← All briefings

SimpleHelp · libssh2 · Oracle E-Business Suite

DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-06-30 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

EXECUTIVE SUMMARY

The most critical new development is active exploitation of CVE-2026-48558, a SimpleHelp authentication bypass now on the CISA KEV catalog, with confirmed deployment of a previously undocumented infostealer (Djinn Stealer). A public proof-of-concept for CVE-2026-55200 (libssh2) materially raises exploitation risk for that client-side SSH flaw. Oracle E-Business Suite CVE-2026-46817 is now being actively exploited in the wild, with Nissan and NAIC among confirmed breach victims linked to the ShinyHunters group. Microsoft’s StegoAd operation — 119 malicious Edge extensions hiding payloads in image and font files — has been dismantled.

CRITICAL VULNERABILITIES

NEW

CVE-2026-48558 (SimpleHelp)

  • Affected products: SimpleHelp (all versions with OIDC authentication configured)
  • Severity: Critical (CVSS not yet published); CISA KEV listed, due date 2026-07-02
  • EPSS: Not yet scored; CISA KEV confirms active exploitation
  • Technical detail: An authentication bypass in SimpleHelp’s OIDC flow accepts identity tokens without verifying their cryptographic signature (CWE-347). A remote, unauthenticated attacker can submit a forged token with arbitrary identity claims to obtain a fully authenticated technician session. In some configurations this also bypasses multi-factor authentication. Exploitation has been confirmed in the wild with deployment of Djinn Stealer, a previously undocumented cross-platform infostealer targeting Windows, macOS, and Linux.
  • Exploitation status: Actively exploited; CISA KEV listed.
  • Remediation: Apply the vendor patch immediately. Federal agencies must remediate by 2026-07-02; all other organizations should treat this as emergency priority. If OIDC is not required, disable it. Review technician session logs for unauthorized access. Hunt for Djinn Stealer indicators on endpoints managed via SimpleHelp.

CVE-2026-55200 (libssh2)

  • Affected products: libssh2 versions up to and including 1.11.1
  • Severity: CVSS 4.0 score 9.2 (Critical)
  • EPSS: Not yet scored; public PoC now available — exploitation probability elevated
  • Technical detail: A memory corruption flaw in the libssh2 client library allows a malicious or compromised SSH server to trigger heap corruption on a connecting client, with potential for remote code execution. No credentials or user interaction are required beyond initiating an SSH connection. libssh2 is embedded in a wide range of applications, language bindings, and automation tooling, meaning the attack surface extends well beyond direct SSH clients. A public proof-of-concept was released on 2026-06-29.
  • Exploitation status: No confirmed in-the-wild exploitation; public PoC significantly raises risk.
  • Remediation: Update libssh2 to a patched release immediately. Audit all applications and tooling that bundle libssh2 and update accordingly. Restrict SSH client connections to trusted servers where possible.

CVE-2026-46817 (Oracle E-Business Suite)

  • Affected products: Oracle E-Business Suite (EBS) financial application
  • Severity: Critical (exact CVSS not yet confirmed in source data)
  • EPSS: Not yet scored; active exploitation confirmed
  • Technical detail: Attackers have begun actively exploiting this critical Oracle EBS vulnerability. Confirmed breach victims include Nissan (employee data exposed) and the National Association of Insurance Commissioners (NAIC), with the ShinyHunters extortion group attributed to the campaign. Oracle EBS is widely deployed in enterprise finance and HR environments, making this a high-value target for data theft and extortion. The exploitation vector is consistent with the broader ShinyHunters Oracle PeopleSoft/EBS campaign observed in recent weeks.
  • Exploitation status: Actively exploited in the wild; multiple confirmed breach victims.
  • Remediation: Apply Oracle Critical Patch Update patches for EBS immediately. Review EBS access logs for unauthorized data access. Assess whether sensitive employee or financial data may have been exfiltrated. Engage Oracle support if patch status is unclear.

CVE-2026-56290 (Page Builder CK for Joomla)

  • Affected products: JoomlaCK.fr Page Builder CK extension for Joomla, versions 1.0 through 3.6.0
  • Severity: CVSS 10.0
  • EPSS: 0 (newly published; no exploitation history yet)
  • Technical detail: An unauthenticated arbitrary file upload vulnerability allows remote attackers to upload executable files and achieve full remote code execution on the web server. No authentication is required. Joomla-based sites running this extension in the affected version range are fully compromised by a single HTTP request. The broad version range (1.0 to 3.6.0) suggests a large number of potentially affected installations.
  • Exploitation status: No confirmed exploitation; CVSS 10.0 and unauthenticated attack vector make this a high-priority patch.
  • Remediation: Update Page Builder CK to a version beyond 3.6.0 immediately. If no patch is available, disable or remove the extension. Review web server logs for suspicious file upload activity.

