logo

Critical Lantronix flaw actively exploited; Cisco SD-WAN zero-day; 27M credentials recovered

ID: 8300e1ce-c87a-5c08-900e-717c9086c087

STIX ID: report--8300e1ce-c87a-5c08-900e-717c9086c087

Feed Name: defend.network

Threat Score
85/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

...
...

**High-level briefing:** Active exploitation of critical infrastructure and supply‑chain risks: CISA warns of Lantronix EDS5000 exploitation with a June 26 remediation deadline, Mandiant details Cisco Catalyst SD‑WAN zero‑day abuse to create rogue root accounts, Amadey and StealC botnets were disrupted with 27 million credentials recovered, researchers disclosed the Cordyceps CI/CD pattern impacting 300+ GitHub repositories, and a malicious Edge extension (Edgecution) uses Native Messaging to deploy a Python backdoor; immediate patching, CI/CD workflow audits, extension controls, credential resets, and IOC monitoring are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.