Issue #204 - June 22, 2026
- Jun 22
- 2 min read
CISA warns of max severity Ubiquiti flaws exploited in attacks
Source: BleepingComputer
CISA warned that attackers are actively exploiting critical Ubiquiti UniFi OS flaws and Lantronix serial-to-ethernet server vulnerabilities. The directive gives federal agencies only three days to apply fixes or mitigations, underscoring how exposed edge and network management systems remain high-value targets for fast-moving exploitation.
More Malicious OpenClaw Skills Threaten AI Supply Chain
Source: Dark Reading
Researchers found five malicious skills in OpenClaw’s ClawHub marketplace that could steal credentials, evade scanning, exfiltrate files, or manipulate agent behavior. The report highlights a growing AI supply chain risk: third-party agent extensions often receive broad local and service access while appearing like ordinary productivity add-ons.
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
Source: The Hacker News
A new backdoor called Mistic, also tracked as MLTBackdoor, has appeared in financially motivated campaigns targeting insurance, education, IT, and professional services organizations. Researchers linked the activity to the KongTuke initial access broker and observed Mistic being dropped alongside ModeloRAT in ClickFix-style attack chains.
Slow OT Patching a Boon for Iranian Nation-State Hackers
Source: Data Breach Today
Researchers warned that Iranian nation-state hackers are exploiting slow operational technology patching, including exposed Barix audio infrastructure used in emergency warning and public address systems. The story reinforces a recurring OT problem: internet-facing devices often remain difficult to update, poorly inventoried, and attractive for psychological disruption.
Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware
Source: SecurityWeek
Microsoft, law enforcement, and cybersecurity partners disrupted shared infrastructure used by Amadey and StealC, two malware families that support credential theft and follow-on compromise. The operation targeted hundreds of domains and servers, seized millions of stolen credentials, and focused on the broader “cybercrime assembly line” rather than one isolated tool.



