Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-06-08
Daily Brief·2026-06-08·14 Items

Rosetta Daily · Jun 8, 2026

Generated automatically · 29 sources configured (WebSearch mode + direct RansomLook API; news feed allowlist still in effect) · 14 items selected
Window: past 24 hours (2026-06-07 → 2026-06-08). Monday edition — weekend backlog rolling in; several items are still-hot carry-overs alongside a fresh China-linked espionage cluster.

In-the-Wild Exploitation / Actively Exploited

  • 🔥⚠️ Cisco Catalyst SD-WAN Manager CVE-2026-20245 — 7th Cisco SD-WAN 0-day of 2026, exploited in the wild, still no patch (carry-over, still the top open item)
    Cisco PSIRT's actively-exploited, unpatched CLI flaw (CVSS 7.8) remains the highest-priority open exposure: insufficient input validation lets an authenticated netadmin-level attacker upload a crafted file and run arbitrary commands as root. Mandiant reported the exploitation, including attackers pushing config changes to edge devices. It's chained with the May SD-WAN bugs (CVE-2026-20182 / CVE-2026-20127) to first obtain the authenticated foothold. Affects on-prem, Cloud-Pro, Cisco-managed cloud and FedRAMP gov deployments. Still no fix for 20245; interim guidance: be on the 20182-fixed release (5/14) and lock down netadmin access.
    Help Net Security · BleepingComputer

  • 🔥⚠️ Android Framework CVE-2025-48595 — actively-exploited 0-day in the June 2026 Android update (124 flaws), in CISA KEV (carry-over, deadline passed 6/5)
    Google's June 2026 Android Security Bulletin fixes 124 vulnerabilities, headlined by CVE-2025-48595, an integer-overflow elevation-of-privilege flaw in the Android Framework (CVSS 8.4) under "limited, targeted exploitation" requiring no user interaction. Affects Android 14–16 and 16 QPR2; CISA KEV with a 6/5 FCEB deadline now passed. Roll the June patch level to managed fleets; prioritize devices that can't auto-update.
    The Hacker News · CISA KEV

  • 🔥 Reminder — Microsoft Defender CVE-2026-41091 / CVE-2026-45498 (KEV, FCEB deadline was 6/3) and Magento Cache Warmer CVE-2026-45247 (CVSS 9.8, deadline 6/6) still need closure
    Two carry-over KEV clusters remain open across estates: the Microsoft Defender EoP/DoS pair (CVE-2026-41091, CVSS 7.8, + CVE-2026-45498) added to KEV with a 6/3 FCEB remediation deadline, and the Mirasvit Cache Warmer for Magento unauth PHP-object-injection RCE (CVE-2026-45247, CVSS 9.8) whose 6/6 deadline has passed. Verify endpoint and e-commerce stacks are at fixed builds.
    The Hacker News — Defender · CISA KEV

Critical Vulnerabilities & Advisories

  • 🔴 Cisco Secure Workload CVE-2026-20223 (CVSS 10.0) — unauth REST-API auth bypass to Site Admin across tenant boundaries; patch out (carry-over, no ITW yet)
    Maximum-severity auth-bypass flaw in Cisco Secure Workload's internal REST APIs lets an unauthenticated, remote attacker gain Site Admin privileges, read sensitive data and modify configuration across isolated tenant boundaries — full control of data-center/cloud infrastructure config. Found via internal testing; Cisco reports no public exploitation yet. Fixed in 3.10.8.3 and 4.0.3.17 — patch immediately given the 10.0 rating.
    The Hacker News · Cisco advisory · SecurityAffairs

  • 🔴 Apache Flink CVE-2026-35194 — critical SQL-injection → RCE via the SQL-to-Java code-generation engine; full-cluster compromise
    Unsafe string interpolation in Flink's SQL code-generation path lets an authenticated user with query-submission rights inject payloads that escape string boundaries and execute arbitrary code on TaskManager nodes — leading to full cluster compromise, data manipulation or lateral movement. Disclosed by an Apache contributor mid-May and rated critical; now circulating in Chinese security media. Patch Flink to the fixed release and restrict who can submit SQL/queries to production clusters.
    CyberSecurityNews · Apache Flink Security

Vendor Advisories

  • Windows Secure Boot — 2011 CA certificates begin expiring; Microsoft KEK CA 2011 lapses 6/24 (carry-over, deadline imminent)
    The Secure Boot certificate transition is now ~2 weeks out. Devices without the 2023 CAskeep booting but lose boot-level security updates(Boot Manager, DB/DBX revocations, bootkit mitigations), entering a "degraded security state." Most PCs built since 2024 already carry the 2023 certs. Roll out the 2023 CAs via Microsoft's Secure Boot playbook before the 2011 CAs lapse on 6/24.
    Microsoft Tech Community playbook· Microsoft Support