CVE-2026-41052 (SUSE Rancher)

  • Affected products: Rancher 2.12.x before 2.12.10, 2.13.x before 2.13.6, 2.14.x before 2.14.2
  • Severity: CVSS 9.4
  • EPSS: 0 (newly published)
  • Technical detail: Improper privilege handling allows users with the Project Owner role to escalate privileges within Rancher, a widely used Kubernetes management platform. In enterprise environments where Rancher manages multi-tenant Kubernetes clusters, a compromised or malicious project owner could gain control over resources beyond their intended scope, potentially affecting the entire cluster management plane.
  • Exploitation status: No confirmed exploitation.
  • Remediation: Upgrade Rancher to 2.12.10, 2.13.6, or 2.14.2 as appropriate. Review Project Owner role assignments and audit privilege boundaries.

ONGOING

  • CVE-2026-42208 (LiteLLM Proxy): actively exploited, CISA KEV, Metasploit module public; patch and rotate API keys.
  • CVE-2026-45087 (Dalfox Server): public Metasploit RCE exploit; upgrade beyond 2.12.0, restrict exposure.
  • CVE-2026-58053 (Gitea act_runner): container escape; upgrade beyond 0.262.0.
  • CVE-2026-58050 / CVE-2026-58051 (libssh2): heap flaws; update libssh2 and bundled applications.
  • CVE-2026-46331 / CVE-2026-43503 (Linux kernel): public exploits; apply distribution kernel patches.
  • CVE-2026-49869 / CVE-2026-53576 (Kestra): CVSS 10.0; upgrade to 1.0.45 or 1.3.21.
  • CVE-2026-54350 (Budibase): CVSS 10.0; upgrade to 3.39.12.
  • CVE-2026-52785 (OpenProject): SQL injection and RCE; upgrade to 17.3.3 or 17.4.1.
  • CVE-2026-12415 (WordPress Invoice Generator): EPSS 0.66; update or disable plugin.

EUROPEAN ADVISORIES

BSI published a high volume of updated and new advisories on 2026-06-29. New advisories of note:

WID-SEC-2026-2117 (HCL BigFix Compliance / Ruby): Multiple vulnerabilities enabling RCE, security bypass, data manipulation, information disclosure, and DoS. Organizations using HCL BigFix Compliance should apply available patches promptly.

WID-SEC-2026-2116 (Gitea act_runner): Privilege escalation by authenticated remote attacker. Cross-reference: CVE-2026-58053, covered in Critical Vulnerabilities in yesterday’s report; patch action remains open.

WID-SEC-2026-2113 (Froxlor): Multiple vulnerabilities including XSS, SQL injection, security bypass, and information disclosure. Froxlor is a widely used open-source server management panel in German hosting environments. Apply available updates immediately.

WID-SEC-2026-2109 (ffmpeg RASC decoder): DoS and memory corruption via remote unauthenticated attacker. Update ffmpeg; sandbox media processing pipelines.

WID-SEC-2026-2108 (Microsoft Edge Chromium): RCE by authenticated remote attacker. Apply the latest Edge update.

WID-SEC-2026-2103 (Coolify): Security bypass by authenticated remote attacker. Multiple Coolify CVEs (CVE-2026-57498, CVE-2026-34594, CVE-2026-34597, CVE-2026-34592) published simultaneously; upgrade to 4.0.0-beta.474 or later.

WID-SEC-2026-2102 (Linux Kernel): Local privilege escalation to administrator. Apply current distribution kernel patches.

WID-SEC-2026-0098 (Node.js) and WID-SEC-2026-2041 (Budibase): Updated advisories; Budibase covered in prior report — upgrade to 3.39.12 remains required.

Updated advisories for IBM App Connect Enterprise, Apache Kafka, Hitachi Virtual Storage Platform, PostgreSQL, Golang Go, GnuTLS, MariaDB, NGINX, Notepad++, Red Hat Enterprise Linux (Flatpak): apply vendor patches per existing guidance.

CVE-2026-13165 (SzafirHost, CERT-PL): A Zip parser inconsistency in the Polish KIR SzafirHost digital signature library allows a malicious archive to pass signature verification while delivering different content during extraction. Update to version 1.2.2 or later. Relevant to organizations using Polish e-signature infrastructure.

CVE-2026-25707 (SUSE libzypp): Path traversal in repository metadata processing allows a malicious repository to overwrite arbitrary system files. Update libzypp to 17.38.10 or later. Relevant to SUSE/openSUSE enterprise deployments.

