Cyber Risk Brief: 29 June 2026
Disclaimer:This brief is governance commentary for leadership and risk teams, not incident notification, public attribution, legal advice, or quantitative risk analysis. Threat prioritization, framework mappings, attribution, and risk-zone groupings are informational only. Validate all technical claims against vendor advisories and internal telemetry before operational response.
Threat Intelligence Summary
This week's register splits between the patch clock and the breach ledger. Three actively-exploited KEV flaws lead it, each with a federal deadline already passed: Lantronix EDS5000 OT command injection (T1), PTC Windchill PLM web shells (T2), and three CVSS 10.0 Ubiquiti UniFi OS flaws (T3). Four confirmed breaches follow — 3.08M identity records at a Texas vendor (T4), 1.4M health records at Xsolis (T5), the widening Klue/Icarus OAuth supply-chain breach now spanning two dozen enterprises (T6), and a Canadian utility breach at London Hydro (T7). A patched Amazon Q developer-tool credential-theft flaw (T8) closes the register on the AI-tooling governance question. What connects them: in every case the time from disclosure to exploitation, or from vendor to victim, was shorter than the controls assumed.
Threat Register: 29/06/2026
| Threat | |||||
|---|---|---|---|---|---|
| T1 | Lantronix EDS5000 Unauthenticated OS Command Injection (CVE-2025-67038) A network attacker can take full root control of a Lantronix EDS5000 serial-to-IP device server with no credentials — CVE-2025-67038 injects OS commands through the username field of the failed-authentication handler. Forescout observed exploitation against honeypots from April 5, 2026, before public technical disclosure. CISA added it to KEV on June 23 with a June 26 federal deadline, now passed. The fixed firmware version is not stated in vendor reporting. | 9.8 | 1.13% | Critical | Immediate |
| T2 | PTC Windchill & FlexPLM RCE with Web-Shell Persistence (CVE-2026-12569) Attackers are implanting persistent web shells in PTC Windchill and FlexPLM systems through CVE-2026-12569, an unauthenticated deserialization flaw enabling remote code execution. PTC confirmed ongoing exploitation and published indicators including a JSP web-shell pattern and attacker command-and-control address. This is the first PTC vulnerability CISA has ever added to KEV; the June 28 federal deadline has passed. NVD scores it 9.3 (CVSS 4.0) and 9.8 (CVSS 3.1). | 9.3 | 1.11% | Critical | Immediate |
| T3 | Ubiquiti UniFi OS Critical Vulnerabilities (CVE-2026-34908 / 34909 / 34910) Three maximum-severity UniFi OS flaws — CVE-2026-34908, 34909, and 34910, each CVSS 10.0 — let an unauthenticated network attacker make system changes, traverse the filesystem, and inject commands on UniFi OS Server. Users reported exploitation creating rogue “John Sim” administrator accounts before patches existed. CISA added all three to KEV on June 23 with a June 26 deadline, now passed. The command-injection flaw carries a 78.55% EPSS exploitation-probability score. | 10.0 | 78.55% | Critical | Immediate |
| T4 | Texas Parks and Wildlife Department Vendor Data Breach (3,087,721 Records) 3,087,721 Texas hunting and fishing license holders had driver's licenses, passport numbers, and contact details exposed through a breach of an unnamed third-party vendor contracted by the Texas Parks and Wildlife Department. Texas Cyber Command discovered the unauthorized access; TPWD disclosed it June 18, 2026. Social Security numbers, dates of birth, and financial data were not obtained. Attack method, entry date, and access duration remain under investigation. | — | — | High | Post-incident |
