Executive Summary -
Highlights of Cyber Threat Intelligence Digest
Vulnerabilities
Google Discloses CVE-2026-12537 Affecting Gemini CLI - On 24 June 2026, Google disclosed CVE-2026-12537, a critical-severity improper input validation vulnerability affecting Gemini CLI versions prior to 0.39.1 and the run-gemini-cli GitHub Action versions prior to 0.1.22. The flaw stems from Gemini CLI's automatic workspace trust behaviour when operating in headless CI/CD environments, and successful exploitation would allow an unprivileged threat actor to achieve pre-sandbox, host-level remote code execution via maliciously crafted .gemini/.env files.
To reduce the risk of exploitation, organisations are advised to update Gemini CLI to version 0.39.1 or 0.40.0-preview.3, and to update the run-gemini-cli GitHub Action to version 0.1.22 or later.
Synology Patches Three Vulnerabilities (CVE-2026-13136, CVE-2025-15660, CVE-2026-13135) in MailPlus Server - On 26 June 2026, Synology released security updates for Synology MailPlus Server in DSM, addressing three vulnerabilities, including two of critical severity. The flaws affect Synology MailPlus Server for DSM versions 7.3, 7.2.2, and 7.2.1, and are patched in DSM 7.3 to 4.0.1-31663 or later, and DSM 7.2.2 or DSM 7.2.1 to 4.0.1-21663 or later; no active exploitation had been reported at the time of writing. CVE-2026-13136 is a critical incorrect authorisation vulnerability that could allow unauthenticated remote threat actors to read or write arbitrary files and conduct denial-of-service (DoS) attacks, while CVE-2025-15660 is a critical weak pseudo-random number generator vulnerability that could allow adjacent threat actors to do the same.
CVE-2026-13135, meanwhile, is a moderate improper communication-channel restriction vulnerability that could allow unauthenticated remote threat actors to access internal services. Organisations running affected versions of Synology MailPlus Server are advised to apply the relevant updates promptly to mitigate these risks.
Dell Patches Two Remote Code Execution Vulnerabilities (CVE-2026-41120, CVE-2026-49506) in Wyse Management Suite - On 16 June 2026, Dell patched two remote code execution (RCE) vulnerabilities, tracked as CVE-2026-41120 and CVE-2026-49506, affecting Wyse Management Suite versions prior to 5.5 HF1. Exploitation of either flaw could allow threat actors to conduct RCE, though no reports of exploitation in the wild had emerged at the time of writing.
To prevent threat actors from exploiting these vulnerabilities, Insikt Group recommends updating Wyse Management Suite to version 5.5 HF1 or later.
Potential Threats
Threat Actors Use Fake Purchase Receipts in Shopify Shop Application to Conduct Callback Phishing - On 24 June 2026, Gen Digital reported that threat actors had abused Shopify's Shop order-tracking application to place fraudulent purchase receipts within users' Shop order histories as part of a callback phishing campaign. The fraudulent receipts impersonated brands including Norton, McAfee, Apple, and PayPal, and appeared alongside legitimate purchases within Shop. Researchers found no evidence that Shop, Shopify, or the impersonated brands had been compromised, and could not determine whether the threat actors had abused Shop's email parsing, account association, merchant order workflows, or another legitimate mechanism to insert the fraudulent receipts.
The fraudulent receipts claimed unauthorised purchases or subscription renewals and embedded support phone numbers within the order details to prompt victims into disputing the alleged charges. Calling the number connected victims to a threat actor posing as a customer support representative, who used social engineering to request account credentials, payment card information, or one-time passwords; in some cases, the threat actor also persuaded victims to install remote access software.
US-Based LastPass Reports Third-Party Data Breach Following Klue OAuth Token Compromise Affecting Customer CRM Information - On 12 June 2026, LastPass determined that unknown threat actors had conducted a cyberattack affecting Klue, a third-party market intelligence platform integrated with its Salesforce and Gong environments, and had accessed customer data stored within LastPass's Salesforce instance. LastPass found that the threat actors obtained OAuth tokens for multiple Klue customers and used those credentials to access customer relationship management (CRM) data within LastPass's Salesforce environment. Potentially exposed data includes customer names, phone numbers, email addresses, physical addresses, support case information, and sales-related records.
