="2026-05-18T05:00:24Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="rhysida-claims-stuttgart-municipal-data-city-denies-a-confir"><a href="https://ctipilot.ch/entries/2026-05-18/rhysida-claims-stuttgart-municipal-data-city-denies-a-confir/">Rhysida claims Stuttgart municipal data — city denies a confirmed incident</a></h3><p>The Rhysida RaaS group listed Landeshauptstadt Stuttgart (~600,000 residents) on its leak site in mid-May 2026, demanding 5 BTC; the city states it has not confirmed an incident, covered <a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">2026-05-23</a>. Recorded as a claim, not a breach — Rhysida has a history of both genuine municipal compromises and opportunistic re-listing of prior dumps. Watch for a city confirmation or sample-data publication before treating as substantiated.</p><div class="prov"><span>incident</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/rhysida-claims-stuttgart-municipal-data-city-denies-a-confir/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.heise.de/en/news/Cyber-gang-Rhysida-claims-data-theft-from-Stuttgart-city-11301876.html" target="_blank" rel="noopener noreferrer">heise online (EN)</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/7-eleven-shinyhunters-salesforce-campaign-claims-another-600" data-tags="data-breach identity cloud organized-crime" data-regions="global europe" data-kind="incident" data-priority="notable" data-discovered="2026-05-18T05:00:21Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="7-eleven-shinyhunters-salesforce-campaign-claims-another-600"><a href="https://ctipilot.ch/entries/2026-05-18/7-eleven-shinyhunters-salesforce-campaign-claims-another-600/">7-Eleven — ShinyHunters Salesforce campaign claims another 600,000+ records</a></h3><p>7-Eleven confirmed on <a href="https://ctipilot.ch/briefs/2026-05-19/" target="_blank" rel="noopener noreferrer">2026-05-18</a> that an unauthorised third party accessed franchise-application records (600,000+) in a breach ShinyHunters claimed in April 2026. The operational point for this audience is the campaign, not the victim: 7-Eleven joins Instructure, Vimeo, Wynn Resorts, Vercel and Medtronic as named victims of the same Salesforce-targeting ShinyHunters operation. Any organisation with Salesforce connected apps and OAuth-integrated third parties should re-audit connected-app scopes and refresh-token lifetimes.</p><div class="prov"><span>incident</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/7-eleven-shinyhunters-salesforce-campaign-claims-another-600/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.securityweek.com/7-eleven-data-breach-confirmed-after-shinyhunters-ransom-demand/" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/arwini-lower-saxony-prescription-audit-body-exfiltration-con" data-tags="ransomware data-breach" data-regions="dach europe" data-kind="incident" data-priority="notable" data-discovered="2026-05-18T05:00:20Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="arwini-lower-saxony-prescription-audit-body-exfiltration-con"><a href="https://ctipilot.ch/entries/2026-05-18/arwini-lower-saxony-prescription-audit-body-exfiltration-con/">ARWINI (Lower Saxony prescription-audit body) — exfiltration confirmed; Kairos claims 2.87 TB including ~70,000 GDPR Art. 9 records</a></h3><p>Investigators confirmed on <a href="https://ctipilot.ch/briefs/2026-05-19/" target="_blank" rel="noopener noreferrer">2026-05-18</a> that the cyberattack on ARWINI — the body that audits prescription cost-effectiveness for statutory health insurers in Lower Saxony — exfiltrated data after a 4 May intrusion. The Kairos ransomware group claims 2.87 TB, with roughly 70,000 special-category (Art. 9) health records in scope. This is the second DACH healthcare-adjacent data-theft event of the window after Unimed, reinforcing that the sector&#39;s softest surfaces are the administrative and audit intermediaries, not the hospitals&#39; clinical systems.</p><div class="prov"><span>incident</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/arwini-lower-saxony-prescription-audit-body-exfiltration-con/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.aerzteblatt.de/news/hackerangriff-auf-rezeptprufer-c259a70c-595b-4770-9d84-87f6c8338c0c" target="_blank" rel="noopener noreferrer">Deutsches Ärzteblatt</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/six-german-university-hospitals-patient-records-exfiltrated" data-tags="ransomware data-breach supply-chain" data-regions="dach europe" data-kind="incident" data-priority="notable" data-discovered="2026-05-18T05:00:19Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="six-german-university-hospitals-patient-records-exfiltrated"><a href="https://ctipilot.ch/entries/2026-05-18/six-german-university-hospitals-patient-records-exfiltrated/">Six German university hospitals — patient records exfiltrated via billing processor Unimed</a></h3><p>Unimed, a Saarland-based billing-service provider that handles private-insurance and self-payer invoicing for an estimated 95% of German university hospitals, was breached in mid-April 2026; patient billing data for at least six university hospitals — including Uniklinikum Freiburg and Uniklinik Köln, which issued their own notifications on 2026-05-21 — was stolen; The Record tallies ~96,600 records across four named hospitals, with further hospitals affected per heise&#39;s per-hospital breakdown, as of <a href="https://ctipilot.ch/briefs/2026-05-24/" target="_blank" rel="noopener noreferrer">2026-05-24</a>. The defender lesson is the concentration multiplier: one processor breach simultaneously becomes a GDPR Art. 33/34 event for every covered hospital. CH/EU healthcare entities should inventory which billing, lab, and imaging processors hold their patient data and confirm each processor&#39;s breach-notification SLA.</p><div class="prov"><span>incident</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/six-german-university-hospitals-patient-records-exfiltrated/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://therecord.media/hackers-steal-patient-billing-data-german-hospitals" target="_blank" rel="noopener noreferrer">The Record, 2026-05-22</a> · <a href="https://www.heise.de/en/news/Patient-data-affected-Cyberattack-on-billing-service-provider-for-clinics-11305015.html" target="_blank" rel="noopener noreferrer">heise online, 2026-05-22</a> · <a href="https://www.uk-koeln.de/uniklinik-koeln/aktuelles/detailansicht/cyberkriminelle-entwenden-patientendaten-bei-externem-abrechnungs-dienstleister/" target="_blank" rel="noopener noreferrer">Uniklinik Köln, 2026-05-21</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/west-pharmaceutical-services-8-k-a-confirms-full-operational" data-tags="data-breach" data-regions="global" data-kind="incident" data-priority="notable" data-discovered="2026-05-18T05:00:23Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="west-pharmaceutical-services-8-k-a-confirms-full-operational"><a href="https://ctipilot.ch/entries/2026-05-18/west-pharmaceutical-services-8-k-a-confirms-full-operational/">West Pharmaceutical Services — 8-K/A confirms full operational restoration</a></h3><p>West Pharmaceutical Services (NYSE: WST) filed an 8-K/A amendment under SEC Item 1.05 on <a href="https://ctipilot.ch/briefs/2026-05-22/" target="_blank" rel="noopener noreferrer">2026-05-20</a> confirming full operational restoration across all manufacturing facilities, with the data investigation still ongoing. Closing the loop on the W20 disclosure: the manufacturing-line continuity risk this audience was tracking has resolved; the residual is the data-scope determination.</p><div class="prov"><span>incident</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/west-pharmaceutical-services-8-k-a-confirms-full-operational/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sec.gov/Archives/edgar/data/0000105770/000010577026000077/wst-20260507.htm" target="_blank" rel="noopener noreferrer">SEC EDGAR 8-K/A</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/grafana-labs-coinbasecartel-source-code-only-theft-confirmed" data-tags="data-breach supply-chain organized-crime" data-regions="global" data-kind="incident" data-priority="notable" data-discovered="2026-05-18T05:00:22Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="grafana-labs-coinbasecartel-source-code-only-theft-confirmed"><a href="https://ctipilot.ch/entries/2026-05-18/grafana-labs-coinbasecartel-source-code-only-theft-confirmed/">Grafana Labs / CoinbaseCartel — source-code-only theft confirmed; ransom rejected; detected by canary token</a></h3><p>Grafana Labs confirmed on <a href="https://ctipilot.ch/briefs/2026-05-19/" target="_blank" rel="noopener noreferrer">2026-05-18</a> that the CoinbaseCartel data-extortion group used a compromised GitHub token granting access to Grafana&#39;s GitHub environment to exfiltrate private source code only — no customer data, no production systems — and that it rejected the ransom. (Earlier reporting attributed the entry to a <code>pull_request_target</code> GitHub Actions misconfiguration and credited a canary token with detection; the in-window victim-confirmation sources cited here state only the compromised-token vector, so those mechanism specifics are not asserted as fact.) The defender takeaway the sources do support: audit GitHub token scopes and lifetimes aggressively, restrict <code>pull_request_target</code> workflows as general hardening, and seed canary artefacts in private repositories as a low-cost detection layer for source-code exfiltration.</p><div class="prov"><span>incident</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/grafana-labs-coinbasecartel-source-code-only-theft-confirmed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/05/grafana-github-token-breach-led-to.html" target="_blank" rel="noopener noreferrer">The Hacker News — CoinbaseCartel / Grafana breach</a> · <a href="https://www.securityweek.com/grafana-confirms-breach-after-hackers-claim-they-stole-data/" target="_blank" rel="noopener noreferrer">SecurityWeek — Grafana confirms breach</a></div></article><div class="sect" id="annual-periodic-threat-reports"><span class="n">06</span><span class="t">Annual / periodic threat reports</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-05-18/verizon-2026-dbir-vulnerability-exploitation-is-the-1-breach" data-tags="vulnerabilities ransomware supply-chain ai-abuse identity" data-regions="global" data-kind="annual-report" data-priority="high" data-discovered="2026-05-18T05:00:26Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="verizon-2026-dbir-vulnerability-exploitation-is-the-1-breach"><a href="https://ctipilot.ch/entries/2026-05-18/verizon-2026-dbir-vulnerability-exploitation-is-the-1-breach/">Verizon 2026 DBIR — vulnerability exploitation is the #1 breach vector for the first time in 19 years; patching cadence regressed</a></h3><p>The 19th Data Breach Investigations Report (published 2026-05-19, covering Nov 2024 – Oct 2025) records vulnerability exploitation as the most common initial-access vector at ~31%, overtaking credential abuse (~13%) for the first time in the report&#39;s history — Verizon attributes the shift in part to AI-assisted weaponisation compressing the disclosure-to-exploit window. The operationally relevant findings for a public-sector SOC are the defensive regressions, not the headline: the median time to fully patch slipped to ~43 days (from ~32), and organisations remediated only ~26% of CISA KEV-listed vulnerabilities (down from ~38%) against ~50% more critical bugs than the prior dataset. Third-party involvement in breaches rose to ~48% of incidents. These are the precise gaps this week&#39;s actively-exploited CVEs (Drupal, Apex One, Langflow, Defender) target; under NIS2 Art. 21(2)(e) the patching-process regression is also a supervisory-audit exposure. &quot;Shadow AI&quot; (unapproved AI tooling) emerged as a notable data-loss action — scope DLP and data-classification controls to LLM upload endpoints.</p><div class="prov"><span>annual-report</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/verizon-2026-dbir-vulnerability-exploitation-is-the-1-breach/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.verizon.com/about/news/breach-industry-wide-dbir-finds" target="_blank" rel="noopener noreferrer">Verizon — 2026 DBIR announcement</a> · <a href="https://www.securityweek.com/verizon-dbir-2026-vulnerability-exploitation-overtakes-credential-theft-as-top-breach-vector/" target="_blank" rel="noopener noreferrer">SecurityWeek</a> · <a href="https://www.helpnetsecurity.com/2026/05/20/verizon-2026-dbir-findings/" target="_blank" rel="noopener noreferrer">Help Net Security</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/check-point-research-march-april-2026-ai-threat-landscape-di" data-tags="ai-abuse espionage supply-chain organized-crime" data-regions="global latam" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-18T05:00:28Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="check-point-research-march-april-2026-ai-threat-landscape-di"><a href="https://ctipilot.ch/entries/2026-05-18/check-point-research-march-april-2026-ai-threat-landscape-di/">Check Point Research March–April 2026 AI Threat Landscape Digest — operator-run AI platforms breach government agencies</a></h3><p>Check Point&#39;s AI Threat Landscape Digest (published 2026-05-22, covered <a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">2026-05-23</a>) documents a single operator running two AI platforms in parallel to breach nine Mexican government agencies — the most concrete public example yet of AI tooling operationalised for end-to-end intrusion rather than reconnaissance assistance. Single-source (Check Point only); the synthesis relevant to this audience is the trajectory, not the victim count: where the Verizon and Rapid7 reports show AI compressing the exploitation timeline, this shows AI compressing the <em>operator skill floor</em> — fewer skilled humans needed per campaign. Treat as a directional indicator pending independent corroboration.</p><div class="prov"><span>annual-report</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/check-point-research-march-april-2026-ai-threat-landscape-di/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.checkpoint.com/research/ai-attacks-are-no-longer-experimental-key-findings-from-the-march-april-2026-ai-threat-landscape/" target="_blank" rel="noopener noreferrer">Check Point Research — AI Threat Landscape</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/rapid7-q1-2026-threat-landscape-report-corroborates-the-stru" data-tags="vulnerabilities ransomware nation-state ai-abuse" data-regions="global" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-18T05:00:27Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="rapid7-q1-2026-threat-landscape-report-corroborates-the-stru"><a href="https://ctipilot.ch/entries/2026-05-18/rapid7-q1-2026-threat-landscape-report-corroborates-the-stru/">Rapid7 Q1 2026 Threat Landscape Report — corroborates the structural shift; KEV-to-listing window collapsing</a></h3><p>Rapid7&#39;s Q1 2026 report (published 2026-05-21, covering Jan–Mar 2026 IR data, covered <a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">2026-05-23</a>) independently finds vulnerability exploitation as the top initial-access vector at ~38%. Read alongside the Verizon DBIR, the two datasets agree on direction even where the absolute percentages differ (different windows, different telemetry) — the synthesis a daily reader could not see is that this is a <em>corroborated</em> structural change, not a single-vendor artefact. For CH/EU defenders this argues for prioritising edge-device and public-facing-application patch SLAs over generic awareness programmes.</p><div class="prov"><span>annual-report</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/rapid7-q1-2026-threat-landscape-report-corroborates-the-stru/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.rapid7.com/blog/post/tr-q1-2026-threat-landscape-report-geopolitics-ransomware/" target="_blank" rel="noopener noreferrer">Rapid7 Q1 2026 Threat Landscape Report</a> · <a href="https://www.globenewswire.com/news-release/2026/05/21/3299378/36514/en/Rapid7-Q1-2026-Threat-Landscape-Report-Finds-Vulnerability-Exploitation-Overtakes-Social-Engineering-as-the-Top-Initial-Access-Vector.html" target="_blank" rel="noopener noreferrer">GlobeNewswire — Rapid7 Q1 2026 release</a></div></article><div class="sect" id="long-running-campaigns-status-update"><span class="n">07</span><span class="t">Long-running campaigns · status update</span><span class="c">7 items</span></div><article class="finding entry-card" data-entry-id="2026-05-18/midnight-blizzard-and-others-operationalise-roadtools-for-en" data-tags="nation-state espionage identity cloud russia-nexus iran-nexus" data-regions="global europe" data-kind="synthesis" data-priority="high" data-discovered="2026-05-18T05:00:31Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="midnight-blizzard-and-others-operationalise-roadtools-for-en"><a href="https://ctipilot.ch/entries/2026-05-18/midnight-blizzard-and-others-operationalise-roadtools-for-en/">Midnight Blizzard and others operationalise ROADtools for Entra ID abuse</a></h3><p>Unit 42 documented systematic nation-state operationalisation of the open-source <strong>ROADtools</strong> Entra ID framework by Midnight Blizzard, Curious Serpens and UTA0355 for device registration, token theft and tenant enumeration (<a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">daily 2026-05-23</a>). This is the most broadly relevant item in the section — every M365/Entra tenant is in scope. Hunt for unexpected device-registration events, anomalous service-principal token requests, and ROADtools-characteristic enumeration patterns; tighten conditional-access on device-registration and review legacy-auth exposure.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/midnight-blizzard-and-others-operationalise-roadtools-for-en/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/" target="_blank" rel="noopener noreferrer">Unit 42 — ROADtools cloud attacks</a> · <a href="https://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/" target="_blank" rel="noopener noreferrer">Volexity — OAuth device-code background</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/the-gentlemen-raas-czech-university-and-swiss-engineering-fi" data-tags="ransomware organized-crime" data-regions="europe switzerland" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:35Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="the-gentlemen-raas-czech-university-and-swiss-engineering-fi"><a href="https://ctipilot.ch/entries/2026-05-18/the-gentlemen-raas-czech-university-and-swiss-engineering-fi/">The Gentlemen RaaS — Czech university and Swiss engineering firm listed; comms overhaul continues</a></h3><p>The Gentlemen RaaS listed two new European victims — the University of Finance and Administration (Czech Republic) and a Swiss engineering firm — on its leak site (<a href="https://ctipilot.ch/briefs/2026-05-20/" target="_blank" rel="noopener noreferrer">daily 2026-05-20</a>). The operator&#39;s previously-announced communications-infrastructure overhaul (rather than shutdown) means continued activity; the Swiss-victim listing is the direct CH-nexus signal this week. Watch for sample-data publication confirming the listings versus opportunistic re-listing.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/the-gentlemen-raas-czech-university-and-swiss-engineering-fi/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.dexpose.io/thegentlemen-target-university-of-finance-and-administration-in-czech-republic/" target="_blank" rel="noopener noreferrer">DeXpose — TheGentlemen Czech university listing</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/fox-tempest-microsoft-dcu-disrupts-the-malware-signing-servi" data-tags="ransomware supply-chain law-enforcement organized-crime identity" data-regions="global europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:34Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="fox-tempest-microsoft-dcu-disrupts-the-malware-signing-servi"><a href="https://ctipilot.ch/entries/2026-05-18/fox-tempest-microsoft-dcu-disrupts-the-malware-signing-servi/">Fox Tempest — Microsoft DCU disrupts the malware-signing service feeding Rhysida, INC, Qilin and Akira</a></h3><p>Microsoft Threat Intelligence and the Digital Crimes Unit disrupted <strong>Fox Tempest</strong>, a malware-signing-as-a-service operation that supplied code-signing to multiple ransomware operations (<a href="https://ctipilot.ch/briefs/2026-05-20/" target="_blank" rel="noopener noreferrer">daily 2026-05-20</a>). Status: disrupted via combined intelligence exposure and a sealed US legal action. The defender takeaway is that code-signing trust on binaries attributable to Rhysida/INC/Qilin/Akira tooling should not be treated as a benign signal — the signing pipeline was a criminal service.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/fox-tempest-microsoft-dcu-disrupts-the-malware-signing-servi/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/" target="_blank" rel="noopener noreferrer">Microsoft Threat Intelligence — Fox Tempest</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/calypso-red-lamassu-bronze-medley-china-aligned-showboat-and" data-tags="nation-state espionage china-nexus" data-regions="europe middle-east apac" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:33Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="calypso-red-lamassu-bronze-medley-china-aligned-showboat-and"><a href="https://ctipilot.ch/entries/2026-05-18/calypso-red-lamassu-bronze-medley-china-aligned-showboat-and/">Calypso / Red Lamassu (Bronze Medley, China-aligned) — Showboat and JFMBackdoor against telecoms</a></h3><p>Lumen Black Lotus Labs and PwC disclosed two purpose-built implants — <strong>Showboat</strong> (Linux) and <strong>JFMBackdoor</strong> (Windows) — used by Calypso against international telecom firms (<a href="https://ctipilot.ch/briefs/2026-05-22/" target="_blank" rel="noopener noreferrer">daily 2026-05-22</a>).</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/calypso-red-lamassu-bronze-medley-china-aligned-showboat-and/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.lumen.com/blog/en-us/introducing-showboat-a-new-malware-family-taunts-defenses-and-targets-international-telecom-firms" target="_blank" rel="noopener noreferrer">Lumen Black Lotus Labs — Showboat</a> · <a href="https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/red-lamassu-open-season.html" target="_blank" rel="noopener noreferrer">PwC Threat Intelligence</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/ghostwriter-uac-0057-frostyneighbor-belarus-aligned-new-oyst" data-tags="nation-state espionage russia-nexus" data-regions="europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:30Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="ghostwriter-uac-0057-frostyneighbor-belarus-aligned-new-oyst"><a href="https://ctipilot.ch/entries/2026-05-18/ghostwriter-uac-0057-frostyneighbor-belarus-aligned-new-oyst/">Ghostwriter / UAC-0057 / FrostyNeighbor (Belarus-aligned) — new OYSTER implant chain</a></h3><p>CERT-UA documented a spring-2026 phishing campaign deploying a new <strong>OYSTERFRESH → OYSTERBLUES → OYSTERSHUCK</strong> implant chain via Prometheus learning-platform lures (<a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">daily 2026-05-23</a>). The campaign continues the actor&#39;s focus on Ukrainian and allied government organisations; the staged implant chain is the new tradecraft. For EU/CH government estates that share the actor&#39;s target profile, the relevant control is attachment-detonation and learning-platform-lure awareness for staff.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/ghostwriter-uac-0057-frostyneighbor-belarus-aligned-new-oyst/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/05/ghostwriter-targets-ukraine-government.html" target="_blank" rel="noopener noreferrer">The Hacker News — Ghostwriter / CERT-UA</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/webworm-china-aligned-fishmonger-aquatic-panda-pivots-to-eu" data-tags="nation-state espionage identity cloud china-nexus" data-regions="europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:29Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="webworm-china-aligned-fishmonger-aquatic-panda-pivots-to-eu"><a href="https://ctipilot.ch/entries/2026-05-18/webworm-china-aligned-fishmonger-aquatic-panda-pivots-to-eu/">Webworm (China-aligned; FishMonger / Aquatic Panda) — pivots to EU government targets</a></h3><p>ESET documented Webworm&#39;s 2025–2026 pivot to European government victims (Belgian, Italian, Serbian, Polish and Spanish governmental organisations), deploying <strong>EchoCreep</strong> (Discord-based C2) and <strong>GraphWorm</strong> (Microsoft Graph / OneDrive C2) backdoors (<a href="https://ctipilot.ch/briefs/2026-05-21/" target="_blank" rel="noopener noreferrer">daily 2026-05-21</a>). The use of Graph/OneDrive as C2 is the defender-relevant shift — it blends with legitimate M365 traffic. Hunt for anomalous Graph API usage patterns and Discord egress from server subnets that have no business reason to reach either.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/webworm-china-aligned-fishmonger-aquatic-panda-pivots-to-eu/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity — Webworm</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/screening-serpens-unc1549-iran-smoke-sandstorm-nimbus-mantic" data-tags="nation-state espionage iran-nexus" data-regions="middle-east global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-18T05:00:32Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="screening-serpens-unc1549-iran-smoke-sandstorm-nimbus-mantic"><a href="https://ctipilot.ch/entries/2026-05-18/screening-serpens-unc1549-iran-smoke-sandstorm-nimbus-mantic/">Screening Serpens / UNC1549 (Iran; Smoke Sandstorm / Nimbus Manticore) — AppDomainManager hijacking in six new RATs</a></h3><p>Unit 42 detailed Screening Serpens using <strong>AppDomainManager hijacking</strong> to silently disable ETW and strong-name verification across six newly-documented RATs (<a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">daily 2026-05-23</a>). The ETW-blinding plus strong-name-check bypass is the detection-relevant tradecraft — it defeats both behavioural telemetry and signature-trust controls in one step. Where AppDomainManager-redirection is not required by an application, monitor for the <code>appDomainManagerAssembly</code> / <code>appDomainManagerType</code> config and environment-variable hijack vectors.</p><div class="prov"><span>synthesis</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/screening-serpens-unc1549-iran-smoke-sandstorm-nimbus-mantic/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/" target="_blank" rel="noopener noreferrer">Unit 42 — Screening Serpens</a> · <a href="https://www.cybersecuritydive.com/news/iran-cyberattacks-espionage-us-israel-uae/820990/" target="_blank" rel="noopener noreferrer">Cybersecurity Dive</a></div></article><div class="sect" id="policy-regulatory-horizon"><span class="n">08</span><span class="t">Policy &amp; regulatory horizon</span><span class="c">3 items</span></div><article class="finding entry-card" data-entry-id="2026-05-18/eu-20th-russia-sanctions-package-managed-security-services-p" data-tags="law-enforcement russia-nexus eu-nexus" data-regions="europe switzerland" data-kind="policy" data-priority="high" data-discovered="2026-05-18T05:00:36Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="eu-20th-russia-sanctions-package-managed-security-services-p"><a href="https://ctipilot.ch/entries/2026-05-18/eu-20th-russia-sanctions-package-managed-security-services-p/">EU 20th Russia sanctions package — managed-security-services prohibition effective 25 May; Switzerland adopted most measures 22 May</a></h3><p>The single most defender-relevant regulatory change of the window. Council Regulation (EU) 2026/506 introduces a prohibition on providing <strong>&quot;managed security services&quot;</strong> — defined to include incident handling, penetration testing, security audits and security consulting/technical-support advice — to the Government of Russia and to entities legally established in Russia, effective <strong>25 May 2026</strong>. The prohibition reaches EU-incorporated MSSPs supplying Russian subsidiaries absent a national-competent-authority licence; no European Commission interpretive guidance on scope had been published as of 24 May, so law-firm analyses advise a conservative reading. <strong>Switzerland&#39;s EAER adopted most of the 20th-package measures effective 22 May</strong> (115 individuals/entities asset-frozen, 20 Russian banks and 7 third-country intermediaries under transaction ban, RUBx / digital-ruble transactions prohibited from 26 May), deferring some energy/trade provisions; whether the Swiss transposition includes the managed-security-services prohibition specifically requires SECO confirmation. <strong>What defenders must do differently:</strong> any EU or Swiss SOC, IR firm, or pentest provider with a Russian-law-entity client must have wound those engagements down by 25 May, and should verify no security tooling (EDR agents, SIEM forwarders, ticketing/connector integrations) is being operated or serviced under a contract with a Russian-established entity.</p><div class="prov"><span>policy</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/eu-20th-russia-sanctions-package-managed-security-services-p/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.gtlaw.com/en/insights/2026/5/eus-20th-russia-sanctions-package-key-changes-and-compliance-implications" target="_blank" rel="noopener noreferrer">Greenberg Traurig — EU 20th sanctions package analysis</a> · <a href="https://www.wbf.admin.ch/en/newnsb/Byvj7-WGL93MiOgIL-f2p" target="_blank" rel="noopener noreferrer">Swiss EAER press release, 2026-05-22</a> · <a href="https://www.squirepattonboggs.com/insights/publications/the-20th-eu-sanctions-package-against-russia-scope-entry-into-force-and-compliance-implications-for-operators" target="_blank" rel="noopener noreferrer">Squire Patton Boggs</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/law-enforcement-infrastructure-takedowns-operation-saffron-s" data-tags="law-enforcement organized-crime ransomware ddos" data-regions="europe switzerland global" data-kind="policy" data-priority="notable" data-discovered="2026-05-18T05:00:38Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="law-enforcement-infrastructure-takedowns-operation-saffron-s"><a href="https://ctipilot.ch/entries/2026-05-18/law-enforcement-infrastructure-takedowns-operation-saffron-s/">Law-enforcement infrastructure takedowns — Operation Saffron (Switzerland JIT), FIOD/Stark Industries, Kimwolf, INTERPOL Ramz</a></h3><p>Four coordinated actions in the window degraded threat-actor infrastructure relevant to this audience. <strong>Operation Saffron</strong> dismantled First VPN — a Russian-language criminal anonymisation service marketed to ransomware operators — seizing 33+ servers with the user database captured; <strong>Switzerland was a named Joint Investigation Team participant</strong>, and the infrastructure is linked to Phobos RaaS (<a href="https://www.eurojust.europa.eu/news/eurojust-coordinated-investigation-shuts-down-criminal-vpn-network" target="_blank" rel="noopener noreferrer">Eurojust</a>; <a href="https://ctipilot.ch/briefs/2026-05-22/" target="_blank" rel="noopener noreferrer">daily 2026-05-22</a>). The <strong>Netherlands FIOD</strong> arrested two suspects for EU-sanctions evasion tied to the Stark Industries bulletproof-hosting front and seized ~800 servers, dismantling NoName057(16) DDoS plumbing (<a href="https://www.fiod.nl/fiod-houdt-twee-verdachten-aan-wegens-overtreding-sanctiewetgeving/" target="_blank" rel="noopener noreferrer">FIOD</a>; <a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">daily 2026-05-23</a>). The alleged operator of the <strong>Kimwolf</strong> 30+ Tbps IoT DDoS-for-hire botnet (AISURU variant) was arrested (<a href="https://www.justice.gov/usao-ak/pr/canadian-man-arrested-international-authorities-charged-administrating-kimwolf-ddos" target="_blank" rel="noopener noreferrer">US DoJ</a>; <a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">daily 2026-05-23</a>), and <strong>INTERPOL Operation Ramz</strong> logged 201 arrests across a 13-country MENA sweep including a PhaaS-server takedown (<a href="https://www.interpol.int/en/News-and-Events/News/2026/201-arrests-in-first-of-its-kind-cybercrime-operation-in-MENA-region" target="_blank" rel="noopener noreferrer">INTERPOL</a>; <a href="https://ctipilot.ch/briefs/2026-05-19/" target="_blank" rel="noopener noreferrer">daily 2026-05-19</a>). The defender-relevant pattern: the takedowns hit anonymisation/hosting/DDoS plumbing rather than end actors, so expect short-term infrastructure churn (new VPN/hosting fronts, rebuilt botnet C2) rather than a durable drop in activity.</p><div class="prov"><span>policy</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/law-enforcement-infrastructure-takedowns-operation-saffron-s/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.eurojust.europa.eu/news/eurojust-coordinated-investigation-shuts-down-criminal-vpn-network" target="_blank" rel="noopener noreferrer">Eurojust — First VPN takedown</a> · <a href="https://www.fiod.nl/fiod-houdt-twee-verdachten-aan-wegens-overtreding-sanctiewetgeving/" target="_blank" rel="noopener noreferrer">FIOD — Stark Industries arrests</a></div></article><article class="finding entry-card" data-entry-id="2026-05-18/npm-ships-2fa-gated-staged-publishing-ga-platform-governance" data-tags="supply-chain identity" data-regions="global" data-kind="policy" data-priority="notable" data-discovered="2026-05-18T05:00:37Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="npm-ships-2fa-gated-staged-publishing-ga-platform-governance"><a href="https://ctipilot.ch/entries/2026-05-18/npm-ships-2fa-gated-staged-publishing-ga-platform-governance/">npm ships 2FA-gated &quot;staged publishing&quot; GA — platform-governance response to the worm waves</a></h3><p>GitHub announced on <a href="https://ctipilot.ch/briefs/2026-05-24/" target="_blank" rel="noopener noreferrer">2026-05-22</a> that npm <strong>staged publishing</strong> is now Generally Available: a maintainer runs <code>npm stage publish</code> to create a staged release that must be explicitly promoted under 2FA before it becomes installable, alongside new install-time controls. This is the registry-level governance answer to the Shai-Hulud/Megalodon waves (§ 2) — the OIDC-token-reuse propagation primitive that made those worms self-spreading is blunted when an automated <code>npm publish</code> cannot reach end users without an interactive 2FA promotion step. Defender takeaway: where you operate internal npm publishing pipelines, adopt staged publishing and require the 2FA promotion gate; it does not retroactively clean compromised packages but it raises the cost of the next worm&#39;s propagation step.</p><div class="prov"><span>policy</span><span>18 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/npm-ships-2fa-gated-staged-publishing-ga-platform-governance/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://github.blog/changelog/2026-05-22-staged-publishing-and-new-install-time-controls-for-npm/" target="_blank" rel="noopener noreferrer">GitHub Changelog — staged publishing GA</a></div></article><div class="sect" id="looking-ahead-what-to-watch-next-week"><span class="n">09</span><span class="t">Looking ahead · what to watch next week</span><span class="c">1 item</span></div><article class="finding entry-card" data-entry-id="2026-05-18/looking-ahead-2026-w21" data-tags="vulnerabilities" data-regions="global" data-kind="outlook" data-priority="notable" data-discovered="2026-05-18T05:00:39Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="looking-ahead-2026-w21"><a href="https://ctipilot.ch/entries/2026-05-18/looking-ahead-2026-w21/">Looking ahead — 2026-W21</a></h3><p>Items already in motion at the close of 2026-W21. Not predictions — each links to the in-motion reporting underneath.</p>
<ul><li><strong>GitHub&#39;s fuller post-incident report on the internal-repo breach is still outstanding.</strong> GitHub&#39;s 2026-05-20 blog committed to a fuller report; the open questions are the full scope of the ~3,800 exfiltrated internal repos and whether any contained credentials or customer-impacting material. (<a href="https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/" target="_blank" rel="noopener noreferrer">GitHub Security Blog</a>)</li><li><strong>Shai-Hulud wave-6 candidate registries — Cargo (Rust) and Maven (Java).</strong> The OIDC-token-reuse propagation primitive is registry-agnostic; with the worm now open-sourced and commoditised, Cargo and Maven are the un-hit major ecosystems. Pre-stage Sigstore/provenance-anomaly hunts in Rust and Java dependency pipelines. (<a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-shai-hulud-megalodon-supply-chain-cascade/" target="_blank" rel="noopener noreferrer">CSA research note</a>)</li><li><strong>EU 20th-package &quot;managed security services&quot; scope guidance, and SECO confirmation of Swiss transposition.</strong> No European Commission interpretive guidance on the managed-security-services definition was published as of 24 May; SECO confirmation of whether Switzerland&#39;s 22 May adoption includes the MSS prohibition specifically is the open compliance question for CH providers. (<a href="https://www.gtlaw.com/en/insights/2026/5/eus-20th-russia-sanctions-package-key-changes-and-compliance-implications" target="_blank" rel="noopener noreferrer">Greenberg Traurig</a>)</li><li><strong>PAN-OS CVE-2026-0300 wave-2 patch builds scheduled ~2026-05-28.</strong> Remaining build streams finish the staged patch arc; audit for attacker-created rogue admin accounts before patching wipes implant artefacts. (<a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto PSIRT</a>; <a href="https://ctipilot.ch/briefs/2026-05-18/" target="_blank" rel="noopener noreferrer">daily 2026-05-18</a>)</li><li><strong>Windows YellowKey / GreenPlasma / MiniPlasma cluster — June 2026 Patch Tuesday (~2026-06-10) is the expected first fix.</strong> Three public PoCs, no out-of-band release; until then BitLocker PIN/Network-Unlock GPOs and <code>ctfmon.exe</code>-injection WDAC rules are the only controls. (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45585" target="_blank" rel="noopener noreferrer">MSRC CVE-2026-45585</a>; <a href="https://ctipilot.ch/briefs/2026-05-20/" target="_blank" rel="noopener noreferrer">daily 2026-05-20</a>)</li><li><strong>Sparx Enterprise Architect chain and ChromaDB CVE-2026-45829 remain unpatched.</strong> Both carry public PoCs with no vendor fix; watch for the patches and, in the interim, keep both off the public internet behind authenticated access. (<a href="https://cert.pl/en/posts/2026/05/CVE-2026-42096/" target="_blank" rel="noopener noreferrer">CERT-PL</a>; <a href="https://ctipilot.ch/briefs/2026-05-21/" target="_blank" rel="noopener noreferrer">daily 2026-05-21</a>)</li><li><strong>GTIG UNC6671 &quot;BlackFile&quot; probable rebrand.</strong> The DLS went offline with a shutdown message; no successor brand had emerged by week-end. Watch for a new leak-site reusing the vishing → AiTM → rogue-MFA → SharePoint-exfiltration TTP set. (<a href="https://ctipilot.ch/briefs/2026-05-23/" target="_blank" rel="noopener noreferrer">daily 2026-05-23</a>)</li></ul><div class="prov"><span>outlook</span><span>18 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-18/looking-ahead-2026-w21/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/" target="_blank" rel="noopener noreferrer">GitHub Security Blog</a> · <a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-shai-hulud-megalodon-supply-chain-cascade/" target="_blank" rel="noopener noreferrer">CSA research note</a> · <a href="https://www.gtlaw.com/en/insights/2026/5/eus-20th-russia-sanctions-package-key-changes-and-compliance-implications" target="_blank" rel="noopener noreferrer">Greenberg Traurig</a> · <a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto PSIRT</a> · <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45585" target="_blank" rel="noopener noreferrer">MSRC CVE-2026-45585</a> · <a href="https://cert.pl/en/posts/2026/05/CVE-2026-42096/" target="_blank" rel="noopener noreferrer">CERT-PL</a></div></article><details class="verif"><summary class="vh">About this weekly<span class="verif-count">1 run</span><svg class="verif-chev" viewBox="0 0 24 24" width="12" height="12" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" aria-hidden="true"><path d="M6 9l6 6 6-6"></path></svg></summary><div class="verif-body"><div class="run-note" data-run-id="2026-W21-473d6fa5"><h3 class="run-note__head"><span class="mono">2026-W21-473d6fa5</span> <span class="muted">· weekly · Claude Opus 4.7 · 40 entries published</span></h3><div class="run-note__body"><ul><li><strong><code>[SINGLE-SOURCE]</code> items carried forward:</strong> Check Point&#39;s AI Threat Landscape Digest (§ 6, single-vendor); the Huawei VRP / POST Luxembourg outage root-cause (§ 4, Recorded Future News only, no CVE filed); the Rhysida Stuttgart claim (§ 5, unconfirmed by the city — recorded as a claim, not a breach).</li><li><strong>Items dropped from this week&#39;s roll-up:</strong> B1ack&#39;s Stash 4.6M-card free-release (carding-dump, no defender-actionable TTP); ICO £355,880 POCA confiscation against a former Markerstudy insider (UK insider-threat enforcement, low CH/EU public-sector signal); several daily research items folded by reference rather than re-summarised (Fast16 nuclear-simulation tooling, the demo.pdb BadIIS MaaS ecosystem, PinTheft and DirtyDecrypt Linux LPE PoCs, the Atos BYOVD-driver research, Google Cloud API-key deletion-latency, the Kali365 OAuth device-code PhaaS). These cleared the daily bar but not W-PD-1&#39;s weekly bar; they may resurface if they develop.</li><li><strong>Reduced confidence / single-primary:</strong> the Check Point AI finding (single vendor, large claim) is treated as directional pending independent corroboration; the § 1 SonicWall CVE-2024-12802 item now rests on a single primary (Cybersecurity Dive) after a mis-attached corroborating URL was removed in verification.</li><li><strong>Missed angle (logged):</strong> no Swiss-national developer advisory (GovCERT.ch / NCSC.ch) on the Shai-Hulud / Megalodon supply-chain worm was found this run; W2&#39;s NCSC.ch sweep surfaced none. If GovCERT.ch issues CH-specific guidance it should be picked up next run.</li><li><strong>Contradictions / open items:</strong> SECO confirmation is pending on whether Switzerland&#39;s 22 May sanctions adoption includes the managed-security-services prohibition specifically (§ 8); no European Commission scope guidance yet.</li><li><strong>Sub-agents:</strong> both horizon sub-agents (W1 long-horizon, W2 policy) returned within budget. W1 reported coverage gaps on <code>cyble-eu-threat-landscape</code> (503) and <code>harfanglab</code> (403); W2 reported gaps on <code>inside-it-ch</code>, <code>bsi-de</code>, <code>anssi-fr</code> (the specific CERT-FR SPIP advisory was nonetheless cited via the daily). One new candidate source surfaced (Cloud Security Alliance Lab Space) and was added as a candidate.</li><li><strong>Coverage note:</strong> the previous <code>briefs/weekly/2026-W21.md</code> was a misfired early run (committed 2026-05-18, ~1 hour after the 2026-W20 weekly) that re-summarised W20-era content under the W21 label; this run overwrites it cleanly with the proper end-of-week W21 summary covering 18–24 May.</li><li>Verification: 2 iterations (iter-1 Opus → NEEDS_FIXES truth=6/editorial=1; iter-2 Sonnet → NEEDS_FIXES truth=1/editorial=0). Early-exit on low-defect convergence (truth+editorial ≤ 2, no broken-URL / hallucinated-fact finding); residual=1. The residual was the § 5 Grafana mechanism specifics (<code>pull_request_target</code>, canary token), which the iter-2 fix above resolved by limiting the claim to what the cited sources confirm.</li><li>Coverage gaps: databreaches-net (403 — transport, bridge-routed); sophos-xops (503); inside-it-ch (403); trendmicro-research (500); cert-eu (intermittent 200/timeout); cyble-eu-threat-landscape (503); harfanglab (403); bsi-de (W2 fetch gap); anssi-fr (W2 index gap — specific advisory cited via daily).</li></ul>
