Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-06-09
Daily Brief·2026-06-09·16 Items

Rosetta Daily · Jun 9, 2026

Generated automatically · 31 sources configured (WebSearch aggregation mode; direct RSS/Atom egress still blocked by sandbox allowlist) · 16 items selected
Window: past 24 hours (2026-06-08 → 2026-06-09). Tuesday — June Patch Tuesday lands today. Headline themes: edge-device exploitation (Citrix/Netlogon/Exchange), a large npm supply-chain worm (Miasma), and the first reported fully AI-driven intrusion.

In-the-Wild Exploitation / Actively Exploited

  • 🔴🔥⚠️ Citrix NetScaler ADC/Gateway CVE-2026-3055 — CVSS 9.8, large-scale exploitation confirmed; SAML IDP memory overread → unauth RCE
    An out-of-bounds read (memory overread) in NetScaler ADC/Gateway when configured as a SAML Identity Provider lets an unauthenticated, remote attacker send crafted SAML requests to leak memory and, in chained use, achieve code execution. Fortinet's threat-intel team confirmed large-scale active exploitation against internet-facing appliances. Fix: upgrade to 13.1-62.23 / 14.1-60.58 (standard) or 13.1-37.262 (FIPS/NDcPP) immediately; rotate any secrets exposed via memory leak.
    Threat-Modeling.com · Rapid7 · Citrix bulletin CTX696300

  • 🔴🔥⚠️ Windows Netlogon CVE-2026-41089 — RCE on domain controllers, now exploited in the wild (CCB warning)
    A stack-based buffer overflow in Windows Netlogon lets an attacker send a specially crafted network request to a DC and execute code over the network — a domain-takeover-class flaw. Belgium's CCB warns of active exploitation. Microsoft has shipped patches for Server 2016/2019/2022/23H2/2025. Fix: apply via Windows Update immediately; treat any unpatched internet- or perimeter-reachable DC as critical exposure.
    Help Net Security · Tenable — Patch Tuesday context

  • 🔥⚠️ Microsoft Exchange Server CVE-2026-42897 — Critical spoofing flaw exploited; no patch yet, auto-mitigation via EEMS
    Microsoft reports exploitation of CVE-2026-42897, a Critical-rated spoofing vulnerability in on-prem Exchange. No patch is available at this time; per Microsoft, the Exchange Emergency Mitigation Service (EEMS) applies mitigation automatically and is on by default. Action: confirm EEMS is enabled on all Exchange servers and watch for the out-of-band fix.
    Tenable CVE · Help Net Security — Vuln Intel

  • 🔥⚠️ Cisco Catalyst SD-WAN Manager CVE-2026-20245 — actively exploited, still no patch (CVSS 7.8, carry-over)
    Cisco's unpatched, actively-exploited CLI flaw remains a top open item: insufficient input validation lets an authenticated netadmin upload a crafted file and run commands as root. Chains with May's SD-WAN bugs (CVE-2026-20182 / -20127) for the initial foothold. Interim: be on the 20182-fixed build and lock down netadmin access.
    The Hacker News

  • 🔥⚠️ Android Framework CVE-2025-48595 — actively-exploited 0-day in June 2026 update; in CISA KEV (carry-over)
    Google's June 2026 Android update fixes an integer-overflow EoP flaw under "limited, targeted exploitation" requiring no user interaction; Android 14–16. CISA KEV–listed (FCEB deadline 6/5 passed). Action: roll the June patch level to managed fleets, prioritize devices that can't auto-update.
    Help Net Security · CISA KEV

Critical Vulnerabilities & Advisories

  • 🔥 CISA KEV update — CVE-2026-45247 (Mirasvit Full Page Cache Warmer, deserialization of untrusted data) added 6/3; deadline passed
    CISA added the Mirasvit Cache Warmer for Magento unsafe-deserialization RCE (CVSS 9.8) to the KEV catalog on June 3 on evidence of active exploitation; the FCEB remediation deadline (6/6) has now passed. Action: verify e-commerce / Magento stacks are at fixed builds.
    CISA alert (6/3) · CISA KEV

  • 🔴 June 2026 Patch Tuesday lands today (6/9) — light forecast, but Netlogon + Exchange dominate the open exposures
    Help Net's forecast flagged an unusually quiet pre-Patch-Tuesday week; the practical priority for this cycle is closing the Netlogon RCE (CVE-2026-41089) and tracking the out-of-band Exchange (CVE-2026-42897) mitigation alongside the May Defender KEV pair. Action: plan the June rollout around DC and mail-server exposure first.
    Help Net — June 2026 forecast · Zecurit Patch Tuesday

