CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited

2026-06-24T19:24:09Zf44f9ec824303463d3d468a0adcd4e595693a3b93ee4cae27a25c5dbbd9b916a
AmadeyCI/CDCISACVE-2025-67038CVE-2026-20230CiscoCordycepsDifyTapEDS5000EuropolFortiBleedFortiGateFortinetGitHubLantronixMalware campaignsShapedPluginSquidbleedStealCUnified CMWordPress supply-chainactions/checkoutcredential-harvestnpm malwaresupply-chain

What happened

This feed highlights multiple high-impact incidents and supply-chain risks: CISA warns that CVE-2025-67038 (Lantronix EDS5000) — a critical code-injection flaw (CVSS 9.8) — is being actively exploited and federal agencies were urged to patch immediately. Cisco Unified Communications is also being actively exploited via CVE-2026-20230 (CVSS 8.6). Large-scale credential theft and disruption operations were reported: Europol-led takedown of Amadey/StealC recovered ~27M credentials, and the FortiBleed campaign harvested ~110M credentials from FortiGate devices. Researchers disclosed widespread CI/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
f44f9ec824303463d3d468a0adcd4e595693a3b93ee4cae27a25c5dbbd9b916a
Enrichment time
2026-06-24T19:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited · Baitaphish