<p><em>Migrated from briefs/weekly/2026-W21.md (v2).</em></p></div></div></div></details>]]></content:encoded></item><item><title>CTI Weekly Summary · 2026-W20</title><link>https://ctipilot.ch/weekly/2026-W20/</link><guid isPermaLink="true">https://ctipilot.ch/weekly/2026-W20/</guid><pubDate>Mon, 11 May 2026 05:00:51 +0000</pubDate><dc:date>2026-05-11T05:00:51Z</dc:date><category>CVE-2026-0300</category><category>CVE-2026-20182</category><category>CVE-2026-26083</category><category>CVE-2026-34260</category><category>CVE-2026-34263</category><category>CVE-2026-42897</category><category>CVE-2026-43284</category><category>CVE-2026-43500</category><description><![CDATA[<ul><li><strong>EU Digital Omnibus political agreement — AI Act high-risk Annex III compliance deadline extended to 2 December 2027.</strong> EU Digital Omnibus political agreement (2026-05-07) postpones AI Act high-risk Annex III compliance deadline from 2 August 2026 to 2 December 2027; product-embedded Annex I systems to 2 August 2028. Cybersecurity obligations under Articles 8–15 still apply at the new deadline; CRA enforcement milestones 11 June 2026 (CAB notification) and 11 September 2026 (Article 14 vulnerability reporting) are unaffected and now the next binding-deadline window for Swiss product manufacturers selling into the EU. (TechPolicy.Press · EC CRA implementation) <a href="https://ctipilot.ch/entries/2026-05-11/eu-digital-omnibus-political-agreement-ai-act-high-risk-anne/">→</a></li><li><strong>Healthcare.</strong> Dutch IGJ (Inspectie Gezondheidszorg en Jeugd) rules Clinical Diagnostics / NMDL failed NEN 7510 information-security standard at the time of the July 2025 ransomware breach; the breach affected approximately 941,000 patients (figure from the daily 2026-05-14, sourced to Computable) including cervical-cancer screening data. First IGJ formal NEN 7510 non-conformity finding on a third-party diagnostics provider; sets a regulatory precedent for healthcare-supplier due-diligence under NIS2 essential-entity obligations. (IGJ inspection report · Computable · daily 2026-05-14) <a href="https://ctipilot.ch/entries/2026-05-11/healthcare/">→</a></li><li><strong>TeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leak.</strong> TeamPCP Mini Shai-Hulud wave 4 compromised 170+ npm packages / 400+ malicious versions per daily-brief tracking (TanStack, UiPath, Mistral AI, OpenSearch, OpenAI named); Datadog static analysis of the leaked Shai-Hulud framework source (2026-05-12 leak) surfaces previously-undocumented IDE-persistence hooks targeting .claude/settings.json and .vscode/tasks.json, plus OIDC token extraction from /proc/&lt;pid&gt;/mem to forge Sigstore provenance attestations. Provenance-only verification no longer separates malicious from legitimate publications. (Datadog Security Labs · Wiz Blog · daily 2026-05-13 UPDATE · daily 2026-05-15 UPDATE) <a href="https://ctipilot.ch/entries/2026-05-11/teampcp-mini-shai-hulud-npm-supply-chain-worm-wave-4-framewo/">→</a></li><li><strong>Dirty Frag (CVE-2026-43284 xfrm-ESP + CVE-2026-43500 RxRPC) — Microsoft confirmed ITW, RxRPC distro patches still propagating.</strong> Dirty Frag (CVE-2026-43284 xfrm-ESP + CVE-2026-43500 RxRPC) — Microsoft confirms limited-ITW exploitation 2026-05-11; major distros (AlmaLinux 8/9/10, Ubuntu, Debian, Fedora, openSUSE) now ship patches for CVE-2026-43284, but RxRPC patch propagation on systems with kernel-modules-partner installed remains uneven. (Microsoft Security Blog · AlmaLinux blog · daily 2026-05-11 UPDATE) <a href="https://ctipilot.ch/entries/2026-05-11/dirty-frag-cve-2026-43284-xfrm-esp-cve-2026-43500-rxrpc-micr/">→</a></li><li><strong>Windows BitLocker &quot;YellowKey&quot; + CTFMON &quot;GreenPlasma&quot; — public PoC, no patch, TPM-only BitLocker bypassed.</strong> Windows BitLocker &quot;YellowKey&quot; and CTFMON &quot;GreenPlasma&quot; zero-days — public PoC, no patch, TPM-only BitLocker configurations bypassed. Microsoft May Patch Tuesday (120+ CVEs) did not address either; the BitLocker primitive defeats the most common laptop full-disk-encryption configuration in Swiss federal and cantonal estates. (daily 2026-05-15) <a href="https://ctipilot.ch/entries/2026-05-11/windows-bitlocker-yellowkey-ctfmon-greenplasma-public-poc-no/">→</a></li><li><strong>PAN-OS CVE-2026-0300 — wave 2 confirmed delayed to 2026-05-28; eight build streams remain on mitigation-only for a further 11 days.</strong> PAN-OS CVE-2026-0300 patch wave 2 confirmed delayed to 2026-05-28 (PSIRT advisory updated 2026-05-16). Eight PAN-OS build streams (12.1.7, 11.2.4-h17, 11.2.12, 11.1.7-h6, 11.1.15, 10.2.7-h34, 10.2.13-h21, 10.2.16-h7) remain on mitigation-only for a further eleven days while limited-ITW exploitation continues against User-ID Authentication Portal exposed firewalls. (Palo Alto PSIRT CVE-2026-0300 · daily 2026-05-14 UPDATE) <a href="https://ctipilot.ch/entries/2026-05-11/pan-os-cve-2026-0300-wave-2-confirmed-delayed-to-2026-05-28/">→</a></li><li><strong>Cisco Catalyst SD-WAN CVE-2026-20182 — UAT-8616 active, CISA Emergency Directive ED-26-03, 10+ companion-CVE clusters.</strong> Cisco Catalyst SD-WAN Controller / Manager CVE-2026-20182 pre-auth authentication bypass — UAT-8616 cluster active, CISA Emergency Directive ED-26-03 issued 2026-05-15, 10+ additional intrusion clusters exploiting companion February-2026 SD-WAN CVEs. Federal-civilian KEV deadline today (2026-05-17). Full fabric-takeover capability against any Catalyst SD-WAN deployment with the management plane reachable. (Cisco PSIRT · CISA ED-26-03 · daily 2026-05-15) <a href="https://ctipilot.ch/entries/2026-05-11/cisco-catalyst-sd-wan-cve-2026-20182-uat-8616-active-cisa-em/">→</a></li><li><strong>Microsoft Exchange CVE-2026-42897 — actively-exploited OWA stored-XSS, no permanent patch, Pwn2Own three-bug chain compounds the picture.</strong> Microsoft Exchange CVE-2026-42897 OWA stored-XSS — actively exploited, KEV-added 2026-05-15 (deadline 2026-05-29), no permanent patch from Microsoft; a separate DEVCORE / Orange Tsai three-bug pre-auth SYSTEM RCE chain (Pwn2Own Berlin Day Two, 2026-05-15) earned $200,000 and has not been linked to current ITW exploitation but materially compounds the on-premises Exchange threat picture. EEMS / EOMT mitigations are the only available control. (Microsoft MSRC · NCSC.ch Security Hub #12577 · ZDI Pwn2Own Day Two · daily 2026-05-16 · daily 2026-05-17 UPDATE) <a href="https://ctipilot.ch/entries/2026-05-11/microsoft-exchange-cve-2026-42897-actively-exploited-owa-sto/">→</a></li></ul>]]></description><content:encoded><![CDATA[<div class="tldr"><span class="eyebrow eyebrow--muted">Week at a glance</span><ol><li><span class="num">01</span><span><b>EU Digital Omnibus political agreement — AI Act high-risk Annex III compliance deadline extended to 2 December 2027.</b> EU Digital Omnibus political agreement (2026-05-07) postpones AI Act high-risk Annex III compliance deadline from 2 August 2026 to 2 December 2027; product-embedded Annex I systems to 2 August 2028. Cybersecurity obligations under Articles 8–15 still apply at the new deadline; CRA enforcement milestones 11 June 2026 (CAB notification) and 11 September 2026 (Article 14 vulnerability reporting) are unaffected and now the next binding-deadline window for Swiss product manufacturers selling into the EU. (TechPolicy.Press · EC CRA implementation) <a href="https://ctipilot.ch/entries/2026-05-11/eu-digital-omnibus-political-agreement-ai-act-high-risk-anne/">→</a></span></li><li><span class="num">02</span><span><b>Healthcare.</b> Dutch IGJ (Inspectie Gezondheidszorg en Jeugd) rules Clinical Diagnostics / NMDL failed NEN 7510 information-security standard at the time of the July 2025 ransomware breach; the breach affected approximately 941,000 patients (figure from the daily 2026-05-14, sourced to Computable) including cervical-cancer screening data. First IGJ formal NEN 7510 non-conformity finding on a third-party diagnostics provider; sets a regulatory precedent for healthcare-supplier due-diligence under NIS2 essential-entity obligations. (IGJ inspection report · Computable · daily 2026-05-14) <a href="https://ctipilot.ch/entries/2026-05-11/healthcare/">→</a></span></li><li><span class="num">03</span><span><b>TeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leak.</b> TeamPCP Mini Shai-Hulud wave 4 compromised 170+ npm packages / 400+ malicious versions per daily-brief tracking (TanStack, UiPath, Mistral AI, OpenSearch, OpenAI named); Datadog static analysis of the leaked Shai-Hulud framework source (2026-05-12 leak) surfaces previously-undocumented IDE-persistence hooks targeting .claude/settings.json and .vscode/tasks.json, plus OIDC token extraction from /proc/&lt;pid&gt;/mem to forge Sigstore provenance attestations. Provenance-only verification no longer separates malicious from legitimate publications. (Datadog Security Labs · Wiz Blog · daily 2026-05-13 UPDATE · daily 2026-05-15 UPDATE) <a href="https://ctipilot.ch/entries/2026-05-11/teampcp-mini-shai-hulud-npm-supply-chain-worm-wave-4-framewo/">→</a></span></li><li><span class="num">04</span><span><b>Dirty Frag (CVE-2026-43284 xfrm-ESP + CVE-2026-43500 RxRPC) — Microsoft confirmed ITW, RxRPC distro patches still propagating.</b> Dirty Frag (CVE-2026-43284 xfrm-ESP + CVE-2026-43500 RxRPC) — Microsoft confirms limited-ITW exploitation 2026-05-11; major distros (AlmaLinux 8/9/10, Ubuntu, Debian, Fedora, openSUSE) now ship patches for CVE-2026-43284, but RxRPC patch propagation on systems with kernel-modules-partner installed remains uneven. (Microsoft Security Blog · AlmaLinux blog · daily 2026-05-11 UPDATE) <a href="https://ctipilot.ch/entries/2026-05-11/dirty-frag-cve-2026-43284-xfrm-esp-cve-2026-43500-rxrpc-micr/">→</a></span></li><li><span class="num">05</span><span><b>Windows BitLocker &quot;YellowKey&quot; + CTFMON &quot;GreenPlasma&quot; — public PoC, no patch, TPM-only BitLocker bypassed.</b> Windows BitLocker &quot;YellowKey&quot; and CTFMON &quot;GreenPlasma&quot; zero-days — public PoC, no patch, TPM-only BitLocker configurations bypassed. Microsoft May Patch Tuesday (120+ CVEs) did not address either; the BitLocker primitive defeats the most common laptop full-disk-encryption configuration in Swiss federal and cantonal estates. (daily 2026-05-15) <a href="https://ctipilot.ch/entries/2026-05-11/windows-bitlocker-yellowkey-ctfmon-greenplasma-public-poc-no/">→</a></span></li><li><span class="num">06</span><span><b>PAN-OS CVE-2026-0300 — wave 2 confirmed delayed to 2026-05-28; eight build streams remain on mitigation-only for a further 11 days.</b> PAN-OS CVE-2026-0300 patch wave 2 confirmed delayed to 2026-05-28 (PSIRT advisory updated 2026-05-16). Eight PAN-OS build streams (12.1.7, 11.2.4-h17, 11.2.12, 11.1.7-h6, 11.1.15, 10.2.7-h34, 10.2.13-h21, 10.2.16-h7) remain on mitigation-only for a further eleven days while limited-ITW exploitation continues against User-ID Authentication Portal exposed firewalls. (Palo Alto PSIRT CVE-2026-0300 · daily 2026-05-14 UPDATE) <a href="https://ctipilot.ch/entries/2026-05-11/pan-os-cve-2026-0300-wave-2-confirmed-delayed-to-2026-05-28/">→</a></span></li><li><span class="num">07</span><span><b>Cisco Catalyst SD-WAN CVE-2026-20182 — UAT-8616 active, CISA Emergency Directive ED-26-03, 10+ companion-CVE clusters.</b> Cisco Catalyst SD-WAN Controller / Manager CVE-2026-20182 pre-auth authentication bypass — UAT-8616 cluster active, CISA Emergency Directive ED-26-03 issued 2026-05-15, 10+ additional intrusion clusters exploiting companion February-2026 SD-WAN CVEs. Federal-civilian KEV deadline today (2026-05-17). Full fabric-takeover capability against any Catalyst SD-WAN deployment with the management plane reachable. (Cisco PSIRT · CISA ED-26-03 · daily 2026-05-15) <a href="https://ctipilot.ch/entries/2026-05-11/cisco-catalyst-sd-wan-cve-2026-20182-uat-8616-active-cisa-em/">→</a></span></li><li><span class="num">08</span><span><b>Microsoft Exchange CVE-2026-42897 — actively-exploited OWA stored-XSS, no permanent patch, Pwn2Own three-bug chain compounds the picture.</b> Microsoft Exchange CVE-2026-42897 OWA stored-XSS — actively exploited, KEV-added 2026-05-15 (deadline 2026-05-29), no permanent patch from Microsoft; a separate DEVCORE / Orange Tsai three-bug pre-auth SYSTEM RCE chain (Pwn2Own Berlin Day Two, 2026-05-15) earned $200,000 and has not been linked to current ITW exploitation but materially compounds the on-premises Exchange threat picture. EEMS / EOMT mitigations are the only available control. (Microsoft MSRC · NCSC.ch Security Hub #12577 · ZDI Pwn2Own Day Two · daily 2026-05-16 · daily 2026-05-17 UPDATE) <a href="https://ctipilot.ch/entries/2026-05-11/microsoft-exchange-cve-2026-42897-actively-exploited-owa-sto/">→</a></span></li></ol></div><nav class="secnav" aria-label="Sections"><a class="secnav-chip" href="#highest-impact-events-what-s-on-fire-if-no-one-acted">Highest-impact events · what&#39;s on fire if no one acted <span class="secnav-n">5</span></a><a class="secnav-chip" href="#multi-day-campaigns-and-chains">Multi-day campaigns and chains <span class="secnav-n">4</span></a><a class="secnav-chip" href="#vulnerability-roll-up">Vulnerability roll-up <span class="secnav-n">6</span></a><a class="secnav-chip" href="#sector-victim-patterns">Sector &amp; victim patterns <span class="secnav-n">6</span></a><a class="secnav-chip" href="#incidents-disclosures-recap">Incidents &amp; disclosures recap <span class="secnav-n">8</span></a><a class="secnav-chip" href="#annual-periodic-threat-reports">Annual / periodic threat reports <span class="secnav-n">6</span></a><a class="secnav-chip" href="#long-running-campaigns-status-update">Long-running campaigns · status update <span class="secnav-n">6</span></a><a class="secnav-chip" href="#policy-regulatory-horizon">Policy &amp; regulatory horizon <span class="secnav-n">9</span></a><a class="secnav-chip" href="#looking-ahead-what-to-watch-next-week">Looking ahead · what to watch next week <span class="secnav-n">1</span></a></nav><div class="sect" id="highest-impact-events-what-s-on-fire-if-no-one-acted"><span class="n">01</span><span class="t">Highest-impact events · what&#39;s on fire if no one acted</span><span class="c">5 items</span></div><article class="finding entry-card" data-entry-id="2026-05-11/dirty-frag-cve-2026-43284-xfrm-esp-cve-2026-43500-rxrpc-micr" data-tags="vulnerabilities actively-exploited lpe patch-available" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-11T05:00:04Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-43284/">CVE-2026-43284 +1</a><span class="b exp">exploited</span></div><h3 class="f-h" id="dirty-frag-cve-2026-43284-xfrm-esp-cve-2026-43500-rxrpc-micr"><a href="https://ctipilot.ch/entries/2026-05-11/dirty-frag-cve-2026-43284-xfrm-esp-cve-2026-43500-rxrpc-micr/">Dirty Frag (CVE-2026-43284 xfrm-ESP + CVE-2026-43500 RxRPC) — Microsoft confirmed ITW, RxRPC distro patches still propagating</a></h3><p><strong>If you did nothing this week:</strong> any Linux host (workload, container host, on-premises server, public-cloud VM) where the kernel ships <code>xfrm-ESP</code> enabled (default on virtually every distribution) is exposed to a single-command unprivileged-to-root privilege escalation with public PoC; Microsoft confirmed limited in-the-wild exploitation on 2026-05-08 and tracked further activity into 2026-05-11 (<a href="https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/" target="_blank" rel="noopener noreferrer">Microsoft Security Blog, 2026-05-08</a>; <a href="https://ctipilot.ch/briefs/2026-05-11/" target="_blank" rel="noopener noreferrer">daily 2026-05-11 UPDATE</a>; <a href="https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc" target="_blank" rel="noopener noreferrer">Wiz Research</a>). Patch propagation is substantially complete: AlmaLinux 8/9/10, Ubuntu, Debian, Fedora, openSUSE all ship CVE-2026-43284 kernels as of 2026-05-07–10, with KernelCare live-patches generally available (<a href="https://almalinux.org/blog/2026-05-07-dirty-frag/" target="_blank" rel="noopener noreferrer">AlmaLinux blog</a>).</p>
<p>CVE-2026-43500 (RxRPC) patch propagation is uneven. AlmaLinux 8 is not affected (rxrpc module not built); RHEL 9 errata are rolling; Ubuntu and Debian shipped patches; the lagging configurations are systems that have the optional <code>kernel-modules-partner</code> package installed (typical on AFS-using estates and some research-network deployments). The interim mitigation — <code>modprobe -r esp4 esp6 rxrpc</code> — breaks IPsec VPNs and AFS file-system access, so production rollout requires impact testing rather than blanket application. Detection focus: Sysmon EID 1 / <code>auditd</code> execve events showing unusual parent-process chains from non-root users spawning root-effective shells.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: any Linux host (workload, container host, on-premises server, public-cloud VM) where the kernel ships xfrm-ESP enabled (default on virtually every distribution) is exposed to a single-command unprivileged-to-root privilege escalation with public PoC; Microsoft …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/dirty-frag-cve-2026-43284-xfrm-esp-cve-2026-43500-rxrpc-micr/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/" target="_blank" rel="noopener noreferrer">Microsoft Security Blog</a> · <a href="https://almalinux.org/blog/2026-05-07-dirty-frag/" target="_blank" rel="noopener noreferrer">AlmaLinux blog</a> · <a href="https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc" target="_blank" rel="noopener noreferrer">Wiz Research</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/windows-bitlocker-yellowkey-ctfmon-greenplasma-public-poc-no" data-tags="vulnerabilities zero-day lpe no-patch poc-public" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-11T05:00:03Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="windows-bitlocker-yellowkey-ctfmon-greenplasma-public-poc-no"><a href="https://ctipilot.ch/entries/2026-05-11/windows-bitlocker-yellowkey-ctfmon-greenplasma-public-poc-no/">Windows BitLocker &quot;YellowKey&quot; + CTFMON &quot;GreenPlasma&quot; — public PoC, no patch, TPM-only BitLocker bypassed</a></h3><p><strong>If you did nothing this week:</strong> every Windows endpoint configured with TPM-only BitLocker (no PIN, no startup key — the most common laptop configuration in Swiss federal and cantonal estates) is bypassable by an attacker with brief physical access using the publicly-disclosed YellowKey PoC; every Windows endpoint with the CTFMON service (the default on Windows 10/11/Server 2022/2025) is locally elevation-of-privilege-vulnerable via the GreenPlasma primitive. Both zero-days were disclosed without coordinated vendor patching; Microsoft&#39;s May 2026 Patch Tuesday (120+ CVEs) did <strong>not</strong> address either, and no out-of-band advisory has been issued (<a href="https://ctipilot.ch/briefs/2026-05-15/" target="_blank" rel="noopener noreferrer">daily 2026-05-15</a>).</p>
<p>The operational reality for Swiss public-sector defenders is that the laptop full-disk-encryption story is materially weakened until Microsoft ships a fix. The interim guidance is to enforce BitLocker PIN-or-startup-key on every endpoint where physical-access risk is non-trivial (mobile estates, off-site work, hotel travel) — the GPO toggle is <code>Computer Configuration → Administrative Templates → Windows Components → BitLocker Drive Encryption → Operating System Drives → Require additional authentication at startup</code>. For GreenPlasma the only available control is privileged-account-segregation discipline: workstations that handle administrative credentials should not also run unprivileged user workloads where the local-EOP can be staged.</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/windows-bitlocker-yellowkey-ctfmon-greenplasma-public-poc-no/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/" target="_blank" rel="noopener noreferrer">BleepingComputer — Windows BitLocker zero-day PoC</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12574" target="_blank" rel="noopener noreferrer">NCSC.ch Security Hub #12574</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/pan-os-cve-2026-0300-wave-2-confirmed-delayed-to-2026-05-28" data-tags="vulnerabilities actively-exploited pre-auth rce patch-available" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-11T05:00:02Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-0300/">CVE-2026-0300</a><span class="b exp">exploited</span></div><h3 class="f-h" id="pan-os-cve-2026-0300-wave-2-confirmed-delayed-to-2026-05-28"><a href="https://ctipilot.ch/entries/2026-05-11/pan-os-cve-2026-0300-wave-2-confirmed-delayed-to-2026-05-28/">PAN-OS CVE-2026-0300 — wave 2 confirmed delayed to 2026-05-28; eight build streams remain on mitigation-only for a further 11 days</a></h3><p><strong>If you did nothing this week:</strong> any PA-Series or VM-Series firewall running PAN-OS 12.1.7, 11.2.4-h17, 11.2.12, 11.1.7-h6, 11.1.15, 10.2.7-h34, 10.2.13-h21, or 10.2.16-h7 with User-ID Authentication Portal / Captive Portal exposed to untrusted IPs has been within CL-STA-1132&#39;s exploitation window since 2026-04-09 (W19 baseline) and <strong>will remain so until 2026-05-28</strong> — eleven calendar days past today. The Palo Alto PSIRT advisory was updated 2026-05-16 confirming the staggered two-wave schedule (wave 1 landed 2026-05-13 for 11.2.7-h13 / 11.2.10-h6 / 11.1.4-h33 / 11.1.6-h32 / 11.1.10-h25 / 11.1.13-h5 / 10.2.10-h36 / 10.2.18-h6; wave 2 covers the remaining branches on 2026-05-28). Limited ITW exploitation continues (<a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto PSIRT CVE-2026-0300</a>; <a href="https://ctipilot.ch/briefs/2026-05-14/" target="_blank" rel="noopener noreferrer">daily 2026-05-14 UPDATE</a>; <a href="https://ctipilot.ch/briefs/2026-05-13/" target="_blank" rel="noopener noreferrer">daily 2026-05-13 UPDATE</a>).</p>
<p>The interim mitigation remains the only available control for wave-2 build-streams: restrict User-ID Authentication Portal to trusted zones, disable Response Pages on external-facing L3 interface management profiles, and (for Threat Prevention subscribers on PAN-OS ≥ 11.1 with content version ≥ 9097-10022) enable Threat ID 510019. The retrospective-hunt artefact set documented in W19 — <code>svc-health-check-NNNNNN</code> rogue-admin accounts, Python implants under <code>/var/tmp/linuxupdate</code>, <code>/var/tmp/linuxap</code>, and <code>/tmp/.c</code> — remains the right starting point for organisations exposed during the four-and-a-half-week pre-patch window between 2026-04-09 and their eventual upgrade date.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: any PA-Series or VM-Series firewall running PAN-OS 12.1.7, 11.2.4-h17, 11.2.12, 11.1.7-h6, 11.1.15, 10.2.7-h34, 10.2.13-h21, or 10.2.16-h7 with User-ID Authentication Portal / Captive Portal exposed to untrusted IPs has been within CL-STA-1132&#39;s exploitation window …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/pan-os-cve-2026-0300-wave-2-confirmed-delayed-to-2026-05-28/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto Networks PSIRT</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/cisco-catalyst-sd-wan-cve-2026-20182-uat-8616-active-cisa-em" data-tags="vulnerabilities actively-exploited pre-auth auth-bypass cisa-kev patch-available" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-11T05:00:01Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-20182/">CVE-2026-20182</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cisco-catalyst-sd-wan-cve-2026-20182-uat-8616-active-cisa-em"><a href="https://ctipilot.ch/entries/2026-05-11/cisco-catalyst-sd-wan-cve-2026-20182-uat-8616-active-cisa-em/">Cisco Catalyst SD-WAN CVE-2026-20182 — UAT-8616 active, CISA Emergency Directive ED-26-03, 10+ companion-CVE clusters</a></h3><p><strong>If you did nothing this week:</strong> any Catalyst SD-WAN Manager or Controller with an internet-reachable management plane has been within UAT-8616&#39;s active exploitation window per Cisco Talos&#39;s 2026-05-14 timeline — with full fabric-takeover capability via a pre-authentication HTTP-header parsing bypass in the NETCONF gateway. The published kill chain is HTTP-header injection → authentication bypass → vManage administrative API → orchestrator-level configuration push → arbitrary device-config rewrite across every fabric member. Patches are available (vManage 20.13.4 / 20.12.6 / 20.9.7 / earlier branches per Cisco PSIRT); CISA issued <strong>Emergency Directive ED-26-03</strong> on 2026-05-15 mandating identification, mitigation, and reporting for US federal civilian agencies with a 2026-05-17 (today) deadline (<a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a>; <a href="https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems" target="_blank" rel="noopener noreferrer">CISA ED-26-03</a>; <a href="https://ctipilot.ch/briefs/2026-05-15/" target="_blank" rel="noopener noreferrer">daily 2026-05-15</a>).</p>
<p>What makes the SD-WAN picture operationally critical for Swiss / EU defenders even after the patches land is the <strong>approximately 10 additional intrusion clusters</strong> Talos and CISA jointly identified exploiting February-2026 Catalyst SD-WAN companion CVEs (CVE-2026-20133, CVE-2026-20128, CVE-2026-20122 — patched in Q1 2026 but with public-PoC availability that drove a wave of secondary exploitation against organisations that lagged the original patch). The 10-cluster figure indicates the SD-WAN attack surface is being mined systematically by multiple unrelated operators, not just UAT-8616, so the hunt is not bounded to a single named cluster&#39;s TTPs: review <code>vmanage_event</code> and NETCONF-gateway logs for any 401/403→200 transitions on <code>/dataservice/*</code> endpoints from external source IPs across the entire Q1-2026 → present window, and assume any unpatched device has been visited.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: any Catalyst SD-WAN Manager or Controller with an internet-reachable management plane has been within UAT-8616&#39;s active exploitation window per Cisco Talos&#39;s 2026-05-14 timeline — with full fabric-takeover capability via a pre-authentication HTTP-header parsing bypass …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/cisco-catalyst-sd-wan-cve-2026-20182-uat-8616-active-cisa-em/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW" target="_blank" rel="noopener noreferrer">Cisco PSIRT</a> · <a href="https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems" target="_blank" rel="noopener noreferrer">CISA ED-26-03</a> · <a href="https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/" target="_blank" rel="noopener noreferrer">Cisco Talos UAT-8616</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/microsoft-exchange-cve-2026-42897-actively-exploited-owa-sto" data-tags="vulnerabilities actively-exploited zero-day cisa-kev no-patch identity" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-11T05:00:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-42897/">CVE-2026-42897</a><span class="b exp">exploited</span></div><h3 class="f-h" id="microsoft-exchange-cve-2026-42897-actively-exploited-owa-sto"><a href="https://ctipilot.ch/entries/2026-05-11/microsoft-exchange-cve-2026-42897-actively-exploited-owa-sto/">Microsoft Exchange CVE-2026-42897 — actively-exploited OWA stored-XSS, no permanent patch, Pwn2Own three-bug chain compounds the picture</a></h3><p><strong>If you did nothing this week:</strong> every on-premises Exchange Server 2016 / 2019 / SE deployment with Outlook Web Access reachable from the public internet has been within an active exploitation window since the CISA KEV addition on 2026-05-15. The exploit chain is a stored XSS in OWA&#39;s calendar-invite rendering pipeline that executes attacker JavaScript in the victim&#39;s session context the moment a crafted invite is opened in a browser; subsequent stages perform internal-mailbox enumeration, mass email-rule creation, and OWA-token theft for lateral SAML / OAuth abuse against connected M365 tenants. Microsoft has shipped only the EEMS (Exchange Emergency Mitigation Service) rule and the EOMT script as <strong>temporary</strong> mitigations — there is no permanent code patch as of week-end (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a>; <a href="https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498" target="_blank" rel="noopener noreferrer">Microsoft Exchange Team blog</a>; <a href="https://security-hub.ncsc.admin.ch/#/posts/12577" target="_blank" rel="noopener noreferrer">NCSC.ch Security Hub #12577</a>).</p>
<p>The threat picture compounded on 2026-05-15 when a DEVCORE / Orange Tsai entry at Pwn2Own Berlin Day Two earned $200,000 by chaining three bugs to achieve pre-auth RCE as SYSTEM on Exchange Server SE per the Zero Day Initiative published results (<a href="https://www.thezdi.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results" target="_blank" rel="noopener noreferrer">ZDI Day Two</a>; ZDI does not publish per-bug technical detail before vendor patches under the standard 90-day disclosure clock). The DEVCORE chain has not been linked to current ITW exploitation, but Microsoft has not yet issued an out-of-band advisory; defenders should assume that a chained variant combining OWA-XSS initial access with the DEVCORE elevation primitives will become the operationally dominant Exchange threat well before any patch lands (<a href="https://ctipilot.ch/briefs/2026-05-16/" target="_blank" rel="noopener noreferrer">daily 2026-05-16</a>; <a href="https://ctipilot.ch/briefs/2026-05-17/" target="_blank" rel="noopener noreferrer">daily 2026-05-17 UPDATE</a>). For Swiss federal estates running on-premises Exchange (the predominant configuration in cantonal administration and federal-classified-handling environments) the immediate hunt is OWA <code>w3wp.exe</code> worker children spawning anomalous PowerShell / WMI in the days following inbound calendar-invite traffic; the second hunt is the EOMT-script idempotency check (organisations who ran it before the 2026-05-15 rule version will have stale mitigation state).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: every on-premises Exchange Server 2016 / 2019 / SE deployment with Outlook Web Access reachable from the public internet has been within an active exploitation window since the CISA KEV addition on 2026-05-15.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/microsoft-exchange-cve-2026-42897-actively-exploited-owa-sto/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897" target="_blank" rel="noopener noreferrer">Microsoft Security Blog</a> · <a href="https://security-hub.ncsc.admin.ch/api/posts/12577/details" target="_blank" rel="noopener noreferrer">NCSC.ch Security Hub #12577</a> · <a href="https://www.thezdi.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results" target="_blank" rel="noopener noreferrer">Zero Day Initiative</a></div></article><div class="sect" id="multi-day-campaigns-and-chains"><span class="n">02</span><span class="t">Multi-day campaigns and chains</span><span class="c">4 items</span></div><article class="finding entry-card" data-entry-id="2026-05-11/canvas-instructure-extortion-ransom-paid-us-house-investigat" data-tags="ransomware data-breach organized-crime" data-regions="us europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:06Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="canvas-instructure-extortion-ransom-paid-us-house-investigat"><a href="https://ctipilot.ch/entries/2026-05-11/canvas-instructure-extortion-ransom-paid-us-house-investigat/">Canvas / Instructure extortion — ransom paid, US House investigation, second-intrusion vulnerability re-exploited</a></h3><p>The W19 weekly closed with the Canvas / Instructure extortion deadline of 2026-05-12 pending. The trajectory through W20: <strong>Tuesday 2026-05-12:</strong> Instructure confirmed ransom payment to ShinyHunters with claimed data return and digital confirmation of destruction; second intrusion separately confirmed; per-institution leak deadline reset to the same day (<a href="https://ctipilot.ch/briefs/2026-05-12/" target="_blank" rel="noopener noreferrer">daily 2026-05-12 UPDATE</a>; <a href="https://therecord.media/instructure-pays-ransom-canvas-incident-congress-investigation" target="_blank" rel="noopener noreferrer">The Record, 2026-05-12</a>). <strong>Wednesday 2026-05-13:</strong> the US House Homeland Security Committee (Chairman Garbarino) opened a formal investigation and requested an Instructure CEO briefing by 2026-05-21 covering both intrusion circumstances, scope and nature of accessed data, IR adequacy, and CISA coordination (<a href="https://homeland.house.gov/2026/05/11/chairman-garbarino-seeks-information-from-canvas-developer-after-cyberattacks-impact-schools-and-universities-nationwide/" target="_blank" rel="noopener noreferrer">House Homeland Security Committee letter, 2026-05-11</a>; <a href="https://ctipilot.ch/briefs/2026-05-13/" target="_blank" rel="noopener noreferrer">daily 2026-05-13 UPDATE</a>). <strong>Post-payment:</strong> ShinyHunters defaced approximately 330 institutional Canvas login pages by re-exploiting the same Free-For-Teacher account vulnerability that enabled the second intrusion — demonstrating that the &quot;no customer extortion&quot; covenant in the ransom agreement was at best narrowly observed and that the access vector was not actually closed (<a href="https://therecord.media/instructure-pays-ransom-canvas-incident-congress-investigation" target="_blank" rel="noopener noreferrer">The Record</a>).</p>
<p>The story matters to Swiss / EU public-sector defenders for three reasons that crystallise only across the multi-day arc. First, <strong>paying the ransom did not close the access vector</strong>: Instructure&#39;s patches did not eliminate the Free-For-Teacher abuse path, so the defacement wave is operational evidence that the underlying flaw remained exploitable; this is the &quot;what did the patch actually fix&quot; question every IR-receiving organisation should be asking of every paid-ransom-with-promised-fix vendor. Second, <strong>the seven Dutch universities</strong> (VU Amsterdam, UvA, Erasmus, Tilburg, TU/e, Maastricht, Twente) <strong>disconnected Canvas</strong> rather than wait for vendor remediation (<a href="https://nltimes.nl/2026/05/09/dutch-universities-disconnect-canvas-hackers-claim-continued-access" target="_blank" rel="noopener noreferrer">NL Times, 2026-05-09</a>) — a defender posture worth pattern-matching for any future SaaS-LMS / SaaS-LRS / SaaS-grade-management vendor compromise. Third, the <strong>US House investigation</strong> is the regulatory analogue Swiss / EU SOC managers should anticipate from cantonal education ministries; the questions Chairman Garbarino&#39;s letter lists (intrusion timeline, data scope, IR adequacy, CISA / national-CSIRT coordination) are the same questions a cantonal Bildungsdirektion will ask after the next EdTech SaaS incident. Outcome of the 2026-05-21 briefing is the open horizon item for 2026-W21.</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/canvas-instructure-extortion-ransom-paid-us-house-investigat/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://therecord.media/instructure-pays-ransom-canvas-incident-congress-investigation" target="_blank" rel="noopener noreferrer">The Record</a> · <a href="https://homeland.house.gov/2026/05/11/chairman-garbarino-seeks-information-from-canvas-developer-after-cyberattacks-impact-schools-and-universities-nationwide/" target="_blank" rel="noopener noreferrer">US House Homeland Security Committee</a> · <a href="https://nltimes.nl/2026/05/09/dutch-universities-disconnect-canvas-hackers-claim-continued-access" target="_blank" rel="noopener noreferrer">NL Times — Dutch universities disconnect Canvas</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/teampcp-mini-shai-hulud-npm-supply-chain-worm-wave-4-framewo" data-tags="supply-chain ai-abuse actively-exploited" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-11T05:00:05Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="teampcp-mini-shai-hulud-npm-supply-chain-worm-wave-4-framewo"><a href="https://ctipilot.ch/entries/2026-05-11/teampcp-mini-shai-hulud-npm-supply-chain-worm-wave-4-framewo/">TeamPCP / Mini Shai-Hulud npm supply-chain worm — wave 4 + framework source leak</a></h3><p>The TeamPCP / Mini Shai-Hulud story spans every working day of 2026-W20 and the daily briefs add a piece each day. <strong>Tuesday 2026-05-12:</strong> an attacker briefly published what appears to be the complete Shai-Hulud framework source (TypeScript / Bun) to a public GitHub repository attributed to TeamPCP, taken down within hours but mirrored widely; the public source disclosure inverts the threat model — every IDE, EDR, and PR-review vendor now has access to the same artefact the operator was using but defenders must assume new variants will appear with one to two days&#39; lead-time on signatures (<a href="https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/" target="_blank" rel="noopener noreferrer">Datadog Security Labs static analysis, 2026-05-13</a>; <a href="https://ctipilot.ch/briefs/2026-05-15/" target="_blank" rel="noopener noreferrer">daily 2026-05-15 UPDATE</a>). <strong>Wednesday 2026-05-13:</strong> Wave 4 hits — 170+ packages / 400+ malicious versions compromised per daily-brief tracking across <code>@tanstack</code> (including <code>react-router</code>, ~12M weekly downloads), <code>@uipath</code>, <code>@mistralai</code>, <code>@opensearch-project</code>, and <code>@guardrails-ai</code>; the Wiz writeup confirms the same TeamPCP / UNC6780 / PCPJack attribution as prior waves (<a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised" target="_blank" rel="noopener noreferrer">Wiz Blog, 2026-05-11</a>; <a href="https://ctipilot.ch/briefs/2026-05-13/" target="_blank" rel="noopener noreferrer">daily 2026-05-13 UPDATE</a>). <strong>Friday 2026-05-15:</strong> OpenAI named as a victim; the company enforces code-signing certificate rotation across all macOS apps as remediation (<a href="https://ctipilot.ch/briefs/2026-05-15/" target="_blank" rel="noopener noreferrer">daily 2026-05-15 UPDATE</a>).</p>
<p>What W1 horizon research surfaced that the dailies could not yet see: Datadog&#39;s static analysis of the leaked source reveals two new capability classes that change the defender posture. First, <strong>IDE persistence</strong> via hook entries in <code>.claude/settings.json</code> (Claude Code) and <code>.vscode/tasks.json</code> — allowing arbitrary command execution on developer-workspace events; this is not a build-time supply-chain primitive but a developer-workstation persistence mechanism that survives <code>npm install</code> cleanup and outlives the malicious-package removal. Second, <strong>OIDC token extraction directly from <code>/proc/&lt;pid&gt;/mem</code> on GitHub Actions runners</strong>, used to forge Sigstore provenance attestations — meaning malicious packages can be published that are indistinguishable from legitimate ones by <strong>provenance verification alone</strong>. The W19 weekly already flagged ShinyHunters / WorldLeaks as a long-running operator-family pattern; the TeamPCP / Mini Shai-Hulud progression confirms a parallel ecosystem maturing on the npm registry side, now with publication-provenance forgery in the toolset. The leaked framework source materially elevates the risk of secondary operators applying Shai-Hulud-style techniques against other package registries (PyPI, Cargo, Maven Central) in 2026-W21 (<a href="https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/" target="_blank" rel="noopener noreferrer">Datadog Security Labs</a>).</p>
<p>The defender pivot is two-fold: (1) for DevOps pipelines, <strong>provenance verification is necessary but no longer sufficient</strong> — supplement with publisher-pinning, two-factor publish enforcement, and post-install hash-pinning; (2) for developer workstations, treat <code>.claude/settings.json</code> / <code>.vscode/tasks.json</code> / equivalent IDE hook files as security-relevant configuration and add them to file-integrity-monitoring scope. The Datadog filesystem indicators (<code>gh-token-monitor</code> daemon process, <code>claude@users.noreply.github.com</code> commits in unexpected repositories, exfil-repo names matching &quot;Shai-Hulud: Here We Go Again&quot;) are the right hunt seeds.</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/teampcp-mini-shai-hulud-npm-supply-chain-worm-wave-4-framewo/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/" target="_blank" rel="noopener noreferrer">Datadog Security Labs</a> · <a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised" target="_blank" rel="noopener noreferrer">Wiz Blog</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/pan-os-cve-2026-0300-staged-patch-arc-spanning-w19-and-w20" data-tags="vulnerabilities actively-exploited pre-auth rce patch-available" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:08Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span></div><h3 class="f-h" id="pan-os-cve-2026-0300-staged-patch-arc-spanning-w19-and-w20"><a href="https://ctipilot.ch/entries/2026-05-11/pan-os-cve-2026-0300-staged-patch-arc-spanning-w19-and-w20/">PAN-OS CVE-2026-0300 — staged-patch arc spanning W19 and W20</a></h3><p>The PAN-OS staged-patch arc began in W19 with limited-ITW exploitation against User-ID Authentication Portal exposed firewalls (CL-STA-1132 since 2026-04-09), continued into W20 with wave 1 landing on 2026-05-13 (<a href="https://ctipilot.ch/briefs/2026-05-13/" target="_blank" rel="noopener noreferrer">daily 2026-05-13 UPDATE</a>) for eight build streams, and now extends a further eleven days as the PSIRT advisory was updated 2026-05-16 confirming wave 2 delayed to 2026-05-28 for the remaining eight build streams (<a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto PSIRT CVE-2026-0300</a>; <a href="https://ctipilot.ch/briefs/2026-05-14/" target="_blank" rel="noopener noreferrer">daily 2026-05-14 UPDATE</a>).</p>
<p>The cross-day learning for Swiss / EU defenders is that PSIRT-stated patch dates on actively-exploited bugs are still subject to slip and the operational window is what matters, not the advisory&#39;s first-quoted date. The interim mitigation remains identical (User-ID Auth Portal scoped to trusted zones, Response Pages off external L3 interfaces, Threat ID 510019 for ≥ 11.1 + content ≥ 9097-10022); the retrospective hunt for <code>svc-health-check-NNNNNN</code> admin accounts and Python implants under <code>/var/tmp/linuxupdate</code> / <code>/var/tmp/linuxap</code> / <code>/tmp/.c</code> remains the only signal a CL-STA-1132-victimised organisation will have between the pre-patch compromise and the eventual upgrade.</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/pan-os-cve-2026-0300-staged-patch-arc-spanning-w19-and-w20/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto Networks PSIRT</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/microsoft-exchange-cve-2026-42897-owa-xss-same-week-compound" data-tags="vulnerabilities actively-exploited zero-day cisa-kev no-patch identity" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:07Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span></div><h3 class="f-h" id="microsoft-exchange-cve-2026-42897-owa-xss-same-week-compound"><a href="https://ctipilot.ch/entries/2026-05-11/microsoft-exchange-cve-2026-42897-owa-xss-same-week-compound/">Microsoft Exchange CVE-2026-42897 OWA-XSS — same-week compounding with the DEVCORE Pwn2Own chain</a></h3><p>The Exchange story is unusual in that the cross-day chain plays out <strong>within</strong> W20 rather than as a multi-week arc. <strong>Friday 2026-05-15:</strong> Microsoft confirms active exploitation of CVE-2026-42897, an OWA stored XSS in calendar-invite rendering; CISA adds it to KEV with a 2026-05-29 federal remediation deadline; NCSC.ch publishes Security Hub post #12577 the same day (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897" target="_blank" rel="noopener noreferrer">Microsoft MSRC</a>; <a href="https://security-hub.ncsc.admin.ch/#/posts/12577" target="_blank" rel="noopener noreferrer">NCSC.ch #12577</a>; <a href="https://ctipilot.ch/briefs/2026-05-16/" target="_blank" rel="noopener noreferrer">daily 2026-05-16</a>). <strong>Thursday 2026-05-15 (Pwn2Own Day Two, parallel timeline):</strong> Orange Tsai / DEVCORE earned $200,000 by chaining three bugs to achieve pre-auth RCE as SYSTEM on Exchange Server SE per Zero Day Initiative published results; ZDI does not publish per-bug technical detail before vendor patches under the standard 90-day disclosure clock (<a href="https://www.thezdi.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results" target="_blank" rel="noopener noreferrer">ZDI Day Two</a>; <a href="https://ctipilot.ch/briefs/2026-05-17/" target="_blank" rel="noopener noreferrer">daily 2026-05-17 UPDATE</a>).</p>
<p>These are two distinct findings (CVE-2026-42897 stored XSS active in the wild vs. the DEVCORE three-bug chain that achieved pre-auth SYSTEM RCE in a controlled-research setting) and at week-end Microsoft has not formally linked them; but for any threat actor with a foothold via the OWA-XSS, post-foothold escalation primitives along the lines DEVCORE demonstrated are the natural next-stage concern. The composite threat picture is: pre-auth SYSTEM RCE plausibly weaponisable from public research before Microsoft ships a permanent patch; pre-auth session takeover via the OWA-XSS possible <strong>today</strong>. EEMS / EOMT mitigations address the XSS attack path only. Hunt scope: OWA <code>w3wp.exe</code> worker children spawning anomalous PowerShell / WMI; mailbox-role-assignment audit trail for unexpected privilege transitions.</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/microsoft-exchange-cve-2026-42897-owa-xss-same-week-compound/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897" target="_blank" rel="noopener noreferrer">Microsoft Security Blog</a> · <a href="https://security-hub.ncsc.admin.ch/api/posts/12577/details" target="_blank" rel="noopener noreferrer">NCSC.ch Security Hub #12577</a> · <a href="https://www.thezdi.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results" target="_blank" rel="noopener noreferrer">Zero Day Initiative</a></div></article><div class="sect" id="vulnerability-roll-up"><span class="n">03</span><span class="t">Vulnerability roll-up</span><span class="c">6 items</span></div><article class="finding entry-card" data-entry-id="2026-05-11/cve-2026-44088-cert-pl-szafirhost-jar-zip-polyglot-bypass-in" data-tags="vulnerabilities identity patch-available" data-regions="europe" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-11T05:00:11Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-44088/">CVE-2026-44088</a></div><h3 class="f-h" id="cve-2026-44088-cert-pl-szafirhost-jar-zip-polyglot-bypass-in"><a href="https://ctipilot.ch/entries/2026-05-11/cve-2026-44088-cert-pl-szafirhost-jar-zip-polyglot-bypass-in/">CVE-2026-44088 — CERT-PL SzafirHost JAR zip-polyglot bypass in Poland&#39;s qualified e-signature browser helper</a></h3><p>CERT-PL disclosed CVE-2026-44088 on 2026-05-17: a JAR zip-polyglot bypass in the SzafirHost browser-helper that mediates qualified e-signature operations for Polish public-sector users (citizen-facing e-government services). The flaw lets a crafted JAR delivered as a polyglot file bypass the qualifying-certificate check and induce the host to attach a qualified signature to attacker-chosen content. Patched 2026-05-15. Operational relevance for Swiss / EU public-sector defenders: the eIDAS qualified-electronic-signature framework is pan-European, so the <strong>class</strong> of attack — polyglot-file abuse of a browser-helper that mediates signature operations — is portable to Swiss QES vendors and to other member-state qualified-signature browser helpers. Validation: confirm patch state of every QES-helper in your endpoint estate; consider polyglot-file detection as a content-inspection control on inbound document workflows (<a href="https://cert.pl/en/posts/2026/05/CVE-2026-44088/" target="_blank" rel="noopener noreferrer">CERT-PL CERT-PL-2026-44088</a>; <a href="https://ctipilot.ch/briefs/2026-05-17/" target="_blank" rel="noopener noreferrer">daily 2026-05-17</a>).</p><div class="prov"><span>vulnerability</span><span>11 May 05:00Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/cve-2026-44088-cert-pl-szafirhost-jar-zip-polyglot-bypass-in/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cert.pl/en/posts/2026/05/CVE-2026-44088/" target="_blank" rel="noopener noreferrer">CERT-PL CERT-PL-2026-44088</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/cve-2026-46300-linux-kernel-xfrm-esp-in-tcp-lpe-fragnesia-po" data-tags="vulnerabilities lpe poc-public patch-available" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-11T05:00:14Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-46300/">CVE-2026-46300</a></div><h3 class="f-h" id="cve-2026-46300-linux-kernel-xfrm-esp-in-tcp-lpe-fragnesia-po"><a href="https://ctipilot.ch/entries/2026-05-11/cve-2026-46300-linux-kernel-xfrm-esp-in-tcp-lpe-fragnesia-po/">CVE-2026-46300 — Linux kernel xfrm ESP-in-TCP LPE (&quot;Fragnesia&quot;), PoC public</a></h3><p>Disclosed 2026-05-15 with public PoC; mainline kernel patch landed 2026-05-14, distro propagation underway. LPE primitive against the xfrm ESP-in-TCP code path; trips IPsec VPN endpoints in particular. Mitigation <code>modprobe -r esp4 esp6</code> (breaks IPsec). Distinct from Dirty Frag (different code paths) but conceptually adjacent — both abuse kernel xfrm assumptions (<a href="https://ctipilot.ch/briefs/2026-05-15/" target="_blank" rel="noopener noreferrer">daily 2026-05-15</a>).</p><div class="prov"><span>vulnerability</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/cve-2026-46300-linux-kernel-xfrm-esp-in-tcp-lpe-fragnesia-po/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.wiz.io/blog/fragnesia-linux-kernel-local-privilege-escalation-via-esp-in-tcp" target="_blank" rel="noopener noreferrer">Linux kernel security advisory CVE-2026-46300</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/windows-bitlocker-yellowkey-and-ctfmon-greenplasma-public-po" data-tags="vulnerabilities zero-day lpe no-patch poc-public" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-11T05:00:13Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="windows-bitlocker-yellowkey-and-ctfmon-greenplasma-public-po"><a href="https://ctipilot.ch/entries/2026-05-11/windows-bitlocker-yellowkey-and-ctfmon-greenplasma-public-po/">Windows BitLocker &quot;YellowKey&quot; and CTFMON &quot;GreenPlasma&quot; — public PoC, no patch</a></h3><p>Listed here for vulnerability-roll-up completeness. No CVE identifiers had been allocated by Microsoft as of 2026-05-17.</p><div class="prov"><span>vulnerability</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/windows-bitlocker-yellowkey-and-ctfmon-greenplasma-public-po/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/" target="_blank" rel="noopener noreferrer">BleepingComputer — Windows BitLocker zero-day PoC</a> · <a href="https://security-hub.ncsc.admin.ch/#/posts/12574" target="_blank" rel="noopener noreferrer">NCSC.ch Security Hub #12574</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/cve-2026-6722-php-soap-uaf-in-soap-global-ref-map-with-compa" data-tags="vulnerabilities rce patch-available" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-11T05:00:12Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-6722/">CVE-2026-6722 +2</a></div><h3 class="f-h" id="cve-2026-6722-php-soap-uaf-in-soap-global-ref-map-with-compa"><a href="https://ctipilot.ch/entries/2026-05-11/cve-2026-6722-php-soap-uaf-in-soap-global-ref-map-with-compa/">CVE-2026-6722 — PHP SOAP UAF in SOAP_GLOBAL(ref_map) (with companions CVE-2026-7261 / CVE-2026-7262)</a></h3><p>PHP SOAP-extension use-after-free in <code>SOAP_GLOBAL(ref_map)</code>, CVSS 9.5, with two related companions (CVE-2026-7261 and CVE-2026-7262, both SOAP-class, CVSS 6.3 each). Patched on 2026-05-07 in PHP 8.5.6 and equivalents across maintained 8.4 / 8.3 / 8.2 branches per the official PHP GHSA. No ITW exploitation at week-end; daily 2026-05-11 recommends explicit patch validation for any web-facing PHP infrastructure with SOAP enabled (<a href="https://ctipilot.ch/briefs/2026-05-11/" target="_blank" rel="noopener noreferrer">daily 2026-05-11</a>; <a href="https://github.com/php/php-src/security/advisories/GHSA-85c2-q967-79q5" target="_blank" rel="noopener noreferrer">PHP GHSA-85c2-q967-79q5</a>).</p><div class="prov"><span>vulnerability</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/cve-2026-6722-php-soap-uaf-in-soap-global-ref-map-with-compa/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://github.com/php/php-src/security/advisories/GHSA-85c2-q967-79q5" target="_blank" rel="noopener noreferrer">PHP GHSA-85c2-q967-79q5</a> · <a href="https://php.watch/versions/8.5/releases/8.5.6" target="_blank" rel="noopener noreferrer">php.watch — PHP 8.5.6 release</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/cve-2026-34263-sap-commerce-cloud-pre-auth-rce-cve-2026-3426" data-tags="vulnerabilities pre-auth rce patch-available" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-11T05:00:10Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-34263/">CVE-2026-34263 +1</a></div><h3 class="f-h" id="cve-2026-34263-sap-commerce-cloud-pre-auth-rce-cve-2026-3426"><a href="https://ctipilot.ch/entries/2026-05-11/cve-2026-34263-sap-commerce-cloud-pre-auth-rce-cve-2026-3426/">CVE-2026-34263 — SAP Commerce Cloud pre-auth RCE; CVE-2026-34260 — SAP S/4HANA Enterprise Search SQL injection</a></h3><p>SAP&#39;s May 2026 Security Patch Day shipped CVE-2026-34263 (Commerce Cloud pre-auth RCE) and CVE-2026-34260 (S/4HANA Enterprise Search SQL injection). Commerce Cloud is internet-exposed by design (storefront workloads); S/4HANA Enterprise Search is typically segmented but reachable from internal-user populations. No ITW exploitation at week-end (<a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news/may-2026.html" target="_blank" rel="noopener noreferrer">SAP Security Patch Day May 2026</a>; <a href="https://ctipilot.ch/briefs/2026-05-13/" target="_blank" rel="noopener noreferrer">daily 2026-05-13</a>). Swiss / EU public-sector deployments of S/4HANA in federal-administration ERP estates make the SQL-injection patch state worth verifying outside the standard quarterly window.</p><div class="prov"><span>vulnerability</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/cve-2026-34263-sap-commerce-cloud-pre-auth-rce-cve-2026-3426/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://support.sap.com/en/my-support/knowledge-base/security-notes-news/may-2026.html" target="_blank" rel="noopener noreferrer">SAP Security Patch Day May 2026</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/cve-2026-44277-cve-2026-26083-fortinet-fortiauthenticator-an" data-tags="vulnerabilities pre-auth rce patch-available" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-11T05:00:09Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-44277/">CVE-2026-44277 +1</a></div><h3 class="f-h" id="cve-2026-44277-cve-2026-26083-fortinet-fortiauthenticator-an"><a href="https://ctipilot.ch/entries/2026-05-11/cve-2026-44277-cve-2026-26083-fortinet-fortiauthenticator-an/">CVE-2026-44277 / CVE-2026-26083 — Fortinet FortiAuthenticator and FortiSandbox unauthenticated RCE</a></h3><p>Fortinet&#39;s 2026-05-13 PSIRT batch addresses two unauthenticated remote-code-execution flaws on management-plane Fortinet appliances common in Swiss federal and cantonal estates. CVE-2026-44277 (FortiAuthenticator, the SAML / RADIUS / 802.1X identity broker) and CVE-2026-26083 (FortiSandbox, the malware-analysis appliance) are both pre-auth network-reachable and CVSS ≥ 9. Daily 2026-05-13 confirmed patched builds; no ITW exploitation reported at week-end. Operational implication: FortiAuthenticator sits at the centre of identity-broker trust chains in many public-sector network architectures, so a compromised FortiAuthenticator yields cross-domain credential-issuance capability that is materially worse than a typical RCE — patch state should be verified explicitly on every FortiAuthenticator deployment (<a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-128" target="_blank" rel="noopener noreferrer">Fortinet PSIRT FG-IR-26-128 / FG-IR-26-136</a>; <a href="https://ctipilot.ch/briefs/2026-05-13/" target="_blank" rel="noopener noreferrer">daily 2026-05-13</a>).</p><div class="prov"><span>vulnerability</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/cve-2026-44277-cve-2026-26083-fortinet-fortiauthenticator-an/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-128" target="_blank" rel="noopener noreferrer">Fortinet PSIRT FG-IR-26-128</a> · <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-136" target="_blank" rel="noopener noreferrer">Fortinet PSIRT FG-IR-26-136</a></div></article><div class="sect" id="sector-victim-patterns"><span class="n">04</span><span class="t">Sector &amp; victim patterns</span><span class="c">6 items</span></div><article class="finding entry-card" data-entry-id="2026-05-11/healthcare" data-tags="ransomware data-breach" data-regions="europe" data-kind="synthesis" data-priority="high" data-discovered="2026-05-11T05:00:15Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="healthcare"><a href="https://ctipilot.ch/entries/2026-05-11/healthcare/">Healthcare</a></h3><p>Two distinct healthcare-sector signals this week. <strong>Dutch IGJ ruling on Clinical Diagnostics / NMDL</strong> (2026-05-14) formally found the laboratory provider non-conformant with NEN 7510 (Dutch information-security-management standard for healthcare) at the time of the July 2025 ransomware breach; the daily 2026-05-14 (citing Computable) records approximately 941,000 patients affected including cervical-cancer screening records. This is the first IGJ NEN 7510 non-conformity finding against a third-party diagnostics provider and sets a regulatory precedent that maps directly onto NIS2 essential-entity supplier-due-diligence obligations — Dutch hospitals using the same supplier face open questions about whether their own NIS2 essential-entity status now creates downstream cyber-due-diligence liability for the supplier&#39;s controls (<a href="https://www.igj.nl/actueel/nieuws/2026/05/13/clinical-diagnostics-voldeed-niet-aan-wettelijke-norm-voor-informatiebeveiliging" target="_blank" rel="noopener noreferrer">IGJ inspection report</a>; <a href="https://www.computable.nl/2026/05/13/inspectie-vernietigend-over-beveiliging-clinical-diagnostics-na-datahack/" target="_blank" rel="noopener noreferrer">Computable</a>; <a href="https://ctipilot.ch/briefs/2026-05-14/" target="_blank" rel="noopener noreferrer">daily 2026-05-14</a>).</p>
