
Daily Cybersecurity News - June 24, 2026
Cisco SD-WAN Zero-Day Roots the Manager
Attackers are hitting Cisco Catalyst SD-WAN Manager with a zero-day that turns a normal admin session into full root access.
CVE-2026-20245 lives in the CLI file upload path. An authenticated user uploads a crafted CSV and the manager runs it as root, letting the attacker create a new root account. CVSS 7.8, actively exploited with no patch available yet.
The flaw affects Catalyst SD-WAN Manager, Controller, and Validator deployments at service providers and large enterprises running the control plane.
Cisco credited Mandiant with reporting the flaw, but public reports do not detail the exact exploitation steps. Earlier Cisco SD-WAN intrusions used rogue peering to gain trusted access before root-level follow-on activity.
CISA Adds Ubiquiti and Lantronix Flaws to KEV
CISA just added four high-severity bugs in Ubiquiti UniFi OS and Lantronix EDS5000 devices to its Known Exploited Vulnerabilities catalog.
CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 are CVSS 10 flaws in UniFi OS that chain into unauthenticated remote code execution. CVE-2025-67038 is a command injection issue in Lantronix servers rated CVSS 9.8. All four are on CISA KEV.
UniFi OS runs on Ubiquiti gateways and controllers used in homes, offices, and small MSP deployments. Lantronix EDS5000 devices appear in industrial serial-to-Ethernet setups.
UniFi patches shipped in May as part of Security Advisory Bulletin 064.
Scope of Salesforce Attacks Expands as Icarus Leaks Data
Attackers breached Klue, a market intelligence platform, and stole OAuth tokens that let them pull customer data from Salesforce.
The Icarus group claims responsibility after using the tokens to query Salesforce APIs and grab business contacts, sales notes, and pricing details from multiple victims.
Klue was an integration point rather than the final target, and the activity resembles earlier Salesforce-related OAuth abuse patterns, but Huntress said there is no clear link between Icarus and previous Salesforce incidents.
Icarus listed Huntress and several other firms on its leak site by June 22.
How Hackers Broke into Madison Square Garden
Hackers stole more than 45GB of data from Madison Square Garden, including talent files and Knicks information.
404 Media reported that clues in the stolen data point to vishing against a low-level employee’s Microsoft Entra account.
The breach stayed quiet until the data surfaced elsewhere, revealing operational details the company never disclosed.
The files include internal chat logs and booking records from multiple venues.
Embedding Forbidden Text in Spyware to Discourage AI Analysis
A malware developer is stuffing spyware with nuclear and biological weapons talk to block automated AI scanning.
The index.js payload opens with a big JavaScript block comment. It contains fake system instructions and policy-triggering content that trips AI content filters.
This is novel. Most malware avoids drawing extra attention, yet this crew deliberately plants red-flag text to exploit safety layers in analysis tools.
The technique targets JavaScript-based droppers and has shown up in multiple recent samples.
New macOS ClickFix Attack Silently Mounts DMGs
Attackers are running a fresh macOS ClickFix campaign that tricks users into pasting Terminal commands.
The commands silently download, mount, and execute DMG files that drop an infostealer. No user interaction beyond the initial copy-paste is needed once the command runs.
ClickFix attacks involving DMGs are not new, but this campaign combines Terminal copy-paste commands with quiet DMG download, mounting, and launch. Earlier variants relied on direct script execution or file downloads without the disk image layer.
Active since at least early June 2026 with multiple distinct DMG samples observed in the wild.
Fake AI Agent Skill Passed Security Scans
A fake AI agent skill reportedly cleared every tested scanner and allegedly reached roughly 26,000 agents.
Security firm AIR built the skill, ran it through a popular marketplace plus an Instagram ad, and noted it hit some corporate accounts. Every scanner tested marked the payload safe. The payload stayed harmless by design.
This shows current AI agent marketplaces rely on scanners that miss obvious fakes when the code does nothing malicious on install.
The test used one harmless skill uploaded once.