Skip to content

Flash Briefings

high

GhostLock: 15-Year Linux Kernel Flaw Opens Root and Container Escape

A 15-year-old Linux kernel use-after-free vulnerability tracked as CVE-2026-43499 allows any logged-in user to gain root access on unpatched systems. Public exploit code is available and the flaw enables container escape, making patching of cloud, server, and multi-tenant Linux infrastructure an immediate priority.

high Armored Likho

Armored Likho Deploys BusySnake Stealer Against Government and Power Sector

Russia-linked threat actor Armored Likho has launched a credential theft campaign targeting government agencies and electric power infrastructure across Russia, Kazakhstan, and Brazil. The Python-based BusySnake infostealer extracts browser credentials, Telegram sessions, and crypto wallet keys while operating in-memory to evade disk-based detection.

critical

CISA Flags Critical Unauthenticated RCE in StoneFly Storage Appliances

CISA's June 30 ICS advisory batch reveals CVSS 9.8 flaws in StoneFly Storage Concentrator including unauthenticated command injection granting remote root access via TCP port 9000, alongside hardcoded credentials and SQL injection.

critical

CVE-2026-55200: Public PoC for Critical libssh2 Flaw Exposes Enterprise Infrastructure

A public proof-of-concept has been released for a CVSS 9.2 client-side flaw in libssh2 that enables zero-authentication remote code execution when connecting to a malicious or compromised SSH server. No official patched release exists yet.

critical

PTC Windchill RCE Exploited: JSP Web Shells Hit Manufacturing PLM

Attackers are deploying persistent JSP web shells via CVE-2026-12569, a critical unauthenticated RCE flaw in PTC Windchill and FlexPLM affecting 1.5 million users across defence, aerospace, and automotive manufacturing.

high Handala (MOIS / Banished Kitten)

Handala Breaches California Water Service via Third-Party Pivot, Mandiant Finds No OT Compromise

MOIS-affiliated Handala group accessed Cal Water billing systems via RTKBase pivot, exfiltrating 5GB of customer PII. Mandiant investigation found no OT access — but the claimed capability to disrupt water supply remains unverified propaganda.

critical

CISA KEV: Lantronix EDS5000 and Ubiquiti UniFi Under Active Attack

CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog on June 23, 2026, including a CVSS 9.8 code injection flaw in Lantronix EDS5000 serial device servers widely used in OT environments, and three maximum-severity flaws in Ubiquiti UniFi OS.

critical Velvet Ant

Velvet Ant's Operation Highland: China-Nexus APT Backdoored Linux Auth Stack for Nearly a Decade

Sygnia's disclosure of Operation Highland reveals a China-linked threat actor that modified PAM and OpenSSH components to maintain persistent, credential-harvesting access inside isolated networks from 2016 to at least 2026.

critical

CVE-2026-41089: Critical Windows Netlogon RCE Now Actively Exploited — Every Unpatched Domain Controller at Risk

Active exploitation of CVE-2026-41089, a pre-authentication zero-click RCE in Windows Netlogon, was confirmed by Belgium's Centre for Cybersecurity on 29 May. Successful exploitation gives an attacker SYSTEM-level control of the domain controller and full ownership of the Active Directory domain.

critical

Critical Unpatched RCE in Siemens RUGGEDCOM and ScadaBR -- No Fix Available for Either

CISA's May 19 ICS advisories flag unauthenticated root-level code execution in Siemens RUGGEDCOM APE1808 and ScadaBR SCADA software. Neither has a patch. The ScadaBR vendor has not responded to CISA.

critical Volt Typhoon

NCSC Warns: Volt Typhoon Reconnaissance Extends to Tier 2 UK Government Suppliers

Intelligence confirms Volt Typhoon pre-positioning activity has moved beyond primary CNI operators into the Tier 2 supplier networks that service UK central government and defence. Smaller suppliers with privileged access to government systems are now directly in scope.

critical Volt Typhoon

Volt Typhoon Activity Confirmed Across UK Water and Energy OT Networks

NCSC and Five Eyes partners have confirmed Volt Typhoon intrusions at operational technology networks in UK water treatment and regional energy distribution. The group is not causing disruption -- it is waiting.

Deep Analysis

high Gamaredon 10 min read

Gamaredon in 2026: Russia's Most Persistent APT Upgrades to a Modular Framework and Exploits WinRAR for Initial Access

Gamaredon (Primitive Bear, Aqua Blizzard) — Russia's FSB-linked APT targeting Ukraine since 2014 — has deployed a newly modularised malware framework in 2026, using HTML smuggling and CVE-2025-8088 WinRAR exploitation for initial access. Sekoia's June 2026 analysis reveals a four-stage VBScript loader chain, Telegram-based dead drop resolvers, and five distinct payload families covering every phase of the kill chain.

critical Sandworm 22 min read

Sandworm: Inside Russia's Most Destructive Cyber Weapon

Sandworm -- GRU Unit 74455 -- is responsible for the most destructive cyberattacks in history: the 2015 and 2016 Ukraine power grid attacks, NotPetya, Olympic Destroyer, and continuous destructive campaigns against Ukraine since 2022. This deep-dive covers their history, capabilities, and why they remain the most dangerous threat actor operating today.

critical Volt Typhoon 18 min read

Volt Typhoon: The Long Game in Western Critical Infrastructure

A deep analysis of Volt Typhoon's objectives, methods, and targets -- and what the sustained Chinese pre-positioning campaign in Western CNI means for how operators, regulators, and governments need to respond.

Commentary

8 min read

The 2026 Iran Conflict and the Dawn of Cyber-Enabled Kinetic Targeting

Iran's conflict with the US and Israel in 2026 confirmed what threat analysts had long theorised: cyberspace is now inseparable from kinetic warfare. What the Iran war reveals about hybrid doctrine — and what it means for critical infrastructure operators.

9 min read

The Attack Is Coming From Inside the Country: China's Compromised-Device Networks and Why Your Perimeter Controls Miss Them

A joint advisory from CISA, NCSC, and ten allied nations describes how China-linked threat actors have abandoned dedicated attack infrastructure in favour of networks of compromised home routers and IoT devices. The implication for defenders is worse than it sounds.

8 min read

The OT/ICS Blind Spot: Why Your Cyber Risk Picture Is Missing Half the Picture

Most boards have a reasonable grasp of IT cyber risk. Almost none have adequate visibility into the operational technology that runs their industrial processes, utilities, and physical infrastructure. This gap is exactly what state actors are exploiting.

8 min read

The Real Cost of a Critical Infrastructure Attack: Beyond the Ransom

When a critical infrastructure operator is hit, the ransom payment is usually the smallest line on the eventual damage assessment. The true costs -- operational, regulatory, reputational, and systemic -- are far larger and far longer-lasting.