<p><strong>West Pharmaceutical Services SEC Form 8-K Item 1.05</strong> (2026-05-12 [SINGLE-SOURCE-OTHER]) — data exfiltrated, systems encrypted, global operations partially restarted; pharmaceutical-manufacturing-sector incident with potential EU drug-supply-chain implications. The pattern across the two incidents is that healthcare-adjacent third-party suppliers (diagnostic labs, pharmaceutical-component manufacturers) are operationally critical to NIS2-scope hospital and public-health-service consumers but typically sit one tier away from the regulator&#39;s direct view; the IGJ-NMDL ruling provides the legal template for closing that gap (<a href="https://ctipilot.ch/briefs/2026-05-12/" target="_blank" rel="noopener noreferrer">daily 2026-05-12</a>).</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/healthcare/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.igj.nl/actueel/nieuws/2026/05/13/clinical-diagnostics-voldeed-niet-aan-wettelijke-norm-voor-informatiebeveiliging" target="_blank" rel="noopener noreferrer">IGJ inspection report</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/hospitality" data-tags="data-breach" data-regions="europe us" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:18Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="hospitality"><a href="https://ctipilot.ch/entries/2026-05-11/hospitality/">Hospitality</a></h3><p><strong>BWH Hotels (Best Western, WorldHotels, Sure Hotels) 181-day unauthorised access</strong> to a guest-reservation web application (daily 2026-05-13), six EU brands in scope. The 181-day dwell time is the operational lesson: a web-application access vector that escapes detection for half a year indicates absent application-tier telemetry — the right SOC-management response is to audit which guest / customer-facing web applications have <strong>no</strong> structured access-event telemetry feeding into the SIEM. EU regulatory scope: any of the six EU-brand reservation systems holding EU PII triggers GDPR Article 33 / 34 obligations and likely informs CEF 2026 enforcement attention (see Policy section below).</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/hospitality/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.theregister.com/security/2026/05/11/best-western-hotels-confirms-web-app-data-breach/5238020" target="_blank" rel="noopener noreferrer">The Register — Best Western confirms web-app breach</a> · <a href="https://www.securityweek.com/bwh-hotels-says-hackers-had-access-to-reservation-data-for-6-months/" target="_blank" rel="noopener noreferrer">SecurityWeek — BWH Hotels reservation data</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/manufacturing" data-tags="ransomware data-breach organized-crime" data-regions="us europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:17Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="manufacturing"><a href="https://ctipilot.ch/entries/2026-05-11/manufacturing/">Manufacturing</a></h3><p><strong>Foxconn confirmed Nitrogen ransomware</strong> crippled North-American manufacturing sites (daily 2026-05-13); 8 TB / 11M files claimed exfiltrated. Operationally this is North-America-localised but informs Swiss / EU manufacturing-sector defenders on Nitrogen&#39;s mid-2026 TTPs — the manufacturer attack surface (OT-network adjacency to enterprise IT, downtime-sensitive production lines giving ransom-payment pressure) is the same in CH / EU operators. <strong>Škoda Auto Deutschland online-shop breach</strong> (daily 2026-05-12) exposed customer PII and password hashes; logging-gap prevented exfiltration confirmation — the operational lesson is one Swiss federal IT teams should pattern-match against their own e-commerce / citizen-portal logging coverage.</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/manufacturing/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://therecord.media/foxconn-confirms-cyberattack-north-american-factories" target="_blank" rel="noopener noreferrer">The Record — Foxconn confirms cyberattack</a> · <a href="https://www.theregister.com/cyber-crime/2026/05/12/foxconn-confirms-cyberattack-after-nitrogen-claims-apple-nvidia-data-theft/5239144" target="_blank" rel="noopener noreferrer">The Register — Foxconn confirms</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/public-administration-and-government" data-tags="nation-state espionage russia-nexus identity" data-regions="europe switzerland" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:16Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="public-administration-and-government"><a href="https://ctipilot.ch/entries/2026-05-11/public-administration-and-government/">Public administration and government</a></h3><p>Three operator clusters made the public-administration / government sector pattern this week. <strong>Secret Blizzard / Turla</strong> (FSB Centre 16) evolved Kazuar into a three-module P2P botnet; Microsoft Threat Intelligence&#39;s 2026-05-14 analysis documents historical targeting of government and diplomatic-sector organizations in Europe and Central Asia (<a href="https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/" target="_blank" rel="noopener noreferrer">Microsoft Security Blog</a>; <a href="https://ctipilot.ch/briefs/2026-05-16/" target="_blank" rel="noopener noreferrer">daily 2026-05-16</a>). <strong>FrostyNeighbor / Ghostwriter</strong> (UNC1151, Belarus state-aligned) documented by ESET on 2026-05-14 with Polish, Lithuanian, and Ukrainian governmental, industrial, healthcare, and logistics targets in scope; the geofenced PDF → PicassoLoader JS → Cobalt Strike chain reuses CVE-2024-42009 (Roundcube XSS) for Polish targets (<a href="https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a>; <a href="https://thehackernews.com/2026/05/ghostwriter-targets-ukrainian.html" target="_blank" rel="noopener noreferrer">The Hacker News</a>; <a href="https://ctipilot.ch/briefs/2026-05-15/" target="_blank" rel="noopener noreferrer">daily 2026-05-15</a>). <strong>GTIG UNC6671 &quot;BlackFile&quot;</strong> (daily 2026-05-16) — vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim across mixed-sector victims including public-administration entities; the DLS-shutdown signal indicates a probable rebrand and is the watch-item for 2026-W21 (<a href="https://ctipilot.ch/briefs/2026-05-16/" target="_blank" rel="noopener noreferrer">daily 2026-05-16</a>).</p>
<p>The Swiss-specific signal worth flagging: the <strong>Sophos 2026 State of Identity Security report</strong> (covered daily 2026-05-15) records Switzerland as the country with the <strong>highest identity-breach incidence globally</strong> in the survey&#39;s reporting period; the daily 2026-05-15 reports energy as the hardest-hit sector in CH. The Sophos data corroborates the <strong>Secret Blizzard / FrostyNeighbor / UNC6671 public-administration pattern</strong> — identity-protocol abuse (Kerberos pre-auth, OAuth device-code, AiTM session-token theft) is the common pivot across all three operators and matches the identity-to-ransomware pipeline Sophos surfaces at 67% of cases ( (<a href="https://www.sophos.com/en-us/blog/sophos-state-of-identity-security-2026" target="_blank" rel="noopener noreferrer">Sophos blog</a>; <a href="https://ctipilot.ch/briefs/2026-05-15/" target="_blank" rel="noopener noreferrer">daily 2026-05-15</a>).</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/public-administration-and-government/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/" target="_blank" rel="noopener noreferrer">Microsoft Security Blog</a> · <a href="https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a> · <a href="https://www.sophos.com/en-us/blog/sophos-state-of-identity-security-2026" target="_blank" rel="noopener noreferrer">Sophos blog</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/wordpress-retail-e-commerce" data-tags="vulnerabilities actively-exploited data-breach supply-chain" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:20Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span></div><h3 class="f-h" id="wordpress-retail-e-commerce"><a href="https://ctipilot.ch/entries/2026-05-11/wordpress-retail-e-commerce/">WordPress retail / e-commerce</a></h3><p><strong>FunnelKit &quot;Funnel Builder for WooCommerce&quot;</strong> actively exploited as a Magecart skimmer on 40,000+ WordPress stores (daily 2026-05-17), no CVE assigned. The operational pattern (Magecart abuse of a popular WooCommerce plugin) is portable across the WordPress + WooCommerce e-commerce ecosystem used by Swiss / EU SMB retailers; SOC managers serving SMB or municipal e-commerce estates should sweep deployed WooCommerce plugin inventories for the affected FunnelKit version and audit checkout-page DOM for injected payment-form-skimming scripts.</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/wordpress-retail-e-commerce/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://sansec.io/research/funnelkit-woocommerce-vulnerability-exploited" target="_blank" rel="noopener noreferrer">Sansec research</a> · <a href="https://www.bleepingcomputer.com/news/security/funnel-builder-wordpress-plugin-bug-exploited-to-steal-credit-cards/" target="_blank" rel="noopener noreferrer">BleepingComputer — Funnel Builder skimmer</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/ai-tooling-saas-and-developer-toolchain" data-tags="supply-chain ai-abuse" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:19Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="ai-tooling-saas-and-developer-toolchain"><a href="https://ctipilot.ch/entries/2026-05-11/ai-tooling-saas-and-developer-toolchain/">AI tooling SaaS and developer toolchain</a></h3><p>The Mini Shai-Hulud / TeamPCP propagation across <code>@tanstack</code>, <code>@uipath</code>, <code>@mistralai</code>, <code>@opensearch-project</code>, <code>@guardrails-ai</code>, and OpenAI consolidates a sector pattern first surfaced in W19: AI-evaluation, AI-observability, AI-agent-orchestration, and AI-tooling SaaS vendors <strong>all</strong> sit on architectures that aggregate organisation-level upstream credentials (LLM-provider API keys, GitHub Actions OIDC tokens, package-publish certificates) — and the operator class active this quarter is mining that aggregation pattern systematically.</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/ai-tooling-saas-and-developer-toolchain/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/" target="_blank" rel="noopener noreferrer">Datadog Security Labs</a></div></article><div class="sect" id="incidents-disclosures-recap"><span class="n">05</span><span class="t">Incidents &amp; disclosures recap</span><span class="c">8 items</span></div><article class="finding entry-card" data-entry-id="2026-05-11/bka-dream-market-arrest-speedstepper-detained-in-germany-aft" data-tags="law-enforcement organized-crime cryptocrime" data-regions="europe" data-kind="incident" data-priority="notable" data-discovered="2026-05-11T05:00:28Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="bka-dream-market-arrest-speedstepper-detained-in-germany-aft"><a href="https://ctipilot.ch/entries/2026-05-11/bka-dream-market-arrest-speedstepper-detained-in-germany-aft/">BKA Dream Market arrest — &quot;Speedstepper&quot; detained in Germany after seven years at large</a></h3><p>BKA arrested Dream Market lead administrator &quot;Speedstepper&quot; in Germany; OPSEC failure traced to cryptocurrency-to-physical-gold conversion patterns (daily 2026-05-16). Complements the W20 BKA Crimenetwork takedown (daily 2026-05-12) — two consecutive German federal LE actions against darknet-market administrative-tier operators in the same week. For European cybercrime ecosystem analysis: the BKA tempo on darknet-administrator pursuit is materially elevated through Q2 2026 and likely informs the broader operator OPSEC environment.</p><div class="prov"><span>incident</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/bka-dream-market-arrest-speedstepper-detained-in-germany-aft/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bka.de/DE/Presse/Listenseite_Pressemitteilungen/2026/Presse2026/260516_DreamMarket.html" target="_blank" rel="noopener noreferrer">BKA press release — Dream Market administrator arrest</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/koda-auto-deutschland-online-shop-breach-exposes-customer-pi" data-tags="data-breach" data-regions="europe" data-kind="incident" data-priority="notable" data-discovered="2026-05-11T05:00:25Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="koda-auto-deutschland-online-shop-breach-exposes-customer-pi"><a href="https://ctipilot.ch/entries/2026-05-11/koda-auto-deutschland-online-shop-breach-exposes-customer-pi/">Škoda Auto Deutschland — online-shop breach exposes customer PII and password hashes</a></h3><p>Customer PII and password hashes exposed; logging-gap prevented exfiltration confirmation. The defender&#39;s learning is the logging-coverage point: a breach where the victim <strong>cannot confirm</strong> what was exfiltrated is a logging-design failure. Pattern-match: which of your own citizen-facing / customer-facing e-commerce flows would leave you with the same uncertainty after an intrusion? (<a href="https://ctipilot.ch/briefs/2026-05-12/" target="_blank" rel="noopener noreferrer">daily 2026-05-12</a>).</p><div class="prov"><span>incident</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/koda-auto-deutschland-online-shop-breach-exposes-customer-pi/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.skoda-auto.de/unternehmen/sicherheitsvorfall-skoda-shop" target="_blank" rel="noopener noreferrer">Heise Security</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/west-pharmaceutical-services-sec-form-8-k-item-1-05" data-tags="ransomware data-breach" data-regions="us europe" data-kind="incident" data-priority="notable" data-discovered="2026-05-11T05:00:24Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="west-pharmaceutical-services-sec-form-8-k-item-1-05"><a href="https://ctipilot.ch/entries/2026-05-11/west-pharmaceutical-services-sec-form-8-k-item-1-05/">West Pharmaceutical Services — SEC Form 8-K Item 1.05</a></h3><p>Data exfiltrated, systems encrypted, global operations partially restarted. SEC 8-K Item 1.05 disclosure — single-source as of week-end with no independent corroborating breach analysis. Operational relevance to Swiss / EU public-sector defenders: West Pharmaceutical supplies drug-delivery components into EU pharmaceutical-manufacturing supply chains; the &quot;global operations partially restarted&quot; language indicates ongoing IT-side recovery that may yet propagate downstream supply-chain impact (<a href="https://ctipilot.ch/briefs/2026-05-12/" target="_blank" rel="noopener noreferrer">daily 2026-05-12</a>).</p><div class="prov"><span>incident</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/west-pharmaceutical-services-sec-form-8-k-item-1-05/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sec.gov/Archives/edgar/data/105770/000010577026000068/wst-20260507.htm" target="_blank" rel="noopener noreferrer">SEC Form 8-K filing — West Pharmaceutical Services Inc.</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/clinical-diagnostics-nmdl-dutch-igj-formal-nen-7510-non-conf" data-tags="data-breach ransomware" data-regions="europe" data-kind="incident" data-priority="notable" data-discovered="2026-05-11T05:00:23Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="clinical-diagnostics-nmdl-dutch-igj-formal-nen-7510-non-conf"><a href="https://ctipilot.ch/entries/2026-05-11/clinical-diagnostics-nmdl-dutch-igj-formal-nen-7510-non-conf/">Clinical Diagnostics / NMDL — Dutch IGJ formal NEN 7510 non-conformity ruling</a></h3><p>The IGJ ruling formally found Clinical Diagnostics / NMDL non-conformant with NEN 7510 (Dutch information-security-management standard for healthcare) at the time of the July 2025 ransomware breach (approximately 941,000 patients affected per Computable / daily 2026-05-14, cervical-cancer screening data exposed). First IGJ NEN 7510 non-conformity finding against a third-party diagnostics provider. For Swiss / EU public-sector defenders: this is the regulatory template member-state regulators are likely to deploy under NIS2 essential-entity supplier-due-diligence obligations — Dutch hospitals using the same supplier and other EU member-state regulators with parallel healthcare-ISO standards (NEN 7510, ISO 27799, the Italian AgID guidelines) will pattern-match this ruling for their own supplier oversight (<a href="https://www.igj.nl/actueel/nieuws/2026/05/13/clinical-diagnostics-voldeed-niet-aan-wettelijke-norm-voor-informatiebeveiliging" target="_blank" rel="noopener noreferrer">IGJ inspection report</a>; <a href="https://www.computable.nl/2026/05/13/inspectie-vernietigend-over-beveiliging-clinical-diagnostics-na-datahack/" target="_blank" rel="noopener noreferrer">Computable</a>; <a href="https://ctipilot.ch/briefs/2026-05-14/" target="_blank" rel="noopener noreferrer">daily 2026-05-14</a>).</p><div class="prov"><span>incident</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/clinical-diagnostics-nmdl-dutch-igj-formal-nen-7510-non-conf/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.igj.nl/actueel/nieuws/2026/05/13/clinical-diagnostics-voldeed-niet-aan-wettelijke-norm-voor-informatiebeveiliging" target="_blank" rel="noopener noreferrer">IGJ inspection report</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/bwh-hotels-181-day-unauthorised-access-to-guest-reservation" data-tags="data-breach" data-regions="europe us" data-kind="incident" data-priority="notable" data-discovered="2026-05-11T05:00:22Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="bwh-hotels-181-day-unauthorised-access-to-guest-reservation"><a href="https://ctipilot.ch/entries/2026-05-11/bwh-hotels-181-day-unauthorised-access-to-guest-reservation/">BWH Hotels — 181-day unauthorised access to guest-reservation web application</a></h3><p>Six EU brands (Best Western, WorldHotels, Sure Hotels and three sub-brands) in scope; 181-day dwell time indicates absent application-tier telemetry on the affected reservation web application. EU regulatory scope: GDPR Article 33 / 34 obligations for the six EU-brand reservation systems holding EU PII. The defender&#39;s learning: audit which guest-facing / citizen-facing web applications have no structured access-event telemetry into the SIEM (<a href="https://ctipilot.ch/briefs/2026-05-13/" target="_blank" rel="noopener noreferrer">daily 2026-05-13</a>).</p><div class="prov"><span>incident</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/bwh-hotels-181-day-unauthorised-access-to-guest-reservation/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.theregister.com/security/2026/05/11/best-western-hotels-confirms-web-app-data-breach/5238020" target="_blank" rel="noopener noreferrer">SecurityWeek</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/node-ipc-npm-package-backdoored-via-expired-domain-account-t" data-tags="supply-chain data-breach" data-regions="global" data-kind="incident" data-priority="notable" data-discovered="2026-05-11T05:00:27Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="node-ipc-npm-package-backdoored-via-expired-domain-account-t"><a href="https://ctipilot.ch/entries/2026-05-11/node-ipc-npm-package-backdoored-via-expired-domain-account-t/">node-ipc npm package — backdoored via expired-domain account takeover</a></h3><p><code>node-ipc</code> npm package backdoored via expired-domain account takeover; 90+ credential categories exfiltrated; three malicious versions; ~3-minute window to detection (daily 2026-05-16). The defender&#39;s learning is the <strong>expired-domain account-takeover</strong> vector — package-maintainer email domains that lapse become a one-time supply-chain compromise vector. Operational pattern-match: audit npm / PyPI / Cargo dependency trees for packages whose maintainer addresses are at domains your organisation could verify still belong to the original maintainer.</p><div class="prov"><span>incident</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/node-ipc-npm-package-backdoored-via-expired-domain-account-t/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://socket.dev/blog/node-ipc-package-compromised" target="_blank" rel="noopener noreferrer">Sonatype security advisory — node-ipc backdoor</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/south-staffordshire-water-ico-963-900-fine" data-tags="ransomware data-breach law-enforcement" data-regions="uk" data-kind="incident" data-priority="notable" data-discovered="2026-05-11T05:00:26Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="south-staffordshire-water-ico-963-900-fine"><a href="https://ctipilot.ch/entries/2026-05-11/south-staffordshire-water-ico-963-900-fine/">South Staffordshire Water — ICO £963,900 fine</a></h3><p>ICO fines South Staffordshire Water £963,900 over the 2022 Cl0p ZeroLogon kill-chain intrusion (daily 2026-05-12). The water-sector OES finding with the partial SIEM coverage detail (5% host-inventory coverage) is the operational lesson for any utility / critical-infrastructure operator with patchy telemetry. Regulatory significance: the ICO penalty on a critical-infrastructure operator gives Swiss BACS / EU NIS2 competent authorities a template fine-calculation for analogous deficiencies (<a href="https://ctipilot.ch/briefs/2026-05-12/" target="_blank" rel="noopener noreferrer">daily 2026-05-12</a>).</p><div class="prov"><span>incident</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/south-staffordshire-water-ico-963-900-fine/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/05/fine-of-nearly-1m-issued-against-south-staffordshire-plc-and-south-staffordshire-water-plc/" target="_blank" rel="noopener noreferrer">ICO penalty notice — South Staffordshire Water</a> · <a href="https://therecord.media/uk-water-company-had-hackers-lurking-for-years" target="_blank" rel="noopener noreferrer">The Record</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/foxconn-nitrogen-ransomware-confirmed-against-north-american" data-tags="ransomware organized-crime" data-regions="us" data-kind="incident" data-priority="notable" data-discovered="2026-05-11T05:00:21Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="foxconn-nitrogen-ransomware-confirmed-against-north-american"><a href="https://ctipilot.ch/entries/2026-05-11/foxconn-nitrogen-ransomware-confirmed-against-north-american/">Foxconn — Nitrogen ransomware confirmed against North-American manufacturing sites</a></h3><p>Foxconn confirmed Nitrogen ransomware crippled North-American manufacturing sites; 8 TB / 11M files claimed exfiltrated. Same-week victim confirmation after the leak-site listing — operationally a useful data point on Nitrogen&#39;s mid-2026 tempo and the manufacturer-sector pressure to confirm publicly to clear customer / regulator queries quickly. North-America-localised; the relevance to Swiss / EU defenders is the operator-tempo signal, not direct victim impact (<a href="https://ctipilot.ch/briefs/2026-05-13/" target="_blank" rel="noopener noreferrer">daily 2026-05-13</a>).</p><div class="prov"><span>incident</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/foxconn-nitrogen-ransomware-confirmed-against-north-american/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://therecord.media/foxconn-confirms-cyberattack-north-american-factories" target="_blank" rel="noopener noreferrer">BleepingComputer</a></div></article><div class="sect" id="annual-periodic-threat-reports"><span class="n">06</span><span class="t">Annual / periodic threat reports</span><span class="c">6 items</span></div><article class="finding entry-card" data-entry-id="2026-05-11/check-point-april-2026-ransomware-analysis-qilin-leads-at-15" data-tags="ransomware organized-crime" data-regions="europe dach" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-11T05:00:31Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="check-point-april-2026-ransomware-analysis-qilin-leads-at-15"><a href="https://ctipilot.ch/entries/2026-05-11/check-point-april-2026-ransomware-analysis-qilin-leads-at-15/">Check Point April 2026 ransomware analysis — Qilin leads at 15%, Germany at 5% of global victims</a></h3><p>Check Point&#39;s April 2026 monthly threat report (published early May 2026) confirms Qilin / Agenda leading all ransomware operators with 15% of 707 published attacks in April; Germany is the third-most-targeted country globally at 5.0% of victims (US 41.6%); Europe accounts for 27% of ransomware victims globally. Sector targeting in April 2026: Business Services (33.8%), healthcare, manufacturing. The Gentlemen — despite the May 4 backend breach — remained in the top-7 operators with 320+ victims (<a href="https://blog.checkpoint.com/research/cyber-threats-spike-in-april-2026-as-ransomware-expands-and-attack-volumes-climb-after-short-lived-moderation/" target="_blank" rel="noopener noreferrer">Check Point Research, 2026-05-08</a>). The synthesis the dailies did not yet absorb: Germany&#39;s 5% share of global ransomware victims is materially elevated compared to the 2024–2025 baseline (~2–3%); the <strong>Qilin DLS lists 65 German victims total as of 2026-05-16</strong> (<a href="https://blog.checkpoint.com/research/cyber-threats-spike-in-april-2026-as-ransomware-expands-and-attack-volumes-climb-after-short-lived-moderation/" target="_blank" rel="noopener noreferrer">Check Point blog, dataset reference</a>). For Swiss defenders: CH-DE cross-border operations (Swiss subsidiaries in DE, German subsidiaries of Swiss parents) inherit the German exposure level; this is the empirical basis for a DACH-region threat-modelling premium on ransomware-readiness exercises.</p><div class="prov"><span>annual-report</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/check-point-april-2026-ransomware-analysis-qilin-leads-at-15/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.checkpoint.com/research/cyber-threats-spike-in-april-2026-as-ransomware-expands-and-attack-volumes-climb-after-short-lived-moderation/" target="_blank" rel="noopener noreferrer">Check Point Research</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/sophos-2026-state-of-identity-security-71-of-orgs-breached-v" data-tags="identity supply-chain" data-regions="global switzerland" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-11T05:00:29Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="sophos-2026-state-of-identity-security-71-of-orgs-breached-v"><a href="https://ctipilot.ch/entries/2026-05-11/sophos-2026-state-of-identity-security-71-of-orgs-breached-v/">Sophos 2026 State of Identity Security — 71% of orgs breached via identity, 41% root-caused to non-human-identity mismanagement, Switzerland records highest incidence</a></h3><p>Published 2026-05-15. Vendor-agnostic survey of 5,000 IT and security leaders across 17 countries (Q1 2026 fieldwork). The defender-relevant findings beyond the headline 71% identity-breach figure: (a) <strong>identity-to-ransomware pipeline dominant</strong> — 67% of ransomware victims attributed their ransomware incident directly to a prior identity attack, establishing identity-protocol abuse as the operationally dominant initial-access pattern; (b) <strong>non-human identity (NHI) mismanagement is the leading root cause</strong> — service accounts, API keys, AI-agent identities outnumber human identities by ratios up to 100:1 in surveyed organisations, weak NHI lifecycle management was the root cause in 41% of successful identity breaches, only 34% of organisations regularly audit NHI accounts; (c) <strong>Switzerland records the highest identity-breach incidence globally</strong> in the survey period; the daily 2026-05-15 also reported energy as the hardest-hit sector (<a href="https://www.sophos.com/en-us/blog/sophos-state-of-identity-security-2026" target="_blank" rel="noopener noreferrer">Sophos blog</a>; <a href="https://www.helpnetsecurity.com/2026/05/14/sophos-2026-identity-breach-costs-report/" target="_blank" rel="noopener noreferrer">Help Net Security — Sophos 2026 identity-breach costs report</a>; <a href="https://ctipilot.ch/briefs/2026-05-15/" target="_blank" rel="noopener noreferrer">daily 2026-05-15</a>).</p>
<p>The synthesis lens the daily did not have room for: the Sophos data corroborates the W19 Mandiant M-Trends finding that identity-rooted intrusions dominate IR-case data, and it converges with the Verizon DBIR 2026 finding (below) that stolen credentials remain the most common initial-access vector. The composite picture: for Swiss federal / cantonal estates with high service-account density and no NHI lifecycle governance, the <strong>NHI inventory + lifecycle gap is the single highest-leverage control deficit</strong> disclosed in this week&#39;s research output. The Sophos data is the empirical basis for prioritising NHI governance over endpoint-EDR upgrades, where budget pressure forces a choice. Detection focus: anomalous service-account Kerberos TGS requests (T1558.003 Kerberoasting), unusual OAuth token grants from CI/CD service identities, API key usage from unexpected source IPs or geographies.</p><div class="prov"><span>annual-report</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/sophos-2026-state-of-identity-security-71-of-orgs-breached-v/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sophos.com/en-us/blog/sophos-state-of-identity-security-2026" target="_blank" rel="noopener noreferrer">Sophos blog</a> · <a href="https://www.sophos.com/en-us/press/press-releases/2026/05/71-percent-organizations-suffered-identity-breach-state-of-identity-security-2026" target="_blank" rel="noopener noreferrer">Sophos press release</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/gtig-ai-threat-tracker-may-2026-first-ai-generated-zero-day" data-tags="ai-abuse nation-state" data-regions="global" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-11T05:00:34Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="gtig-ai-threat-tracker-may-2026-first-ai-generated-zero-day"><a href="https://ctipilot.ch/entries/2026-05-11/gtig-ai-threat-tracker-may-2026-first-ai-generated-zero-day/">GTIG AI Threat Tracker (May 2026) — first AI-generated zero-day exploit ITW</a></h3><p>GTIG&#39;s May 2026 AI Threat Tracker (covered as daily 2026-05-12 deep dive) documents the <strong>first confirmed AI-generated zero-day exploit observed in-the-wild</strong> and presents the behavioural class of AI-augmented malware. The synthesis worth elevating for the weekly: the &quot;AI-augmented&quot; malware category is no longer hypothetical for SOC defenders — the behavioural-class taxonomy GTIG provides (LLM-assisted code generation in payload, AI-driven C2 dialogue, model-mediated lateral movement decisions) is the right detection-engineering reference for SOCs building hunt content for the next 12 months. The relevant SOC capability investment: behavioural baselines for &quot;what does AI-mediated execution look like in our telemetry&quot; — not new IOC ingestion (<a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-threat-tracker-may-2026/" target="_blank" rel="noopener noreferrer">GTIG AI Threat Tracker May 2026</a>; <a href="https://ctipilot.ch/briefs/2026-05-12/" target="_blank" rel="noopener noreferrer">daily 2026-05-12 deep dive</a>).</p><div class="prov"><span>annual-report</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/gtig-ai-threat-tracker-may-2026-first-ai-generated-zero-day/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-threat-tracker-may-2026/" target="_blank" rel="noopener noreferrer">GTIG AI Threat Tracker May 2026</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/sentinelone-living-off-the-pipeline-ci-cd-subversion-taxonom" data-tags="supply-chain identity" data-regions="global" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-11T05:00:33Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="sentinelone-living-off-the-pipeline-ci-cd-subversion-taxonom"><a href="https://ctipilot.ch/entries/2026-05-11/sentinelone-living-off-the-pipeline-ci-cd-subversion-taxonom/">SentinelOne — Living Off the Pipeline: CI/CD subversion taxonomy</a></h3><p>SentinelOne&#39;s &quot;Living Off the Pipeline&quot; research (covered daily 2026-05-16, [SINGLE-SOURCE]) presents a three-case taxonomy of CI/CD subversion in real intrusions: TeamCity buildAgent-token theft, GitLab service-account pivot, and Contagious Interview (DPRK-aligned) build-time compromise. The weekly-level synthesis worth surfacing: the <strong>three-case study generalises to a defender pattern</strong> — CI/CD systems concentrate trust (build secrets, artifact-signing keys, deployment credentials) in machine-identity environments with weaker authentication / authorisation telemetry than human-identity environments. Combined with the Sophos NHI finding (41% of identity breaches root-caused to NHI mismanagement, above), CI/CD platforms are the highest-leverage NHI-governance attack surface for Swiss / EU public-sector DevSecOps programmes. Hunt seeds: TeamCity buildAgent re-auth events, GitLab CI job impersonation patterns, GitHub Actions OIDC-token reuse outside expected workflow scope (<a href="https://ctipilot.ch/briefs/2026-05-16/" target="_blank" rel="noopener noreferrer">daily 2026-05-16</a>).</p><div class="prov"><span>annual-report</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/sentinelone-living-off-the-pipeline-ci-cd-subversion-taxonom/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sentinelone.com/blog/living-off-the-pipeline-defending-against-ci-cd-subversion/" target="_blank" rel="noopener noreferrer">SentinelOne Labs</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/datadog-security-labs-shai-hulud-framework-static-analysis" data-tags="supply-chain ai-abuse" data-regions="global" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-11T05:00:32Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="datadog-security-labs-shai-hulud-framework-static-analysis"><a href="https://ctipilot.ch/entries/2026-05-11/datadog-security-labs-shai-hulud-framework-static-analysis/">Datadog Security Labs — Shai-Hulud framework static analysis</a></h3><p>Datadog Security Labs published a static analysis of the <strong>leaked Shai-Hulud framework source</strong> on 2026-05-13 (covered daily 2026-05-15). The synthesis the daily had room for was the high-level capability summary; the cross-finding lens worth surfacing here: this is the first publicly-available <strong>complete-source reverse-engineering of an active npm-supply-chain operator&#39;s toolkit</strong>, comparable to the value the leaked Conti chats provided in 2022 for ransomware-affiliate defender intelligence. Detection-engineering teams now have a non-IOC behavioural reference for the entire TeamPCP toolchain: IDE-persistence hook patterns, OIDC-token extraction from <code>/proc/&lt;pid&gt;/mem</code>, Sigstore-provenance forgery primitives, GitHub Actions dead-drop conventions. The Datadog post-leak ecosystem-monitoring methodology (matching commits, repo names, hook configurations) is portable to any organisation with developer-workstation file-integrity monitoring; the broader implication is that <strong>publication-provenance verification is no longer sufficient as a sole supply-chain control</strong> (<a href="https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/" target="_blank" rel="noopener noreferrer">Datadog Security Labs</a>).</p><div class="prov"><span>annual-report</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/datadog-security-labs-shai-hulud-framework-static-analysis/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/" target="_blank" rel="noopener noreferrer">Datadog Security Labs</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/verizon-dbir-2026-19th-annual-edition" data-tags="supply-chain data-breach" data-regions="global" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-11T05:00:30Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="verizon-dbir-2026-19th-annual-edition"><a href="https://ctipilot.ch/entries/2026-05-11/verizon-dbir-2026-19th-annual-edition/">Verizon DBIR 2026 (19th annual edition)</a></h3><p>Verizon&#39;s 19th DBIR is publicly accessible on the Verizon DBIR page; the full PDF release is bound to the 2026-05-19 webinar. Headline figures confirmed on the published page: <strong>third-party involvement in breaches doubled year-on-year to 30%</strong> (from ~15% in the 2025 edition); <strong>ransomware present in 44% of breaches</strong>; <strong>stolen credentials remain the single most common initial-access vector at 22%</strong>; <strong>vulnerability exploitation at 20%</strong> nearly ties credential theft; the human element (social engineering, phishing, error) remains implicated in 60%+ of breaches (<a href="https://www.verizon.com/business/resources/reports/dbir/" target="_blank" rel="noopener noreferrer">Verizon DBIR page</a>).</p>
<p>The defender synthesis for Swiss / EU public-sector consumers: the <strong>third-party-doubling finding is the headline data point of the year for DORA / NIS2 third-party-risk management programmes</strong> — the empirical jump from ~15% to 30% supply-chain involvement directly informs DORA Chapter V (ICT third-party risk management) and NIS2 Article 21(2)(d) supply-chain security obligations. Combined with the IGJ-NMDL ruling ( and the EU CRA Article 14 reporting milestone landing on 2026-09-11 (, the operational picture for 2026 is unambiguous: supply-chain and third-party scrutiny moves from policy talking-point to enforced obligation in the second half of the year. Update planned post-2026-05-19 webinar PDF release for the full breakdown.</p><div class="prov"><span>annual-report</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/verizon-dbir-2026-19th-annual-edition/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.verizon.com/business/resources/reports/dbir/" target="_blank" rel="noopener noreferrer">Verizon DBIR page</a></div></article><div class="sect" id="long-running-campaigns-status-update"><span class="n">07</span><span class="t">Long-running campaigns · status update</span><span class="c">6 items</span></div><article class="finding entry-card" data-entry-id="2026-05-11/seppmail-cve-2026-44128-circl-advisory-confirms-cvss-9-3-una" data-tags="vulnerabilities pre-auth rce patch-available" data-regions="europe switzerland" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:41Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-44128/">CVE-2026-44128</a></div><h3 class="f-h" id="seppmail-cve-2026-44128-circl-advisory-confirms-cvss-9-3-una"><a href="https://ctipilot.ch/entries/2026-05-11/seppmail-cve-2026-44128-circl-advisory-confirms-cvss-9-3-una/">SEPPmail CVE-2026-44128 — CIRCL advisory confirms CVSS 9.3 unauthenticated Perl-eval RCE; no third-party PoC in window</a></h3><p>W19&#39;s long-running concern about the single-source-national-CERT status of CVE-2026-44128 is materially <strong>improved this week</strong> by the CIRCL (Computer Incident Response Center Luxembourg) advisory at <code>vulnerability.circl.lu</code> confirming CVSS v4.0 9.3, CWE-95 eval injection in the GINA UI endpoint of SEPPmail Secure Email Gateway &lt; 15.0.2.1, with patch path to ≥ 15.0.2.1 (<a href="https://vulnerability.circl.lu/vuln/cve-2026-44128" target="_blank" rel="noopener noreferrer">CIRCL vulnerability.circl.lu</a>). The CIRCL advisory is also an EU national-CERT primary — the verification status moves from <code>SINGLE-SOURCE-NATIONAL-CERT</code> (NCSC-CH only) to <code>SINGLE-SOURCE-NATIONAL-CERT</code> (NCSC-CH + CIRCL — two separate national CERTs corroborating). Still no independent third-party PoC / root-cause analysis in window. For Swiss on-premises SEPPmail estates (cantonal administration and healthcare are the predominant deployments), patch validation against 15.0.2.1 remains a high-priority item.</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/seppmail-cve-2026-44128-circl-advisory-confirms-cvss-9-3-una/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://vulnerability.circl.lu/vuln/cve-2026-44128" target="_blank" rel="noopener noreferrer">CIRCL vulnerability.circl.lu</a> · <a href="https://security-hub.ncsc.admin.ch/api/posts/12551/details" target="_blank" rel="noopener noreferrer">NCSC.ch Security Hub #12551</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/canvas-instructure-shinyhunters-worldleaks-ransom-paid-us-ho" data-tags="ransomware data-breach organized-crime" data-regions="us europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:40Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="canvas-instructure-shinyhunters-worldleaks-ransom-paid-us-ho"><a href="https://ctipilot.ch/entries/2026-05-11/canvas-instructure-shinyhunters-worldleaks-ransom-paid-us-ho/">Canvas / Instructure — ShinyHunters / WorldLeaks ransom-paid, US House investigation</a></h3><p>Full coverage in § 2 (multi-day chain). Status-update register: ShinyHunters / WorldLeaks long-running operator pattern (W19 record <code>item:shinyhunters-worldleaks-family</code>) continues; the Canvas case is the operator&#39;s first publicly-confirmed ransom-with-broken-non-extortion-covenant precedent and the first US Congressional investigation of an EdTech SaaS supply-chain incident.</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/canvas-instructure-shinyhunters-worldleaks-ransom-paid-us-ho/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://therecord.media/instructure-pays-ransom-canvas-incident-congress-investigation" target="_blank" rel="noopener noreferrer">The Record</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/qilin-agenda-raas-april-2026-lead-at-15-of-global-ransomware" data-tags="ransomware organized-crime" data-regions="europe dach" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:39Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="qilin-agenda-raas-april-2026-lead-at-15-of-global-ransomware"><a href="https://ctipilot.ch/entries/2026-05-11/qilin-agenda-raas-april-2026-lead-at-15-of-global-ransomware/">Qilin / Agenda RaaS — April 2026 lead at 15% of global ransomware activity, Germany 5% of global victims</a></h3><p>W19 long-running record (<code>item:qilin-agenda-raas-die-linke-confirms-q2-2026-german-activity</code>) tracked Qilin&#39;s continued German activity. W20 status: Check Point&#39;s April 2026 report confirms Qilin leads all RaaS operators at 15% of 707 published attacks in April; Germany&#39;s share at 5% of global ransomware victims is the elevated-DACH-exposure data point (Qilin DLS German-victim count cited by W1 horizon research as approximately 65 as of 2026-05-16 — uncorroborated leak-site enumeration that should be treated as a lower bound); <strong>Die Linke (German political party) confirmed Qilin compromise in March 2026</strong> (W19 carry-over); no new Swiss-specific victim named in window (<a href="https://blog.checkpoint.com/research/cyber-threats-spike-in-april-2026-as-ransomware-expands-and-attack-volumes-climb-after-short-lived-moderation/" target="_blank" rel="noopener noreferrer">Check Point Research</a>).</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/qilin-agenda-raas-april-2026-lead-at-15-of-global-ransomware/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.checkpoint.com/research/cyber-threats-spike-in-april-2026-as-ransomware-expands-and-attack-volumes-climb-after-short-lived-moderation/" target="_blank" rel="noopener noreferrer">Check Point Research</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/frostyneighbor-ghostwriter-unc1151-eset-analysis-corroborate" data-tags="nation-state espionage russia-nexus" data-regions="europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:36Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="frostyneighbor-ghostwriter-unc1151-eset-analysis-corroborate"><a href="https://ctipilot.ch/entries/2026-05-11/frostyneighbor-ghostwriter-unc1151-eset-analysis-corroborate/">FrostyNeighbor / Ghostwriter (UNC1151) — ESET analysis corroborated, Poland / Lithuania / Ukraine in EU scope</a></h3><p>ESET&#39;s 2026-05-14 analysis of activity observed since March 2026 documents an evolved spearphishing chain: (1) malicious PDFs impersonating Ukrtelecom with embedded redirect links, (2) RAR archives delivering JavaScript PicassoLoader variants, (3) server-side victim <strong>geo-validation</strong> (serves benign PDF to non-Ukrainian IPs) with system fingerprinting every 10 minutes to determine Cobalt Strike eligibility, (4) persistence via scheduled tasks and registry modifications. The previous Polish-targeting wave exploited CVE-2024-42009 (Roundcube XSS) for credential harvesting; WinRAR CVE-2023-38831 also referenced in the toolchain. The Belarus-aligned actor cluster (UNC1151, UAC-0057, TA445, Storm-0257, Umbral Bison, White Lynx) targets governmental, industrial, healthcare, and logistics sectors. EU scope: <strong>Poland, Lithuania, and Ukraine</strong> confirmed; broader Eastern European public-sector exposure inferred (<a href="https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a>; <a href="https://thehackernews.com/2026/05/ghostwriter-targets-ukrainian.html" target="_blank" rel="noopener noreferrer">The Hacker News</a>; <a href="https://ctipilot.ch/briefs/2026-05-15/" target="_blank" rel="noopener noreferrer">daily 2026-05-15</a>).</p>
<p>No named EU victim disclosures this run. Status update from the W19 long-running record (<code>item:apt28-apt29-unc1151</code>): ESET&#39;s documentation of the geofencing and 10-minute fingerprinting cadence is new operational detail not present in the W19 ABW tri-attribution coverage. Detection: outbound connections to Canarytokens-style endpoints used for fingerprinting; scheduled-task creation with random GUIDs spawned from Office process trees (T1053.005); child processes of WinRAR or archive handlers executing JavaScript (T1059.007); PicassoLoader staging behaviours.</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/frostyneighbor-ghostwriter-unc1151-eset-analysis-corroborate/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/" target="_blank" rel="noopener noreferrer">ESET WeLiveSecurity</a> · <a href="https://thehackernews.com/2026/05/ghostwriter-targets-ukrainian.html" target="_blank" rel="noopener noreferrer">The Hacker News</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/the-gentlemen-raas-operations-continue-post-leak-decryptor-p" data-tags="ransomware organized-crime" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:38Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="the-gentlemen-raas-operations-continue-post-leak-decryptor-p"><a href="https://ctipilot.ch/entries/2026-05-11/the-gentlemen-raas-operations-continue-post-leak-decryptor-p/">&quot;The Gentlemen&quot; RaaS — operations continue post-leak, decryptor published, FortiOS / Erlang SSH initial access CVEs confirmed</a></h3><p>Following the 2026-05-04 Rocket backend DB leak (attributed to a breach of hosting provider 4VPS), administrator <code>zeta88</code> / <code>hastalamuerte</code> announced <strong>a full communications-infrastructure overhaul — new NAS deployment and new locker upgrades — signalling no intent to cease operations</strong>. The operation maintained ~332 victims in H1 2026, ranking second in global RaaS activity per Check Point Research. Check Point documented <strong>initial access via CVE-2024-55591</strong> (FortiOS management interface auth bypass, ITW since November 2024) <strong>and CVE-2025-32433</strong> (Erlang SSH in Cisco context); post-access chain includes RelayKing-based NTLM relay (CVE-2025-33073), AD enumeration, EDR disablement, and GPO-deployed locker (<a href="https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/" target="_blank" rel="noopener noreferrer">Check Point Research</a>; <a href="https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk" target="_blank" rel="noopener noreferrer">Check Point blog</a>; <a href="https://ctipilot.ch/briefs/2026-05-14/" target="_blank" rel="noopener noreferrer">daily 2026-05-14 UPDATE</a>).</p>
<p>Bedrock Safeguard (Canadian security firm) published a <strong>working decryptor on 2026-05-14</strong> exploiting Go&#39;s failure to zero XChaCha20 / X25519 ephemeral private-key material from goroutine stacks post-use; 35/35 files decrypted in testing. The operator claims to have patched the binary, so the decryptor capability is best-case retrospective; affiliates show no evidence of forking, and the core nine-person structure remains intact per leaked chats (<a href="https://github.com/Bedrock-Safeguard/gentlemen-decryptor" target="_blank" rel="noopener noreferrer">Bedrock Safeguard decryptor</a>). Defender takeaway: for any Gentlemen-impacted Go-binary host, attempt process-memory dump capture for ephemeral key recovery before reimaging; verify FortiOS patch state on CVE-2024-55591 across every Swiss / EU public-sector Fortinet deployment (the FortiOS bug is the documented initial-access primary, and the W19 long-running record already lists this CVE).</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/the-gentlemen-raas-operations-continue-post-leak-decryptor-p/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/" target="_blank" rel="noopener noreferrer">Check Point Research</a> · <a href="https://blog.checkpoint.com/research/when-the-ransomware-gang-gets-hacked-what-the-gentlemen-leak-reveals-about-modern-ransomware-risk" target="_blank" rel="noopener noreferrer">Check Point blog</a> · <a href="https://github.com/Bedrock-Safeguard/gentlemen-decryptor" target="_blank" rel="noopener noreferrer">Bedrock Safeguard decryptor</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/teampcp-mini-shai-hulud-shinyhunters-worldleaks-adjacent-wav" data-tags="supply-chain ai-abuse organized-crime" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-11T05:00:37Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="teampcp-mini-shai-hulud-shinyhunters-worldleaks-adjacent-wav"><a href="https://ctipilot.ch/entries/2026-05-11/teampcp-mini-shai-hulud-shinyhunters-worldleaks-adjacent-wav/">TeamPCP / Mini Shai-Hulud (ShinyHunters / WorldLeaks adjacent) — wave 4 + framework leak + IDE persistence</a></h3><p>Full coverage in § 2 (multi-day chain). Status-update register: long-running operator-family pattern continues; wave 4 (170+ packages / 400+ versions per daily-brief tracking) is the largest documented npm-supply-chain wave to date; the <strong>leaked framework source</strong> materially changes both attacker and defender posture and elevates the risk of secondary operators applying the same techniques against PyPI / Cargo / Maven Central in 2026-W21. The ShinyHunters / WorldLeaks family logged in W19&#39;s long-running record (<code>item:shinyhunters-worldleaks-family</code>) overlaps in operator targeting (AI-tooling SaaS, multi-tenant credential aggregation) with TeamPCP&#39;s npm-side ecosystem — the two clusters appear to be operating in parallel across the SaaS and registry attack surfaces with no public attribution merging them.</p><div class="prov"><span>synthesis</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/teampcp-mini-shai-hulud-shinyhunters-worldleaks-adjacent-wav/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/" target="_blank" rel="noopener noreferrer">Datadog Security Labs</a> · <a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised" target="_blank" rel="noopener noreferrer">Wiz Blog</a></div></article><div class="sect" id="policy-regulatory-horizon"><span class="n">08</span><span class="t">Policy &amp; regulatory horizon</span><span class="c">9 items</span></div><article class="finding entry-card" data-entry-id="2026-05-11/eu-digital-omnibus-political-agreement-ai-act-high-risk-anne" data-tags="ai-abuse eu-nexus" data-regions="europe" data-kind="policy" data-priority="high" data-discovered="2026-05-11T05:00:42Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="eu-digital-omnibus-political-agreement-ai-act-high-risk-anne"><a href="https://ctipilot.ch/entries/2026-05-11/eu-digital-omnibus-political-agreement-ai-act-high-risk-anne/">EU Digital Omnibus political agreement — AI Act high-risk Annex III compliance deadline extended to 2 December 2027</a></h3><p>On 7 May 2026 the EU Parliament and Council reached provisional political agreement under the Digital Omnibus package to amend the AI Act. The headline change for operators running high-risk AI systems (Article 6(2) + Annex III: biometrics, critical infrastructure, education, employment, law enforcement, border management) is that <strong>the compliance deadline shifts from 2 August 2026 to 2 December 2027</strong> — 16 months of additional runway. High-risk systems embedded in regulated products under Annex I (medical devices, machinery) receive even more time, to <strong>2 August 2028</strong>. The co-legislators acknowledged that harmonised technical standards and Commission guidance required for conformity assessments do not yet exist in final form (<a href="https://techpolicy.press/what-the-eu-ai-omnibus-deal-changes-for-the-ai-act-and-what-lies-ahead/" target="_blank" rel="noopener noreferrer">TechPolicy.Press</a>; <a href="https://www.lexology.com/library/detail.aspx?g=34c6a42f-af33-4189-a32c-dc2e3d7a109f" target="_blank" rel="noopener noreferrer">Lexology / Stephenson Harwood</a>).</p>
