← All briefings

Mirasvit Full Page Cache Warmer · Android Framework · Linux Kernel

DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-05 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership Classification: TLP:CLEAR


EXECUTIVE SUMMARY

The current threat landscape is dominated by several high-priority items requiring immediate attention. CISA has added three vulnerabilities to its Known Exploited Vulnerabilities catalog within the past 72 hours, including an actively exploited Magento deserialization flaw and an Android Framework privilege escalation. A China-linked threat actor, TA4922, has expanded phishing operations to explicitly target Germany and other European nations. Multiple enterprise platforms face critical exposure: Cisco Unified Communications Manager has a public proof-of-concept exploit for a server-side request forgery flaw, Microsoft Azure HorizonDB carries a CVSS 10.0 authentication bypass, and SolarWinds Serv-U is vulnerable to unauthenticated denial-of-service. A broad malvertising campaign is actively distributing malware via fake open-source tool sites, and a macOS backdoor campaign is spreading through Google and YouTube ads. Security teams should prioritize patching KEV-listed items and review detections for TA4922 TTPs targeting European organizations.


CRITICAL VULNERABILITIES

CVE-2026-45247

  • Affected products: Mirasvit Full Page Cache Warmer (Magento extension)
  • Severity: Critical (CVSS 9.8)
  • Exploitation status: Actively exploited in the wild; added to CISA KEV on 2026-06-03; due date for federal remediation was 2026-06-06
  • Remediation: Update to the patched version per Mirasvit changelog at mirasvit.com/package/changelog. If patching is not immediately possible, disable the extension and monitor CacheWarmer cookie values for serialized PHP object patterns.

CVE-2025-48595

  • Affected products: Android Framework (all supported Android versions)
  • Severity: High (CVSS 8.4)
  • Exploitation status: Actively exploited in the wild; added to CISA KEV on 2026-06-02; confirmed in Google June 2026 Android Security Bulletin
  • Remediation: Apply the June 2026 Android security update immediately. Prioritize managed and corporate-enrolled devices. No user interaction is required for exploitation.

CVE-2022-0492

  • Affected products: Linux Kernel (cgroups v1 release_agent feature)
  • Severity: High (CWE-287/CWE-862)
  • Exploitation status: Added to CISA KEV on 2026-06-02; enables local privilege escalation and potential container escape
  • Remediation: Apply vendor-specific kernel patches. Verify cgroups v1 is disabled or restricted in container environments. Check with distribution vendors (Red Hat, SUSE, Canonical, Debian) for patch availability.

CVE-2026-48567

  • Affected products: Microsoft Azure HorizonDB (cloud-hosted service)
  • Severity: Critical (CVSS 10.0)
  • Exploitation status: No confirmed exploitation reported; newly published 2026-06-04
  • Remediation: Microsoft-managed service; no customer action required for patching. Monitor for anomalous privilege escalation activity in Azure environments and review access logs.

CVE-2026-20230

  • Affected products: Cisco Unified Communications Manager (Unified CM)
  • Severity: High (CVSS not confirmed in source data; described as SSRF enabling root access)
  • Exploitation status: Proof-of-concept exploit publicly available; no confirmed in-the-wild exploitation reported by Cisco PSIRT as of 2026-06-04
  • Remediation: Apply Cisco patch immediately. PoC availability significantly shortens the exploitation window. Restrict network access to Unified CM management interfaces.

CVE-2026-20245

  • Affected products: Cisco Catalyst SD-WAN Manager (formerly vManage)
  • Severity: High (CVSS 7.8)
  • Exploitation status: Cisco has observed limited cases of exploitation resulting in configuration changes pushed to edge devices; requires netadmin privileges
  • Remediation: Upgrade to fixed software per Cisco advisory published 2026-05-14. Verify edge device configurations for unauthorized changes. Requires valid credentials or chaining with other vulnerabilities.

CVE-2026-28318

  • Affected products: SolarWinds Serv-U (versions prior to 15.5.4 Hotfix 1)
  • Severity: High (CVSS 7.5)
  • Exploitation status: No confirmed exploitation; unauthenticated denial-of-service via crafted POST request with Content-Encoding: deflate
  • Remediation: Upgrade to Serv-U 15.5.4 Hotfix 1. Apply vendor mitigations from SolarWinds Trust Center if immediate patching is not possible.

