Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-06-03
Daily Brief·2026-06-03·16 Items

Rosetta Daily · Jun 3, 2026

Auto-generated · 29 sources configured (WebSearch mode — feed allowlist still in effect) · 16 items selected
Window: past 24 hours (2026-06-02 → 2026-06-03)

In-the-Wild / Actively Exploited

  • 🔴🔥⚠️ Gogs CVE-2025-8110 — unpatched 0-day RCE, 700+ of 1,400 exposed instances already compromised
    Wiz disclosed a still-unpatched remote-code-execution 0-day in the self-hosted Git service Gogs — a bypass of a previously-patched RCE bug. It affects instances on ≤ 0.13.3 with open registration enabled (the default). Wiz found ~1,400 exposed instances and 700+ already compromised — an over-1-in-2 breach rate. All infected hosts shared the same fingerprint (8-character random owner/repo names created in one short window), pointing to a single actor/toolset. Wiz reported it on July 17; the maintainers acknowledged receipt only on Oct 30, and no fix has shipped. Treat any internet-facing Gogs as suspect: disable open registration, restrict network exposure, hunt for the rogue-repo pattern.
    Bleeping Computer · Wiz research · SecurityWeek · Dark Reading

  • 🔴🔥⚠️ Android June 2026 update — actively-exploited zero-day CVE-2025-48595 (Framework EoP), 124 flaws total
    Google's June 2026 Android Security Bulletin patches 124 vulnerabilities including one zero-day under limited, targeted exploitation. CVE-2025-48595 is an integer-overflow elevation-of-privilege bug in the Android Framework spanning Android 14, 15, 16 and 16-qpr2. Exploitation needs no user interaction and the vector is local — most likely a malicious app the target is tricked into installing — yielding full device/data access. Google did not name the discoverer or attribute the activity (commercial spyware vendor vs. APT unknown). Roll the June patch level across fleet devices.
    Help Net Security · Bleeping Computer · Android Security Bulletin

  • 🔥 Trend Micro Apex One CVE-2026-34926 — exploited 0-day, CISA KEV deadline tomorrow (June 4)
    A directory-traversal flaw in the Apex One (on-prem) 2019 server lets a pre-authenticated local attacker modify a key table to inject malicious code that is then pushed to agents. TrendAI confirmed at least one in-the-wild exploitation attempt; CISA added it to KEV with an FCEB remediation deadline of 2026-06-04. Affects server/agent builds < 17079; fixed in SP1 Critical Patch Build 18012 (existing SP1) / Build 17079 (new installs). Cloud/SaaS Apex One is not affected.
    Bleeping Computer · Help Net Security · SecurityWeek · CISA KEV

  • 🔥 Oracle WebLogic CVE-2024-21182 added to CISA KEV (June 1)
    CISA added the Oracle WebLogic Server flaw CVE-2024-21182 to its Known Exploited Vulnerabilities catalog on 2026-06-01 based on evidence of active exploitation. WebLogic remains a recurring attack vector against enterprise middleware; FCEB agencies must remediate by the assigned deadline. Inventory internet-reachable WebLogic, apply the Oracle CPU fix, and restrict T3/IIOP exposure.
    CISA alert (6/1) · CISA KEV catalog

Critical Vulnerabilities & Advisories

  • 🔴 OTRS Community Edition CVE-2026-48188 (CVSS 9.1) — unauthenticated SQLi → auth bypass (disclosed June 1)
    An improper-input-validation flaw in the OTRS Community Edition database-layer module allows unauthenticated SQL injection leading to authentication bypass, publicly disclosed 2026-06-01. OTRS sits at the help-desk/ticketing core of many orgs (often holding sensitive correspondence and credentials), so an unauth bypass is a high-value pivot. Restrict exposure and apply the vendor advisory.
    TheHackerWire — CVE-2026-48188

  • 🔴 Kirki WordPress plugin CVE-2026-8206 (CVSS 9.8)
    A critical flaw in the Kirki WordPress customizer framework (used by many themes/plugins) is rated CVSS 9.8. Given WordPress's exploit-at-scale history (cf. WP Maps Pro on 6/2), expect opportunistic mass-scanning; update affected installs and audit for tampering.
    TheHackerWire — CVE-2026-8206 · Feedly CVSS 9–10 tracker