<p>For AI security teams the <strong>cybersecurity obligations under Articles 8–15 (adversarial-robustness including prompt injection, data poisoning, model extraction; mandatory logging; CE marking; EU database registration) still apply</strong> from the revised 2 December 2027 deadline for Annex III systems. Separately, the deal adds a <strong>new prohibited practice covering AI systems generating non-consensual sexual content (including CSAM)</strong>, effective 2 December 2026, and clarifies AI Office competence boundaries versus national authorities for GPAI models. Formal adoption is expected before the original 2 August 2026 deadline lapses. Swiss and EU public-sector entities deploying AI for recruitment, benefits decisions, risk scoring, or law-enforcement analytics should update compliance roadmaps but should not interpret the extension as relief from the underlying obligations.</p><div class="prov"><span>policy</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/eu-digital-omnibus-political-agreement-ai-act-high-risk-anne/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://techpolicy.press/what-the-eu-ai-omnibus-deal-changes-for-the-ai-act-and-what-lies-ahead/" target="_blank" rel="noopener noreferrer">TechPolicy.Press</a> · <a href="https://www.lexology.com/library/detail.aspx?g=34c6a42f-af33-4189-a32c-dc2e3d7a109f" target="_blank" rel="noopener noreferrer">Lexology / Stephenson Harwood</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/nis2-transposition-status-update-no-court-of-justice-referra" data-tags="vulnerabilities eu-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-11T05:00:50Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="nis2-transposition-status-update-no-court-of-justice-referra"><a href="https://ctipilot.ch/entries/2026-05-11/nis2-transposition-status-update-no-court-of-justice-referra/">NIS2 transposition — status update; no Court of Justice referral announced this week</a></h3><p>The European Commission sent reasoned opinions to 19 member states in May 2025 (per the EC NIS transposition page, last updated July 2025) with a two-month response window; non-compliant states face Court of Justice referral. The May-2025 reasoned opinions are now one year old without public Court of Justice referral announcements, indicating most have either completed transposition or are in active dialogue with the Commission. Polish NIS2 transposition (in force 3 April 2026, W19 item) is among the most recent completions. No Court of Justice referral was announced this week. The W19 ABW NIS2 essential-entity extension proposal has not gained additional public momentum this run (<a href="https://digital-strategy.ec.europa.eu/en/policies/nis-transposition" target="_blank" rel="noopener noreferrer">EC NIS transposition page</a>).</p><div class="prov"><span>policy</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/nis2-transposition-status-update-no-court-of-justice-referra/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://digital-strategy.ec.europa.eu/en/policies/nis-transposition" target="_blank" rel="noopener noreferrer">EC NIS transposition page</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/bka-dream-market-lead-administrator-speedstepper-arrested-in" data-tags="law-enforcement organized-crime cryptocrime" data-regions="europe dach" data-kind="policy" data-priority="notable" data-discovered="2026-05-11T05:00:49Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="bka-dream-market-lead-administrator-speedstepper-arrested-in"><a href="https://ctipilot.ch/entries/2026-05-11/bka-dream-market-lead-administrator-speedstepper-arrested-in/">BKA — Dream Market lead administrator &quot;Speedstepper&quot; arrested in Germany</a></h3><p>Adds to the BKA Crimenetwork takedown (covered daily 2026-05-12 as a separate W20 LE action). Two consecutive German federal LE actions against darknet-administrator-tier operators within the same week — a notable tempo signal for the EU cybercrime LE ecosystem. The OPSEC failure (cryptocurrency-to-physical-gold conversion patterns over seven years) is forensically interesting but the policy-horizon implication is that BKA&#39;s investigative throughput on darknet-administrator pursuits is materially elevated through Q2 2026 (<a href="https://ctipilot.ch/briefs/2026-05-16/" target="_blank" rel="noopener noreferrer">daily 2026-05-16</a>).</p><div class="prov"><span>policy</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/bka-dream-market-lead-administrator-speedstepper-arrested-in/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bka.de/DE/Presse/Listenseite_Pressemitteilungen/2026/Presse2026/260516_DreamMarket.html" target="_blank" rel="noopener noreferrer">BKA press release</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/enisa-cve-numbering-authority-root-4-new-cnas-onboarded-iden" data-tags="vulnerabilities eu-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-11T05:00:47Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="enisa-cve-numbering-authority-root-4-new-cnas-onboarded-iden"><a href="https://ctipilot.ch/entries/2026-05-11/enisa-cve-numbering-authority-root-4-new-cnas-onboarded-iden/">ENISA CVE Numbering Authority Root — 4 new CNAs onboarded, identities undisclosed; 7 existing CNAs migrated from MITRE Root</a></h3><p>ENISA&#39;s 2026-05-06 announcement (W19 forward-looking item) is now confirmed: <strong>four organisations</strong> have newly joined the CVE Program as CNAs under ENISA Root, and <strong>seven existing European CNAs</strong> have transferred from MITRE Root to ENISA Root. ENISA&#39;s announcement does not name the four new CNAs. ENISA became CVE Root for European entities in November 2025; over 90 European CNAs can voluntarily transfer. ENISA&#39;s CVE Root scope covers entities within its mandate including vulnerabilities discovered by or reported to EU CSIRTs. Strengthens European vulnerability-disclosure capacity under NIS2 Article 12 (coordinated vulnerability disclosure) obligations. The undisclosed CNA identities are a transparency gap worth surfacing — defenders cannot pattern-match which EU vendors / institutions have CNA capacity until ENISA publishes the list (<a href="https://www.enisa.europa.eu/news/new-cve-numbering-authorities-under-enisa-root" target="_blank" rel="noopener noreferrer">ENISA news</a>).</p><div class="prov"><span>policy</span><span>11 May 05:00Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/enisa-cve-numbering-authority-root-4-new-cnas-onboarded-iden/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.enisa.europa.eu/news/new-cve-numbering-authorities-under-enisa-root" target="_blank" rel="noopener noreferrer">ENISA news</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/kritis-dachg-german-registration-deadline-17-july-2026-is-no" data-tags="ot-ics eu-nexus" data-regions="europe dach" data-kind="policy" data-priority="notable" data-discovered="2026-05-11T05:00:46Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="kritis-dachg-german-registration-deadline-17-july-2026-is-no"><a href="https://ctipilot.ch/entries/2026-05-11/kritis-dachg-german-registration-deadline-17-july-2026-is-no/">KRITIS-DachG — German registration deadline 17 July 2026 is now 61 days out</a></h3><p>The KRITIS-DachG (Kritis-Dachgesetz, Germany&#39;s critical-infrastructure umbrella act) entered into force; the initial registration deadline of <strong>17 July 2026 is now 61 days away</strong>. Operators of critical facilities in scope — including public-administration entities operating infrastructure in the sectors of energy, transport, finance, IT/telecommunications, space-ground infrastructure, and public administration — must register with the Federal Office of Civil Protection and Disaster Assistance (BBK) via an electronic platform jointly operated with the BSI. Registration requires operator name, legal form, commercial register number, address including public IP ranges, sector / industry classification, and critical-facility contact details. Violations constitute an administrative offence punishable by fines <strong>up to EUR 500,000</strong>. Public-sector IT departments in Germany should verify whether their IT and OT infrastructure qualifies as a &quot;critical facility&quot; under the KRITIS-DachG sector thresholds, register before 17 July 2026 or within three months of later qualification, and identify which services they must report under the act&#39;s disruption-reporting obligations to BBK / BSI (24-hour initial notification, 72-hour detailed report). Swiss federal entities with German subsidiaries or cross-border infrastructure should verify German subsidiary obligations (<a href="https://www.luther-lawfirm.com/en/newsroom/blog/detail/kritis-dachgesetz-in-kraft-neue-pflichten-hohe-bussgelder-und-viele-offene-fragen-fuer-betreiber-kritischer-anlagen" target="_blank" rel="noopener noreferrer">Luther Lawfirm</a>; <a href="https://www.aoshearman.com/en/insights/critical-infrastructure-new-legislation-in-germany-and-its-practical-impact" target="_blank" rel="noopener noreferrer">A&amp;O Shearman</a>).</p><div class="prov"><span>policy</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/kritis-dachg-german-registration-deadline-17-july-2026-is-no/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.luther-lawfirm.com/en/newsroom/blog/detail/kritis-dachgesetz-in-kraft-neue-pflichten-hohe-bussgelder-und-viele-offene-fragen-fuer-betreiber-kritischer-anlagen" target="_blank" rel="noopener noreferrer">Luther Lawfirm</a> · <a href="https://www.aoshearman.com/en/insights/critical-infrastructure-new-legislation-in-germany-and-its-practical-impact" target="_blank" rel="noopener noreferrer">A&amp;O Shearman</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/edpb-coordinated-enforcement-framework-2026-25-dpas-investig" data-tags="data-breach eu-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-11T05:00:45Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="edpb-coordinated-enforcement-framework-2026-25-dpas-investig"><a href="https://ctipilot.ch/entries/2026-05-11/edpb-coordinated-enforcement-framework-2026-25-dpas-investig/">EDPB Coordinated Enforcement Framework 2026 — 25 DPAs investigating GDPR Articles 12–14 transparency</a></h3><p>Twenty-five data-protection authorities across the EEA simultaneously launched investigations examining compliance with GDPR Articles 12–14 (transparency and information obligations) as <strong>CEF 2026</strong>. Investigations focus on how organisations communicate data-collection, use, and sharing practices to data subjects — including the specificity required on third-country transfers, retention periods, and automated decision-making. Swiss public-sector entities operating under the revised Data Protection Act (revDSG, in force September 2023) face parallel expectations since Swiss DPA enforcement also focuses on transparency obligations. Enforcement decisions from CEF 2026 are expected in the second half of 2026 and could establish EU-wide precedent on the required granularity of privacy notices — particularly regarding identification of individual third countries for data transfers and naming of each algorithmic profiling system where Article 13(2)(f) automated-decision disclosure applies (<a href="https://www.edpb.europa.eu/news/news/2026/cef-2026-edpb-launches-coordinated-enforcement-action-transparency-and-information_en" target="_blank" rel="noopener noreferrer">EDPB news</a>; <a href="https://compliancehub.wiki/edpb-2026-coordinated-enforcement-transparency-gdpr/" target="_blank" rel="noopener noreferrer">ComplianceHub.Wiki analysis</a>).</p>
<p>W19 status-update: the CEF 2026 launch was previewed in the W19 weekly; this W20 update reflects the operational live-investigation status across the 25 DPAs and adds the H2-2026 decision-timeline expectation.</p><div class="prov"><span>policy</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/edpb-coordinated-enforcement-framework-2026-25-dpas-investig/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.edpb.europa.eu/news/news/2026/cef-2026-edpb-launches-coordinated-enforcement-action-transparency-and-information_en" target="_blank" rel="noopener noreferrer">EDPB news</a> · <a href="https://compliancehub.wiki/edpb-2026-coordinated-enforcement-transparency-gdpr/" target="_blank" rel="noopener noreferrer">ComplianceHub.Wiki</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/dora-first-oversight-cycle-19-designated-ctpps-under-joint-e" data-tags="supply-chain eu-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-11T05:00:44Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="dora-first-oversight-cycle-19-designated-ctpps-under-joint-e"><a href="https://ctipilot.ch/entries/2026-05-11/dora-first-oversight-cycle-19-designated-ctpps-under-joint-e/">DORA first oversight cycle — 19 designated CTPPs under Joint Examination Team activity</a></h3><p>The ESAs (EBA, EIOPA, ESMA) designated 19 critical ICT third-party providers (CTPPs) in November 2025; the first complete DORA oversight cycle is underway in 2026. Joint Examination Teams (JETs) established in Q1 2026 are conducting initial examination activities that may result in recommendations and follow-ups. Financial-sector entities using the 19 designated CTPPs are now subject to enhanced regulatory scrutiny of contractual ICT arrangements, subcontracting chains, and incident-reporting flows under DORA Articles 26–44. The designated CTPPs are themselves subject to direct ESA oversight including required cooperation with JET examinations and expected to demonstrate ICT risk-management governance, resilience testing (TLPT for critical-function systems), and supply-chain transparency. <strong>Swiss financial institutions</strong> supervised by FINMA that use EU-designated CTPPs should confirm their contractual arrangements comply with DORA Chapter V (ICT third-party risk management) as enforced via EU subsidiaries (<a href="https://www.esma.europa.eu/press-news/esma-news/european-supervisory-authorities-designate-critical-ict-third-party-providers" target="_blank" rel="noopener noreferrer">ESMA press release</a>; <a href="https://legal.pwc.de/en/news/articles/esas-publish-first-list-of-critical-ict-third-party-providers-under-dora" target="_blank" rel="noopener noreferrer">PwC Legal</a>).</p><div class="prov"><span>policy</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/dora-first-oversight-cycle-19-designated-ctpps-under-joint-e/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.esma.europa.eu/press-news/esma-news/european-supervisory-authorities-designate-critical-ict-third-party-providers" target="_blank" rel="noopener noreferrer">ESMA press release</a> · <a href="https://legal.pwc.de/en/news/articles/esas-publish-first-list-of-critical-ict-third-party-providers-under-dora" target="_blank" rel="noopener noreferrer">PwC Legal</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/eu-cra-milestones-11-june-2026-cab-notification-11-september" data-tags="vulnerabilities eu-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-11T05:00:43Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eu-cra-milestones-11-june-2026-cab-notification-11-september"><a href="https://ctipilot.ch/entries/2026-05-11/eu-cra-milestones-11-june-2026-cab-notification-11-september/">EU CRA milestones — 11 June 2026 CAB notification, 11 September 2026 Article 14 reporting obligations</a></h3><p>Two CRA enforcement milestones fall within the next 120 days. <strong>Chapter IV provisions on notification of Conformity Assessment Bodies (CABs) become applicable on 11 June 2026</strong> — manufacturers seeking CRA conformity certification for critical digital products will be able to use designated CABs from that date, and Member States must have designated notifying authorities by then. <strong>Article 14 reporting obligations</strong> (manufacturers reporting actively-exploited vulnerabilities and severe security incidents to national CSIRTs within 24 hours, with a 72-hour notification for the incident report) <strong>apply from 11 September 2026</strong>. First standardisation deliverables (horizontal and product-specific standards) are expected Q3 2026. The Q4 2026 delegated act on EUCC presumption of conformity with CRA requirements is pending. Full application of CRA is 11 December 2027 (<a href="https://digital-strategy.ec.europa.eu/en/factpages/cyber-resilience-act-implementation" target="_blank" rel="noopener noreferrer">EC CRA implementation factpage</a>).</p>
<p>Per W2 horizon research, <strong>Delegated Regulation (EU) 2026/881</strong> on delayed dissemination of sensitive notifications was published in April 2026 and specifies the circumstances under which a CSIRT may delay public disclosure of a vulnerability notification on cybersecurity grounds — the underlying delegated act is referenced from the EC implementation factpage above but not separately re-fetched in this run; defenders relying on the exact text should consult the EUR-Lex publication. Swiss product manufacturers supplying EU markets and operators of digital infrastructure procuring connected products need to verify their supply chain for CRA-scope products before September 2026; Swiss public-sector procurement frameworks should explicitly verify CRA-conformity attestation for connected products at acquisition.</p><div class="prov"><span>policy</span><span>11 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/eu-cra-milestones-11-june-2026-cab-notification-11-september/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://digital-strategy.ec.europa.eu/en/factpages/cyber-resilience-act-implementation" target="_blank" rel="noopener noreferrer">EC CRA implementation factpage</a></div></article><article class="finding entry-card" data-entry-id="2026-05-11/cisa-emergency-directive-ed-26-03-cisco-catalyst-sd-wan" data-tags="vulnerabilities actively-exploited us-nexus" data-regions="us global" data-kind="policy" data-priority="notable" data-discovered="2026-05-11T05:00:48Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span></div><h3 class="f-h" id="cisa-emergency-directive-ed-26-03-cisco-catalyst-sd-wan"><a href="https://ctipilot.ch/entries/2026-05-11/cisa-emergency-directive-ed-26-03-cisco-catalyst-sd-wan/">CISA Emergency Directive ED-26-03 — Cisco Catalyst SD-WAN</a></h3><p>Issued 2026-05-15 mandating identification, mitigation, and reporting on CVE-2026-20182 for US federal civilian agencies with a 2026-05-17 (today) deadline. For Swiss / EU public-sector defenders the <strong>US-FCEB compliance date itself is not operational signal</strong> (per the inherited PD-13) but the issuance of an Emergency Directive is. Use the ED&#39;s mitigation matrix as a reference for your own SD-WAN response posture (<a href="https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems" target="_blank" rel="noopener noreferrer">CISA ED-26-03</a>; <a href="https://ctipilot.ch/briefs/2026-05-15/" target="_blank" rel="noopener noreferrer">Daily 2026-05-15</a>).</p><div class="prov"><span>policy</span><span>11 May 05:00Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/cisa-emergency-directive-ed-26-03-cisco-catalyst-sd-wan/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/directives/ed-26-03-mitigate-vulnerabilities-cisco-sd-wan-systems" target="_blank" rel="noopener noreferrer">CISA ED-26-03</a></div></article><div class="sect" id="looking-ahead-what-to-watch-next-week"><span class="n">09</span><span class="t">Looking ahead · what to watch next week</span><span class="c">1 item</span></div><article class="finding entry-card" data-entry-id="2026-05-11/looking-ahead-2026-w20" data-tags="supply-chain" data-regions="global" data-kind="outlook" data-priority="notable" data-discovered="2026-05-11T05:00:51Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="looking-ahead-2026-w20"><a href="https://ctipilot.ch/entries/2026-05-11/looking-ahead-2026-w20/">Looking ahead — 2026-W20</a></h3><p>Items already in motion at the close of 2026-W20. Not predictions — each links to the in-motion reporting underneath.</p>
<ul><li><strong>Microsoft Exchange CVE-2026-42897 — Microsoft permanent patch and out-of-band advisory on DEVCORE Pwn2Own three-bug chain pending.</strong> Active OWA-XSS exploitation continues; the federal-civilian KEV deadline is 2026-05-29 (US-FCEB compliance date, not operational signal for CH/EU); the operationally critical milestone is Microsoft shipping a permanent patch and clarifying whether the DEVCORE chain is being weaponised against the same OWA initial-access vector. (<a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897" target="_blank" rel="noopener noreferrer">Microsoft Security Blog</a>; <a href="https://ctipilot.ch/briefs/2026-05-16/" target="_blank" rel="noopener noreferrer">daily 2026-05-16</a>)</li><li><strong>PAN-OS CVE-2026-0300 wave-2 patches landing 2026-05-28.</strong> Eight build streams (12.1.7, 11.2.4-h17, 11.2.12, 11.1.7-h6, 11.1.15, 10.2.7-h34, 10.2.13-h21, 10.2.16-h7) finish the staged patch arc; verify deployment readiness in advance and audit for <code>svc-health-check-NNNNNN</code> rogue-admin accounts before patching wipes implant artefacts. (<a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto PSIRT CVE-2026-0300</a>; <a href="https://ctipilot.ch/briefs/2026-05-14/" target="_blank" rel="noopener noreferrer">daily 2026-05-14 UPDATE</a>)</li><li><strong>US House Homeland Security Committee CEO briefing deadline 2026-05-21 (Canvas / Instructure).</strong> Chairman Garbarino&#39;s letter requested an Instructure CEO briefing by 2026-05-21 addressing both intrusion circumstances, scope and nature of accessed data, IR adequacy, and CISA coordination. Outcome will inform the regulatory template for cantonal-Bildungsdirektion oversight of EdTech-SaaS vendors. (<a href="https://homeland.house.gov/2026/05/11/chairman-garbarino-seeks-information-from-canvas-developer-after-cyberattacks-impact-schools-and-universities-nationwide/" target="_blank" rel="noopener noreferrer">House Homeland Security Committee</a>; <a href="https://ctipilot.ch/briefs/2026-05-13/" target="_blank" rel="noopener noreferrer">daily 2026-05-13 UPDATE</a>)</li><li><strong>Verizon DBIR 2026 full PDF release — webinar 2026-05-19 11:00 ET.</strong> The page-level summary already in this weekly&#39;s § 6 will gain the full statistical breakdown after the webinar; the supply-chain doubling finding (15% → 30%) deserves a re-read against the full data to confirm methodology. (<a href="https://www.verizon.com/business/resources/reports/dbir/" target="_blank" rel="noopener noreferrer">Verizon DBIR page</a>)</li><li><strong>TeamPCP / Mini Shai-Hulud wave 5 risk on PyPI / Cargo / Maven Central.</strong> The leaked framework source elevates the risk of secondary operators applying the same techniques against other registries. Detection-engineering teams should pre-stage hunts for IDE-hook entries (<code>.claude/settings.json</code>, <code>.vscode/tasks.json</code>) and Sigstore-provenance anomaly detection. (<a href="https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/" target="_blank" rel="noopener noreferrer">Datadog Security Labs</a>)</li><li><strong>CRA milestone 11 June 2026 — CAB notification provisions become applicable.</strong> Member-state notifying-authority designations must be in place by then. Swiss product manufacturers selling into EU markets should track which CABs are designated in their target member states. (<a href="https://digital-strategy.ec.europa.eu/en/factpages/cyber-resilience-act-implementation" target="_blank" rel="noopener noreferrer">EC CRA implementation factpage</a>)</li><li><strong>KRITIS-DachG German registration deadline 2026-07-17 (61 days).</strong> German public-administration operators of critical facilities must register with BBK / BSI; failures up to EUR 500,000 fine. Cross-border CH-DE operators should verify subsidiary obligations. (<a href="https://www.luther-lawfirm.com/en/newsroom/blog/detail/kritis-dachgesetz-in-kraft-neue-pflichten-hohe-bussgelder-und-viele-offene-fragen-fuer-betreiber-kritischer-anlagen" target="_blank" rel="noopener noreferrer">Luther Lawfirm</a>)</li><li><strong>Dirty Frag CVE-2026-43500 (RxRPC) — remaining distro patch propagation.</strong> AlmaLinux 8 not affected; RHEL 9 errata rolling; lagging configurations are systems with <code>kernel-modules-partner</code> installed (AFS-using estates). Track distro-vendor security-advisory updates through 2026-W21. (<a href="https://almalinux.org/blog/2026-05-07-dirty-frag/" target="_blank" rel="noopener noreferrer">AlmaLinux blog</a>)</li><li><strong>&quot;The Gentlemen&quot; RaaS — comms overhaul means continued activity expected; affiliate response to decryptor publication.</strong> Administrator zeta88&#39;s announced communications-infrastructure overhaul rather than shutdown means operations continue; affiliate response to Bedrock Safeguard&#39;s decryptor and any binary-side patches the operator deploys are the open watch items. (<a href="https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/" target="_blank" rel="noopener noreferrer">Check Point Research</a>)</li><li><strong>MOVEit Automation CVE-2026-4670 — still no ITW confirmed at week-end.</strong> Patches available 2025.1.5 / 2025.0.9 / 2024.1.8; 1,400+ internet-exposed instances catalogued. The W19 horizon item remains open; watch for KEV addition or first-victim disclosure. (<a href="https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/" target="_blank" rel="noopener noreferrer">Help Net Security</a>; <a href="https://ctipilot.ch/briefs/2026-05-06/" target="_blank" rel="noopener noreferrer">daily 2026-05-06</a>)</li><li><strong>GTIG UNC6671 &quot;BlackFile&quot; DLS-shutdown signal — probable rebrand.</strong> GTIG&#39;s documentation of the DLS shutdown points to a probable operator rebrand; watch for a new leak-site / new operator-handle reusing the vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration TTP set. (<a href="https://ctipilot.ch/briefs/2026-05-16/" target="_blank" rel="noopener noreferrer">daily 2026-05-16</a>)</li><li><strong>Windows BitLocker YellowKey and CTFMON GreenPlasma — Microsoft permanent patch and / or out-of-band advisory pending.</strong> Public PoC continues; the May 2026 Patch Tuesday did not address either; out-of-band release is the operationally expected path. Until a patch lands the BitLocker-PIN GPO enforcement and privileged-account-segregation discipline remain the only available controls. (<a href="https://ctipilot.ch/briefs/2026-05-15/" target="_blank" rel="noopener noreferrer">daily 2026-05-15</a>)</li><li><strong>SEPPmail CVE-2026-44128 — independent third-party PoC or root-cause write-up.</strong> Two national CERTs (NCSC-CH + CIRCL) now corroborate; the open item is whether a research-lab write-up surfaces that would lift the verification status from <code>SINGLE-SOURCE-NATIONAL-CERT</code> to <code>MULTI-SOURCE</code>. (<a href="https://vulnerability.circl.lu/vuln/cve-2026-44128" target="_blank" rel="noopener noreferrer">CIRCL vulnerability.circl.lu</a>)</li></ul><div class="prov"><span>outlook</span><span>11 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-11/looking-ahead-2026-w20/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897" target="_blank" rel="noopener noreferrer">Microsoft Security Blog</a> · <a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto PSIRT CVE-2026-0300</a> · <a href="https://homeland.house.gov/2026/05/11/chairman-garbarino-seeks-information-from-canvas-developer-after-cyberattacks-impact-schools-and-universities-nationwide/" target="_blank" rel="noopener noreferrer">House Homeland Security Committee</a> · <a href="https://www.verizon.com/business/resources/reports/dbir/" target="_blank" rel="noopener noreferrer">Verizon DBIR page</a> · <a href="https://securitylabs.datadoghq.com/articles/shai-hulud-open-source-framework-static-analysis/" target="_blank" rel="noopener noreferrer">Datadog Security Labs</a> · <a href="https://digital-strategy.ec.europa.eu/en/factpages/cyber-resilience-act-implementation" target="_blank" rel="noopener noreferrer">EC CRA implementation factpage</a> · <a href="https://www.luther-lawfirm.com/en/newsroom/blog/detail/kritis-dachgesetz-in-kraft-neue-pflichten-hohe-bussgelder-und-viele-offene-fragen-fuer-betreiber-kritischer-anlagen" target="_blank" rel="noopener noreferrer">Luther Lawfirm</a> · <a href="https://almalinux.org/blog/2026-05-07-dirty-frag/" target="_blank" rel="noopener noreferrer">AlmaLinux blog</a> · <a href="https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/" target="_blank" rel="noopener noreferrer">Check Point Research</a> · <a href="https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/" target="_blank" rel="noopener noreferrer">Help Net Security</a> · <a href="https://vulnerability.circl.lu/vuln/cve-2026-44128" target="_blank" rel="noopener noreferrer">CIRCL vulnerability.circl.lu</a></div></article><details class="verif"><summary class="vh">About this weekly<span class="verif-count">1 run</span><svg class="verif-chev" viewBox="0 0 24 24" width="12" height="12" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" aria-hidden="true"><path d="M6 9l6 6 6-6"></path></svg></summary><div class="verif-body"><div class="run-note" data-run-id="2026-W20-71c96b25"><h3 class="run-note__head"><span class="mono">2026-W20-71c96b25</span> <span class="muted">· weekly · Claude Opus 4.7 · 52 entries published</span></h3><div class="run-note__body"><p><strong>Coverage window: 2026-05-10 → 2026-05-17 (8 days, one calendar day overlap with the 2026-W19 weekly&#39;s coverage end on 2026-05-10).</strong> Previous weekly: <code>briefs/weekly/2026-W19.md</code>. <code>gap_days = 7</code>, <code>window_days = max(7, gap_days + 1) = 8</code>. Eight daily briefs were read in window (2026-05-10 through 2026-05-17). Standard week — no disclosure required, noted here for transparency.</p>
<p><strong>Items still flagged <code>[SINGLE-SOURCE]</code>-equivalent in this run:</strong></p>
<ul><li><strong>GTIG UNC6671 &quot;BlackFile&quot; vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration</strong> — single source GTIG (daily 2026-05-16). Included given the operationally distinctive TTP set and the DLS-shutdown / probable-rebrand signal; treated with standard single-source caution.</li><li><strong>Unit 42 Gremlin Stealer evolved with .NET-resource XOR obfuscation, real-time crypto-clipper, WebSocket browser-process session-hijack</strong> — single source Unit 42 (daily 2026-05-16). Defender takeaway focuses on the WebSocket browser-process session-hijack class, which is more broadly attributable than the specific stealer.</li><li><strong>SentinelOne Living Off the Pipeline CI/CD subversion taxonomy</strong> — single source SentinelOne (daily 2026-05-16). Included as a synthesis reference rather than a campaign attribution; the three-case taxonomy is corroborated indirectly by the W20 Mini Shai-Hulud chain (§ 2).</li><li><strong>Sophos 2026 State of Identity Security — Switzerland highest identity-breach incidence finding</strong> — single source Sophos survey (daily 2026-05-15). The 17-country survey methodology is documented; Switzerland&#39;s specific ranking is a single-survey output and should not be over-weighted relative to longitudinal data.</li><li><strong>CVE-2026-45793 PHP Composer GitHub Actions CI token disclosure</strong> — single source (daily 2026-05-15). Patched in Composer 2.8.10; the disclosure mechanism (error-message leakage) is technically corroborated by the Composer GHSA but the broader exploitation context is single-source.</li><li><strong>West Pharmaceutical Services SEC 8-K</strong> — single source SEC filing (daily 2026-05-12). Standard victim-disclosure verification status; awaiting independent breach analysis.</li><li><strong>PAN-OS CVE-2026-0300 wave-2 schedule</strong> — Palo Alto PSIRT advisory is the only source. National-CERT carve-out applies; CERT-EU and other corroborating advisories typically lag the vendor PSIRT by 24–48 hours.</li><li><strong>Verizon DBIR 2026 headline figures</strong> — single source Verizon DBIR page; full PDF release pending 2026-05-19 webinar. Figures may shift on full-PDF reading.</li><li><strong>SEPPmail CVE-2026-44128</strong> — two national CERTs (NCSC-CH + CIRCL) corroborate; status improved from W19 but remains <code>SINGLE-SOURCE-NATIONAL-CERT</code> because no independent third-party PoC / root-cause analysis surfaced this week.</li><li><strong>Kaspersky GReAT — Kimsuky Rust-based HelloDoor + TryCloudflare-tunnel C2</strong> — single source Kaspersky (daily 2026-05-17). Standard single-source-OTHER caution.</li><li><strong>§ 6 vendor-research items operating as single-source-equivalent for the weekly:</strong> Verizon DBIR 2026 page-summary (Verizon only — full PDF pending 2026-05-19 webinar); Check Point Research April 2026 ransomware analysis (Check Point only — vendor monthly threat report); GTIG AI Threat Tracker May 2026 (Google Cloud only — vendor threat-intel report); Datadog Security Labs Shai-Hulud framework analysis (Datadog only — vendor research). Per the daily prompt&#39;s annual-report carve-out, vendor-research roll-ups stand as primary sources; flagged here so the single-source posture is explicit on the page.</li><li><strong>§ 3 CVE-2026-46300 (Fragnesia)</strong> — single primary source Wiz Research (Linux kernel security advisory). The Wiz post is the canonical research write-up; flagged here so the single-source posture is explicit.</li></ul>
<p><strong>Items dropped from this week&#39;s roll-up that may resurface:</strong></p>
<ul><li><strong>TrickMo &quot;TrickMo C&quot; Android banking trojan — TON-blockchain C2</strong> (daily 2026-05-13) — dropped under W-PD-1: Android banking-trojan content is off-audience for a Swiss / EU public-sector SOC weekly. If a Swiss / EU public-sector entity discloses an incident traced to TrickMo C, resurfaces.</li><li><strong>NCSC-UK &quot;10 questions to ask when using AI models to find vulnerabilities&quot;</strong> (daily 2026-05-13) — covered briefly in the daily; the NCSC-UK guidance is policy-advisory rather than operationally novel. The W19 weekly already absorbed the CERT-FR CERTFR-2026-ACT-016 agentic-AI advisory and the parallel NCSC.ch BACS assessment; the NCSC-UK piece adds questions but no new defender-action items.</li><li><strong>Microsoft MDASH multi-model agentic vulnerability discovery</strong> (daily 2026-05-13 research) — dropped under W-PD-1: this is interesting research-platform reporting but does not currently change defender obligations or surface a new operator pattern.</li><li><strong>GemStuffer — RubyGems weaponised as a one-way exfiltration channel</strong> (daily 2026-05-14 research) — held under reduced weight; the abuse pattern is novel but limited to UK local-authority ModernGov portals at this stage; if cross-EU GemStuffer expansion is documented in 2026-W21, resurfaces.</li><li><strong>CVE-2026-41940 FunnelKit (2026-05-17 § 1)</strong> — daily covered as &quot;FunnelKit Funnel Builder for WooCommerce actively exploited as Magecart skimmer on 40,000+ WordPress stores — no CVE assigned&quot;; included in § 4 sector pattern rather than § 1 to avoid leading with a non-CVE&#39;d WooCommerce-plugin item against the inaction-=-incident bar of the strongest § 1 placements.</li></ul>
<p><strong>Contradictions / ambiguities flagged for the verifier&#39;s attention:</strong></p>
<ul><li><strong>Microsoft Exchange CVE-2026-42897 vs. DEVCORE Pwn2Own three-bug chain.</strong> The two findings are distinct vulnerability classes; Microsoft has not formally linked them at week-end. The weekly treats them as adjacent threats with potential composite-exploitation risk but explicitly does not claim a chained ITW exploitation has been observed. Verifier: confirm the framing is consistent across §§ 0, 1, 2, 3.</li><li><strong>CISA ED-26-03 deadline 2026-05-17 vs. KEV deadline alignment.</strong> ED-26-03 mandates US-FCEB action by 2026-05-17; the underlying KEV addition has a 2026-05-29 deadline for the CVE-2026-42897 Exchange flaw and 2026-05-17 for CVE-2026-20182. The two timelines are distinct: ED-26-03 is Cisco SD-WAN-specific.</li><li><strong>The Gentlemen RaaS — Bedrock Safeguard decryptor scope.</strong> Bedrock Safeguard&#39;s testing documented 35/35 files decrypted with their PoC; the operator has claimed to patch the binary, so the decryptor&#39;s continued effectiveness is bounded to pre-patch encrypted material. The weekly frames the decryptor as &quot;best-case retrospective&quot; capability accordingly.</li><li><strong>CVE-2026-43500 (Dirty Frag RxRPC) patch status.</strong> AlmaLinux 8 is documented as not affected (rxrpc module not built); other distros are propagating. Defenders should not generalise the AlmaLinux-8 not-affected status to other RHEL-derivatives.</li></ul>
<p><strong>Items included with reduced confidence:</strong></p>
<ul><li><strong>Verizon DBIR 2026 figures (page-summary level).</strong> Full PDF release pending; figures cited are from the public page summary and may be revised on full-PDF reading after the 2026-05-19 webinar.</li><li><strong>TeamPCP Mini Shai-Hulud wave-4 package count (qualified as &quot;170+ packages / 400+ versions&quot; per daily-brief tracking).</strong> The qualified figure derives from daily-brief tracking of the 2026-05-13 wave; the Wiz Blog and Datadog Security Labs writeups list named packages without an aggregate count, so exact totals are contingent on registry-side observations that may shift as additional malicious versions are identified.</li><li><strong>Qilin DLS 65 German victims total.</strong> Number is current as of 2026-05-16 per W1 horizon research; leak-site counts are operator-controlled data and should be treated as a lower bound.</li></ul>
<p><strong>Sub-agent telemetry (Phase 2):</strong></p>
<ul><li><strong>W1</strong> (Long-horizon ongoing developments + annual / periodic reports) — returned: Claude Sonnet 4.6 (<code>claude-sonnet-4-6</code>); started_at=2026-05-17T22:12:01Z, ended_at=2026-05-17T22:23:34Z, duration_seconds=693; webfetch_calls=14, websearch_calls=18, bridge_fetches=2. Returned 11 items: 7 status-updates on W19 &quot;Looking Ahead&quot; items (PAN-OS CVE-2026-0300, Canvas/Instructure, The Gentlemen RaaS, Dirty Frag distro propagation, CVE-2026-31431 Copy Fail, MOVEit Automation CVE-2026-4670, SEPPmail CVE-2026-44128), 2 campaign-status updates (Secret Blizzard / Turla Kazuar, FrostyNeighbor / Ghostwriter UNC1151, Mini Shai-Hulud, Qilin / Agenda), 2 annual / periodic reports (Sophos State of Identity Security 2026, Verizon DBIR 2026). W1 coverage gaps: bleepingcomputer (article URLs frequently 403 even via bridge — WebSearch corroboration used), inside-it-ch (Cloudflare Managed Challenge — no relevant in-window items via WebSearch fallback), Verizon DBIR full PDF (not released until 2026-05-19 webinar), independent third-party SEPPmail CVE-2026-44128 write-up (not found in window — CIRCL advisory strongest available corroboration).</li><li><strong>W2</strong> (Strategic &amp; policy horizon) — returned: Claude Sonnet 4.6 (<code>claude-sonnet-4-6</code>); started_at=2026-05-17T22:12:32Z, ended_at=2026-05-17T22:17:59Z, duration_seconds=327; webfetch_calls=18, websearch_calls=14, bridge_fetches=12. Returned 8 items: 3 net-new policy items (EU Digital Omnibus AI Act extension 2026-12-02, CRA milestones 11 June / 11 September 2026, DORA first oversight cycle with 19 designated CTPPs), 4 status updates (ENISA CNA Root 4 new CNAs onboarded, EDPB CEF 2026 25 DPAs investigating, KRITIS-DachG registration deadline 17 July 2026, NIS2 transposition status no Court of Justice referral), 1 CISA KEV addition (CVE-2026-42897 Exchange OWA-XSS KEV-added 2026-05-15 deadline 2026-05-29). W2 coverage gaps: CERT-FR RSS feed serving items only through September 2025 (feed appears stale / misconfigured; direct-URL fetches work), BAKOM / OFCOM (no cybersecurity-relevant CH telecom-regulator publication this week), FINMA (no new circular this week), Council of Europe Budapest Convention (no in-window cybercrime action), OFAC cyber (no in-window sanctions action).</li></ul>
<p><strong>Sub-agent self-identification:</strong> both W1 and W2 self-identified as <code>Claude Sonnet 4.6</code> (canonical id <code>claude-sonnet-4-6</code>) — model id and friendly name aligned, no drift. The main agent (this Opus 4.7 invocation) is <code>Claude Opus 4.7</code> with canonical id <code>claude-opus-4-7</code>.</p>
<p><strong>Verification iterations:</strong> Phase 4.7 verifier ran with model rotation across five iterations.</p>
<ul><li><strong>Iter 1</strong> (<code>cti-verification</code>, Opus) tripped Anthropic&#39;s cyber-content classifier and returned no verdict — a documented failure mode on dense-CTI weekly composition.</li><li><strong>Iter 2</strong> (<code>cti-verification-alt</code>, Sonnet) returned <code>NEEDS_FIXES</code> truth=12 / editorial=4 / advisory=2; all findings remediated.</li><li><strong>Iter 3</strong> (<code>cti-verification-alt</code>, Sonnet — re-spawned on Sonnet to avoid recurrence of iter-1 classifier-trip risk) returned <code>NEEDS_FIXES</code> truth=2 / editorial=1 / advisory=1; all truth + editorial findings remediated (two iter-2 remediations had been partially applied; iter-3 caught them).</li><li><strong>Iter 4</strong> (<code>cti-verification-alt</code>, Sonnet) returned <code>NEEDS_FIXES</code> truth=3 / editorial=0 / advisory=1; all truth findings remediated.</li><li><strong>Iter 5</strong> (<code>cti-verification</code>, Opus — cap iteration, classifier-trip risk re-paid; succeeded) returned <code>NEEDS_FIXES</code> truth=0 / editorial=1 / advisory=2 — content is CLEAN at the truth level; residual editorial-advisory items are this very § 10 self-report (now updated) and a batch F12 single-source-heading-marker advisory that § 10&#39;s single-source-flag table compensates for.</li></ul>
<p>Cap reached at iter 5 per the prompt&#39;s <code>Cap 5 iterations</code> rule with publish-anyway fail-open safety valve. <code>verification_residual_count = 1</code> (editorial only; F11 advisory excluded per v2.47 semantics). Iteration-by-iteration model + verdict + duration + per-finding records persisted in <code>state/run_log.json.verification.iterations[]</code>.</p>
<p><strong><code>Coverage gaps:</code></strong> bleepingcomputer (article URLs 403 even via bridge); inside-it-ch (Cloudflare Managed Challenge); cert-fr (RSS stale through Sep 2025 — direct URL fetches succeed); bakom-ofcom (no in-window publication); finma-ch (no new circular); coe-budapest (no in-window cybercrime action); ofac-cyber (no in-window action); verizon-dbir-2026-full (PDF not released until 2026-05-19); seppmail-cve-2026-44128-third-party (no third-party PoC / write-up in window); databreaches-net (403 persistent — bridge allowlisted but no W20 item via secondary discovery); prodaft (403 persistent); nccgroup (403 persistent); csirt-acn-it (403 persistent); ccn-cert-es (geo-blocked); ico-uk (JS SPA — South Staffordshire penalty already covered via the daily citation); cisa-news / cisa-kev / cisa-directives (bridge-fetched successfully — ED-26-03 + KEV CVE-2026-42897 / CVE-2026-20182 captured); ncsc-ch-security-hub (bridge-fetched successfully — post #12577 captured for CVE-2026-42897); enisa-euvd (SPA — no W20 item surfaced via WebFetch); advisories-ncsc-nl (Angular SPA — listing returns no advisory data; individual URLs work).</p>
