In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw
2026-06-26T02:51:43Z•a9abc7b2e5889db6742f8c65cf576d1985ee2d4596dff37285d6d8335aad4d9e
APT/GamaredonCisco CUCMCisco SD-WANEurope targetingFortiBleedFortiGateFortinetKlueOAuth token theftOracle ERPPhantom stealerRokarollaSSRFSalesforceShinyHuntersSocGholishSprySOCKS kernel evasion','DifyTap','AI supply chain','OpenClaw/TDScredential harvestingexploited in the wildfileless malwareprivilege escalationransomwaresupply chain compromisezero-day
What happened
Multiple actively exploited vendor and supply-chain vulnerabilities and large-scale campaigns are dominating the news cycle. Notable incidents include rapid weaponization of a Cisco Unified CM (CUCM) SSRF that allows privilege escalation to root, exploitation of a Cisco SD‑WAN flaw before disclosure, mass credential‑harvesting campaigns targeting Fortinet/FortiGate devices (FortiBleed-related activity), an Oracle ERP zero‑day abused by threat actors, and ongoing supply‑chain/OAuth abuses (Klue → Salesforce). Additional high-risk items include fileless and kernel‑abusing malware (Phantom steale
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- a9abc7b2e5889db6742f8c65cf576d1985ee2d4596dff37285d6d8335aad4d9e
- Enrichment time
- 2026-06-26T02:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.