← All briefings

Cisco Unified Communications Manager · Kibana · OPNsense

DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-07-03 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

EXECUTIVE SUMMARY

No new CISA KEV additions in the last 24 hours. BSI published a significant batch of new advisories covering Kibana, OPNsense, Ubiquiti UniFi, Coolify, MediaWiki, and IBM DataPower Gateway. Cisco has confirmed active exploitation of a Unified Communications Manager vulnerability patched in June. The ToddyCat threat actor has been linked to new Umbrij malware abusing OAuth to silently access corporate Gmail accounts. An AI-driven ransomware attack attributed to operator JADEPUFFER exploited Langflow RCE to automate a full database encryption incident — a notable operational milestone.

CRITICAL VULNERABILITIES

NEW

Cisco Unified Communications Manager (Unified CM) — Unspecified Vulnerability

  • Affected products: Cisco Unified Communications Manager (patched in early June 2026)
  • Severity: Not yet assigned public CVSS at time of writing
  • EPSS: Not yet scored
  • Technical detail: Cisco has now confirmed that attackers are actively exploiting a vulnerability in Unified CM that was patched in early June. Unified CM is widely deployed in enterprise telephony environments and is frequently internet-adjacent or reachable from internal networks. The specific attack vector has not been fully disclosed, but active exploitation in the wild elevates this to immediate priority. Organizations that have not applied the June patch cycle are exposed.
  • Exploitation status: Actively exploited in the wild; confirmed by Cisco.
  • Remediation: Apply the June 2026 Cisco Unified CM security update immediately. Audit Unified CM access logs for anomalous activity. Restrict management interface access to trusted administrative networks.

CVE-2026-45659 (Microsoft SharePoint Server)

  • STATUS CHANGE: CISA KEV deadline is 2026-07-04 — tomorrow. Organizations not yet patched are in breach of BOD 26-04. This remains the highest-priority remediation action. Full entry in yesterday’s report.

Kibana — Multiple Vulnerabilities (WID-SEC-2026-2179)

  • Affected products: Kibana (versions unspecified in advisory)
  • Severity: High (BSI rating)
  • EPSS: Not yet scored
  • Technical detail: Multiple vulnerabilities allow a remote authenticated attacker to conduct denial-of-service attacks, execute arbitrary code, bypass security controls, and disclose sensitive information. Kibana is widely deployed as the visualization layer for Elastic Stack in enterprise SIEM, observability, and log analytics environments. Code execution in Kibana can expose underlying Elasticsearch data and pivot to adjacent infrastructure. Authentication is required, but in many deployments Kibana is accessible to a broad internal user base.
  • Exploitation status: No confirmed exploitation; enterprise relevance is high.
  • Remediation: Apply Elastic’s available Kibana security updates. Review Kibana access controls and restrict to authorized users. Monitor for anomalous query or API activity.

OPNsense — Multiple Vulnerabilities (WID-SEC-2026-2177)

  • Affected products: OPNsense (versions unspecified in advisory)
  • Severity: High (BSI rating)
  • EPSS: Not yet scored
  • Technical detail: Multiple vulnerabilities allow an attacker to execute arbitrary code with administrator privileges, bypass security controls, conduct cross-site scripting attacks, manipulate files, disclose information, and cause denial of service. OPNsense is a widely used open-source firewall and routing platform in European SME and enterprise environments. Code execution with admin rights on a perimeter firewall represents a critical network security risk. XSS flaws in the management interface can be leveraged for session hijacking against administrators.
  • Exploitation status: No confirmed exploitation.
  • Remediation: Update OPNsense to the latest available release. Restrict management interface access to trusted administrative hosts; do not expose the web GUI to the internet.

Ubiquiti UniFi — Multiple Vulnerabilities (WID-SEC-2026-2171)

  • Affected products: Ubiquiti UniFi (versions unspecified in advisory)
  • Severity: High (BSI rating)
  • EPSS: Not yet scored
  • Technical detail: Multiple vulnerabilities allow arbitrary code execution, SQL injection, privilege escalation, security bypass, denial of service, data manipulation, and information disclosure. UniFi network management infrastructure is extensively deployed in enterprise, campus, and SME environments across Europe. SQL injection and privilege escalation in network management platforms can lead to full infrastructure compromise and lateral movement.
  • Exploitation status: No confirmed exploitation.
  • Remediation: Apply available Ubiquiti UniFi security updates. Restrict UniFi controller access to management VLANs; enforce strong authentication on the management interface.