Web Security Research

  • PortSwigger — Top 10 Web Hacking Techniques of 2025 (community-curated reading list) still the active research thread; HTTP desync + SAML auth-bypass headline
    PortSwigger Research's 19th annual Top 10 Web Hacking Techniques of 2025remains the must-read list for appsec teams — this edition spotlights new request-smuggling/desync techniques(malformed chunks, browser-redirect stalls feeding exploit chains) and SAML exploitation enabling complete auth bypass. James Kettle will debut "Meet the HTTP Terminator"at Black Hat USA 2026. Review desync and SAML exposure now.
    PortSwigger — Top 10 of 2025· PortSwigger Research

AI Security

  • ⚠️🛡 ReliaQuest agentic AI uncovers OP-512 — China-linked custom IIS web-shell framework (also see Threat Intel) — AI-on-defense data point
    ReliaQuest disclosed (6/5) that its agentic AI surfaced OP-512, a previously-undocumented, China-linked cluster running a purpose-built three-part IIS web-shell framework where each deployment is cryptographically unique to defeat signature detection. The find is a concrete example of AI accelerating defensive threat-hunting against bespoke, evasive tooling — the mirror image of offensive AI use. Treat unique-per-host web shells as the new baseline; lean on behavioral/anomaly detection over signatures.
    ReliaQuest · The Hacker News

  • ⚠️🛡 OpenAI ships GPT-5.5-Cyber to partners — a dedicated cyber model answering Anthropic's Claude Mythos (also see AI Frontier)
    OpenAI rolled out GPT-5.5-Cyber, a cybersecurity-focused model, to a large partner cohort for testing — its direct answer to Anthropic's Claude Mythos cyber model and a continuation of the Daybreak vuln-detection/patch-validation initiative (Codex-Security agent). The frontier labs are now openly racing on dual-use cyber capability, which compresses both the defender tooling cycle and the misuse-risk timeline. Track capability + access policy on these cyber-tuned models; they cut both ways.
    TechBuzz · SiliconRepublic

  • ⚠️🛡 Carry-over — indirect prompt injection still OWASP #1; MCP-client adversarial study spans Claude Desktop/Code, Cursor, Cline, Continue, Gemini CLI, Langflow
    Indirect/web-based prompt injection remains the top agentic-AI threat into 2026; recent 2026 papers comparatively adversarial-test seven widely-used MCP clients (Claude Desktop, Claude Code, Cursor, Cline, Continue, Gemini CLI, Langflow), reinforcing that containment (sandboxing, tool allowlists, least-privilege tool calls) beats prevention. Audit any agent path where model output reaches an interpreter or tool; sandbox tool calls. ·

Threat Intelligence

  • ⚠️ OP-512 — China-linked cluster targets Microsoft IIS with a bespoke web-shell framework; espionage-aligned target selection
    Fresh ReliaQuest research (6/5) details OP-512, a moderate-to-high-confidence China-linked, espionage-focused cluster targeting IIS servers with three distinct, cryptographically-unique web shells, Potato-Suite SYSTEM escalation and timestomping. Target selection mirrors Chinese collection priorities (IP, supply-chain data, government network access). It's the 4th IIS-focused cluster in 12 months after CL-STA-0048, DragonRank and GhostRedirector — but the first using a purpose-built framework designed to evade detections that catch the others. Hunt IIS for anomalous ASPX/ASHX handlers and unique-per-host shells; don't rely on signatures.
    The Hacker News · SC Media · Cyberpress

  • ⚠️ MuddyWater exploiting Langflow CVE-2025-34291 — CORS misconfig → token theft used by Iran-aligned actor
    The Iran-aligned MuddyWater APT has been observed leveraging Langflow CVE-2025-34291 (a CORS-related flaw enabling token theft) against AI-pipeline / Langflow deployments — another case of agentic-AI infrastructure becoming a direct APT target surface. Patch Langflow, lock CORS to trusted origins, and rotate any exposed tokens.
    The Hacker News · breachsense

  • Carry-over — ShinyHunters spree (Carnival ~6M, Charter/Spectrum 4.9M confirmed) still the dominant breach storyline; vishing → Entra/Salesforce
    The ShinyHunters social-engineering campaign continues to anchor the breach landscape: Carnival (~6M affected, gov-ID numbers exposed) and Charter/Spectrum (4.9M emails confirmed, 42M claimed) both traced to voice-phishing of an employee's Microsoft Entra account enabling Salesforce access. Enforce phishing-resistant MFA; harden Entra/Salesforce against vishing-driven session takeover.
    ·

