THE INFRASTRUCTURE DEFENDER
Cyber Threat Intelligence Summary
June 22, 2026 | Auth ID: one-IMPRIMIS
Source: Imprimis, Inc. | CyberDeck Blog

Reporting Period: June 16, 2026 – June 22, 2026
This week's landscape is dominated by three developments: mass exploitation of the SimpleHelp RMM authentication bypass (CVE-2026-48558, CVSS 10.0) cascading through the MSP supply chain to deliver the TaskWeaver loader and Djinn Stealer; the ShinyHunters Oracle PeopleSoft zero-day wave (CVE-2026-35273) breaking into a coordinated July 3 breach-disclosure cluster spanning Nissan, Kubota, Aflac, and the NAIC; and CISA's July 1 KEV addition of an actively exploited Microsoft SharePoint Server RCE (CVE-2026-45659) carrying a July 4 federal remediation deadline. Edge infrastructure remains under sustained pressure, with large-scale credential-compromise campaigns against Fortinet and Palo Alto VPN gateways and six new KEV entries targeting infrastructure-management platforms.
A CVSS 10.0 authentication bypass in SimpleHelp RMM's OIDC flow accepts forged identity tokens without signature verification, handing unauthenticated attackers fully authenticated technician sessions. It is being actively exploited to mass-deploy the TaskWeaver Node.js loader and Djinn Stealer across managed endpoints. CISA added it to the KEV catalog with a July 2, 2026 remediation deadline; a single compromised MSP instance cascades to every endpoint under management.
Direct MSP supply-chain exposure — organizations should confirm whether any service provider runs SimpleHelp and require attestation of patch level plus technician-session audit. Maps to NIST 800-171 3.14.1 (flaw remediation) and 3.1.12 (remote access monitoring); RMM tooling sits inside the CUI assessment boundary when used to administer in-scope systems.
CISA added CVE-2026-45659 (CVSS 8.8), a deserialization-of-untrusted-data remote code execution flaw in SharePoint Server Subscription Edition, 2019, and 2016, to the KEV catalog on July 1 following confirmed active exploitation. Microsoft patched the flaw in May 2026; FCEB agencies must remediate by July 4, 2026.
On-premises SharePoint frequently stores CUI — confirmed exploitation constitutes a reportable incident under DFARS 252.204-7012 (72-hour rule). Verify May 2026 cumulative update installation and review IIS/ULS logs for deserialization indicators. Maps to NIST 800-171 3.14.1 and 3.6.2 (incident reporting).
First in-the-wild exploitation of CVE-2026-46817 (CVSS 9.8) in Oracle Payments' File Transmission component (ibytransmit endpoint) was recorded June 27 — roughly six weeks after Oracle's May patch and before any public proof-of-concept existed. About 950 internet-exposed E-Business Suite instances (12.2.3–12.2.15) are considered potentially vulnerable; the observed exploit invoked internal Java functions directly to read /etc/passwd.
ERP and payments systems processing contract financial data require expedited patch verification. Pre-PoC exploitation indicates a capable actor with patch-diffing capability, shortening realistic remediation windows. Maps to NIST 800-171 3.11.2 (vulnerability scanning) and 3.14.6 (monitoring for attack indicators).
On June 29 CISA added six actively exploited vulnerabilities to the KEV catalog, affecting PTC Windchill/FlexPLM (11.1 SP8X through 13.0.1.0), Cisco Unified Communications Manager (SSRF), Lantronix EDS5000, and Ubiquiti UniFi OS (fixed in 4.0.6 and later). Four of the six affect network or infrastructure-management platforms that provide high-value administrative access.
PTC Windchill is a PLM platform common in defense manufacturing — CUI technical-data exposure is plausible where Windchill is in scope. UniFi OS exposure is relevant to SMB and managed-network environments. Maps to NIST 800-171 3.11.2 and 3.14.1; KEV remediation deadlines fall in mid-July.
Adobe released fixes for ColdFusion and Campaign Classic addressing seven CVSS 10.0 vulnerabilities, including unrestricted file upload (CVE-2026-48283, CVE-2026-48276) and path traversal (CVE-2026-48282). CVE-2026-48282 came under active exploitation within hours of public disclosure.
ColdFusion remains widely deployed in legacy government and contractor web stacks. Hours-to-exploitation compresses patch SLAs far below standard 30-day cycles — emergency change control is warranted. Maps to NIST 800-171 3.14.1 and CMMC CM.L2-3.4.3 (change tracking for emergency patches).
Google confirmed that ShinyHunters-linked actors exploited CVE-2026-35273, a critical Oracle PeopleSoft remote code execution flaw, as a zero-day between May 27 and June 9, before Oracle shipped an emergency patch June 10. The campaign has allegedly impacted more than 100 organizations, with a coordinated victim-notification wave landing the first week of July.
Organizations running PeopleSoft HR or financials must assume compromise-window exposure from May 27 and conduct retroactive hunting, not merely patch. Maps to NIST 800-171 3.6.1 (incident handling capability) and 3.14.7 (identify unauthorized use of systems).
