Threat Brief — 2026-06-30 — Oracle Zero-Days Fuel Espionage & Credential Theft
Executive Summary
Two critical vendor zero-days dominate today's landscape: Oracle E-Business Suite (CVE-2026-46817KEV) is under active exploitation in the wild, and a SimpleHelp authentication bypass (CVE-2026-48558KEV) is being leveraged to deploy the new Djinn infostealer targeting cloud and AI credentials. ShinyHunters continued exploitation of an Oracle PeopleSoft zero-day has now hit both NAIC and Nissan, with Nissan confirming an employee data breach. Nation-state activity remains high, with Iran, Russia, and China targeting water utilities through basic hygiene failures, Gamaredon expanding Ukraine operations, and Mustang Panda abusing Zoho WorkDrive as a C2 channel against Indian government and hydropower targets.
Top Items
- CVE-2026-46817KEV — Oracle E-Business Suite, actively exploited (CVSS 9.8): Critical improper privilege management flaw in Oracle EBS financial application; Defused Cyber reports in-the-wild exploitation. No public patch timeline confirmed yet. Organizations running Oracle EBS financial modules should assume exposure. The Hacker News | BleepingComputer
- ShinyHunters PeopleSoft campaign — NAIC and Nissan breached: ShinyHunters exploited an Oracle PeopleSoft zero-day to breach NAIC (stealing public data, outdated logs, configs) and Nissan (employee data breach affecting current and former staff). Pattern suggests ongoing targeting of Oracle enterprise platforms. BleepingComputer — NAIC | BleepingComputer — Nissan
- CVE-2026-48558KEV — SimpleHelp auth bypass enabling Djinn Stealer deployment: Critical authentication bypass in SimpleHelp remote support software is being exploited to deploy Djinn Stealer, a new cross-platform (Windows/macOS/Linux) infostealer specifically targeting cloud and AI credentials bridging dev and admin environments. Dark Reading | BleepingComputer
- CVE-2026-55200 — libssh2 client-side SSH flaw, public PoC available: A malicious or compromised SSH server can trigger memory corruption on a connecting client with possible code execution — no credentials or user interaction required. Public proof-of-concept released. Any system using libssh2 to connect to untrusted SSH servers is at risk. The Hacker News
- Amazon Q VS Code extension flaw — cloud credential theft via malicious repo: Adversaries can plant a malicious repository that executes arbitrary code and steals cloud credentials through the Amazon Q VS Code extension, highlighting growing MCP (Model Context Protocol) supply-chain risk. Dark Reading
- Hijacked npm and Go packages deploy Python infostealer via VS Code Tasks: Two hijacked npm packages plus a cluster of Go packages use VS Code task automation to deploy a Python-based infostealer across Windows, Linux, and macOS. Avoids common detection patterns. The Hacker News
- Microsoft removes 119 malicious Edge extensions: Long-running operation hid payloads in image and font files, lying dormant for days post-install before activating credential theft and ad fraud. Demonstrates browser extension store trust gaps. The Hacker News
- Mustang Panda targets Indian government & hydropower via Zoho WorkDrive C2: China-aligned APT deployed new malware and repurposed Zoho WorkDrive as a command channel, expanding cloud-service abuse for stealthy C2. The Hacker News
- Gamaredon expands Ukraine attacks with 35+ new malware variants: Russian APT continues evolving its arsenal with new malware families and cloud service abuse throughout 2025 operations. The Hacker News
- Iran, Russia, China targeting U.S. water systems: Nation-state actors are breaching water utilities through weak passwords, exposed PLCs, and poor network segmentation — not advanced malware. Highlights ICS/OT hygiene gaps. Dark Reading
- U.S. offers $10M bounty for UNC5792 and UNC4221: State Department reward for identifying members of Russian-linked groups targeting WhatsApp and Signal users. BleepingComputer
- 236,000 DCloud Uni-App sites serving crypto scams and wallet drainers: Infoblox identifies massive abuse of a legitimate Chinese cross-platform dev framework to deploy investment scam templates, phishing, and wallet-draining infrastructure at scale. The Hacker News
Themes
- Oracle enterprise platform targeting: Three separate findings (CVE-2026-46817KEV in EBS, ShinyHunters' PeopleSoft zero-day hitting NAIC and Nissan) point to a concentrated campaign against Oracle enterprise suites. Any organization running Oracle EBS or PeopleSoft should prioritize patching, log review for privilege escalation, and external-facing access restrictions.
- Developer toolchain as attack surface: Amazon Q VS Code extension, hijacked npm/Go packages using VS Code Tasks, and the malicious Perplexity Chrome extension all exploit developer and productivity tooling. The common thread is trusted extension/package ecosystems being abused to reach cloud credentials and enterprise environments — a supply-chain pattern accelerating alongside AI agent adoption.
- libssh2 vulnerability cluster: Alongside the critical CVE-2026-55200 with public PoC, MSRC published two additional libssh2 CVEs (CVE-2026-58050 integer overflow in publickey subsystem, CVE-2026-58051 uninitialized pointer free in publickey cleanup). Any libssh2-based SSH client tooling warrants immediate version review and patching.
- Infostealer evolution toward cloud/AI credentials: Djinn Stealer explicitly targets credentials connecting dev and admin environments to broader cloud and AI systems — a shift from traditional browser/data theft toward agentic AI and cloud identity compromise.
