Cybersecurity Daily Briefings

Critical vulnerabilities, active threats, and security news — curated for professionals.

Updated every workday at 08:00 CET
10 Jun 2026
Daily Cybersecurity Briefing
6 CVEs 4 threats 5 news items
Critical Vulnerabilities 6
CVE-2026-48567 CVSS 10.0 Microsoft Azure HorizonDB

Authentication bypass by spoofing in Azure HorizonDB allows unauthorized attackers to elevate privileges over a network. Max-severity vulnerability in June 2026 Patch Tuesday.

Source
CVE-2026-45657 CVSS 9.8 Windows Kernel (Windows 11/Server 2022/2025)

Remote, unauthenticated kernel RCE at SYSTEM level without user interaction. Described as wormable. Affects Windows 11 23H2/24H2/25H2/26H1 and Server 2022/2025.

Source
CVE-2026-44815 CVSS 9.8 Windows DHCP Client Service

Stack-based buffer overflow in Windows DHCP Client allows unauthenticated remote code execution over a network. Exploitation assessed as 'more likely'.

Source
CVE-2026-50751 CVSS 9.3 Check Point VPN Remote Access

Critical IKEv1 authentication bypass vulnerability under active exploitation. Qilin ransomware affiliate observed exploiting this zero-day for initial access.

Source
CVE-2026-3300 CVSS Critical Everest Forms Pro (WordPress Plugin)

Unauthenticated remote code execution via PHP eval() injection. Actively exploited in the wild allowing complete site takeover.

Source
CVE-2026-20245 CVSS 8.6 Cisco Catalyst SD-WAN Manager

Privilege escalation zero-day exploited in the wild against SD-WAN management interfaces, potentially compromising entire network fabrics.

Source
Malware & Threats 4
OP-512 APT / Web Shell Framework Targets: Microsoft IIS Servers — government and enterprise networks

Newly identified China-linked threat cluster deploying a custom three-web-shell framework. Operators wait up to 75 days before deploying full espionage toolkit.

Source
Qilin Ransomware Ransomware Targets: Global enterprise networks via Check Point VPN appliances

Qilin affiliate actively exploiting CVE-2026-50751 (Check Point VPN zero-day) for initial access. Marks operational shift with ransomware groups weaponizing VPN zero-days within days.

Source
Payload Ransomware Ransomware Targets: Manufacturing, healthcare, technology sectors

Financially motivated ransomware group. Top affected industries in 2026 include manufacturing, healthcare, and technology sectors per CYFIRMA intelligence.

Source
Infostealer Proliferation Infostealer Targets: Global phishing campaigns

Cybercriminals increasingly using infostealers as primary phishing payload over traditional credential-harvesting pages. Reduces friction, scales well, widely available on underground markets.

Source
Security News 5
Microsoft Breaks Patch Tuesday Record: 206 Vulnerabilities Fixed

June 2026 Patch Tuesday addresses a record 206 CVEs (571 including third-party), 32 Critical, 3 publicly disclosed zero-days. Surge attributed to AI-assisted development accelerating code production.

Read more
'RoguePlanet' — Microsoft Defender Zero-Day Exploit Released Publicly

Researcher 'Nightmare Eclipse' released public PoC exploit granting SYSTEM privileges via race condition. Released hours after Patch Tuesday amid ongoing bug bounty dispute.

Read more
Kyushu Electric Power Reports SSD Missing — 10.9M Customers Affected

Kyushu Electric Power Transmission and Distribution Co. reported an SSD containing personal data for up to 10.9 million customers went missing on June 8. Investigation ongoing.

Read more
Cisco SD-WAN Zero-Day (CVE-2026-20245) Exploited in the Wild

Privilege escalation zero-day affecting Cisco Catalyst SD-WAN Manager exploited by attackers to gain elevated access to SD-WAN management interfaces.

Read more
Anthropic Launches Claude Mythos 5 — Strongest Cybersecurity AI Model

Anthropic released Claude Mythos 5 with striking proficiency at computer security tasks. Project Mythos launched to study responsible deployment of advanced AI in cybersecurity.

