- Critical Unified CM vulnerability allowing root privilege escalation via SSRF
- Unified CM flaw enabling threat actors to gain root access
- Prior critical Unified CM RCE vulnerability actively exploited as zero-day in January
ThreatNoir Afternoon Brief — June 4
Afternoon Review in IT Security — June 4, 2026
The security landscape continues to shift rapidly as critical vulnerabilities emerge across enterprise communications platforms, development tools, and open-source ecosystems. Today's afternoon briefing covers four significant threats ranging from supply-chain attacks to sophisticated espionage campaigns targeting financial sector leadership.
Cisco Warns of Critical Unified CM Flaw with PoC Exploit Code
Cisco has released security updates to address a critical-severity vulnerability in Unified Communications Manager (Unified CM) that allows attackers to gain root privileges on affected systems. The flaw, tracked as CVE-2024-20253, has been accompanied by the release of proof-of-concept exploit code, elevating the urgency for organizations running Unified CM deployments. Two additional related CVEs, CVE-2026-20045 and CVE-2026-20230, have also been identified as part of this vulnerability cluster.
Organizations operating Unified CM infrastructure should prioritize patching efforts immediately given the critical severity rating and public availability of working exploit code. Source: Cisco warns of critical Unified CM flaw with PoC exploit code
Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
Cybersecurity researchers have identified a large-scale operation impersonating legitimate open-source and freeware projects to distribute malware through a Traffic Distribution System (TDS). The campaign funnels unsuspecting users to counterfeit project portals that closely resemble authentic sites, ultimately delivering malware families including Remus Stealer, AnimateClipper, Lumma Stealer, and the SessionGate framework. These fraudulent sites have achieved high search engine rankings, making them particularly dangerous to developers and users seeking legitimate tools.
The sophistication of these fake portals underscores the ongoing threat to the open-source ecosystem and highlights how search engine visibility can be weaponized in supply-chain attacks. Organizations and developers should exercise caution when downloading tools and verify authenticity through official channels and cryptographic signatures. Source: Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
Unknown attackers maintained persistent access to the Outlook mailbox of a senior executive at a major global stock exchange for at least five months, systematically copying inbox contents in small batches and exfiltrating data through Dropbox and OneDrive to blend the activity with legitimate cloud traffic. Symantec and Carbon Black's Threat Hunter Team disclosed the campaign, which employed tools including an Aspose-based mailbox stealer, FRPC, Secretsdump, and SharpDecryptPwd, suggesting a sophisticated, well-resourced threat actor focused on intelligence gathering rather than financial gain.
The campaign's extended duration and careful operational security indicate nation-state level espionage activity targeting financial sector leadership. The use of legitimate cloud services for data exfiltration demonstrates how attackers continue to exploit the difficulty of distinguishing malicious cloud activity from normal business operations. Source: Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
VS Code Vulnerability Allows One-Click GitHub Token Theft
A researcher has disclosed a vulnerability in Visual Studio Code that enables one-click theft of GitHub authentication tokens, with proof-of-concept code released without prior notification to Microsoft. The flaw can be exploited through malicious VS Code extensions, creating a direct pathway to compromise developer credentials and access to code repositories. The premature public disclosure amplifies the risk to the development community.
This vulnerability represents a critical supply-chain risk given VS Code's ubiquity in development environments and the value of GitHub tokens to attackers seeking repository access or lateral movement within organizations. Developers should review their installed extensions and verify the legitimacy of any recently added tools. Source: VS Code Vulnerability Allows One-Click GitHub Token Theft
Today's threat landscape reflects the convergence of multiple attack vectors: from infrastructure vulnerabilities requiring immediate patching to sophisticated social engineering through counterfeit open-source sites, executive-level espionage campaigns, and developer tool compromises. Organizations should prioritize inventory assessment, patch management, and user awareness training across all these threat categories.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- AnimateClipperCryptocurrency clipper replacing wallet addresses across 20+ blockchains
- Lumma StealerParent stealer variant of Remus Stealer
- Remus StealerInformation stealer MaaS variant delivering browser/wallet data; 2,000-3,500 VirusTotal submissions
- SessionGateMulti-stage obfuscated loader delivering PUAs with anti-analysis mechanisms
- FRPCTraffic tunneling tool used in wider intrusion kit
- Aspose-based mailbox stealerCustom .NET library-wrapped tool that converted Outlook OST/PST files to PST format for exfiltration
- SecretsdumpWindows credential dumping tool deployed in intrusion
- SharpDecryptPwdTool for recovering saved application passwords
temp.shPublic file hosting service tested once in November 2025, then abandoned
- malicious VS Code extensionExtension installed via simulated keystrokes in Jupyter notebook to steal GitHub tokens