CVE-2026-25550 and CVE-2026-25551 (consolidated)

  • Affected products: Seagull Software BarTender 2010, 2016, 2019, 2021 R1 through 12.0.1
  • Severity: Critical (CVSS 9.8 remote; 8.5 local escalation)
  • Exploitation status: No confirmed exploitation; CVE-2026-25550 allows unauthenticated RCE via exposed .NET Remoting service on TCP port 7375; CVE-2026-25551 allows local privilege escalation to SYSTEM via deserialization
  • Remediation: Update BarTender to the latest version. Block TCP port 7375 at the network perimeter. BarTender is widely deployed in manufacturing and logistics environments common in European industrial settings.

Acer Connect M6E 5G Firmware (multiple CVEs)

  • Affected products: Acer Connect M6E 5G mobile hotspot, firmware up to m6e_ai_1.00.000019
  • Severity: Multiple Critical and High findings (CVE-2026-49188, CVE-2026-49191, CVE-2026-50211, CVE-2026-50208, CVE-2026-49190, CVE-2026-49194, and others)
  • Exploitation status: No confirmed exploitation; vendor advisory and mitigations published
  • Remediation: Apply firmware update per Acer advisory at community.acer.com/en/kb/articles/19707. Issues include unauthenticated RCE, hard-coded API keys, disabled TLS validation, exposed diagnostic interfaces, and MDM endpoint hijacking.

EUROPEAN ADVISORIES

CERT-EU Cyber Brief 26-06 (May 2026 Overview)

  • Published 2026-06-02; TLP:CLEAR monthly executive summary covering the most relevant cybersecurity developments for EU institutions and member state leadership
  • No specific technical indicators published in the open summary; full details available upon request to CERT-EU constituency members
  • Reference: cert.europa.eu/publications/threat-intelligence/cb26-06/

Turkish USOM Advisories (via NVD)

  • CVE-2026-4104: SQL injection in Akmer Informatics TeknoPass (CVSS 9.8); affects versions from 2021-05-01 through 2026-04-29; advisory published by TR-CERT at siberguvenlik.gov.tr
  • CVE-2026-5228: Improper access control in Kurt Software Studio WriteUp Mobile App (CVSS 8.8); affects versions 1.3.0 through 2026-04-06; advisory published by TR-CERT
  • Note: BSI and CERT-EU have not published new technical advisories within the past 24 hours based on available data.

ACTIVE THREATS AND CAMPAIGNS

TA4922 - China-Linked Phishing Campaign Targeting Europe

  • A China-linked threat actor tracked as TA4922 has expanded phishing operations to explicitly target organizations in Germany, the United Kingdom, Italy, and South Africa
  • Malware families in use include ValleyRAT (also known as Winos 4.0), Atlas RAT (also known as AtlasCross RAT), and previously undisclosed families
  • The group is operating at a rapid tempo with a continuously evolving toolset
  • Defenders in Germany should treat this as a direct and active threat; review email gateway logs for spear-phishing indicators and monitor for ValleyRAT and Atlas RAT IOCs

Gamaredon - WinRAR Exploitation Against Ukraine (Spillover Risk)

  • Russian state-linked Gamaredon group is actively exploiting CVE-2025-8088, a path traversal flaw in WinRAR, to deliver GammaPhish HTA payloads, GammaWorm, and GammaSteel data-theft malware
  • Primary targeting is Ukrainian government and defense entities; spillover risk to European organizations with Ukrainian partnerships or shared infrastructure is assessed as moderate
  • Ensure WinRAR is patched against CVE-2025-8088 across all endpoints

Operation FlutterBridge - macOS Malvertising

  • A macOS backdoor named FlutterShell is being distributed via malicious Google and YouTube advertisements in a campaign called Operation FlutterBridge
  • Linked to a previously tracked cluster called JSCoreRunner (FileRipple) from August 2025
  • Targets macOS users who click on ads impersonating legitimate software; delivers a persistent backdoor
  • Relevant for organizations with macOS endpoints; review endpoint telemetry for FlutterShell indicators and enforce application allowlisting

Fake Open-Source Tool Sites Delivering Malware via TDS

  • A large-scale campaign is using convincing fake websites impersonating open-source and freeware projects to redirect users through a Traffic Distribution System
  • Delivered malware families include Remus Stealer, AnimateClipper, and the SessionGate framework
  • Sites rank highly in search engine results; developers and IT staff searching for tools are at elevated risk
  • Enforce download policies requiring verified sources; block known TDS redirect domains at the proxy layer

