Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-06-11
Daily Brief·2026-06-11·19 Items

Rosetta Daily · Jun 11, 2026

Generated automatically · 31 sources configured (WebSearch aggregation + RansomLook API direct) · 19 items selected
Window: past 24h (2026-06-10 → 2026-06-11). Thursday — two days after June Patch Tuesday. Main threads: a fresh Veeam Backup & Replication 9.4 RCE (backup servers = ransomware's #1 target), a public PoC ("RoguePlanet") for the Defender EoP patched Tuesday, the Check Point VPN 0-day → Qilin campaign continuing under its CISA KEV deadline, the Tchap French-government messenger breach, and a leak-site surge led by a LockBit5 mass dump.

In-the-Wild Exploitation (CISA KEV)

  • 🔴🔥⚠️ Check Point VPN CVE-2026-50751 — CVSS 9.3 auth bypass, exploited as 0-day since 5/7; in CISA KEV (added 6/8)
    Improper-authentication flaw in Remote Access VPN / Mobile Access lets attackers establish a VPN session without valid credentials on gateways using deprecated IKEv1 and accepting legacy clients. Check Point confirms in-the-wild exploitation since May 7 with a June spike; at least one intrusion is linked (medium confidence) to a Qilin ransomware affiliate. CISA ordered FCEB agencies to patch. Action: apply the Check Point hotfix; disable/replace legacy IKEv1 remote access; enforce machine certificates.
    Rapid7 · Check Point · BleepingComputer — CISA order

  • 🔴🔥⚠️ BerriAI LiteLLM CVE-2026-42271 — added to CISA KEV (6/8), actively exploited AI gateway flaw
    CISA added a LiteLLM vulnerability to KEV alongside the Check Point flaw after confirming active exploitation. LiteLLM is a widely deployed LLM-proxy/gateway, so this is AI infrastructure being hit directly in the wild. Action: patch LiteLLM to the fixed release; restrict gateway exposure and rotate provider keys reachable from the proxy.
    Windows Forum — KEV update · CISA KEV

  • 🔴⚠️ Everest Forms Pro (WordPress) CVE-2026-3300 — CVSS 9.8 unauth RCE, exploited, full site takeover
    PHP eval() injection via the Complex Calculation feature allows unauthenticated remote code execution and complete WordPress takeover. Public-facing forms are directly exposed; exploitation is ongoing. Action: update immediately; hunt for webshells and rogue admin accounts on affected hosts.
    The Hacker News · CISA KEV

  • 🔥 SolarWinds Serv-U CVE-2026-28318 — CVSS 7.5 DoS, in CISA KEV (added 6/5), FCEB deadline 6/19
    Crafted HTTP requests can crash the Serv-U multi-protocol file server. Action: upgrade Serv-U and tighten exposure of the management interface.
    CyberSecurityNews · CISA KEV

  • ⚠️ Microsoft Defender EoP CVE-2026-41091 — public PoC "RoguePlanet" released; multiple ITW acknowledgements
    A researcher using the handle "Chaotic Eclipse" released a working PoC ("RoguePlanet") tested against Windows 11/10 with the June Patch Tuesday updates installed; the patch credited multiple parties, signaling meaningful in-the-wild activity. Action: confirm Defender platform/engine updates have reached every endpoint.
    Krebs/aggregate · ZDI — June review

Critical Vulnerabilities & Advisories

  • 🔴 Veeam Backup & Replication CVE-2026-44963 — CVSS 9.4 RCE; any domain user can take over the backup server
    Disclosed 6/9 by Sina Kheirkhah (watchTowr). Affects B&R 12 through 12.3.2.4465; 13.x is not affected. On domain-joined servers, an authenticated non-admin domain user can achieve RCE on the backup server — a textbook pre-ransomware target. No ITW exploitation yet, but Veeam warns of rapid weaponization. Action: upgrade to 12.3.2.4854 now; isolate backup infrastructure off the domain where feasible.
    BleepingComputer · The Hacker News · Veeam advisory

  • 🔴 June 2026 Patch Tuesday (6/9) — record ~200 CVEs, ~36 critical, public exploit code for ≥3
    Microsoft's largest-ever monthly batch: nearly 200 fixes, three dozen critical, and at least three flaws with publicly available exploit code (see Defender above). Action: prioritize the critical RCE/EoP items and the publicly-exploitable trio.
    ZDI — June 2026 review · SecurityWeek

  • 🔴 n8n — max-severity defect exposes public instances to takeover
    Researchers are warning defenders of a critical flaw in the n8n automation platform that puts public-facing instances at risk of takeover. Action: put n8n behind SSO/private network and upgrade to the fixed release.
    CyberScoop

Vendor Advisories

  • Veeam — Backup & Replication 12.3.2.4854fixes CVE-2026-44963 (9.4 RCE). Treat as priority given backup servers' ransomware value. BleepingComputer
  • Microsoft — June 2026 Patch Tuesdaycumulative updates (~200 CVEs incl. the exploited/public-PoC items). ZDI
  • Check Point — IKEv1 remote-access VPN hotfix(CVE-2026-50751 + CVE-2026-50752); handle as emergency given confirmed 0-day use. Check Point

Web Security Research

  • PortSwigger — Top 10 Web Hacking Techniques of 2025 (19th edition)
    PortSwigger's community-powered ranking is live, continuing the dominant threads of malformed-chunk HTTP desync, browser redirect/timing chains, and SAML auth bypass. Useful as a retest checklist for any public-facing stack. Action:re-run desync and SAML exposure checks against internet-facing services.
    PortSwigger — Top 10 of 2025· Research index

