Isometric network nodes depicting widespread cybersecurity flaws.

Daily Cybersecurity News - June 25, 2026

PixelSmash flaw turns video files into attack tools

A critical FFmpeg bug lets attackers turn a small video file into a remote code execution vector on systems that process it.

CVE-2026-8461 is a heap out-of-bounds write in the MagicYUV decoder inside libavcodec. CVSS 8.8, researchers turned the crash into reliable RCE with a crafted media file.

Affects FFmpeg versions before 8.1.2. Hits any app using the decoder for thumbnails, playback or metadata on Linux desktops, Jellyfin, Nextcloud, NAS devices and media servers.

Researchers escalated a simple crash to full remote code execution using just one malicious 50 KB file.

Source: Malwarebytes

Mandiant Reveals Cisco SD WAN Zero Day Root Access

Attackers exploited Cisco Catalyst SD-WAN Manager as a zero-day to escalate from a compromised administrative account to root-level access.

CVE-2026-20245 was used in the wild before public disclosure. Attackers abused an authenticated/local command-injection flaw after gaining access, likely through rogue peering or stolen certificate material.

The flaw affected Cisco Catalyst SD WAN deployments running vulnerable firmware versions across enterprise networks.

Mandiant tracked the activity against SD-WAN infrastructure at a service provider, but the exact initial access path and actor continuity remain unclear.

CISA Warns Ubiquiti Flaws Exploited

CISA added three critical Ubiquiti UniFi OS bugs to its Known Exploited Vulnerabilities list after seeing active attacks.

CVE-2026-34908 lets unauthenticated attackers bypass access controls and reconfigure systems. CVE-2026-34909 and CVE-2026-34910 add path traversal and command injection, chaining for unauth root on UniFi OS.

UniFi OS versions before 5.0.8 are exposed, plus Lantronix EDS5000 servers on firmware 2.1.0.0R3 via a separate root command injection.

Bishop Fox released a detection script on GitHub after chaining the three flaws for full remote root.

macOS Flaw Lets Standard Users Disable EDR and MDM

A macOS XPC flaw lets any standard user knock out endpoint detection and mobile device management tools.

The technique chains weakly validated XPC connections, NIB injection, and macOS trust-cache behavior to impersonate trusted app components and disable security tools.

Affects macOS versions from Ventura through the latest Sequoia release. Breaks EDR agents and MDM enrollment on managed laptops.

XM Cyber plans to release an open-source discovery tool called XPC Hunter at Black Hat US in August 2026.

Malicious Edge Extension Abuses Native Messaging

A malicious Microsoft Edge extension called Edgecution is breaking out of the browser sandbox to drop ransomware and a Python backdoor.

It abuses Native Messaging to launch a helper process outside the sandbox. The helper then executes the Python payload and maintains access.

Native Messaging bridges are familiar but rarely weaponized this way for full sandbox escape in a browser extension. Most campaigns still rely on traditional downloaders or malicious documents.

The campaign has appeared in recent attacks tied to ransomware initial access activity.

New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI Assisted Analysis

A new Rust based macOS implant called Gaslight steals data and tries to sabotage AI analysis tools.

It embeds a prompt injection payload directly in the binary. The payload is crafted to make analyst AI tools abort or refuse the job when they scan the sample.

The trick is novel for macOS malware. Most implants still focus on stealth and data theft rather than attacking the analysis pipeline itself.

SentinelOne analyzed a macOS.Gaslight sample uploaded to VirusTotal on June 23, 2026, and assessed it with high confidence as North Korea-aligned.

When Information Becomes the Attack Surface

Attackers now poison data sources that AI agents read to hijack decisions.

The article describes hidden content injections and cognitive state poisoning that turn trusted feeds into traps for autonomous systems. No survey numbers or vendor funding details appear in the piece.

The framing stays conceptual. It offers no independent dataset or year-over-year comparison to judge whether these attacks are rising in practice.

The piece is an opinion-style analysis rather than a data-driven report.

Source: SecurityWeek