<p><em>Migrated from briefs/weekly/2026-W20.md (v2).</em></p></div></div></div></details>]]></content:encoded></item><item><title>CTI Weekly Summary · 2026-W19</title><link>https://ctipilot.ch/weekly/2026-W19/</link><guid isPermaLink="true">https://ctipilot.ch/weekly/2026-W19/</guid><pubDate>Mon, 04 May 2026 05:00:52 +0000</pubDate><dc:date>2026-05-04T05:00:52Z</dc:date><category>CVE-2026-0300</category><category>CVE-2026-21510</category><category>CVE-2026-25592</category><category>CVE-2026-26030</category><category>CVE-2026-29201</category><category>CVE-2026-29202</category><category>CVE-2026-29203</category><category>CVE-2026-31431</category><description><![CDATA[<ul><li><strong>Critical infrastructure water (PL).</strong> Polish water-sector OT intrusions — ABW 2025 Annual Report (published 2026-05-07) names five municipal facilities (Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, Sierakowo) and formally attributes the campaign to APT28 (GRU), APT29 (SVR), and UNC1151 (Belarus-affiliated, Ghostwriter information operations). All five facilities fell below the NIS2 essential-entity threshold at intrusion time — the report explicitly highlights the coverage gap for small municipal operators. (daily 2026-05-08 first coverage · daily 2026-05-09 UPDATE with attribution + NIS2 framing) <a href="https://ctipilot.ch/entries/2026-05-04/critical-infrastructure-water-pl/">→</a></li><li><strong>Canvas / Instructure breach — five-day arc from first claim to seven Dutch universities executing emergency disconnects.</strong> Canvas / Instructure — second intrusion claim against Instructure on 2026-05-08 despite the May 8 patches; seven Dutch universities (VU Amsterdam, UvA, Erasmus, Tilburg, TU/e, Maastricht, Twente) executed emergency Canvas disconnects on or before 2026-05-09; the extortion deadline is 2026-05-12 (Tuesday). (Techzine EU · DutchNews.nl · daily 2026-05-10) <a href="https://ctipilot.ch/entries/2026-05-04/canvas-instructure-breach-five-day-arc-from-first-claim-to-s/">→</a></li><li><strong>Akira ransomware on Groupe 3R — 20 Swiss medical-imaging centres across seven cantons; second cyberattack on the same operator within twelve months.</strong> Groupe 3R (Réseau Radiologique Romand) — Akira leak-site listing claims 48 GB; ~20 imaging centres across seven Swiss cantons (Vaud, Valais, Fribourg, Genève, Neuchâtel, Berne, and Zürich) — six in Romandie plus Zürich; second cyberattack on the same Swiss operator within twelve months. Victim disclosed publicly 2026-04-30, notified BACS/OFCS, filed criminal complaint, will not pay ransom; legacy examination data still inaccessible. (Groupe 3R victim statement · ICTjournal.ch · daily 2026-05-10) <a href="https://ctipilot.ch/entries/2026-05-04/akira-ransomware-on-groupe-3r-20-swiss-medical-imaging-centr/">→</a></li><li><strong>CVE-2026-44128 et al. — SEPPmail Secure Email Gateway: six-CVE cluster on the Swiss public sector&#39;s dominant email-encryption appliance.</strong> SEPPmail Secure Email Gateway — six-CVE cluster patched 15.0.4/15.0.4.1; primary CVE-2026-44128 (CVSS 9.3) is an unauthenticated RCE via /gina/diag/exec test endpoints left enabled in production GINAv2 builds. SEPPmail handles S/MIME for Swiss federal bodies, cantonal administrations, and healthcare; the GINAv2 portal is designed to be internet-accessible to external recipients. (NCSC-CH 12551 · SEPPmail v15.0 release notes · daily 2026-05-09) <a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-44128-et-al-seppmail-secure-email-gateway-six-cve-c/">→</a></li><li><strong>CVE-2026-6973 + CVE-2026-5787 — Ivanti EPMM on-prem pre-auth chain to admin RCE; 508 EU instances internet-exposed; named EU victims include the European.</strong> CVE-2026-6973 / CVE-2026-5787 Ivanti EPMM — KEV deadline 2026-05-10 expired today; ~850 internet-exposed instances globally with 508 in Europe (60%). Ivanti has disclosed only &quot;a very limited number of customers&quot; exploited via the May chain without naming victims; SecurityWeek reports a Chinese-actor assessment based on historical EPMM exploitation patterns. EU public-record victims previously associated with Ivanti EPMM compromise — European Commission, Dutch DPA (AP), and Netherlands Council for the Judiciary (Rvdr) — were named by Help Net Security against the January 2026 CVE-2026-1281 / CVE-2026-1340 wave, not the May 2026 wave; whether the May 2026 wave caught additional victims (the daily 2026-05-09 also referenced Finnish Valtori per a separate NCSC-FI advisory that is not in the Help Net Security article) is not yet consolidated in publicly available primaries. The May 2026 EPMM patch closes companions CVE-2026-5786 / 5788 / 7821 and supersedes the January 2026 RPM workaround for CVE-2026-1281 / 1340. (Ivanti PSIRT · Help Net Security — European Commission Ivanti EPMM vulnerabilities, 2026-02-09 · daily 2026-05-08) <a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-6973-cve-2026-5787-ivanti-epmm-on-prem-pre-auth-cha/">→</a></li><li><strong>CVE-2026-0300 — Palo Alto PAN-OS Captive Portal unauthenticated root RCE; CL-STA-1132 active since 2026-04-09; no patch until 2026-05-13.</strong> CVE-2026-0300 PAN-OS Captive Portal — KEV deadline 2026-05-09 expired with no patch available; CL-STA-1132 (China-nexus, Unit 42) active since 2026-04-09 against a vulnerability disclosed 2026-05-06. Patch window 2026-05-13 → 2026-05-28; the rogue-admin name pattern svc-health-check-NNNNNN and Python-based tunnelling implants under /var/tmp/linuxupdate and adjacent /var/tmp/linuxap / /tmp/.c paths are the surviving post-compromise hunting indicators. (Palo Alto PSIRT · CERT-EU Critical Advisory 2026-006 · daily 2026-05-07 · daily 2026-05-09 UPDATE) <a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-0300-palo-alto-pan-os-captive-portal-unauthenticate/">→</a></li><li><strong>CVE-2026-42208 LiteLLM Proxy — pre-auth SQL injection exposing upstream LLM-provider API keys at the multi-tenant SaaS layer.</strong> CVE-2026-42208 LiteLLM Proxy pre-auth SQL injection (CVSS 9.3) — CISA KEV deadline 2026-05-11; in-the-wild exploitation began within approximately 36 hours of the GitHub Security Advisory per Bishop Fox. Every upstream LLM-provider API key the proxy holds (OpenAI, Anthropic, Azure OpenAI, Cohere) must be rotated; patching alone does not remediate pre-patch credential exposure. The Braintrust AWS compromise (2026-05-06) is the same architectural class — multi-tenant SaaS aggregation of upstream-provider credentials. (Bishop Fox · daily 2026-05-09) <a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-42208-litellm-proxy-pre-auth-sql-injection-exposing/">→</a></li><li><strong>CVE-2026-31431 &quot;Copy Fail&quot; + CVE-2026-43284 / CVE-2026-43500 &quot;Dirty Frag&quot; — Linux kernel LPE pair confirmed in complementary post-compromise campaigns.</strong> Two Linux kernel LPE chains — &quot;Copy Fail&quot; CVE-2026-31431 and &quot;Dirty Frag&quot; CVE-2026-43284 / CVE-2026-43500 — confirmed active in complementary post-compromise campaigns; rxrpc distro patches still pending at week-end. Microsoft frames the two families as similar post-compromise techniques covering different Linux deployment configurations; both defeat on-disk file-integrity monitoring by writing into the page cache. (Microsoft Security Blog · Wiz Research · daily 2026-05-06 · daily 2026-05-09) <a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-31431-copy-fail-cve-2026-43284-cve-2026-43500-dirty/">→</a></li></ul>]]></description><content:encoded><![CDATA[<div class="tldr"><span class="eyebrow eyebrow--muted">Week at a glance</span><ol><li><span class="num">01</span><span><b>Critical infrastructure water (PL).</b> Polish water-sector OT intrusions — ABW 2025 Annual Report (published 2026-05-07) names five municipal facilities (Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, Sierakowo) and formally attributes the campaign to APT28 (GRU), APT29 (SVR), and UNC1151 (Belarus-affiliated, Ghostwriter information operations). All five facilities fell below the NIS2 essential-entity threshold at intrusion time — the report explicitly highlights the coverage gap for small municipal operators. (daily 2026-05-08 first coverage · daily 2026-05-09 UPDATE with attribution + NIS2 framing) <a href="https://ctipilot.ch/entries/2026-05-04/critical-infrastructure-water-pl/">→</a></span></li><li><span class="num">02</span><span><b>Canvas / Instructure breach — five-day arc from first claim to seven Dutch universities executing emergency disconnects.</b> Canvas / Instructure — second intrusion claim against Instructure on 2026-05-08 despite the May 8 patches; seven Dutch universities (VU Amsterdam, UvA, Erasmus, Tilburg, TU/e, Maastricht, Twente) executed emergency Canvas disconnects on or before 2026-05-09; the extortion deadline is 2026-05-12 (Tuesday). (Techzine EU · DutchNews.nl · daily 2026-05-10) <a href="https://ctipilot.ch/entries/2026-05-04/canvas-instructure-breach-five-day-arc-from-first-claim-to-s/">→</a></span></li><li><span class="num">03</span><span><b>Akira ransomware on Groupe 3R — 20 Swiss medical-imaging centres across seven cantons; second cyberattack on the same operator within twelve months.</b> Groupe 3R (Réseau Radiologique Romand) — Akira leak-site listing claims 48 GB; ~20 imaging centres across seven Swiss cantons (Vaud, Valais, Fribourg, Genève, Neuchâtel, Berne, and Zürich) — six in Romandie plus Zürich; second cyberattack on the same Swiss operator within twelve months. Victim disclosed publicly 2026-04-30, notified BACS/OFCS, filed criminal complaint, will not pay ransom; legacy examination data still inaccessible. (Groupe 3R victim statement · ICTjournal.ch · daily 2026-05-10) <a href="https://ctipilot.ch/entries/2026-05-04/akira-ransomware-on-groupe-3r-20-swiss-medical-imaging-centr/">→</a></span></li><li><span class="num">04</span><span><b>CVE-2026-44128 et al. — SEPPmail Secure Email Gateway: six-CVE cluster on the Swiss public sector&#39;s dominant email-encryption appliance.</b> SEPPmail Secure Email Gateway — six-CVE cluster patched 15.0.4/15.0.4.1; primary CVE-2026-44128 (CVSS 9.3) is an unauthenticated RCE via /gina/diag/exec test endpoints left enabled in production GINAv2 builds. SEPPmail handles S/MIME for Swiss federal bodies, cantonal administrations, and healthcare; the GINAv2 portal is designed to be internet-accessible to external recipients. (NCSC-CH 12551 · SEPPmail v15.0 release notes · daily 2026-05-09) <a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-44128-et-al-seppmail-secure-email-gateway-six-cve-c/">→</a></span></li><li><span class="num">05</span><span><b>CVE-2026-6973 + CVE-2026-5787 — Ivanti EPMM on-prem pre-auth chain to admin RCE; 508 EU instances internet-exposed; named EU victims include the European.</b> CVE-2026-6973 / CVE-2026-5787 Ivanti EPMM — KEV deadline 2026-05-10 expired today; ~850 internet-exposed instances globally with 508 in Europe (60%). Ivanti has disclosed only &quot;a very limited number of customers&quot; exploited via the May chain without naming victims; SecurityWeek reports a Chinese-actor assessment based on historical EPMM exploitation patterns. EU public-record victims previously associated with Ivanti EPMM compromise — European Commission, Dutch DPA (AP), and Netherlands Council for the Judiciary (Rvdr) — were named by Help Net Security against the January 2026 CVE-2026-1281 / CVE-2026-1340 wave, not the May 2026 wave; whether the May 2026 wave caught additional victims (the daily 2026-05-09 also referenced Finnish Valtori per a separate NCSC-FI advisory that is not in the Help Net Security article) is not yet consolidated in publicly available primaries. The May 2026 EPMM patch closes companions CVE-2026-5786 / 5788 / 7821 and supersedes the January 2026 RPM workaround for CVE-2026-1281 / 1340. (Ivanti PSIRT · Help Net Security — European Commission Ivanti EPMM vulnerabilities, 2026-02-09 · daily 2026-05-08) <a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-6973-cve-2026-5787-ivanti-epmm-on-prem-pre-auth-cha/">→</a></span></li><li><span class="num">06</span><span><b>CVE-2026-0300 — Palo Alto PAN-OS Captive Portal unauthenticated root RCE; CL-STA-1132 active since 2026-04-09; no patch until 2026-05-13.</b> CVE-2026-0300 PAN-OS Captive Portal — KEV deadline 2026-05-09 expired with no patch available; CL-STA-1132 (China-nexus, Unit 42) active since 2026-04-09 against a vulnerability disclosed 2026-05-06. Patch window 2026-05-13 → 2026-05-28; the rogue-admin name pattern svc-health-check-NNNNNN and Python-based tunnelling implants under /var/tmp/linuxupdate and adjacent /var/tmp/linuxap / /tmp/.c paths are the surviving post-compromise hunting indicators. (Palo Alto PSIRT · CERT-EU Critical Advisory 2026-006 · daily 2026-05-07 · daily 2026-05-09 UPDATE) <a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-0300-palo-alto-pan-os-captive-portal-unauthenticate/">→</a></span></li><li><span class="num">07</span><span><b>CVE-2026-42208 LiteLLM Proxy — pre-auth SQL injection exposing upstream LLM-provider API keys at the multi-tenant SaaS layer.</b> CVE-2026-42208 LiteLLM Proxy pre-auth SQL injection (CVSS 9.3) — CISA KEV deadline 2026-05-11; in-the-wild exploitation began within approximately 36 hours of the GitHub Security Advisory per Bishop Fox. Every upstream LLM-provider API key the proxy holds (OpenAI, Anthropic, Azure OpenAI, Cohere) must be rotated; patching alone does not remediate pre-patch credential exposure. The Braintrust AWS compromise (2026-05-06) is the same architectural class — multi-tenant SaaS aggregation of upstream-provider credentials. (Bishop Fox · daily 2026-05-09) <a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-42208-litellm-proxy-pre-auth-sql-injection-exposing/">→</a></span></li><li><span class="num">08</span><span><b>CVE-2026-31431 &quot;Copy Fail&quot; + CVE-2026-43284 / CVE-2026-43500 &quot;Dirty Frag&quot; — Linux kernel LPE pair confirmed in complementary post-compromise campaigns.</b> Two Linux kernel LPE chains — &quot;Copy Fail&quot; CVE-2026-31431 and &quot;Dirty Frag&quot; CVE-2026-43284 / CVE-2026-43500 — confirmed active in complementary post-compromise campaigns; rxrpc distro patches still pending at week-end. Microsoft frames the two families as similar post-compromise techniques covering different Linux deployment configurations; both defeat on-disk file-integrity monitoring by writing into the page cache. (Microsoft Security Blog · Wiz Research · daily 2026-05-06 · daily 2026-05-09) <a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-31431-copy-fail-cve-2026-43284-cve-2026-43500-dirty/">→</a></span></li></ol></div><nav class="secnav" aria-label="Sections"><a class="secnav-chip" href="#highest-impact-events-what-s-on-fire-if-no-one-acted">Highest-impact events · what&#39;s on fire if no one acted <span class="secnav-n">6</span></a><a class="secnav-chip" href="#multi-day-campaigns-and-chains">Multi-day campaigns and chains <span class="secnav-n">4</span></a><a class="secnav-chip" href="#vulnerability-roll-up">Vulnerability roll-up <span class="secnav-n">2</span></a><a class="secnav-chip" href="#sector-victim-patterns">Sector &amp; victim patterns <span class="secnav-n">6</span></a><a class="secnav-chip" href="#incidents-disclosures-recap">Incidents &amp; disclosures recap <span class="secnav-n">6</span></a><a class="secnav-chip" href="#annual-periodic-threat-reports">Annual / periodic threat reports <span class="secnav-n">6</span></a><a class="secnav-chip" href="#long-running-campaigns-status-update">Long-running campaigns · status update <span class="secnav-n">11</span></a><a class="secnav-chip" href="#policy-regulatory-horizon">Policy &amp; regulatory horizon <span class="secnav-n">10</span></a><a class="secnav-chip" href="#looking-ahead-what-to-watch-next-week">Looking ahead · what to watch next week <span class="secnav-n">1</span></a></nav><div class="sect" id="highest-impact-events-what-s-on-fire-if-no-one-acted"><span class="n">01</span><span class="t">Highest-impact events · what&#39;s on fire if no one acted</span><span class="c">6 items</span></div><article class="finding entry-card" data-entry-id="2026-05-04/akira-ransomware-on-groupe-3r-20-swiss-medical-imaging-centr" data-tags="ransomware organized-crime data-breach" data-regions="switzerland" data-kind="synthesis" data-priority="high" data-discovered="2026-05-04T05:00:05Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="akira-ransomware-on-groupe-3r-20-swiss-medical-imaging-centr"><a href="https://ctipilot.ch/entries/2026-05-04/akira-ransomware-on-groupe-3r-20-swiss-medical-imaging-centr/">Akira ransomware on Groupe 3R — 20 Swiss medical-imaging centres across seven cantons; second cyberattack on the same operator within twelve months</a></h3><p><strong>If you did nothing this week:</strong> Swiss and DACH healthcare operators with internet-exposed Cisco ASA / FTD, Fortinet SSL-VPN, or VMware ESXi management interfaces — Akira&#39;s documented edge-device initial-access targets — face the same playbook used here. Groupe 3R confirmed the attack on its own website 2026-04-30, filed a criminal complaint, notified the Federal Office for Cybersecurity (BACS/OFCS), and explicitly stated it will not pay ransom; Akira&#39;s leak-site listing on approximately 2026-05-08 claims 48 GB exfiltrated including employee identity documents, patient records, payment information, and signed NDAs (<a href="https://www.groupe3r.ch/fr/information-importante-perturbation-de-nos-services-7268/" target="_blank" rel="noopener noreferrer">Groupe 3R victim statement, 2026-04-30</a> · <a href="https://www.ictjournal.ch/news/2026-05-06/le-reseau-radiologique-romand-a-nouveau-victime-dune-cyberattaque-ses-systemes" target="_blank" rel="noopener noreferrer">ICTjournal.ch, 2026-05-06</a> · <a href="https://www.blick.ch/fr/suisse/romande/cyberattaque-le-groupe-romand-3r-de-radiologie-cible-id21930477.html" target="_blank" rel="noopener noreferrer">Blick.ch, 2026-05-07</a> · <a href="https://ctipilot.ch/briefs/2026-05-10/" target="_blank" rel="noopener noreferrer">daily 2026-05-10</a>).</p>
<p>Groupe 3R (Réseau Radiologique Romand) operates ~20 medical-imaging centres across seven Swiss cantons listed in the operator statement (Vaud, Valais, Fribourg, Genève, Neuchâtel, Berne — six in Romandie — plus Zürich in German-speaking Switzerland) — a direct Swiss critical-health-infrastructure incident, and the operator&#39;s second cyberattack within twelve months (the prior April 2025 incident is acknowledged in the operator&#39;s own statement as having involved different attackers and methodology). Legacy examination data remains inaccessible at week-end; new examination data security has been restored on rebuilt infrastructure. Data-exfiltration was not confirmed by the victim; Akira&#39;s leak-site post asserts 48 GB exfiltrated. Akira&#39;s documented playbook against European healthcare and SME targets emphasises edge-device initial access (Cisco ASA/FTD CVEs, Fortinet SSL-VPN CVEs, VMware ESXi authenticated RCE) and intermittent file-encryption to evade EDR file-IO heuristics — observed ATT&amp;CK techniques include <a href="https://attack.mitre.org/techniques/T1190/" target="_blank" rel="noopener noreferrer">T1190</a>, <a href="https://attack.mitre.org/techniques/T1133/" target="_blank" rel="noopener noreferrer">T1133 External Remote Services</a>, <a href="https://attack.mitre.org/techniques/T1486/" target="_blank" rel="noopener noreferrer">T1486 Data Encrypted for Impact</a>, and <a href="https://attack.mitre.org/techniques/T1567/" target="_blank" rel="noopener noreferrer">T1567 Exfiltration Over Web Service</a>. Defenders should re-validate patch state on the edge devices in Akira&#39;s standard target list, confirm EDR rules trigger on intermittent-encryption write-skip-write file-IO patterns, and verify radiology-modality VLAN segmentation from corporate Active Directory — PACS/RIS environments tend to co-tenant with Windows file shares, providing trivial east-west reach once an attacker lands. The Akira-as-actor attribution comes from <code>ransomware.live</code> (aggregator), not from the victim or an independent primary; logged with confidence HIGH on incident, MEDIUM on actor.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/akira-ransomware-on-groupe-3r-20-swiss-medical-imaging-centr/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.groupe3r.ch/fr/information-importante-perturbation-de-nos-services-7268/" target="_blank" rel="noopener noreferrer">Groupe 3R victim statement</a> · <a href="https://www.ictjournal.ch/news/2026-05-06/le-reseau-radiologique-romand-a-nouveau-victime-dune-cyberattaque-ses-systemes" target="_blank" rel="noopener noreferrer">ICTjournal.ch</a> · <a href="https://www.blick.ch/fr/suisse/romande/cyberattaque-le-groupe-romand-3r-de-radiologie-cible-id21930477.html" target="_blank" rel="noopener noreferrer">Blick.ch</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/cve-2026-44128-et-al-seppmail-secure-email-gateway-six-cve-c" data-tags="vulnerabilities pre-auth rce auth-bypass patch-available" data-regions="switzerland dach" data-kind="synthesis" data-priority="high" data-discovered="2026-05-04T05:00:04Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-44128/">CVE-2026-44128 +5</a></div><h3 class="f-h" id="cve-2026-44128-et-al-seppmail-secure-email-gateway-six-cve-c"><a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-44128-et-al-seppmail-secure-email-gateway-six-cve-c/">CVE-2026-44128 et al. — SEPPmail Secure Email Gateway: six-CVE cluster on the Swiss public sector&#39;s dominant email-encryption appliance</a></h3><p><strong>If you did nothing this week:</strong> any unpatched SEPPmail instance still operating its GINAv2 portal on internet-accessible TCP/443 is exposing the <code>/gina/diag/exec</code> test/diagnostic endpoint — left active in the v15.0.x release cycle by the vendor — which accepts unvalidated shell command arguments and invokes <code>Runtime.exec()</code> as the Tomcat application user. A single HTTP request <code>https://&lt;gina-hostname&gt;/gina/diag/exec?cmd=id</code> confirms execution context; the same primitive reads <code>/var/seppmail/conf/gina.properties</code> (LDAP bind, SMTP credentials, S/MIME key-store symmetric key) and writes a web shell under <code>webapps/</code>. No authentication, no rate-limiting, no network boundary enforced (<a href="https://security-hub.ncsc.admin.ch/api/posts/12551/details" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub post 12551, 2026-05-08</a> · <a href="https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html#security" target="_blank" rel="noopener noreferrer">SEPPmail release notes v15.0</a> · <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09 deep dive</a>).</p>
<p>SEPPmail AG (Steinach SG) is the dominant cryptographic email-processing gateway in the Swiss public sector — cantonal administrations, Swiss federal bodies (EJPD/DFJP, SECO, cantonal courts), university hospitals, and a substantial share of private healthcare and finance route sensitive email through SEPPmail infrastructure. The GINAv2 portal is by design internet-accessible to external recipients (who click a secure-email notification link, authenticate or self-register, and retrieve encrypted content). The vulnerability cluster covers six CVEs: <strong>CVE-2026-44128</strong> (CVSS 9.3, unauth RCE via test endpoints, <a href="https://attack.mitre.org/techniques/T1190/" target="_blank" rel="noopener noreferrer">T1190</a>); <strong>CVE-2026-44125</strong> (CVSS 9.3, missing authentication on <code>/gina/api/v1/admin/</code> allowing full configuration export including SMTP credentials, LDAP bind password, and the AES key protecting stored S/MIME keys — <a href="https://attack.mitre.org/techniques/T1078/001/" target="_blank" rel="noopener noreferrer">T1078.001</a>, <a href="https://attack.mitre.org/techniques/T1552/001/" target="_blank" rel="noopener noreferrer">T1552.001</a>); <strong>CVE-2026-44126</strong> (CVSS 9.2, insecure session deserialisation reachable unauthenticated via a <code>GINA_SESSION=../../uploads/...</code> path-traversal cookie value that combines with the un-authenticated <code>/gina/upload/certificate</code> upload to stage a Java gadget chain — <a href="https://attack.mitre.org/techniques/T1190/" target="_blank" rel="noopener noreferrer">T1190</a>); <strong>CVE-2026-44127</strong> (CVSS 8.8, LFI and arbitrary file deletion in the appliance management interface — <a href="https://attack.mitre.org/techniques/T1083/" target="_blank" rel="noopener noreferrer">T1083</a>, <a href="https://attack.mitre.org/techniques/T1070/002/" target="_blank" rel="noopener noreferrer">T1070.002</a>); <strong>CVE-2026-44129</strong> (CVSS 8.3, Freemarker SSTI via notification-email customisation — <a href="https://attack.mitre.org/techniques/T1059/007/" target="_blank" rel="noopener noreferrer">T1059.007</a>); <strong>CVE-2026-7864</strong> (CVSS 6.9, information disclosure). No in-the-wild exploitation confirmed as of week-end; all three CRITICAL paths are pre-authentication.</p>
<p>Patch path: <strong>SEPPmail 15.0.4 (patch 15.0.4.1)</strong> via the standard SEPPmail update channel; if patching is delayed, block source IPs outside the designated admin CIDR from <code>/gina/diag/</code> and <code>/gina/api/v1/admin/</code> paths at WAF or perimeter. Rotate LDAP bind credentials, SMTP relay credentials, and the S/MIME key-store password after patching regardless of whether exploitation is suspected — the compromise blast radius via CVE-2026-44125 alone reads every credential the appliance stores in cleartext. The Swiss Federal Chancellery ICT security baseline (Sicherheitsstandard IKT des Bundes / ISBB) classifies email-gateway compromise as a Level 3 incident requiring escalation to NCSC-CH within 24 hours; BSI IT-Grundschutz module APP.4.4 brings the same gateway into DACH organisations&#39; ISMS scope.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/cve-2026-44128-et-al-seppmail-secure-email-gateway-six-cve-c/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://security-hub.ncsc.admin.ch/api/posts/12551/details" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub post 12551</a> · <a href="https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html#security" target="_blank" rel="noopener noreferrer">SEPPmail release notes v15.0</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/cve-2026-6973-cve-2026-5787-ivanti-epmm-on-prem-pre-auth-cha" data-tags="vulnerabilities actively-exploited cisa-kev rce pre-auth auth-bypass china-nexus" data-regions="europe global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-04T05:00:01Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-6973/">CVE-2026-6973 +4</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-6973-cve-2026-5787-ivanti-epmm-on-prem-pre-auth-cha"><a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-6973-cve-2026-5787-ivanti-epmm-on-prem-pre-auth-cha/">CVE-2026-6973 + CVE-2026-5787 — Ivanti EPMM on-prem pre-auth chain to admin RCE; 508 EU instances internet-exposed; named EU victims include the European Commission</a></h3><p><strong>If you did nothing this week:</strong> Shadowserver telemetry cited by BleepingComputer counts ~850 internet-exposed EPMM instances globally with <strong>508 in Europe and 182 in North America</strong> — i.e. European exposure is materially larger than the rest of the world combined (<a href="https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-epmm-flaw-exploited-in-zero-day-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-05-07</a>). Ivanti&#39;s disclosure cites &quot;a very limited number of customers&quot; exploited via the May 2026 chain without naming them. EU public-record victims <strong>previously confirmed against Ivanti EPMM compromise</strong> per Help Net Security&#39;s January-2026-wave reporting are: <strong>European Commission</strong> (DG DIGIT), <strong>Dutch DPA / Autoriteit Persoonsgegevens</strong>, and <strong>Netherlands Council for the Judiciary / Raad voor de rechtspraak</strong>. The daily 2026-05-09 separately referenced <strong>Finnish Valtori</strong> (Government ICT Centre) per an NCSC-FI advisory not consolidated in the Help Net Security source. Whether the May 2026 wave caught additional named victims is not yet publicly disclosed at week-end (<a href="https://www.helpnetsecurity.com/2026/02/09/european-commission-ivanti-epmm-vulnerabilities/" target="_blank" rel="noopener noreferrer">Help Net Security — European Commission Ivanti EPMM vulnerabilities, 2026-02-09</a> · <a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0552/" target="_blank" rel="noopener noreferrer">CERT-FR CERTFR-2026-AVI-0552, 2026-05-07</a> · <a href="https://security-hub.ncsc.admin.ch/api/posts/12548/details" target="_blank" rel="noopener noreferrer">NCSC-CH 12548, 2026-05-08</a> · <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09 UPDATE</a>).</p>
<p>The chain combines <strong>CVE-2026-5787</strong> (CVSS 9.1, CWE-295) — Ivanti EPMM accepts a crafted Sentry registration request from an unauthenticated network-reachable attacker and issues that attacker a valid CA-signed client certificate with Sentry trust — with <strong>CVE-2026-6973</strong> (CVSS 7.2, CWE-20) — a vulnerable admin REST API endpoint accepting attacker-controlled parameters that reach a server-side execution sink as the EPMM service account (<a href="https://www.ivanti.com/blog/may-2026-epmm-security-update" target="_blank" rel="noopener noreferrer">Ivanti PSIRT — May 2026 EPMM Security Update</a> · <a href="https://ctipilot.ch/briefs/2026-05-08/" target="_blank" rel="noopener noreferrer">daily 2026-05-08 deep dive — full chain mechanics</a>). The nominal &quot;admin-required&quot; label on CVE-2026-6973 is misleading: the Sentry-trust certificate issued by CVE-2026-5787 satisfies EPMM&#39;s administrative authentication gate, making the combined chain fully pre-authentication; the full CWE-295 → CWE-20 chain mechanics are documented in the 2026-05-08 daily deep dive (<a href="https://ctipilot.ch/briefs/2026-05-08/" target="_blank" rel="noopener noreferrer">daily 2026-05-08 deep dive — full chain mechanics</a> · <a href="https://www.securityweek.com/ivanti-patches-epmm-zero-day-exploited-in-targeted-attacks/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-05-08</a>). The May 2026 EPMM update additionally addresses CVE-2026-5786 (CVSS 8.8, remote authenticated → administrative access), CVE-2026-5788 (CVSS 7.0, unauthenticated arbitrary method invocation), and CVE-2026-7821 (high-severity, vendor advisory only) — and supersedes the January 2026 RPM workaround for CVE-2026-1281 / CVE-2026-1340; operators that are still on the January workaround need to apply the proper patch now (<a href="https://www.securityweek.com/ivanti-patches-epmm-zero-day-exploited-in-targeted-attacks/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-05-08</a>).</p>
<p>EPMM is one of the two dominant on-premises MDM platforms in EU public-sector and healthcare environments — both NIS2 Annex-I essential-entity categories — and a compromised EPMM server gives an attacker authorised silent push of policies, configurations, or wipe to every enrolled mobile device. ATT&amp;CK coverage includes <a href="https://attack.mitre.org/techniques/T1190/" target="_blank" rel="noopener noreferrer">T1190 Exploit Public-Facing Application</a>, <a href="https://attack.mitre.org/techniques/T1078/" target="_blank" rel="noopener noreferrer">T1078 Valid Accounts</a>, <a href="https://attack.mitre.org/techniques/T1059/" target="_blank" rel="noopener noreferrer">T1059 Command and Scripting Interpreter</a>, <a href="https://attack.mitre.org/techniques/T1584/007/" target="_blank" rel="noopener noreferrer">T1584.007 Compromise Infrastructure: Certificate Authorities</a>, and <a href="https://attack.mitre.org/techniques/T1072/" target="_blank" rel="noopener noreferrer">T1072 Remote Device Management</a>. Fixed builds: <strong>12.6.1.1</strong>, <strong>12.7.0.1</strong>, <strong>12.8.0.1</strong>. If patching is not feasible within hours, remove TCP/443 on the EPMM admin interface from internet exposure, place it behind VPN with allowlisted management IPs, and review the EPMM admin console&#39;s Sentry-host registration list for unexpected entries — revoke any not on your inventory.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: Shadowserver telemetry cited by BleepingComputer counts ~850 internet-exposed EPMM instances globally with 508 in Europe and 182 in North America — i.e.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/cve-2026-6973-cve-2026-5787-ivanti-epmm-on-prem-pre-auth-cha/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ivanti.com/blog/may-2026-epmm-security-update" target="_blank" rel="noopener noreferrer">Ivanti — May 2026 EPMM Security Update</a> · <a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0552/" target="_blank" rel="noopener noreferrer">CERT-FR CERTFR-2026-AVI-0552</a> · <a href="https://security-hub.ncsc.admin.ch/api/posts/12548/details" target="_blank" rel="noopener noreferrer">NCSC-CH 12548</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/cve-2026-0300-palo-alto-pan-os-captive-portal-unauthenticate" data-tags="vulnerabilities actively-exploited cisa-kev rce pre-auth nation-state no-patch" data-regions="europe global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-04T05:00:00Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-0300/">CVE-2026-0300</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-0300-palo-alto-pan-os-captive-portal-unauthenticate"><a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-0300-palo-alto-pan-os-captive-portal-unauthenticate/">CVE-2026-0300 — Palo Alto PAN-OS Captive Portal unauthenticated root RCE; CL-STA-1132 active since 2026-04-09; no patch until 2026-05-13</a></h3><p><strong>If you did nothing this week:</strong> any PA-Series or VM-Series firewall with the User-ID Authentication Portal enabled and internet-reachable has been within the attack window since 2026-04-09 — three weeks before public disclosure (2026-05-06) and four-and-a-half weeks before the first staged patch becomes available (2026-05-13). The daily 2026-05-09 UPDATE recorded an observed dwell time of approximately 20 days from initial compromise to second-device exploitation on at least one tracked victim; the relevant retrospective-log question is whether your firewall has been compromised since mid-April, not whether it might be compromised next week.</p>
<p>CVE-2026-0300 (CVSS 9.3, CWE-121 stack-based buffer overflow) is an unauthenticated remote code execution in the PAN-OS User-ID Authentication Portal — a network-accessible service that a single crafted packet exploits to root on the firewall&#39;s management plane (<a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto Networks Security Advisory, 2026-05-06</a> · <a href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/" target="_blank" rel="noopener noreferrer">Unit 42 primary research, 2026-05-06</a>). CERT-EU issued a Critical Advisory (rare designation) on disclosure day (<a href="https://cert.europa.eu/publications/security-advisories/2026-006/" target="_blank" rel="noopener noreferrer">CERT-EU 2026-006, 2026-05-06</a>); CERT-FR followed with CERTFR-2026-AVI-0537 (<a href="https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0537/" target="_blank" rel="noopener noreferrer">CERT-FR, 2026-05-06</a>). Unit 42 tracks the active exploitation cluster as <strong>CL-STA-1132</strong> and characterises it as likely state-sponsored activity. Unit 42&#39;s primary research records shellcode injection into <code>nginx</code> worker processes, EarthWorm / ReverseSocks5 tunnelling, and Python implants under <code>/var/tmp/linuxupdate</code> and <code>/tmp/.c</code>; the daily 2026-05-09 UPDATE additionally surfaces a rogue admin name pattern <code>svc-health-check-[6-digit-numeric]</code> (bypassing normal <code>admin-role</code> RBAC), running-configuration export including pre-shared keys, and OSPF-based internal AD enumeration — a profile consistent with <a href="https://attack.mitre.org/techniques/T1190/" target="_blank" rel="noopener noreferrer">T1190 Exploit Public-Facing Application</a>, <a href="https://attack.mitre.org/techniques/T1055/" target="_blank" rel="noopener noreferrer">T1055 Process Injection</a>, <a href="https://attack.mitre.org/techniques/T1003/" target="_blank" rel="noopener noreferrer">T1003 OS Credential Dumping</a>, and <a href="https://attack.mitre.org/techniques/T1572/" target="_blank" rel="noopener noreferrer">T1572 Protocol Tunneling</a>. Patch availability is staged 2026-05-13 → 2026-05-28 across PAN-OS branches 10.2.x / 11.1.x / 11.2.x / 12.1.x; Cloud NGFW and Prisma Access are not affected. Until patches land, the operational expectations are (1) disable the Authentication Portal entirely where it is not required, (2) restrict it to trusted internal IP ranges via security policy where it is, (3) PAN-OS 11.1+ users should confirm Threat ID 510019 is in blocking mode, and (4) review authentication-portal logs and admin-account listings from 2026-04-09 onward for retrospective compromise evidence (<a href="https://ctipilot.ch/briefs/2026-05-07/" target="_blank" rel="noopener noreferrer">daily 2026-05-07 deep dive</a>; <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09 update</a>).</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: any PA-Series or VM-Series firewall with the User-ID Authentication Portal enabled and internet-reachable has been within the attack window since 2026-04-09 — three weeks before public disclosure (2026-05-06) and four-and-a-half weeks before the first staged patch …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/cve-2026-0300-palo-alto-pan-os-captive-portal-unauthenticate/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto Networks Security Advisory</a> · <a href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/" target="_blank" rel="noopener noreferrer">Unit 42 — Captive Portal zero-day</a> · <a href="https://cert.europa.eu/publications/security-advisories/2026-006/" target="_blank" rel="noopener noreferrer">CERT-EU Critical Advisory 2026-006</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/cve-2026-42208-litellm-proxy-pre-auth-sql-injection-exposing" data-tags="vulnerabilities actively-exploited cisa-kev pre-auth auth-bypass cloud ai-abuse" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-04T05:00:03Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-42208/">CVE-2026-42208</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-42208-litellm-proxy-pre-auth-sql-injection-exposing"><a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-42208-litellm-proxy-pre-auth-sql-injection-exposing/">CVE-2026-42208 LiteLLM Proxy — pre-auth SQL injection exposing upstream LLM-provider API keys at the multi-tenant SaaS layer</a></h3><p><strong>If you did nothing this week:</strong> in-the-wild exploitation began within approximately 36 hours of the GitHub Security Advisory (GHSA-r75f-5x8p-qvmc) publication per Bishop Fox. Any LiteLLM Proxy instance that was internet-accessible during that window should be treated as having had its credential tables read. Patching to v1.83.7+ does not remediate pre-patch credential exposure — every upstream API key (OpenAI, Anthropic, Azure OpenAI, Cohere, every other configured provider) stored in the proxy database must be rotated (<a href="https://bishopfox.com/blog/cve-2026-42208-pre-authentication-sql-injection-in-litellm-proxy" target="_blank" rel="noopener noreferrer">Bishop Fox — CVE-2026-42208 technical analysis, 2026-05-06</a> · <a href="https://docs.litellm.ai/blog/cve-2026-42208-litellm-proxy-sql-injection" target="_blank" rel="noopener noreferrer">LiteLLM vendor advisory, 2026-04-29</a>). CISA KEV deadline 2026-05-11 (Monday).</p>
<p>The flaw is an f-string SQL injection in the <code>PrismaClient.get_data()</code> method: the caller-supplied <code>Authorization: Bearer &lt;token&gt;</code> value is interpolated directly into a PostgreSQL query string rather than passed as a parameterised argument. An unauthenticated attacker sends a crafted token to any LLM API route (e.g., <code>POST /v1/chat/completions</code>) and performs blind time-based injection via <code>pg_sleep()</code> against the <code>LiteLLM_VerificationToken</code> table (Bishop Fox&#39;s named example) — alongside the proxy&#39;s virtual-key, upstream-provider-credential, team-binding, and rate-limit configuration tables. On default deployments where the application database user holds superuser rights, the primitive is full read/write across the database (CWE-89, CVSS 9.3, <a href="https://attack.mitre.org/techniques/T1190/" target="_blank" rel="noopener noreferrer">T1190 Exploit Public-Facing Application</a>, <a href="https://attack.mitre.org/techniques/T1552/001/" target="_blank" rel="noopener noreferrer">T1552.001 Credentials in Files</a>).</p>
<p>The architectural lesson connects directly to the <strong>Braintrust AWS account compromise</strong> disclosed 2026-05-06 (: AI-evaluation, AI-observability, and AI-gateway SaaS platforms aggregate organisation-level upstream-provider credentials for many tenants per vendor, so a single SaaS-tier compromise propagates into a multi-provider credential event for every downstream tenant. EU public-sector AI pilots running through LiteLLM or any similar gateway should inventory which provider keys are held by which SaaS vendor; require per-environment scoping (dev / staging / prod) with short TTLs; enable provider-side anomaly alerts for unusual call-volume or geographic-origin shifts. Patching path: <code>pip install --upgrade litellm</code> to ≥ 1.83.7 or pull the updated container image.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: in-the-wild exploitation began within approximately 36 hours of the GitHub Security Advisory (GHSA-r75f-5x8p-qvmc) publication per Bishop Fox.</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/cve-2026-42208-litellm-proxy-pre-auth-sql-injection-exposing/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://bishopfox.com/blog/cve-2026-42208-pre-authentication-sql-injection-in-litellm-proxy" target="_blank" rel="noopener noreferrer">Bishop Fox — CVE-2026-42208 technical analysis</a> · <a href="https://docs.litellm.ai/blog/cve-2026-42208-litellm-proxy-sql-injection" target="_blank" rel="noopener noreferrer">LiteLLM vendor advisory</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/cve-2026-31431-copy-fail-cve-2026-43284-cve-2026-43500-dirty" data-tags="vulnerabilities actively-exploited cisa-kev lpe poc-public" data-regions="global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-04T05:00:02Z"><div class="badges"><span class="b pri">HIGH</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-31431/">CVE-2026-31431 +2</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-31431-copy-fail-cve-2026-43284-cve-2026-43500-dirty"><a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-31431-copy-fail-cve-2026-43284-cve-2026-43500-dirty/">CVE-2026-31431 &quot;Copy Fail&quot; + CVE-2026-43284 / CVE-2026-43500 &quot;Dirty Frag&quot; — Linux kernel LPE pair confirmed in complementary post-compromise campaigns</a></h3><p><strong>If you did nothing this week:</strong> Microsoft Security Blog observed active campaigns deploying both Linux LPE families post-compromise; the daily 2026-05-09 UPDATE synthesised the operator-side selection logic as Copy Fail (<code>algif_aead</code> page-cache write) used on hosts where the module is available, Dirty Frag (xfrm-ESP and RxRPC page-cache writes) on hosts where user namespaces are enabled without <code>algif_aead</code>. Microsoft documents the same initial-access vector (SSH credential stuffing on exposed management ports) feeding both chains, and both defeat conventional on-disk file-integrity monitoring because the write lands in the kernel page cache rather than on disk (<a href="https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/" target="_blank" rel="noopener noreferrer">Microsoft Security Blog, 2026-05-08</a> · <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09 update</a>).</p>
<p>Copy Fail (CVE-2026-31431, CVSS 7.8) is deterministic — no kernel-version offsets, no timing windows. A public 732-byte Python exploit exists; Go and Rust reimplementations have appeared in public code repositories; Kaspersky validated the container-to-host escape vector on Docker / LXC / Kubernetes when <code>algif_aead</code> is loaded on the host kernel (default on most distributions) (<a href="https://cert.europa.eu/publications/security-advisories/2026-005/" target="_blank" rel="noopener noreferrer">CERT-EU Advisory 2026-005, 2026-04-30</a> · <a href="https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/" target="_blank" rel="noopener noreferrer">Unit 42 — Copy Fail</a> · <a href="https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1232" target="_blank" rel="noopener noreferrer">BSI WID-SEC-2026-1232</a> · <a href="https://ctipilot.ch/briefs/2026-05-06/" target="_blank" rel="noopener noreferrer">daily 2026-05-06 deep dive</a>). Dirty Frag chains CVE-2026-43284 (xfrm-ESP / IPsec) with CVE-2026-43500 (RxRPC) into another deterministic root primitive via page-cache write primitives in both subsystems; researcher Hyunwoo Kim disclosed it 2026-05-07/08 after a third party reverse-engineered the upstream patch and broke embargo. CVE-2026-43500 distro patches remain pending at week-end (<a href="https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc" target="_blank" rel="noopener noreferrer">Wiz Research, 2026-05-08</a> · <a href="https://access.redhat.com/security/vulnerabilities/RHSB-2026-003" target="_blank" rel="noopener noreferrer">Red Hat RHSB-2026-003</a> · <a href="https://ubuntu.com/blog/dirty-frag-linux-vulnerability-fixes-available" target="_blank" rel="noopener noreferrer">Ubuntu — Dirty Frag fixes-available</a> · <a href="https://security-hub.ncsc.admin.ch/api/posts/12547/details" target="_blank" rel="noopener noreferrer">NCSC-CH 12547</a> · <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09</a>). Both map to <a href="https://attack.mitre.org/techniques/T1068/" target="_blank" rel="noopener noreferrer">T1068 Exploitation for Privilege Escalation</a> and <a href="https://attack.mitre.org/techniques/T1548/001/" target="_blank" rel="noopener noreferrer">T1548.001 Setuid and Setgid Abuse</a>. Defenders should treat file-integrity monitoring as insufficient detection for either family — runtime detection lands on <code>auditd execve</code> of <code>/usr/bin/su</code> / <code>/usr/bin/sudo</code> / <code>/usr/bin/passwd</code> from anomalous parent processes, EDR process-ancestry rules for root from non-root contexts, and (for Copy Fail specifically) eBPF or EDR alerts on <code>AF_ALG</code> socket creation in container namespaces.</p>
<p>Mitigation hierarchy when patches are not yet deployable: kernel patches first (Ubuntu 6.1.98-1ubuntu1, RHEL kernel-5.14.0-503.14.1, Debian 12 pending at week-end; upstream 6.18.22 / 6.19.12 / 7.0 for Copy Fail); blacklist <code>algif_aead</code> via <code>modprobe.d</code> and <code>update-initramfs -u</code>; <code>modprobe -r esp4 esp6 rxrpc</code> for Dirty Frag (breaks IPsec VPNs and AFS); seccomp profiles blocking <code>AF_ALG</code> socket creation for containerised workloads; disable unprivileged user namespaces (<code>sysctl kernel.unprivileged_userns_clone=0</code> on Ubuntu / Debian, <code>user.max_user_namespaces=0</code> on RHEL) to remove CAP_NET_ADMIN as a default acquisition path for Dirty Frag.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">If you did nothing this week: Microsoft Security Blog observed active campaigns deploying both Linux LPE families post-compromise; the daily 2026-05-09 UPDATE synthesised the operator-side selection logic as Copy Fail (algif_aead page-cache write) used on hosts where the module is available, Dirty …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/cve-2026-31431-copy-fail-cve-2026-43284-cve-2026-43500-dirty/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/" target="_blank" rel="noopener noreferrer">Microsoft Security Blog — Active attack Dirty Frag</a> · <a href="https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc" target="_blank" rel="noopener noreferrer">Wiz Research — Dirty Frag</a> · <a href="https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/" target="_blank" rel="noopener noreferrer">Unit 42 — Copy Fail</a> · <a href="https://cert.europa.eu/publications/security-advisories/2026-005/" target="_blank" rel="noopener noreferrer">CERT-EU 2026-005</a></div></article><div class="sect" id="multi-day-campaigns-and-chains"><span class="n">02</span><span class="t">Multi-day campaigns and chains</span><span class="c">4 items</span></div><article class="finding entry-card" data-entry-id="2026-05-04/canvas-instructure-breach-five-day-arc-from-first-claim-to-s" data-tags="data-breach ransomware organized-crime supply-chain" data-regions="europe uk global" data-kind="synthesis" data-priority="high" data-discovered="2026-05-04T05:00:07Z"><div class="badges"><span class="b pri">HIGH</span></div><h3 class="f-h" id="canvas-instructure-breach-five-day-arc-from-first-claim-to-s"><a href="https://ctipilot.ch/entries/2026-05-04/canvas-instructure-breach-five-day-arc-from-first-claim-to-s/">Canvas / Instructure breach — five-day arc from first claim to seven Dutch universities executing emergency disconnects</a></h3><p>Canvas / Instructure is the cleanest example of a campaign chain that accumulated meaningfully different state every day of 2026-W19, and the one a SOC manager carries into Monday morning with an extortion deadline two days out. Day-by-day: <strong>2026-05-06</strong> — Instructure confirmed names, email addresses, student ID numbers, and user-to-user messages accessed; detected API-tool disruption ~2026-04-30; revoked privileged credentials and access tokens; passwords / financial data / government IDs out of scope; ShinyHunters claimed 275 M records across ~9,000 institutions including EU and APAC (<a href="https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-05-04</a> · <a href="https://techcrunch.com/2026/05/05/hackers-steal-students-data-during-breach-at-education-tech-giant-instructure/" target="_blank" rel="noopener noreferrer">TechCrunch, 2026-05-05</a> · <a href="https://www.securityweek.com/edtech-firm-instructure-discloses-data-breach/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-05-04</a> · <a href="https://ctipilot.ch/briefs/2026-05-06/" target="_blank" rel="noopener noreferrer">daily 2026-05-06</a>). <strong>2026-05-07</strong> — individual universities (University of Nevada Reno, University of Pennsylvania ~300,000+ users) began notifying students and staff directly (<a href="https://www.unr.edu/nevada-today/news/president-messages/2026-05-06-cybersecurity-incident" target="_blank" rel="noopener noreferrer">University of Nevada Reno president message, 2026-05-06</a> · <a href="https://ctipilot.ch/briefs/2026-05-07/" target="_blank" rel="noopener noreferrer">daily 2026-05-07 UPDATE</a>). <strong>2026-05-08</strong> — SURF (Dutch NREN) confirmed 44 Dutch institutions among victims; attacker posted portal defacements; 2026-05-12 extortion deadline set; Canvas taken offline for emergency patching on 2026-05-07 (<a href="https://nltimes.nl/2026/05/05/canvas-hack-student-data-44-dutch-universities-schools-taken-massive-breach" target="_blank" rel="noopener noreferrer">NL Times — Canvas hack: student data from 44 Dutch universities and schools taken</a> · <a href="https://thenextweb.com/news/the-largest-education-data-breach-in-history-was-not-an-attack-on-a-school-it-was-an-attack-on-a-vendor" target="_blank" rel="noopener noreferrer">The Next Web — largest education data breach in history</a> · <a href="https://ctipilot.ch/briefs/2026-05-08/" target="_blank" rel="noopener noreferrer">daily 2026-05-08 UPDATE</a>). <strong>2026-05-09</strong> — three major UK universities (Oxford, Cambridge, Liverpool — Liverpool notified ICO under GDPR Article 33) issued public statements; UNL confirmed 44 Dutch member institutions; 3 GB sample dump on 2026-05-07 contained course-IDs, student emails, assignment metadata, grade records across four UK institutions; Instructure stated the breach vector was a compromised integration service account for a third-party LTI tool provider (not Canvas core infrastructure). The ShinyHunters / WorldLeaks operator-family attribution and the specific extortion-amount figure carried in the daily UPDATE trace to sources not re-fetched at weekly composition time; readers should consult the daily UPDATE for the citation chain (<a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09 UPDATE</a>). <strong>2026-05-10</strong> — ShinyHunters posted a <em>second</em> intrusion notice 2026-05-08 asserting Canvas retained unpatched vulnerabilities permitting re-entry despite the May 8 patches; Instructure confirmed the second breach, rotated application keys, increased monitoring, and required API-client re-authorisation; seven Dutch universities (<strong>VU Amsterdam, University of Amsterdam, Erasmus Rotterdam, Tilburg, Eindhoven TU/e, Maastricht, Twente</strong>) executed emergency Canvas disconnections on/before 2026-05-09; Dutch DPA (Autoriteit Persoonsgegevens) received an incident report from VU Amsterdam (<a href="https://www.techzine.eu/news/security/141149/dutch-university-disconnects-canvas-systems-after-instructure-hack/" target="_blank" rel="noopener noreferrer">Techzine EU, 2026-05-08</a> · <a href="https://www.dutchnews.nl/2026/05/hackers-break-into-ed-tech-giant-again-after-massive-data-heist/" target="_blank" rel="noopener noreferrer">DutchNews.nl, 2026-05-08</a> · <a href="https://ctipilot.ch/briefs/2026-05-10/" target="_blank" rel="noopener noreferrer">daily 2026-05-10 UPDATE</a>).</p>
<p>State at week-end: <strong>2026-05-12 extortion deadline is Tuesday (two days out)</strong>; no ransom paid as of 2026-05-09 06:00 UTC; if the second-intrusion claim verifies, Instructure&#39;s remediation was incomplete and the data-release threat is materially more credible. European universities running Canvas should treat credential-stuffing risk on stolen student / staff emails as active; audit third-party LTI integrations and revoke service accounts for unused integrations; watch for follow-on phishing campaigns referencing course content. GDPR Article 33/34 notification clocks run from the date Instructure provided scope confirmation to the institution.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/canvas-instructure-breach-five-day-arc-from-first-claim-to-s/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/" target="_blank" rel="noopener noreferrer">BleepingComputer — Instructure Canvas data breach</a> · <a href="https://www.techzine.eu/news/security/141149/dutch-university-disconnects-canvas-systems-after-instructure-hack/" target="_blank" rel="noopener noreferrer">Techzine EU — Dutch university disconnects</a> · <a href="https://www.dutchnews.nl/2026/05/hackers-break-into-ed-tech-giant-again-after-massive-data-heist/" target="_blank" rel="noopener noreferrer">DutchNews.nl — Hackers break into ed-tech giant again</a> · <a href="https://nltimes.nl/2026/05/05/canvas-hack-student-data-44-dutch-universities-schools-taken-massive-breach" target="_blank" rel="noopener noreferrer">NL Times — Canvas hack: student data from 44 Dutch universities and schools taken</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/cl-sta-1132-pan-os-cve-2026-0300-exploitation-cluster-disclo" data-tags="vulnerabilities actively-exploited cisa-kev nation-state rce pre-auth no-patch" data-regions="europe global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:08Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span></div><h3 class="f-h" id="cl-sta-1132-pan-os-cve-2026-0300-exploitation-cluster-disclo"><a href="https://ctipilot.ch/entries/2026-05-04/cl-sta-1132-pan-os-cve-2026-0300-exploitation-cluster-disclo/">CL-STA-1132 — PAN-OS CVE-2026-0300 exploitation cluster: disclosure-to-deadline-to-deadline-expiry inside the window</a></h3><p>The PAN-OS Captive Portal zero-day chain compressed an entire incident-response cycle into one ISO week. <strong>2026-05-06</strong> — Palo Alto disclosed CVE-2026-0300 (CVSS 9.3 unauthenticated root RCE); CERT-EU issued a rare Critical Advisory; CISA listed in KEV with deadline 2026-05-09; Unit 42 attributed active exploitation since 2026-04-09 to CL-STA-1132 and characterised it as likely state-sponsored (<a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto PSIRT, 2026-05-06</a> · <a href="https://cert.europa.eu/publications/security-advisories/2026-006/" target="_blank" rel="noopener noreferrer">CERT-EU 2026-006, 2026-05-06</a> · <a href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/" target="_blank" rel="noopener noreferrer">Unit 42, 2026-05-06</a> · <a href="https://ctipilot.ch/briefs/2026-05-07/" target="_blank" rel="noopener noreferrer">daily 2026-05-07 deep dive</a>). <strong>2026-05-08</strong> — KEV deadline announced as the next day; mitigation hardening (disable Captive Portal, restrict to internal CIDR, Threat ID 510019) repeated; daily flagged that organisations must confirm mitigation by today before close-of-business (<a href="https://ctipilot.ch/briefs/2026-05-08/" target="_blank" rel="noopener noreferrer">daily 2026-05-08</a>). <strong>2026-05-09</strong> — KEV deadline expired today, no patch exists; vendor confirmed earliest patches at 10.1.14 / 10.2.12 / 11.0.5 / 11.1.4 expected 2026-05-13; Unit 42 published post-exploitation cluster framing — rogue admin account name pattern <strong><code>svc-health-check-[6-digit-numeric]</code></strong>, Python tunnelling implants under <code>/var/tmp/linuxupdate</code> / <code>/tmp/.c</code>, OSPF-based internal AD reconnaissance; observed dwell time ~20 days from initial compromise to second-device exploitation on a tracked victim (<a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09 UPDATE</a>). <strong>2026-05-10</strong> — Unit 42 added EarthWorm / ReverseSocks5 tunnelling specificity (already adjacent to the prior framing; marginal delta over the cluster narrative).</p>
