In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw

2026-06-26T02:51:43Za9abc7b2e5889db6742f8c65cf576d1985ee2d4596dff37285d6d8335aad4d9e
APT/GamaredonCisco CUCMCisco SD-WANEurope targetingFortiBleedFortiGateFortinetKlueOAuth token theftOracle ERPPhantom stealerRokarollaSSRFSalesforceShinyHuntersSocGholishSprySOCKS kernel evasion','DifyTap','AI supply chain','OpenClaw/TDScredential harvestingexploited in the wildfileless malwareprivilege escalationransomwaresupply chain compromisezero-day

What happened

Multiple actively exploited vendor and supply-chain vulnerabilities and large-scale campaigns are dominating the news cycle. Notable incidents include rapid weaponization of a Cisco Unified CM (CUCM) SSRF that allows privilege escalation to root, exploitation of a Cisco SD‑WAN flaw before disclosure, mass credential‑harvesting campaigns targeting Fortinet/FortiGate devices (FortiBleed-related activity), an Oracle ERP zero‑day abused by threat actors, and ongoing supply‑chain/OAuth abuses (Klue → Salesforce). Additional high-risk items include fileless and kernel‑abusing malware (Phantom steale

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
a9abc7b2e5889db6742f8c65cf576d1985ee2d4596dff37285d6d8335aad4d9e
Enrichment time
2026-06-26T02:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw · Baitaphish