Vendor Advisories

  • Citrix security bulletin CTX696300 (CVE-2026-3055 + CVE-2026-4368)— fixed builds and SAML-IDP hardening guidance; treat as emergency given confirmed mass exploitation. Citrix
  • Microsoft Exchange — EEMS auto-mitigationfor CVE-2026-42897 is on by default; verify it has not been disabled in hardened/locked-down deployments. Tenable

Web Security Research

  • PortSwigger Research — "Meet the HTTP Terminator" to debut at Black Hat USA 2026; Top 10 Web Hacking Techniques of 2025 still the active reading thread
    PortSwigger teased an autonomous system that invents new attack techniques and hacks live targets at scale("HTTP Terminator") for Black Hat USA 2026, and recently demonstrated end-to-end email account takeovers using CSS/HTMLagainst multiple major providers. The Top 10 of 2025 list continues to headline request-smuggling/desyncand SAML auth-bypass. Action:re-check desync and SAML exposure on internet-facing stacks.
    PortSwigger — Black Hat preview· Top 10 of 2025

AI Security

  • ⚠️🛡 Miasma npm supply-chain worm — 32 @redhat-cloud-services packages (96 versions) trojanized; harvests cloud/CI secrets (also see Threat Intel)
    Microsoft Threat Intelligence and Wiz detail Miasma, a self-spreading npm worm: a compromised Red Hat employee GitHub account pushed malicious orphan commits, trojanizing 32 @redhat-cloud-servicespackages (96 versions, ~117k weekly downloads). A preinstall hook runs a 4.29 MB obfuscated dropper that harvests GitHub/npm tokens, cloud creds, HashiCorp Vault and Kubernetes secrets, including scraping CI-runner process memory. Derived from the "Mini Shai-Hulud" code open-sourced by TeamPCP (5/12). Action: audit for the affected scope, rotate any CI/cloud secrets, and enforce 2FA + provenance on publish pipelines.
    Microsoft Security Blog · Wiz · Red Hat RHSB-2026-006

  • ⚠️🛡 First reported fully AI-driven intrusion — LLM agent breaches an exposed marimo notebook (CVE-2026-39987) in ~22 minutes (Sysdig)
    Sysdig reports what it calls the first AI-driven cyberattack observed in the wild: an LLM agent generated attack commands in real time, exploited an exposed marimo notebook server (CVE-2026-39987), and exfiltrated internal databases in roughly 22 minutes end-to-end. This is the offensive mirror of the AI-on-defense trend — automation compressing the intrusion timeline to minutes. Action: don't expose notebook/dev servers to the internet; assume sub-hour dwell on any internet-reachable misconfiguration.
    FreeBuf · Unit 42 — 2026 IR Report context

  • ⚠️🛡 Microsoft: "When prompts become shells" — RCE-class vulnerabilities across AI agent frameworks; prompt injection remains OWASP #1 (2026)
    Microsoft's security research documents how prompt-injection can escalate to remote code execution inside agent frameworks where model output reaches an interpreter or tool. Indirect prompt injection remains the . sandbox tool calls, enforce tool allowlists and least-privilege, and treat any model-output→interpreter path as an injection surface. ·

Threat Intelligence

  • ⚠️ Screening Serpens (Iran-nexus APT) — AppDomainManager hijacking + six new RAT variants targeting aerospace/defense/telecom (Unit 42)
    Unit 42 tracks Screening Serpens expanding from the Middle East into Western Europe, hitting aerospace, defense manufacturing and telecom via AppDomainManager hijacking and six new RAT variants built Feb–Apr 2026. Action: hunt for AppDomainManager .config side-loading and anomalous .NET app-domain behavior in defense-sector estates.
    Unit 42

  • ⚠️ Unit 42 2026 Global IR Report — AI makes attacks ~4× faster; 65% of initial access is identity-based, 87% multi-surface
    The annual IR report finds AI moving actors from initial access to exfiltration in minutes (data exfil <1h in some cases), with 65% of intrusions identity-driven and 87% spanning multiple attack surfaces. Action: prioritize phishing-resistant MFA and identity-threat detection; assume compressed response windows.
    Unit 42 IR Report

  • ⚠️ GitHub account compromise → npm supply chain (Miasma / TeamPCP) — the dominant supply-chain storyline this week
    The Miasma campaign and the related TeamPCP "Mini Shai-Hulud" lineage underscore that a single compromised maintainer GitHub account now reliably converts into mass package-registry poisoning. Chinese media also report GitHub itself confirming a TeamPCP breach with ~4,000 private repos offered for sale. Action: harden maintainer accounts (hardware 2FA), require signed/provenance-verified publishes, and monitor for orphan-commit pushes.
    Wiz · StepSecurity