AI Security

  • ⚠️🛡 Prompt injection still "unpatchable" — Google sees +32% malicious payloads (Nov 2025 → Feb 2026); OWASP #1; OpenAI ships Lockdown Mode
    Coverage compiles the consensus that prompt injection affects every major assistant (OpenAI, Anthropic, Google, Microsoft). Google measured a 32% rise in injection payloads embedded in web content; Unit 42 published ITW indirect-injection observations; OpenAI launched Lockdown Mode / Elevated-Risk labels (Feb 13) after admitting browser injection "may never be fully solved." Action: treat injection as unsolved — enforce tool allowlists + least privilege, require human confirmation for high-impact actions, isolate "model output → interpreter" paths.
    Frank's World — unpatchable flaw · Vectra

  • ⚠️🛡 First fully AI-driven intrusion documented — Sysdig: LLM agent improvised attack, breached an exposed marimo notebook server in 22 minutes
    Sysdig reports the first observed case of an attacker using an LLM agent to generate attack commands in real time, compromising an exposed marimo notebook server in ~22 minutes. Pairs with the ongoing OpenClaw / ClawHub "skill" supply-chain poisoning thread. Action: lock down exposed notebook/dev services; treat agent skills/MCP tools as untrusted code.
    FreeBuf weekly (CN-SEC mirror)

Threat Intelligence

  • 🛡 Unit 42 — Iranian APT "Screening Serpens" using AppDomainManager hijacking + new RAT variants vs. tech/defense
    Unit 42 details fresh espionage campaigns leveraging AppDomainManager hijacking and novel RATs against technology and defense targets. Action: hunt for AppDomainManager hijack artifacts; review .NET config-driven load paths.
    Unit 42

  • Tchap (French government messenger) breached via hijacked account; attacker claims 13.5 GB exfiltrated
    ANSSI detected the intrusion 6/7; a threat actor used a compromised account (claiming hardcoded LDAP creds leaked via a PowerShell script). Officials say impact was limited to public rooms; the actor claims 73k accounts, 643k messages and "Diffusion Restreinte" references — unverified. Action: audit for hardcoded creds in scripts; review SSO/account-takeover monitoring.
    BleepingComputer · The Register

  • ShinyHunters dumps ~396k BCD Travel customer records after missed ransom deadline
    After BCD Travel did not pay, ShinyHunters published ~396,313 unique email addresses (from a Salesforce dataset, plus SharePoint corporate data) with names, addresses, phones and job titles. Action: phishing-aware comms for affected travelers; monitor for credential-stuffing using leaked PII.
    Cybernews · HIBP

Chinese-Language Community Picks

  • OpenClaw becomes a new supply-chain poisoning target / Sysdig's first AI-driven attack / GitHub breached by TeamPCP(FreeBuf weekly)
    This cycle's FreeBuf weekly roundup: OpenClawhas become a new poisoning target via malicious "skills" distributed through ClawHub; Sysdigdocumented the first AI-driven intrusion (marimo compromised in 22 minutes); GitHubwas breached by TeamPCP, with roughly 4,000 private repositories stolen and offered for USD 50,000 (CI/CD credentials exfiltrated); and the new BitUnlockertool exploits the gap between patch rollout and certificate revocation to physically crack a patched Windows 11 BitLocker volume in five minutes.
    FreeBuf weekly (CN-SEC mirror)· FreeBuf vulnerabilities

Ransomware Today

32 new leak-site posts in the window across 7 groups. Most active: LockBit5 (16 — mass dump / resurgence), Qilin (6), then Akira / RansomHouse / Termite / Stormous (2 each) and Nova (1). Watchlist group hits: lockbit, qilin, akira. The RansomLook API returned group + timestamp only this run (no victim/sector titles), so sector/geo matching is unavailable today. Notable named victim from news: BCD Travel (ShinyHunters). → Full ransomware table


AI Frontier

OpenAI

  • GPT-5.3-Codexreleased — OpenAI claims the model "played a crucial role in creating itself," extending the self-improving-coding-model trend.

Anthropic

  • Claude Fable 5 (Mythos-class) shipped publicly (~6/9)— GA on Amazon Bedrock and GitHub Copilot. Security/compliance catch:Fable 5 mandates 30-day data retention with human reviewfor trust & safety, which overrides existing Zero-Data-Retention (ZDR) agreementsfor this model class — a notable change for regulated enterprises. Released days after Anthropic's 6/4 essay "When AI builds itself"calling for a coordinated frontier slowdown; Anthropic also confidentially filed for IPO (~6/1).
    Anthropic· Cybernews — retention
  • Project Glasswing expanded— ~150 more orgs given Claude Mythos preview access; program reportedly helped partners find 10k+ high-severity vulns.

Google DeepMind / AI

  • Gemini 3.5 Pro expected this month(Pichai: "give us until next month"); Gemini 3.5 Flashis already the default in the Gemini app and Search AI Mode.
  • Gemini Robotics-ER 1.6integrated into Boston Dynamics' Spot + Orbit inspection platform (Google Cloud partnership).

🛡 = security-relevant


Failed / Degraded Sources

  • RansomLook RSS (rss.xml) — returned binary/undecodable payload; used the JSON postsAPI instead (group + timestamp only, no victim titles this run).
  • Several RSS feeds not directly parseable via fetch (Apple HT201222, xz.aliyun.com, vendor Atom) — covered via WebSearch aggregation.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jun 10, 2026
Next →
Rosetta Daily · Jun 12, 2026