DesckVB RAT via Google DoubleClick Malspam

  • A malspam campaign is routing victims through Google’s DoubleClick domain before redirecting to attacker infrastructure delivering DesckVB RAT
  • The use of a trusted Google domain is intended to bypass email security gateways and proxy filters
  • Review email security rules to inspect redirect chains through legitimate domains; do not whitelist DoubleClick as inherently safe

Stock Exchange Executive Email Espionage

  • Attackers maintained persistent access to the Outlook mailbox of a senior executive at a major global stock exchange for at least five months
  • Data was exfiltrated in small batches via Dropbox and OneDrive to blend with normal cloud traffic
  • Assessed as espionage-motivated; attribution not confirmed
  • Financial sector organizations should audit cloud storage access patterns and review executive mailbox access logs for anomalous activity

SECURITY NEWS AND CONTEXT

  • Cisco has patched CVE-2026-20230 in Unified Communications Manager; a public proof-of-concept is available and exploitation is expected imminently. Cisco also confirmed limited exploitation of CVE-2026-20245 in SD-WAN Manager.

  • A flaw in Anthropic’s Claude Code GitHub Action allowed repository takeover via a single malicious GitHub issue. The vulnerability affected Anthropic’s own action repository, creating supply chain risk for downstream consumers. Patched; organizations using the action should verify they are on the updated version.

  • A one-click attack via Microsoft Visual Studio Code and the GitHub.dev feature can steal GitHub OAuth tokens with read and write access to private repositories. Developers should be cautious with VS Code extension links from untrusted sources.

  • An unpatched Windows Search URI handler vulnerability can be used to steal NTLMv2 hashes, similar to the previously disclosed CVE-2026-33829 affecting the Snipping Tool URI handler. No CVE assigned yet; no patch available. Mitigate by blocking outbound SMB at the perimeter and enforcing NTLMv2 restrictions.

  • A new HTTP/2 Bomb denial-of-service vulnerability affects NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora in their default configurations. Discovered by an AI-assisted research tool. Patches and mitigations are being released by vendors; review web server configurations.

  • Redis patched CVE-2026-23479, a use-after-free RCE flaw introduced in version 7.2.0 and present for over two years. Authenticated users could execute arbitrary OS commands. Patch to the latest Redis release.

  • The U.S. Department of Justice concluded a Disruption Week operation targeting Southeast Asia-based cryptocurrency fraud networks, freezing 3.8 million USD in assets and taking down millions of fraudulent accounts.

  • CERT-EU published its monthly Cyber Brief 26-06 covering May 2026 developments for EU leadership audiences.


RECOMMENDED ACTIONS

Immediate (within 24 hours):

  • Patch or disable Mirasvit Full Page Cache Warmer on all Magento instances; CVE-2026-45247 is actively exploited and the CISA KEV deadline has passed
  • Apply the June 2026 Android security update to all managed devices; CVE-2025-48595 is actively exploited
  • Apply Linux kernel patches addressing CVE-2022-0492 on all Linux hosts, especially container hosts; verify cgroups v1 is restricted
  • Patch Cisco Unified CM against CVE-2026-20230; public PoC is available

Short-term (within 72 hours):

  • Patch Cisco SD-WAN Manager against CVE-2026-20245; limited exploitation confirmed; audit edge device configurations for unauthorized changes
  • Update SolarWinds Serv-U to version 15.5.4 Hotfix 1
  • Update BarTender to the latest version and block TCP port 7375 at the network perimeter
  • Apply Acer Connect M6E 5G firmware update if devices are deployed in the environment
  • Patch Redis to the latest stable release addressing CVE-2026-23479

Ongoing:

  • Distribute TA4922 IOCs (ValleyRAT, Atlas RAT) to email gateway and endpoint detection teams; treat Germany as an active target
  • Ensure WinRAR is patched against CVE-2025-8088 to reduce Gamaredon spillover risk
  • Enforce verified download sources for software; brief developers on fake open-source tool site campaign
  • Review executive and privileged user mailbox access logs for anomalous cloud exfiltration patterns via Dropbox and OneDrive
  • Implement NTLMv2 relay mitigations and block outbound SMB to address unpatched Windows Search URI handler issue
  • Review web server HTTP/2 configurations for NGINX, Apache, and IIS; apply vendor mitigations as they become available
  • Audit GitHub Actions workflows for use of the Claude Code action; verify updated version is in use