Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
This weekend's cybersecurity landscape was dominated by a coordinated international advisory on Russian state-sponsored phishing targeting Zimbra webmail users, a critical unpatched RCE in Alibaba's Fastjson library (CVSS 9.0), and a 9.8-rated Bing Images vulnerability exposed by XBOW researchers. Healthcare saw the massive DentaQuest breach notification (15M+ individuals) and a report highlighting a surge in malicious insider incidents. Cl0p affiliates launched a new data extortion campaign against manufacturers using PTC Windchill/FlexPLM (CVE-2026-12569, CVSS 9.3). On the regulatory front, Connecticut AG led a 42-state settlement with 23andMe over its 2023 breach, CalPrivacy launched its first CCPA compliance audit targeting gig economy platforms, and the US State Department imposed visa restrictions on foreign cyber scammers. An Australian major energy supplier confirmed a customer data breach, and federal agencies broadened their advisory on Iran-linked OT attacks.
Incident Map
Government & Policy 7 stories
US State Department Imposes Visa Restrictions on Foreign Cyber Scammers
Secretary of State Marco Rubio announced visa restrictions targeting individuals involved in cyber scams, expanding the US government's toolkit for deterring transnational cybercrime.
Extension of CISA 2015 Info-Sharing Protections Passes as Part of House Defence Bill
The US House of Representatives passed an extension of CISA's 2015 information-sharing liability protections as part of the defence authorisation bill, ensuring continued legal safe harbour for cyber threat intelligence sharing.
Connecticut AG Leads 42-State Settlement With 23andMe Over 2023 Data Breach
A coalition of 42 state attorneys general reached a settlement with 23andMe's bankruptcy trustee, resolving claims from the company's 2023 data breach that exposed genetic and personal data of millions of customers.
CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit
The California Privacy Protection Agency launched its first formal CCPA compliance audit, targeting gig economy tech platforms operating in California.
UK Signals Continuity on Cyber Policy โ Minister Reappointed Despite Ministry Scrapping
Mayor Andy Burnham signalled continuity on UK cyber policy, reappointing the cyber minister despite the government's decision to scrap the dedicated ministry.
CISA Plans to Finalise Cyber Incident Reporting Regulations in September 2026
CISA continues working toward finalising regulations implementing the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022, with a final rule now expected in September 2026.
French Parliament Greenlights Social Media Ban for Under-15s
France's National Assembly passed legislation banning social media access for children under 15, one of Europe's most restrictive digital age laws.
Geopolitical & State-Sponsored Activity 5 stories
CISA/FBI Joint Advisory: Russian State-Sponsored Zimbra Phishing Campaign (AA26-204A)
CISA and international partners released a joint cybersecurity advisory detailing a Russian state-sponsored phishing campaign targeting users of the Zimbra Collaboration Suite. The advisory provides IOCs, TTPs, and mitigation guidance for organisations using Zimbra.
CISA Advisory: Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting (AA26-194A)
CISA released guidance on improving router security hygiene to defend against Russian state-sponsored targeting of network infrastructure devices.
BlueNoroff (North Korea) Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
North Korean threat actor BlueNoroff has operationalised a sophisticated phishing platform that profiles victims' cryptocurrency wallets before delivering malware, enabling selective targeting of high-value victims via typosquatted Zoom and Microsoft Teams domains.
Federal Agencies Broaden Alert on Iran-Linked OT Attacks
US federal agencies issued a broadened alert on Iran-linked attacks targeting operational technology (OT) environments, expanding previous guidance on ICS/SCADA threats.
New Kimsuky Campaign Compromises South Korean Software Vendors
The North Korean Kimsuky group conducted a new campaign compromising South Korean software vendors as part of ongoing espionage operations.
Manufacturing & Critical Infrastructure 2 stories
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM With Unauthenticated RCE (CVE-2026-12569)
Threat actors linked to the Cl0p ransomware campaign are exploiting internet-exposed PTC Windchill and FlexPLM deployments using CVE-2026-12569 (CVSS 9.3), chaining an information disclosure with a server-side flaw for unauthenticated RCE and JSP web shell deployment. Targets include manufacturing, automotive, aerospace, and retail sectors.
Swiss Train Maker Stadler Refuses Everest $12 Million Ransomware Demand
Swiss rolling stock manufacturer Stadler Rail refused to pay a $12 million ransom demand from the Everest ransomware group following a cyberattack, choosing to restore systems from backups instead.
Energy & Utilities 1 story
Major Australian Energy Supplier Confirms Customer Data Compromised
A major Australian electricity infrastructure provider confirmed that customer data was compromised in a cybersecurity incident, underscoring ongoing threats to critical energy infrastructure in the region.
Healthcare 5 stories
DentaQuest Starts Notifying 15 Million+ Individuals About May 2026 Cyber Incident
Dental benefits administrator DentaQuest began issuing notification letters to over 15 million individuals affected by a May 2026 cybersecurity incident โ one of the largest healthcare data breaches of the year.