Read more
9 Jun 2026
Daily Cybersecurity Briefing
1 CVE 3 threats 6 news items
Critical Vulnerabilities 1
CVE-2026-50751 CVSS 9.3 Check Point Remote Access VPN / Mobile Access

Logic flow weakness in certificate validation in deprecated IKEv1 key exchange allows unauthenticated remote attacker to bypass user authentication and establish VPN connection. Actively exploited in the wild since May 7, 2026. Qilin ransomware affiliate linked to exploitation.

Source
Malware & Threats 3
OP-512 China-linked Threat Cluster / Web Shell Framework Targets: Microsoft IIS Servers

Newly identified China-linked threat cluster using a custom three-web-shell framework for remote access, command execution, and data exfiltration. Discovered by ReliaQuest researchers using agentic AI.

Source
Silent Ransom Group (SRG) / Luna Moth / Chatty Spider Ransomware Targets: US Law Firms

Google and FBI joint advisory: SRG sends fake IT workers in-person to law firms, uses USB drops and remote access tools to compromise networks and deploy ransomware.

Source
Qilin Ransomware Affiliate Ransomware Targets: Check Point VPN users

Qilin ransomware affiliate exploiting CVE-2026-50751 (Check Point VPN zero-day) for initial access and ransomware deployment.

Source
Security News 6
CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog

CVE-2026-28318 (CVSS 7.5) allows unauthenticated attackers to crash SolarWinds Serv-U via crafted POST requests. Federal agencies must patch by June 19, 2026.

Read more
Instagram Fixes Password Reset Flaw Exposing User Emails & Phone Numbers

Critical logic bug in Instagram web-based password reset flow exposed unredacted email addresses and phone numbers. Demonstrated June 6, 2026. Meta has fixed the issue.

Read more
IBM Whistleblower Accuses Company of Covering Up Multiple Data Breaches

Former IBM cybersecurity executive alleges core network was routinely hacked by foreign state actors over several years with data exfiltrated and breaches covered up.

Read more
TechCrunch Publishes Mid-Year 2026 Worst Breaches Roundup

Major incidents highlighted include massive DOGE data breach, hacking of critical energy/water systems, and compromise of FBI surveillance system.

Read more
Android Framework Zero-Day (CVE-2025-48595) Actively Exploited

Google June 2026 Android update patches 124 flaws including CVE-2025-48595, a Framework zero-day actively exploited in targeted attacks. CISA added to KEV catalog June 2.

Read more
Euro-Office Launches as European Open-Source Alternative to Microsoft 365

Sovereign office suite Euro-Office launches June 9, 2026 as Europe open-source answer to Microsoft Office and Google Docs, integrated with Nextcloud Hub 26.

Read more
8 Jun 2026
Daily Cybersecurity Briefing
4 CVEs 4 threats 5 news items
Critical Vulnerabilities 4
CVE-2026-7312 CVSS 10.0 Progress Sitefinity CMS

Insufficiently protected credentials vulnerability allowing remote unauthenticated attackers to access credentials and restricted data.

Source
CVE-2026-41089 CVSS 9.8 Windows Netlogon (Microsoft)

Stack-based buffer overflow in Windows Netlogon service enabling remote code execution on domain controllers. Actively exploited in the wild.

Source
CVE-2026-10187 CVSS 9.8 Totolink N300RH Router

Critical stack-based buffer overflow in the Web Management Interface allowing remote code execution without authentication.

Source
CVE-2026-45748 CVSS 9.8 Termix (Web-based Server Management)

Unauthenticated OS command injection vulnerability via SSH tunnel command. Update to version 2.3.2 to fix.

Source
Malware & Threats 4
C0XMO (Gafgyt Botnet Variant) Botnet Targets: DD-WRT Routers & IoT Devices

New Gafgyt variant exploiting CVE-2021-27137 in DD-WRT firmware to hijack devices. Spreads across multiple CPU architectures and removes rival malware.

Source
Brickstorm Backdoor (UNC5221) Backdoor/APT Targets: Microsoft 365, US Organizations

Chinese espionage group UNC5221 deploying Brickstorm backdoor to maintain persistent access to compromised Microsoft 365 environments.

Source
Silent Ransom Group (UNC3753 / Luna Moth) Ransomware Targets: Law Firms, Financial Services

Ransomware group using fake IT support calls and in-person visits to gain physical access to law firms. FBI and Google issued joint warning.

Source
Pushka Financial Malware / RAT Targets: Financial Institutions

IBM Trusteer discovered new financial malware with remote access trojan capabilities designed for on-device fraud.

Source
Security News 5
IBM Whistleblower Alleges Cover-Up of Chinese Hacks

Former IBM VP of Threat Intelligence filed a whistleblower lawsuit alleging IBM and AT&T concealed multiple breaches by Chinese hackers, including 56,000+ network hits.

Read more
OpenAI Launches ChatGPT Lockdown Mode

New feature limits outbound ChatGPT requests to reduce prompt injection data exfiltration risk. Rolled out June 5 to all ChatGPT accounts.

Read more
Cisco Warns of 7th SD-WAN Zero-Day in 2026

CVE-2026-20245 (CVSS 7.8) allows authenticated local attackers to execute arbitrary commands as root on Cisco Catalyst SD-WAN Manager. Actively exploited, no patch available.

Read more
Claude Code MCP Traffic Hijacking Discovered

Researchers detail a five-step attack chain that silently redirects Claude Code MCP traffic through attacker-controlled servers to steal OAuth tokens.

Read more
TechCrunch: Worst Breaches of 2026 So Far

Mid-year roundup covering DOGE data breach, critical energy/water system hacks, FBI surveillance system compromise, and Telus breach (700TB stolen by ShinyHunters).

Read more
5 Jun 2026
Daily Cybersecurity Briefing
9 CVEs 4 threats 7 news items
Critical Vulnerabilities 9
CVE-2026-9311 CVSS 9.0 IBM WebSphere Application Server 8.5 & 9.0

Remote Code Execution via security control bypass. Attacker can bypass security controls and execute arbitrary code.

Source
CVE-2026-9319 CVSS 9.0 IBM WebSphere Application Server 8.5 & 9.0

Remote Code Execution via deserialization of untrusted data in JAX-WS endpoints with WS-Security.

Source
CVE-2026-8644 CVSS Critical (IBM SIR) IBM WebSphere Application Server 8.5 & 9.0

Identity spoofing vulnerability allowing attacker to impersonate legitimate users.

Source
CVE-2026-20230 CVSS 8.6 (Cisco SIR: Critical) Cisco Unified Communications Manager

Unauthenticated SSRF vulnerability allowing file writes. PoC exploit code publicly available. No workarounds.

Source
CVE-2026-10868 CVSS Critical MISP Threat Intelligence Platform

Mass assignment vulnerability in MISP user edit functionality due to insufficient filtering.

Source
CVE-2026-42897 CVSS KEV (Active Exploitation) Microsoft Exchange Server

XSS vulnerability actively exploited. Added to CISA Known Exploited Vulnerabilities catalog May 15, 2026.

Source
CVE-2025-48595 CVSS KEV (Active Exploitation) Android Framework

Zero-day actively exploited. Patched in Google June 2026 Android Security Update. Added to CISA KEV on June 3, 2026.

Source
CVE-2022-0492 CVSS 7.0 Linux Kernel

Improper authentication privilege escalation flaw added to CISA KEV. Federal agencies required to patch by June 5, 2026.

Source
CVE-2026-23479 CVSS High (RCE) Redis 7.2.0+

Use-after-free RCE vulnerability discovered by autonomous AI security tool. Affects all stable versions since Redis 7.2.0.

Source
Malware & Threats 4
Miasma Supply Chain / Credential-Stealing Worm Targets: Red Hat Hybrid Cloud Console / npm ecosystem users

Compromised 32+ packages (90+ versions) under @redhat-cloud-services npm namespace. Steals GitHub credentials, cloud platform keys, SSH keys, and npm tokens. Auto-propagates through CI/CD environments.

Source
WeedHack Malware-as-a-Service / Infostealer Targets: Minecraft players (gaming community)

Large-scale campaign infecting over 116,000 systems since January 2026. Distributed via YouTube SEO poisoning and fake mod downloads. MaaS platform costs as little as $5/month. 2,000-3,000 new infections daily.

Source
Atlas RAT (TA4922) Remote Access Trojan (RAT) Targets: European organizations (UK, Germany)

Chinese-speaking cybercrime group expands to Europe. Deploys previously undocumented Atlas backdoor using credential phishing and social engineering.

Source
DesckVB RAT Remote Access Trojan (RAT) Targets: General targets via malspam emails

Abuses Google's DoubleClick ad platform to deliver RAT via 5-stage infection chain. Evades traditional detection by routing traffic through legitimate Google domains.

Source
Security News 7
HTTP/2 Bomb DoS Attack Crashes Major Web Servers

Autonomous AI tool (Codex) discovers HTTP/2 Bomb DoS exploit affecting NGINX, Apache HTTPD, IIS, Envoy, Cloudflare Pingora. Single connection holds 32GB memory in 20 seconds. NGINX patched; Apache not yet.

Read more
Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

Google patches 124 Android vulnerabilities including actively exploited zero-day CVE-2025-48595 in Framework component. CISA adds to KEV with June 5 remediation deadline.

Read more
CISA Adds Android Zero-Day and Linux Kernel Flaw to KEV Catalog

CISA adds CVE-2025-48595 (Android) and CVE-2022-0492 (Linux Kernel) to Known Exploited Vulnerabilities catalog. Federal agencies ordered to patch by June 5, 2026.

Read more
Cisco Warns of Critical Unified CM SSRF Flaw with Public PoC Exploit

CVE-2026-20230 allows unauthenticated SSRF in Cisco Unified Communications Manager. PoC exploit code publicly available. No workarounds available.

Read more
ShinyHunters Escalates Instructure/Canvas Extortion Campaign

ShinyHunters continues targeting Instructure's Canvas LMS, claiming 275M records stolen. Hackers defaced Canvas login pages for multiple schools. Ongoing threat to educational institutions.

Read more
Autonomous AI Tool Discovers 2-Year-Old Redis RCE Vulnerability

CVE-2026-23479: Use-after-free RCE in Redis undetected for over 2 years. Found by autonomous AI security tool. Affects all versions since Redis 7.2.0.

Read more
Red Hat npm Supply Chain Attack: Miasma Credential-Stealing Worm

32+ @redhat-cloud-services npm packages compromised. Worm-like malware steals credentials from CI/CD environments. Microsoft, Wiz, Snyk publish analysis.

Read more
4 Jun 2026
Daily Cybersecurity Briefing
3 CVEs 3 threats 5 news items
Critical Vulnerabilities 3
CVE-2026-41089 CVSS 9.8 Windows Netlogon (Windows Server 2012-2025)

Critical stack buffer overflow in Windows Netlogon allowing remote code execution. Actively exploited in the wild with Belgium CCB warnings issued.

Source
CVE-2026-10061 CVSS 9.8 TRENDnet TEW-432BRP (firmware 3.10B20)

Remote command injection in formWPS function (/goform/formWPS). Unauthenticated remote attackers can execute arbitrary commands.

Source
CVE-2025-34291 CVSS 9.4 Langflow

Origin validation vulnerability added to CISA KEV catalog on May 22, 2026. Evidence of active exploitation; federal agencies required to patch by June 4, 2026.

Source
Malware & Threats 3
Miasma Supply Chain Worm Targets: Red Hat Cloud Services npm ecosystem

Compromised 90+ versions of @redhat-cloud-services npm packages. Malicious preinstall hook steals credentials and spreads via trusted CI/CD workflows. Linked to Mini Shai-Hulud malware family.

Source
GammaWorm / GammaSteel / GammaPhish APT Malware Suite (Gamaredon) Targets: Ukraine

Russian APT group Gamaredon exploiting WinRAR vulnerability. GammaPhish (HTA payload) retrieves VB Script dropping GammaWorm (persistence) and GammaSteel (data theft).

Source
JINX-0164 New Threat Actor Targets: Cryptocurrency firms / developers

Active since mid-2025. Uses fake LinkedIn recruiter messages and social engineering to target crypto developers with custom macOS Python-based malware for digital asset theft.

Source
Security News 5
"HTTP/2 Bomb" DoS Attack Crashes Web Servers in Seconds

New single-machine DoS technique exploiting HTTP/2 stream handling. nginx patched; Apache patch still pending. Discovered by OpenAI Codex agent under Calif researchers.

Read more
Google June 2026 Android Update Patches 124 Flaws Including Actively Exploited Zero-Day

124 Android vulnerabilities patched. CVE-2025-48595 (Framework component) under active exploitation. Affects Samsung Galaxy and Pixel devices.

Read more
CIFSwitch (CVE-2026-46243) — 19-Year-Old Linux Kernel Root Privilege Escalation

Local privilege escalation in Linux kernel CIFS subsystem. Allows low-privileged users to gain root. PoC exploit code publicly released. Affects multiple distributions.

Read more
CISA Adds Android and Linux Kernel Flaws to Known Exploited Vulnerabilities Catalog

June 3, 2026: CISA added actively exploited Android and Linux kernel vulnerabilities to KEV, mandating federal agencies to patch.

Read more
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Actively Exploited

Authentication bypass in Palo Alto Networks PAN-OS GlobalProtect VPN (CVSS 7.8). Allows unauthorized VPN connections. Rapid7 discovered active exploitation in the wild.

Read more
3 Jun 2026
Daily Cybersecurity Briefing
4 CVEs 3 threats 4 news items
Critical Vulnerabilities 4
CVE-2026-42826 CVSS 10.0 Microsoft Azure DevOps

Critical information disclosure vulnerability allowing unauthenticated remote attackers to disclose sensitive information over a network. CVSS v3.1 vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.

Source
CVE-2026-0257 CVSS 9.1 Palo Alto Networks PAN-OS GlobalProtect

Authentication bypass in GlobalProtect portal and gateway. Actively exploited in the wild since May 17, 2026. Added to CISA KEV catalog. Enables unauthorized VPN access.

Source
CVE-2026-48172 CVSS 9.8 LiteSpeed cPanel Plugin

Privilege escalation vulnerability (possibly to root) in LiteSpeed User-End cPanel Plugin before v2.4.5. Actively exploited in the wild in May 2026. Added to CISA KEV.

Source
CVE-2026-8206 CVSS 9.8 Kirki WordPress Plugin

Unauthenticated privilege escalation via account takeover in Kirki Freeform Page Builder. Affects ~150,000 WordPress sites. Allows attacker to reset any user's password to attacker-controlled email.

Source
Malware & Threats 3
Miasma (Mini Shai-Hulud Variant) Supply Chain Worm Targets: Red Hat Cloud Services npm ecosystem

Compromised 30+ official @redhat-cloud-services npm packages on June 1, 2026. Malicious preinstall hook steals credentials. Tied to threat actor TeamPCP.

Source
AUDIOFIX Python Infostealer Targets: macOS users

Fake audio fix utility that extracts stored browser credentials, SSH keys, and cryptocurrency wallets from compromised macOS systems.

Source
EvilTokens / Device Code Phishing Kits Phishing-as-a-Service Targets: Global organizations using OAuth 2.0

Device code phishing attacks abusing OAuth 2.0 Device Authorization Grant flow have surged 37x in 2026. New phishing kits like EvilTokens enable low-sophistication attackers to hijack accounts.

Source
Security News 4
Google June 2026 Android Security Bulletin Patches 124 Flaws Including Actively Exploited Zero-Day

Google patched 124 Android vulnerabilities including CVE-2025-48595 (CVSS 8.4), a Framework component zero-day under limited targeted exploitation. Affects Android 14, 15, and 16.

Read more
CISA Adds Oracle WebLogic CVE-2024-21182 to Known Exploited Vulnerabilities Catalog

CISA added CVE-2024-21182 (CVSS 7.5) affecting Oracle WebLogic Server to its KEV catalog on June 1, 2026. The flaw allows unauthenticated attackers to take over affected servers via the T3 protocol.

Read more
CIFSwitch (CVE-2026-46243) — 19-Year-Old Linux Kernel Privilege Escalation Disclosed

A local privilege escalation vulnerability (CVSS 7.8) in the Linux kernel's CIFS/SMB client subsystem discovered via LLM-assisted research. Allows any low-privileged local user to escalate to root on affected distributions.

Read more
Nx Console Supply Chain Attack (CVE-2026-48027) Compromises VS Code Extension

Malicious version 18.95.0 of Nx Console VS Code extension published, stealing developer credentials. Affected organizations include OpenAI and Grafana. Added to CISA KEV catalog.

Read more
2 Jun 2026
Daily Cybersecurity Briefing
7 CVEs 5 threats 7 news items
Critical Vulnerabilities 7
CVE-2026-41089 CVSS 9.8 Microsoft Windows Netlogon (all supported Windows Server versions incl. Server 2025)

Stack-based buffer overflow in Windows Netlogon allows unauthenticated remote code execution on domain controllers. Belgium's CCB confirmed active exploitation in the wild. Patched in May 2026 Patch Tuesday — patch immediately.

Source
CVE-2026-8732 CVSS 9.8 WP Maps Pro WordPress Plugin

Critical vulnerability allows unauthenticated attackers to create administrative accounts on WordPress sites running vulnerable versions. Over 1,700 attacks blocked in the past 24 hours. Actively exploited.

Source
CVE-2026-40933 CVSS 9.9 Flowise AI (MCP Adapter)

Unsafe serialization of stdio commands in the MCP adapter allows attackers to add a malicious MCP stdio server with an arbitrary command, achieving OS-level code execution — often as root in containerized deployments. Public exploit code available.

Source
CVE-2026-35616 CVSS 9.1 FortiClient Endpoint Management Server (EMS)

Critical flaw actively exploited to deploy 'EKZ Infostealer' credential-stealing malware across managed endpoints via trusted endpoint management infrastructure.

Source
N/A (No CVE assigned) CVSS 9.4 Gogs Self-Hosted Git Service

Any authenticated Gogs user can achieve RCE by creating a pull request with a malicious branch name that injects --exec into git rebase during merge. No patch available.

Source
CVE-2026-26980 CVSS 9.4 Ghost CMS Content API

SQL injection in Ghost's Content API allowing unauthenticated data reads. Exploited to inject malicious JavaScript for ClickFix attacks on 700+ sites.

Source
CVE-2026-48172 CVSS 10.0 LiteSpeed User-End cPanel Plugin

Maximum-severity incorrect privilege assignment flaw. Any cPanel user (including compromised accounts) can run arbitrary scripts with root privileges. Under active exploitation.

Source
Malware & Threats 5
Miasma (Mini Shai-Hulud variant) Supply Chain Worm / Credential Stealer Targets: Developers using Red Hat @redhat-cloud-services npm packages

Over 30 npm packages compromised to distribute self-propagating credential-stealing worm. Uses install-time execution, credential harvesting, CI/CD targeting, and encrypted exfiltration.

Source
DriveSurge (ClickFix + FakeUpdate) Initial Access Broker / Malware Distribution Targets: Website visitors globally via thousands of compromised websites

Large-scale campaign using zTDS Traffic Distribution System to redirect visitors to ClickFix social engineering or FakeUpdate lures. Operates as pay-per-install model for follow-on attacks.

Source
codexui-android Token Stealer Token Stealer / Supply Chain Targets: OpenAI Codex developers (29,000+ weekly npm downloads)

Functional npm package advertised as OpenAI Codex remote web UI silently exfiltrates Codex authentication tokens. GitHub repo appears clean — malicious code only in npm package.

Source
Operation Dragon Weave (AdaptixC2) Cyber Espionage / APT (China-aligned) Targets: Czech Republic & Taiwan — government, research, technology, finance sectors

Spear-phishing with ZIP attachments delivering AdaptixC2 agent via Rust-based loader. Multi-stage infection chain for data exfiltration and remote control.

Source
WordPress Steam C2 Campaign Web Shell / Backdoor with C2 Targets: ~2,000 WordPress websites

Malware campaign hides C2 data in Steam Community profile comments — an evasive technique leveraging a legitimate platform to avoid detection.

Source
Security News 7
Dashlane Brute-Force Attack — Encrypted Vaults of <20 Users Downloaded

Dashlane disclosed a brute-force attack on May 31 targeting 2FA bypass. Fewer than 20 personal-plan users had encrypted vaults downloaded. Vaults remain encrypted; accounts secured.

Read more
Dutch Police Dismantle 17-Million-Device Botnet

Dutch authorities seized C2 servers tied to a botnet of 17+ million infected devices used to power a residential proxy network for cybercrime. Over 200 servers seized.

