Rosetta Daily · Jun 5, 2026
Generated automatically · 29 sources configured (WebSearch mode, feed allowlist still in effect) · 14 items selected
Window: past 24 hours (2026-06-04 → 2026-06-05)
In-the-Wild Exploitation / Actively Exploited
-
🔴🔥 Mirasvit Full Page Cache Warmer CVE-2026-45247 (CVSS 9.8) — unauthenticated Magento RCE added to CISA KEV (6/3), exploitation confirmed
CISA added this critical PHP object injection flaw in the Mirasvit Cache Warmer extension for Magento 2 / Adobe Commerce to the KEV catalog on June 3. Any storefront request carrying a craftedCacheWarmercookie reaches PHP's nativeunserialize()on attacker-controlled data — no auth, no admin session, no config toggle — yielding full server compromise via a gadget chain. Imperva has observed live exploitation attempts with serialized PHP object payloads. Detection signature: aCacheWarmer:cookie value whose base64 starts withTz,QzorYT. Patched in Cache Warmer 1.11.12 (5/25). Patch internet-facing Magento storefronts now; risk includes payment skimming and data theft.
The Hacker News · Sansec · Imperva · SecurityWeek -
⚠️🛡 codexui-android npm package (29k weekly downloads) silently exfiltrated OpenAI Codex tokens for a month
A legitimate-looking "remote web UI for OpenAI Codex," advertised on GitHub and npm, embedded credential-stealing code in its npm build only — its GitHub repo stayed clean. Every invocation exfiltrated Codex access, refresh and ID tokens plus account IDs to an attacker-controlled server. The refresh token does not expire, letting an attacker impersonate the developer indefinitely. Aikido also flagged a linked Android app (gptos.intelligence.assistant) running the package in a PRoot sandbox and shipping the same credentials to the same endpoint. Audit dependency trees, revoke and rotate Codex/OpenAI tokens, and treat "remote UI" wrappers for AI dev tools as high-risk.
The Hacker News · Aikido · Hackread · Cybernews -
🔥 Reminder — Android Framework CVE-2025-48595 KEV deadline is today (6/5)
The actively exploited integer-overflow privilege-escalation 0-day from Google's June Android bulletin (124 flaws patched) carries an FCEB remediation deadline of 2026-06-05. Affects Android 14/15/16/16 QPR2. Confirm the June Android patch level is deployed across the fleet today.
The Hacker News · Help Net Security · CISA KEV
Critical Vulnerabilities & Advisories
-
🔴 Redis CVE-2026-23479 (CVSS 8.8) — 2-year-old use-after-free RCE found by an autonomous AI bug hunter
Redis patched a use-after-free in its blocking-client code (MSG_OOB-style path) that lets an authenticated user run arbitrary OS commands on the host. Introduced in Redis 7.2.0, it sat unnoticed for over two years until an autonomous AI code-analysis tool (reported by Team Xint Code) surfaced it. Wiz notes Redis runs in a large majority of cloud environments, mostly without a password — and in default deployments the default user already holds every privilege the exploit chain needs. Fixed in 7.2.14 / 7.4.9 / 8.2.6 / 8.4.3 / 8.6.3 (5/5). Patch and require authentication; ~60,000 instances are estimated exposed.
The Hacker News · Redis advisory · SecurityWeek -
🔴 HP Poly VVX / Trio VoIP phones CVE-2026-0826 (CVSS 9.2) — unauthenticated RCE as root, Metasploit module published
Rapid7 disclosed a stack-based buffer overflow in the SDP/ICE attribute parser of HP Poly VVX (150/250/350/450) and Trio (8300/8500/8800) phones. A remote unauthenticated attacker reaches root-level RCE when the non-default ICE feature is enabled; a working Metasploit module exists. Rapid7 frames the real risk as an enterprise foothold and as a staging point for executive voice deepfakes. Fixed in Poly UCS 6.4.8 (VVX), 8.1.7 (Trio 8300), 7.2.8 (Trio 8500/8800). Inventory Poly devices, disable ICE where unused, and update UCS.
Rapid7 · SecurityWeek · CSO Online
Vendor Advisories
- Unpatched Windows
search:URI handler leaks NTLMv2 hashes — Microsoft declines to fix (no CVE)
Huntress disclosed that the Windowssearch:URI handler leaks a user's NTLMv2 hash via acrumb=location:parameter — technically identical to the previously-patched Snipping Tool flaw CVE-2026-33829. A crafted link coerces the host into authenticating to an attacker SMB server, exposing the hash for relay/cracking. After responsible disclosure (4/15), Microsoft said it "doesn't meet our bar for servicing." Mitigate: block outbound SMB (TCP/445, 139) where unneeded, enforce SMB signing, disable NTLM where feasible.
