Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-06-05
Daily Brief·2026-06-05·14 Items

Rosetta Daily · Jun 5, 2026

Generated automatically · 29 sources configured (WebSearch mode, feed allowlist still in effect) · 14 items selected
Window: past 24 hours (2026-06-04 → 2026-06-05)

In-the-Wild Exploitation / Actively Exploited

  • 🔴🔥 Mirasvit Full Page Cache Warmer CVE-2026-45247 (CVSS 9.8) — unauthenticated Magento RCE added to CISA KEV (6/3), exploitation confirmed
    CISA added this critical PHP object injection flaw in the Mirasvit Cache Warmer extension for Magento 2 / Adobe Commerce to the KEV catalog on June 3. Any storefront request carrying a crafted CacheWarmer cookie reaches PHP's native unserialize() on attacker-controlled data — no auth, no admin session, no config toggle — yielding full server compromise via a gadget chain. Imperva has observed live exploitation attempts with serialized PHP object payloads. Detection signature: a CacheWarmer: cookie value whose base64 starts with Tz, Qz or YT. Patched in Cache Warmer 1.11.12 (5/25). Patch internet-facing Magento storefronts now; risk includes payment skimming and data theft.
    The Hacker News · Sansec · Imperva · SecurityWeek

  • ⚠️🛡 codexui-android npm package (29k weekly downloads) silently exfiltrated OpenAI Codex tokens for a month
    A legitimate-looking "remote web UI for OpenAI Codex," advertised on GitHub and npm, embedded credential-stealing code in its npm build only — its GitHub repo stayed clean. Every invocation exfiltrated Codex access, refresh and ID tokens plus account IDs to an attacker-controlled server. The refresh token does not expire, letting an attacker impersonate the developer indefinitely. Aikido also flagged a linked Android app (gptos.intelligence.assistant) running the package in a PRoot sandbox and shipping the same credentials to the same endpoint. Audit dependency trees, revoke and rotate Codex/OpenAI tokens, and treat "remote UI" wrappers for AI dev tools as high-risk.
    The Hacker News · Aikido · Hackread · Cybernews

  • 🔥 Reminder — Android Framework CVE-2025-48595 KEV deadline is today (6/5)
    The actively exploited integer-overflow privilege-escalation 0-day from Google's June Android bulletin (124 flaws patched) carries an FCEB remediation deadline of 2026-06-05. Affects Android 14/15/16/16 QPR2. Confirm the June Android patch level is deployed across the fleet today.
    The Hacker News · Help Net Security · CISA KEV

Critical Vulnerabilities & Advisories

  • 🔴 Redis CVE-2026-23479 (CVSS 8.8) — 2-year-old use-after-free RCE found by an autonomous AI bug hunter
    Redis patched a use-after-free in its blocking-client code (MSG_OOB-style path) that lets an authenticated user run arbitrary OS commands on the host. Introduced in Redis 7.2.0, it sat unnoticed for over two years until an autonomous AI code-analysis tool (reported by Team Xint Code) surfaced it. Wiz notes Redis runs in a large majority of cloud environments, mostly without a password — and in default deployments the default user already holds every privilege the exploit chain needs. Fixed in 7.2.14 / 7.4.9 / 8.2.6 / 8.4.3 / 8.6.3 (5/5). Patch and require authentication; ~60,000 instances are estimated exposed.
    The Hacker News · Redis advisory · SecurityWeek

  • 🔴 HP Poly VVX / Trio VoIP phones CVE-2026-0826 (CVSS 9.2) — unauthenticated RCE as root, Metasploit module published
    Rapid7 disclosed a stack-based buffer overflow in the SDP/ICE attribute parser of HP Poly VVX (150/250/350/450) and Trio (8300/8500/8800) phones. A remote unauthenticated attacker reaches root-level RCE when the non-default ICE feature is enabled; a working Metasploit module exists. Rapid7 frames the real risk as an enterprise foothold and as a staging point for executive voice deepfakes. Fixed in Poly UCS 6.4.8 (VVX), 8.1.7 (Trio 8300), 7.2.8 (Trio 8500/8800). Inventory Poly devices, disable ICE where unused, and update UCS.
    Rapid7 · SecurityWeek · CSO Online

Vendor Advisories

  • Unpatched Windows search:URI handler leaks NTLMv2 hashes — Microsoft declines to fix (no CVE)
    Huntress disclosed that the Windows search:URI handler leaks a user's NTLMv2 hash via a crumb=location:parameter — technically identical to the previously-patched Snipping Tool flaw CVE-2026-33829. A crafted link coerces the host into authenticating to an attacker SMB server, exposing the hash for relay/cracking. After responsible disclosure (4/15), Microsoft said it "doesn't meet our bar for servicing." Mitigate: block outbound SMB (TCP/445, 139) where unneeded, enforce SMB signing, disable NTLM where feasible.
    The Hacker News· Huntress· SC Media