LastPass has completed remediation efforts and rotated the affected OAuth tokens. At the time of writing, the identity of the threat actor remains unknown, as no-one has claimed responsibility for the attack on Klue or LastPass on dark web sources.
Threat Actors Abuse Calendly and Google URL Redirection to Deliver TonRAT in Hospitality Phishing Campaign - On 25 June 2026, Microsoft reported a malware campaign targeting hospitality organisations across Europe and Asia, operating since April 2026. Threat actors used phishing emails impersonating booking and scheduling notifications to deliver TonRAT, a Node.js-based implant family. Microsoft has not attributed the activity to a known actor but assesses that its persistence and evasion mechanisms indicate an effort to retain long-term access to compromised systems. The actors abused Calendly's email notification infrastructure and Google's URL redirection service to bypass email authentication, a technique Microsoft calls authentication laundering, using multilingual hospitality-themed lures such as guest complaints and bedbug reports to prompt recipients to download a photo-themed ZIP archive containing malicious LNK files disguised as PNG images.
In the first wave, opening the shortcuts launched an obfuscated PowerShell downloader that retrieved and deployed TonRAT; in the second, the script invoked the C# compiler to generate a .NET DLL before deployment. The malware persists via Run and RunOnce registry entries, adds Defender process exclusions before dropping further payloads, and beacons to command-and-control (C2) servers. Microsoft also observed automated headless browser sessions, network reconnaissance queries, forced system shutdowns, and additional payload downloads after Defender blocked an earlier executable, since the Node.js implant remained on the compromised system.
General News
Microsoft accelerates quantum-safe roadmap as risks grow - Microsoft has announced that it is accelerating its quantum-safe security roadmap, stating that advances in quantum computing mean the need to replace today's encryption standards is arriving sooner than previously anticipated. While current quantum computers cannot yet break modern encryption, researchers have long warned of "harvest now, decrypt later" attacks, in which data stolen today is stockpiled until future quantum computers become powerful enough to decrypt it. Firms including Apple, Google, and Signal have already begun rolling out post-quantum cryptography (PQC) to replace existing public-key encryption. Microsoft now plans to transition its critical products and services to PQC by 2029 under its Quantum Safe Program (QSP), and will fold quantum-safe requirements into its Secure Future Initiative (SFI); the company said its view of the risk timeline is shifting as quantum research advances and preparation needs become clearer.
Rather than focusing purely on adopting new algorithms, Microsoft says organisations should first modernise their infrastructure to ease the eventual transition, and has set out three priorities: upgrading network cryptography by adopting modern protocols such as TLS 1.3 to support future hybrid and post-quantum key exchange; building "crypto-agility" so cryptographic algorithms can be swapped for PQC variants without redesigning applications; and modernising cryptographic trust chains used for code signing, certificate issuance, software updates, and hardware-backed key protection. Folding PQC planning into the Secure Future Initiative will allow quantum-safe readiness to be tracked alongside other security goals, however Microsoft has not disclosed the specific developments that prompted the accelerated timeline.
WhatsApp rolls out usernames to help users hide their phone number - WhatsApp is finally allowing users to reserve usernames, a privacy feature that lets them hide their phone numbers from people outside their contact list. Meta says more than three billion people across over 180 countries use the platform, which began life as an alternative to SMS on mobile devices. Users will also be able to set an optional key that others must know before messaging them via the new username. "Starting this week, you can reserve a username to use later this year when we launch this feature," Meta said in a Monday announcement, adding that reservations were opened early given how often names overlap across its user base.
Meta added that usernames are its latest step towards greater privacy on WhatsApp, since there is no directory to browse and no suggestions offered; people will need to know a user's exact username to make first contact, and the optional username key adds a further layer of control over who can do so. The feature is rolling out gradually over the coming months, with users notified once it reaches their country; in the meantime, a username can be reserved via Settings > Account > Username after updating to the latest version of the app. Reserved usernames can be changed or deleted at any time, though doing so frees them for others to claim, and Meta noted that certain usernames are reserved for governments, public figures, and businesses. Signal, by comparison, has offered custom usernames since February 2024, following a public test phase that began in November 2023.