Ransomware Today

  • RansomLook API (24h): 1 structured post— a single low-frequency group name blackwater(discovered 2026-06-06T20:48Z, no victim field). RSS fallback returned unparseable binary via the sandbox fetcher, so victim detail is supplemented by WebSearch aggregation. Weekend → Monday lull; backlog typically posts from Monday. Quarterly structure unchanged: Qilin #1(>1,880 tracked victims, still leading), The Gentlemen #2(one new RaaS ≈10% of 2026 global victims), Akira #3; manufacturing + business-services + healthcare remain the top sectors, US the top victim geo. Watch:new/low-frequency group blackwater— flag if it sustains posting or shows rebrand TTP overlap.
  • Full victim table + watchlist hits → intel/ransomware/daily/2026-06-08.html

AI Frontier

OpenAI

  • GPT-5.5-Cyber shipped to partners— a dedicated cybersecurity model and OpenAI's direct answer to Anthropic's Claude Mythos; continues the Daybreakvuln-detection/patch-validation push (Codex-Security agent). SiliconRepublic· TechBuzz
  • IPO prep (reported June)— OpenAI reportedly preparing a confidential IPO filing in the coming weeks, potential listing as soon as September 2026, ~$730B private valuation. CNBC
  • Real-time audio + translation models for agents (carry-over)— live voice, transcription and multilingual flows for agent builders. LLM-Stats

Anthropic

  • Claude Mythos / Project Glasswing scaled to critical infrastructure across 15+ countries (6/2)— Mythos Preview extended to ~150 new orgs (power, water, healthcare, comms, hardware); Claude Security(repo scans + patch suggestions, using Opus 4.8) shipping; partners have found 10,000+ high/critical bugs. TechCrunch· GovInfoSecurity
  • Claude Opus 4.8 — 1M-token default context (model claude-opus-4-8, GA late May)— hybrid reasoning model pushing the coding/agent frontier; Claude Code gained Dynamic Workflows. Anthropic — Opus 4.8
  • Confidential S-1 filed (6/1)— Anthropic submitted a confidential draft S-1 to the SEC, formalizing its IPO process. CNBC

Google DeepMind / AI

  • Gemini 3.5 Pro imminent— Pichai's I/O line "give us until next month"; Gemini 3.5 Flashalready GA (5/19), default in the Gemini app and AI Mode in Search ($1.50/$9.00 per Mtok). WaveSpeed· llm-stats
  • Gemini Robotics-ER 1.6 in Boston Dynamics Spot— DeepMind + Google Cloud integrating embodied Gemini into Spot and the Orbit AI inspection platform. DeepMind models
  • SynthID provenance watermarking (carry-over)— cross-vendor adoption (OpenAI, Kakao, ElevenLabs) continues to firm up AI-content attribution / anti-abuse. Google blog

🛡 = security-relevant


Chinese Community Picks

  • Supply chain (供应链) stays the dominant local topic— FreeBuf / AnQuanKe / YiJingLab continue follow-up on the codexui-androidnpm package (typosquat exfiltrating persistent refresh_tokenvia fake Sentry traffic), HiddenLayer's Hugging Face Open-OSS/privacy-filtertyposquat poisoning the AI-dev community, and the earlier tampered Jenkins/Checkmarx plugin thread. FreeBuf 供应链
  • Apache Flink CVE-2026-35194 (SQL-injection → RCE)is on local big-data / infra-security radars given Flink's footprint in Chinese data platforms. CyberSecurityNews
  • Anthropic Project Glasswing / Claude Mythos expansionresonates as a concrete "AI 自动化攻防" case (10,000+ bugs found), paired with OpenAI's GPT-5.5-Cyber as the frontier-lab cyber arms-race framing. FreeBuf

Failed / Limited Sources

  • RansomLook RSS (rss.xml)— returned unparseable binary via the sandbox fetcher; the /api/posts?days=1JSON endpoint worked but returned only 1 structured post (no victim field). Per-victim ransomware detail supplemented via WebSearch aggregation; exact discovery timestamps not guaranteed.
  • Direct RSS/Atom feeds (CISA, The Hacker News, BleepingComputer, vendor blogs, Chinese feeds)— direct fetch blocked by the sandbox egress allowlist; this edition reconstructed via WebSearch over the same source set.

Source configuration: see intel/sources.yaml

← Prev
Rosetta Daily · Jun 7, 2026
Next →
Rosetta Daily · Jun 9, 2026

arXiv — MCP clients
LLM Security Risks 2026
Malwarebytes — Carnival
The Register — Charter