| T5 | Xsolis Data Breach (1,396,519 Individuals) 1,396,519 individuals had Social Security numbers, dates of birth, health-insurance details, and medical-treatment information exposed in a breach of Tennessee healthtech firm Xsolis. A targeted phishing attack on January 20, 2026 gave attackers system access detected two days later; Xsolis disclosed the breach in early June. The data belonged to Xsolis's hospital and payer clients. No group has claimed the attack, and Xsolis says it is unaware of misuse. | — | — | High | Post-incident |
| T6 | Klue/Icarus Salesforce OAuth Supply-Chain Breach The Icarus extortion group stole OAuth tokens that market-intelligence vendor Klue held for its customers and used them to reach those customers' Salesforce data — a breach that has now widened to LastPass, BeyondTrust, Recorded Future, Tanium, Jamf, Autodesk, Deel, and others, with roughly two dozen firms publicly confirming impact and 195 alleged. Access traced to compromised legacy credentials for an integration service. Salesforce disabled Klue's integration on June 17. In a further turn, Icarus was itself breached and the stolen data re-extorted by a second actor. | — | — | High | Post-incident |
| T7 | London Hydro Data Breach London Hydro, the electricity distributor for London, Ontario serving roughly 170,000 customers, disclosed on June 20, 2026 that attackers stole customer names, addresses, contact details, and account information. Financial data, dates of birth, government ID numbers, and banking details were not compromised. The number of affected individuals and the attack vector have not been disclosed, and no group has claimed responsibility. | — | — | High | Post-incident |
| T8 | Amazon Q Developer Trust-Boundary Code Execution & Credential Theft (CVE-2026-12957 / 12958) Opening a malicious repository in an IDE running Amazon Q Developer can silently execute code and steal a developer's cloud credentials and API keys — CVE-2026-12957 and CVE-2026-12958, found by Wiz. The extension auto-acted on workspace configuration files without permission, spawning shells that inherited the environment. AWS patched the flaws in language server 1.65.0 on May 12, 2026, with automatic updates. The vulnerabilities are local — they require a developer to open the malicious repository — and no in-the-wild exploitation has been reported. | 8.5 | < 1% | High | 7 days |
| Select a row for narrative, affected systems, remediation, and sources. | |||||
Strategic context
The exploit window is collapsing — months, not years
- On June 23 the Five Eyes — US, UK, Canada (CCCS), Australia, New Zealand — warned that frontier AI is compressing the time between vulnerability disclosure and exploitation to “months, not years.” This register is that warning made concrete: Lantronix was exploited weeks after its February patch (T1), PTC Windchill web shells were deployed before the KEV listing (T2), and an AI developer tool auto-executed untrusted code (T8).
- The alliance's prescription — faster patching, least privilege, secure-by-default, and AI-tooling governance — maps onto every threat above. For boards, the alert converts “patch faster” from best practice into a documented government expectation, and the external citation that justifies funding emergency-patch SLAs and AI-tooling governance now.
Threat Actor Profiling
Only T6 carries a named actor — the Icarus extortion group, whose own operation was subsequently breached. T1 is tracked as activity cluster Chaya_006 by Forescout; all other threats are unattributed per their sources. T8 is a research disclosure (Wiz) with no in-the-wild actor. MITRE technique codes are shown as hover-to-define abbreviations.