The Hacker News· Huntress· SC Media
Web Security Research
- NGINX "Rift" CVE-2026-42945 (CVSS 9.2) — 18-year-old heap overflow in the rewrite module, unauthenticated RCE, AI-discovered
A heap buffer overflow inngx_http_rewrite_module, present since NGINX 0.6.27 (2008), allows an unauthenticated attacker to corrupt the worker heap with a single crafted HTTP request — RCE on ASLR-disabled hosts, DoS crash-loops everywhere. Triggered when arewritedirective is followed byrewrite/if/setwith an unnamed PCRE capture ($1,$2) and a replacement string containing?. Found by depthfirst's autonomous AI analysis of the NGINX repo and disclosed 4/21. Affects NGINX Plus R32–R36 and Open Source 1.0.0–1.30.0. Fixed in Plus R32 P6 / R36 P4, OSS 1.30.1 / 1.31.0. Mitigation without patching: switch to named PCRE captures.
The Hacker News· Orca Security· CSA Labs
AI Security
- Agentic browsers — Brave research confirms "unseeable" prompt injection via screenshots is systemic across the category
Brave's ongoing work (delivered against Perplexity Comet and Fellou) shows page-summarization and Q&A features carry exceptionally high indirect-prompt-injection risk (73% / 71% attack success in tests). Instructions hidden as faint light-blue-on-yellow text are OCR'd from screenshots and executed with the user's authenticated privileges, nullifying same-origin protections and reaching banks, email and cloud storage. Combined-defense frameworks cut success from 73% to ~9% while keeping 94% task performance. A clean reminder that agentic/web-connected AI clients are the new cross-domain RCE surface— directly relevant to the codexui-android and Gemini-notification cases above.
Brave· The Hacker News· Anthropic — prompt injection defenses
Threat Intelligence
-
🛡 Gamaredon (FSB) weaponizes WinRAR CVE-2025-8088 — GammaPhish → GammaLoad → GammaWorm + GammaSteel against Ukraine
The Russia/FSB-linked group is exploiting the WinRAR path-traversal flaw (CVSS 7.5) in a four-stage chain: a GammaPhish HTA drops the GammaLoad VBScript downloader, which installs GammaWorm (persistence + arbitrary execution, hiding in NTFS alternate data streams) and GammaSteel (info-stealer exfiltrating to AWS S3). Targets are Ukrainian government, military and critical-infrastructure orgs; activity first observed January 2026. Ensure WinRAR is patched (≥ 7.13) and hunt for HTA→VBScript chains and ADS-resident payloads.
The Hacker News · Infosecurity Magazine · GBHackers -
WeedHack — Minecraft-themed MaaS infostealer infects 116,000+ systems (McAfee)
A clear-net, free-to-use MaaS infostealer dubbed WeedHack has compromised 116,464 systems since January (~2–3k/day), spread via malicious Minecraft mods/clients/cheats pushed through YouTube and SEO poisoning (240+ URLs, 3,820 unique JARs). It steals Minecraft session IDs, cookies and passwords across 36 browsers, 56 crypto add-ons, 12 wallet apps, plus Discord/Steam/Telegram; a $5/mo tier adds remote control, keylogging and webcam access. Most victims are in the US, Germany, India and UK — many operators appear to be teens using it for harassment. Block known distribution domains; warn users off third-party Minecraft mods.
Bleeping Computer · Help Net Security · CyberInsider -
Carnival breach — ~6 million customers exposed via social-engineered employee account; ShinyHunters claims 8.7M records
Carnival Corporation disclosed (announced 5/27, discovered 4/14) that an attacker used social engineering against an employee account to access customer names, addresses and government IDs (driver's license / passport numbers). ShinyHunters claimed responsibility, asserting 8.7M records. Carnival is offering two years of credit monitoring. The incident anchors a June wave of account-compromise breaches and reinforces the identity-and-helpdesk attack pattern ShinyHunters has run all year. · ·
Ransomware Today
- ~30–40 new DLS posts in the past 24hacross ~90 active leak sites (public-aggregator estimate; direct RansomLook fetch blocked by sandbox egress allowlist). Most active groups: Qilin, Akira, DragonForce, INC Ransom, with The Gentlemen and Nova/RALord also posting. Newly seen victim example: SETS Solutions (DragonForce). Carry-over confirmed 6/3 victims continued surfacing across trackers (Qilin → Singing River Health System / MarketJoy / JNP ENG / Eat Salad; Akira → Hal Otey Financial; INC → Öztuğ Otomotiv; DragonForce → Copamex). Today's watchlist hits:Qilin × healthcare/multi-sector, Akira × financial/manufacturing, INC × manufacturing — US geography prominent. Structure unchanged: Qilin remains #1 (>1,700 tracked victims), Akira #2; ransom-payment rate near historic low (~28%).