Web Security Research

  • NGINX "Rift" CVE-2026-42945 (CVSS 9.2) — 18-year-old heap overflow in the rewrite module, unauthenticated RCE, AI-discovered
    A heap buffer overflow in ngx_http_rewrite_module, present since NGINX 0.6.27 (2008), allows an unauthenticated attacker to corrupt the worker heap with a single crafted HTTP request — RCE on ASLR-disabled hosts, DoS crash-loops everywhere. Triggered when a rewritedirective is followed by rewrite/if/setwith an unnamed PCRE capture ($1, $2) and a replacement string containing ?. Found by depthfirst's autonomous AI analysis of the NGINX repo and disclosed 4/21. Affects NGINX Plus R32–R36 and Open Source 1.0.0–1.30.0. Fixed in Plus R32 P6 / R36 P4, OSS 1.30.1 / 1.31.0. Mitigation without patching: switch to named PCRE captures.
    The Hacker News· Orca Security· CSA Labs

AI Security

  • Agentic browsers — Brave research confirms "unseeable" prompt injection via screenshots is systemic across the category
    Brave's ongoing work (delivered against Perplexity Comet and Fellou) shows page-summarization and Q&A features carry exceptionally high indirect-prompt-injection risk (73% / 71% attack success in tests). Instructions hidden as faint light-blue-on-yellow text are OCR'd from screenshots and executed with the user's authenticated privileges, nullifying same-origin protections and reaching banks, email and cloud storage. Combined-defense frameworks cut success from 73% to ~9% while keeping 94% task performance. A clean reminder that agentic/web-connected AI clients are the new cross-domain RCE surface— directly relevant to the codexui-android and Gemini-notification cases above.
    Brave· The Hacker News· Anthropic — prompt injection defenses

Threat Intelligence

  • 🛡 Gamaredon (FSB) weaponizes WinRAR CVE-2025-8088 — GammaPhish → GammaLoad → GammaWorm + GammaSteel against Ukraine
    The Russia/FSB-linked group is exploiting the WinRAR path-traversal flaw (CVSS 7.5) in a four-stage chain: a GammaPhish HTA drops the GammaLoad VBScript downloader, which installs GammaWorm (persistence + arbitrary execution, hiding in NTFS alternate data streams) and GammaSteel (info-stealer exfiltrating to AWS S3). Targets are Ukrainian government, military and critical-infrastructure orgs; activity first observed January 2026. Ensure WinRAR is patched (≥ 7.13) and hunt for HTA→VBScript chains and ADS-resident payloads.
    The Hacker News · Infosecurity Magazine · GBHackers

  • WeedHack — Minecraft-themed MaaS infostealer infects 116,000+ systems (McAfee)
    A clear-net, free-to-use MaaS infostealer dubbed WeedHack has compromised 116,464 systems since January (~2–3k/day), spread via malicious Minecraft mods/clients/cheats pushed through YouTube and SEO poisoning (240+ URLs, 3,820 unique JARs). It steals Minecraft session IDs, cookies and passwords across 36 browsers, 56 crypto add-ons, 12 wallet apps, plus Discord/Steam/Telegram; a $5/mo tier adds remote control, keylogging and webcam access. Most victims are in the US, Germany, India and UK — many operators appear to be teens using it for harassment. Block known distribution domains; warn users off third-party Minecraft mods.
    Bleeping Computer · Help Net Security · CyberInsider

  • Carnival breach — ~6 million customers exposed via social-engineered employee account; ShinyHunters claims 8.7M records
    Carnival Corporation disclosed (announced 5/27, discovered 4/14) that an attacker used social engineering against an employee account to access customer names, addresses and government IDs (driver's license / passport numbers). ShinyHunters claimed responsibility, asserting 8.7M records. Carnival is offering two years of credit monitoring. The incident anchors a June wave of account-compromise breaches and reinforces the identity-and-helpdesk attack pattern ShinyHunters has run all year. · ·

Ransomware Today

  • ~30–40 new DLS posts in the past 24hacross ~90 active leak sites (public-aggregator estimate; direct RansomLook fetch blocked by sandbox egress allowlist). Most active groups: Qilin, Akira, DragonForce, INC Ransom, with The Gentlemen and Nova/RALord also posting. Newly seen victim example: SETS Solutions (DragonForce). Carry-over confirmed 6/3 victims continued surfacing across trackers (Qilin → Singing River Health System / MarketJoy / JNP ENG / Eat Salad; Akira → Hal Otey Financial; INC → Öztuğ Otomotiv; DragonForce → Copamex). Today's watchlist hits:Qilin × healthcare/multi-sector, Akira × financial/manufacturing, INC × manufacturing — US geography prominent. Structure unchanged: Qilin remains #1 (>1,700 tracked victims), Akira #2; ransom-payment rate near historic low (~28%).
  • Full victim table + watchlist hits: intel/ransomware/daily/2026-06-05.html

