Data pipelines depicting widespread cyber vulnerabilities and data breaches.

Daily Cybersecurity News - June 26, 2026

MCP Auto Execution From Git Clone to Cloud Compromise

Amazon Q in VS Code pulled config files from cloned repos and ran MCP servers automatically.

Attackers planted a malicious MCP server config in a public repo. After a developer opened the cloned folder in VS Code and activated Amazon Q, the vulnerable extension could auto-load the malicious MCP config and run it with access to credentials loaded in the developer environment.

Users on vulnerable Amazon Q Developer versions were exposed if they opened an untrusted workspace containing a malicious MCP config before the AWS fix.

Wiz researchers demonstrated the full chain in under 30 seconds from clone to credential access.

Source: Wiz Blog

Attackers Weaponize Cisco CUCM Flaw in 24 Hours

Attackers weaponized a Cisco Unified Communications Manager flaw within 24 hours of public PoC and exploit-chain release.

The bug allows unauthenticated SSRF on systems where WebDialer is enabled, and the public exploit chain can turn that into file write, remote code execution, and eventual root access. Public proof-of-concept code appeared fast.

Impacts Cisco Unified CM and Unified CM SME in enterprise voice setups running recent versions.

Proof-of-concept surfaced on GitHub less than 24 hours after the advisory.

Source: Dark Reading

First Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild

Attackers have started exploiting a remote code execution flaw in PTC Windchill, a widely used PLM platform.

CVE-2026-12569 carries CVSS 9.8 and sits on CISA's Known Exploited Vulnerabilities list. The bug lets unauthenticated remote users run arbitrary commands on the server.

Windchill deployments in manufacturing and engineering firms are now exposed. CISA flagged the issue after real-world exploitation attempts surfaced.

This marks the first confirmed in-the-wild activity against this specific vulnerability.

Source: SecurityWeek

One Million Passports Leaked Online

Nearly one million passport and ID images were exposed online through systems tied to cannabis dispensary identity checks.

The passports came from an ID check system used by cannabis dispensaries. A low-value verification service stored and processed the high-value documents.

The real problem was poor design. High-value credentials sat in an ancillary system never meant to protect them.

The leak surfaced two months ago and notifications have not reached affected individuals.

Malware Hijacks Chrome Sessions Via Extension

A phishing campaign pushes a malicious Chrome extension that grabs session cookies and hands attackers full account access.

Targets receive an email attachment disguised as a PDF. The malware then installs a Chrome extension through policy changes and steals active browser session data.

The extension approach sidesteps password managers and two-factor prompts by riding existing sessions directly.

Campaign has hit several hundred users across multiple regions since early June.

Source: Malwarebytes

Russian APT Deploys StockStay Backdoor Against Ukrainian Targets

Turla is using a fresh backdoor called StockStay against Ukrainian government and military targets.

GTIG observed phishing and lure infrastructure, including compromised accounts, malicious RDP files, and downloader components used to deploy STOCKSTAY and related payloads.

The group has run similar espionage operations for years, but this backdoor adds a new tool to their kit.

GTIG says STOCKSTAY has been developed and deployed by Turla since at least December 2022, with significant observed targeting of Ukrainian government and military organizations.

Source: SecurityWeek

Poland Busts SIM Swapping Gang Tied To Crypto Theft

Polish police arrested four people running a SIM swapping crew that stole millions in crypto.

The group compromised telecom partners and hijacked email accounts to take over phone numbers. They targeted cryptocurrency holders and drained wallets.

This hits low-level operators who execute the swaps. The organizers who supply the targets and move the funds are likely untouched.

The crew worked with telecom insiders who gave them access to customer data.