ACTIVE THREATS AND CAMPAIGNS

NEW — Mustang Panda / Zoho WorkDrive C2 (Indian Government Targeting) Acronis Threat Research Unit has identified active Mustang Panda (China-aligned) intrusions inside Indian government networks, including machines used by senior administrative staff. The campaign uses Zoho WorkDrive as a command-and-control channel, abusing a legitimate cloud service to blend C2 traffic with normal business activity. New malware variants have been deployed. European organizations with diplomatic or governmental ties to India, or those sharing infrastructure with Indian government entities, should review outbound Zoho WorkDrive traffic for anomalous patterns and apply relevant IOCs.

NEW — Microsoft-Tracked Multi-Stage Attack Campaign Against Hospitality Sector Microsoft Threat Intelligence is tracking a multi-stage attack wave targeting the hotel and hospitality sector across Asia and Europe. Attackers are establishing persistent footholds within victim networks. European hospitality organizations should review endpoint telemetry for signs of staged intrusion activity and ensure phishing-resistant authentication is enforced.

ONGOING — Russian Intelligence Messenger Credential Theft: Targeting Signal Backup Recovery Keys; prohibit sharing recovery keys via any channel. ONGOING — Gamaredon: 35+ spear-phishing campaigns against Ukrainian targets in 2025, evolving malware arsenal and cloud service abuse. ONGOING — SharkLoader / StrikeShark: Cobalt Strike loader targeting government and diplomatic organizations; apply Kaspersky IOCs. ONGOING — Turla STOCKSTAY: .NET backdoor targeting Ukrainian government and Italian foreign policy entities; apply GTIG IOCs. ONGOING — Miasma supply chain malware: targeting npm and GitHub Actions; audit CI/CD pipeline dependencies.

SECURITY NEWS AND CONTEXT

StegoAd: Microsoft removed 119 malicious Edge extensions hiding credential-stealing and ad-fraud payloads inside image and font files via steganography. The operation has been active since at least 2021. Security teams should audit installed Edge extensions across managed endpoints and enforce extension allowlisting.

A malicious Chrome extension impersonating the Perplexity AI search engine was found intercepting all search queries and address bar input, routing them to an attacker-controlled server. Google removed it following Microsoft’s responsible disclosure. Enforce browser extension policies and audit installed extensions on enterprise endpoints.

Over 236,000 websites built on the DCloud Uni-App framework are being used for cryptocurrency scams, pig-butchering operations, WhatsApp phishing, and wallet drainers, according to Infoblox research. Block known malicious domains at the perimeter.

Rapid7 published a policy paper on modernizing global vulnerability standards for the AI era, noting CVE submissions grew 263% between 2020 and 2025 and that AI-driven discovery is accelerating pressure on NVD, CVSS, and EPSS infrastructure.

RECOMMENDED ACTIONS

  1. Patch SimpleHelp immediately (CVE-2026-48558) — CISA KEV, actively exploited, Djinn Stealer deployed; deadline 2026-07-02. Hunt for infostealer activity on managed endpoints.
  2. Update libssh2 to patched release (CVE-2026-55200) — public PoC released; audit all applications bundling the library.
  3. Apply Oracle EBS patches immediately (CVE-2026-46817) — actively exploited by ShinyHunters; review access logs for data exfiltration.
  4. Update Page Builder CK for Joomla beyond 3.6.0 (CVE-2026-56290) — CVSS 10.0, unauthenticated RCE; disable if no patch available.
  5. Upgrade SUSE Rancher to 2.12.10, 2.13.6, or 2.14.2 (CVE-2026-41052) — privilege escalation in Kubernetes management plane.
  6. Update Froxlor and SzafirHost (BSI WID-SEC-2026-2113; CVE-2026-13165) — relevant to German hosting and Polish e-signature environments.
  7. Upgrade SUSE libzypp to 17.38.10 (CVE-2026-25707) — path traversal allowing system file overwrite via malicious repository.
  8. Audit all browser extensions on managed endpoints — remove or block unauthorized Chrome and Edge extensions; enforce allowlisting policy.
  9. Review outbound Zoho WorkDrive traffic for anomalous C2 patterns — Mustang Panda campaign active against government targets.
  10. Continue remediation of previously reported items: CVE-2026-42208 (LiteLLM), CVE-2026-45087 (Dalfox), CVE-2026-58053 (Gitea), libssh2 heap flaws, Linux kernel exploits, Kestra, Budibase, OpenProject, Keycloak, PowerDNS, Fluentd, WSO2 API Manager, WordPress Invoice Generator.