Stealthy Mistic backdoor linked to ransomware access broker KongTuke

2026-06-24T13:23:30Z3a1610160e21aca65f30755a0c6ebf077913a815585626e4a8b1033ba0ba4f79
CVE-2026-20230Cisco Unified Communications ManagerDoSFFmpegFortiBleedFortiGateKlueKongTukeLastPassMisticPixelSmashRCESSRFTata ElectronicsVBScriptWhatsAppXsolisbackdoorcredential-theftdata-breachinfostealermacOS ClickFixphishingransomware-access-brokersupply-chain

What happened

Multiple high-impact security incidents and vulnerabilities were reported: a stealthy new backdoor dubbed Mistic linked to the ransomware access broker 'KongTuke' is being used in financially motivated attacks against insurance, education, IT, and professional services organizations; a high-severity SSRF in Cisco Unified Communications Manager (CVE-2026-20230) is being actively exploited; large data exposures and supply-chain breaches were disclosed (Xsolis, Tata Electronics, LastPass via the Klue attack); FFmpeg’s 'PixelSmash' flaw can enable RCE/DoS in media services; a macOS ClickFix DMG-ls

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
3a1610160e21aca65f30755a0c6ebf077913a815585626e4a8b1033ba0ba4f79
Enrichment time
2026-06-24T13:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Stealthy Mistic backdoor linked to ransomware access broker KongTuke · Baitaphish