
Daily Cybersecurity News - June 27, 2026
CISA Sets Urgent Deadline to Fix Cisco Flaw
CISA just gave federal agencies until Sunday to patch a Cisco flaw already under active attack.
The vulnerability sits in Cisco Unified Communications Manager Server. Attackers exploit an unauthenticated SSRF flaw that can write files to the system and later be used to elevate privileges to root. Actively exploited and now tracked on CISA KEV.
Affects enterprise VoIP and collaboration deployments running the affected Cisco versions. Federal agencies face the hard deadline, but any exposed install should be reviewed.
Defused observed exploitation last weekend, and CISA added the flaw to KEV with a June 28 deadline.
Linux Pedit COW Flaw Gives Root
Linux kernel flaw lets any local user grab root by poisoning cached binaries.
CVE-2026-46331 is an out-of-bounds write in the act_pedit traffic control code. It corrupts shared page cache memory so a setuid binary like su loads attacker data on next exec. CVSS 7.8 and public PoC available.
Affects kernels since 5.10 across major distros including Ubuntu, Debian, and RHEL. Highest risk is on systems where local users are not fully trusted, including multi-tenant servers, CI/CD runners, Kubernetes nodes, build workers, and shared lab machines.
Public working exploit appeared days after disclosure.
Amazon Q Developer Flaw Lets Malicious Repos Run Code
A flaw in Amazon Q Developer lets a malicious repo run commands and grab developer cloud credentials after a single workspace trust click.
CVE-2026-12957 scores CVSS 8.5. The path is short. Open the repo, trust the workspace, and Amazon Q executes the attacker's MCP config.
Affects developers using Amazon Q inside VS Code or JetBrains with untrusted or cloned repositories. Amazon has released a patch.
Public PoC appeared within days of disclosure.
Polymarket Loses 3 Million In Supply Chain Hit
Polymarket customers lost an estimated 3 million after attackers compromised a third party vendor and pushed a malicious script into the betting platform frontend.
The vendor breach let attackers inject code that stole funds directly from user wallets. Polymarket confirmed the incident and said it will reimburse affected customers in full.
Supply chain compromises through small vendors keep hitting crypto platforms. The attackers focused on the frontend rather than backend servers.
Polymarket said it contained the incident and removed the affected dependency, but it has not shared detailed timing for how long the malicious script was active.
Pentagon Probes Dialog Breach Unmasking Officials
A data exposure at Dialog, a private events group, exposed personal information and login tokens for US and allied national security figures.
The Pentagon opened a review after records surfaced showing a senior White House intelligence official and an active duty special operations officer.
The exposure happened through a private group whose data ended up online. The incident highlights how commercial chat platforms can surface cleared personnel.
WIRED said the exposure appears to have come from a misconfigured Dialog website, not a confirmed prior breach.
FBI Warns Russian Hackers Target Signal Backups
Russian state hackers tied to intelligence services are now phishing Signal users for their backup recovery keys.
The campaign started as credential theft against Russian targets but shifted to stealing recovery keys. This lets attackers decrypt and read historical encrypted messages stored in Signal backups.
The key angle is the move from basic phishing to targeting the backup mechanism itself, which reuses familiar social engineering but now exploits how Signal handles encrypted backups.
FBI and CISA issued the alert after observing the tactic against multiple victims linked to Russian services.