ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-06-26
▶The Wire — Daily Briefing

The Wire — Friday, June 26, 2026

Critical infrastructure under siege as threat actors close the detection gap

35 stories analyzed

Critical infrastructure under siege as threat actors close the detection gap

Today's threat landscape crystallizes around a single, urgent truth: critical systems are being actively exploited while defenders remain several moves behind. We're seeing the convergence of four distinct attack trends—infrastructure vulnerabilities with known exploits, supply chain infiltration, nation-state operational evolution, and the emergence of AI-aware malware—all accelerating simultaneously. The industry's detection playbooks, built for yesterday's threats, are failing against today's reality.

The most immediately dangerous story is the active exploitation of PTC Windchill's RCE vulnerability (CVE-2026-12569). This isn't theoretical—unauthenticated webshells are live in the wild, targeting manufacturing and defense contractors. CISA's first-ever PTC KEV listing with a June 28 federal deadline tells you everything about urgency. Yet Windchill is just one thread in a larger tapestry of operational technology vulnerabilities suddenly under active attack.

The Lantronix EDS5000 serial-to-IP converter flaw (CVE-2025-67038) is already being exploited to gain root access to healthcare networks. Delta Electronics' critical deserialization vulnerability in DTM Soft allows arbitrary code execution on manufacturing systems when opening project files—a delivery vector as simple as email or USB. The Daktronics controller vulnerabilities, with default credentials and path traversal flaws, threaten emergency services' coordination systems. These aren't waiting for patches; they're active compromises in operational networks right now. What ties them together is institutional neglect. OT systems run on decades-old architecture with no real expectation of patching. When vulnerabilities do surface, the friction of validating updates creates a gap where attackers operate freely.

Supply chain infiltration is taking a different but equally dangerous form. EdTech attackers are shifting from schools to their software suppliers, a classic pivot: compromise one vendor, reach thousands of institutions simultaneously. The order-tracking app Shop is being abused to push phishing and malware, leveraging its legitimacy to bypass user skepticism. Most troubling: a popular YouTube ad blocker with 10+ million installs harbors dormant script injection capability—a remote execution payload waiting for activation. These aren't backdoors we'll discover during incident response. They're trojan horses already living in users' browsers. And the ecosystem isn't helping: MCP's new enterprise redesign shifts security responsibility from protocol to developers, creating a patchwork of inconsistent protections just as organizations adopt the standard at scale.

Nation-state actors are simultaneously evolving their playbooks. Russia's APT Turla has deployed StockStay, a .NET backdoor masquerading as legitimate apps, against Ukrainian government and military targets with modern WebSocket C2 infrastructure. Russian APT Gamaredon has launched 35 phishing campaigns with six new malware variants and USB attack vectors. The pattern is clear: traditional espionage infrastructure is modernizing, and the volume is climbing. Organized crime is following suit. Polish authorities busted a SIM-swapping syndicate responsible for millions in cryptocurrency theft, but the takedown didn't dismantle the tactic. SIM swapping is now commodified attack infrastructure. Once inside via account takeover, attackers blend seamlessly with legitimate user behavior—a problem so fundamental it remains one of the hardest threats to stop.

The arms race against detection itself is now visible. North Korean malware Gaslight uses prompt injection to confuse AI-powered security tools, abandoning traditional evasion for psychological manipulation of the analytical process. This is detection sabotage—malware that targets the machine learning systems designed to find it.

The industry is responding, but unevenly. Richard Bejtlich argues that traditional defenses fail because they focus on blocking entry, not detecting lateral movement. Network detection and response shifts focus to the dwell phase—overdue but not yet universal. Europe has become ransomware's favorite region, with 684 attacks in early 2026—a 55% surge from 2025. This isn't random; it's criminals adapting after US law enforcement disruptions. Where enforcement succeeds, threat actors migrate.

Institutional realities compound the problem. Microsoft extended Windows 10 free ESU support to October 2027, a two-year postponement that signals retreat from Windows 11 pressure. The vulnerability surface remains fractured across OS versions for years. A 25-year-old vulnerability in Curl was patched only after AI-driven scanning surfaced it. Legacy code harbors risks we haven't even categorized.

The threat landscape isn't getting simpler—it's fractalizing. Defenders are tested simultaneously on infrastructure, endpoints, networks, applications, and supply chains. Critical vulnerabilities have government deadlines. The detection gap is widening. Threat actors operate with increasing sophistication and mobility.

What security teams must do now: patch critical infrastructure vulnerabilities on CISA timelines, not internal schedules. Inventory third-party software and browser extensions for dormant capabilities. Assume account takeovers are happening and shift detection focus to lateral movement. Prepare for evasion tactics that target your tools, not your infrastructure.

Key Takeaways

  • Critical OT vulnerabilities are actively exploited with government deadlines. PTC Windchill, Lantronix, Delta, and Daktronics flaws are live in production. Organizations have days to weeks to patch before attackers deepen access.
  • Supply chain infiltration is the default attack vector. Malware in legitimate apps, dormant capabilities in extensions, and vendor compromises show defenders can't trust software they didn't write.
  • Detection systems themselves are now targets. Malware designed to confuse AI analysis marks a shift from evasion to sabotage of the analytical process.
  • Nation-states and organized crime coordinate on technique evolution. Upgraded backdoors, industrialized phishing, and SIM-swapping-as-a-service show synchronized operational maturation.

The Wire is HackWire's daily editorial briefing, published every morning.