Stone-Knight Security

STONE-KNIGHT SECURITY

Morning Muster Daily cyber threat brief · CESAR feed
LIVE
Updated 2026-06-30 11:02 UTC
Articles: 96 · Sources: 8
Auto-refresh: 15m

🌍 Global Ransomware Heatmap 2174 victims · last 90d · top: US

Critical CVEs & Vulnerabilities 18 items

The Hacker News2026-06-30 07:38 UTC
A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patch is available. If you run LoadMaster with the…
The Hacker News2026-06-30 05:04 UTC
A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Payments that could be abused to take over…
Dark Reading2026-06-29 21:29 UTC
The infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp, targeting credentials linking development and admin environments to wider enterprise systems.
Bleeping Computer2026-06-29 20:30 UTC
The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. [...]
Bleeping Computer2026-06-29 14:00 UTC
Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux. [...]
CISA KEV2026-06-29 00:00 UTC
Added to KEV 2026-06-29. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-25 00:00 UTC
Added to KEV 2026-06-25. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-23 00:00 UTC
Added to KEV 2026-06-23. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-23 00:00 UTC
Added to KEV 2026-06-23. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-23 00:00 UTC
Added to KEV 2026-06-23. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-16 00:00 UTC
Added to KEV 2026-06-16. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…

Active Threats & Malware 13 items

SecurityWeek2026-06-30 09:25 UTC
Only a handful of the 100 organizations targeted in the PeopleSoft campaign have been confirmed. The post Nissan Employee Data Breached in Oracle PeopleSoft Hack appeared first on SecurityWeek .
SecurityWeek2026-06-30 08:43 UTC
The threat actor is focused on collecting credentials, SSH keys, cryptocurrency wallets, and development tooling. The post Critical SimpleHelp Vulnerability Exploited for Malware Delivery appeared first on SecurityWeek .
The Hacker News2026-06-29 15:03 UTC
The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel. Acronis Threat Research Unit found active compromises inside Indian government networks, including…
The Hacker News2026-06-29 11:57 UTC
New findings unearthed by Infoblox show that more than 236,000 websites are using investment scam templates built using a legitimate Chinese open-source, cross-platform application development framework called DCloud Uni-App. The templates power bogus cryptocurrency exchanges, multi-language pig-butchering…
The Hacker News2026-06-29 11:40 UTC
A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against Ukraine throughout 2025. Slovakian cybersecurity company ESET said it observed 35 distinct spear-phishing campaigns mounted by Gamaredon against new targets, with most…
Krebs on Security2026-06-18 17:37 UTC
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to…
Krebs on Security2026-06-10 14:03 UTC
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life…
Krebs on Security2026-05-21 21:50 UTC
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity…

Data Breaches 3 items

Krebs on Security2026-05-22 16:34 UTC
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry…
Krebs on Security2026-05-18 20:48 UTC
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files…

Tools & Research 18 items

SecurityWeek2026-06-30 10:00 UTC
As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. The post The AI Token Costs That Can Break Cybersecurity appeared first on SecurityWeek .
The Hacker News2026-06-30 09:27 UTC
Two researchers have found six security flaws in AirDrop and Quick Share, the wireless features that beam files between nearby devices with no cables or shared network. An attacker within wireless range, with just a laptop and no prior connection, can crash the sharing service on a Mac or iPhone set to receive from…
The Hacker News2026-06-30 08:37 UTC
Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user's credentials and sending them to an attacker. The targets included OpenAI's ChatGPT…
The Hacker News2026-06-30 07:15 UTC
Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security. The WebKit vulnerabilities are listed below -…
SecurityWeek2026-06-30 06:40 UTC
Quantifind will accelerate international expansion and extend its platform’s localized risk intelligence capabilities. The post Quantifind Raises $200 Million for AI-Native Risk Intelligence appeared first on SecurityWeek .
The Hacker News2026-06-29 18:40 UTC
Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real results. Microsoft says Google removed…
The Hacker News2026-06-29 16:09 UTC
WhatsApp on Monday officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion users on the messaging platform. The optional feature is designed to help users connect with someone on the service through usernames, as opposed to directly sharing…

📺 NetworkChuck Cliff Notes

2026-06-19 · watch on YouTube ↗
Shadow AI — unsanctioned AI tools used inside organizations — pose serious data leakage and compliance risks that most security teams aren't tracking.
  • Employees are adopting AI tools (ChatGPT, Copilot, etc.) without IT/security approval — classic shadow IT, now with LLMs
  • Sensitive corporate data is being fed into unvetted AI platforms, creating data exfiltration and compliance exposure
  • Most orgs lack visibility into which AI tools are running on their networks or in their SaaS stack
  • Vanta is pitched as a solution to discover and govern AI tool usage across the org
  • Key takeaway: AI governance policies and tooling for SaaS/AI discovery need to be part of your security program now
2026-06-18 · watch on YouTube ↗
Live 90-min AMA for Summer of CCNA covering cert questions, study strategies, and CCNA exam guidance from NetworkChuck.
  • Live Q&A format addressing viewer questions on CCNA certification path and exam prep
  • Part of the ongoing Summer of CCNA series hosted via NetworkChuck Academy
  • Covers common certification doubts, study strategies, and networking fundamentals
  • Audience engagement-driven session — questions sourced live from viewers
  • Call-to-action: enroll at academy.networkchuck.com/course/premium-summer-of-ccna
2026-06-18 · watch on YouTube ↗
HTTPS encrypts data in transit but still leaks the domains you visit via SNI, DNS queries, and metadata visible to your ISP.
  • TLS SNI (Server Name Indication) exposes the destination hostname in plaintext during the handshake, even on HTTPS
  • DNS queries reveal browsing activity unless encrypted DNS (DoH/DoT) is used
  • ISPs can log and sell metadata including domains visited, timestamps, and traffic volume
  • Mitigations: Encrypted Client Hello (ECH), DNS over HTTPS/TLS, and a trusted VPN or Tor
  • The padlock only guarantees payload encryption — it does not provide anonymity or hide destinations
2026-06-18 · watch on YouTube ↗
Cisco Cloud Control unifies network management into a single AI-driven platform where AI agents actively automate and execute networking tasks.
  • Cisco Cloud Control consolidates multi-domain network management into one centralized cloud platform
  • AI agents move beyond visibility — they actively perform configuration, troubleshooting, and remediation tasks
  • Reduces operational complexity by eliminating tool sprawl across fragmented network management consoles
  • Positions Cisco's infrastructure for agentic automation, not just monitoring or analytics
  • Sponsored content — evaluate independently for production adoption decisions
2026-06-16 · watch on YouTube ↗
NetworkChuck hosts a 90-min live AMA for Summer of CCNA, answering viewer certification questions live at 5PM ET.
  • Live Q&A session focused on CCNA certification prep questions from the community
  • Part of the Summer of CCNA series — structured Cisco networking curriculum
  • Covers certification strategy, exam tips, and networking fundamentals Q&A
  • Viewers can enroll in the full Summer of CCNA course at NetworkChuck Academy
  • Interactive format: community-driven questions answered in real time