CIA chief highlights major shifts in agency’s tech approach - The head of the CIA on Tuesday touted recent changes marking what he called a "fundamental reshaping" of how the agency pursues technology. "We simply can't afford to wait for a risk-free approach... we have to move fast, we have to be aggressive," CIA Director John Ratcliffe said at the AWS Summit in Washington, D.C., adding that frontier AI models' capabilities were akin to "digital nuclear weapons" and that excelling in AI was vital to US strategic advantage. His remarks served as a progress report on his pledge, made during confirmation last year, to make the CIA less risk-averse against foreign competitors, particularly China. He noted the agency had elevated its Center for Cyber Intelligence into its own mission centre and transformed its Directorate of Digital Innovation into the Directorate of Mission Systems, dropping offensive cyber and open-source duties in favour of core functions like cybersecurity and infrastructure services, which he said would strengthen the agency's entire IT architecture.
Ratcliffe added that the CIA is running an aggressive data sprint to improve discovery and exploitation of mission data, standardise data agency-wide, and train officers on new capabilities. He also said procurement reforms had cut technology adoption times from nearly three years to roughly six months, driving hundreds of new acquisitions, while a new Office of Corporate Partnerships now gives industry partners a single point of access. Dismissing suggestions these were merely organisational changes, Ratcliffe insisted they represent a fundamental reshaping of the CIA's approach to technology.
Threat Actor Weekly Graph
Over the past 7 days, we have been tracking the following intent and opportunity changes within our Threat Actor Landscape.
Intent represents the potential targets of a group. When a group is observed attacking a different organisation or entity, their intent will increase.
Opportunity represents the various methods and technologies these groups may use. For example, if a group started using a new attack vector, such as a new kind of ransomware, their opportunity would increase.
Both intent and opportunity are scored out of 100 and are responsible for scoring the group's severity. These updates can be seen below.

| ● Limited Severity | ● Basic Severity | ● Moderate Severity | ● High Severity |
| Threat Actor | Severity Increase | Opportunity | Intent | ||||||
|---|---|---|---|---|---|---|---|---|---|
| ShinyHunters | ● Moderate | → | ● Moderate | ● 49 | → | ● 49 | ● 61 | → | ● 62 |
| KongTuke | NEW | → | ● Basic | NEW | → | ● 49 | NEW | → | ● 25 |
| Russian Hackers | NEW | → | ● Basic | NEW | → | ● 35 | NEW | → | ● 25 |
| EvaN47 | NEW | → | ● Basic |
NEW | → | ● 25 | NEW | → | ● 30 |
| Sociedad Privada 157 | NEW | → | ● Basic | NEW | → | ● 25 | NEW | → | ● 25 |
Global Trends Powered by Recorded Future
Within each category, we have provided the current top five globally trending items. Each item is linked to how actively trending it is and is marked with a small symbol.
The spikes in references are calculated over 60 days and are normalised to ensure they aren't disproportionate when compared to bigger entities that will naturally have more baseline mentions.
▲- Spike – This indicates a large increase in reporting volume and a high diversity in the event descriptions.
▲- Rise – This indicates a small increase in reporting volume with little diversity in the descriptions.
| Attackers | Methods | Vulnerabilities | Targets | |||||
|---|---|---|---|---|---|---|---|---|
| RedDelta | ▲ | ZOHOMURK | ▲ | CVE-2026-48558 | ▲ | Tata Group | ▲ | |
| Anonymous | ▲ | Dark Crystal RAT | ▲ | CVE-2026-46817 | ▲ | Insurance | ▲ | |
| Akira Ransomware Group | ▲ | LOTUSLITE | ▲ | CVE-2026-33825 | ▲ | Aflac Holdings LLC | ▲ | |
| CMD Organization Group | ▲ |
Backdoor |
▲ | CVE-2026-20245 | ▲ | Nissan Motor | ▲ | |
| TAG-132 | ▲ | EvilTokens | ▲ | CVE-2026-8037 | ▲ | Klue | ▲ | |
Prominent Information Security Events
Threat Actor Abuse Calendly and Google URL Redirection to Deliver TonRAT in Hospitality Phishing Campaign
Source: Insikt Group | Validated Intelligence Event
IOC: Hash - c5baa0c16b0074a1e94b48aa0177e9bfc23746aca8a5b42848a6685da85658b5
On 25 June 2026, Microsoft reported a malware campaign targeting hospitality organisations across Europe and Asia that had been operating since April 2026. Threat actors used phishing emails impersonating booking and scheduling notifications to deliver the TonRAT implant family, a Node.js-based implant. Microsoft has not attributed the activity to a known threat actor but assesses that the campaign's persistence and evasion mechanisms indicate an effort to retain access to compromised systems for further malicious activity.