ONGOING

  • CVE-2026-45659 (Microsoft SharePoint Server): CISA KEV deadline 2026-07-04 — patch immediately if not yet done.
  • CVE-2026-44939 (SUSE Rancher): command injection, very high exploitation probability; upgrade to patched release.
  • CVE-2026-8037 (Progress Kemp LoadMaster): actively exploited; patch or isolate management interface.
  • CVE-2026-48558 (SimpleHelp): CISA KEV deadline passed; hunt for Djinn Stealer indicators.
  • CVE-2026-46817 (Oracle E-Business Suite): actively exploited by ShinyHunters; patch immediately.
  • CVE-2026-10109 (IBM Db2): pre-auth RCE; patch and restrict port 50000.
  • Adobe ColdFusion CVE-2026-48283 et al.: CVSS 10.0 unauthenticated RCE; apply patches if not yet done.
  • BlueHammer (Windows Defender privilege escalation): actively exploited by ransomware gangs; ensure patch applied.
  • Google Chrome: update to 150.0.7871.46 if not yet deployed.

EUROPEAN ADVISORIES

BSI published a large batch of new and updated advisories on 2026-07-02.

New advisories: WID-SEC-2026-2179 (Kibana) and WID-SEC-2026-2177 (OPNsense) and WID-SEC-2026-2171 (Ubiquiti UniFi) are detailed in the Critical Vulnerabilities section above.

WID-SEC-2026-2182 (Coolify): A remote authenticated attacker can exploit a vulnerability in the Coolify self-hosted PaaS platform to execute arbitrary code and disclose information. Coolify is increasingly used in European developer and SME environments as a self-hosted Heroku alternative. Apply available patches and restrict access to trusted users.

WID-SEC-2026-2170 (MediaWiki and Extensions): Multiple vulnerabilities allow cross-site scripting, open redirect, authentication bypass, and SQL injection. MediaWiki is widely deployed for internal knowledge management in enterprises and public institutions. Apply the latest MediaWiki security release and audit installed extensions.

WID-SEC-2026-2169 (IBM DataPower Gateway): Multiple vulnerabilities allow denial of service, information disclosure, and data manipulation. Apply IBM’s available fixes for affected DataPower Gateway versions.

WID-SEC-2026-2166 (Red Hat Satellite): Multiple vulnerabilities allow privilege escalation to administrator, authentication bypass, data manipulation, information disclosure, and denial of service. Apply Red Hat’s available Satellite updates.

Updated advisories (consolidated): BSI updated advisories for Node.js (WID-SEC-2026-0098, kritisch), GNU libc (WID-SEC-2026-1190, kritisch), Kemp LoadMaster (WID-SEC-2026-1812, kritisch — see Critical Vulnerabilities), IBM WebSphere Application Server (WID-SEC-2026-2159, -2001, -2050), IBM App Connect Enterprise Certified Container (WID-SEC-2026-1407), Google Chrome (WID-SEC-2026-2143), Microsoft SharePoint Server (WID-SEC-2026-1652 — see Critical Vulnerabilities), Linux Kernel (multiple advisories), IBM DB2 (WID-SEC-2026-0262), Red Hat Enterprise Linux urllib3 (WID-SEC-2026-0207), and FreeRDP (WID-SEC-2026-0145, -0111). Apply current vendor patches for all affected components.

Heise Security reported that Synology MailPlus Server contains vulnerabilities allowing attackers to bypass authentication or gain unauthorized access. A security patch is available. Apply the update and review MailPlus Server exposure. Adobe ColdFusion and Campaign Classic patches were also noted; covered in yesterday’s report.

ACTIVE THREATS AND CAMPAIGNS

NEW — ToddyCat: Umbrij Malware Abusing OAuth for Gmail Access Kaspersky attributed a new malware family, Umbrij, to the ToddyCat threat actor. Umbrij abuses the Google API via OAuth to silently access corporate email communications hosted on Gmail, targeting credential compromise through API access rather than direct credential theft. The technique bypasses traditional email security controls and MFA. Organizations using Gmail for corporate communications should audit OAuth application grants, revoke unknown or suspicious third-party app authorizations, and enable Google Workspace alerts for unusual API access patterns.

