
Weekly Threat Intelligence Briefing — July 06, 2026
WEEKLY THREAT INTELLIGENCE BRIEFING | MONDAY, JULY 6, 2026
This week’s exploited-in-the-wild additions cluster on the two surfaces that matter most to defense and maritime operators: the systems that hold CUI, and the edge devices nobody inventories.
On-prem CUI surfaces are the story
Microsoft SharePoint Server picked up an actively exploited deserialization flaw (CVE-2026-45659), added to CISA’s KEV catalog on July 1 with remediation due July 4 — that window has closed. On-prem SharePoint sits inside CUI scope for a large share of the Defense Industrial Base. Two weeks earlier, PTC Windchill and FlexPLM (CVE-2026-12569) and Cisco Unified Communications Manager (CVE-2026-20230) were added June 25. Windchill deserves particular attention: PLM is where technical data packages, drawings, and CUI actually live in defense manufacturing. A product-lifecycle platform on the KEV list is a CUI-exposure item, not a routine patch.
The edge keeps getting quieter — and more exploited
June 23 added four more: Lantronix EDS5000 (CVE-2025-67038), a serial-to-Ethernet device server, plus three Ubiquiti UniFi OS flaws (CVE-2026-34908 / 34909 / 34910). Serial device servers are the industrial and maritime OT bridges that rarely make an asset inventory — which is exactly why they are being hit. This extends the covert-networks / edge-device pattern the Five-Eyes advisories flagged in April.
Supply-chain credential theft is industrializing into ransomware
Sophos reported July 2 that TeamPCP — a group specializing in large-scale developer-credential theft — has partnered with Vect, a ransomware-as-a-service operation that emerged in late 2025. TeamPCP’s March compromise of Aqua Security’s Trivy scanner reportedly touched roughly 10,000 CI/CD workflows and yielded more than 500,000 credentials, including cloud tokens. Any organization whose developer credentials were harvested is now a warm lead for a ransomware deployment. This is the logical next chapter of the Nx and TanStack dependency cascades from June.
Ransomware baseline. The Gentlemen — active since August 2025 — grew from 35 victims in Q4 2025 to 182 in Q1 2026. INC Ransom, the operation historically tied to defense-contractor extortion, was posting transport and logistics victims as recently as July 3.
What this means
Three of this fortnight’s KEV additions — SharePoint, Windchill, and the edge cluster — map directly onto where CUI lives and how it moves. If your SSP inventories the application but not the PLM platform behind it, or the serial gateway feeding your OT, your attestation and your attack surface have diverged. The credential-theft-to-ransomware pipeline says the same thing from the other direction: the software development environment is a governed asset, whether your controls treat it that way or not.
Security brings compliance. Compliance does not bring security.
Full structured tracking of these actors and campaigns over time is now live in PSYber360.
Craig Wood, CISM | CCA Lead Assessor | ISO 27001 Lead Auditor | PSY Logistics Technology Partners
#ThreatIntelligence #DIB #CMMC #CUI #MaritimeCybersecurity #vCISO #CISA #KEV #SupplyChainSecurity #OTSecurity