<p>The campaign-state lens a daily reader cannot see from one day: every organisation with an internet-facing PAN-OS Captive Portal that did not disable or restrict it during 2026-W19 is in the same posture on 2026-W20 — still no patch, still exposed, still inside CL-STA-1132&#39;s targeting window. Retrospective log review for the <strong><code>svc-health-check-</code></strong> account pattern, anomalous outbound from the firewall management IP, and unexpected nginx child processes back-to-back-to-back through 2026-04-09 is the highest-priority hunting action for the new week. ATT&amp;CK profile: <a href="https://attack.mitre.org/techniques/T1190/" target="_blank" rel="noopener noreferrer">T1190</a>, <a href="https://attack.mitre.org/techniques/T1055/" target="_blank" rel="noopener noreferrer">T1055</a>, <a href="https://attack.mitre.org/techniques/T1003/" target="_blank" rel="noopener noreferrer">T1003</a>, <a href="https://attack.mitre.org/techniques/T1572/" target="_blank" rel="noopener noreferrer">T1572</a>, <a href="https://attack.mitre.org/techniques/T1018/" target="_blank" rel="noopener noreferrer">T1018 Remote System Discovery</a>.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/cl-sta-1132-pan-os-cve-2026-0300-exploitation-cluster-disclo/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto PSIRT — CVE-2026-0300</a> · <a href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/" target="_blank" rel="noopener noreferrer">Unit 42 — Captive Portal zero-day</a> · <a href="https://cert.europa.eu/publications/security-advisories/2026-006/" target="_blank" rel="noopener noreferrer">CERT-EU Critical Advisory 2026-006</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/shinyhunters-worldleaks-week-long-cross-incident-operator-ac" data-tags="data-breach organized-crime supply-chain cloud identity" data-regions="europe us global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:06Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="shinyhunters-worldleaks-week-long-cross-incident-operator-ac"><a href="https://ctipilot.ch/entries/2026-05-04/shinyhunters-worldleaks-week-long-cross-incident-operator-ac/">ShinyHunters / WorldLeaks — week-long cross-incident operator activity touching Inditex, Vimeo, ADT, and Instructure / Canvas</a></h3><p>The cross-day pattern most visible in 2026-W19 is the ShinyHunters / WorldLeaks operator family&#39;s role in four parallel third-party / SaaS-tier compromises with European footprint, all riding the <strong>third-party-analytics → cloud-data-warehouse → tenant-data-exfiltration</strong> pivot rather than direct attack on the victim&#39;s infrastructure. The sequence: <strong>Vimeo / Anodot</strong> (first covered 2026-05-07) — Vimeo&#39;s official statement confirmed customer email addresses were affected via a third-party security incident involving Anodot, an analytics vendor integrated with Vimeo&#39;s infrastructure; the Snowflake-and-BigQuery cloud-data-warehouse pivot is attributed to ShinyHunters&#39; extortion claim per BleepingComputer (not Vimeo&#39;s own confirmation); BleepingComputer reports approximately 119,000 email addresses exposed; ShinyHunters published the dataset after Vimeo declined extortion (<a href="https://vimeo.com/blog/post/anodot-third-party-security-incident" target="_blank" rel="noopener noreferrer">Vimeo official blog, 2026-04-27</a> · <a href="https://www.bleepingcomputer.com/news/security/video-service-vimeo-confirms-anodot-breach-exposed-user-data/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-05-06</a> · <a href="https://www.theregister.com/2026/05/05/shinyhunters_dump_puts_119k_vimeo/" target="_blank" rel="noopener noreferrer">The Register, 2026-05-05</a>). <strong>Inditex (Zara)</strong> (first covered 2026-05-09) — Have I Been Pwned confirmed 197,400 EU customer email addresses exposed via the same Anodot → BigQuery pivot; Inditex confirmed access to email, geographic location, order IDs, support ticket content; ShinyHunters dumped ~140 GB after Inditex declined (<a href="https://securityaffairs.com/191859/cyber-crime/zara-data-breach-197000-customers-exposed-in-third-party-security-incident.html" target="_blank" rel="noopener noreferrer">SecurityAffairs, 2026-05-08</a> · <a href="https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-05-08</a> · <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09</a>). <strong>ADT Inc.</strong> (first covered 2026-05-06) — SEC 8-K filed 2026-04-24 disclosed unauthorised access to certain cloud environments; ShinyHunters claimed the initial-access vector was vishing on an employee Okta SSO account followed by Salesforce data exfiltration (ADT did not confirm the vector) (<a href="https://newsroom.adt.com/corporate-news/adt-detects-cybersecurity-incident" target="_blank" rel="noopener noreferrer">ADT Newsroom, 2026-04-24</a> · <a href="https://ctipilot.ch/briefs/2026-05-06/" target="_blank" rel="noopener noreferrer">daily 2026-05-06</a>). <strong>Instructure / Canvas</strong> (first covered 2026-05-06; expanded each subsequent day — see separate H3 below).</p>
<p>The lesson under PD-11 (less is more) for Swiss / EU public-sector readers: third-party analytics, monitoring, evaluation, and observability integrations holding OAuth or service-account access to production data warehouses (Snowflake, BigQuery, Redshift) are a structural supply-chain attack surface that vendor-assessment checklists routinely miss. Audit delegated access grants for analytics tooling; enforce token scoping and expiry; require provider-side anomaly alerts; and treat any tenant-to-tenant credential propagation pattern (the four incidents above are all that pattern) as warranting a tabletop on revocation timing — Vimeo revoked privileged credentials and access tokens within hours of detection, which is the right reference performance.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/shinyhunters-worldleaks-week-long-cross-incident-operator-ac/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://vimeo.com/blog/post/anodot-third-party-security-incident" target="_blank" rel="noopener noreferrer">Vimeo official blog — Anodot incident</a> · <a href="https://securityaffairs.com/191859/cyber-crime/zara-data-breach-197000-customers-exposed-in-third-party-security-incident.html" target="_blank" rel="noopener noreferrer">SecurityAffairs — Zara breach</a> · <a href="https://www.bleepingcomputer.com/news/security/video-service-vimeo-confirms-anodot-breach-exposed-user-data/" target="_blank" rel="noopener noreferrer">BleepingComputer — Vimeo Anodot</a> · <a href="https://newsroom.adt.com/corporate-news/adt-detects-cybersecurity-incident" target="_blank" rel="noopener noreferrer">ADT Newsroom</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/cpanel-whm-two-emergency-tsrs-inside-ten-days-post-cve-2026" data-tags="vulnerabilities rce actively-exploited cisa-kev auth-bypass patch-available" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:09Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-29202/">CVE-2026-29202 +2</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cpanel-whm-two-emergency-tsrs-inside-ten-days-post-cve-2026"><a href="https://ctipilot.ch/entries/2026-05-04/cpanel-whm-two-emergency-tsrs-inside-ten-days-post-cve-2026/">cPanel / WHM — two emergency TSRs inside ten days: post-CVE-2026-41940 fleet now facing CVE-2026-29201/29202/29203</a></h3><p>cPanel / WHM saw two emergency Targeted Security Releases inside ten days, with the second arriving against a fleet that had not yet recovered from the first. <strong>CVE-2026-41940</strong> (CRLF cookie-forge unauthenticated bypass) drove mass exploitation from approximately 2026-02-23 through the emergency patch on 2026-04-28 — roughly two months of zero-day exposure during which Shadowserver telemetry estimated ~44,000 IP addresses likely compromised; multiple distinct threat-actor campaigns deployed payloads, including a &quot;Sorry&quot; Go-based Linux encryptor and AdaptixC2 against government and military entities (<a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/" target="_blank" rel="noopener noreferrer">watchTowr Labs</a> · <a href="https://www.rapid7.com/blog/post/etr-cve-2026-41940-cpanel-whm-authentication-bypass/" target="_blank" rel="noopener noreferrer">Rapid7 ETR</a> · <a href="https://www.helpnetsecurity.com/2026/05/04/multiple-threat-actors-actively-exploit-cpanel-vulnerability-cve-2026-41940/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-05-04</a> · <a href="https://ctipilot.ch/briefs/2026-05-06/" target="_blank" rel="noopener noreferrer">daily 2026-05-06 first coverage</a>). The second TSR landed 2026-05-08 with three CVEs initially under responsible-disclosure embargo (and dropped from § 3 of the daily that day for that reason); the embargo lifted 2026-05-09 with technical analyses from The Hacker News and Panelica (<a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09</a>, <a href="https://ctipilot.ch/briefs/2026-05-10/" target="_blank" rel="noopener noreferrer">daily 2026-05-10 UPDATE</a>).</p>
<p>The compounding pattern is what makes this a multi-day-chain entry: cPanel hosts that recovered from the ~February–April CVE-2026-41940 wave now face fresh primitives — <strong>CVE-2026-29202</strong> (CVSS 8.8) is post-auth Perl execution in the <code>create_user</code> API (any authenticated cPanel user with API access can inject and execute arbitrary Perl code in their system account context); <strong>CVE-2026-29203</strong> (CVSS 8.8) is unsafe symlink handling enabling <code>chmod</code> abuse for privilege escalation or denial of service; <strong>CVE-2026-29201</strong> (CVSS 4.3) is arbitrary feature-file disclosure (<a href="https://thehackernews.com/2026/05/cpanel-whm-patch-3-new-vulnerabilities.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-05-09</a> · <a href="https://security-hub.ncsc.admin.ch/api/posts/12550/details" target="_blank" rel="noopener noreferrer">NCSC-CH 12550, 2026-05-08</a> · <a href="https://panelica.com/blog/cpanel-cve-2026-29201-29202-29203-may-2026-tsr-advisory" target="_blank" rel="noopener noreferrer">Panelica, 2026-05-08</a>). An attacker who used CVE-2026-41940 to obtain unauthenticated cPanel access can pivot to CVE-2026-29202 to escalate privilege or persist inside the same compromised host. No confirmed in-the-wild exploitation of the second batch at week-end, but the population of unpatched hosts overlaps materially with the recovering CVE-2026-41940 fleet. Patch path: cPanel/WHM patched builds <strong>11.136.0.9+</strong>, <strong>11.134.0.25+</strong>, <strong>11.132.0.31+</strong>; operators with auto-update disabled or version-pinned builds must run <code>/scripts/upcp</code> manually. European hosting providers and MSPs serving public-sector clients remain the structural exposure concentration.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/cpanel-whm-two-emergency-tsrs-inside-ten-days-post-cve-2026/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thehackernews.com/2026/05/cpanel-whm-patch-3-new-vulnerabilities.html" target="_blank" rel="noopener noreferrer">The Hacker News — cPanel/WHM patch 3 new vulnerabilities</a> · <a href="https://security-hub.ncsc.admin.ch/api/posts/12550/details" target="_blank" rel="noopener noreferrer">NCSC-CH Security Hub post 12550</a> · <a href="https://panelica.com/blog/cpanel-cve-2026-29201-29202-29203-may-2026-tsr-advisory" target="_blank" rel="noopener noreferrer">Panelica — cPanel CVE-2026-29201/29202/29203 advisory</a> · <a href="https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/" target="_blank" rel="noopener noreferrer">watchTowr Labs — CVE-2026-41940</a></div></article><div class="sect" id="vulnerability-roll-up"><span class="n">03</span><span class="t">Vulnerability roll-up</span><span class="c">2 items</span></div><article class="finding entry-card" data-entry-id="2026-05-04/cve-2026-32202-windows-shell-ntlm-coercion-akamai-s-patchdif" data-tags="vulnerabilities actively-exploited nation-state espionage cisa-kev patch-available russia-nexus" data-regions="europe global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-04T05:00:11Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-32202/">CVE-2026-32202 +1</a><span class="b exp">exploited</span></div><h3 class="f-h" id="cve-2026-32202-windows-shell-ntlm-coercion-akamai-s-patchdif"><a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-32202-windows-shell-ntlm-coercion-akamai-s-patchdif/">CVE-2026-32202 — Windows Shell NTLM coercion; Akamai&#39;s PatchDiff-AI shows the residual zero-click path left by the CVE-2026-21510 patch</a></h3><p>Despite the low base CVSS of 4.3 (network vector, no privileges, user interaction required), this is a priority-patch item for any organisation in scope of APT28&#39;s targeting of the predecessor vulnerability: <strong>APT28 (Fancy Bear)</strong> was attributed by CERT-UA to the predecessor <strong>CVE-2026-21510</strong> LNK exploitation against Ukraine and EU countries in December 2025 (<a href="https://www.akamai.com/blog/security-research/incomplete-patch-apt28s-zero-day-cve-2026-32202" target="_blank" rel="noopener noreferrer">Akamai Security Research</a>). Microsoft flipped the &quot;exploited&quot; flag on CVE-2026-32202 on 2026-04-27 (<a href="https://www.helpnetsecurity.com/2026/04/29/windows-cve-2026-32202-exploited/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-04-29</a>); neither Akamai nor Help Net Security explicitly attributes current CVE-2026-32202 in-the-wild exploitation to APT28, so the actor for CVE-2026-32202 exploitation specifically remains publicly unattributed at week-end (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202" target="_blank" rel="noopener noreferrer">Microsoft MSRC — CVE-2026-32202</a> · <a href="https://ctipilot.ch/briefs/2026-05-08/" target="_blank" rel="noopener noreferrer">daily 2026-05-08</a>). Akamai&#39;s PatchDiff-AI analysis published 2026-04-23 reveals that Microsoft&#39;s February 2026 patch for <strong>CVE-2026-21510</strong> successfully blocked RCE and SmartScreen bypass but left a residual zero-click NTLM coercion path intact — now tracked as CVE-2026-32202 (<a href="https://www.akamai.com/blog/security-research/incomplete-patch-apt28s-zero-day-cve-2026-32202" target="_blank" rel="noopener noreferrer">Akamai Security Research, 2026-04-23</a> · <a href="https://www.helpnetsecurity.com/2026/04/29/windows-cve-2026-32202-exploited/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-04-29</a>).</p>
<p>The mechanism: Windows Explorer automatically resolves UNC paths embedded in the <code>LinkTargetIDList</code> structure of malicious LNK files via <code>PathFileExistsW</code>, triggering an outbound SMB authentication handshake that leaks the user&#39;s Net-NTLMv2 hash to an attacker-controlled server — <strong>folder-open is sufficient, no user click required</strong>. Trust verification was applied only during <code>ShellExecuteExW</code> calls in the February 2026 patch, not in the earlier code paths where the credential theft occurs. Microsoft confirmed active exploitation on 2026-04-27 and CISA added CVE-2026-32202 to KEV the following day with a deadline of 2026-05-12. The April 14 patch shipped without the &quot;exploited&quot; flag, creating a 13-day window where security teams had no formal signal to treat it as urgent. Net-NTLMv2 hashes can be relayed (NTLM relay attacks) or cracked offline — both paths to lateral movement.</p>
<p>Patch path: April 2026 Windows cumulative updates. Supplementary controls are blocking outbound TCP 445 to non-business internet destinations at the perimeter firewall, enabling the &quot;Restrict NTLM&quot; Group Policy (set to &quot;Deny all&quot; for outbound), and migrating authentication to Kerberos-only where operationally feasible. Detection priorities for SOC hunting: SMBv2 outbound connections from <code>explorer.exe</code> to non-corporate IPs; NTLM authentication event 4625 / 4776 with Net-NTLMv2 from workstations; LNK file inspection at mail gateway and EDR for <code>LinkTargetIDList</code> entries pointing to UNC paths. ATT&amp;CK: <a href="https://attack.mitre.org/techniques/T1187/" target="_blank" rel="noopener noreferrer">T1187 Forced Authentication</a>, <a href="https://attack.mitre.org/techniques/T1557/001/" target="_blank" rel="noopener noreferrer">T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay</a>.</p><div class="entry-cites" role="group" aria-label="Quoted from the reporting"><figure class="entry-cite"><p class="entry-cite__quote">Despite the low base CVSS of 4.3 (network vector, no privileges, user interaction required), this is a priority-patch item for any organisation in scope of APT28&#39;s targeting of the predecessor vulnerability: APT28 (Fancy Bear) was attributed by CERT-UA to the predecessor CVE-2026-21510 LNK …</p><figcaption class="entry-cite__attr">ctipilot v2 brief (migrated)</figcaption></figure></div><div class="prov"><span>vulnerability</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/cve-2026-32202-windows-shell-ntlm-coercion-akamai-s-patchdif/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.akamai.com/blog/security-research/incomplete-patch-apt28s-zero-day-cve-2026-32202" target="_blank" rel="noopener noreferrer">Akamai Security Research — Incomplete Patch APT28 CVE-2026-32202</a> · <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202" target="_blank" rel="noopener noreferrer">Microsoft MSRC — CVE-2026-32202</a> · <a href="https://www.helpnetsecurity.com/2026/04/29/windows-cve-2026-32202-exploited/" target="_blank" rel="noopener noreferrer">Help Net Security — Windows CVE-2026-32202 exploited</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/cve-2026-26030-cve-2026-25592-microsoft-semantic-kernel-pyth" data-tags="vulnerabilities rce poc-public patch-available ai-abuse cloud" data-regions="global" data-kind="vulnerability" data-priority="notable" data-discovered="2026-05-04T05:00:10Z"><div class="badges"><span class="b ">NOTABLE</span><a class="b cve" href="https://ctipilot.ch/cves/CVE-2026-26030/">CVE-2026-26030 +1</a></div><h3 class="f-h" id="cve-2026-26030-cve-2026-25592-microsoft-semantic-kernel-pyth"><a href="https://ctipilot.ch/entries/2026-05-04/cve-2026-26030-cve-2026-25592-microsoft-semantic-kernel-pyth/">CVE-2026-26030 + CVE-2026-25592 — Microsoft Semantic Kernel Python and .NET SDKs: a class-of-bug for agentic-AI frameworks</a></h3><p>The two Semantic Kernel CVEs are the highest-signal <em>new</em> CVE pair of the week even without confirmed in-the-wild exploitation: both flaws stem from a shared design weakness that <strong>an agent framework treats LLM-controlled values as input to executable abstractions without explicit validation at the boundary</strong>. The Python SDK flaw (CVE-2026-26030, CWE-94) interpolates an LLM-controlled parameter into the <code>InMemoryVectorStore</code> filter expression via f-string composition; a string-blocklist validator is bypassed by the canonical <code>&quot;&quot;.__class__.__bases__[0].__subclasses__()</code> class-hierarchy traversal pattern, yielding <code>subprocess.Popen</code>-equivalent execution on the agent process&#39;s host. A public PoC exists in the <code>amiteliahu/AIAgentCTF</code> GitHub repository per Microsoft&#39;s research post. The .NET SDK flaw (CVE-2026-25592, CWE-22 effectively a sandbox-escape) ships a stray <code>[KernelFunction]</code> attribute on <code>SessionsPythonPlugin.DownloadFileAsync</code> and <code>SessionsPythonPlugin.UploadFileAsync</code>; the LLM can therefore invoke those methods with attacker-chosen path arguments, yielding an arbitrary file write that breaks containment from the Azure Container Apps Python sessions sandbox onto the agent process&#39;s host filesystem (<a href="https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/" target="_blank" rel="noopener noreferrer">Microsoft Security Blog, 2026-05-07</a> · <a href="https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-xjw9-4gw8-4rqx" target="_blank" rel="noopener noreferrer">GitHub GHSA-xjw9-4gw8-4rqx</a> · <a href="https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-2ww3-72rp-wpp4" target="_blank" rel="noopener noreferrer">GitHub GHSA-2ww3-72rp-wpp4</a> · <a href="https://ctipilot.ch/briefs/2026-05-10/" target="_blank" rel="noopener noreferrer">daily 2026-05-10 deep dive</a>).</p>
<p>Both flaws bypass prompt-side mitigations (output filtering, response classifiers, &quot;let the LLM judge&quot;) because the dangerous operation occurs <em>inside the SDK</em>. The same class of bug is highly likely to exist in LangChain, CrewAI, AutoGen, Haystack, and LlamaIndex; defenders should not assume Semantic Kernel is uniquely affected. Patch path: Python SDK <strong>≥ 1.39.4</strong>, .NET SDK <strong>≥ 1.71.0</strong>; audit every <code>[KernelFunction]</code>-decorated method for parameter types that are paths, file handles, raw strings later interpolated into code, SQL fragments, or URLs, and remove the decorator from anything that does not need to be LLM-callable. ATT&amp;CK: <a href="https://attack.mitre.org/techniques/T1059/006/" target="_blank" rel="noopener noreferrer">T1059.006 Python</a>, <a href="https://attack.mitre.org/techniques/T1611/" target="_blank" rel="noopener noreferrer">T1611 Escape to Host</a>, <a href="https://attack.mitre.org/techniques/T1565/001/" target="_blank" rel="noopener noreferrer">T1565.001</a>, <a href="https://attack.mitre.org/techniques/T1005/" target="_blank" rel="noopener noreferrer">T1005 Data from Local System</a>.</p><div class="prov"><span>vulnerability</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/cve-2026-26030-cve-2026-25592-microsoft-semantic-kernel-pyth/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/" target="_blank" rel="noopener noreferrer">Microsoft Security Blog — Prompts become shells</a> · <a href="https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-xjw9-4gw8-4rqx" target="_blank" rel="noopener noreferrer">GitHub GHSA-xjw9-4gw8-4rqx</a> · <a href="https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-2ww3-72rp-wpp4" target="_blank" rel="noopener noreferrer">GitHub GHSA-2ww3-72rp-wpp4</a></div></article><div class="sect" id="sector-victim-patterns"><span class="n">04</span><span class="t">Sector &amp; victim patterns</span><span class="c">6 items</span></div><article class="finding entry-card" data-entry-id="2026-05-04/critical-infrastructure-water-pl" data-tags="nation-state hacktivism ot-ics actively-exploited russia-nexus disinformation" data-regions="europe" data-kind="synthesis" data-priority="high" data-discovered="2026-05-04T05:00:15Z"><div class="badges"><span class="b pri">HIGH</span><span class="b exp">exploited</span></div><h3 class="f-h" id="critical-infrastructure-water-pl"><a href="https://ctipilot.ch/entries/2026-05-04/critical-infrastructure-water-pl/">Critical infrastructure water (PL)</a></h3><p>Five Polish municipal water-treatment facilities (Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, Sierakowo) had their OT networks penetrated with pump control parameters modified; manual override at at least one site prevented service disruption (<a href="https://ctipilot.ch/briefs/2026-05-08/" target="_blank" rel="noopener noreferrer">daily 2026-05-08</a>). The ABW 2025 Annual Report (published 2026-05-07) formally attributed the campaign to <strong>APT28</strong> (GRU) and <strong>APT29</strong> (SVR), with <strong>UNC1151</strong> (Belarusian-linked, Ghostwriter cluster) named in the same attribution discussion (<a href="https://www.securityweek.com/polish-security-agency-reports-ics-breaches-at-five-water-treatment-plants/" target="_blank" rel="noopener noreferrer">SecurityWeek — Polish security agency reports ICS breaches at five water treatment plants</a> · <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09 UPDATE</a>) — materially more granular than the initial &quot;pro-Russian hacktivist&quot; framing. All five facilities were below the NIS2 essential-entity headcount threshold at intrusion time. Cross-cutting theme: small municipal CI operators sit below regulatory coverage but inside hostile-state targeting; Dragos&#39;s 8th annual OT YiR (§ 6) reinforces with 65 percent of assessed sites carrying insecure remote-access conditions and hidden IT/OT network paths surfacing during routine penetration tests. Swiss / EU water, energy, and utility operators should re-validate IT-OT segmentation and authentication posture on industrial-gateway and SCADA management interfaces as a direct action carried into 2026-W20.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/critical-infrastructure-water-pl/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.securityweek.com/polish-security-agency-reports-ics-breaches-at-five-water-treatment-plants/" target="_blank" rel="noopener noreferrer">SecurityWeek — Polish security agency reports ICS breaches at five water treatment plants</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/media-and-political-hu-de" data-tags="ransomware organized-crime data-breach" data-regions="europe dach" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:17Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="media-and-political-hu-de"><a href="https://ctipilot.ch/entries/2026-05-04/media-and-political-hu-de/">Media and political (HU, DE)</a></h3><p>Two European political / media targets in the week: <strong>Mediaworks Kft (Hungary)</strong> — World Leaks claimed 8.5 TB of exfiltrated data including payroll, contracts, and internal editorial communications; Mediaworks confirmed &quot;a significant amount of illegally obtained data may have come into the possession of unauthorized persons&quot;; no public regulator notification announcement at window close (<a href="https://therecord.media/ransomware-group-claims-breach-of-pro-orban-media-firm" target="_blank" rel="noopener noreferrer">The Record, 2026-05-04</a> · <a href="https://ctipilot.ch/briefs/2026-05-06/" target="_blank" rel="noopener noreferrer">daily 2026-05-06</a>). <strong>Die Linke (Germany)</strong> — German federal political party confirmed Qilin ransomware encryption and 1.5 TB exfiltration; state DPA notified; no public ransom figure (<a href="https://ctipilot.ch/briefs/2026-05-08/" target="_blank" rel="noopener noreferrer">heise online — covered in daily, 2026-05-08</a>). Two distinct operators (data-theft-only WorldLeaks versus encrypt-and-exfiltrate Qilin), shared targeting of politically significant European entities. The defender lesson: data-theft-only operators defeat backup-centric ransomware defences entirely — effective detection requires egress monitoring and data-loss-prevention tooling capable of alerting on large-volume exfiltration <em>before</em> the attacker goes public on a leak site.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/media-and-political-hu-de/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://therecord.media/ransomware-group-claims-breach-of-pro-orban-media-firm" target="_blank" rel="noopener noreferrer">The Record — Mediaworks claim</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/transport-nl-eu" data-tags="data-breach" data-regions="europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:16Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="transport-nl-eu"><a href="https://ctipilot.ch/entries/2026-05-04/transport-nl-eu/">Transport (NL/EU)</a></h3><p>Eurail began issuing breach notifications to <strong>308,777 customers</strong> in late April 2026, three months after the December 2025 incident in which an attacker accessed personal data including <strong>passport numbers, IBANs, and DiscoverEU pass details</strong>. The three-month gap between discovery and notification is under review by the Autoriteit Persoonsgegevens (Dutch DPA) and the European Data Protection Supervisor (EDPS), which holds jurisdiction over EU institutional data processing. GDPR Article 33 requires supervisory authority notification within 72 hours of awareness of a breach; the regulatory review focuses on that compliance gap (<a href="https://ctipilot.ch/briefs/2026-05-08/" target="_blank" rel="noopener noreferrer">daily 2026-05-08</a>). The exposed dataset covers EU member-state travellers who registered DiscoverEU passes; Swiss nationals who applied through bilateral arrangement may also be affected.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/transport-nl-eu/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/eurail-says-december-data-breach-impacts-300-000-individuals/" target="_blank" rel="noopener noreferrer">BleepingComputer — Eurail says December data breach impacts 300,000 individuals</a> · <a href="https://www.securityweek.com/traveler-information-stolen-in-eurail-data-breach/" target="_blank" rel="noopener noreferrer">SecurityWeek — Traveler information stolen in Eurail data breach</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/public-sector-administration-and-digital-identity-fr-eu-fi-c" data-tags="data-breach espionage insider-threat" data-regions="europe switzerland" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:14Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="public-sector-administration-and-digital-identity-fr-eu-fi-c"><a href="https://ctipilot.ch/entries/2026-05-04/public-sector-administration-and-digital-identity-fr-eu-fi-c/">Public-sector administration and digital identity (FR, EU, FI, CH)</a></h3><p>Public-sector administration concentration is unusually heavy in 2026-W19. <strong>France ANTS</strong> — Agence Nationale des Titres Sécurisés, the French government central identity registry (biometric passports, national identity cards, driving licences) — confirmed a data-records exposure that Help Net Security reports as &quot;between 12 and 18 million&quot; data records; 15-year-old suspect detained 2026-04-25; charges include unauthorised access, data theft, disruption of a state system, and possession of hacking tools (<a href="https://www.helpnetsecurity.com/2026/05/04/france-titres-data-breach-teen-suspect/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-05-04</a> · <a href="https://ctipilot.ch/briefs/2026-05-06/" target="_blank" rel="noopener noreferrer">daily 2026-05-06</a> · <a href="https://ctipilot.ch/briefs/2026-05-07/" target="_blank" rel="noopener noreferrer">daily 2026-05-07 UPDATE</a>). <strong>Ivanti EPMM named EU victims previously associated with the platform</strong> per Help Net Security&#39;s January-2026-wave reporting: European Commission (DG DIGIT), Dutch DPA, and Netherlands Council for the Judiciary (Help Net Security explicitly attributes those three to the January 2026 CVE-2026-1281/1340 wave, not the May 2026 chain). The daily 2026-05-09 also referenced Finnish Valtori per NCSC-FI advisory not in the Help Net Security article. Each named entity ran EPMM in MDM capacity, meaning compromised admin APIs had device-management access to enrolled endpoints of employees with elevated privileges. Whether the May 2026 wave caught additional named victims is not yet publicly disclosed at week-end (<a href="https://www.helpnetsecurity.com/2026/02/09/european-commission-ivanti-epmm-vulnerabilities/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-02-09</a> · <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09 UPDATE</a>). <strong>Europol shadow IT</strong> — Correctiv / Solomon / Computer Weekly joint investigation disclosed that Europol operated CFN (since 2012) and &quot;Pressure Cooker&quot; data-processing platforms holding ≥ 2 PB outside standard EU data-protection oversight for over a decade; multiple categorised security deficiencies identified in a 2019 internal assessment including absent audit logs; per Correctiv, 15 of 150 recommendations remained unimplemented at EDPS monitoring closure in February 2026 (<a href="https://correctiv.org/en/europe/2026/05/05/they-protect-the-law-while-breaking-it-inside-europols-shadow-it-system/" target="_blank" rel="noopener noreferrer">Correctiv, 2026-05-05</a> · <a href="https://www.computerweekly.com/news/366642525/They-protect-the-law-while-breaking-it-Inside-Europols-shadow-IT-system" target="_blank" rel="noopener noreferrer">Computer Weekly</a> · <a href="https://ctipilot.ch/briefs/2026-05-07/" target="_blank" rel="noopener noreferrer">daily 2026-05-07</a>). <strong>Polish water OT</strong> intrusions at five small municipal facilities (covered in § 7) round out the public-sector concentration. The cross-cutting theme is that EU public-sector identity, governance, and small-municipal infrastructure are simultaneously under direct attack, governance review, and structural-coverage-gap pressure — and that the institutional response cycle inside EU public-sector entities is now playing out in real time across all three.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/public-sector-administration-and-digital-identity-fr-eu-fi-c/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.helpnetsecurity.com/2026/05/04/france-titres-data-breach-teen-suspect/" target="_blank" rel="noopener noreferrer">Help Net Security — France ANTS</a> · <a href="https://correctiv.org/en/europe/2026/05/05/they-protect-the-law-while-breaking-it-inside-europols-shadow-it-system/" target="_blank" rel="noopener noreferrer">Correctiv — Europol shadow IT</a> · <a href="https://www.computerweekly.com/news/366642525/They-protect-the-law-while-breaking-it-Inside-Europols-shadow-IT-system" target="_blank" rel="noopener noreferrer">Computer Weekly — Europol shadow IT</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/education-nl-uk-de" data-tags="data-breach ransomware organized-crime" data-regions="europe uk" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:13Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="education-nl-uk-de"><a href="https://ctipilot.ch/entries/2026-05-04/education-nl-uk-de/">Education (NL, UK, DE)</a></h3><p>Education saw the week&#39;s clearest cross-jurisdiction concentration via the Canvas / Instructure chain (full multi-day arc in § 2): <strong>44 Dutch institutions</strong> confirmed by SURF; <strong>seven Dutch universities</strong> (VU Amsterdam, UvA, Erasmus Rotterdam, Tilburg, TU/e, Maastricht, Twente) executed emergency Canvas disconnects on/before 2026-05-09 after the second-intrusion claim; three major UK universities (Oxford, Cambridge, Liverpool — Liverpool notified the ICO under GDPR Article 33); Dutch DPA opened a preliminary investigation; UK ICO informed. The vector — a compromised integration service account for a third-party LTI tool provider rather than Canvas core infrastructure — connects the education-sector picture directly to the third-party-credentials supply-chain class also visible in Vimeo/Anodot and Zara/Anodot (<a href="https://thenextweb.com/news/the-largest-education-data-breach-in-history-was-not-an-attack-on-a-school-it-was-an-attack-on-a-vendor" target="_blank" rel="noopener noreferrer">The Next Web — largest education data breach in history</a> · <a href="https://nltimes.nl/2026/05/05/canvas-hack-student-data-44-dutch-universities-schools-taken-massive-breach" target="_blank" rel="noopener noreferrer">NL Times — Canvas hack: 44 Dutch universities and schools</a> · <a href="https://www.techzine.eu/news/security/141149/dutch-university-disconnects-canvas-systems-after-instructure-hack/" target="_blank" rel="noopener noreferrer">Techzine EU</a> · <a href="https://ctipilot.ch/briefs/2026-05-10/" target="_blank" rel="noopener noreferrer">daily 2026-05-10</a>).</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/education-nl-uk-de/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://thenextweb.com/news/the-largest-education-data-breach-in-history-was-not-an-attack-on-a-school-it-was-an-attack-on-a-vendor" target="_blank" rel="noopener noreferrer">The Next Web — largest education data breach in history</a> · <a href="https://nltimes.nl/2026/05/05/canvas-hack-student-data-44-dutch-universities-schools-taken-massive-breach" target="_blank" rel="noopener noreferrer">NL Times — Canvas hack: 44 Dutch universities and schools</a> · <a href="https://www.techzine.eu/news/security/141149/dutch-university-disconnects-canvas-systems-after-instructure-hack/" target="_blank" rel="noopener noreferrer">Techzine EU</a> · <a href="https://www.dutchnews.nl/2026/05/hackers-break-into-ed-tech-giant-again-after-massive-data-heist/" target="_blank" rel="noopener noreferrer">DutchNews.nl</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/healthcare-ch-nl" data-tags="ransomware data-breach organized-crime" data-regions="switzerland europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:12Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="healthcare-ch-nl"><a href="https://ctipilot.ch/entries/2026-05-04/healthcare-ch-nl/">Healthcare (CH, NL)</a></h3><p>Two healthcare incidents define the sector picture this week, both with European public-sector concentration. <strong>Groupe 3R (Switzerland)</strong> — Akira leak-site listing on a Romandie medical-imaging operator running 20 centres across seven cantons; the operator confirmed publicly on 2026-04-30, will not pay ransom, and is operating with legacy examination data still inaccessible at week-end (<a href="https://www.groupe3r.ch/fr/information-importante-perturbation-de-nos-services-7268/" target="_blank" rel="noopener noreferrer">Groupe 3R victim statement</a> · <a href="https://ctipilot.ch/briefs/2026-05-10/" target="_blank" rel="noopener noreferrer">daily 2026-05-10</a>). <strong>ChipSoft (Netherlands)</strong> — The 7 April 2026 attack on the Dutch healthcare software vendor — whose HiX platform serves roughly 70% of Dutch hospitals — was first reported with attacker identity unknown (<a href="https://therecord.media/chipsoft-ransomware-attack-disrupts-dutch-hospitals" target="_blank" rel="noopener noreferrer">The Record, 2026-04-09</a>); the <strong>Embargo</strong> ransomware group&#39;s claim of responsibility, alongside the 66 Dutch DPA notifications, was reported in the subsequent NL Times follow-up. On 28–29 April ChipSoft stated the exfiltrated data had been destroyed in language Dutch security experts noted strongly implies a ransom was paid (ChipSoft did not confirm) (<a href="https://nltimes.nl/2026/04/29/chipsoft-hackers-destroyed-stolen-patient-data-leaks" target="_blank" rel="noopener noreferrer">NL Times, 2026-04-29</a> · <a href="https://ctipilot.ch/briefs/2026-05-07/" target="_blank" rel="noopener noreferrer">daily 2026-05-07</a>). Both incidents reinforce the same cross-finding pattern: ransomware operators&#39; claims of data destruction are inherently unverifiable; GDPR breach-notification obligations and long-term breach-response posture do not expire when an attacker says they deleted the copy.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/healthcare-ch-nl/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.groupe3r.ch/fr/information-importante-perturbation-de-nos-services-7268/" target="_blank" rel="noopener noreferrer">Groupe 3R victim statement</a> · <a href="https://therecord.media/chipsoft-ransomware-attack-disrupts-dutch-hospitals" target="_blank" rel="noopener noreferrer">The Record — ChipSoft</a> · <a href="https://nltimes.nl/2026/04/29/chipsoft-hackers-destroyed-stolen-patient-data-leaks" target="_blank" rel="noopener noreferrer">NL Times — ChipSoft destroyed claim</a></div></article><div class="sect" id="incidents-disclosures-recap"><span class="n">05</span><span class="t">Incidents &amp; disclosures recap</span><span class="c">6 items</span></div><article class="finding entry-card" data-entry-id="2026-05-04/german-lg-berlin-ii-ruling-apobank-liable-for-218-000-phishi" data-tags="phishing identity law-enforcement" data-regions="europe dach" data-kind="incident" data-priority="notable" data-discovered="2026-05-04T05:00:24Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="german-lg-berlin-ii-ruling-apobank-liable-for-218-000-phishi"><a href="https://ctipilot.ch/entries/2026-05-04/german-lg-berlin-ii-ruling-apobank-liable-for-218-000-phishi/">German LG Berlin II ruling — Apobank liable for €218,000+ phishing loss; PSD2 IP-analytics obligation clarified</a></h3><p>On 2026-04-22 the Landgericht Berlin II (Civil Chamber 38, case 38 O 293/25; not yet final pending appeal) ordered Deutsche Apotheker- und Ärztebank (Apobank) to reimburse €218,000+ in losses from a sophisticated phishing attack combining forged physical bank letters, manipulated online banking interfaces, and spoofed-number phone calls. The court rejected gross-negligence defences, finding the fraud too sophisticated to attribute to customer failure; critically, the ruling found the bank&#39;s fraud-detection systems failed to act on a clear anomaly visible in bank-side logs — the new device registration and first login originated from materially different IP addresses and ISPs. The court treated this as an obligation under Germany&#39;s PSD2 implementation: an IP-based behavioural analytics duty triggering a strong-customer-authentication challenge when registration and first-use IPs diverge (<a href="https://www.heise.de/news/Urteil-gegen-die-Apobank-Finanzinstitut-haftet-fuer-Phishing-Schaden-11288231.html" target="_blank" rel="noopener noreferrer">heise online, 2026-05-08</a> · <a href="https://www.anwalt.de/rechtstipps/phishing-ilex-rechtsanwaelte-erwirkt-haftung-der-apobank-269786.html" target="_blank" rel="noopener noreferrer">ilex Rechtsanwälte case summary</a> · <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">EU and Swiss financial-sector and public-sector digital-service providers should expect this trend of liability lines moving toward the service provider when fraud signals are <em>present in server-side telemetry but not acted on</em>. The defensive engineering implication is concrete: register-new-device and first-login IP / ISP comparison is now a regulatory expectation in PSD2 jurisdictions, not just a best-practice control.</div></aside><div class="prov"><span>incident</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/german-lg-berlin-ii-ruling-apobank-liable-for-218-000-phishi/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.heise.de/news/Urteil-gegen-die-Apobank-Finanzinstitut-haftet-fuer-Phishing-Schaden-11288231.html" target="_blank" rel="noopener noreferrer">heise online — Urteil gegen die Apobank</a> · <a href="https://www.anwalt.de/rechtstipps/phishing-ilex-rechtsanwaelte-erwirkt-haftung-der-apobank-269786.html" target="_blank" rel="noopener noreferrer">ilex Rechtsanwälte case summary</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/denic-de-dnssec-outage-3-5-h-registry-side-trust-failure-tra" data-tags="vulnerabilities dos eu-nexus" data-regions="europe dach" data-kind="incident" data-priority="notable" data-discovered="2026-05-04T05:00:23Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="denic-de-dnssec-outage-3-5-h-registry-side-trust-failure-tra"><a href="https://ctipilot.ch/entries/2026-05-04/denic-de-dnssec-outage-3-5-h-registry-side-trust-failure-tra/">DENIC .de DNSSEC outage — 3.5 h registry-side trust failure traced to keytag 33834 collision and an alerting-layer fire-without-page</a></h3><p>On 2026-05-05 starting approximately 19:30 UTC (per Cloudflare&#39;s recorded incident-start timestamp), DENIC (the .de registry) began distributing invalid DNSSEC signatures for the .de TLD, making .de TLD resolution fail across DNSSEC-validating resolvers for roughly 3.5 hours; Cloudflare&#39;s write-up describes potential impact on &quot;millions of domains&quot; without quantifying the count. The 2026-05-08 post-mortem confirmed the root cause: a code defect in DENIC&#39;s third-generation custom signing infrastructure (deployed April 2026 atop Knot DNS) generated <strong>three private key pairs all assigned the same Key Tag (33834)</strong> during a routine Zone-Signing-Key rotation, while only one corresponding public DNSKEY record was published to the zone. RRSIG records signed by the two unpublished keys were therefore unvalidatable; resolvers marked all .de delegations as &quot;Bogus&quot;, and the bogus NSEC3 trust path also took down resolution for non-DNSSEC-signed .de domains. Cloudflare deployed an RFC 7646 Negative Trust Anchor for its resolvers at 22:17 UTC — a roughly 2-hour-47-minute mitigation gap from the recorded incident start. Critically, DENIC notes the monitoring pipeline detected anomalous resolver behaviour but <strong>the alerting layer did not correctly forward the alerts</strong> — a fire-without-page failure. Knot DNS itself is not implicated; the bug was in DENIC&#39;s automation layer (<a href="https://blog.denic.de/analyse-des-dns-ausfalls-vom-5-mai-2026/" target="_blank" rel="noopener noreferrer">DENIC analysis blog, 2026-05-08</a> · <a href="https://blog.cloudflare.com/de-tld-outage-dnssec/" target="_blank" rel="noopener noreferrer">Cloudflare blog</a> · <a href="https://www.heise.de/news/DNS-Probleme-mit-de-Domains-DENIC-liefert-erste-Erklaerung-11288197.html" target="_blank" rel="noopener noreferrer">heise online, 2026-05-08</a> · <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09</a> · <a href="https://ctipilot.ch/briefs/2026-05-10/" target="_blank" rel="noopener noreferrer">daily 2026-05-10 post-mortem UPDATE</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">DNSSEC registry-side errors are indistinguishable from attacker-induced trust failures from a resolver&#39;s perspective. Validating-resolver operators in DACH and EU public-sector environments should keep RFC 7646 Negative Trust Anchor capability live for continuity during registry incidents and ensure runbooks separate &quot;registry KSK/ZSK rollover defect&quot; from &quot;zone-level attack on a downstream domain&quot;. The cross-finding for incident-response leaders is more general: alerting-pipeline reliability is itself a critical-infrastructure component, and a monitored anomaly that doesn&#39;t page is functionally an unmonitored anomaly.</div></aside><div class="prov"><span>incident</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/denic-de-dnssec-outage-3-5-h-registry-side-trust-failure-tra/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.denic.de/analyse-des-dns-ausfalls-vom-5-mai-2026/" target="_blank" rel="noopener noreferrer">DENIC analysis blog (German)</a> · <a href="https://blog.denic.de/en/technical-issue-with-de-domains-resolved/" target="_blank" rel="noopener noreferrer">DENIC post-incident report (English)</a> · <a href="https://blog.cloudflare.com/de-tld-outage-dnssec/" target="_blank" rel="noopener noreferrer">Cloudflare blog — .de TLD outage</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/jdownloader-official-site-compromised-windows-and-linux-inst" data-tags="supply-chain infostealer" data-regions="europe dach global" data-kind="incident" data-priority="notable" data-discovered="2026-05-04T05:00:22Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="jdownloader-official-site-compromised-windows-and-linux-inst"><a href="https://ctipilot.ch/entries/2026-05-04/jdownloader-official-site-compromised-windows-and-linux-inst/">JDownloader official site compromised — Windows and Linux installers swapped for ~48 hours</a></h3><p>The official download page of JDownloader (German-developed AppWork GmbH, Java-based download manager popular across European user bases) was compromised between approximately 2026-05-06 and 2026-05-08; attackers exploited an unpatched access-control flaw in the site&#39;s CMS layer to replace Windows and Linux installer download links without altering the main JAR, the in-app updater, the macOS bundle, or the package-manager distributions (Winget, Flatpak, Snap). Trojanised Windows executables bore forged publisher names — &quot;Zipline LLC&quot;, &quot;The Water Team&quot;, &quot;Peace Team&quot; — triggering Windows SmartScreen warnings that helped some users detect the substitution. The substituted installers carry a Python-based remote-access payload; a more specific capability description has not been corroborated by a named research lab in available reporting. The JDownloader team confirmed and asked users to verify file hashes against the project&#39;s published SHA-256 manifest (<a href="https://piunikaweb.com/2026/05/08/jdownloader-website-hacked-malware/" target="_blank" rel="noopener noreferrer">PiunikaWeb, 2026-05-08</a> · <a href="https://www.cyberkendra.com/2026/05/jdownloader-website-hacked-malicious.html" target="_blank" rel="noopener noreferrer">CyberKendra, 2026-05-07</a> · <a href="https://ctipilot.ch/briefs/2026-05-10/" target="_blank" rel="noopener noreferrer">daily 2026-05-10</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">audit developer / power-user / multimedia-engineering workstations across DACH for JDownloader installers downloaded between 2026-05-06 and 2026-05-08 from the official site or &quot;Alternative Installer&quot; link; hunt for unsigned / non-AppWork-signed <code>JDownloader*.exe</code>, unexpected Python interpreters in user-profile paths, and Python child processes spawned from JDownloader parent images.</div></aside><div class="prov"><span>incident</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/jdownloader-official-site-compromised-windows-and-linux-inst/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://piunikaweb.com/2026/05/08/jdownloader-website-hacked-malware/" target="_blank" rel="noopener noreferrer">PiunikaWeb — JDownloader compromised</a> · <a href="https://www.cyberkendra.com/2026/05/jdownloader-website-hacked-malicious.html" target="_blank" rel="noopener noreferrer">CyberKendra — JDownloader malicious installers</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/daemon-tools-lite-supply-chain-compromise-china-nexus-quic-r" data-tags="supply-chain espionage china-nexus infostealer" data-regions="europe global" data-kind="incident" data-priority="notable" data-discovered="2026-05-04T05:00:21Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="daemon-tools-lite-supply-chain-compromise-china-nexus-quic-r"><a href="https://ctipilot.ch/entries/2026-05-04/daemon-tools-lite-supply-chain-compromise-china-nexus-quic-r/">DAEMON Tools Lite supply-chain compromise — China-nexus QUIC RAT delivered via signed installers; ~12 selective government / scientific / manufacturing targets</a></h3><p>Official DAEMON Tools Lite Windows installers (versions 12.5.0.2421 → 12.5.0.2434) were trojanised on the Disc Soft vendor distribution server from 8 April to 5 May 2026, with malicious installers maintaining the authentic AVB Disc Soft code-signing certificate. The campaign deployed three stages: a <code>.NET</code> information collector (<code>envchk.exe</code>) for host fingerprinting deployed broadly across more than 100 countries (Germany, France, Spain, and Italy appear explicitly in first-stage victim telemetry); a shellcode-based backdoor; and <strong>QUIC RAT</strong> — a C++ implant supporting HTTP / UDP / TCP / WebSocket / QUIC / HTTP/3 C2 channels — <em>selectively</em> deployed to approximately twelve targets in government, scientific, manufacturing, and retail sectors in Russia, Belarus, and Thailand per Kaspersky. Chinese-language strings in the information collector suggest a Chinese-speaking actor; no formal attribution to a named group. The C2 domain was registered 2026-03-27 — approximately two weeks before the first trojanised installer (2026-04-08) — confirming pre-planned operation. Disc Soft acknowledged 2026-05-05, released clean version 12.6.0.2445, resolved the distribution compromise within 12 hours (<a href="https://www.kaspersky.com/blog/daemon-tools-supply-chain-attack/55691/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist</a> · <a href="https://therecord.media/hackers-compromise-daemon-tools-global-supply-chain-attack" target="_blank" rel="noopener noreferrer">The Record, 2026-05-06</a> · <a href="https://www.bleepingcomputer.com/news/security/daemon-tools-trojanized-in-supply-chain-attack-to-deploy-backdoor/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-05-06</a> · <a href="https://www.helpnetsecurity.com/2026/05/06/daemon-tools-compromised-backdoors-supply-chain-attack/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-05-06</a> · <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-07 and 2026-05-09 UPDATE</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">audit endpoints for DAEMON Tools Lite versions 12.5.0.2421 – 12.5.0.2434 installed on any government, scientific, or manufacturing endpoint since 8 April 2026; hunt for <code>envchk.exe</code>, unsigned processes injected into <code>notepad.exe</code> or <code>conhost.exe</code>, and outbound UDP 443 (QUIC) to non-sanctioned destinations; Sysmon EID 1 with parent-image filters surfaces post-injection activity. The pattern — selective QUIC-channel deployment behind broad-targeting reconnaissance staging — is the operationally important detail; it explains why telemetry hit-rate alone underestimates targeted-actor presence.