This briefing covers critical cybersecurity developments from June 28-29, 2026. The period saw significant data breach activity affecting over 18 million individuals across multiple sectors. The KDDI telecommunications breach exposed up to 14.2 million email credentials across six Japanese ISPs, representing the largest incident. AssuranceAmerica's breach impacted 1.1 million people across seven US states, while Sysco experienced a ShinyHunters extortion campaign exposing 2.7 million records. Multiple ransomware groups including Redact and cmdorganization claimed high-profile victims in healthcare and insurance sectors.
Vulnerability disclosures included 14 new CVEs, with one critical-severity flaw (CVE-2026-58053) in Gitea's act_runner allowing container escape through Docker backend manipulation. High-severity vulnerabilities affected widely-used components including libssh2, FFmpeg, and multiple web applications with SQL injection flaws. The threat landscape remained active with 50 malware distribution URLs identified, predominantly delivering Mozi and Mirai IoT botnets alongside ClearFake campaigns and ConnectWise RAT deployments.
Organizations should prioritize credential rotation for affected KDDI users, patch critical container security vulnerabilities, and monitor for Mozi/Mirai botnet activity targeting IoT devices. The concentration of SQL injection vulnerabilities in web applications underscores the need for secure coding practices and input validation.
Multiple significant data breaches exposed over 18 million records, including large-scale credential leaks and ransomware victim disclosures
Japanese telecommunications operator KDDI disclosed a breach affecting up to 14.22 million email addresses and passwords across six ISPs. Attackers gained unauthorized access to a shared email system on June 17, 2026. Exposed data includes email addresses and passwords for ISP mail services.
Food distribution company Sysco targeted by ShinyHunters extortion group with 2.69 million unique email addresses exposed. Data includes corporate contact information: names, phone numbers, physical addresses, job titles, employers, and customer feedback. Mix of staff and customer records compromised.
Data breach affecting over 1.1 million individuals across California, Massachusetts, Nebraska, South Carolina, Texas, Vermont, and Washington. State officials issued breach notifications to affected residents. Specific data classes not yet disclosed.
Medical supplies company with $4B USD revenue claimed as victim by Redact ransomware group. Healthcare sector impact with potential exposure of sensitive medical supply chain data.
Insurance sector organization compromised by Redact ransomware group. Potential exposure of policyholder and claims data.
Security solutions provider compromised by cmdorganization ransomware group. Ironic targeting of a security company highlights insider threats to the security industry itself.
Wellington-based pharmacy experienced data leak exposing 29 patients' private messages on its website. Organization scrambled to scrub sensitive patient information from internet. Incident attributed to website error affecting message handling.
14 new CVE disclosures including one critical-severity container escape vulnerability and multiple high-severity flaws in widely-used software
Critical vulnerability in Gitea act_runner with Docker backend (through act 0.262.0) allows container escape. System passes workflow container.options string to Docker HostConfig and only forces Privileged flag off when configured with privileged: false, while allowing dangerous options like --pid=host, --cap-add, and --security-opt to merge through. Enables full container breakout.
Zephyr's IP socket recvmsg() implementation fails to properly validate user-supplied ancillary buffer before writing control messages. Function validates only payload length before writing full aligned cmsg header and payload, enabling buffer overflow condition in socket operations.
FFmpeg's RASC video decoder performs 32-bit reads/writes at row cursor before boundary check and validates DLTA region in pixel rather than byte units. On PAL8 frames, DLTA runs can access several bytes past row allocation. Crafted video files can trigger memory corruption.
WordPress Frontend File Manager Plugin (up to version 23.6) vulnerable to authenticated arbitrary file deletion. Case-sensitive bypass of wpfm_dir_path parameter sanitization in wpfm_file_meta_update AJAX handler allows supplying WPFM_DIR_PATH to circumvent security checks and delete arbitrary files.
RustDesk gates incoming control messages on per-capability flags rather than session's authorized connection type. File-transfer sessions don't clear capability flags, allowing peer with only FileTransfer authorization to inject keyboard/mouse input and access screen-sharing functionalities.
Zephyr's BSD-sockets getaddrinfo() implementation passes pointer to stack-allocated state object as user_data of asynchronous DNS resolver query. Socket layer waits on semaphore with deliberate timeout, creating use-after-free condition when DNS query completes after timeout.
Vulnerability in antlr ANTLR4 up to 4.13.2 affecting Grammar Action Block Handler in OutputFile.java. Remote attackers can manipulate the component to achieve code injection through crafted grammar files.
libssh2 through 1.11.1 reads attacker-controlled 32-bit attribute count from publickey-subsystem response and uses it in allocation calculation without bounds checking. On 32-bit platforms, multiplication overflows to undersized buffer enabling heap corruption by malicious SSH servers.
Six SQL injection vulnerabilities disclosed: CVE-2026-13498 (restaurent-management-system /forgotpassword.php), CVE-2026-13488, CVE-2026-13487, CVE-2026-13486, CVE-2026-13485 (SourceCodester Class and Exam Timetabling System multiple endpoints). All remotely exploitable with public exploits available, CVSS 7.3.
MyBB 1.8.40 doesn't restrict which usergroup a limited Admin Control Panel user may assign when creating/editing users. User module offers Administrators group (gid 4) and datahandler's verify_usergroup() unconditionally returns true. Admin with only delegated user-management can create administrator accounts.
50 malicious URLs identified distributing IoT botnets, remote access tools, and fake update campaigns
Extensive Mozi botnet distribution campaign identified with over 35 malicious URLs serving ELF binaries targeting MIPS and ARM IoT devices. Majority hosted on compromised Asian ISP infrastructure. Mozi continues as persistent IoT threat despite 2021 disruption attempts.
Multiple URLs distributing Mirai variants alongside Mozi, indicating co-infection or infrastructure reuse. ARM and MIPS ELF binaries targeting IoT devices. Example: http://105.187.27.99:47889/i serving Mirai payloads.
Multiple HTTPS URLs distributing ScreenConnect client setup executables from suspicious infrastructure: 64.89.161.150, 193.202.84.59, 193.202.84.58. Likely legitimate remote access tool being abused for unauthorized access or deployed via social engineering.
Four URLs identified distributing ClearFake malware through typosquatted domains (jarayemaleyhamval.xyz, 1xboropartners.com, iranfitness.top, 1xfa.bio). ClearFake typically uses fake browser update prompts to deliver malware payloads.
Three URLs on 91.92.242.236 distributing executables dropped by Amadey loader (files-129312398 directory). Amadey is commodity malware typically used for initial access and loading additional payloads.
PowerShell script (Troubleshoot.ps1) hosted at 199.217.98.86 identified as dropper/loader. PowerShell-based attacks remain prevalent for initial access and payload delivery.
Multiple ransomware groups and extortion actors demonstrated continued operations against corporate targets
ShinyHunters group conducted 'pay or leak' extortion campaign against Sysco, subsequently publishing 2.7M records when demands weren't met. Group continues pattern of corporate data theft and public leak threats to pressure victims into payment.
Redact ransomware group claimed two high-value victims: Hologic ($4B medical supplies) and FCCI Insurance Group. Demonstrates continued targeting of healthcare and financial sectors with high-impact victims.
cmdorganization ransomware group compromised Fidelity Security Group, a security solutions provider. Targeting of security companies represents both intelligence gathering opportunity and embarrassment tactic.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.