Stone-Knight Security

STONE-KNIGHT SECURITY

Morning Muster Daily cyber threat brief · CESAR feed
LIVE
Updated 2026-06-28 11:03 UTC
Articles: 86 · Sources: 7
Auto-refresh: 15m

Critical CVEs & Vulnerabilities 18 items

The Hacker News2026-06-26 13:57 UTC
A flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed "pedit COW," is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page-cache memory. A public, working exploit appeared within a day of…
The Hacker News2026-06-26 13:53 UTC
A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the rest. Amazon has patched it. Tracked as CVE-2026-12957 (CVSS 8.5), the bug sat in how Amazon's AI…
The Hacker News2026-06-26 12:31 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Known Exploited Vulnerabilities (KEV)…
The Hacker News2026-06-26 11:51 UTC
DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this variant. Tracked as CVE-2026-43503 (CVSS 8.8), it lets a local user corrupt file-backed memory through a…
CISA KEV2026-06-25 00:00 UTC
Added to KEV 2026-06-25. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-23 00:00 UTC
Added to KEV 2026-06-23. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-23 00:00 UTC
Added to KEV 2026-06-23. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-23 00:00 UTC
Added to KEV 2026-06-23. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-16 00:00 UTC
Added to KEV 2026-06-16. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-12 00:00 UTC
Added to KEV 2026-06-12. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-11 00:00 UTC
Added to KEV 2026-06-11. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…

Active Threats & Malware 15 items

The Hacker News2026-06-27 17:27 UTC
The Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to break into the messaging accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe,…
Bleeping Computer2026-06-27 14:22 UTC
An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers. [...]
Bleeping Computer2026-06-26 22:06 UTC
The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims' historical messages. [...]
The Hacker News2026-06-26 19:38 UTC
The FBI and CISA have updated their March warning about Russian intelligence phishing Signal accounts, and the operators have added a step: they now coax targets into handing over their Signal Backup Recovery Key. Hand it over once, and the attacker can restore the account's backup, read the private and group message…
The Hacker News2026-06-26 18:17 UTC
A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts. Kaspersky, which is tracking the activity under the moniker StrikeShark, said the campaign has targeted a…
The Hacker News2026-06-26 16:21 UTC
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. The activity, particularly aimed at state-owned enterprises in the energy and government sectors, has…
SecurityWeek2026-06-26 14:30 UTC
Other noteworthy stories that might have slipped under the radar: Russia used Cellebrite to hack activist’s phone, Five Eyes issue urgent AI threat warning, macOS Gaslight backdoor, Scattered Spider guilty pleas. The post In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs appeared first on…
The Hacker News2026-06-26 11:05 UTC
Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propagated to the Go ecosystem. "The latest activity includes malicious npm releases affecting…
The Hacker News2026-06-26 09:27 UTC
An active phishing campaign has been targeting hotel and other hospitality organizations across Europe and Asia since April 2026, using photo-themed ZIP files to drop a Node.js implant and dig into front-desk machines, Microsoft says. The company has not attributed the activity to a known threat actor, and the…
Bleeping Computer2026-06-25 19:45 UTC
Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software. [...]

Data Breaches 3 items

Bleeping Computer2026-06-26 18:04 UTC
Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform's frontend following a breach at a third-party vendor. [...]
SecurityWeek2026-06-26 15:01 UTC
Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact. The post More Klue Breach Victims Identified as Hackers Get Hacked appeared first on SecurityWeek .

