Stone-Knight Security

STONE-KNIGHT SECURITY

Morning Muster Daily cyber threat brief · CESAR feed
LIVE
Updated 2026-06-26 11:02 UTC
Articles: 96 · Sources: 8
Auto-refresh: 15m

🌍 Global Ransomware Heatmap 2248 victims · last 90d · top: US

Critical CVEs & Vulnerabilities 18 items

The Hacker News2026-06-25 05:46 UTC
An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant. The vulnerability, tracked as CVE-2026-20245 (CVSS score: 7.8), allows an…
CISA KEV2026-06-25 00:00 UTC
Added to KEV 2026-06-25. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-23 00:00 UTC
Added to KEV 2026-06-23. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-23 00:00 UTC
Added to KEV 2026-06-23. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-23 00:00 UTC
Added to KEV 2026-06-23. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-16 00:00 UTC
Added to KEV 2026-06-16. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-12 00:00 UTC
Added to KEV 2026-06-12. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-11 00:00 UTC
Added to KEV 2026-06-11. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
Krebs on Security2026-06-09 22:07 UTC
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at…

Active Threats & Malware 16 items

The Hacker News2026-06-26 09:27 UTC
An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig into front-desk machines, Microsoft says. The company has not attributed the activity to a known threat actor, and the…
The Hacker News2026-06-26 07:15 UTC
The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine, and entities that have an interest in Italian foreign policy. Describing the Windows backdoor as…
Bleeping Computer2026-06-25 19:45 UTC
Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software. [...]
The Hacker News2026-06-25 09:23 UTC
A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst's artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the artifact. The malware has been codenamed Gaslight owing to…
The Hacker News2026-06-25 08:54 UTC
A new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated attacks aimed at multiple organizations spanning insurance, education, IT, and professional services sectors since April 2026. According to Symantec and Carbon Black's Threat Hunter Team, the backdoor, also tracked as…
The Hacker News2026-06-24 15:59 UTC
A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. "The main common goal was to disrupt the 'assembly lines' cybercriminals use to launch…
Krebs on Security2026-06-18 17:37 UTC
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to…
Krebs on Security2026-06-10 14:03 UTC
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life…
Krebs on Security2026-05-21 21:50 UTC
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity…

Data Breaches 4 items

Krebs on Security2026-05-22 16:34 UTC
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry…
Krebs on Security2026-05-18 20:48 UTC
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files…

Nation State Activity 1 items

Tools & Research 18 items

SecurityWeek2026-06-26 09:47 UTC
The decentralized prediction market said hackers targeted some of its users through a compromise of a third-party vendor. The post $3 Million Reportedly Stolen in Polymarket Hack appeared first on SecurityWeek .
The Hacker News2026-06-26 08:49 UTC
Russian authorities used Cellebrite's UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021, three months after Cellebrite said it would stop selling its tools and services to Russia and Belarus. The finding, published June 25 by the Citizen Lab, rests on two…
SecurityWeek2026-06-26 08:00 UTC
A major overhaul of the Model Context Protocol shifts critical security responsibilities from the protocol itself to developers and platform operators. The post New Enterprise-Ready MCP Specification Brings New Security Challenges appeared first on SecurityWeek .
SecurityWeek2026-06-26 05:13 UTC
Martin brings experience from Coinbase, Palantir, Amazon, and the U.S. Army to lead Uber's cybersecurity and enterprise security organization. The post Philip Martin Joins Uber as Chief Information Security Officer appeared first on SecurityWeek .
The Hacker News2026-06-25 14:12 UTC
An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the extension, named Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk), has more than 10 million installs and carries a Featured badge on the Chrome Web…
Bleeping Computer2026-06-25 14:01 UTC
Fraudsters don't attack just one transaction. They target accounts, platforms, and entire ecosystems. IPQS explains the four elevations of fraud prevention and why broader visibility improves fraud detection. [...]
SecurityWeek2026-06-25 12:39 UTC
The startup’s platform functions as a secure control layer, aiming to secure AI tools across enterprises. The post Runlayer Raises $30 Million in Series A Funding appeared first on SecurityWeek .

📺 NetworkChuck Cliff Notes

2026-06-19 · watch on YouTube ↗
Shadow AI exposes companies to hidden risk as employees use unauthorized AI tools — Vanta helps security teams discover and govern them.
  • Shadow AI refers to unsanctioned AI tools employees use without IT/security approval, creating blind spots in data governance and compliance
  • Unauthorized AI use can expose sensitive corporate data to third-party models with unknown retention and training policies
  • Attack surface expands as shadow AI tools bypass DLP, CASB, and endpoint controls — traditional tooling often can't see them
  • Discovery and inventory of AI tool usage is the critical first step — you can't protect what you don't know exists
  • Vanta automates AI tool discovery and risk management, mapping shadow AI back to compliance frameworks
2026-06-18 · watch on YouTube ↗
NetworkChuck hosts a live 90-min AMA focused on certification questions during his Summer of CCNA program.
  • Live Q&A format targeting CCNA exam prep and study strategy
  • Part of the structured Summer of CCNA course series on NetworkChuck Academy
  • Covers certification path questions from the community in real time
  • Aimed at learners actively pursuing Cisco CCNA certification
  • Session runs 90 minutes at 5PM ET with open audience questions
2026-06-18 · watch on YouTube ↗
HTTPS encrypts your data in transit but SNI and DNS queries still expose which domains you visit to your ISP and network observers.
  • TLS SNI (Server Name Indication) leaks the destination hostname in plaintext during the handshake — visible to ISPs even with HTTPS
  • DNS queries reveal every domain you look up unless you're using encrypted DNS (DoH or DoT)
  • Encrypted Client Hello (ECH) is the emerging fix for SNI leakage but adoption is still limited
  • VPNs and Tor are the practical mitigations that hide both DNS and SNI from your ISP
  • The padlock only means the payload is encrypted — metadata (who you talk to) is a separate problem
2026-06-18 · watch on YouTube ↗
Cisco Cloud Control unifies network management into a single platform with AI agents now actively automating and executing network operations.
  • Cisco Cloud Control centralizes visibility and control across network infrastructure in one dashboard
  • AI agents move beyond monitoring — they actively perform network tasks and remediation
  • Reduces operational complexity by eliminating tool sprawl across distributed environments
  • Represents a shift from human-driven CLI/GUI workflows to intent-based, agent-driven networking
  • Sponsored deep-dive — positions Cisco as leaning into agentic AI for enterprise network automation
2026-06-16 · watch on YouTube ↗
NetworkChuck hosts a live 90-min Summer of CCNA AMA session answering certification questions from viewers on June 18, 2026.
  • Live Q&A format focused on CCNA exam prep, study strategies, and certification roadmap guidance
  • Part of the structured Summer of CCNA program hosted on NetworkChuck Academy
  • Covers viewer-submitted questions on networking concepts relevant to Cisco CCNA curriculum
  • Encourages enrollment in the Summer of CCNA course at academy.networkchuck.com
  • Community-driven session aimed at helping learners accelerate through CCNA certification