On July 1, CISA announced the Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure (ANCHOR-CI), a new advisory-body framework that builds on lessons from CIPAC and expands public-private engagement to a wider range of critical infrastructure stakeholders for real-time threat coordination.
This changes the machinery through which sector threat-sharing reaches DIB and MSSP stakeholders. No direct control mapping; monitor for updated CISA engagement channels and sector coordinating council changes affecting information-sharing agreements.
Under FedRAMP's Consolidated Rules for 2026 (finalized June 24), the grace period for Security Inbox and Secure Configuration Guide requirements ended July 1, with eight additional core requirements effective July 4. The legacy 'FedRAMP Ready' designation retires July 28, and the Moderate baseline is being relabeled 'FedRAMP Rev5 Class C.'
Cloud service providers serving federal or DIB customers must evidence the new core requirements now. Downstream, contractors consuming cloud services should re-verify authorization-status language in SSPs and flowdowns that reference FedRAMP Moderate terminology.
NIST's NCCoE released the initial public draft of SP 1800-41, 'Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector,' with public comments due July 8, 2026. Separately, the Crypto Publication Review Board's comment window on SP 800-52 Rev. 2 (TLS implementation guidance) runs through July 10.
Directly relevant to DIB manufacturers building incident response and recovery capability mapped to NIST 800-171 3.6.x. Both comment windows close this week — sector-specific feedback on OT recovery guidance should be submitted now if it affects client runbooks.
With the CMMC DFARS final rule in force (and the CMMC Unique Identifier amendment effective May 7, 2026), DoD may begin conditioning contract awards on Level 2 C3PAO and Level 3 DIBCAC assessment requirements as of November 10, 2026 — roughly 18 weeks out. The CMMC UID, a ten-character alphanumeric code per assessed system, is now the contractual identifier of record.
Contractors targeting FY27 awards need C3PAO scheduling now given assessor capacity constraints. SSPs, POA&Ms, and SPRS scores must be current, and the UID requirement means system-boundary definitions must be locked before assessment begins.
Apple released iOS/iPadOS 26.5.2, macOS Tahoe 26.5.2, and Safari 26.5.2 in late June, addressing 37 CVEs — 31 in WebKit/WebRTC — plus kernel flaws including CVE-2026-43724, a kernel memory write reachable from an app. Apple stated it will no longer hold security fixes for scheduled point releases, moving to expedited standalone security updates.
For Intune/MDM-managed Apple fleets, the expedited cadence requires tighter declarative device management enforcement windows and updated minimum-OS compliance pins. Kernel memory-write primitives are privilege-escalation grade. Maps to NIST 800-171 3.14.1.
Cisco PSIRT published its July 1, 2026 advisory bundle disclosing vulnerabilities in Cisco Catalyst Center and Secure Endpoint Connectors for Linux, Mac, and Windows. The publication follows Cisco Unified Communications Manager's SSRF entry into the CISA KEV catalog earlier the same week.
Secure Endpoint connector flaws affect the EDR layer itself — validate connector versions across managed fleets, since EDR integrity underpins NIST 800-171 3.14.6 and 3.14.7 monitoring controls. Catalyst Center holds network-wide configuration authority and warrants priority patching.
CISA issued multiple ICS advisories between June 30 and July 2 (ICSA-26-181-01 through -07 and ICSA-26-183-01), including one for Schneider Electric EcoStruxure IT Data Center Expert (ICSA-26-181-03). Affected products span data-center infrastructure management deployed across manufacturing and facilities environments.
DCIM platforms bridge IT/OT boundaries — review network segmentation and remote-access paths for in-scope facilities. Maps to NIST 800-171 3.13.1 (boundary protection); OT asset owners should track ICS-CERT remediation guidance.
Citrix patched six NetScaler ADC/Gateway vulnerabilities, including four high-severity out-of-bounds read, memory overflow, and arbitrary file read bugs (CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816), plus a NetScaler-specific identifier (CVE-2026-13474) for the HTTP/2 Bomb denial-of-service technique (CVE-2026-49975).
NetScaler devices are historically fast-exploited, high-value edge targets (CitrixBleed precedent). Edge appliances are in-scope boundary devices under NIST 800-171 3.13.1 — patch promptly and capture remediation evidence for continuous-monitoring records.
GitLab patched multiple vulnerabilities including CVE-2026-6552, an improper access control flaw in the Group SAML Identity API that allows an authenticated user with the Group Owner role to take over another member's account. Affected: GitLab EE 15.5 up to fixed releases 18.10.8, 18.11.5, and 19.0.2.
Source-code platforms hold configuration-as-code and pipeline secrets; account takeover bypasses the identity assurances underpinning NIST 800-171 3.1.1/3.1.2 (access control) and 3.5.x (identification and authentication). Audit group-owner role assignments after patching.
Fragnesia, a privilege-escalation flaw in the Linux kernel's XFRM ESP-in-TCP subsystem (CVE-2026-46300), allows unprivileged local users to escalate to root. National CERT-level alerts have flagged active exploitation of Linux kernel LPE chains, and public exploit code circulates for the related Dirty Frag flaws (CVE-2026-43284, CVE-2026-43500).