| Threats | Actor | Sectors | MITRE tradecraft | Kill chain |
|---|---|---|---|---|
| T1 | Unattributed OT-targeting actor (cluster Chaya_006, per Forescout) | Industrial / OT, Healthcare | T1190T1059.004 | Crafted request to the failed-auth handler with a command-injected username → shell executes payload as root → device control → lateral movement to serial-connected systems. |
| T2 | Unattributed PLM-targeting actor | Manufacturing, Aerospace & Defense | T1190T1505.003T1059T1041 | Deserialization payload to the Windchill login endpoint → RCE → JSP web shell dropped to /Windchill/login/ → persistent command execution → exfiltration over attacker C2. |
| T3 | Unattributed threat actor (automated reconnaissance, per SecurityWeek) | Network infrastructure | T1190T1059.004T1136.001 | Unauthenticated network request to UniFi OS Server → command injection / access-control bypass → rogue administrator account created → persistent control of the network-management plane. |
| T4 | Unattributed threat actor | Government, Public sector | T1213T1078 | Breach of the unnamed third-party licensing vendor (method undisclosed) → access to the customer-PII database → extraction of 3,087,721 records including government-issued identity data. |
| T5 | Unattributed threat actor | Healthcare | T1566T1078T1213 | Targeted phishing (Jan 20) → account access → unauthorized system activity (detected Jan 22) → collection of PHI/PII → exposure of 1,396,519 records. |
| T6 | Icarus (extortion group) — operation subsequently breached by a second actor | SaaS supply chain, Cross-sector enterprise | T1199T1528T1078.004T1530 | Compromise of Klue's legacy integration-service credentials → theft of customer OAuth tokens → authentication to customers' Salesforce → extraction of CRM/contact data → secondary theft and re-extortion after Icarus is itself breached. |
| T7 | Unattributed threat actor | Critical infrastructure / Utility | T1213 | Undisclosed intrusion into London Hydro's environment → access to the customer-account repository → extraction of customer names, contact details, and account information. Entry vector not disclosed in sources. |
| T8 | Unattributed (research disclosure by Wiz — no in-the-wild actor) | Software development, AI developer tooling | T1204.002T1059T1552 | Developer opens a malicious repository in an IDE with Amazon Q Developer < 1.65.0 → extension auto-acts on embedded configuration → shell spawned with inherited environment → cloud credentials and API keys captured. |
▶Table methodology & sourcing notes
- Actors are named only where a source attributes the incident; otherwise “unattributed.” T2 and T3 use the parent technique T1059 where the host OS is not specified in sources. T7 (London Hydro) maps a single collection technique because the attack vector was not disclosed — additional techniques would be inference, not evidence.
- All CVSS, EPSS, and KEV values were verified directly against NVD, the FIRST EPSS API, and the CISA KEV catalog (2026-06-27); they are not carried from secondary reporting.
Control Deficiency & Framework Mapping
| Threat | Control gaps | ISO 27001 | NIST CSF 2.0 | CIS Controls | Privacy Act / PIPEDA | ITSG-33 | OSFI B-13 | ISO 42001 |
|---|---|---|---|---|---|---|---|---|
T1Lantronix EDS5000 Unauthenticated OS Command Injection (CVE-2025-67038) |
| A.8.8, A.8.9, A.8.20, A.8.22, A.8.16 | ID.AM-01, ID.RA-01, PR.PS-01, PR.AA-05, DE.CM-09 | CIS 1, CIS 7, CIS 12, CIS 13 | — | SI-2, RA-5, CM-7, SC-7 | B-13 Patch Mgmt, B-13 Vulnerability Management | — |
T2PTC Windchill & FlexPLM RCE with Web-Shell Persistence (CVE-2026-12569) |
| A.8.8, A.8.9, A.8.16, A.8.20, A.8.25 | ID.AM-01, PR.PS-01, DE.CM-01, DE.AE-02, RS.CO-02 | CIS 7, CIS 10, CIS 13, CIS 16 | — | SI-2, RA-5, CM-7, SC-7 | B-13 Patch Mgmt, B-13 Vulnerability Management | — |