Ransomware Today

  • ransomware.live snapshot (updated 2026-06-07; victims discovered 6/5–6/6): ~12 fresh posts across ~10 groups.Most active in-window: Qilin, Akira, Play, with Nova, Anubis, Krybit, INC Ransom (Incransom)also posting. Watchlist hits: Play → Pearson Ford (US, transport/logistics), INC → kelmreuter.com / obrieneng.com (US), Nova → Aspire Hospital (IN, healthcare) & Universitas Nasional (ID, education), Krybit → huashan.com.cn (CN semiconductor manufacturer). Quarterly structure unchanged: Qilin #1(Q1: 338 victims, 3rd straight quarter), LockBit recovered to #4 (163), with Qilin+Akira+The Gentlemen+LockBit ≈ 41% of all victims. Weekend lull; expect mid-week backlog to post.
  • Full victim table + watchlist hits → intel/ransomware/daily/2026-06-09.html

AI Frontier

OpenAI

  • ChatGPT "Active sessions" + "Lockdown Mode" security features— review/sign-out of account sessions (device, location, sign-in time, trusted status); Lockdown Mode restricts network-enabled capabilities (live browsing, deep research, agent mode, file downloads). Releasebot — OpenAI
  • GPT-5.5 Instant rolling out to all ChatGPT users; GPT-4.5 retires from ChatGPT 6/27 (30-day sunset). Releasebot — ChatGPT
  • Memory upgrade ("dreaming")— 2× memory for Plus/Pro, auto-revised memories, location/time-aware recommendations; a quality-gated version reaches free users. Releasebot — OpenAI

Anthropic

  • Project Glasswing expanded — Claude Mythos Preview to ~150 new orgs across 15+ countries (mostly critical infrastructure); Claude Security shipsrepo scans + patch suggestions using Claude Opus 4.8; partners have found 10,000+ critical bugs. Anthropic — Expanding Glasswing· Anthropic — Claude Code security
  • Claude Managed Agents — self-hosted sandbox (public beta) + private MCP serverswithin enterprise boundaries; tool execution moves to your environment while the agent loop stays on Anthropic infra. InfoQ
  • Claude Opus 4.8 released(stronger coding/agentic/reasoning vs 4.7); confidential draft S-1 filed with the SEC 6/1. Releasebot — Anthropic· CNBC

Google DeepMind / AI

  • Gemini 3.5 Pro nearing June GA— 2M-token context, "Deep Think" reasoning, frontier multimodal; 3.5 Flashalready GA (5/19), default in the Gemini app and AI Mode in Search. TechTimes· blog.google — Gemini 3.5
  • Gemini Robotics-ER 1.6 in Boston Dynamics Spot— DeepMind + Google Cloud integrate embodied Gemini into Spot and the Orbit AI inspection platform. Google Cloud Blog

Cross-lab

  • OpenAI + Anthropic + Google + Microsoft CEOs' joint letter to Congress (6/5)calling for mandatory synthetic-DNA-provider screening— a notable bio-misuse safety ask spanning the frontier labs. Yellow.com

🛡 = security-relevant


Chinese Community Picks

  • Sysdig — "first AI-driven cyberattack"(LLM agent, exposed marimo notebook CVE-2026-39987, ~22-min breach) is the standout local story, framing AI-automated offense as no longer theoretical. FreeBuf· 微步在线 X 情报社区
  • Supply chain (供应链) stays dominant— local follow-up on Miasma(@redhat-cloud-services npm) and the earlier codexui-androidnpm typosquat (exfiltrating persistent refresh_token); GitHub reportedly confirmed a TeamPCPbreach (~4,000 private repos, $50k sale). FreeBuf 供应链· 安全内参
  • Domestic ransomware victim— huashan.com.cn(Shantou Huashan, a Chinese semiconductor-device maker) posted by Krybit— a reminder that CN manufacturing is on extortion radars. ransomware.live

Failed / Limited Sources

  • RansomLook /api/posts?days=1and rss.xml— unreachable from the sandbox (egress 403 / not in fetch-provenance set). Ransomware detail this edition is sourced from ransomware.live(snapshot updated 2026-06-07) plus WebSearch aggregation; exact per-victim discovery timestamps not 100% guaranteed.
  • Direct RSS/Atom feeds (CISA, The Hacker News, BleepingComputer, MSRC, PortSwigger, Mandiant/Unit 42, Chinese feeds)— direct fetch blocked by the sandbox egress allowlist + web_fetch provenance restriction; this edition was reconstructed via WebSearch over the same configured source set.

Source configuration: see intel/sources.yaml

← Prev
Rosetta Daily · Jun 8, 2026
Next →
Rosetta Daily · Jun 10, 2026
OWASP #1 AI threat for 2026
Action:

Microsoft Security Blog
Securance — OWASP #1