Stone-Knight Security

STONE-KNIGHT SECURITY

Morning Muster Daily cyber threat brief · CESAR feed
LIVE
Updated 2026-06-25 11:02 UTC
Articles: 96 · Sources: 8
Auto-refresh: 15m

🌍 Global Ransomware Heatmap 2250 victims · last 90d · top: US

Critical CVEs & Vulnerabilities 18 items

SecurityWeek2026-06-25 06:08 UTC
CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching. The post Cisco SD-WAN Zero-Day Exploited Months Before Patching appeared first on SecurityWeek .
The Hacker News2026-06-25 05:46 UTC
An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant. The vulnerability, tracked as CVE-2026-20245 (CVSS score: 7.8), allows an…
The Hacker News2026-06-24 06:50 UTC
Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input…
CISA KEV2026-06-23 00:00 UTC
Added to KEV 2026-06-23. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-23 00:00 UTC
Added to KEV 2026-06-23. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-23 00:00 UTC
Added to KEV 2026-06-23. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-16 00:00 UTC
Added to KEV 2026-06-16. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-12 00:00 UTC
Added to KEV 2026-06-12. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
CISA KEV2026-06-11 00:00 UTC
Added to KEV 2026-06-11. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or…
Krebs on Security2026-06-09 22:07 UTC
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at…
CISA KEV2026-06-09 00:00 UTC
Added to KEV 2026-06-09. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. by 2026-06-23. Arista Extensible Operating System (EOS) contains an incomplete comparison with missing factors vulnerability when…

Active Threats & Malware 17 items

The Hacker News2026-06-25 09:23 UTC
A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst's artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the artifact. The malware has been codenamed Gaslight owing to…
The Hacker News2026-06-25 08:54 UTC
A new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated attacks aimed at multiple organizations spanning insurance, education, IT, and professional services sectors since April 2026. According to Symantec and Carbon Black's Threat Hunter Team, the backdoor, also tracked as…
The Hacker News2026-06-24 15:59 UTC
A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. "The main common goal was to disrupt the 'assembly lines' cybercriminals use to launch…
The Hacker News2026-06-23 18:20 UTC
A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed that has targeted over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, involves collecting credential lists, searching for…
Krebs on Security2026-06-18 17:37 UTC
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to…
Krebs on Security2026-06-10 14:03 UTC
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life…
Krebs on Security2026-05-21 21:50 UTC
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity…

Data Breaches 4 items

Krebs on Security2026-05-22 16:34 UTC
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry…
Krebs on Security2026-05-18 20:48 UTC
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files…

Tools & Research 18 items

SecurityWeek2026-06-25 09:25 UTC
The latest version of the open source data transfer tool resolves 18 medium and low-severity vulnerabilities. The post 25-Year-Old Vulnerability Patched in Curl appeared first on SecurityWeek .
SecurityWeek2026-06-25 08:29 UTC
The guidance aims to establish product cybersecurity requirements for IoT devices integrated into federal agencies’ networks. The post NIST Opens Updated IoT Security Guidance to Public Review appeared first on SecurityWeek .
SecurityWeek2026-06-25 07:56 UTC
More than half of the bugs are use-after-free defects, which can potentially lead to remote code execution. The post Chrome 149 Update Resolves 18 Severe Vulnerabilities appeared first on SecurityWeek .
Dark Reading2026-06-24 19:10 UTC
Dark Reading Confidential Episode 19: Kickbacks, no-show jobs, "dirty" VCs, and shelf ware — industry expert Robert "RSnake" Hansen explains why he thinks its time for a CISO code of ethics to ensure cybersecurity bosses aren't engaged in self-dealing that could risk enterprise, and even national, security.
The Hacker News2026-06-24 17:19 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 26, 2026. The vulnerability in question is…
SecurityWeek2026-06-24 14:30 UTC
The new framework seeks to help security teams identify which software supply chain vulnerabilities pose the greatest operational, safety, and business risks in AI-driven environments. The post Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk appeared first on SecurityWeek .
Bleeping Computer2026-06-24 14:02 UTC
Service desks have become a favored target for attackers seeking password resets, MFA changes, and access to corporate accounts. Specops Software breaks down how service desk social engineering attacks work and how organizations can defend against them. [...]
SecurityWeek2026-06-24 13:50 UTC
A standard non-admin account is sufficient to conduct an attack that exploits legitimate OS behavior rather than software vulnerabilities. The post macOS Weaknesses Chained to Silently Disable Endpoint Security Agents appeared first on SecurityWeek .
SecurityWeek2026-06-24 12:52 UTC
Nathan Austad has been ordered to pay roughly $1.8 million in forfeiture and restitution, and the sentence also includes 3 years of supervised release. The post Third DraftKings Hacker Sentenced to 18 Months in Prison appeared first on SecurityWeek .
The Hacker News2026-06-24 12:48 UTC
Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The "critical exploitable pattern" has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of…
SecurityWeek2026-06-24 12:32 UTC
The flaws allow remote, unauthenticated attackers to make system changes, access underlying accounts, and inject commands. The post Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairs appeared first on SecurityWeek .