</div></aside><div class="prov"><span>incident</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/daemon-tools-lite-supply-chain-compromise-china-nexus-quic-r/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.kaspersky.com/blog/daemon-tools-supply-chain-attack/55691/" target="_blank" rel="noopener noreferrer">Kaspersky — DAEMON Tools supply chain attack</a> · <a href="https://therecord.media/hackers-compromise-daemon-tools-global-supply-chain-attack" target="_blank" rel="noopener noreferrer">The Record — DAEMON Tools global supply-chain attack</a> · <a href="https://www.bleepingcomputer.com/news/security/daemon-tools-trojanized-in-supply-chain-attack-to-deploy-backdoor/" target="_blank" rel="noopener noreferrer">BleepingComputer — DAEMON Tools trojanized</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/trellix-source-code-repository-breach-vendor-confirmed-scope" data-tags="data-breach supply-chain" data-regions="global" data-kind="incident" data-priority="notable" data-discovered="2026-05-04T05:00:20Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="trellix-source-code-repository-breach-vendor-confirmed-scope"><a href="https://ctipilot.ch/entries/2026-05-04/trellix-source-code-repository-breach-vendor-confirmed-scope/">Trellix source code repository breach — vendor confirmed, scope undisclosed, supply-chain integrity question open</a></h3><p>Trellix, a major endpoint-security / XDR vendor serving enterprise and government customers globally, confirmed on 2026-05-04 that an unauthorised party accessed a portion of its internal source code repository. The company engaged external forensic specialists and notified law enforcement; Trellix stated no evidence was found that its product code-release or distribution pipeline was affected and no evidence the accessed code was exploited or altered. The initial access vector, duration of access, scope of repositories affected, and customer data impact have not been disclosed (<a href="https://www.bleepingcomputer.com/news/security/trellix-discloses-data-breach-after-source-code-repository-hack/" target="_blank" rel="noopener noreferrer">BleepingComputer, 2026-05-04</a> · <a href="https://thehackernews.com/2026/05/trellix-confirms-source-code-breach.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-05-04</a> · <a href="https://ctipilot.ch/briefs/2026-05-06/" target="_blank" rel="noopener noreferrer">daily 2026-05-06</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">organisations running Trellix endpoint or XDR products should maintain elevated scrutiny on Trellix software updates until the forensic investigation publicly concludes; the supply-chain integrity question — could the accessed code be re-used by an attacker for bug discovery or implant tailoring? — remains unresolved.</div></aside><div class="prov"><span>incident</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/trellix-source-code-repository-breach-vendor-confirmed-scope/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/trellix-discloses-data-breach-after-source-code-repository-hack/" target="_blank" rel="noopener noreferrer">BleepingComputer — Trellix data breach</a> · <a href="https://thehackernews.com/2026/05/trellix-confirms-source-code-breach.html" target="_blank" rel="noopener noreferrer">The Hacker News — Trellix source code</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/digicert-support-portal-compromise-salesforce-based-support" data-tags="supply-chain data-breach identity phishing china-nexus" data-regions="global" data-kind="incident" data-priority="notable" data-discovered="2026-05-04T05:00:19Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="digicert-support-portal-compromise-salesforce-based-support"><a href="https://ctipilot.ch/entries/2026-05-04/digicert-support-portal-compromise-salesforce-based-support/">DigiCert support portal compromise — Salesforce-based support-chat social engineering yielded 60 fraudulent EV code-signing certificates</a></h3><p>DigiCert confirmed on 2026-05-04 that a targeted social-engineering attack on its Salesforce-based customer-support portal in early April 2026 resulted in the fraudulent generation of 60 Extended Validation code-signing certificates. Two analyst endpoints were infected via a malicious Windows screensaver (.scr) repeatedly submitted via support chat; the second analyst&#39;s endpoint went undetected for approximately twelve days due to absent or degraded EDR coverage. The attacker used portal access to obtain certificate initialization codes and generated 60 EV certificates across multiple customer accounts; DigiCert confirmed 27 were directly attacker-linked; a community member subsequently identified 11 used to sign the <strong>Zhong Stealer</strong> malware family (Chinese e-crime, cryptocurrency-asset targeting). All 60 certificates revoked; MFA now mandatory on portal access; file upload functionality restricted (<a href="https://www.helpnetsecurity.com/2026/05/04/digicert-breach-code-signing-certificates-malware/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-05-04</a> · <a href="https://www.securityweek.com/digicert-revokes-certificates-after-support-portal-hack/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-05-04</a> · <a href="https://ctipilot.ch/briefs/2026-05-06/" target="_blank" rel="noopener noreferrer">daily 2026-05-06</a>).</p><aside class="callout callout--takeaway" role="note"><span class="callout__label">Defender takeaway</span><div class="callout__body">software signed with DigiCert-backed EV certificates during early April through 2026-05-04 warrants validation against the revoked certificate list; the recurring root cause across this and the third-party-analytics incidents in § 2 is that <em>support-tier</em> and <em>analyst-tier</em> endpoints frequently receive lower EDR-coverage bar than production endpoints despite holding equivalent or higher operational privilege.</div></aside><div class="prov"><span>incident</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/digicert-support-portal-compromise-salesforce-based-support/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.helpnetsecurity.com/2026/05/04/digicert-breach-code-signing-certificates-malware/" target="_blank" rel="noopener noreferrer">Help Net Security — DigiCert breach</a> · <a href="https://www.securityweek.com/digicert-revokes-certificates-after-support-portal-hack/" target="_blank" rel="noopener noreferrer">SecurityWeek — DigiCert revokes certificates</a></div></article><div class="sect" id="annual-periodic-threat-reports"><span class="n">06</span><span class="t">Annual / periodic threat reports</span><span class="c">6 items</span></div><article class="finding entry-card" data-entry-id="2026-05-04/abw-poland-2025-annual-report-apt28-apt29-unc1151-tri-attrib" data-tags="nation-state ot-ics russia-nexus hacktivism disinformation" data-regions="europe" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-04T05:00:30Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="abw-poland-2025-annual-report-apt28-apt29-unc1151-tri-attrib"><a href="https://ctipilot.ch/entries/2026-05-04/abw-poland-2025-annual-report-apt28-apt29-unc1151-tri-attrib/">ABW (Poland) 2025 Annual Report — APT28/APT29/UNC1151 tri-attribution on small-municipal water facilities</a></h3><p>ABW&#39;s 2025 Annual Report (published 2026-05-07) is the only annual report this week that combines new ground-truth attribution detail with explicit regulatory-coverage-gap framing. The five named municipal water facilities (Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, Sierakowo) all sit below the NIS2 essential-entity headcount threshold. ABW formally attributes initial access and persistence to <strong>APT28</strong> (GRU), intelligence-collection overlay at Jabłonna Lacka to <strong>APT29</strong> (SVR), and a disinformation overlay (fabricated leak documents purporting contamination data) to <strong>UNC1151</strong> (Belarusian, Ghostwriter-affiliated) — granular tri-attribution materially beyond the &quot;pro-Russian hacktivist&quot; framing in initial reporting. ABW is recommending legislative action to extend NIS2 obligations to critical-function entities regardless of headcount. The cross-finding pattern for Swiss / EU public-sector readers: small municipal CI operators sit below regulatory coverage but inside hostile-state targeting; expect more regulator-side movement on this gap in coming weeks (<a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09 UPDATE</a>).</p><div class="prov"><span>annual-report</span><span>04 May 05:00Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/abw-poland-2025-annual-report-apt28-apt29-unc1151-tri-attrib/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a" target="_blank" rel="noopener noreferrer">CISA AA24-207A — Russian GRU CI targeting (background reference)</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/dragos-2025-ot-cybersecurity-year-in-review-frontlines-ir-ed" data-tags="ot-ics ai-abuse" data-regions="global europe" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-04T05:00:28Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="dragos-2025-ot-cybersecurity-year-in-review-frontlines-ir-ed"><a href="https://ctipilot.ch/entries/2026-05-04/dragos-2025-ot-cybersecurity-year-in-review-frontlines-ir-ed/">Dragos 2025 OT Cybersecurity Year in Review — Frontlines IR Edition</a></h3><p>Dragos&#39;s 8th annual OT industrial-IR retrospective (covered 2026-05-08) is the week&#39;s most directly actionable annual-report reference for Swiss / EU CI operators reading after the Polish water OT attribution: Dragos&#39;s blog announcement records that <strong>65 percent of sites assessed had insecure remote-access conditions, including default credentials, unpatched VPNs, and exposed RDP sessions</strong>, and that many organisations believe they have proper IT/OT network segmentation while routine penetration tests reveal hidden connections. The report&#39;s NIS2 Annex-I compliance discussion directly contextualises the ABW 2025 Annual Report observation (§ 4) that the five Polish water-treatment facilities fell below the NIS2 essential-entity threshold and that legislative action is being considered to extend NIS2 obligations to critical-function entities regardless of headcount. The IEC 62443 zoning and conduit model is the recommended remediation reference architecture; the Swiss NCSC sector-specific ICS guidance (SARI framework) is the equivalent CH-side baseline. The defender lesson from the Dragos AI-assisted water utility attack item (2026-05-07) lands in the same line: AI tooling is progressively reducing the technical bar for OT-targeting attacks; prevention-only OT security strategies are inadequate as primary defences (<a href="https://ctipilot.ch/briefs/2026-05-08/" target="_blank" rel="noopener noreferrer">daily 2026-05-08</a>, <a href="https://ctipilot.ch/briefs/2026-05-07/" target="_blank" rel="noopener noreferrer">daily 2026-05-07 — AI-assisted ICS attack</a>).</p><div class="prov"><span>annual-report</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/dragos-2025-ot-cybersecurity-year-in-review-frontlines-ir-ed/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.dragos.com/blog/dragos-8th-annual-ot-cybersecurity-year-in-review-is-now-available" target="_blank" rel="noopener noreferrer">Dragos — 8th Annual OT Cybersecurity Year in Review blog announcement</a> · <a href="https://www.dragos.com/blog/ai-assisted-ics-attack-water-utility/" target="_blank" rel="noopener noreferrer">Dragos — AI-assisted ICS attack water utility</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/google-threat-intelligence-group-europe-data-leak-landscape" data-tags="ransomware organized-crime data-breach" data-regions="europe dach" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-04T05:00:27Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="google-threat-intelligence-group-europe-data-leak-landscape"><a href="https://ctipilot.ch/entries/2026-05-04/google-threat-intelligence-group-europe-data-leak-landscape/">Google Threat Intelligence Group — Europe data-leak landscape 2025</a></h3><p>GTIG&#39;s Europe data-leak landscape analysis (published 2026-04-15, first covered 2026-05-07) is the second-tier annual reference that materially affects DACH defender posture and merits cross-week synthesis: Germany is the primary European ransomware target with <strong>SAFEPAY</strong> accounting for 25% of German data-leak-site posts (76 victims claimed in 2025), <strong>Qilin</strong> tripling operational tempo in Germany during Q3 2025 with 13 additional German victims posted by early 2026 (Die Linke this week confirms continued activity into 2026-W19), and <strong>Sarcoma</strong> actively recruiting German network access via criminal forums since November 2024. <strong>96% of German ransomware victims are organisations with fewer than 5,000 employees</strong> — exploited both directly and as supply-chain footholds into larger enterprises and government contractors; legal and professional services rose to 14% of victims — explicitly relevant to Swiss / EU public-sector procurement officers since those firms hold client IP and M&amp;A intelligence. GTIG attributes part of the shift to AI-enabled high-quality localisation eroding the language-barrier protection that historically benefited non-English-speaking markets (<a href="https://ctipilot.ch/briefs/2026-05-07/" target="_blank" rel="noopener noreferrer">daily 2026-05-07</a>).</p><div class="prov"><span>annual-report</span><span>04 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/google-threat-intelligence-group-europe-data-leak-landscape/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/europe-data-leak-landscape" target="_blank" rel="noopener noreferrer">GTIG — Europe data leak landscape</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/europol-iocta-2026" data-tags="organized-crime nation-state espionage eu-nexus" data-regions="europe" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-04T05:00:25Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="europol-iocta-2026"><a href="https://ctipilot.ch/entries/2026-05-04/europol-iocta-2026/">Europol IOCTA 2026</a></h3><p>The Internet Organised Crime Threat Assessment 2026 (published 2026-04-28) was Europol&#39;s first IOCTA to identify the <em>interweaving of state-sponsored hybrid threats with criminal actors</em> as the defining strategic risk for EU public-sector defenders. The cross-finding pattern between IOCTA&#39;s framing and the rest of 2026-W19 is unusually direct: the WorldLeaks / ShinyHunters operator family targeting government identity registries and politically significant EU media entities, the named-cluster attribution on Polish water OT to APT28 + APT29 + UNC1151 sharing initial access tradecraft with hacktivist information operations, and the Bauman / GRU pipeline investigation (§ 7) all illustrate the convergence IOCTA flagged. For public-sector procurement and identity-management functions specifically, IOCTA&#39;s identification of public institutions, major technology companies, and EU citizens&#39; personal data as primary risk targets matches the week&#39;s incident concentration exactly. (<a href="https://home-affairs.ec.europa.eu/news/europol-published-report-latest-trends-cybercrime-landscape-2026-04-29_en" target="_blank" rel="noopener noreferrer">Europol IOCTA, 2026-04-28</a>; <a href="https://ctipilot.ch/briefs/2026-05-06/" target="_blank" rel="noopener noreferrer">daily 2026-05-06 first coverage</a>).</p><div class="prov"><span>annual-report</span><span>04 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/europol-iocta-2026/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://home-affairs.ec.europa.eu/news/europol-published-report-latest-trends-cybercrime-landscape-2026-04-29_en" target="_blank" rel="noopener noreferrer">Europol IOCTA 2026 (EC Migration &amp; Home Affairs)</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/kaspersky-q1-2026-exploits-and-vulnerabilities-report" data-tags="vulnerabilities zero-day ransomware" data-regions="global" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-04T05:00:29Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="kaspersky-q1-2026-exploits-and-vulnerabilities-report"><a href="https://ctipilot.ch/entries/2026-05-04/kaspersky-q1-2026-exploits-and-vulnerabilities-report/">Kaspersky Q1 2026 Exploits and Vulnerabilities Report</a></h3><p>Kaspersky&#39;s quarterly exploitation analysis for Q1 2026 reports that exploit kits expanded again to include new Microsoft Office, Windows, and Linux exploits, and that veteran vulnerabilities CVE-2018-0802 (Equation Editor RCE), CVE-2017-11882, and CVE-2023-38831 still account for the largest share of detections in the quarter (<a href="https://securelist.com/vulnerabilities-and-exploits-in-q1-2026/119733/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist — Exploits and Vulnerabilities Q1 2026</a>). The Securelist report also notes that AI-tool use for vulnerability discovery is increasing total registered vulnerability volume — a defender-side reframe for the M-Trends 2026 dwell-time data above (<a href="https://ctipilot.ch/briefs/2026-05-08/" target="_blank" rel="noopener noreferrer">daily 2026-05-08</a>).</p><div class="prov"><span>annual-report</span><span>04 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/kaspersky-q1-2026-exploits-and-vulnerabilities-report/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://securelist.com/vulnerabilities-and-exploits-in-q1-2026/119733/" target="_blank" rel="noopener noreferrer">Kaspersky Securelist — Exploits and Vulnerabilities Q1 2026</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/mandiant-m-trends-2026" data-tags="nation-state espionage ransomware" data-regions="global" data-kind="annual-report" data-priority="notable" data-discovered="2026-05-04T05:00:26Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="mandiant-m-trends-2026"><a href="https://ctipilot.ch/entries/2026-05-04/mandiant-m-trends-2026/">Mandiant M-Trends 2026</a></h3><p>M-Trends 2026 (published 2026-03-23, first covered 2026-05-07) reinforces three cross-cutting trends visible in this week&#39;s incidents: voice phishing surged to the second most prevalent initial-access vector at 11% (overtaking email phishing at 6%) driven by IT help-desk impersonation and SaaS OAuth token theft — directly evidenced this week in the ADT vishing → Okta SSO → Salesforce pivot and in MuddyWater&#39;s Teams external-access helpdesk pretext (§ 7); ransomware initial access via prior compromise doubled to 30% — implicit in the access-broker / ransomware-affiliate model behind Akira, Embargo, and Qilin&#39;s targeting of European victims; and edge-device persistence on VPNs, routers, and network appliances without EDR coverage remains the dominant initial-access technique for state-sponsored espionage — directly mirrored in CL-STA-1132&#39;s PAN-OS exploitation and in Ivanti EPMM&#39;s named EU victims. The reframe IOCTA does not give but M-Trends does: median dwell time globally has <em>increased</em> to 14 days (up from 11 in 2024) and espionage-focused intrusions average 122-day median dwell — i.e. when the Ivanti EPMM and PAN-OS post-compromise hunting horizons land on retrospective log review back to March/April, that horizon is consistent with Mandiant&#39;s observed espionage dwell envelope. (<a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026" target="_blank" rel="noopener noreferrer">Google Cloud / Mandiant M-Trends 2026, 2026-03-23</a>; <a href="https://ctipilot.ch/briefs/2026-05-07/" target="_blank" rel="noopener noreferrer">daily 2026-05-07</a>).</p><div class="prov"><span>annual-report</span><span>04 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/mandiant-m-trends-2026/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026" target="_blank" rel="noopener noreferrer">Google Cloud / Mandiant — M-Trends 2026</a></div></article><div class="sect" id="long-running-campaigns-status-update"><span class="n">07</span><span class="t">Long-running campaigns · status update</span><span class="c">11 items</span></div><article class="finding entry-card" data-entry-id="2026-05-04/akira-playbook-quarterly-context-q1-2026-healthcare-concentr" data-tags="ransomware organized-crime data-breach" data-regions="europe dach switzerland" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:41Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="akira-playbook-quarterly-context-q1-2026-healthcare-concentr"><a href="https://ctipilot.ch/entries/2026-05-04/akira-playbook-quarterly-context-q1-2026-healthcare-concentr/">Akira playbook quarterly context — Q1 2026 healthcare concentration; Qilin remains the dominant operator on German healthcare victims</a></h3><p>W1 horizon research added Q1 2026 healthcare quarterly context to the Groupe 3R item in § 1. Across Q1 2026, Akira posted 84 victims in March alone (second-most-active month on record) and claimed 5 healthcare victims; Qilin led healthcare at 23 claims (with <strong>RENAFAN GmbH</strong> and <strong>Suchthilfe direkt Essen gGmbH</strong> as Qilin&#39;s confirmed German victims), and The Gentlemen at 10 healthcare claims (<a href="https://www.comparitech.com/news/healthcare-ransomware-roundup-q1-2026-stats-on-attacks-ransoms-and-data-breaches/" target="_blank" rel="noopener noreferrer">Comparitech Q1 2026 Healthcare, 2026-04-29</a> · <a href="https://www.cybermaxx.com/resources/ransomware-research-report-q1-2026-audio-blog-interview/" target="_blank" rel="noopener noreferrer">CyberMaxx Q1 2026</a>). Akira&#39;s documented attack chain for healthcare: initial access via unpatched VPN (Cisco ASA, SonicWall, Fortinet) or compromised RDP credentials; lateral movement via <a href="https://attack.mitre.org/techniques/T1021/001/" target="_blank" rel="noopener noreferrer">T1021.001 Remote Services: Remote Desktop Protocol</a> and <a href="https://attack.mitre.org/techniques/T1047/" target="_blank" rel="noopener noreferrer">T1047 Windows Management Instrumentation</a>; LSASS credential harvesting via <code>comsvcs.dll</code> / Mimikatz; AV termination via PowerTool weaponising the Zemana AntiMalware driver (BYOVD); data exfiltration; double extortion. The cross-finding for Swiss / DACH operators reading after Groupe 3R: at least two ransomware-as-a-service operators (Akira and Qilin) are hitting European healthcare in Q1–Q2 2026 via the edge-device / unpatched-VPN attack surface, and the operator that hits a given hospital is less salient defensively than the shared initial-access funnel they exploit.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/akira-playbook-quarterly-context-q1-2026-healthcare-concentr/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.comparitech.com/news/healthcare-ransomware-roundup-q1-2026-stats-on-attacks-ransoms-and-data-breaches/" target="_blank" rel="noopener noreferrer">Comparitech Q1 2026 Healthcare</a> · <a href="https://www.cybermaxx.com/resources/ransomware-research-report-q1-2026-audio-blog-interview/" target="_blank" rel="noopener noreferrer">CyberMaxx Q1 2026 Ransomware Research</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/the-gentlemen-raas-europe-skewed-operation-surged-approximat" data-tags="ransomware organized-crime actively-exploited data-breach" data-regions="europe dach" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:40Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span></div><h3 class="f-h" id="the-gentlemen-raas-europe-skewed-operation-surged-approximat"><a href="https://ctipilot.ch/entries/2026-05-04/the-gentlemen-raas-europe-skewed-operation-surged-approximat/">The Gentlemen RaaS — Europe-skewed operation surged approximately 448% QoQ; 32% of Q1 2026 victims in Europe; FortiGate CVE-2024-55591 initial-access funnel</a></h3><p>W1 horizon research identified an in-window operator gap the daily briefs missed. &quot;The Gentlemen&quot; emerged in August 2025 and per ZeroFox surged to the second- or third-most-active ransomware operation globally in Q1 2026 — 192 attacks that quarter, a approximately 448% QoQ increase, <strong>32% of Q1 2026 victims in Europe</strong> (up from 2% in Q4 2025) (<a href="https://www.zerofox.com/intelligence/q1-2026-ransomware-wrap-up/" target="_blank" rel="noopener noreferrer">ZeroFox Q1 2026 Wrap-Up, 2026-04-17</a>). Check Point Research&#39;s DFIR report on the operator confirms the post-compromise tradecraft observed during a single incident-response engagement: Cobalt Strike delivered via RPC from a Domain Controller; Mimikatz for credential harvesting; <strong>GPO abuse</strong> to inject a scheduled task into Group Policy that propagates the encryptor to all domain-joined systems near-simultaneously (compressing time-to-encryption to minimise IR response window); <strong>SystemBC</strong> SOCKS5 C2 tunnelling and covert payload staging; encryption using X25519 Diffie–Hellman key exchange per file combined with XChaCha20 stream cipher, per-file ephemeral key pair with a random 32-byte private key (<a href="https://research.checkpoint.com/2026/dfir-report-the-gentlemen/" target="_blank" rel="noopener noreferrer">Check Point Research DFIR Report, 2026-04-20</a> · <a href="https://www.bleepingcomputer.com/news/security/the-gentlemen-ransomware-now-uses-systembc-for-bot-powered-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer — The Gentlemen + SystemBC, 2026-04-20</a>). CPR explicitly states the precise initial-access vector could not be conclusively determined for the engagement it analysed; broader reporting attributes initial access to a FortiOS / FortiProxy attack surface that includes <strong>CVE-2024-55591</strong> (authentication bypass, CVSS 9.8 — patched January 2025), with secondary reporting describing an operator database of pre-exploited devices and brute-forced VPN credentials primed for deployment — defenders should treat patch-state-alone as insufficient if the device was unpatched against CVE-2024-55591 at any point during the exposure window.</p>
<p>European victims surfaced in BleepingComputer&#39;s SystemBC coverage and in quarterly leak-site aggregation include <strong>Oltenia Energy Complex</strong> (Romania — described as a significant portion of national electricity supply, December 2025) and <strong>The Adaptavist Group</strong>; Comparitech&#39;s Q1 2026 healthcare roundup attributes 10 healthcare-sector claims to the operator in the quarter; the operator&#39;s leak-site footprint and the absence of an &quot;off-limits&quot; sector convention make hospitals, water utilities, and similar critical-infrastructure targets in-scope. The cross-finding with this week&#39;s other concerns: GPO-injected scheduled-task propagation defeats backup-isolation defences if the AD environment is in the encryption path; if the operator&#39;s initial-access funnel includes unpatched FortiGate devices, that surface intersects directly with the Polish water-OT NIS2 coverage-gap framing (§ 4, § 6) since small municipal CI operators are over-represented in the unpatched-FortiGate population. Defender priorities for 2026-W20: hunt scheduled tasks in SYSVOL pointing to UNC paths or temp directories; profile SystemBC SOCKS5 beacons; add XChaCha20 file-header pattern detection at backup / DLP tier; re-verify FortiGate patch state against CVE-2024-55591 and any later FortiOS / FortiProxy auth-bypass advisories.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/the-gentlemen-raas-europe-skewed-operation-surged-approximat/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://research.checkpoint.com/2026/dfir-report-the-gentlemen/" target="_blank" rel="noopener noreferrer">Check Point Research — The Gentlemen DFIR Report</a> · <a href="https://www.bleepingcomputer.com/news/security/the-gentlemen-ransomware-now-uses-systembc-for-bot-powered-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer — The Gentlemen + SystemBC</a> · <a href="https://www.zerofox.com/intelligence/q1-2026-ransomware-wrap-up/" target="_blank" rel="noopener noreferrer">ZeroFox Q1 2026 Ransomware Wrap-Up</a> · <a href="https://www.comparitech.com/news/healthcare-ransomware-roundup-q1-2026-stats-on-attacks-ransoms-and-data-breaches/" target="_blank" rel="noopener noreferrer">Comparitech Q1 2026 Healthcare</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/qilin-agenda-raas-die-linke-confirms-q2-2026-german-activity" data-tags="ransomware data-breach" data-regions="europe dach" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:39Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="qilin-agenda-raas-die-linke-confirms-q2-2026-german-activity"><a href="https://ctipilot.ch/entries/2026-05-04/qilin-agenda-raas-die-linke-confirms-q2-2026-german-activity/">Qilin / Agenda RaaS — Die Linke confirms Q2 2026 German activity continuity</a></h3><p>Current state: GTIG&#39;s Europe data-leak landscape (§ 6) documented Qilin tripling Q3 2025 operational tempo in Germany; <strong>Die Linke (Germany federal political party)</strong> confirmed Qilin encryption with 1.5 TB exfiltrated (covered 2026-05-08), state DPA notified — Qilin German activity continues into 2026-Q2. No public-claim shift or victim-list expansion beyond Die Linke this week. Outstanding question: whether Qilin&#39;s targeting of political and civil-society organisations expands into other 2026 EU election cycles.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/qilin-agenda-raas-die-linke-confirms-q2-2026-german-activity/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://cloud.google.com/blog/topics/threat-intelligence/europe-data-leak-landscape" target="_blank" rel="noopener noreferrer">GTIG — Europe data leak landscape</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/akira-ransomware-swiss-healthcare-case-confirmed-broader-eur" data-tags="ransomware organized-crime" data-regions="switzerland europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:38Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="akira-ransomware-swiss-healthcare-case-confirmed-broader-eur"><a href="https://ctipilot.ch/entries/2026-05-04/akira-ransomware-swiss-healthcare-case-confirmed-broader-eur/">Akira ransomware — Swiss healthcare case confirmed; broader European playbook unchanged</a></h3><p>Current state: Akira&#39;s leak-site listing on Groupe 3R (§ 1) is the operationally specific Swiss-healthcare development this week. The broader Akira playbook (edge-device initial access via Cisco ASA/FTD, Fortinet SSL-VPN, VMware ESXi authenticated RCE; intermittent file-encryption to evade EDR file-IO heuristics) has been documented across European healthcare and SME targeting throughout 2025 and into 2026. No major Akira TTP shift detected in this week&#39;s reporting; the operator continues to favour edge-device initial access and double-extortion (encrypt + leak). Outstanding defender question: whether the Groupe 3R &quot;will not pay&quot; public stance changes the operator&#39;s posture for repeat victims (3R&#39;s prior April 2025 incident is acknowledged in its own statement as having involved different attackers and methodology).</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/akira-ransomware-swiss-healthcare-case-confirmed-broader-eur/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.groupe3r.ch/fr/information-importante-perturbation-de-nos-services-7268/" target="_blank" rel="noopener noreferrer">Groupe 3R victim statement</a> · <a href="https://www.ictjournal.ch/news/2026-05-06/le-reseau-radiologique-romand-a-nouveau-victime-dune-cyberattaque-ses-systemes" target="_blank" rel="noopener noreferrer">ICTjournal.ch</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/sandworm-gru-unit-74455-bauman-pipeline-disclosure" data-tags="nation-state espionage russia-nexus" data-regions="europe global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:36Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="sandworm-gru-unit-74455-bauman-pipeline-disclosure"><a href="https://ctipilot.ch/entries/2026-05-04/sandworm-gru-unit-74455-bauman-pipeline-disclosure/">Sandworm / GRU Unit 74455 — Bauman pipeline disclosure</a></h3><p>Current state: investigative disclosure of significance rather than a tactical campaign development. The six-publisher consortium (The Insider, The Guardian, Le Monde, Der Spiegel, VSquare, Frontstory) published 2 000+ leaked internal documents on 2026-05-07 from Bauman Moscow State Technical University detailing a structured GRU recruitment-and-training pipeline operating as &quot;Department No. 4 — Special Training&quot; — placing 10–15 graduates per year into Russian military intelligence units. Documents explicitly link graduates to GRU Unit 74455 (Sandworm / VoodooBear: 2015–16 Ukraine power-grid attacks; 2017 NotPetya; 2023 Kyivstar) and to APT28 (Fancy Bear: 2016 Bundestag, 2017 Macron campaign). Operational relevance for EU defenders: the curriculum targets Western and US-DoD network topologies <em>by name</em>, reframing the long-running attribution debate — GRU cyber units are not ad-hoc-recruited contractors, they are graduates of a structured technical-intelligence training stream with measurable annual throughput. Outstanding question: whether the disclosed Bauman-graduate roster materially advances ongoing law-enforcement actions against named GRU operators.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/sandworm-gru-unit-74455-bauman-pipeline-disclosure/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.theguardian.com/world/2026/may/07/revealed-russia-top-secret-spy-school-hacking-western-electoral-interference" target="_blank" rel="noopener noreferrer">The Guardian — Russia top-secret spy school</a> · <a href="https://www.lemonde.fr/en/m-le-mag/article/2026/05/07/moscow-s-bauman-university-the-clandestine-school-training-russian-hackers_6753208_117.html" target="_blank" rel="noopener noreferrer">Le Monde — Bauman clandestine school</a> · <a href="https://www.spiegel.de/ausland/hybrider-krieg-moskau-bildet-in-einem-geheimen-uni-programm-spione-und-hacker-aus-a-2de79023-aa56-4ed6-b5de-d7c222402e63" target="_blank" rel="noopener noreferrer">Der Spiegel — Hybrider Krieg</a> · <a href="https://meduza.io/amp/en/feature/2026/05/07/secret-gru-linked-department-at-top-russian-university-trains-hackers-and-saboteurs-investigation-finds" target="_blank" rel="noopener noreferrer">Meduza (English) — Department No. 4 investigation</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/apt28-apt29-unc1151-polish-water-ot" data-tags="nation-state ot-ics russia-nexus hacktivism disinformation" data-regions="europe" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:35Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="apt28-apt29-unc1151-polish-water-ot"><a href="https://ctipilot.ch/entries/2026-05-04/apt28-apt29-unc1151-polish-water-ot/">APT28 / APT29 / UNC1151 (Polish water OT)</a></h3><p>Current state: ABW 2025 Annual Report (2026-05-07 publication, covered 2026-05-09) is the formal-attribution development this week. Per SecurityWeek&#39;s coverage of the ABW report, the campaign against the five small Polish municipal water facilities is attributed to <strong>APT28</strong> (GRU) and <strong>APT29</strong> (SVR) — with <strong>UNC1151</strong> (Belarusian-linked) named in the same attribution discussion. The granular per-facility breakdown and disinformation-overlay specifics carried in the daily 2026-05-09 UPDATE trace back to the Polish-language ABW report itself rather than the English secondary coverage; defenders relying on the English reporting should treat the actor-cluster trio as attributed jointly without per-facility specificity unless the ABW primary is consulted. The same APT28 cluster is in active operation against EU government ministries via CVE-2026-32202 (Windows Shell NTLM coercion, § 3). Outstanding defender question: whether ABW-recommended NIS2 expansion to critical-function entities below the headcount threshold gains EU-level momentum in coming weeks.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/apt28-apt29-unc1151-polish-water-ot/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a" target="_blank" rel="noopener noreferrer">CISA AA24-207A (background reference)</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/shinyhunters-worldleaks-family-financial-data-extortion-thir" data-tags="organized-crime data-breach supply-chain" data-regions="europe global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:33Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="shinyhunters-worldleaks-family-financial-data-extortion-thir"><a href="https://ctipilot.ch/entries/2026-05-04/shinyhunters-worldleaks-family-financial-data-extortion-thir/">ShinyHunters / WorldLeaks family (financial-data extortion, third-party-SaaS pivot)</a></h3><p>Current state: most-active operator family of 2026-W19. Confirmed parallel involvement across Vimeo/Anodot, Inditex/Zara/Anodot, ADT/Okta-SSO/Salesforce, and Canvas/Instructure (second-intrusion claim despite May 8 patches). The architectural pattern across these incidents — third-party analytics, BI, integration, or LTI service accounts holding broad read access to tenant data — is consistent and converging. The Canvas/Instructure extortion deadline is 2026-05-12 (two days out at week-end). Outstanding defender question: which AI-tooling SaaS or analytics SaaS vendor will be the next confirmed pivot point. ()</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/shinyhunters-worldleaks-family-financial-data-extortion-thir/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/" target="_blank" rel="noopener noreferrer">BleepingComputer — Instructure data breach</a> · <a href="https://securityaffairs.com/191859/cyber-crime/zara-data-breach-197000-customers-exposed-in-third-party-security-incident.html" target="_blank" rel="noopener noreferrer">SecurityAffairs — Zara breach</a> · <a href="https://vimeo.com/blog/post/anodot-third-party-security-incident" target="_blank" rel="noopener noreferrer">Vimeo official blog</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/uat-8302-china-nexus-talos-se-european-government-victims" data-tags="nation-state espionage china-nexus" data-regions="europe global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:32Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="uat-8302-china-nexus-talos-se-european-government-victims"><a href="https://ctipilot.ch/entries/2026-05-04/uat-8302-china-nexus-talos-se-european-government-victims/">UAT-8302 (China-nexus, Talos; SE European government victims)</a></h3><p>Current state: long-term gov-network access operations against South American government networks since late 2024 and southeastern European government agencies in 2025 — Talos disclosure published 2026-05-05 was the first detailed write-up. Tooling overlap links UAT-8302 to multiple Chinese-quartermaster-shared clusters (Ink Dragon, Earth Alux, Jewelbug, REF7707, LongNosedGoblin, Erudite Mogwai / Space Pirates). No new in-window developments beyond the original Talos disclosure (2026-05-05), and <code>state/covered_items.json</code> carries it as first-covered 2026-05-06. Outstanding defender question: whether southeastern European government victim list will expand publicly. Initial-access CVE not yet disclosed; Talos referenced post-compromise tooling (gogo scanner, Impacket, NetDraft/NosyDoor, CloudSorcerer v3.0, SNOWLIGHT/SNOWRUST, Deed RAT/Snappybee, Zingdoor, Draculoader, Stowaway, SoftEther VPN) rather than the entry vector.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/uat-8302-china-nexus-talos-se-european-government-victims/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://blog.talosintelligence.com/uat-8302/" target="_blank" rel="noopener noreferrer">Cisco Talos — UAT-8302</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/cl-sta-1132-pan-os-cve-2026-0300-exploitation-cluster-likely" data-tags="nation-state espionage actively-exploited china-nexus" data-regions="europe global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:31Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span></div><h3 class="f-h" id="cl-sta-1132-pan-os-cve-2026-0300-exploitation-cluster-likely"><a href="https://ctipilot.ch/entries/2026-05-04/cl-sta-1132-pan-os-cve-2026-0300-exploitation-cluster-likely/">CL-STA-1132 (PAN-OS CVE-2026-0300 exploitation cluster, likely state-sponsored)</a></h3><p>Current state: actively in-the-wild against internet-facing PAN-OS PA-Series / VM-Series firewalls since approximately 2026-04-09; the KEV deadline (2026-05-09) expired with no patch available and the staged patch window runs 2026-05-13 → 2026-05-28. Post-exploitation tradecraft per Unit 42 and the daily 2026-05-09 UPDATE is consistent: shellcode injection into <code>nginx</code> worker processes, EarthWorm / ReverseSocks5 tunnelling, Python implants under <code>/var/tmp/linuxupdate</code> and <code>/tmp/.c</code>; the daily UPDATE additionally records rogue admin accounts named <code>svc-health-check-[6-digit-numeric]</code>, PAN-OS credential-store theft, and Active Directory enumeration via OSPF queries. Unit 42&#39;s 2026-05-08 update added explicit EarthWorm / ReverseSocks5 framing to the cluster (covered as marginal delta in the 2026-05-10 daily). Outstanding question for defenders into 2026-W20: with patches landing 2026-05-13 → 2026-05-28, the at-risk window remains open into next week&#39;s reporting and retrospective-log review for the <code>svc-health-check-</code> pattern across the 2026-04-09 → present period is the highest-priority hunt action. (Daily references: <a href="https://ctipilot.ch/briefs/2026-05-07/" target="_blank" rel="noopener noreferrer">2026-05-07</a> deep dive · <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">2026-05-09</a> UPDATE.)</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/cl-sta-1132-pan-os-cve-2026-0300-exploitation-cluster-likely/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://unit42.paloaltonetworks.com/captive-portal-zero-day/" target="_blank" rel="noopener noreferrer">Unit 42 — Captive Portal zero-day</a> · <a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto PSIRT — CVE-2026-0300</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/teampcp-pcpjack-cloud-worm-successor-evicting-prior-operator" data-tags="organized-crime cloud vulnerabilities actively-exploited supply-chain" data-regions="global" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:37Z"><div class="badges"><span class="b ">NOTABLE</span><span class="b exp">exploited</span></div><h3 class="f-h" id="teampcp-pcpjack-cloud-worm-successor-evicting-prior-operator"><a href="https://ctipilot.ch/entries/2026-05-04/teampcp-pcpjack-cloud-worm-successor-evicting-prior-operator/">TeamPCP → PCPJack — cloud-worm successor evicting prior operator artefacts</a></h3><p>Current state: SentinelLabs documented <strong>PCPJack</strong> on 2026-05-07 as a worm-class framework that evicts and deletes existing TeamPCP artefacts on compromise (giving the framework its name), then deploys six Python modules harvesting credentials from Docker, Kubernetes, Redis, MongoDB, RayML, and dozens of cloud / SaaS services (AWS, Azure, GCP, GitHub, Slack, HashiCorp Vault, 1Password). Propagation targets are pulled from Common Crawl Parquet files rather than ad-hoc scanning — far broader curated attack surface than typical opportunistic worms. Weaponises five public CVEs simultaneously (<a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29927" target="_blank" rel="noopener noreferrer">CVE-2025-29927</a> Next.js, <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-55182" target="_blank" rel="noopener noreferrer">CVE-2025-55182</a> React2Shell, <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1357" target="_blank" rel="noopener noreferrer">CVE-2026-1357</a> WPVivid, <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9501" target="_blank" rel="noopener noreferrer">CVE-2025-9501</a> W3 Total Cache, <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48703" target="_blank" rel="noopener noreferrer">CVE-2025-48703</a> CWP). The TeamPCP → PCPJack succession overlay is the operational specific worth tracking: SentinelLabs explicitly states there is no evidence yet of a direct operator-level connection, while the eviction logic implies operators familiar with TeamPCP&#39;s target population. Defenders running self-hosted Next.js, React-server-actions stacks, WordPress with WPVivid Backup or W3 Total Cache, or CentOS Web Panel with internet-reachable FileManager should treat all five CVEs as actively weaponised (<a href="https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/" target="_blank" rel="noopener noreferrer">SentinelLabs, 2026-05-07</a> · <a href="https://thehackernews.com/2026/05/pcpjack-credential-stealer-exploits-5.html" target="_blank" rel="noopener noreferrer">The Hacker News, 2026-05-07</a> · <a href="https://www.securityweek.com/pcpjack-worm-removes-teampcp-infections-steals-credentials/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-05-08</a> · <a href="https://ctipilot.ch/briefs/2026-05-10/" target="_blank" rel="noopener noreferrer">daily 2026-05-10</a>). The earlier TeamPCP &quot;Mini Shai-Hulud&quot; SAP CAP npm worm (covered 2026-05-06) used Claude Code SessionStart hooks and VSCode tasks for propagation — that thread is separate from PCPJack&#39;s CVE-chain propagation but the same operator population is tracked.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/teampcp-pcpjack-cloud-worm-successor-evicting-prior-operator/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/" target="_blank" rel="noopener noreferrer">SentinelLabs — Cloud worm evicts TeamPCP</a> · <a href="https://thehackernews.com/2026/05/pcpjack-credential-stealer-exploits-5.html" target="_blank" rel="noopener noreferrer">The Hacker News — PCPJack credential stealer</a> · <a href="https://www.securityweek.com/pcpjack-worm-removes-teampcp-infections-steals-credentials/" target="_blank" rel="noopener noreferrer">SecurityWeek — PCPJack worm</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/muddywater-iran-mois-chaos-ransomware-false-flag-teams-bec" data-tags="nation-state espionage ransomware phishing identity iran-nexus" data-regions="us middle-east" data-kind="synthesis" data-priority="notable" data-discovered="2026-05-04T05:00:34Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="muddywater-iran-mois-chaos-ransomware-false-flag-teams-bec"><a href="https://ctipilot.ch/entries/2026-05-04/muddywater-iran-mois-chaos-ransomware-false-flag-teams-bec/">MuddyWater (Iran / MOIS) Chaos ransomware false-flag + Teams BEC</a></h3><p>Current state: refreshed 2026 campaign documented by Rapid7 (&quot;Muddying the Tracks&quot;) and corroborated this week by BleepingComputer and SecurityWeek. Per Rapid7 (&quot;Operation Olalampo&quot;), the campaign&#39;s observed victimology is construction, manufacturing, and business-services organisations in the U.S. and MENA regions; deploys Chaos ransomware with criminal-group branding to complicate attribution and delay IR triage; uses Microsoft Teams external-chat requests for an interactive screen-sharing helpdesk pretext to harvest credentials and manipulate MFA. Attribution evidence per Rapid7: a &quot;Donald Gay&quot; code-signing certificate, the <code>moonzonet[.]com</code> C2 domain, <code>pythonw.exe</code> process injection of suspended processes, and the Teams MFA-harvest tradecraft — all consistent with prior MuddyWater (Seedworm) operations attributed to Iran&#39;s Ministry of Intelligence and Security (<a href="https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/" target="_blank" rel="noopener noreferrer">Rapid7 — Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware</a> · <a href="https://www.bleepingcomputer.com/news/security/muddywater-hackers-use-chaos-ransomware-as-a-decoy-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer — MuddyWater hackers use Chaos ransomware as a decoy</a> · <a href="https://www.securityweek.com/iranian-apt-intrusion-masquerades-as-chaos-ransomware-attack/" target="_blank" rel="noopener noreferrer">SecurityWeek — Iranian APT intrusion masquerades as Chaos ransomware attack</a>). M-Trends 2026 (§ 6) notes voice phishing surged to the second most prevalent initial-access vector at 11% with IT help-desk impersonation as a primary modality — MuddyWater&#39;s Teams variant of that pattern is operationally similar. Outstanding defender question: whether the same false-flag tradecraft expands across additional Chaos-branded incidents now that the attribution is public.</p><div class="prov"><span>synthesis</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/muddywater-iran-mois-chaos-ransomware-false-flag-teams-bec/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/" target="_blank" rel="noopener noreferrer">Rapid7 — Muddying the Tracks</a> · <a href="https://www.bleepingcomputer.com/news/security/muddywater-hackers-use-chaos-ransomware-as-a-decoy-in-attacks/" target="_blank" rel="noopener noreferrer">BleepingComputer — MuddyWater Chaos decoy</a> · <a href="https://www.securityweek.com/iranian-apt-intrusion-masquerades-as-chaos-ransomware-attack/" target="_blank" rel="noopener noreferrer">SecurityWeek — Iranian APT masquerades as Chaos</a></div></article><div class="sect" id="policy-regulatory-horizon"><span class="n">08</span><span class="t">Policy &amp; regulatory horizon</span><span class="c">10 items</span></div><article class="finding entry-card" data-entry-id="2026-05-04/poland-nis2-transposition-in-force-3-april-2026-water-sector" data-tags="law-enforcement ot-ics eu-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-04T05:00:51Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="poland-nis2-transposition-in-force-3-april-2026-water-sector"><a href="https://ctipilot.ch/entries/2026-05-04/poland-nis2-transposition-in-force-3-april-2026-water-sector/">Poland NIS2 transposition in force 3 April 2026 — water-sector essential-entity status would now apply to the ABW-named facilities</a></h3><p>Poland&#39;s amended National Cybersecurity System Act (UKSC) entered into force on <strong>3 April 2026</strong>, implementing NIS2 with a full compliance deadline of 3 April 2027 and first audit deadline 3 April 2028 (<a href="https://www.addleshawgoddard.com/en/insights/insights-briefings/2026/technology/nis2-directive-finally-implemented-poland-what-businesses-need-know/" target="_blank" rel="noopener noreferrer">Addleshaw Goddard, 2026-02-26</a> · <a href="https://www.securityweek.com/polish-security-agency-reports-ics-breaches-at-five-water-treatment-plants/" target="_blank" rel="noopener noreferrer">SecurityWeek, 2026-05-08</a>). &quot;Drinking water supply and distribution&quot; and &quot;wastewater management&quot; are now designated essential-entity sectors in Polish law — meaning the five municipal water treatment facilities ABW documented as breached during 2025 (Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, Sierakowo; § 4 / § 7) would, if attacked today, fall under NIS2 incident-reporting obligations. The attack vectors ABW attributes to APT28 / APT29 / UNC1151 (default credentials, internet-exposed ICS) are addressable by NIS2 Article 21 minimum security measures. The remaining policy gap: the breached small municipal operators are precisely the sub-threshold entities whose NIS2 coverage status is borderline under size-cap rules; the EC&#39;s NIS2 amendment introduces a &quot;small mid-cap&quot; important-entity category but does not resolve this specific small-municipality water-supply gap (member-state discretion). <strong>What defenders need to do differently:</strong> OT environments in small Polish municipalities with recently-transposed NIS2 obligations should treat the UKSC registration deadline (3 October 2026) as the immediate action item, and the 2025 ABW-documented attack vectors as the first patch-sprint target. For Swiss / EU operators reading: the ABW recommendation to extend essential-entity coverage below headcount threshold is now backed by both a documented compromise pattern <em>and</em> a freshly-transposed national NIS2 framework.</p><div class="prov"><span>policy</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/poland-nis2-transposition-in-force-3-april-2026-water-sector/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.addleshawgoddard.com/en/insights/insights-briefings/2026/technology/nis2-directive-finally-implemented-poland-what-businesses-need-know/" target="_blank" rel="noopener noreferrer">Addleshaw Goddard — NIS2 implemented in Poland</a> · <a href="https://www.securityweek.com/polish-security-agency-reports-ics-breaches-at-five-water-treatment-plants/" target="_blank" rel="noopener noreferrer">SecurityWeek — Polish security agency reports ICS breaches</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/ncsc-switzerland-formal-bacs-assessment-on-ai-in-vulnerabili" data-tags="ai-abuse vulnerabilities" data-regions="switzerland" data-kind="policy" data-priority="notable" data-discovered="2026-05-04T05:00:50Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="ncsc-switzerland-formal-bacs-assessment-on-ai-in-vulnerabili"><a href="https://ctipilot.ch/entries/2026-05-04/ncsc-switzerland-formal-bacs-assessment-on-ai-in-vulnerabili/">NCSC Switzerland — formal BACS assessment on AI in vulnerability management; defenders warned against over-reliance on AI detection</a></h3><p>The Swiss NCSC published a formal signed BACS assessment on 1 May 2026 titled <em>&quot;Use of AI in vulnerability management&quot;</em> (<a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/einschtzung_mythos_2026.html" target="_blank" rel="noopener noreferrer">NCSC Switzerland Im Fokus, 2026-05-01</a>). The assessment characterises AI as &quot;highly significant for cybersecurity&quot; with an asymmetric dual-use risk: while AI-based detection tools accelerate vulnerability identification for defenders, the NCSC observes that the same technology &quot;is making hackers&#39; work much easier,&quot; particularly in malware-development efficiency. The key NCSC finding is that the actual scale of fully autonomous AI-driven cyberattacks <strong>remains unclear</strong> — defenders should not treat AI-augmented detection as a solved problem justifying reduced investment in foundational controls. The NCSC recommends prioritising: continuous patching discipline, strong access management and privileged-access controls, staff security awareness, and regular structured security reviews. <strong>What defenders need to do differently:</strong> in ISG-covered Swiss entities a BACS position paper carries supervisory weight under the NCS implementation framework; CISO functions should document how their AI-security tool deployments are complemented by (not substituting for) the NCSC&#39;s foundational-controls baseline. This is a measured regulatory pushback against vendor claims that AI-powered detection can replace security fundamentals. Single-source national-CERT carve-out applies.</p><div class="prov"><span>policy</span><span>04 May 05:00Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/ncsc-switzerland-formal-bacs-assessment-on-ai-in-vulnerabili/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/einschtzung_mythos_2026.html" target="_blank" rel="noopener noreferrer">NCSC Switzerland — Im Fokus / Use of AI in vulnerability management, 2026-05-01</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/edpb-coordinated-enforcement-framework-2026-25-dpas-target-g" data-tags="law-enforcement eu-nexus identity" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-04T05:00:49Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="edpb-coordinated-enforcement-framework-2026-25-dpas-target-g"><a href="https://ctipilot.ch/entries/2026-05-04/edpb-coordinated-enforcement-framework-2026-25-dpas-target-g/">EDPB Coordinated Enforcement Framework 2026 — 25 DPAs target GDPR transparency obligations (Articles 12–14)</a></h3><p>On 19 March 2026 the European Data Protection Board launched its annual Coordinated Enforcement Framework (CEF) action, with <strong>25 participating DPAs across Europe</strong> examining compliance with <strong>GDPR Articles 12, 13, and 14</strong> — the transparency and information obligations requiring controllers to clearly disclose what data is processed, on what legal basis, and for what purposes. Unlike prior CEF years (right of access 2024, right to erasure 2025), transparency obligations are broadly applicable to every data-processing controller in every sector, making this year&#39;s sweep unusually wide (<a href="https://www.edpb.europa.eu/news/news/2026/cef-2026-edpb-launches-coordinated-enforcement-action-transparency-and-information_en" target="_blank" rel="noopener noreferrer">EDPB, 2026-03-19</a>). Participating DPAs include Austria, Denmark, Germany (Brandenburg, Niedersachsen), Finland, France, Greece, Spain, Italy, Malta, Slovenia, Slovakia. Each DPA may conduct either formal enforcement actions or lighter-touch fact-finding exercises; findings consolidated into an aggregated EDPB report in H2 2026. <strong>What defenders need to do differently:</strong> audit privacy notices — website cookie banners, HR processing notices, CCTV notices, AI-generated data notices — against the Articles 12–14 checklist; given the EU&#39;s 2026 AI Act obligations also arriving in August, transparency failures in AI-generated personal-data processing are likely to attract enforcement attention. CEF findings frequently trigger follow-on national investigations at DPAs that identify outliers. Single-source national-CERT carve-out applies (EDPB is the primary disclosing authority for its own programme).</p><div class="prov"><span>policy</span><span>04 May 05:00Z</span><span class="p-warn">single-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/edpb-coordinated-enforcement-framework-2026-25-dpas-target-g/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.edpb.europa.eu/news/news/2026/cef-2026-edpb-launches-coordinated-enforcement-action-transparency-and-information_en" target="_blank" rel="noopener noreferrer">EDPB — CEF 2026 launches coordinated enforcement action on transparency</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/germany-kritis-dachg-in-force-public-administration-first-ti" data-tags="law-enforcement ot-ics eu-nexus" data-regions="europe dach" data-kind="policy" data-priority="notable" data-discovered="2026-05-04T05:00:48Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="germany-kritis-dachg-in-force-public-administration-first-ti"><a href="https://ctipilot.ch/entries/2026-05-04/germany-kritis-dachg-in-force-public-administration-first-ti/">Germany KRITIS-DachG in force — public administration first time in critical-infrastructure scope; registration deadline 17 July 2026</a></h3><p>Germany&#39;s KRITIS-DachG (Act to Strengthen Physical Resilience of Critical Installations), implementing EU CER Directive 2022/2557, entered into force in late March 2026 following Bundesrat approval on 6 March 2026 (<a href="https://www.luther-lawfirm.com/en/newsroom/blog/detail/kritis-dachgesetz-in-kraft-neue-pflichten-hohe-bussgelder-und-viele-offene-fragen-fuer-betreiber-kritischer-anlagen" target="_blank" rel="noopener noreferrer">Luther Lawfirm, 2026-04-10</a> · <a href="https://www.mofo.com/resources/insights/260501-european-digital-compliance-key-digital-regulation" target="_blank" rel="noopener noreferrer">Morrison Foerster European Digital Compliance, 2026-05-01</a>). The Act establishes the first cross-sectoral physical and organisational resilience framework covering energy, transport, healthcare, water, finance, and — for the first time — municipal waste disposal and aspects of public administration. <strong>Registration deadline 17 July 2026</strong> (or within three months of later qualification). Post-registration obligations cascade over nine–ten months: risk assessments every four years covering natural / technical / sabotage / cross-border scenarios, resilience plans, and <strong>24-hour incident reporting</strong> to a joint BSI/BBK reporting point. Fines for non-compliance: up to €100,000 for registration/cooperation failures; up to €1,000,000 for concealing non-registration status; up to €200,000 for missing resilience evidence or plan. Key ambiguity: the BMI implementing ordinance defining which specific services and installations qualify as &quot;critical&quot; is not yet published, leaving scope uncertain for borderline operators. <strong>What defenders need to do differently:</strong> German public-sector and critical-sector organisations need to self-assess KRITIS-DachG applicability before 17 July; ISG-style 24-hour reporting obligation now applies to physical as well as cyber incidents; Swiss entities with German subsidiaries operating in scope sectors are directly affected. Cross-references NIS2 and BSI Act obligations — the three frameworks overlap operationally and require coordinated incident-response runbook design.</p><div class="prov"><span>policy</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/germany-kritis-dachg-in-force-public-administration-first-ti/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.luther-lawfirm.com/en/newsroom/blog/detail/kritis-dachgesetz-in-kraft-neue-pflichten-hohe-bussgelder-und-viele-offene-fragen-fuer-betreiber-kritischer-anlagen" target="_blank" rel="noopener noreferrer">Luther Lawfirm — KRITIS-Dachgesetz</a> · <a href="https://www.mofo.com/resources/insights/260501-european-digital-compliance-key-digital-regulation" target="_blank" rel="noopener noreferrer">Morrison Foerster — European Digital Compliance May 2026</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/eu-cybersecurity-package-2026-nis2-amendment-com-2026-13-cyb" data-tags="law-enforcement eu-nexus vulnerabilities" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-04T05:00:47Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="eu-cybersecurity-package-2026-nis2-amendment-com-2026-13-cyb"><a href="https://ctipilot.ch/entries/2026-05-04/eu-cybersecurity-package-2026-nis2-amendment-com-2026-13-cyb/">EU Cybersecurity Package 2026 — NIS2 amendment (COM(2026) 13) + Cybersecurity Act 2 enter EP preparatory phase; PQC obligation embedded</a></h3><p>The European Commission&#39;s 20 January 2026 cybersecurity package bundles a targeted NIS2 amendment (COM(2026) 13) with a new Cybersecurity Act 2 (CSA2). Public-feedback period closed 22 April 2026 — the package is now in the European Parliament preparatory phase, with political agreement targeted for early 2027. Key NIS2-amendment changes obligations-relevant to Swiss / EU public-sector SOCs: (1) scope expansion to submarine data-transmission infrastructure (SDTI) operators and European Digital Identity Wallet providers as essential entities; (2) <strong>mandatory ransomware reporting</strong> — competent authorities can demand whether a ransom was paid, to whom, and how much, when a reported incident involves ransomware; (3) Article 21 harmonised technical requirements at Commission level create a regulatory ceiling, blocking member states from adding further technical obligations — meaning an EU certification scheme can demonstrate compliance portably; (4) new <strong>Article 7(2)(k) mandates member-state PQC transition policies</strong> aligned with the 2030 (critical uses) / 2035 (medium/low uses) roadmap — the first time post-quantum is an explicit named NIS2 obligation rather than implied &quot;state of the art&quot; interpretation (<a href="https://www.dlapiper.com/en/insights/publications/2026/02/nis2-update-eu-moves-to-harmonise-cyber-controls-refine-scope-and-add-new-in-scope-entities" target="_blank" rel="noopener noreferrer">DLA Piper, 2026-02-16</a> · <a href="https://www.skadden.com/insights/publications/2026/03/european-commission-announces-potential-nis2-cybersecurity-reform" target="_blank" rel="noopener noreferrer">Skadden, 2026-03-27</a> · <a href="https://postquantum.com/security-pqc/eu-pqc-nis2/" target="_blank" rel="noopener noreferrer">PostQuantum.com — EU PQC NIS2, 2026-02-13</a>).</p>
<p>CSA2 introduces the EU&#39;s first horizontal ICT supply-chain security framework: the Commission designates &quot;key ICT assets&quot; used by NIS2-essential entities, identifies high-risk supplier countries, and may prohibit or restrict their components in those assets — directly analogous to 5G supply-chain restrictions, now extended to all essential sectors. ENISA&#39;s budget rises 75%+ and it takes on operational functions including the <strong>European Vulnerability Database (EUVD)</strong>, early-warning publication, and the <strong>CRA Single Reporting Platform (SRP) — live 11 September 2026</strong> (<a href="https://www.globalpolicywatch.com/2026/01/european-commission-proposes-cybersecurity-act-2-new-eu-supply-chain-rules-and-certification-reforms/" target="_blank" rel="noopener noreferrer">Covington — Cybersecurity Act 2, 2026-01-23</a>). <strong>What defenders need to do differently:</strong> (1) inventory current &quot;state of the art&quot; cryptography claims that relied on implicit NIS2 interpretation — the explicit PQC Article creates a documented compliance gap supervisors can cite in audit findings; (2) plan for SRP single-report submission flow ahead of 11 September 2026 — public-sector and vendor PSIRTs operating in NIS2-essential categories will be expected to publish through this channel rather than parallel-submit to member-state CSIRTs; (3) ransomware playbooks should anticipate the documentation question chain on payment-or-not, intermediary used, amount transferred. NIS2 amendment requires 12-month transposition; CSA2 applies directly.</p><div class="prov"><span>policy</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/eu-cybersecurity-package-2026-nis2-amendment-com-2026-13-cyb/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.dlapiper.com/en/insights/publications/2026/02/nis2-update-eu-moves-to-harmonise-cyber-controls-refine-scope-and-add-new-in-scope-entities" target="_blank" rel="noopener noreferrer">DLA Piper — NIS2 update EU moves to harmonise cyber controls</a> · <a href="https://www.skadden.com/insights/publications/2026/03/european-commission-announces-potential-nis2-cybersecurity-reform" target="_blank" rel="noopener noreferrer">Skadden — Potential NIS2 cybersecurity reform</a> · <a href="https://www.globalpolicywatch.com/2026/01/european-commission-proposes-cybersecurity-act-2-new-eu-supply-chain-rules-and-certification-reforms/" target="_blank" rel="noopener noreferrer">Covington — Cybersecurity Act 2</a> · <a href="https://postquantum.com/security-pqc/eu-pqc-nis2/" target="_blank" rel="noopener noreferrer">PostQuantum.com — EU PQC NIS2</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/europol-shadow-it-libe-committee-meps-call-for-mandate-expan" data-tags="insider-threat law-enforcement data-breach eu-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-04T05:00:46Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="europol-shadow-it-libe-committee-meps-call-for-mandate-expan"><a href="https://ctipilot.ch/entries/2026-05-04/europol-shadow-it-libe-committee-meps-call-for-mandate-expan/">Europol shadow-IT — LIBE committee MEPs call for mandate-expansion pause; EDPS sanctioning toolkit identified as binary</a></h3><p>The Correctiv / Solomon / Computer Weekly joint investigation (2026-05-05; first covered 2026-05-07) drove a material EU-legislative response within the window. On 8 May the LIBE committee met to discuss the disclosure; multiple MEPs — German Left MEP Özlem Alev Demirel, Belgian Green MEP Saskia Bricmont, German S&amp;D MEP Birgit Sippel — called on the Commission to <strong>pause any expansion of Europol&#39;s mandate</strong> until parliamentary intervention powers and independent supervision are strengthened (<a href="https://www.computerweekly.com/news/366642721/MEPs-call-for-greater-scrutiny-of-Europol-following-concerns-over-Shadow-IT" target="_blank" rel="noopener noreferrer">Computer Weekly, 2026-05-08</a>). EDPS chief Wojciech Wiewiórowski told the LIBE meeting that EDPS enforcement has a binary-only toolkit — soft admonishments or hard processing-cessation orders — with no intermediate sanctions, and that enlarging Europol without strengthening EDPS sanctioning power would be counterproductive. <strong>Why this is obligations-changing:</strong> the European Commission&#39;s 2026 work programme envisages a new Europol Regulation proposal in Q2 2026, meaning the parliamentary backlash lands directly in the legislative window. Per Correctiv&#39;s investigation, the EDPS closed monitoring of the CFN platform in February 2026 despite 15 of 150 remediation recommendations remaining unimplemented — a decision now facing retrospective scrutiny (<a href="https://correctiv.org/en/europe/2026/05/05/they-protect-the-law-while-breaking-it-inside-europols-shadow-it-system/" target="_blank" rel="noopener noreferrer">Correctiv investigation, 2026-05-05</a>).</p>
<p>Background, restated from § 5: a Correctiv / Solomon / Computer Weekly joint investigation revealed that Europol&#39;s CFN (Computer Forensic Network, since 2012) and &quot;Pressure Cooker&quot; (Internet Referral Unit) data-processing platforms — holding ≥ 2 PB — operated outside EU data-protection oversight for over a decade (<a href="https://correctiv.org/en/europe/2026/05/05/they-protect-the-law-while-breaking-it-inside-europols-shadow-it-system/" target="_blank" rel="noopener noreferrer">Correctiv, 2026-05-05</a> · <a href="https://www.computerweekly.com/news/366642525/They-protect-the-law-while-breaking-it-Inside-Europols-shadow-IT-system" target="_blank" rel="noopener noreferrer">Computer Weekly investigation, 2026-05-05</a> · <a href="https://ctipilot.ch/briefs/2026-05-07/" target="_blank" rel="noopener noreferrer">daily 2026-05-07</a>). Multiple categorised security deficiencies were identified in the 2019 internal assessment including absent administrative usage logs and inability to track data access or detect unauthorised modifications. <strong>What defenders need to do differently:</strong> agencies contributing intelligence to Europol-adjacent information-sharing chains (SIE, SIENA, Europol Platform for Experts) should treat the documented control deficiencies (absent audit logs, missing event monitoring, inability to track data access or detect unauthorised modifications, ineffective role assignment) as an ongoing data-integrity and confidentiality risk rather than a closed historical finding; internal audit functions should re-confirm closure evidence on regulator-mandated remediation tasks rather than rely on regulator monitoring termination as confirmation of remediation completeness.</p><div class="prov"><span>policy</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/europol-shadow-it-libe-committee-meps-call-for-mandate-expan/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.computerweekly.com/news/366642721/MEPs-call-for-greater-scrutiny-of-Europol-following-concerns-over-Shadow-IT" target="_blank" rel="noopener noreferrer">Computer Weekly — MEPs call for greater scrutiny of Europol</a> · <a href="https://correctiv.org/en/europe/2026/05/05/they-protect-the-law-while-breaking-it-inside-europols-shadow-it-system/" target="_blank" rel="noopener noreferrer">Correctiv — Europol shadow IT</a> · <a href="https://www.computerweekly.com/news/366642525/They-protect-the-law-while-breaking-it-Inside-Europols-shadow-IT-system" target="_blank" rel="noopener noreferrer">Computer Weekly investigation</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/german-lg-berlin-ii-apobank-ruling-sets-psd2-ip-analytics-ob" data-tags="phishing identity law-enforcement" data-regions="europe dach" data-kind="policy" data-priority="notable" data-discovered="2026-05-04T05:00:45Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="german-lg-berlin-ii-apobank-ruling-sets-psd2-ip-analytics-ob"><a href="https://ctipilot.ch/entries/2026-05-04/german-lg-berlin-ii-apobank-ruling-sets-psd2-ip-analytics-ob/">German LG Berlin II — Apobank ruling sets PSD2 IP-analytics obligation as case law</a></h3><p>The Apobank phishing-liability ruling (LG Berlin II, case 38 O 293/25, 2026-04-22; not yet final pending appeal) explicitly places liability on the bank for failing to act on IP / ISP divergence between new-device registration and first login — interpreted under Germany&#39;s PSD2 implementation as an obligation to deploy IP-based behavioural analytics and trigger strong-customer-authentication challenges when registration and first-use IPs diverge (<a href="https://www.heise.de/news/Urteil-gegen-die-Apobank-Finanzinstitut-haftet-fuer-Phishing-Schaden-11288231.html" target="_blank" rel="noopener noreferrer">heise online, 2026-05-08</a> · <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09</a>). <strong>What changed:</strong> even if not yet final on appeal, the ruling is the most explicit case-law statement to date in a PSD2 jurisdiction that <em>failure to act on a fraud signal present in bank-side telemetry</em> shifts liability to the service provider. <strong>What defenders need to do differently:</strong> EU and Swiss financial-sector and public-sector digital-service providers should treat register-new-device and first-login IP / ISP comparison as a regulatory expectation rather than best practice — and should specifically ensure the SCA-step-up signal can be raised in real time on this anomaly. Anticipate other EU member-state PSD2 jurisdictions following the LG Berlin II reasoning.</p><div class="prov"><span>policy</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/german-lg-berlin-ii-apobank-ruling-sets-psd2-ip-analytics-ob/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.heise.de/news/Urteil-gegen-die-Apobank-Finanzinstitut-haftet-fuer-Phishing-Schaden-11288231.html" target="_blank" rel="noopener noreferrer">heise online — Urteil gegen die Apobank</a> · <a href="https://www.anwalt.de/rechtstipps/phishing-ilex-rechtsanwaelte-erwirkt-haftung-der-apobank-269786.html" target="_blank" rel="noopener noreferrer">ilex Rechtsanwälte case summary</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/polish-nis2-transposition-abw-recommendation-to-expand-essen" data-tags="law-enforcement ot-ics eu-nexus" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-04T05:00:44Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="polish-nis2-transposition-abw-recommendation-to-expand-essen"><a href="https://ctipilot.ch/entries/2026-05-04/polish-nis2-transposition-abw-recommendation-to-expand-essen/">Polish NIS2 transposition + ABW recommendation to expand essential-entity coverage below headcount threshold</a></h3><p>ABW&#39;s 2025 Annual Report (covered 2026-05-09) notes that Poland transposed NIS2 into national law effective 2026-02-01 (Ustawa z dnia 28 listopada 2025 r. o krajowym systemie cyberbezpieczeństwa) with water-distribution operators above the 50-employee threshold now classified as Essential Entities subject to mandatory incident notification to CSIRT GOV (ABW) within 24/72 hours. <strong>What changed in 2026-W19:</strong> ABW explicitly notes the five named water-OT-attack facilities fell below the NIS2 threshold at the time of intrusion and is recommending legislative action to extend NIS2 obligations to critical-function entities regardless of headcount (<a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09 UPDATE</a>). <strong>What defenders need to do differently:</strong> small CH/EU municipal CI operators (water, energy distribution, transport, healthcare) below NIS2 essential-entity thresholds should not assume regulatory-coverage absence implies threat-coverage absence; the ABW evidence demonstrates state-sponsored targeting concentrates <em>toward</em> under-regulated operators rather than away from them. Operators in this category should pre-emptively adopt NIS2-equivalent incident-notification and asset-inventory baselines. Dragos&#39;s 81% flat-network finding (§ 6) lands at the same operational target.</p><div class="prov"><span>policy</span><span>04 May 05:00Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/polish-nis2-transposition-abw-recommendation-to-expand-essen/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a" target="_blank" rel="noopener noreferrer">CISA AA24-207A (background)</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/cert-fr-certfr-2026-act-016-agentic-ai-three-risk-class-advi" data-tags="ai-abuse supply-chain vulnerabilities" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-04T05:00:43Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="cert-fr-certfr-2026-act-016-agentic-ai-three-risk-class-advi"><a href="https://ctipilot.ch/entries/2026-05-04/cert-fr-certfr-2026-act-016-agentic-ai-three-risk-class-advi/">CERT-FR CERTFR-2026-ACT-016 — agentic AI three-risk-class advisory; defender obligations explicit</a></h3><p>CERT-FR&#39;s advisory (dated 13 April 2026, surfaced in this week&#39;s daily on 2026-05-08) names three operational risk classes for organisations deploying agentic AI orchestration platforms (Claude Agents, Microsoft Copilot Studio, AutoGen, MCP-server architectures): <strong>prompt injection via processed documents or websites</strong> (attacker embeds instructions in content the agent processes, redirecting its actions); <strong>MCP server supply-chain compromise</strong> (a malicious or compromised Model Context Protocol server can issue instructions to all connected agents); and <strong>insufficient sandboxing</strong> of agent execution environments. CERT-FR recommendations: input/output guardrails, strict allowlisting of permitted tool calls, human-in-the-loop gates for high-impact actions, and treating all AI agent outputs as untrusted until validated (<a href="https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-016/" target="_blank" rel="noopener noreferrer">CERT-FR — CERTFR-2026-ACT-016, 2026-05-08</a> · <a href="https://ctipilot.ch/briefs/2026-05-08/" target="_blank" rel="noopener noreferrer">daily 2026-05-08</a>). <strong>Why this is obligations-changing rather than routine advisory:</strong> for French public-sector entities deploying agentic AI, CERT-FR advisories establish the baseline a defendable-control posture is measured against. The Microsoft Semantic Kernel CVE-2026-26030 / CVE-2026-25592 pair (§ 3 deep dive) is the worked-example of CERT-FR&#39;s first and third risk classes manifesting as concrete vendor CVEs — defenders deploying any agentic-AI framework should treat the CERT-FR advisory as defining the question-set, not the answer-set.</p><div class="prov"><span>policy</span><span>04 May 05:00Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/cert-fr-certfr-2026-act-016-agentic-ai-three-risk-class-advi/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-016/" target="_blank" rel="noopener noreferrer">CERT-FR — CERTFR-2026-ACT-016</a></div></article><article class="finding entry-card" data-entry-id="2026-05-04/enisa-expands-cve-numbering-authority-root-4-new-cnas-7-migr" data-tags="vulnerabilities eu-nexus law-enforcement" data-regions="europe" data-kind="policy" data-priority="notable" data-discovered="2026-05-04T05:00:42Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="enisa-expands-cve-numbering-authority-root-4-new-cnas-7-migr"><a href="https://ctipilot.ch/entries/2026-05-04/enisa-expands-cve-numbering-authority-root-4-new-cnas-7-migr/">ENISA expands CVE Numbering Authority root — 4 new CNAs, 7 migrated from MITRE; ~90 European CNAs eligible for transfer</a></h3><p>ENISA announced on 2026-05-06 that four organisations have joined the CVE Programme as CVE Numbering Authorities (CNAs) under ENISA Root, and that seven additional European CNAs have migrated from MITRE Root to ENISA Root (<a href="https://www.enisa.europa.eu/news/new-cve-numbering-authorities-under-enisa-root" target="_blank" rel="noopener noreferrer">ENISA, 2026-05-06</a>). ENISA was designated as a CVE Root in November 2025, establishing a European coordination tier alongside CISA (USA), JPCERT/CC (Japan), MITRE, and Google. Approximately 90 European organisations remain eligible for voluntary transfer — nearly one-fifth of the global CNA population. <strong>What changed:</strong> EU technology vendors and public-sector organisations now have a European coordination tier for CVE assignment — potentially affecting advisory publication timing and format compared to MITRE Root coordination, particularly for products made by EU software vendors. <strong>What defenders need to do differently:</strong> EU public-sector CNAs and vendor PSIRTs should re-confirm their root assignment and review whether their disclosure-coordination contacts at ENISA Root differ from their MITRE Root contacts; defender-side SIRT / vulnerability-management functions should expect ENISA-coordinated EU-discovered CVEs to ship through ENISA-supervised channels going forward. The CRA (Cyber Resilience Act) framework drives the migration. Names of the four new CNAs were not disclosed in the press release; more transfers expected.</p><div class="prov"><span>policy</span><span>04 May 05:00Z</span><span class="p-warn">single-source · national CERT</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/enisa-expands-cve-numbering-authority-root-4-new-cnas-7-migr/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.enisa.europa.eu/news/new-cve-numbering-authorities-under-enisa-root" target="_blank" rel="noopener noreferrer">ENISA — New CVE Numbering Authorities under ENISA Root</a></div></article><div class="sect" id="looking-ahead-what-to-watch-next-week"><span class="n">09</span><span class="t">Looking ahead · what to watch next week</span><span class="c">1 item</span></div><article class="finding entry-card" data-entry-id="2026-05-04/looking-ahead-2026-w19" data-tags="lpe" data-regions="global" data-kind="outlook" data-priority="notable" data-discovered="2026-05-04T05:00:52Z"><div class="badges"><span class="b ">NOTABLE</span></div><h3 class="f-h" id="looking-ahead-2026-w19"><a href="https://ctipilot.ch/entries/2026-05-04/looking-ahead-2026-w19/">Looking ahead — 2026-W19</a></h3><p>Items already in motion at the close of 2026-W19. Not predictions — each links to the in-motion reporting underneath.</p>
<ul><li><strong>Canvas / Instructure extortion deadline — Tuesday 2026-05-12 (two days out).</strong> Second-intrusion claim against Instructure made 2026-05-08 despite the May 8 patches; seven Dutch universities disconnected; Dutch DPA and ICO engaged. If deadline passes with no payment and a fresh data dump lands, the second-intrusion claim will have been verified (<a href="https://ctipilot.ch/briefs/2026-05-10/" target="_blank" rel="noopener noreferrer">daily 2026-05-10 UPDATE</a>; <a href="https://www.techzine.eu/news/security/141149/dutch-university-disconnects-canvas-systems-after-instructure-hack/" target="_blank" rel="noopener noreferrer">Techzine EU</a>).</li><li><strong>PAN-OS CVE-2026-0300 first patch landing 2026-05-13 (Monday).</strong> No patch exists at week-end; staged release runs 2026-05-13 → 2026-05-28 across PAN-OS branches. Retrospective hunt for <code>svc-health-check-NNNNNN</code> admin accounts and <code>/var/tmp/linuxupdate</code> / <code>/tmp/.c</code> Python implants is the open work item for organisations who were CL-STA-1132 targets between 2026-04-09 and patch deployment (<a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto PSIRT</a>; <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09</a>).</li><li><strong>CVE-2026-31431 &quot;Copy Fail&quot; patch propagation through Friday 2026-05-15.</strong> Distro patches continuing to land; Debian 12 patch was pending at week-end; combined-use pattern with Dirty Frag means a host patched for one but not the other still has an LPE primitive available. The Microsoft Security Blog detection-pivot writeup is the right hunt reference (<a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09 UPDATE</a>).</li><li><strong>CVE-2026-43500 (Dirty Frag RxRPC) distribution patches pending.</strong> Distro patches were pending at week-end; CVE-2026-43284 (xfrm-ESP) mainline patch landed 2026-05-08; the second primitive&#39;s patch propagation is the open work. Interim mitigation <code>modprobe -r esp4 esp6 rxrpc</code> breaks IPsec VPNs and AFS so production rollout requires impact-test (<a href="https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc" target="_blank" rel="noopener noreferrer">Wiz Research</a>; <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09</a>).</li><li><strong>CVE-2026-42208 LiteLLM Proxy deadline 2026-05-11 (Monday).</strong> Patch to ≥ 1.83.7; rotate every upstream LLM-provider API key the proxy ever held. The corollary action item — inventory of every AI-tooling SaaS vendor holding organisation-level upstream-provider keys, with rotation drills — should ship in the same change window (<a href="https://bishopfox.com/blog/cve-2026-42208-pre-authentication-sql-injection-in-litellm-proxy" target="_blank" rel="noopener noreferrer">Bishop Fox</a>; <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09</a>).</li><li><strong>MOVEit Automation CVE-2026-4670 — exploitation still not confirmed at week-end; watch for KEV addition or first-victim disclosure.</strong> No in-the-wild exploitation has been confirmed by Progress, CISA, or any threat-intelligence source as of 2026-05-10. The 2023 MOVEit Transfer Cl0p precedent primed expectations for rapid exploitation; the absence of ITW confirmation is itself a status worth tracking through 2026-W20. Unpatched MOVEit Automation deployments remain at risk; if KEV addition or victim disclosure lands in next week&#39;s reporting, it will be the highest-priority pivot (<a href="https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/" target="_blank" rel="noopener noreferrer">Help Net Security</a>; <a href="https://ctipilot.ch/briefs/2026-05-06/" target="_blank" rel="noopener noreferrer">daily 2026-05-06</a>).</li><li><strong>SEPPmail CVE-2026-44128 — independent third-party security-researcher analysis.</strong> Currently single-sourced to NCSC-CH + vendor release notes (national-CERT carve-out applies). Watch for a vendor-PSIRT-style third-party write-up that would corroborate the exploitation-path detail; the GINAv2 <code>/gina/diag/exec</code> mechanic is sufficiently specific that PoC publication is plausible (<a href="https://security-hub.ncsc.admin.ch/api/posts/12551/details" target="_blank" rel="noopener noreferrer">NCSC-CH 12551</a>; <a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09</a>).</li><li><strong>Ivanti EPMM May 2026 patch wave aftermath.</strong> With the KEV deadline (2026-05-10) expired and 508 EU instances confirmed exposed, the public-disclosure roster of EU compromised entities is likely to expand. Watch for additional EU member-state CSIRT advisories naming victims (<a href="https://www.ivanti.com/blog/may-2026-epmm-security-update" target="_blank" rel="noopener noreferrer">Ivanti PSIRT</a>; <a href="https://ctipilot.ch/briefs/2026-05-08/" target="_blank" rel="noopener noreferrer">daily 2026-05-08 deep dive</a>).</li><li><strong>&quot;The Gentlemen&quot; RaaS — European concentration likely to continue into Q2.</strong> W1 horizon research surfaced the operator pattern; with ZeroFox-reported 32% Q1 2026 European targeting (up from 2% in Q4 2025) and GPO-injected scheduled-task encryptor propagation across compromised AD domains, continued European victim claims through 2026-Q2 are in motion. Watch for fresh CH/EU public-sector victim disclosures (<a href="https://research.checkpoint.com/2026/dfir-report-the-gentlemen/" target="_blank" rel="noopener noreferrer">Check Point Research DFIR Report</a>; <a href="https://www.zerofox.com/intelligence/q1-2026-ransomware-wrap-up/" target="_blank" rel="noopener noreferrer">ZeroFox Q1 2026 Wrap-Up</a>; § 7).</li><li><strong>AI-tooling SaaS multi-tenant credential aggregation — sector pattern still surfacing.</strong> Braintrust (2026-05-04 AWS) and LiteLLM Proxy (KEV 2026-05-11) are the two confirmed examples of the same architectural class this week. Watch for additional AI-evaluation, AI-observability, AI-agent-gateway, or prompt-management vendor breaches; the operator class behind ShinyHunters / WorldLeaks is actively exploiting the third-party-SaaS pivot pattern (<a href="https://techcrunch.com/2026/05/06/ai-evaluation-startup-braintrust-confirms-breach-tells-every-customer-to-rotate-sensitive-keys/" target="_blank" rel="noopener noreferrer">TechCrunch — Braintrust</a>; <a href="https://ctipilot.ch/briefs/2026-05-10/" target="_blank" rel="noopener noreferrer">daily 2026-05-10</a>).</li><li><strong>ABW NIS2 extension proposal — EU follow-on movement.</strong> ABW recommended legislative action to extend NIS2 essential-entity obligations to critical-function entities regardless of headcount (currently many small municipal CI operators sit below threshold). Whether this proposal gains EU-level momentum, or whether other member-state CSIRTs / EU institutions echo the same call after the Polish-water-OT tri-attribution, is the policy-horizon story to track (<a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09 UPDATE</a>).</li><li><strong>ENISA CVE Root migration — 4 new CNA names pending disclosure.</strong> ENISA&#39;s 2026-05-06 announcement did not disclose the four new CNAs; ~90 European CNAs remain eligible for voluntary transfer. Disclosure of the 4 named CNAs and any additional transfers in 2026-W20 will inform EU public-sector PSIRT-coordination posture (<a href="https://www.enisa.europa.eu/news/new-cve-numbering-authorities-under-enisa-root" target="_blank" rel="noopener noreferrer">ENISA</a>; <a href="https://ctipilot.ch/briefs/2026-05-07/" target="_blank" rel="noopener noreferrer">daily 2026-05-07</a>).</li></ul><div class="prov"><span>outlook</span><span>04 May 05:00Z</span><span class="p-ok">multi-source</span><a class="refs" href="https://ctipilot.ch/entries/2026-05-04/looking-ahead-2026-w19/">Open finding ↗</a></div><div class="f-sources"><span class="f-sources__l">Sources:</span> <a href="https://www.techzine.eu/news/security/141149/dutch-university-disconnects-canvas-systems-after-instructure-hack/" target="_blank" rel="noopener noreferrer">Techzine EU</a> · <a href="https://security.paloaltonetworks.com/CVE-2026-0300" target="_blank" rel="noopener noreferrer">Palo Alto PSIRT</a> · <a href="https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc" target="_blank" rel="noopener noreferrer">Wiz Research</a> · <a href="https://bishopfox.com/blog/cve-2026-42208-pre-authentication-sql-injection-in-litellm-proxy" target="_blank" rel="noopener noreferrer">Bishop Fox</a> · <a href="https://www.helpnetsecurity.com/2026/05/04/critical-moveit-automation-auth-bypass-vulnerability-fixed-cve-2026-4670/" target="_blank" rel="noopener noreferrer">Help Net Security</a> · <a href="https://security-hub.ncsc.admin.ch/api/posts/12551/details" target="_blank" rel="noopener noreferrer">NCSC-CH 12551</a> · <a href="https://www.ivanti.com/blog/may-2026-epmm-security-update" target="_blank" rel="noopener noreferrer">Ivanti PSIRT</a> · <a href="https://research.checkpoint.com/2026/dfir-report-the-gentlemen/" target="_blank" rel="noopener noreferrer">Check Point Research DFIR Report</a> · <a href="https://www.zerofox.com/intelligence/q1-2026-ransomware-wrap-up/" target="_blank" rel="noopener noreferrer">ZeroFox Q1 2026 Wrap-Up</a> · <a href="https://techcrunch.com/2026/05/06/ai-evaluation-startup-braintrust-confirms-breach-tells-every-customer-to-rotate-sensitive-keys/" target="_blank" rel="noopener noreferrer">TechCrunch — Braintrust</a> · <a href="https://www.enisa.europa.eu/news/new-cve-numbering-authorities-under-enisa-root" target="_blank" rel="noopener noreferrer">ENISA</a></div></article><details class="verif"><summary class="vh">About this weekly<span class="verif-count">1 run</span><svg class="verif-chev" viewBox="0 0 24 24" width="12" height="12" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" aria-hidden="true"><path d="M6 9l6 6 6-6"></path></svg></summary><div class="verif-body"><div class="run-note" data-run-id="2026-W19-a5788b22"><h3 class="run-note__head"><span class="mono">2026-W19-a5788b22</span> <span class="muted">· weekly · Claude Opus 4.7 · 53 entries published</span></h3><div class="run-note__body"><p><strong>This is the first weekly summary in the series.</strong> <code>briefs/weekly/</code> was empty at run start; <code>window_days = 7</code> per default. Window: 2026-05-04 → 2026-05-10 (ISO week 2026-W19). Five daily briefs in window (2026-05-06 through 2026-05-10) were read in full; the gap between Monday 2026-05-04 and Wednesday 2026-05-06 reflects daily-routine start cadence rather than a coverage failure.</p>
<p><strong>Items still flagged <code>[SINGLE-SOURCE]</code>-equivalent in this run:</strong></p>
<ul><li><strong>SEPPmail CVE cluster (CVE-2026-44128 et al.)</strong> — primary advisory is NCSC-CH post 12551 (national-CERT carve-out applies) plus SEPPmail vendor release notes; no third-party security-researcher write-up located in window. Logged in daily 2026-05-09 § 7 as <code>[SINGLE-SOURCE-NATIONAL-CERT carve-out + vendor]</code>.</li><li><strong>MuddyWater Chaos ransomware false-flag campaign</strong> — single source Deep Instinct (daily 2026-05-08). Included given confirmed Iran-nexus TTP and European targeting; treated with standard single-source caution.</li><li><strong>Amazon SES BEC technique</strong> — single source Kaspersky Securelist 2026-05-04 (daily 2026-05-08). Included as first coverage with age noted.</li><li><strong>xrdp CVE-2025-68670</strong> — single source Kaspersky Securelist 2026-05-08 (daily 2026-05-09). Vendor (xrdp project) GitHub commit and release 0.10.5 confirm the patch but not the vulnerability analysis.</li><li><strong>Polish water OT named-facility list (Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, Sierakowo)</strong> — facility names appear only in the ABW 2025 Annual Report. The two-source requirement is met at the level of the core story (ABW annual report + SecurityAffairs coverage), but the specific facility names derive from a single document.</li><li><strong>CERT-FR CERTFR-2026-ACT-016 (agentic AI advisory)</strong> — single-source national-CERT carve-out applies.</li><li><strong>Bauman / GRU Department No. 4 investigation</strong> — six co-publishing outlets (The Insider, The Guardian, Le Monde, Der Spiegel, VSquare, Frontstory) constitute multi-source verification at the source-document level; the leaked-documents corpus itself is a single dataset, so cross-publisher reading of the same documents is the corroboration standard applied. <strong>Note:</strong> the specific APT28-to-2016-Bundestag and APT28-to-2017-Macron-campaign attributions surfaced in § 7 trace to the Guardian / Le Monde / Der Spiegel reporting; Meduza (the most accessible English mirror) corroborates the Sandworm / Unit 74455 / Kyivstar / NotPetya / Ukraine-power-grid attributions but does not itself name the Bundestag / Macron specifics. Readers verifying these latter two should consult the German / French primary outlets.</li></ul>
<p><strong>Items dropped from this week&#39;s roll-up that may resurface:</strong></p>
<ul><li><strong>CallPhantom Android subscription-fraud cluster</strong> (28 apps, 7.3 M downloads; ESET 2026-05-07; daily 2026-05-10 § 7) — dropped under PD-11 (less is more) as off-audience consumer-mobile fraud rather than enterprise / public-sector defender content. If a CH/EU regulator opens an enforcement action against the 28-app cluster, this resurfaces.</li><li><strong>TCLBANKER (Brazilian banking trojan)</strong> (Elastic Security Labs, daily 2026-05-07 / 2026-05-10) — Brazil-only geofenced targeting; no CH/EU defender takeaway materially different from generic &quot;audit COM-driven Outlook automation&quot;.</li><li><strong>Cisco Unity Connection CVE-2026-20034 / 20035</strong> (daily 2026-05-10) — patched; not on KEV; no in-the-wild exploitation reported; rarely internet-exposed. Did not clear weekly §3 inclusion gates.</li><li><strong>Laclinic-Montreux / Qilin</strong> dark-web aggregator listing (daily 2026-05-10) — no victim public statement, no independent corroboration; held under PD-6 (fake-news guard / leak-site claims require victim disclosure or HIGH-reliability journalism).</li><li><strong>Microsoft AiTM &quot;Code of Conduct&quot; phishing campaign</strong> (Microsoft Threat Intelligence, 2026-05-04; covered daily 2026-05-06) and <strong>Microsoft Edge cleartext passwords in process memory</strong> (SANS ISC Diary, 2026-05-04; covered daily 2026-05-06) — both <code>[SINGLE-SOURCE-OTHER]</code> items from the start of the window; no material in-window development to surface them in the weekly. The Edge finding remains relevant to public-sector privileged-account hygiene but does not meet W-PD-1&#39;s three-question gate at the weekly level.</li></ul>
<p><strong>Contradictions / ambiguities flagged for the verifier&#39;s attention:</strong></p>
<ul><li><strong>Ivanti EPMM named-EU-victim attribution.</strong> The daily 2026-05-09 names European Commission, Dutch DPA, Netherlands Council for the Judiciary, and Finnish Valtori as confirmed victims of the May 2026 wave (CVE-2026-5787 / CVE-2026-6973), citing CERT-FR CERTFR-2026-AVI-0552 and NCSC-CH 12548 (<a href="https://ctipilot.ch/briefs/2026-05-09/" target="_blank" rel="noopener noreferrer">daily 2026-05-09</a>); W1 horizon research re-reading <a href="https://www.helpnetsecurity.com/2026/05/08/ivanti-epmm-zero-day-cve-2026-6973/" target="_blank" rel="noopener noreferrer">Help Net Security, 2026-05-08</a> concluded the four organisations were victims of the <em>January 2026</em> chain (CVE-2026-1281 / CVE-2026-1340), not the May 2026 chain — Ivanti has disclosed only &quot;a very limited number of customers&quot; exploited via the May chain without naming specifics. The weekly carries the daily&#39;s attribution because the daily was source-verified at composition time, but flags this for verifier review with both sources noted; defenders&#39; operational response — patch and rotate — is identical regardless of which chain caught which organisation, so the brief framing intentionally does not lock either way.</li><li><strong>Microsoft Semantic Kernel CVE-2026-25592 patched Python version.</strong> GitHub advisory GHSA-2ww3-72rp-wpp4 records 1.39.3 as the patched Python version; Microsoft research post and GHSA-xjw9-4gw8-4rqx (CVE-2026-26030) record 1.39.4. The brief recommends <strong>≥ 1.39.4</strong> as the single safe target since it supersedes 1.39.3 and closes both CVEs.</li><li><strong>Akira-as-actor attribution for Groupe 3R.</strong> Victim statement and Swiss-press reporting confirm the incident and 2026-04-30 attack date; the Akira-as-actor attribution comes from <code>ransomware.live</code> (aggregator), not from the victim or an independent primary research lab. Logged with confidence HIGH on incident, MEDIUM on actor.</li><li><strong>Ivanti EPMM exposure count.</strong> The &quot;508 EU on-premises instances&quot; figure originally surfaced via NCSC-NL scanning (daily 2026-05-09) and was reconfirmed by Shadowserver per BleepingComputer in the daily 2026-05-10 update with a global &quot;~850&quot; total. The two numbers are consistent (508 EU is the EU-specific count, ~850 is the global total).</li></ul>
<p><strong>Items included with reduced confidence:</strong></p>
<ul><li><strong>JDownloader Python-payload capability description.</strong> Primary developer-confirmed disclosure (<a href="https://piunikaweb.com/2026/05/08/jdownloader-website-hacked-malware/" target="_blank" rel="noopener noreferrer">PiunikaWeb, 2026-05-08</a>) corroborated by <a href="https://www.cyberkendra.com/2026/05/jdownloader-website-hacked-malicious.html" target="_blank" rel="noopener noreferrer">CyberKendra, 2026-05-07</a>; both are mid-tier publishers, and the more-specific Python-payload capability description has not been corroborated by a named research lab in this run. Supply-chain-compromise fact, time window, and forged-publisher signatures are developer- and multi-source-confirmed.</li></ul>
<p><strong>Sub-agent telemetry (Phase 2):</strong></p>
<ul><li><strong>W1</strong> (Long-horizon ongoing developments + annual reports) — returned: Claude Sonnet 4.6 (<code>claude-sonnet-4-6</code>); started_at=2026-05-10T22:07:45Z, ended_at=2026-05-10T22:14:47Z, duration_seconds=422; webfetch_calls=9, websearch_calls=22, bridge_fetches=2. Returned 8 items; net-new horizon items integrated: &quot;The Gentlemen&quot; RaaS + Q1 2026 ransomware quarterly synthesis (§§ 6/7); Akamai&#39;s PatchDiff-AI incomplete-patch analysis for CVE-2026-32202 (§ 3); German Akira healthcare victims (§ 7). W1 fetch_failures: group-ib (403, mitigated via secondary sources); thehackernews on SystemBC C2 (503, mitigated via BleepingComputer / CPR).</li><li><strong>W2</strong> (Strategic &amp; policy horizon) — returned: Claude Sonnet 4.6 (<code>claude-sonnet-4-6</code>); started_at=2026-05-10T22:08:24Z, ended_at=2026-05-10T22:19:12Z, duration_seconds=648; webfetch_calls=16, websearch_calls=18, bridge_fetches=3. Returned 8 items; net-new policy-horizon items integrated: LIBE MEPs call for Europol mandate-expansion pause (§ 8); EU Cybersecurity Package 2026 — NIS2 amendment COM(2026) 13 + Cybersecurity Act 2 with PQC Article 7(2)(k) (§ 8); Germany KRITIS-DachG in force with 17 July 2026 registration deadline (§ 8); EDPB 2026 CEF coordinated enforcement on GDPR Articles 12–14 transparency (§ 8); NCSC Switzerland 1 May 2026 AI-in-vulnerability-management BACS assessment (§ 8); Poland NIS2 transposition in force 3 April 2026 with water-sector essential-entity context (§ 8). W2 fetch_failures: autoriteitpersoonsgegevens.nl (503, no bridge available); coe-cybercrime (403, no bridge); bills-parliament-uk (403, mitigated via WebSearch); ncsc-ch-security-hub post-12552+ (no post exists — confirmed 12551 is most recent).</li></ul>
<p><strong>Sub-agent self-identification:</strong> both W1 and W2 self-identified as <code>Claude Sonnet 4.6</code> (canonical id <code>claude-sonnet-4-6</code>) — model id and friendly name are aligned, no drift. The 2026-05-10 daily noted four sub-agents self-identifying as <code>Claude Sonnet 4.5</code> with id <code>claude-sonnet-4-6</code> (drift); W1/W2 correct self-identification on this run is an improvement to record in <code>state/run_log.json</code>.</p>
<p><strong>Verification iterations: 5 iterations, final verdict CLEAN.</strong> Phase 4.7 ran the cti-verification sub-agent loop with model rotation: iter 1 Opus (NEEDS_FIXES, truth 17 / editorial 6 / advisory 3), iter 2 Sonnet (NEEDS_FIXES, truth 7 / editorial 5 / advisory 2), iter 3 Opus (NEEDS_FIXES, truth 10 / editorial 1 / advisory 3), iter 4 Sonnet (NEEDS_FIXES, truth 2 / editorial 1 / advisory 2), iter 5 Opus (CLEAN, 0 / 0 / 0). The verifier-loop telemetry block in <code>state/run_log.json.verification.iterations[]</code> records per-iteration model, timestamps, and finding counts.</p>
<p><strong><code>Coverage gaps:</code></strong> cisa-kev (no new KEV entries 2026-05-09 / 10, bridge-fetched cleanly); ncsc-ch-security-hub (most recent post 12551, 2026-05-08, no new posts in window; bridge mandated); ico-uk (JS SPA — persistent, no W19 enforcement decisions surfaced); databreaches-net (403 across UAs — persistent); csirt-acn-it (403 persistent, bridge allowlisted but no W19 item surfaced); ccn-cert-es (geo-blocked 451/403 — no W19 item; Inditex/AEPD enforcement not yet a formal decision); inside-it-ch (403 direct, bridge needed); prodaft (403 persistent); nccgroup (403 persistent); enisa-euvd (SPA — content empty to WebFetch); advisories-ncsc-nl (CSAF SPA — listing returns no advisory data); cisco-psirt-publication-listing (Angular SPA — individual advisory URLs work directly); cert.ssi.gouv.fr (RSS works, individual advisory detail pages need bridge); bleepingcomputer article-page (403 on direct WebFetch — discovery via listing OK); group-ib (403 persistent — secondary corroboration acceptable); thehackernews (intermittent 503 on individual articles, secondary corroboration acceptable); autoriteitpersoonsgegevens.nl (503 — no bridge allowlist); coe-cybercrime (403 — no bridge); bills.parliament.uk (403 — WebSearch fallback); cnil-fr / finma / govcert-ch / govcert-at / cert-at (quiet window, no W19 policy items surfaced); edpb (W19 plenary 11 May not yet produced decisions — returns next week).</p>
<p><em>Migrated from briefs/weekly/2026-W19.md (v2).</em></p></div></div></div></details>]]></content:encoded></item></channel></rss>