Security Briefing | June 25, 2026 - Cisco SD-WAN Zero-Day Hits Root Access, Critical Lantronix Flaw Exploited, Operation Endgame Recovers 27M Credentials
Threat actors exploited a Cisco Catalyst SD-WAN zero-day (CVE-2026-20245) for at least two months before public disclosure, gaining root access and creating rogue accounts. CISA has flagged active exploitation of a critical Lantronix EDS5000 flaw threatening OT environments. Meanwhile, a coordinated law enforcement operation disrupted Amadey and StealC malware infrastructure, recovering 27 million stolen credentials.
By EACA Summit Content Team

1. Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited for Root Access
Mandiant revealed that threat actors exploited CVE-2026-20245 as a zero-day for at least two months before Cisco disclosed it. The vulnerability allows authenticated local attackers to execute arbitrary commands with elevated privileges, enabling creation of rogue root accounts on affected devices.
Verified Facts
- CVE-2026-20245 is a high-severity vulnerability (CVSS 7.8) in Cisco Catalyst SD-WAN
- Exploitation was observed as a zero-day prior to public disclosure
- Attackers used the flaw to gain root access and create rogue accounts
Evidence
- CVE-2026-20245
- Mandiant investigation
- Cisco advisory
Impact
Organizations using Cisco Catalyst SD-WAN should immediately patch and audit for signs of compromise, as the flaw enables full device takeover.
Confidence Level: High
The Hacker News | BleepingComputer | SecurityWeek
2. CISA Warns of Active Exploitation of Critical Lantronix EDS5000 Flaw
CISA added CVE-2025-67038 to its Known Exploited Vulnerabilities catalog, warning of active attacks against Lantronix EDS5000 serial-to-ethernet devices. The critical code injection flaw (CVSS 9.8) could allow unauthenticated remote code execution, posing a significant risk to OT environments.
Verified Facts
- CVE-2025-67038 is a critical code injection vulnerability (CVSS 9.8)
- CISA confirmed active exploitation and mandated patching by June 26, 2026 for FCEB agencies
- The flaw was disclosed in April 2026 as part of the BRIDGE:BREAK research project
Evidence
- CVE-2025-67038
- CISA Known Exploited Vulnerabilities Catalog
- BRIDGE:BREAK research
Impact
Critical infrastructure and OT networks using Lantronix EDS5000 devices are at high risk; immediate patching is essential.
Confidence Level: High
The Hacker News | BleepingComputer | SecurityWeek
3. Operation Endgame Disrupts Amadey and StealC Malware Infrastructure

A coordinated law enforcement operation involving Europol, Microsoft, Bitdefender, ESET, and others disrupted the shared infrastructure of Amadey and StealC malware operations. Over 27 million stolen credentials were recovered, and hundreds of command-and-control servers were taken down.
Verified Facts
- Operation Endgame targeted the infrastructure of Amadey and StealC malware
- Partners included Europol, Microsoft, Bitdefender, ESET, and Bitsight
- 27 million stolen credentials were recovered
- Hundreds of C2 servers were disrupted
Evidence
- Europol press release
- Microsoft Security Blog
- Industry partner statements
Impact
This takedown disrupts cybercriminal supply chains for ransomware and financial fraud, but defenders should remain vigilant for residual activity.
Confidence Level: High
The Hacker News | BleepingComputer | SecurityWeek
Also Noted
A new macOS malware called Gaslight has been observed using prompt injection techniques specifically designed to evade AI-assisted malware analysis tools, signaling an emerging trend of malware authored to target AI-based detection methods.
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