📺 NetworkChuck Cliff Notes

2026-06-19 · watch on YouTube ↗
Shadow AI exposes hidden, unauthorized AI tools inside organizations, creating security and compliance blind spots that teams struggle to detect and manage.
  • Shadow AI refers to unsanctioned AI tools employees use without IT/security approval — think ChatGPT, Copilot plugins, AI browser extensions
  • Data exfiltration risk: sensitive corporate data fed into external LLMs may be used for model training or exposed via breaches
  • Discovery challenge: traditional DLP and network controls often miss AI API calls, especially HTTPS to major providers
  • Attack surface expansion: unauthorized AI integrations can introduce prompt injection vectors and third-party supply chain risk
  • Mitigation stack: AI usage policy enforcement, network egress filtering, CASB/SSPM tooling, and platforms like Vanta for continuous visibility
2026-06-18 · watch on YouTube ↗
NetworkChuck hosts a 90-min live AMA for his Summer of CCNA program, answering certification questions from students in real time.
  • Live Q&A session focused on CCNA certification prep and study strategies
  • Part of the structured Summer of CCNA course series via NetworkChuck Academy
  • Community-driven format — student questions drive the content
  • Covers networking fundamentals relevant to Cisco CCNA exam objectives
  • Free academy signup available for full Summer of CCNA curriculum access
2026-06-18 · watch on YouTube ↗
HTTPS encrypts traffic content but still exposes visited domains to your ISP via DNS queries and TLS SNI headers.
  • TLS/HTTPS encrypts payload but Server Name Indication (SNI) leaks the destination hostname in plaintext during the handshake
  • DNS queries reveal browsing destinations unless DNS-over-HTTPS (DoH) or DNS-over-TLS (DoT) is used
  • ISPs can log and monetize domain-level browsing data even with HTTPS everywhere
  • Encrypted Client Hello (ECH) is the emerging fix — wraps SNI inside the encrypted handshake
  • VPNs and Tor shift trust to the tunnel endpoint but don't eliminate metadata exposure
2026-06-18 · watch on YouTube ↗
Cisco Cloud Control unifies network management into a single platform with AI agents that actively automate and execute networking tasks.
  • Cisco Cloud Control is a centralized platform for managing network infrastructure across environments
  • AI agents move beyond dashboards to actively perform networking tasks, not just monitor them
  • Demonstrates a shift from reactive network management to autonomous, AI-driven operations
  • Cisco positioning itself at the intersection of cloud networking and agentic AI workflows
  • Relevant for enterprise network engineers evaluating AI-assisted infrastructure automation
2026-06-16 · watch on YouTube ↗
NetworkChuck hosts a live 90-min AMA covering certification questions as part of the Summer of CCNA study program.
  • Live Q&A session focused on CCNA certification prep questions from the community
  • Part of the structured Summer of CCNA cohort program via NetworkChuck Academy
  • Covers networking fundamentals and exam strategy relevant to Cisco CCNA
  • Interactive format lets students get real-time answers on tough exam topics
  • Links to the full Summer of CCNA course at academy.networkchuck.com