2 min read

Threat Report 6/26/26

Threat Report 6/26/26

PAN-OS Authentication Bypass Vulnerability

 

A critical vulnerability has been identified in the GlobalProtect Portal and Gateway of Palo Alto Networks PAN-OS. If exploited, attackers can bypass authentication and establish an unauthorized VPN connection.

Affected Versions

PAN-OS 11.2

  • Earlier than 11.2.4-h17
  • Earlier than 11.2.7-h14
  • Earlier than 11.2.10-h7
  • Earlier than 11.2.12

PAN-OS 11.1

  • Earlier than 11.1.4-h33
  • Earlier than 11.1.6-h32
  • Earlier than 11.1.7-h6
  • Earlier than 11.1.10-h25
  • Earlier than 11.1.13-h5
  • Earlier than 11.1.15

PAN-OS 10.2

  • Earlier than 10.2.7-h34
  • Earlier than 10.2.10-h36
  • Earlier than 10.2.13-h21
  • Earlier than 10.2.16-h7
  • Earlier than 10.2.18-h6

Prisma Access

  • 11.2.0 through versions earlier than 11.2.7-h13
  • 10.2.0 through versions earlier than 10.2.10-h36

Risk Level

  • Large & Medium Businesses: High
  • Small Businesses: High

Recommendations

  • Update all affected PAN-OS and Prisma Access systems immediately.
  • Apply the Principle of Least Privilege, ensuring administrative access is limited to only those who require it.
  • Review VPN access logs for any suspicious activity.

Reference:

https://security.paloaltonetworks.com/CVE-2026-0257



 


Active Exploitation of Cisco Unified CM Vulnerability

 

Attackers are actively exploiting a high-severity vulnerability in Cisco Unified Communications Manager (CUCM) that was patched on June 3.

CVE-2026-20230 allows an unauthenticated attacker to perform Server-Side Request Forgery (SSRF) attacks, which can lead to root-level privilege escalation.

Security researchers at Defused observed active exploitation using publicly available proof-of-concept code. Although the vulnerability is not yet listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, organizations should treat it as an urgent threat.

 

Recommendations



New "Prinz Eugen" Ransomware Emerges

 

Researchers have identified a new Go-based ransomware family named Prinz Eugen that is unusually sophisticated despite being newly discovered.

Key Characteristics

  • Prioritizes recently modified files to maximize disruption.
  • Verifies encrypted files before deleting originals.
  • Reduces opportunities for forensic recovery.
  • Does not leave a ransom note, instead directing victims to an external negotiation channel.

Because it targets files that are actively being used, organizations may lose their most valuable and least-backed-up data first.

Recommendations

  • Maintain regular offline or immutable backups.
  • Monitor for unusual file encryption activity.
  • Ensure endpoint detection and response (EDR) tools are up to date

 


Fake AI Tools Used in Over 33,000 Attacks

 

aspersky's 2026 SMB Threat Report highlights a sharp rise in malware disguised as popular AI tools.

Between January and April 2026, researchers detected more than 33,000 attacks using fake versions of:

  • ChatGPT
  • DeepSeek
  • Grok
  • Claude
  • Gemini

This represents:

  • Nearly 5× more attacks than the same period last year.
  • A 39% increase over malware impersonating traditional office and collaboration software.
  • More than 1,100 unique malware samples, a 21% year-over-year increase.

The report also notes:

  • Over 414,000 attacks used fake messaging and communication apps.
  • Phishing campaigns increasingly impersonate OneDrive, Facebook, Zoom, and Apple.
  • More than half of dark web listings offering corporate network access now target small and medium-sized businesses.
  • Supply chain and trusted-partner attacks continue to increase.

Recommendations

  • Download AI software only from official sources.
  • Train employees to recognize phishing attempts.
  • Enable multi-factor authentication (MFA).
  • Keep endpoint protection updated.

 


AI-Driven Phishing Continues to Grow

 

Artificial intelligence is making phishing attacks significantly more convincing.

Cybercriminals are now using AI to create:

  • Personalized phishing emails
  • Convincing fake websites
  • Deepfake voice calls
  • Fake video messages

Unlike traditional phishing emails, these messages often contain no obvious spelling or grammar mistakes, making them much harder to identify.

Best Practices

  • Verify unexpected requests involving payments, passwords, or sensitive information.
  • Confirm unusual requests through a separate communication method, such as a phone call.
  • Enable multi-factor authentication across all accounts.
  • Continue regular employee security awareness training.

As AI-generated phishing becomes more sophisticated, user awareness remains one of the strongest defenses against these attacks.


 

Threat Report 6/12/26

Threat Report 6/12/26

Critical Security Patches Released for Microsoft Products Microsoft has released security updates addressing multiple vulnerabilities across its...

Read More
Threat Report 1/26/26

1 min read

Threat Report 1/26/26

Microsoft Product Vulnerabilities Multiple security vulnerabilities have been identified across Microsoft products. The most critical issues could...

Read More
Threat Report 3/10/26

1 min read

Threat Report 3/10/26

Multiple Vulnerabilities in Google Android OS Could Allow Remote Code Execution Multiple vulnerabilities have been identified in the Google Android...

Read More