Home  /  Episodes  /  Jun 29, 2026

Episode show notes

Jun 29's Top Cyber News NOW! - Ep 1163

Aired Jun 29, 2026 Daily Cyber Threat Brief Hosted by Dr. Gerald Auger

At a glance

CISA issued an urgent patch deadline for an actively exploited Cisco flaw, while researchers disclosed multiple vulnerabilities in AI coding tools that allow attackers to steal cloud credentials and execute malware through seemingly benign repositories. The week also brought warnings about Russian phishing targeting Ukrainian officials and new FCC cybersecurity rules for emergency systems.

Stories covered

How urgent is CISA's deadline to patch the exploited Cisco flaw?

What happened: CISA ordered federal agencies to patch a server-side request forgery vulnerability in Cisco Unified Communications Manager by June 28th. The vulnerability has been actively exploited in the wild since Cisco released a patch on June 3rd.

Why it matters: SSRF vulnerabilities typically affect web admin interfaces and can be exploited remotely without authentication if the system is Internet-facing. Three weeks between patch availability and enforcement suggests many agencies are still vulnerable to active exploitation.

What to do: Prioritize patching Cisco Unified Communications Manager immediately in your environment. Review OWASP Top 10 guidance on server-side request forgery if managing web applications.

Does China really have a Mythos-equivalent AI bug-finding tool?

What happened: Chinese cybersecurity vendor Qihoo 360 claimed at its 14th annual Beijing Cybersecurity Conference to have developed an AI capable of finding vulnerabilities comparable to Anthropic's Mythos, using what it calls a "multi-agent swarm" approach called Xuan Wu Fang.

Why it matters: This represents positioning in an AI arms race for vulnerability discovery and exploit development. However, the claim is almost certainly post-hoc marketing—a company operating for 14 years with 20 years of threat data would not develop such a tool in response to a recent Mythos ban; development almost certainly predated the U.S. restrictions.

What to do: Monitor for now. The broader trend is that AI-powered vulnerability discovery and exploit generation will continue to accelerate across multiple nation-states and private entities.

Can cloud credentials be stolen through Amazon Q's Visual Studio Code extension?

What happened: Wiz researchers disclosed a high-severity vulnerability in Amazon Q's VS Code extension where the tool would automatically execute configuration files from cloned repositories without user permission, allowing malicious code to access environment variables, API keys, and local config files.

Why it matters: AWS patched this on May 12th after learning of it April 20th, but the underlying risk remains endemic: AI coding assistants cannot distinguish between legitimate and malicious software instructions. Developers allowing AI to operate with their full permission set and credentials creates a direct path to compromise.

What to do: If using Amazon Q or similar AI coding agents, stay actively involved in what they execute. Review cloned repositories manually before letting agents run setup scripts. Consider restricting AI tooling's access to sensitive credential environments.

How are agentic coding tools tricked into running malware from GitHub?

What happened: Mozilla's zero-day investigative network demonstrated how attackers can craft benign-looking GitHub repositories that execute malicious payloads when cloned and set up by AI agents, remaining invisible to security scanners and reviewers. The attack uses DNS over C2 to retrieve attacker-controlled commands.

Why it matters: This is a continuation of the Amazon Q vulnerability pattern—AI agents executing instructions without human verification. The attack spreads malicious logic across multiple steps to evade AI detection of relationships between components, mirroring supply-chain attack techniques used in SolarWinds and LastPass breaches.

What to do: Implement detection for DNS-based C2 in your SIM; C2 via DNS is notably obvious when examined. Educate development teams about this attack vector. Consider application allow-listing and LNK file execution restrictions via GPO on developer machines.

What did the FCC decide about cybersecurity for emergency alert systems?

What happened: The FCC approved new cybersecurity rules on Thursday to strengthen protection of the Emergency Alert System (EAS) and Wireless Emergency Alerts (WEA), as well as undersea cable security standards.