AI Frontier

OpenAI

  • GPT-5.5 Instant readability upgrade + legacy retirements (6/3)— GPT-5.5 Instant rolling out to all users with a cleaner, less bullet-heavy style; Canvas removed in favor of inline writing/code blocks. GPT-4.5 retires from ChatGPT 6/27(30-day sunset); o3 retires 8/26(90-day sunset; o3 stays in the API). gHacks· Bleeping Computer
  • GPT-Rosalind (life sciences) updated— combines GPT-5.5 agentic coding with stronger drug-discovery/genomics performance and new evidence-retrieval + bioinformatics plugins; expanded trusted-access preview. OpenAI News
  • ChatGPT Sites in preview for Business— teams build/deploy internal web apps with Codex, hosted URLs and Sign-in-with-ChatGPT workspace controls. Releasebot
  • codexui-android npm token-theft campaign— see AI Security above; Codex auth tokens exfiltrated for a month. The Hacker News

Anthropic

  • KPMG global alliance (6/3–6/4)— Claude rolled out to all 276,000 KPMG staff across 138 countries, embedding Cowork and Managed Agents into KPMG's Azure-based Digital Gateway (starting with tax/legal); Anthropic named a preferred partner for deploying Claude into PE portfolio companies. The Next Web· Anthropic news
  • Project Glasswing (carry-over)— now ~200 partners across 15+ countries / ~150 new orgs; Claude Security(Opus 4.8-powered repo scanning + patch suggestions) shipping. 10,000+ high/critical bugs storyline continues. Anthropic — Expanding Glasswing
  • IPO (reminder)— confidential SEC filing (late May / 6/1). Washington Post

Google DeepMind / AI

  • Gemini 3.5 Flash GA + Deep Think rollout— 3.5 Flash positioned as the strongest agentic/coding model (key benchmarks beating 3.1 Pro); Gemini 3 Deep Think to Ultra subscribers; Ultra cut to $200/mo, new $100/mo Developer tier. Gemini 3.5· Google Cloud — I/O 26
  • AI-found-bug trend continues— the Redis and NGINX RCEs above were both surfaced by autonomous AI code analyzers, mirroring DeepMind/Big Sleep's earlier wins. The "AI finds bugs faster than defenders patch" theme (Verizon 2026 DBIR) holds. SecurityWeek

🛡 = security-relevant


Chinese Community Picks

  • FreeBuf / AnQuanKe / YiJing Lab et al.continue tracking English-sphere stories with local follow-up: the June Android bulletin (CVE-2025-48595 in-the-wild 0-day), the NGINX Rift CVE-2026-42945 18-year heap overflow, Gamaredon's WinRAR campaign, and Anthropic Claude Mythos / Project Glasswing commercialization (10,000+ critical bugs across ~200 orgs).
  • CVE-2026-45247 Magento Cache Warmer RCEis expected to gain traction in China's e-commerce/站长 circles — Magento + Adobe Commerce storefronts are widely hosted, and the unauthenticated cookie-based RCE plus payment-skimming angle maps directly onto local risk.
  • Supply-chain attacks stay hot— after TanStack/Mini Shai-Hulud and Red Hat npm "Miasma," the codexui-android Codex token-theft package keeps npm/CI supply-chain poisoning a leading discussion thread.
    FreeBuf· FreeBuf Vulnerabilities

Failed Sources

  • RansomLook API + RSS— blocked by sandbox egress allowlist (host not permitted). Ransomware section uses WebSearch second-hand aggregation (ransomware.live / Ransom-DB / vendor trackers) cross-checked against confirmed 6/3 victims; per-victim accuracy not guaranteed.
  • Direct RSS/Atom feeds (CISA, The Hacker News, Bleeping Computer, vendor blogs)— direct fetch blocked by egress allowlist; this edition reconstructed via WebSearch over the same source set.
  • Chinese feeds (FreeBuf / AnQuanKe / Xianzhi)— feed pull unavailable in sandbox; Chinese section assembled from WebSearch summaries.

Source configuration: see intel/sources.yaml

← Prev
Rosetta Daily · Jun 4, 2026
Next →
Rosetta Daily · Jun 6, 2026
Reinforce helpdesk identity verification and MFA-reset controls.

SecurityWeek
TechRepublic
KVUE