- Full victim table + watchlist hits: intel/ransomware/daily/2026-06-05.html
AI Frontier
OpenAI
- GPT-5.5 Instant readability upgrade + legacy retirements (6/3)— GPT-5.5 Instant rolling out to all users with a cleaner, less bullet-heavy style; Canvas removed in favor of inline writing/code blocks. GPT-4.5 retires from ChatGPT 6/27(30-day sunset); o3 retires 8/26(90-day sunset; o3 stays in the API). gHacks· Bleeping Computer
- GPT-Rosalind (life sciences) updated— combines GPT-5.5 agentic coding with stronger drug-discovery/genomics performance and new evidence-retrieval + bioinformatics plugins; expanded trusted-access preview. OpenAI News
- ChatGPT Sites in preview for Business— teams build/deploy internal web apps with Codex, hosted URLs and Sign-in-with-ChatGPT workspace controls. Releasebot
- codexui-android npm token-theft campaign— see AI Security above; Codex auth tokens exfiltrated for a month. The Hacker News
Anthropic
- KPMG global alliance (6/3–6/4)— Claude rolled out to all 276,000 KPMG staff across 138 countries, embedding Cowork and Managed Agents into KPMG's Azure-based Digital Gateway (starting with tax/legal); Anthropic named a preferred partner for deploying Claude into PE portfolio companies. The Next Web· Anthropic news
- Project Glasswing (carry-over)— now ~200 partners across 15+ countries / ~150 new orgs; Claude Security(Opus 4.8-powered repo scanning + patch suggestions) shipping. 10,000+ high/critical bugs storyline continues. Anthropic — Expanding Glasswing
- IPO (reminder)— confidential SEC filing (late May / 6/1). Washington Post
Google DeepMind / AI
- Gemini 3.5 Flash GA + Deep Think rollout— 3.5 Flash positioned as the strongest agentic/coding model (key benchmarks beating 3.1 Pro); Gemini 3 Deep Think to Ultra subscribers; Ultra cut to $200/mo, new $100/mo Developer tier. Gemini 3.5· Google Cloud — I/O 26
- AI-found-bug trend continues— the Redis and NGINX RCEs above were both surfaced by autonomous AI code analyzers, mirroring DeepMind/Big Sleep's earlier wins. The "AI finds bugs faster than defenders patch" theme (Verizon 2026 DBIR) holds. SecurityWeek
🛡 = security-relevant
Chinese Community Picks
- FreeBuf / AnQuanKe / YiJing Lab et al.continue tracking English-sphere stories with local follow-up: the June Android bulletin (CVE-2025-48595 in-the-wild 0-day), the NGINX Rift CVE-2026-42945 18-year heap overflow, Gamaredon's WinRAR campaign, and Anthropic Claude Mythos / Project Glasswing commercialization (10,000+ critical bugs across ~200 orgs).
- CVE-2026-45247 Magento Cache Warmer RCEis expected to gain traction in China's e-commerce/站长 circles — Magento + Adobe Commerce storefronts are widely hosted, and the unauthenticated cookie-based RCE plus payment-skimming angle maps directly onto local risk.
- Supply-chain attacks stay hot— after TanStack/Mini Shai-Hulud and Red Hat npm "Miasma," the codexui-android Codex token-theft package keeps npm/CI supply-chain poisoning a leading discussion thread.
FreeBuf· FreeBuf Vulnerabilities
Failed Sources
- RansomLook API + RSS— blocked by sandbox egress allowlist (host not permitted). Ransomware section uses WebSearch second-hand aggregation (ransomware.live / Ransom-DB / vendor trackers) cross-checked against confirmed 6/3 victims; per-victim accuracy not guaranteed.
- Direct RSS/Atom feeds (CISA, The Hacker News, Bleeping Computer, vendor blogs)— direct fetch blocked by egress allowlist; this edition reconstructed via WebSearch over the same source set.
- Chinese feeds (FreeBuf / AnQuanKe / Xianzhi)— feed pull unavailable in sandbox; Chinese section assembled from WebSearch summaries.
Source configuration: see intel/sources.yaml