Container hosts, hypervisors, and appliance Linux builds inherit exposure — LPE chains convert any foothold to root, defeating agent-based monitoring. Maps to NIST 800-171 3.14.1; prioritize internet-facing and multi-tenant hosts for kernel updates.
IBM X-Force published an advisory on broad exploitation campaigns against Fortinet FortiGate SSL VPN and Palo Alto GlobalProtect endpoints, with estimated scope of 30,000 to 75,000 exposed or compromised devices across 194 countries. Activity blends valid-credential abuse with exploitation of recent gateway CVEs.
Remote-access gateways are the front door of the CUI boundary. Force credential rotation, enforce MFA on all VPN identities (NIST 800-171 3.5.3), and hunt for anomalous VPN authentications. A compromised gateway is a presumptive DFARS 252.204-7012 incident where CUI enclaves sit behind it.
A supply-chain compromise tracked as the Node-gyp Supply Chain Compromise spans 57 npm packages across hundreds of malicious versions, all rated Critical. The attack ships a weaponized binding.gyp file that causes node-gyp to execute attacker-controlled code automatically during npm install, self-propagating via stolen publish tokens.
Build pipelines that ran npm install on affected versions must rotate all CI secrets — npm/PyPI tokens, cloud keys, SSH keys. Maps to NIST 800-171 3.4.8 (software restriction) and 3.14.2 (malicious code protection); lockfile pinning and registry proxying are the compensating controls.
The Miasma supply-chain attack compromised at least 32 packages in the @redhat-cloud-services npm namespace (roughly 80,000 weekly downloads) via a compromised Red Hat employee GitHub account, pushing malicious orphan commits that bypassed code review. The preinstall payload sweeps GitHub Actions tokens, AWS/GCP/Azure credentials, Vault tokens, kubeconfigs, SSH keys, and .env files.
Vendor-namespace trust is not a control — dependency provenance verification (sigstore, npm provenance attestations) belongs in NIST 800-171 3.4.x configuration management. Organizations consuming Red Hat cloud-services SDKs should sweep CI credential history back to June 1.
Cyber-extortion group FulcrumSec claimed theft of approximately 1.3 TB from Novo Nordisk — source code, proprietary drug and trial data, and personal data of employees, doctors, and patients — and demanded $25 million, which the company refused. The group claims more than two months of undetected residence in Novo Nordisk networks before the June disclosure.
Two-month dwell time against a mature enterprise underscores that exfiltration-focused extortion evades encryption-centric ransomware controls. Data-egress monitoring (NIST 800-171 3.13.1) and DLP telemetry are the relevant detection layers; refusal-to-pay postures extend leak-site exposure timelines.
Japanese telecom KDDI disclosed that attackers exploited a third-party software vulnerability in a shared email platform, exposing email addresses and passwords of up to 14.22 million current and former customers across KDDI and five other ISPs (JCOM, NIFTY, BIGLOBE, STNet, Chubu Telecommunications). The compromise was discovered June 17; public disclosure landed June 29.
A textbook shared-infrastructure blast radius: one platform, six brands. Credential-stuffing risk radiates to any service where affected users reuse passwords — relevant to conditional-access posture and impossible-travel alerting on tenant identities with Japanese user populations.
The National Association of Insurance Commissioners confirmed ShinyHunters accessed its Oracle PeopleSoft system via the CVE-2026-35273 zero-day, identified June 11. In late June the group published approximately 3.1 TB (about 105,000 files); NAIC states the material comprised publicly available data, outdated logs, and configuration files.
Even 'public data' dumps leak configuration files useful for follow-on targeting of the insurance regulatory ecosystem. Downstream insurers should treat NAIC-derived configuration artifacts as adversary reconnaissance material against shared integrations and reporting pipelines.
Nissan confirmed that threat actors exploiting the Oracle PeopleSoft vulnerability stole data on current and former employees across the US, Canada, Mexico, and Brazil — including Social Security numbers, banking details, and financial and tax data. Notification arrived July 3 in a disclosure cluster alongside Kubota North America.
HR-system breaches trigger multi-jurisdiction notification obligations and elevate spear-phishing and W-2 fraud risk against affected workforces. Payroll-adjacent identity monitoring and finance-team phishing awareness are the near-term mitigations.
Insurance giant Aflac disclosed a new data breach after attackers compromised systems at its Japan subsidiary, with the confirmation landing in the July 3 disclosure cluster tied to the Oracle PeopleSoft exploitation wave. The scope of affected policyholder data remains under investigation.
This is Aflac's second disclosed incident in roughly a year; subsidiary and affiliate boundaries remain the recurring weak seam in enterprise scoping. The mirror-image lesson applies to CMMC enclave scoping wherever affiliates share identity planes or ERP systems.
Prince George County, Virginia confirmed a cybersecurity incident after outages disrupted county phone, internet, and online payment systems beginning June 11. The RansomHouse extortion group subsequently claimed it had encrypted the county's systems and listed the county on its leak site.
Local-government incidents routinely expose citizen PII and utility-payment data with thin incident-response resources. For municipal and SLTT-adjacent clients, offline backup verification and leak-site monitoring are the operative takeaways.