T3Ubiquiti UniFi OS Critical Vulnerabilities (CVE-2026-34908 / 34909 / 34910) |
| A.8.8, A.8.9, A.5.15, A.5.16, A.8.20 | ID.AM-01, PR.AA-01, PR.AA-05, DE.CM-01, DE.CM-09 | CIS 1, CIS 5, CIS 6, CIS 7 | — | SI-2, RA-5, AC-2, CM-7 | B-13 Patch Mgmt, B-13 Access Control | — |
T4Texas Parks and Wildlife Department Vendor Data Breach (3,087,721 Records) |
| A.5.19, A.5.20, A.5.34, A.8.11, A.8.12 | GV.SC-01, GV.SC-05, PR.AA-05, PR.DS-01, RS.CO-02 | CIS 3, CIS 5, CIS 6, CIS 15 | — | AC-2, AC-4, AU-6, SI-7 | B-13 Third-Party Risk, B-13 Governance, B-13 Access Control | — |
T5Xsolis Data Breach (1,396,519 Individuals) |
| A.5.17, A.6.3, A.8.5, A.5.34, A.8.16 | PR.AA-01, PR.AT-01, DE.CM-01, DE.AE-02, RS.CO-02 | CIS 6, CIS 14, CIS 13, CIS 3 | — | IA-2, IA-5, AC-2, AU-6 | B-13 Third-Party Risk, B-13 Access Control, B-13 Governance | — |
T6Klue/Icarus Salesforce OAuth Supply-Chain Breach |
| A.5.19, A.5.20, A.8.30, A.5.15, A.8.5 | GV.SC-01, GV.SC-05, ID.AM-01, PR.AA-05, DE.CM-01 | CIS 6, CIS 3, CIS 15, CIS 13 | Principle 4.7, Principle 4.1.3, PIPEDA s.10.1, if Canadian PI confirmed | AC-2, AC-4, AC-17, SA-12 | B-13 Third-Party Risk, B-13 Governance, B-13 Access Control | — |
T7London Hydro Data Breach |
| A.8.11, A.8.12, A.5.34, A.8.16, A.5.24 | ID.AM-01, PR.DS-01, DE.CM-01, DE.AE-02, RS.CO-02 | CIS 3, CIS 13, CIS 6, CIS 17 | Principle 4.7, PIPEDA s.10.1, if Canadian PI confirmed | AC-4, AU-6, SI-7, SC-7 | B-13 Governance, B-13 Access Control | — |
T8Amazon Q Developer Trust-Boundary Code Execution & Credential Theft (CVE-2026-12957 / 12958) |
| A.8.25, A.8.5, A.5.19, A.8.8, A.8.31 | ID.AM-02, PR.PS-01, PR.AA-05, ID.RA-01, GV.SC-05 | CIS 2, CIS 16, CIS 6, CIS 4 | — | CM-7, SI-2, AC-6, SA-12 | B-13 Third-Party Risk, B-13 Patch Mgmt | A.4.4, A.10.3, A.6.2.6 |
Privacy Act / PIPEDA & OSFI:T6 (Klue, Vancouver) and T7 (London Hydro, Ontario) carry PIPEDA relevance through Canadian commercial activity — but Klue's breached data is largely B2B contact information and London Hydro may also fall under a provincial regime (MFIPPA), so confirm against data-subject residency with privacy counsel before relying on either. T4 (Texas) and T5 (Xsolis) are US-jurisdiction with no PIPEDA obligation. OSFI B-13 patch, vulnerability, and third-party-risk expectations apply to federally regulated entities.
Risk Triage
Threats are assigned to primary zones based on their dominant organizational risk characteristic. A threat may appear in a secondary zone when it presents a materially distinct compounding risk dimension.
Active exploitation or weaponized capability with immediate organizational exposure if unaddressed.
- T1Lantronix EDS5000 — KEV deadline passed, active exploitation
CVE-2025-67038 is KEV-listed with a deadline now passed; Forescout confirmed exploitation against OT serial-to-IP converters from April 5. Patch and isolate exposed devices now.
- T2PTC Windchill — active web-shell deployment, KEV deadline passed
CVE-2026-12569 is the first PTC entry in KEV; PTC confirms ongoing web-shell deployment with published IoCs. Patch, then hunt for existing shells before declaring closure.
- T3Ubiquiti UniFi OS — three CVSS 10.0 flaws exploited as zero-days
CVE-2026-34908/34909/34910 are KEV-listed with the deadline passed; rogue admin accounts reported and 34910 carries a 78.55% EPSS. Upgrade to 5.0.8 and audit administrator accounts.
Confirmed campaign or large-scale exposure with direct impact on organizations or their data.
- T4Texas Parks & Wildlife vendor breach
3,087,721 driver's-license and passport records obtained through an unnamed third-party licensing vendor; disclosed June 18.
- T5Xsolis healthtech breach
1,396,519 individuals' SSNs and medical-treatment data exposed via phishing at a healthcare processor; five-month gap to disclosure.
