Threat Analysis : Cyber News for Small Business
Threat Analysis : Cyber News for Small Business 0 followers
Follow
Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs

Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs

Jul 6, 2026 • 12min 08s

Episode description

Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs

Today’s briefing covers two active threats facing UK small businesses. First, CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion confirmed to be under active exploitation by the Canadian Centre for Cyber Security and verified by BleepingComputer. The flaw permits unauthenticated remote code execution with a CVSS score of 10.0, affecting legacy installations across SMB websites, internal applications, and shared hosting environments managed by MSPs. Second, a criminal group designated CL-CRI-1147 and tracked as Pink is conducting voice phishing campaigns that impersonate IT helpdesks to extract credentials and bypass multi-factor authentication. Once inside, the group exfiltrates data from SharePoint and OneDrive, then issues a seventy-two-hour ransom demand. The tactic closely mirrors operations by UNC3753, documented by Google Cloud Threat Intelligence. Both threats exploit different attack surfaces but share a common trait: neither discriminates by organisation size. Mauven provides specific procedural guidance for patching, MSP coordination, staff briefings on vishing, and audit log monitoring to detect bulk data downloads before ransom demands arrive.

Chapters

  • Introduction Mauven introduces two current threats facing UK small businesses: an actively exploited Adobe ColdFusion vulnerability and a criminal vishing operation. Both target SMBs without discrimination based on size or sophistication.
  • Adobe ColdFusion CVE-2026-48282: Patch It Today, Not This Week Analysis of CVE-2026-48282, a maximum-severity vulnerability in Adobe ColdFusion confirmed under active exploitation. Covers CVSS 10.0 scoring, unauthenticated remote code execution, exposure through legacy systems and MSP-managed environments, and immediate patching requirements.
  • Call to Action Brief audience prompt to follow the show and share the briefing with colleagues who need current threat intelligence.
  • Pink (CL-CRI-1147): When the Threat Just Calls You Up Examination of the Pink criminal group’s vishing operation that impersonates IT helpdesks to extract credentials and bypass MFA. Details the exfiltration timeline, procedural defences, staff briefing requirements, and technical monitoring for SharePoint and OneDrive bulk downloads.
  • The Pattern Worth Noting Structural analysis connecting the Adobe vulnerability, vishing campaigns, and emerging ClickFix malware ecosystem. All three exploit different attack surfaces but converge on the same principle: automated and human-driven threats do not filter targets by organisation size.
  • Closing Summary of two actionable steps: verify and patch ColdFusion installations immediately, and brief staff on the vishing rule that IT will never request credentials or MFA approval by phone.

Links

  • https://www.bleepingcomputer.com/news/security/adobe-coldfusion-cve-2026-48282-exploited/
  • https://www.cyber.gc.ca/en/alerts-advisories
  • https://cloud.google.com/blog/topics/threat-intelligence/unc3753-vishing-law-firms
Comments0 Activity1 Chapters0 Transcript–
Threat Analysis : Cyber News for Small Business
Threat Analysis : Cyber News for Small Business @ThreatAnalysis Jul 6, 2026
12:08 Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs
Jul 6, 2026
Adobe ColdFusion Zero-Day and Vishing Gang Pink Target UK SMBs
0 0 0
RSS Podcast feed
HomeLinksCreditsMap

Powered by Castopod

Persons