The threat actors abused Calendly's email notification infrastructure and Google's URL redirection service to send phishing emails that bypassed email authentication through a technique Microsoft describes as authentication laundering, using multilingual hospitality-themed lures such as guest complaints, room inquiries, and bedbug reports to persuade recipients to click an embedded link that downloaded a photo-themed ZIP archive containing malicious Windows shortcut (LNK) files disguised as PNG images. In the first wave of the campaign, users who opened the shortcuts launched an obfuscated PowerShell downloader that retrieved the next-stage payload and deployed TonRAT; in the second wave, Microsoft observed the PowerShell script invoking the C# compiler to generate a .NET DLL before deploying TonRAT.
The malware establishes dual registry-based persistence through Run and RunOnce entries, adds Microsoft Defender process exclusions before deploying further payloads, and communicates with command-and-control (C2) servers. Microsoft observed the malware beaconing to C2 servers, launching automated headless browser sessions, querying external services to gather network information, forcing immediate system shutdowns, and downloading additional payloads after Microsoft Defender blocked an earlier executable, given that the Node.js implant remained present on the compromised system.
US-Based LastPass Reports Third-Party Data Breach Following Klue OAuth Token Compromise Affecting Customer CRM Information
Source: Insikt Group | Validated Intelligence Event
IOC: IP: 159.183.181.239
On 12 June 2026, LastPass determined that unknown threat actors had conducted a cyberattack affecting Klue, a third-party market intelligence platform integrated with its Salesforce and Gong environments. The company found that the incident had led to unauthorised access to customer data stored within its own Salesforce instance, marking the latest in a string of supply-chain-style breaches in which attackers have targeted a trusted third-party integration rather than the primary organisation's systems directly.
LastPass's investigation determined that the threat actors had obtained OAuth tokens belonging to multiple Klue customers, and subsequently used those stolen credentials to access customer relationship management (CRM) data held within LastPass's Salesforce environment. The company said the potentially exposed data includes customer names, phone numbers, email addresses, physical addresses, support case information, and sales-related records; there is currently no indication that password vaults, master passwords, or other core LastPass product data were affected by the incident, with exposure limited to the CRM environment reachable via the compromised Klue integration.
LastPass has since completed its remediation efforts and rotated the affected OAuth tokens to cut off any further unauthorised access via that pathway. At the time of writing, the identity of the threat actor behind the attack remains unknown, and Insikt Group has not identified any threat actor publicly claiming responsibility for the attack on either Klue or LastPass across dark web sources monitored to date. Insikt Group will continue to monitor the situation and will provide further updates as more information becomes publicly available.
Remediation Actions
Following the information provided above, we recommend that the technologies mentioned be fully patched and updated. We also want to highlight and recommend applying the following patches where applicable:
-
CVE-2026-12537 (Gemini CLI) – This vulnerability can be remediated by updating to Gemini CLI to version 0.39.1 or 0.40.0-preview.3, and the run-gemini-cli GitHub Action to version 0.1.22 or later.
-
CVE-2026-13136, CVE-2026-13135, CVE-2025-15660 (Synology) – These vulnerabilities can be addressed by patching to DSM versions 4.0.1-31663 and 4.0.1-21663.
-
CVE-2026-41120, CVE-2026-49506 (Dell) – Updating Wyse Management Suite to version 5.5 HF1 or later will remediate this vulnerability.
If you are currently an Acumen Cyber Vulnerability Management customer, we will be proactively performing related searching and hunting activities within your environment.