Tennessee Pathology Group Announces 170K-Record Data Breach
Anatomic and Clinical Laboratory Associates (ACLA) notified almost 170,000 patients about a cybersecurity incident that exposed protected health information.
Report Shows Surge in Malicious Insider Incidents and Mega Data Breaches
A new report highlights a general trend of increasing data breaches, with this year on track to set records for malicious insider incidents and mega breaches (1M+ records).
Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data
Cardiovascular medical practice Heart Care Centers of Illinois announced that a historic phishing attack exposed certain patients' protected health information.
Colorado Behavioral Healthcare Provider Discovers Insider Data Breach
A Colorado behavioural healthcare provider discovered an insider data breach, with patient data accessed by an employee without authorisation.
Technology & Vulnerabilities 7 stories
Fastjson 1.x RCE Vulnerability Under Active Attack โ No Patch Available (CVE-2026-16723, CVSS 9.0)
A critical unauthenticated RCE vulnerability in Alibaba's Fastjson 1.x Java JSON library (CVE-2026-16723, CVSS 9.0) is being actively targeted. No fixed version for the 1.x branch has been released. Mitigations include enabling SafeMode or migrating to Fastjson2.
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers (CVE-2026-32194/32191, CVSS 9.8)
XBOW researchers demonstrated that crafted SVG images submitted to Bing Image Search could execute commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers. Both CVEs rated 9.8, fixed server-side by Microsoft.
GitLab RCE PoC Published โ Authenticated Users Can Run Commands as Git
Security researchers published exploit code for a GitLab flaw allowing any authenticated user who can push to a project to execute commands as the git user. GitLab patched it in June but did not classify it as a security fix โ no CVE was assigned.
Certighost Exploit: Low-Privileged AD Users Can Impersonate a Domain Controller (CVE-2026-54121, CVSS 8.8)
Researchers published exploit code for an AD CS flaw (CVE-2026-54121) that lets low-privileged Active Directory users obtain a certificate for a Domain Controller and perform DCSync attacks. Patched by Microsoft ten days prior.
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Single Phishing Link
Zenity Labs disclosed a CSRF vulnerability in OpenAI's ChatGPT Workspace Agents (dubbed AgentForger) that could allow a single phishing link to stealthily build and deploy an attacker-controlled AI agent inside a victim's organisation. Patched by OpenAI as of June 8.
SourTrade Malvertising: Browser Builds Windows Executable Using Bun Runtime
A malvertising campaign dubbed SourTrade makes victims' browsers build the final Windows executable themselves using a legitimate Bun runtime. The campaign has operated since late 2024, impersonating TradingView, Solana, and Luno.
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
Aikido Security's AI penetration testing agents found eight high-severity flaws in NodeBB forum software in a six-hour code review. All versions before 4.14.0 affected; fixed in 4.14.2.
Cybercrime & Ransomware 5 stories
DevMan RaaS Portal Centralises Payload Builds, Victim Management, and Affiliate Payouts
PRODAFT is tracking a centrally administered RaaS operation (Funky Mantis) with a dedicated web platform offering affiliates build generation, finance, victim chat, support, and payout functions โ representing an industrialisation of the ransomware service model.
Insurance Phishing Evolves Into Real-Time Account Hijacking
CTM360 research reveals a shift in insurance-focused phishing: instead of harvesting credentials for later use, attackers now synchronise activity in real time, authenticating against legitimate insurance portals as victims complete the login process within a single session.
Golden Chickens Resurfaces With Four New Malware Families
The Golden Chickens MaaS ecosystem has resurfaced with four new malware families (TinyEgg, ChonkyChicken, modular ChonkyChicken, ChromEggscalator), deployed via ClickFix social engineering campaigns.
Hermes AI Agent Used Unattended for Post-Exploitation at Thailand's Ministry of Finance
An operator deployed the open-source Hermes AI agent in YOLO mode against Thailand's Ministry of Finance infrastructure. The agent autonomously enumerated hosts, hunted for root access, and crawled personnel records. Hunt.io and Bob Diachenko discovered the exposed logs with 585 files and 470 MB of attack tooling.
'Wrench' Attacks Against Crypto Holders Appear to Be on the Rise
Physical coercion attacks ("wrench attacks") targeting cryptocurrency holders are reportedly increasing, where attackers use physical force or threats to compel victims to transfer digital assets.
Transportation & Logistics 1 story
Japanese Food Logistics Giant Nichirei Recovers as Extortion Group Claims Cyberattack
Japanese food logistics company Nichirei recovered from a cyberattack as an extortion group claimed responsibility. The incident disrupted cold-chain logistics operations.
Legal & Regulatory 2 stories
Spain Fines 23andMe Nearly $3 Million for Cybersecurity Failings Enabling 2023 Hack
Spanish data protection authorities fined 23andMe approximately $3 million for cybersecurity deficiencies that enabled the 2023 data breach exposing genetic data of millions of customers.
Illinois Governor Signs Frontier AI Model Law
Illinois Governor JB Pritzker signed the Artificial Intelligence Safety Measures Act, making Illinois the third US state to enact comprehensive safety and transparency requirements for advanced AI systems.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |