Cybersecurity Daily Briefings

Critical vulnerabilities, active threats, and security news — curated for professionals.

Updated every workday at 08:00 CET
25 Jun 2026
Daily Cybersecurity Briefing
8 CVEs 4 threats 6 news items
Critical Vulnerabilities 8
CVE-2026-34910 CVSS 10.0 Ubiquiti UniFi OS

Improper input validation in UniFi OS enabling remote code execution. Added to CISA KEV June 23 — actively exploited.

Source
CVE-2026-45657 CVSS 9.8 Windows Kernel (Windows 11, Server)

Critical Windows Kernel remote code execution vulnerability patched in June 2026 Patch Tuesday.

Source
CVE-2026-44815 CVSS 9.8 Windows DHCP Client Service

Stack-based buffer overflow RCE in Windows DHCP Client Service.

Source
CVE-2026-45447 CVSS 9.8 OpenSSL (all branches 1.0.2-3.4)

Heap use-after-free in PKCS7_verify() enabling potential RCE. Patched June 2026.

Source
CVE-2026-35273 CVSS 9.8 Oracle PeopleSoft PeopleTools

Unauthenticated RCE actively exploited by ShinyHunters in education sector campaigns.

Source
CVE-2026-41089 CVSS 9.8 Windows Netlogon

Stack-based buffer overflow allowing unauthenticated RCE on Domain Controllers. Actively exploited.

Source
CVE-2026-48579 CVSS 9.1 Microsoft Exchange Online

Critical information disclosure vulnerability in Exchange Online.

Source
CVE-2026-39955 CVSS 9.8 TBD

Critical severity vulnerability published June 24, 2026. NVD analysis pending.

Source
Malware & Threats 4
OXLOADER / CastleStealer Loader / Infostealer Targets: Windows users via malicious Google Ads

New malware loader evading detection via .reloc section abuse and anti-VM checks to deliver CastleStealer infostealer. Uses fake Node.js ads and Storj-hosted payloads.

Source
ShinyHunters - Education Campaign Extortion / Data Theft Targets: Universities globally (University of Nottingham confirmed)

Active compromise campaign via CVE-2026-35273 (Oracle PeopleSoft zero-day). Mandiant/Google Threat Intelligence identified campaign.

Source
Operation Endgame Takedown Law Enforcement Action Targets: SocGholish, Amadey, StealC malware networks

Europol, Microsoft DCU, Dutch Police disrupted major malware networks. Servers taken offline June 24, 2026.

Source
ShinyHunters - Kodak Breach Extortion / Data Theft Targets: Kodak

2.2M records stolen. Kodak confirmed breach after ShinyHunters threatened leak.

Source
Security News 6
CISA Adds 4 Actively Exploited Vulnerabilities to KEV (June 23)

CISA added Lantronix EDS5000 and Ubiquiti UniFi OS flaws to KEV. Federal agencies must patch by June 26.

Read more
Tata Electronics Data Breach — Apple/Tesla Supplier Hit

Supplier confirmed cyber incident after World Leaks group claimed theft of Apple factory data and Tesla trade secrets.

Read more
Microsoft June 2026 Patch Tuesday: Record 206 Flaws

206 vulnerabilities patched including 39 Critical and 6 zero-days (1 actively exploited).

Read more
Chrome 149 Patches Record 429 Security Flaws

Includes 22 critical flaws. One zero-day (CVE-2026-11645) exploited in the wild.

Read more
Cisco UC Manager SSRF Actively Exploited to Deploy Webshells

CVE-2026-20230 now actively exploited to drop webshells and gain root access on Cisco Unified Communications Manager.

Read more
Windows Netlogon CVE-2026-41089 Active Exploitation Confirmed

Belgian government confirms active exploitation of critical Netlogon RCE. Urgent patching advised.

Read more
24 Jun 2026
Daily Cybersecurity Briefing
11 CVEs 4 threats 6 news items
Critical Vulnerabilities 11
CVE-2026-45657 CVSS 9.8 Windows Kernel

Use-after-free vulnerability allowing remote, unauthenticated code execution over network. Patched in June 2026 Patch Tuesday.

Source
CVE-2026-35273 CVSS 9.8 Oracle PeopleSoft PeopleTools

Unauthenticated SSRF-to-RCE vulnerability actively exploited by ShinyHunters. Oracle out-of-band security alert released.

Source
CVE-2026-50751 CVSS 9.3 Check Point VPN (IKEv1)

Authentication bypass in Remote Access VPN and Mobile Access. Actively exploited by Qilin ransomware affiliates since May 7.

Source
CVE-2026-41700 CVSS HIGH Spring for GraphQL

Cross-Site WebSocket Hijacking in Spring for GraphQL applications with WebSocket transport enabled.

Source
CVE-2026-40988 CVSS HIGH Spring Security SAML 2.0

Unbounded DEFLATE inflation in SAML 2.0 Service Provider allowing DoS via crafted SAML assertions.

Source
CVE-2026-40993 CVSS HIGH Spring Security SAML 2.0

Unfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB database entries.

Source
CVE-2026-48618 CVSS 7.5 Node.js (22.x, 24.x, 26.x)

TLS hostname verification bypass via improper Unicode dot separator handling leading to unauthorized connections.

Source
CVE-2026-48934 CVSS MEDIUM Node.js

TLS host identity verification bypass via session reuse with different servername.

Source
CVE-2026-34040 CVSS HIGH Docker Engine / Moby

Authorization plugin bypass (AuthZ) affecting container security. Patched in Docker Engine 29.3.1.

Source
CVE-2026-43407 CVSS N/A Linux kernel (libceph)

Potential out-of-bounds access in ceph_handle_auth_reply() function, could lead to memory corruption or DoS.

Source
CVE-2026-50656 CVSS 7.8 Microsoft Defender (RoguePlanet)

Elevation of privilege in Microsoft Malware Protection Engine. Zero-day publicly disclosed; turns Defender quarantine into attack vector.

Source
Malware & Threats 4
WhatsApp VBS Malware Campaign Crimeware Targets: WhatsApp Web/Desktop users, primarily SEA businesses

Large-scale campaign distributing malicious VBScript files via WhatsApp direct messages. Delivers RATs and info-stealers.

Source
FortiBleed Credential Compromise Campaign Targets: Fortinet FortiGate firewalls across 194 countries

Ongoing large-scale campaign exploiting CVE-2026-24858 and default credentials. Thousands of device credentials leaked.

Source
Miasma Supply Chain Worm Targets: NPM/CI-CD ecosystems, Red Hat Cloud Services users

npm supply chain attack compromising 90+ Red Hat packages. Worm-like self-propagation through CI/CD and Azure repos. Credential-stealing.

Source
DragonForce / Backdoor.Turn RAT / Ransomware Targets: Major US services firm

Go-based RAT abusing Microsoft Teams TURN relay servers to mask C2 traffic. Used by DragonForce ransomware affiliates.

Source
Security News 6
Five Eyes Warn AI Models Could Launch Major Cyberattacks Within Months

US, UK, Canada, Australia, NZ intelligence agencies warn cutting-edge AI could overwhelm defenses of governments and businesses within months.

Read more
Tata Electronics Data Breach Exposes Apple, Tesla Trade Secrets

Indian Apple/Tesla supplier hit by cyberattack. Threat actors claim theft of factory data, supplier documents, and trade secrets.

Read more
ExtraHop: Nearly Half of Ransomware Victims Suffer Data Theft Before Detection

Report finds 48% of ransomware victims had data exfiltrated before ransomware was detected. Emphasizes need for faster detection.

Read more
Microsoft June 2026 Patch Tuesday: Record 200+ Vulnerabilities Fixed

Microsoft patched 200+ vulnerabilities including 33 critical. Highlights: CVE-2026-45657 (Windows Kernel RCE CVSS 9.8), Graphics Component RCEs.

Read more
Node.js Patches 12 CVEs Across All Active Release Lines

June 18 security releases addressed 12 CVEs across Node.js 22.x, 24.x, 26.x. Includes TLS auth bypass and session reuse flaws.

Read more
INC Ransom Ransomware Hits US Healthcare Provider

Horizon Eye Care (US ophthalmology provider) fell victim to INC Ransom group. Discovered June 24, 2026.

Read more
23 Jun 2026
Daily Cybersecurity Briefing
5 CVEs 4 threats 7 news items
Critical Vulnerabilities 5
CVE-2026-10520 CVSS 10.0 Ivanti Sentry

OS Command Injection allowing remote unauthenticated attacker to execute arbitrary commands. Actively exploited.

Source
CVE-2026-10523 CVSS 9.9 Ivanti Sentry

Authentication Bypass (CWE-288) allowing remote unauthenticated attacker to create arbitrary admin accounts.

Source
CVE-2026-44815 CVSS 9.8 Windows DHCP Client Service

Stack-based buffer overflow allowing remote code execution over the network with low attack complexity.

Source
CVE-2026-20253 CVSS 9.8 Splunk Enterprise

Missing Authentication for Critical Function in PostgreSQL sidecar. Unauthenticated RCE. Added to CISA KEV June 18.

Source
CVE-2026-42897 CVSS N/A (Critical) Microsoft Exchange Server

Zero-day spoofing vulnerability in Exchange OWA, actively exploited in attacks. Patched in June 2026 Patch Tuesday.

Source
Malware & Threats 4
INC Ransomware Ransomware-as-a-Service Targets: Global healthcare, finance, and downtime-sensitive sectors

830+ victims since 2023. Rewritten in Rust. Exploits Citrix NetScaler and Veeam backup vulnerabilities. Credential dumping against backup deployments.

Source
SocGholish (FakeUpdates) Malware distribution network Targets: Global - compromised legitimate websites

Disrupted via Operation Endgame (FBI, Dutch Police, Europol). ~15,000 infected websites cleaned. Hunt ongoing for group members.

Source
DriveSurge Initial Access Broker (IAB) Targets: Global via compromised websites

Uses ClickFix and fake browser update redirects. Hijacked thousands of legitimate websites. Delivers Windows and macOS malware.

Source
Search Your Target Market Underground credential marketplace Targets: Global organizations

Emerging underground market that searches stolen credential databases for specific companies/domains. Midpoint in infostealer-to-account-takeover chain.

Source
Security News 7
Klue OAuth Breach — Hundreds of Enterprise Victims

Icarus threat actor exploited dormant OAuth tokens from a defunct Klue integration to access Salesforce CRM data at hundreds of clients including multiple security vendors.

Read more
iRhythm Cyberattack — Patient Data Stolen

Healthcare device maker iRhythm disclosed data breach after hackers accessed third-party-hosted applications. Patient health information stolen, ransom demanded.

Read more
CISA Adds 4 CVEs to KEV Catalog

CISA added Cisco Catalyst SD-WAN Manager (CVE-2026-20245), Chrome V8, Arista EOS, and Splunk Enterprise (CVE-2026-20253) to Known Exploited Vulnerabilities catalog. Federal agencies required to patch by June 23, 2026.

Read more
Microsoft June 2026 Patch Tuesday — Record 204+ Vulnerabilities Fixed

Record-breaking Patch Tuesday: 204-209 vulnerabilities patched including 6 zero-days (3 publicly disclosed), 38+ critical flaws across Windows, Office, Exchange, Azure, Hyper-V.

Read more
RoguePlanet — Microsoft Defender Zero-Day Grants SYSTEM Access

Researcher disclosed Microsoft Defender zero-day granting SYSTEM privileges via race condition in quarantine feature. Permanent patch in progress.

Read more
SAP June 2026 Patch Day — 4 Critical Fixes

SAP released 15 security patches including 4 critical for NetWeaver AS ABAP, SAP Kernel, NetWeaver AS Java, and Commerce Cloud.

Read more
Google Android June 2026 Update — 124 Flaws Fixed

Google patched 124 Android vulnerabilities including actively exploited zero-day CVE-2025-48595. 18 critical flaws in framework, system, and Qualcomm components.

Read more
22 Jun 2026
Daily Cybersecurity Briefing
3 CVEs 3 threats 7 news items
Critical Vulnerabilities 3
CVE-2026-9698 CVSS 9.8 Perl DBI module (< 1.648)

Critical buffer overflow vulnerability in Perl DBI error message handling. Error messages written to a 200-byte buffer without length limit, allowing attackers who can influence error text to trigger a buffer overflow.

Source
CVE-2026-45460 CVSS 9.x Microsoft Office

Critical out-of-bounds read/information disclosure vulnerability in Microsoft Office. An unauthorized attacker can disclose information locally via a buffer over-read.

Source
CVE-2026-47928 (APSB26-64) CVSS Critical Adobe ColdFusion 2025/2023

Critical improper input validation in Adobe ColdFusion. Internet-facing servers should be patched as emergency.

Source
Malware & Threats 3
Prinz Eugen Ransomware Go-based Ransomware Targets: General business targets

New ransomware that prioritizes recent files, leaves no ransom note, extorts out-of-band.

Source
INC Ransomware (RaaS) Ransomware-as-a-Service Targets: Global organizations

INC evolved into one of the most active ransomware groups with 830+ victims.

Source
DragonForce/Backdoor.Turn Ransomware + RAT Targets: MS Teams users

First known malware to abuse Microsoft Teams TURN relay for C2 traffic blending.

Source
Security News 7
FortiBleed: 73,000+ Fortinet VPN Credentials Exposed

Campaign exposes credentials for 73,000+ FortiGate firewalls across 194 countries. Includes IPs, admin passwords, SSL VPN creds.

Read more
ShinyHunters Claims Council of Europe Breach

429,000+ documents stolen including 15 years of payroll data for 10,000+ staff across 46 member states.

Read more
University of Nottingham Hit by Cyberattack

Student data leaked via third-party breach. Linked to ShinyHunters. 8.8M records exposed.

Read more
Microsoft June 2026 Patch Tuesday

200+ flaws including 3 zero-days. Critical: Office info disclosure (CVE-2026-45460), AKS RCE (CVE-2026-32193).

Read more
iRhythm Cardiac Monitoring Patient Data Stolen

PHI and proprietary data stolen from third-party apps. Ransom demanded. Patient safety unaffected.

Read more
Node.js June 2026 Security Release

12 vulnerabilities patched including TLS auth bypass and AES DoS. Upgrades to OpenSSL 3.5.7, llhttp 9.4.2.

Read more
Adobe Critical ColdFusion Patch (APSB26-64)

Emergency patch for ColdFusion 2025/2023. CVE-2026-47928 critical input validation flaw.

Read more
19 Jun 2026
Daily Cybersecurity Briefing
11 CVEs 4 threats 7 news items
Critical Vulnerabilities 11
CVE-2026-48567 CVSS 10.0 Microsoft Azure HorizonDB

Authentication bypass by spoofing allowing unauthorized elevation of privileges over network.

Source
CVE-2026-21962 CVSS 10.0 Oracle HTTP Server / WebLogic Proxy Plug-in

Unauthenticated remote code execution via HTTP.

Source
CVE-2026-9698 CVSS 9.8 Perl DBI (Database Interface) module

Buffer overflow in error message handling — attackers influencing error text can trigger overflow. Versions < 1.648 affected.

Source
CVE-2026-26142 CVSS 9.8 Microsoft Component (June 2026 Patch Tuesday)

Remote Code Execution vulnerability, patched in June 2026 Patch Tuesday.

Source
CVE-2026-44815 CVSS 9.8 Microsoft DHCP Client Service

DHCP Client Service Remote Code Execution Vulnerability.

Source
CVE-2026-41855 CVSS High Spring Framework JMS

Remote Code Execution via unsafe deserialization in Jackson JMS message converters. Affects Spring Framework 5.3.0-7.0.7.

Source
CVE-2026-46300 CVSS High Linux Kernel (Fragnesia)

Container breakout via XFRM ESP-in-TCP privilege escalation affecting Docker, GKE, EKS.

Source
CVE-2026-34040 CVSS High Docker Engine

AuthZ bypass via padded requests enabling dangerous container creation. Fixed in Docker 29.3.1.

Source
CVE-2026-48579 CVSS 9.1 Microsoft Exchange Online

Information disclosure via improper authorization.

Source
CVE-2026-41940 CVSS Critical cPanel & WHM

Authentication bypass via CRLF injection. Actively exploited — 44,000+ servers compromised globally.

Source
Oracle June 2026 CPU CVSS 243 CVEs Oracle Products (multiple)

243 CVEs across 245 security updates including JD Edwards EnterpriseOne, Solaris, and more.

Source
Malware & Threats 4
NarwhalRAT RAT (Python) Targets: Victims of fake Microsoft Account security alerts

North Korean APT37/ScarCruft spreads Python RAT via phishing emails with fake Microsoft alerts. Capable of keystroke logging, screenshot capture, data exfiltration.

Source
FlutterShell Backdoor Targets: macOS users via Google/YouTube ads

Operation FlutterBridge — malvertising campaign delivering Flutter-based backdoor that passed Apple notarization.

Source
Qilin & Warlock Ransomware Targets: Global enterprises

BYOVD attacks disabling 300+ EDR drivers before deploying ransomware. Multi-stage attack chains.

Source
Miasma / Phantom Gyp Supply Chain Worm Targets: npm ecosystem

Self-propagating npm worm abusing native-addon build hooks via binding.gyp to steal CI/CD secrets and persist in GitHub.

Source
Security News 7
FORTIBLEED: Mass Compromise of 74,000+ Fortinet Firewalls Worldwide

Russian-speaking cybercriminal group harvested credentials from ~74,000 Fortinet FortiGate devices across 194 countries. Admin credentials being sold on criminal forums. Fortinet confirmed the credential harvesting campaign.

Read more
Kodak Data Breach — 2.2M Records Stolen by ShinyHunters

Kodak confirmed data breach after ShinyHunters claimed theft of 2.2M records of customer PII and internal corporate data.

Read more
Madison Square Garden / Knicks 45 GB Data Leak Published

ShinyHunters published 45 GB of MSG Sports data including VIP profiles, customer emails, and internal risk assessments.

Read more
CISA KEV Deadline TODAY: SolarWinds Serv-U CVE-2026-28318

CISA added SolarWinds Serv-U DoS vulnerability to KEV with mandatory federal remediation deadline of June 19, 2026.

Read more
Microsoft June 2026 Patch Tuesday: Record 206+ CVEs

Record-setting Patch Tuesday with 206+ CVEs including 38 Critical. CVSS 10.0 Azure HorizonDB vulnerability.

Read more
Oracle June 2026 CPU: 243 CVEs Patched

Largest Oracle CPU of 2026 with 245 security updates across Oracle product families.

Read more
Node.js June 18 Security Releases

Emergency security releases across all active release lines addressing vulnerabilities in llhttp and nghttp2 dependencies.

Read more
18 Jun 2026
Daily Cybersecurity Briefing
8 CVEs 3 threats 7 news items
Critical Vulnerabilities 8
CVE-2026-10520 CVSS 10.0 Ivanti Sentry

OS Command Injection allowing unauthenticated remote code execution. Actively exploited.

Source
CVE-2026-10523 CVSS 9.9 Ivanti Sentry

Authentication Bypass allowing remote creation of arbitrary admin accounts.

Source
CVE-2026-50751 CVSS 9.3 Check Point VPN

Authentication Bypass exploited by Qilin ransomware to compromise VPN deployments.

Source
CVE-2026-47928 CVSS 9.6 Adobe ColdFusion

Improper Input Validation allowing arbitrary code execution with no user interaction.

Source
CVE-2026-44963 CVSS 9.4 Veeam Backup & Replication v12

Remote Code Execution on Backup Server by authenticated domain user.

Source
CVE-2026-20253 CVSS 9.8 Splunk Enterprise

Unauthenticated remote code execution allowing full server compromise.

Source
CVE-2026-54420 CVSS 7.8 LiteSpeed cPanel Plugin

Privilege escalation via symlink following. Added to CISA KEV.

Source
CVE-2026-48907 CVSS 7.5 Joomla JCE (Widget Factory)

Improper access control allowing PHP code execution by unauthenticated users.

Source
Malware & Threats 3
easy-day-js (Mastra Supply Chain RAT) Supply Chain / RAT Targets: @mastra npm organization (140+ packages)

On June 17, @mastra npm org was compromised via typosquatted 'easy-day-js' dependency, delivering cross-platform RAT to 140+ packages.

Source
ShinyHunters (Kodak) Extortion / Data Breach Targets: Eastman Kodak

ShinyHunters claimed 2.2M+ records from Kodak. Deadline expired June 18. Kodak confirmed breach.

Source
Qilin Ransomware Ransomware Targets: Check Point VPN deployments

Qilin affiliates exploiting CVE-2026-50751 Check Point VPN auth bypass to gain initial access.

Source
Security News 7
Kodak confirms data breach after ShinyHunters deadline

Eastman Kodak confirmed data breach involving 2.2M+ records as ShinyHunters extortion deadline expired.

Read more
Microsoft June 2026 Patch Tuesday: 206 flaws fixed

37 critical, 3 zero-days patched across Windows, Office, Defender, and Edge.

Read more
CISA adds two new KEV entries: CVE-2026-54420 & CVE-2026-48907

LiteSpeed cPanel and Joomla JCE vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog.

Read more
Mastra npm supply chain attack compromises 140+ packages

A single hijacked maintainer account backdoored the entire @mastra npm scope with cross-platform RAT malware.

Read more
Ivanti Sentry critical vulnerabilities actively exploited

Two pre-auth CVEs (CVE-2026-10520, CVE-2026-10523) in Ivanti Sentry under active exploitation with CISA KEV addition.

Read more
Oracle June 2026 Critical Security Patch Update released

16 new security patches for Oracle Enterprise Manager, 6 remotely exploitable.

Read more
Google Android June 2026: 124 flaws, 1 exploited zero-day

June 2026 Android security update includes patch for actively exploited zero-day alongside 123 other fixes.

Read more
17 Jun 2026
Daily Cybersecurity Briefing
6 CVEs 4 threats 6 news items
Critical Vulnerabilities 6
CVE-2026-50751 CVSS 9.3 Check Point Remote Access VPN / Mobile Access

Authentication bypass vulnerability in deprecated IKEv1 VPN protocol, actively exploited by Qilin ransomware affiliates. Check Point released urgent hotfix.

Source
CVE-2026-10520 CVSS 10.0 Ivanti Sentry

OS Command Injection vulnerability allows remote unauthenticated attackers to execute arbitrary commands. Affects versions before R10.5.2, R10.6.2, R10.7.1.

Source
CVE-2026-10523 CVSS 9.9 Ivanti Sentry

Authentication bypass vulnerability in Ivanti Sentry allowing remote attackers to bypass security controls.

Source
CVE-2026-35273 CVSS 9.8 Oracle PeopleSoft PeopleTools

Unauthenticated SSRF-to-RCE zero-day vulnerability exploited by ShinyHunters to breach 100+ universities and the Council of Europe. Oracle out-of-band alert on June 10.

Source
CVE-2026-45657 CVSS 9.8 Windows Kernel

Use-after-free vulnerability allowing unauthenticated remote code execution over a network. Wormable class flaw, part of June 2026 Patch Tuesday.

Source
CVE-2026-34040 CVSS 9.9 Docker Engine (Moby)

Authorization plugin (AuthZ) bypass via oversized API request bodies allowing attackers to silently disable security policies. Patched in Moby 29.3.1.

Source
Malware & Threats 4
NarwhalRAT RAT Targets: Korean users, academia, think tanks

North Korean APT37 (ScarCruft) delivers Python RAT via fake Microsoft Account alert spear-phishing emails with ZIP attachments. Multi-stage infection chain targets data theft.

Source
Qilin Ransomware Ransomware Targets: Global enterprises (via Check Point VPN appliances)

Qilin affiliates actively exploiting CVE-2026-50751 authentication bypass in Check Point VPN deployments for initial access. Post-compromise lateral movement confirmed.

Source
GhostTree Evasion Technique Targets: Windows systems worldwide

Abuses NTFS junctions to create recursive directory loops, causing Windows Defender and EDR scanners to hang indefinitely, leaving malware undetected.

Source
ShinyHunters Campaign Data Extortion Targets: Higher education, Council of Europe, Oracle customers

Exploiting CVE-2026-35273 (PeopleSoft zero-day) at scale. Breached 100+ universities (450K+ student records) and Council of Europe (297 GB data including payroll).

Source
Security News 6
Record-Breaking June 2026 Patch Tuesday: 206 Microsoft CVEs, 39 Critical

Microsoft released 206 patches including 39 Critical, 3 zero-days, and a wormable Windows Kernel RCE (CVE-2026-45657, CVSS 9.8). Combined with Adobe (123 CVEs) and Chrome, over 500 CVEs for the month.

Read more
Novo Nordisk Data Breach Exposes Clinical Trial Patient Data

Pharmaceutical giant (Ozempic maker) disclosed cyberattack on June 11. Hackers breached internal IT systems and stole pseudonymized clinical trial patient data.

Read more
iRhythm Ransomware Attack: Cardiac Patient Data Stolen

Cardiac monitoring device maker hit on June 9. Threat actors obtained patient data and proprietary information, issued ransom demand. No impact on device safety.

Read more
Council of Europe Breached via PeopleSoft Exploit

ShinyHunters claims 297 GB data theft including payroll and employee personal information via CVE-2026-35273. Council investigating.

Read more
Node.js High-Severity Security Release Today (June 17, 2026)

Node.js released HIGH severity security updates for 26.x, 24.x, and 22.x release lines. Specific CVEs pending publication. Immediate upgrade recommended.

Read more
Dutch Government Disrupts 17M-Device Botnet

Dutch authorities dismantled massive botnet of 17 million infected devices, seizing 200+ servers at a local hosting provider.

Read more
16 Jun 2026
Daily Cybersecurity Briefing
8 CVEs 6 threats 8 news items
Critical Vulnerabilities 8
CVE-2026-10520 CVSS 10.0 Ivanti Sentry

OS Command Injection allowing remote unauthenticated root-level RCE. Affects Ivanti Sentry before R10.5.2, R10.6.2, R10.7.1.

Source
CVE-2026-45657 CVSS 9.8 Windows Kernel

Use-after-free RCE vulnerability. Part of Microsoft June 2026 Patch Tuesday. Actively exploited as zero-day.

Source
CVE-2026-44815 CVSS 9.8 Windows DHCP Client Service

Stack-based buffer overflow allowing remote code execution. Part of Microsoft June 2026 Patch Tuesday.

Source
CVE-2026-9698 CVSS 9.8 Perl DBI Module (before 1.648)

Buffer overflow in error message handling. Attackers who can influence error text can trigger overflow. Affects all Perl DB applications.

Source
CVE-2026-35273 CVSS 9.8 Oracle PeopleSoft Enterprise PeopleTools

Unauthenticated RCE over HTTP. Actively exploited by ShinyHunters as zero-day before Oracle's June 10 patch.

Source
CVE-2026-20253 CVSS 9.8 Splunk Enterprise

Unauthenticated arbitrary file creation and truncation leading to RCE. Affects versions below 10.2.4 and 10.0.7.

Source
CVE-2026-47928 CVSS 9.6 Adobe ColdFusion (2023.19, 2025.8)

Improper input validation allowing arbitrary code execution with no user interaction. Part of APSB26-64.

Source
CVE-2026-50751 CVSS 9.8 Check Point VPN (IKEv1 Remote Access/Mobile Access)

Authentication bypass vulnerability under active exploitation by Qilin ransomware affiliates since early May 2026.

Source
Malware & Threats 6
Miasma (Shai-Hulud Miasma) Supply Chain Worm Targets: CI/CD, Developer Environments, npm ecosystem

Compromised 32+ @redhat-cloud-services npm packages. Preinstall hook steals cloud credentials, persists in dev tooling, spreads via dependency confusion.

Source
ShinyHunters (UNC6240) Data Theft / Extortion Group Targets: Universities using Oracle PeopleSoft

Exploiting Oracle PeopleSoft zero-day (CVE-2026-35273) to breach university systems, exfiltrate data, and demand extortion payments.

Source
Qilin Ransomware Affiliate Ransomware Targets: Check Point VPN users

Exploiting CVE-2026-50751 (Check Point VPN auth bypass) for initial access to corporate networks.

Source
Lalia Ransomware Ransomware Targets: General Targets

New ransomware strain discovered by CYFIRMA on underground forums.

Source
LockBit 5.0 Ransomware Targets: Wessels Logistics (Logistics Sector)

Ransomware attack on logistics company with data leak threats.

Source
VerdantBamboo (China-nexus APT) Cyber Espionage / APT Targets: Linux Appliances

Deploying BSD variant of BRICKSTORM backdoor plus PLENET/GRIMBOLT and AGENTPSD malware.

Source
Security News 8
Record Microsoft June 2026 Patch Tuesday — 206 flaws fixed including 39 critical, 6 zero-days

Microsoft patched a record 206 vulnerabilities across Windows, Office, and other products, including 3 actively exploited zero-days (CVE-2026-45657 Windows Kernel RCE, 2 Microsoft Defender flaws).

Read more
Oracle PeopleSoft Zero-Day Exploited by ShinyHunters Before Patch Available

CVE-2026-35273 (CVSS 9.8) actively exploited before Oracle's June 10, 2026 advisory. Multiple universities breached and extorted.

Read more
Check Point VPN Flaw Under Active Exploitation by Ransomware Gangs

CVE-2026-50751 (IKEv1 auth bypass) exploited since early May. Qilin ransomware affiliates linked to attacks against corporate VPNs.

Read more
Red Hat npm Supply Chain Attack (Miasma Worm) — 32+ Packages Compromised

Credential-stealing worm compromised official @redhat-cloud-services npm packages. Affects CI/CD pipelines and cloud credential security.

Read more
Critical Splunk Enterprise Vulnerability (CVE-2026-20253, CVSS 9.8)

Unauthenticated arbitrary file operations enabling RCE. Patched in Splunk Enterprise versions 10.2.4 and 10.0.7.

Read more
Google Patches 124 Android Vulnerabilities in June 2026 Security Update

Includes 6 critical severity flaws in Android 14, 15, and 16 covering system components, Framework, and kernel.

Read more
Adobe Releases Critical Patches for ColdFusion and Campaign Classic

APSB26-64 (ColdFusion) and APSB26-66 (Campaign Classic) address multiple critical RCE vulnerabilities. CVE-2026-47928 (CVSS 9.6) tops the list.

Read more
Ivanti Sentry Gets Emergency Patch for CVSS 10.0 Command Injection

CVE-2026-10520 allows remote unauthenticated attackers to execute OS commands as root on Ivanti Sentry appliances.

Read more
15 Jun 2026
Daily Cybersecurity Briefing
9 CVEs 7 threats 12 news items
Critical Vulnerabilities 9
CVE-2026-45657 CVSS 9.8 Windows Kernel

Use-after-free vulnerability enabling remote code execution over the network. Zero-day patched in June 2026 Patch Tuesday.

Source
CVE-2026-47291 CVSS 9.8 Windows HTTP.sys

Integer overflow/wraparound in HTTP.sys kernel-mode driver. Unauthenticated RCE via crafted HTTP requests.

Source
CVE-2026-44815 CVSS 9.8 Windows DHCP Client

Stack-based buffer overflow in DHCP Client. Attacker on same network triggers code execution via malicious DHCP response.

Source
CVE-2026-42904 CVSS 9.6 Windows TCP/IP

Heap-based buffer overflow in TCP/IP stack. Adjacent network attacker elevates privileges via crafted packets.

Source
CVE-2026-10520 CVSS 10.0 Ivanti Sentry

OS command injection vulnerability allowing remote unauthenticated attackers to achieve root-level RCE. Added to CISA KEV June 11.

Source
CVE-2026-50751 CVSS 9.8 Check Point IKEv1 VPN

Authentication bypass vulnerability in deprecated IKEv1 VPN protocol. Under active exploitation. CISA KEV June 8.

Source
CVE-2026-45602 CVSS 9.1 Windows DHCP Server

Tampering vulnerability in Windows DHCP Server enabling man-in-the-middle attacks.

Source
CVE-2026-34040 CVSS 9.0 Docker Engine

Authorization plugin (AuthZ) bypass. Single oversized HTTP request disables all authorization plugins. Affects 92% of enterprise deployments. Fixed in 29.3.1.

Source
CVE-2026-42985 CVSS 9.0 Remote Desktop Client

Heap-based buffer overflow RCE in Remote Desktop Client. Unauthenticated attacker executes code over network.

Source
Malware & Threats 7
Lalia Ransomware Ransomware Targets: Windows OS

New file-encrypting ransomware appending .lalia extension. Deletes Volume Shadow Copies to prevent recovery. Includes anti-analysis checks for sandbox/VMs.

Source
LxBase RAT Remote Access Trojan Targets: Windows OS, Global

Multi-stage malware employing batch/PowerShell scripts, living-off-the-land techniques, obfuscation, and anti-analysis.

Source
Seedworm (MuddyWater) APT Targets: US critical infrastructure (airport, bank, software company, NGO)

Iranian state-sponsored APT group active on networks of multiple US companies since February 2026.

Source
Transparent Tribe (APT36) APT / Cyber Espionage Targets: 30+ countries, aerospace/defense/gov/military

Pakistan-aligned cyber espionage group deploying customized XenoRAT variant targeting Afghan government entities.

Source
ShinyHunters Cybercriminal Group Targets: Global (healthcare, education, finance)

Voice phishing (vishing) campaigns compromising DentaQuest (2.6M), Instructure/Canvas (30M+), Charter (40M), and Carnival.

Source
Operation FlutterBridge Malvertising Targets: macOS users

New macOS malvertising campaign discovered by Unit 42 spreading malware via fake browser updates.

Source
RemusStealer / SessionGate Infostealer / Loader Targets: Global

Fake open-source project sites (Ghidra, dnSpy) used as lure in click-hijacking scheme delivering multiple malware families.

Source
Security News 12
Microsoft Patches Record 206 Flaws in June 2026 Patch Tuesday

32 critical vulnerabilities including 28 RCE flaws, three zero-days. Critical kernel RCE (CVE-2026-45657), HTTP.sys, DHCP Client, and TCP/IP flaws all network-exploitable.

Read more
Trump Issues Memo Revamping Cybersecurity Policy for National Security Systems

New national security memorandum rescinds Biden-era instruction, focuses on cloud-based environment security requirements.

Read more
CISA Issues Binding Operational Directive on Risk-Based Vulnerability Management

New directive requires federal agencies to prioritize vulnerabilities based on risk rather than severity alone.

Read more
House Appropriators Cut CISA Budget by $252.7 Million

FY2027 DHS budget bill reduces CISA funding to $2.35B. Also seeks guidance on agentic AI security and SBOM opportunities.

Read more
EPSS v5 Goes Live — 23% Model Improvement

Exploit Prediction Scoring System version 5 launches June 15, 2026 with significant improvements in predicting vulnerability exploitation likelihood.

Read more
NIST Finalizes Ransomware Risk Management Profile of CSF 2.0

New guidance helps organizations prepare for, respond to, and recover from ransomware attacks under the Cybersecurity Framework.

Read more
DentaQuest Data Breach Exposes 2.6 Million Accounts

ShinyHunters leaked exfiltrated data including names, emails, government IDs, and health insurance information from the dental benefits provider.

Read more
Dashlane Password Manager Brute-Forced via 2FA Codes

Attackers brute-forced two-factor authentication codes to register unauthorized devices and download encrypted password vaults.

Read more
UN World Food Programme Breach Affects 600,000 Gaza Households

Unauthorized access to Gaza self-registration app exposed names, ID numbers, mobile numbers, and location data.

Read more
TechCrunch: Worst Cyber Breaches of 2026 So Far

Includes DOGE Social Security data exposure (potentially largest in US history), Iranian attacks on Stryker, FBI surveillance system breach, and European critical infrastructure attacks.

Read more
Android June Security Patch Fixes 124 Flaws

Includes one actively exploited zero-day (CVE-2025-48595) affecting Android 14+. Framework vulnerability enables local code execution and privilege escalation.

Read more
Cisco Patches Critical CVE-2026-20230 in Unified Communications Manager

Unauthenticated file write vulnerability leading to root compromise. Requires WebDialer enabled. Public PoC published.

Read more
13 Jun 2026
⚠️ SECURITY ALERT: Spring Framework Vulnerabilities — Patch Now
4 CVEs 3 news items
Critical Vulnerabilities 4
CVE-2026-41842 CVSS 7.5 (High) Spring Framework

Denial of Service (DoS) via VersionedResourceResolver. Spring MVC and WebFlux applications vulnerable to DoS when resolving static resources with crafted versioned resource requests. Affects Spring Framework 5.3.0-5.3.48, 6.1.0-6.1.27, 6.2.0-6.2.18, 7.0.0-7.0.7.

Source
CVE-2026-41843 CVSS 5.4 (Medium) Spring Framework

Path Traversal via VersionedResourceResolver. Spring MVC and WebFlux applications vulnerable to path traversal attacks when resolving static resources. Same affected versions as CVE-2026-41842.

Source
CVE-2026-41841 CVSS 5.3 (Medium) Spring Framework

Information Disclosure via Static Resource Cache. Spring MVC and WebFlux applications vulnerable to information disclosure when resolving static resources. Same affected versions.

Source
CVE-2026-22737 CVSS 5.3 (Medium) Spring Framework

Information Disclosure via Java scripting engine (JRuby, Jython) template views in Spring MVC and Spring WebFlux applications.

Source
Security News 3
⚠️ SPECIAL ALERT: Spring Framework — 4 CVEs Disclosed (June 8-9, 2026)

Three Spring Framework vulnerabilities were disclosed on June 8 (CVE-2026-41841, CVE-2026-41842, CVE-2026-41843) affecting static resource handling in Spring MVC and WebFlux. Combined with CVE-2026-22737 (March 2026, Java scripting engine info disclosure), this is a significant batch for one of the most widely used Java frameworks. Spring Boot applications using embedded Tomcat, Jetty, or Undertow are affected. Upgrade to Spring Framework 5.3.49+, 6.1.28+, 6.2.19+, or 7.0.8+.

Read more
CVE-2026-41842: DoS via VersionedResourceResolver — CVSS 7.5

High severity DoS vulnerability. An attacker can send crafted requests to trigger expensive resource resolution, potentially exhausting server resources. No authentication required. Affects all Spring MVC and WebFlux applications using VersionResourceResolver with static resources.

Read more
CVE-2026-41843: Path Traversal via VersionedResourceResolver — CVSS 5.4

Medium severity path traversal. An attacker can read arbitrary files from the server by crafting versioned resource requests. Requires some knowledge of the application structure.

Read more
Featured Project

Zero Day Clock

Track Time-to-Exploit across 83,000+ CVEs in real time

Explore live exploit intelligence →