Read more
Hackers Used Meta's AI Support Bot to Hijack Instagram Accounts

High-profile Instagram accounts (Obama White House, US Space Force) briefly defaced after attackers tricked Meta's AI support chatbot into resetting credentials. Emergency patch deployed.

Read more
Microsoft's Zero-Day Legal Threats Spark Security Community Backlash

After researcher 'Chaotic Eclipse' published several zero-day exploits, Microsoft indicated criminal charges, sparking debate about responsible disclosure vs. legal intimidation.

Read more
Anthropic Opens Mythos AI to EU's ENISA via Project Glasswing

ENISA gains access to Anthropic's defensive cybersecurity initiative that has uncovered 10,000+ high/critical vulnerabilities in widely used software through AI-powered analysis.

Read more
CIFSwitch: 19-Year-Old Linux Kernel Privilege Escalation — PoC Released

Newly discovered Linux kernel vulnerability allows local privilege escalation to root by forging CIFS authentication key descriptions. PoC exploit code publicly released.

Read more
Spain Arrests Doxer Leaking Government Employee Data

Spanish National Police arrested an individual for leaking sensitive information about members of key state organizations including the National Cybersecurity Institute (INCIBE).

Read more
1 Jun 2026
Daily Cybersecurity Briefing
8 CVEs 5 threats 8 news items
Critical Vulnerabilities 8
CVE-2026-35616 CVSS 9.8 Fortinet FortiClient EMS 7.4.5–7.4.6

Pre-authentication API access bypass allows unauthenticated attackers to execute unauthorized code. Actively exploited to deploy EKZ Infostealer credential-stealing malware disguised as Fortinet endpoint updates. Patched in version 7.4.7.

Source
CVE-2026-0257 CVSS 9.1 Palo Alto Networks PAN-OS GlobalProtect

Authentication bypass in GlobalProtect portal and gateway allows unauthorized VPN connections. Under active exploitation since May 29. CISA KEV remediation deadline: June 1, 2026.

Source
CVE-2026-39987 CVSS 9.8 Marimo Python Notebook <= 0.20.4

Pre-authenticated RCE via /terminal/ws WebSocket endpoint lacking authentication. Attackers using LLM agents for post-exploitation including cloud credential extraction. Patched in 0.23.0.

Source
N/A (no CVE assigned) CVSS 9.4 Gogs Git Service (all versions — UNPATCHED)

Critical RCE allowing any authenticated user to execute code via malicious branch names injecting --exec flag into git rebase. No patch available.

Source
CVE-2026-9874 CVSS 9.6 Google Chrome (< 148.0.7778.216)

Use-after-free in Dawn (WebGPU) allows sandbox escape via crafted HTML page. Chromium severity: Critical. Update Chrome immediately.

Source
CVE-2026-8732 CVSS 9.8 WP Maps Pro WordPress Plugin <= 6.1.0

Privilege escalation via administrator account creation through AJAX handler. Actively exploited to create rogue admin accounts on WordPress sites.

Source
CVE-2026-4408 CVSS 9.0 Samba File Servers

Remote code execution via misconfigured 'check password script' feature in Samba file servers and classic domain controllers.

Source
CVE-2026-34311 CVSS 9.8 Oracle Hospitality OPERA 5 Property Services

Critical vulnerability affecting Oracle Hospitality OPERA 5 versions 5.6.19.24, 5.6.22, and 5.6.25.19.

Source
Malware & Threats 5
EKZ Infostealer Credential Stealer Targets: FortiClient EMS managed endpoints

Delivered via CVE-2026-35616 exploitation. Disguised as Fortinet endpoint updates, silently executed via PowerShell to steal credentials.

Source
GREYVIBE APT / Cyber Espionage Targets: Ukraine & Ukraine-related entities (military, government, civilian)

New Russia-linked threat actor using AI-powered attacks, spear-phishing, fake CAPTCHA pages, and custom malware. Active since August 2025.

Source
HTTPSpy / HelloDoor (Kimsuky) APT / Backdoor Targets: South Korean military and corporate entities

North Korean state-sponsored Kimsuky deploying HTTPSpy via fake security installers, alongside HelloDoor backdoor and VS Code tunnel abuse for C2.