- T6Klue/Icarus Salesforce supply-chain breach
Stolen OAuth tokens reached ~two dozen enterprises' Salesforce data; active extortion, with the data re-stolen from Icarus by a second actor.
- T7London Hydro breach (Canadian utility)
Customer contact and account data stolen at the electricity distributor for London, Ontario (~170,000 customers); entry vector undisclosed.
Structural control deficiencies revealed by the day's threats, independent of any single exploit.
- T8Amazon Q Developer — AI-tooling consent & least-privilege gap
CVE-2026-12957 is patched and unexploited, but an AI coding assistant auto-executing untrusted workspace config exposes the governance gap: what AI developer tools may run automatically near production credentials.
- T6OAuth grants as ungoverned standing credentials
The Klue breach (secondary zone) reveals a structural gap: third-party SaaS OAuth grants into crown-jewel data are rarely inventoried or assigned a revocation owner.
Cross-cutting pattern requiring board-level awareness and programme-level response.
- T1 · T2 · T8Five Eyes alert: the exploit window is collapsing to “months, not years”
On June 23 the Five Eyes — including Canada's CCCS — warned that frontier AI is compressing the time from disclosure to exploitation. This week proves it: Lantronix exploited weeks after its patch (T1), Windchill web shells before the KEV listing (T2), an AI tool auto-running untrusted code (T8). Fund emergency-patch SLAs, least privilege, and AI-tooling governance now.
Remediation Actions
Consolidated actions across all eight threats, organized by time horizon. T-badges indicate which threat each action addresses.
0 – 24 hours
Immediate response
- T1Apply the Lantronix EDS5000 firmware update; block external access to the device HTTP RPC interface and hunt for connections from 38.207.136[.]2 / 218.13.42[.]36.
- T2Apply PTC's June 17 Windchill/FlexPLM patches, block C2 5.180.41.35, and scan for JSP web shells matching /Windchill/login/[0-9a-f]{16}.jsp.
- T3Upgrade UniFi OS Server to 5.0.8; remove rogue admin accounts (incl. “John Sim”) and rotate administrator credentials.
7 days
Short-term hardening
- T6Revoke and reissue OAuth tokens granted to Klue and other third-party SaaS integrations with Salesforce access; rotate legacy integration-service credentials.
- T2Search all web access logs for POST requests to /Windchill/login/*.jsp and validate no lateral movement from the host occurred.
- T8Confirm Amazon Q Developer / Language Server for AWS is ≥ 1.65.0 across developer workstations and that auto-updates are not network-blocked.
14 – 30 days
Programme remediation
- T1Conduct a full OT asset inventory of serial-to-IP converters and bring OT firmware into the vulnerability-management program with a defined patch SLA.
- T4T5Audit every third-party vendor holding government-issued identity data or PHI: contractual security requirements, data-minimization scope, and breach-notification SLA.
- T6Inventory every OAuth grant into Salesforce and other SaaS tenants; revoke unused or over-scoped grants and enforce least-privilege scopes with expiry.
Ongoing
Structural controls
- T1T2T3Adopt a KEV-aligned emergency-patch SLA so OT, PLM, and network-infrastructure firmware inherit the same clock as IT — the Five Eyes alliance now states this expectation explicitly.
- T4T5T6Build a third-party risk program that inventories vendor data holdings, security attestations, OAuth grants, and notification SLAs — with a named revocation owner.
- T8Govern AI developer tools as third-party AI components under an ISO 42001 management system: inventory, version-govern, and assess before granting credential-bearing access.
Provenance
Intelligence Sources
Cadence
Published each weekday. Primary intelligence drawn from BleepingComputer, SecurityWeek, The Hacker News, The Record, KrebsOnSecurity, and researcher disclosures, supplemented by vendor advisories, the Canadian Centre for Cyber Security, CVE and NVD records, and MITRE ATT&CK frameworks. Use the Share button on any issue to join the distribution list.
See how this week's threats map to your control gaps.
Book a briefing →