Why it matters: A compromise of EAS/WEA systems could be weaponized to broadcast false alerts, sow disinformation, or disable critical emergency communications during genuine crises. The CIA triad applies directly: availability (disabling alerts), confidentiality (less of a concern), and integrity (spoofing alerts with false information) are all realistic attack vectors that could cause mass panic or prevent coordinated emergency response.

What to do: Monitor for rulemaking details. If your organization is involved in emergency broadcast infrastructure, ensure threat modeling exercises specifically address alert system integrity and the impact of false messaging.

How are Russian intelligence services targeting Ukrainian officials via SMS?

What happened: Ukraine's SSU and the FBI jointly disclosed a long-running campaign where Russian intelligence services send SMS messages impersonating messaging platform support bots, prompting Ukrainian government officials, military personnel, politicians, and activists to disclose account credentials.

Why it matters: This is a successful, low-tech attack against high-value targets despite years of active conflict. The persistence of social engineering against executives suggests inadequate security awareness and GRC enforcement at senior organizational levels.

What to do: Implement mandatory credential-disclosure verification procedures: anyone claiming to be support should be verified through official channels via phone call. Deploy SMS filtering and phishing awareness training with particular focus on C-suite and military/government personnel.

Why is a Russian dairy company's attack noteworthy?

What happened: Ufa Gormolzavod, a dairy producer in Bashkortostan, was hit by what appears to be a LockBit ransomware variant, forcing the company to revert to pen-and-paper operations.

Why it matters: LockBit is a Russian-operated ransomware gang; attacks on Russian businesses by Russian threat actors are atypical and suggest either operational error or financial desperation. This indicates the threat actor may be broadening targets beyond usual scope.

What to do: Conduct tabletop exercises to test your organization's ability to operate on manual processes if IT systems are unavailable. Ensure backup and recovery procedures exist and are regularly tested, regardless of sector.

How is hospitality being targeted via fake guest complaints through Calendly?

What happened: Microsoft threat intelligence reported a campaign running since April targeting the hospitality sector with phishing emails masquerading as guest complaints (mentioning bed bugs, etc.) sent through Calendly. The emails contain links to LNK files disguised as images that execute PowerShell and deploy Ton rat malware.

Why it matters: Hospitality staff (reception, front desk, reservations) are conditioned to respond urgently to guest complaints, making them high-probability targets. The attack uses file masquerading, multi-stage obfuscation, and geolocation/bot-detection evasion to bypass typical defenses.

What to do: If in hospitality, harden reception and front-desk endpoints—disable LNK file execution via GPO, implement application allow-listing, and restrict PowerShell execution. Train staff to verify complaints via phone before clicking links. Block or sandbox Calendly redirects if not business-critical.

Key takeaways

  • AI coding assistants cannot distinguish malware from legitimate code; they execute instructions as given. Stay actively involved in what AI agents deploy with your credentials and permissions.
  • Low-tech social engineering (SMS phishing, fake guest complaints) continues to work at scale against high-value targets because awareness training and credential verification procedures are inconsistently enforced.
  • Ransomware and supply-chain attacks against critical infrastructure (communications systems, emergency alerts, manufacturing) remain high-impact; tabletop exercises and manual operation fallbacks are essential.
  • Patch management timelines matter: three weeks between patch release and enforcement deadline suggests real-world delays and ongoing exploitation windows.
  • Emergency broadcast system integrity is a CIA-triad problem with severe consequences; false alert injection or availability loss could cause mass panic or prevent coordination during genuine crises.

Topics covered

cisco CVE SSRF, Amazon Q credentials theft, AI coding security, GitHub malware, Calendly phishing, Russian intelligence SMS, emergency alert systems, ransomware, supply chain attacks, vulnerability management, AI agents, threat modeling, endpoint hardening

Show notes generated from the live transcript using AI on Wed, 08 Jul 2026 16:08:50 GMT. Errors? Open the YouTube replay for the source of truth.

Want the live experience? The Daily Cyber Threat Brief airs live every weekday at 5am PT / 8am ET on YouTube. 400+ practitioners join the chat in real time.