Vendor Advisories

  • Microsoft Defender CVE-2026-41091 & CVE-2026-45498 — KEV deadline is TODAY (June 3)
    The two actively-exploited Defender flaws (LPE via improper link resolution; DoS) — overlapping the "RedSun" / "UnDefend" Defender zero-days — carry an FCEB remediation deadline of 2026-06-03. Fixed in Antimalware Platform 1.1.26040.8 / 4.18.26040.7. The failure mode is the silent auto-update path — verify the platform actually updated rather than assuming.
    The Hacker News · SecurityWeek · CISA KEV

  • Exim CVE-2026-45185 (CVSS 9.8) — update to 4.99.3
    A critical flaw in the Exim mail transfer agent (CVSS 9.8) was addressed with an update to 4.99.3. Exim powers a large share of internet-facing MTAs; mail servers are perennial RCE/relay targets. Patch promptly and confirm the running build post-upgrade.
    Feedly CVSS 9–10 tracker

Web Security Research

  • Pwn2Own Berlin 2026 — capacity overflow triggers "retaliatory" free 0-day drops
    For the first time in its 19-year history, Pwn2Own Berlin 2026 hit capacity and turned away 150+ researchers with working exploit chains (AI-assisted submissions surged). Locked out, several published full RCE chains for free — no coordinated disclosure, no vendor notice — with community-confirmed drops against Firefox, Ollama, LM Studio, PyTorch, Linux KVM, NVIDIA, Docker, and Claude Code. One Firefox full-chain (researcher ggwhyp) was reported to Mozilla and the resulting fix knocked other entries out of the contest. A structural warning about how ZDI handles capacity — and a reminder that AI-tooling is flooding the bug-discovery pipeline.
    Hackread · Security Point Break · Cybernews

  • ⚠️ CVE-2026-32202 — Windows Shell spoofing (APT28 LNK chain), being exploited despite April patch
    Worth flagging for hunt teams: CVE-2026-32202 is a zero-click Windows Shell spoofing flaw (not the n8n bug the CVE is sometimes confused with). It stems from an incomplete patch for CVE-2026-21510 and, chained with CVE-2026-21513, has been used by APT28 (Fancy Bear) via weaponized LNK files — opening the download folder triggers an SMB connection to the attacker's server, leaking auth. Microsoft shipped a fix on April 14 without marking it exploited; exploitation is ongoing. Confirm the April+ cumulative update is applied.
    Help Net Security · NVD — CVE-2026-32202

AI Security

  • Google GTIG — nation-state actors now use Gemini "at all stages" of attacks; Honestcue malware calls the Gemini API at runtime
    Google's Threat Intelligence Group + DeepMind detail how China-, Russia-, Iran- and North Korea-nexus groupsused Gemini across the full attack lifecycle in late 2025: OSINT/target profiling, phishing-pretext crafting, vulnerability research, scripting and post-compromise work. APT42 (Iran)used it to harvest official emails and build phishing personas; a Chinese group profiled separatist organizations and individuals. Most notably, Honestcue malware leverages the Gemini API to dynamically generate and execute C# in memory— fileless, detection-evading, AI-on-demand. Pair with Mandiant's earlier PROMPTFLUX/PROMPTSTEAL finding: LLM-at-runtime malware is now an operational pattern, not a demo.
    The Record· CyberScoop· The Hacker News

Threat Intelligence

  • AUDIOFIX — Python infostealer purpose-built for macOS; Kimsuky activity tracked alongside
    Fresh threat telemetry flags AUDIOFIX, a Python-based infostealer custom-engineered for macOS that extracts stored browser credentials, SSH keys, and cryptocurrency wallets — continuing the shift of commodity stealers onto the Mac platform. The same reporting window tracks ongoing Kimsuky (North Korea) APT activity. macOS endpoints in dev/finance shops should be in scope for credential-theft hunting, not just Windows.
    Today's Virus Report (6/1)

  • June 2 breach cluster — ransomware-attributed disclosures span healthcare, logistics, hospitality
    Multiple disclosures surfaced 2026-06-02, most ransomware-attributed: Champaign-Urbana Public Health District (INC_RANSOM), Clínica Maitenes (Qilin), Digitall Graphics and Hightower Communications (Play), LCNet — a German logistics/transport firm — (SafePay), and Synex Group (Sri Lanka, engineering) + Taos Mountain Casino (both DragonForce). Healthcare and logistics again over-represented. See Ransomware Today for watchlist hits.
    BreachSense — recent breaches · ransomware.live