NEW — JADEPUFFER: AI-Automated Ransomware via Langflow RCE Sysdig’s Threat Research Team identified what it assesses as the first end-to-end AI-agent-driven ransomware attack. The operator, tracked as JADEPUFFER, exploited a remote code execution vulnerability in Langflow (an AI workflow platform) to gain initial access. An LLM agent then autonomously conducted credential theft, lateral movement, and production database encryption and wiping. Organizations running Langflow should patch immediately, restrict internet exposure, and treat any Langflow instance as a high-value target. This incident signals a material shift in ransomware operational tempo.

NEW — Anubis Ransomware Exploiting Citrix Bleed 2 (CVE-2025-5777) Affiliates of the Anubis ransomware operation are actively exploiting CVE-2025-5777 (Citrix Bleed 2) for initial access. Common post-exploitation tradecraft includes legitimate RMM tooling, credential access, and hands-on-keyboard lateral movement. Organizations running affected Citrix NetScaler ADC or Gateway versions should verify patching status and audit for unauthorized sessions.

NEW — ChocoPoC RAT Targeting Security Researchers via Fake PoC Repos Attackers are distributing a data-stealing trojan called ChocoPoC inside fake Python proof-of-concept repositories on GitHub, targeting vulnerability researchers. Running the fake PoC silently exfiltrates saved passwords, browser cookies, and files, and establishes a reverse shell. Security researchers and red teamers should treat all third-party PoC code as untrusted; sandbox or review before execution.

ONGOING — FortiBleed campaign linked to INC and Lynx ransomware: rotate Fortinet credentials and audit for unauthorized access. ONGOING — Azure CLI password-spray (2a0a:d683::/32): enforce MFA and Conditional Access; monitor sign-in logs. ONGOING — SEO-poisoned ScreenConnect/AsyncRAT campaign: block unauthorized ScreenConnect deployments. ONGOING — Ousaban banking trojan targeting Spain and Portugal: alert Iberian user populations; update email security rules. ONGOING — ConsentFix and ClickFix Microsoft 365 token hijacking: enforce Conditional Access and audit OAuth consent grants.

SECURITY NEWS AND CONTEXT

Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut (Popa) residential proxy network, reducing its pool of usable devices by millions. NetNut spanned approximately two million home devices and was used to anonymize malicious traffic; this follows Google’s January 2026 disruption of the IPIDEA proxy network.

A Scattered Spider suspect has been extradited from Estonia to the United States to face charges of conspiracy, computer intrusion, and fraud. The group remains operationally active.

Opera has introduced a Paste Protect feature to block ClickFix-style attacks that trick users into pasting and executing malicious commands. Defenders should note this as a browser-level mitigation but not a substitute for endpoint controls.

RECOMMENDED ACTIONS

  1. Patch Microsoft SharePoint Server (CVE-2026-45659) today — CISA KEV deadline is 2026-07-04; actively exploited deserialization RCE.
  2. Apply Cisco Unified CM June 2026 security update immediately — active exploitation confirmed; audit access logs for anomalous activity.
  3. Update Kibana, OPNsense, and Ubiquiti UniFi to latest available releases — multiple high-severity flaws including code execution and privilege escalation.
  4. Audit and revoke unauthorized OAuth application grants in Google Workspace — ToddyCat Umbrij malware abuses OAuth for silent Gmail access.
  5. Patch or isolate Langflow instances — JADEPUFFER AI-agent ransomware exploited Langflow RCE for fully automated database encryption.
  6. Verify Citrix NetScaler ADC/Gateway patching status for CVE-2025-5777 — Anubis ransomware affiliates actively exploiting Citrix Bleed 2.
  7. Apply Synology MailPlus Server security patch — authentication bypass vulnerabilities; restrict external exposure.
  8. Warn security research and red team staff against executing unvetted GitHub PoC code — ChocoPoC RAT actively targeting researchers.
  9. Apply Coolify and MediaWiki security updates; restrict management access to trusted users.
  10. Continue remediation of previously reported items: CVE-2026-48558 (SimpleHelp — deadline passed), CVE-2026-46817 (Oracle EBS), CVE-2026-8037 (Kemp LoadMaster), CVE-2026-44939 (SUSE Rancher), Adobe ColdFusion, BlueHammer, IBM Db2, Google Chrome 150.0.7871.46.