Tools & Research 18 items

The Hacker News2026-06-27 12:19 UTC
OpenAI on Friday released three versions of GPT-5.6, called Sol, Terra, and Luna, as a limited preview to a small number of companies as part of an ongoing engagement with the U.S. government. While Sol is the latest flagship model and the most powerful, Terra strikes a balance between efficiency and power, and Luna…
SecurityWeek2026-06-27 12:13 UTC
Threat actors are selling investment scam templates created using the legitimate DCloud Uni-App toolkit. The post Chinese Framework Powers 200,000 Scam Sites appeared first on SecurityWeek .
Bleeping Computer2026-06-26 19:43 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. [...]
Bleeping Computer2026-06-26 14:01 UTC
AI won't replace GRC analysts, but it can eliminate much of the repetitive work they do. Anecdotes walks through building an agent that continuously monitors controls, identifies evidence gaps, and opens remediation tasks. [...]
SecurityWeek2026-06-26 12:37 UTC
The cybersecurity startup provides threat hunting, proactive detection, and behavioral security analytics. The post Nebulock Raises $25 Million for AI-Native Contextual Security appeared first on SecurityWeek .
The Hacker News2026-06-26 11:30 UTC
AI agents are moving through enterprise environments, inheriting permissions, traversing systems, and executing decisions at machine speed with minimal oversight. The identity infrastructure built to govern human access wasn't designed for autonomous actors, and the gap between what enterprises are deploying and what…
SecurityWeek2026-06-26 09:47 UTC
The decentralized prediction market said hackers targeted some of its users through a compromise of a third-party vendor. The post $3 Million Reportedly Stolen in Polymarket Hack appeared first on SecurityWeek .

📺 NetworkChuck Cliff Notes

2026-06-19 · watch on YouTube ↗
Shadow AI exposes companies to data leaks and compliance risk as employees use unauthorized AI tools — Vanta helps discover and govern them.
  • Shadow AI refers to unsanctioned AI tools employees use without IT/security team knowledge or approval
  • Key risks: data exfiltration, IP leakage, compliance violations (HIPAA, SOC2, GDPR)
  • Attack surface expands as AI tools proliferate — traditional DLP and CASB may not catch LLM-based tools
  • Vanta automates discovery of AI tools in the environment and maps them to compliance frameworks
  • Mitigation: inventory all AI tool usage, enforce acceptable-use policy, integrate AI governance into existing GRC workflow
2026-06-18 · watch on YouTube ↗
Live 90-min AMA session covering CCNA certification questions as part of NetworkChuck's Summer of CCNA study program.
  • Live Q&A format addressing viewer CCNA exam and study questions
  • Part of the structured Summer of CCNA course series on NetworkChuck Academy
  • Covers certification path guidance and networking fundamentals
  • Targets learners preparing for Cisco CCNA 200-301 exam
  • Community-driven session encouraging sign-up at academy.networkchuck.com
2026-06-18 · watch on YouTube ↗
HTTPS encrypts traffic content but leaks visited hostnames via SNI and DNS, letting your ISP see every site you visit.
  • TLS SNI (Server Name Indication) exposes the target hostname in plaintext during the handshake even over HTTPS
  • DNS queries are typically unencrypted, revealing domain lookups to your ISP or network observer
  • The padlock icon means data in transit is encrypted — not that your browsing destinations are hidden
  • Encrypted DNS (DoH/DoT) and VPNs or Tor are required to actually obscure destination metadata from ISPs
  • Traffic analysis at the network layer can fingerprint sites even without content inspection
2026-06-18 · watch on YouTube ↗
Cisco Cloud Control centralizes network management and now integrates AI agents to automate tasks across the infrastructure.
  • Cisco Cloud Control is a unified platform for managing network infrastructure from a single pane of glass
  • AI agents are embedded to actively perform network tasks, not just surface insights
  • Reduces operational overhead by automating repetitive network management workflows
  • Positions Cisco as moving beyond observability into autonomous network operations
  • Sponsored deep-dive — practical look at where enterprise networking automation is heading
2026-06-16 · watch on YouTube ↗
Live 90-min AMA for Summer of CCNA covering certification questions, study strategies, and CCNA exam prep guidance.
  • Live Q&A format addressing viewer questions on CCNA certification path and exam topics
  • Part of NetworkChuck's Summer of CCNA structured learning program via NC Academy
  • Covers networking fundamentals relevant to Cisco CCNA exam objectives
  • Study tips and certification roadmap advice for aspiring network engineers
  • Community-driven session — questions sourced directly from live audience