Chinese-Language Community Picks

  • FreeBuf / Yijing Lab and others: continued coverage of Android adbd CVE-2026-0073, a zero-click near-field shell, and the cPanel CVE-2026-29201/2/3 high-severity triple patch; new hot topics for June are Android's June in-the-wild 0-day CVE-2025-48595and the unpatched Gogs 0-day, both expected to see a second wave of Chinese-language coverage.
  • Pwn2Own Berlin 2026 hitting capacity plus retaliatory disclosuressparked debate in the Chinese-language community — a surge of AI-assisted submissions has called ZDI's capacity mechanism into question, and rejected researchers went public with 0-days in Firefox, PyTorch, Docker and Claude Code.
  • OTRS CVE-2026-48188 (unauthenticated SQLi → authentication bypass)is highly relevant to domestic ticketing and service-desk deployments and warrants ops attention.
    FreeBuf· FreeBuf vulnerabilities section

Ransomware Today

  • ~30–40 new DLS posts in last 24hacross ~90 active leak sites (public-aggregator estimate; RansomLook direct fetch blocked). Confirmed 6/2 victims: Qilin → Clínica Maitenes(healthcare), INC_RANSOM → Champaign-Urbana Public Health District(public health/government), Play → Digitall Graphics + Hightower Communications, SafePay → LCNet(German logistics), DragonForce → Synex Group (Sri Lanka) + Taos Mountain Casino. Watchlist hits today: Qilin × healthcare, INC × healthcare/government, Play (group), SafePay × logistics. Structural context unchanged: Qilin holds the multi-quarter #1 spot, Akira second (>$150M 2025 proceeds), DragonForce expanding post-"cartel" rebrand, and the ransom payment rate sits near an all-time low (~28%).
  • Full per-victim breakdown → intel/ransomware/daily/2026-06-03.html

AI Frontier

OpenAI

  • OpenAI frontier models + Codex now GA on AWS (June 2)— enterprises get a faster production path with AWS-native security, governance, billing and compliance. Releasebot
  • Model retirements— GPT-4.5 leaves ChatGPT June 27(30-day sunset); o3 leaves Aug 26(90-day sunset). OpenAI model release notes
  • Codex updates— macOS "Appshots" (attach an app window to a Codex thread via hotkey) and Goal mode GAacross app/IDE/CLI; GPT-5.5 Instant refreshed for response quality. Releasebot
  • GPT-5.6 reportedly slated for June— per ongoing reporting; unconfirmed by OpenAI. Geeky Gadgets

Anthropic

  • Anthropic confidentially files for IPO (June 1)— follows the $65B Series H at a $965B valuation; reported ~$47B annualized revenue. Sets up a public-market test of the AI boom. Washington Post· CBS News
  • Major Claude outage (June 2)— elevated error rates across multiple Claude services, attributed to capacity constraints; recovered same day. The National
  • Claude Mythos / Project Glasswing expands to ~150 companies— enterprise access to Mythos-class models broadens post-IPO-filing; the AI-finds-bugs-at-scale arc continues (cf. AI Security). Yahoo Finance
  • Billing change effective June 15— Claude Agent SDK, claude -p, Claude Code GitHub Actions and third-party agents move off the subscription limit onto separate metered API-rate credits (no rollover). Codersera writeup

Google DeepMind / AI

  • GTIG/DeepMind report — state hackers weaponizing Gemini across the full attack chain(Honestcue runtime-AI malware; APT42 phishing pretexts). See AI Security above.The Record
  • Google I/O 2026 rollout continues— Gemini 3.5 Flash(frontier perf for agents/coding), Gemini Omni(any-to-any image/audio/video/text), Gemini Sparkagentic assistant (Ultra-tier), 900M Gemini MAU; TPU 8th-gen (8t/8i) superpods. HeyGoTrade recap· Tom's Guide

🛡 = security-related


Failed Sources

  • RansomLook API + RSS— blocked by sandbox egress allowlist (HTTP 000/ host not on network allowlist). Ransomware section uses WebSearch aggregation (BreachSense, ransomware.live, vendor trackers) cross-checked against confirmed 6/2 victim disclosures; full per-victim accuracy not guaranteed.
  • Chinese sources (FreeBuf, 安全客, 先知社区)— direct feed fetch not available in current sandbox; coverage based on WebSearch summaries.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jun 2, 2026
Next →
Rosetta Daily · Jun 4, 2026