Source
Malicious Sicoob.Sdk NuGet Supply Chain / Credential Stealer Targets: Brazilian developers using Sicoob banking APIs

Fake NuGet package (versions 2.0.0-2.0.4) exfiltrates client IDs, PFX certificates, and Boleto payment data. Downloaded ~500 times.

Source
ChatGPT Share Link Malware Phishing / Malware Delivery Targets: General internet users

Threat actors abuse ChatGPT share links to host fake outage pages that deliver malware, exploiting trust in the chatgpt.com domain.

Source
Security News 8
Dutch Authorities Dismantle 17-Million-Device Botnet (Asocks)

Dutch Politie and NCSC took down a botnet of 17M+ infected devices used as residential proxies. Over 200 servers in the Netherlands seized.

Read more
Microsoft Criticizes Public Zero-Day Disclosures, Removes Researcher's GitHub Account

Microsoft condemned 'Chaotic Eclipse' for disclosing Windows Defender and BitLocker zero-days without coordinated disclosure. GitHub account removed.

Read more
Carnival Data Breach Exposed 6 Million People

Carnival Corporation disclosed a breach affecting approximately 6 million individuals with personal and health-related data exposed.

Read more
LA Metro Cyberattack Linked to Iranian State-Sponsored Hackers

The Los Angeles Metro transit system cyberattack has been attributed to Iranian state-sponsored threat actors.

Read more
California AG Sues 23andMe Over 2023 Data Breach

California's Attorney General filed suit against 23andMe for failing to protect user data including health information in the 2023 breach.

Read more
2,000+ Exposed Vibe-Coded Apps Leak Sensitive Corporate Data

Red Access found 380K+ public web assets built with AI coding platforms; 2,000+ contained sensitive corporate data without access controls.

Read more
Google Chrome Adds Session Cookie Theft Protection for All Users

Chrome rolled out session cookie theft protection to prevent session hijacking attacks across all users.

Read more
Russian Spies Aggressively Seeking Western Technology

Officials report Russian intelligence increasingly targeting Western tech companies as sanctions bite, with heightened cyber espionage activity.

Read more
29 May 2026
Daily Cybersecurity Briefing
3 CVEs 5 threats 5 news items
Critical Vulnerabilities 3
CVE-2026-GOGS CVSS 9.4 Gogs Git Service

Unpatched zero-day RCE — any authenticated user can achieve remote code execution via malicious branch name injection in git rebase

Source
CVE-2026-35616 CVSS 9.1 FortiClient EMS

Actively exploited pre-auth API bypass delivering 'EKZ' credential stealer. Patch available (7.4.7+)

Source
Multiple CVSS 9.0+ Microsoft Windows

6 zero-day vulnerabilities disclosed without coordination — BlueHammer, RedSun, and UnDefend under active exploitation

Source
Malware & Threats 5
GreyVibe APT Targets: Ukraine

Russia-linked APT using ChatGPT/Gemini across all attack phases

Source
JINX-0164 Social Engineering Targets: Crypto firms

Fake recruiter lures delivering macOS malware

Source
BTMOB RAT-as-a-Service Targets: Android users

Android RAT with custom phishing builder ($700/mo)

Source
Grandoreiro Banking Trojan Targets: Portugal, Spain, Mexico

Banking trojan campaign targeting Iberian and Latin American banks

Source
EKZ Credential Stealer Targets: FortiClient EMS users

New credential stealer delivered via FortiClient EMS exploit

Source
Security News 5
Carnival Cruise Breach Exposes ~6 Million People

Major data breach at Carnival Corporation affecting approximately 6 million customers and employees

Read more
IBM/Red Hat Launch $5B 'Project Lightwell'

Massive investment in open-source supply chain security infrastructure

Read more
Google Launches AI Threat Defense Platform

New AI-powered platform for enterprise threat detection and response

Read more
FBI Warns of 300+ Fake FIFA World Cup Phishing Sites

FBI alert about phishing campaign targeting football fans ahead of 2026 World Cup

Read more
GlassWorm Botnet C2 Takedown

Joint operation by CrowdStrike, Google, and Shadowserver takes down major botnet command infrastructure

Read more