Rosetta Daily · Jun 15, 2026
Generated automatically · 30 sources scanned · 38 items selected
Window: trailing ~72h (Patch Tuesday week + weekend). Items dated 2026-06-08 → 2026-06-13.
Critical Vulnerabilities
-
Critical Check Point VPN Zero-Day — Check Point Remote Access VPN / Mobile Access / Spark, CVE-2026-50751, CVSS 9.3 🔴🔥⚠️
Unauthenticated auth-bypass lets an attacker establish a VPN session without valid credentials. Exploited in the wild since ~May 7, ramping in early June; added to CISA KEV June 8.
Rapid7 analysis -
Microsoft June Patch Tuesday — ~200 CVEs, actively exploited Defender flaw — Windows, CVE-2026-41091 (Defender EoP), CVSS pending 🔴🔥⚠️
Record-breaking cycle (~198–208 CVEs, 33 critical, 28 RCE) with 3 publicly-disclosed zero-days; CVE-2026-41091 Defender elevation-of-privilege is actively exploited.
BleepingComputer · ZDI review -
Everest Forms Pro unauthenticated RCE — WordPress plugin, CVE-2026-3300 🔴⚠️
Unauthenticated remote code execution via PHPeval()injection; actively exploited against WordPress sites.
The Hacker News -
Microsoft Exchange Server spoofing — Exchange, CVE-2026-42897, CVSS 8.1, Critical 🔴
Spoofing flaw rated Critical, shipped in the June cycle; prioritize for internet-facing Exchange.
Security Affairs -
BerriAI LiteLLM command injection — LiteLLM gateway, CVE-2026-42271 🔥⚠️
Command injection in the popular LLM proxy/gateway; added to CISA KEV June 8 — first-class example of AI infrastructure being exploited in the wild.
CISA KEV (Jun 8)
In-the-Wild Exploitation (CISA KEV — additions Jun 8–9)
- CVE-2026-50751— Check Point Security Gateway improper authentication (see above).
- CVE-2026-42271— BerriAI LiteLLM command injection.
- CVE-2026-7473— Arista EOS incomplete comparison / missing factors.
- CVE-2026-11645— Google Chromium V8 out-of-bounds read & write.
- CVE-2026-20245— Cisco Catalyst SD-WAN Manager improper output encoding/escaping.
CISA — Jun 9 (three added)
Vendor Advisories
- Microsoft & Adobe Patch Tuesday (June 9)— Microsoft ~200 CVEs incl. 3 zero-days; Adobe shipped its companion set the same day.
Qualys review - Apple — ongoing 26.5.x updates— Most platforms now on iOS/macOS 26.5+; 2026 has seen multiple exploited zero-days (CVE-2026-20700 dyld; CVE-2026-20643 WebKit SOP bypass).
Apple security releases· TechRepublic roundup - Red Hat RHSB-2026-006— Supply-chain compromise of
@redhat-cloud-servicesnpm packages (see Threat Intel).
Red Hat advisory - Cisco Catalyst SD-WAN Manager— CVE-2026-20245 now in KEV; patch management-plane immediately.
Web Security Research
- "Meet the HTTP Terminator" (PortSwigger / James Kettle)— Debuting at Black Hat USA 2026.
Novel techniques for compromising email accounts by breaking trust boundaries with CSS/HTML, slipping past CSS sanitization and hardened CSP for end-to-end account takeover on multiple major email providers; includes human/AI research collaboration findings.
PortSwigger Research - Novel SAML authentication bypass— Complete auth-bypass class featured in PortSwigger's Top 10 Web Hacking Techniques of 2025.
Top 10 of 2025
AI Security
- Prompt injection is the #1 AI threat of 2026— OWASP's 2026 LLM report cites a 340% YoY surge; LLMs still can't separate trusted instructions from untrusted input in one context window.
EC-Council - CVE-2026-42271 LiteLLM command injection exploited in the wild— AI gateway/proxy added to CISA KEV (cross-listed above).
- Lakera — agent memory-injection research— Indirect prompt injection via poisoned data can corrupt an agent's long-term memory, planting persistent false beliefs about security policy; multi-agent estates without central DLP create per-agent exfil points.
Lakera - OpenAI's response to the TanStack npm supply-chain attack— Vendor writeup on detection/response after a poisoned dependency reached its toolchain.
OpenAI
Threat Intelligence
- Mandiant M-Trends 2026— Drawing on 500k+ investigation hours; defender intervention window has collapsed in some intrusions from hours to 22 seconds, while other actors dwell for years.
SecurityBrief summary @redhat-cloud-servicesnpm supply-chain compromise— Wiz: ≥32 packages / 96 poisoned versions published in a ~72-second automated burst, carrying a credential-stealing worm ("Miasma," akin to Mini Shai-Hulud); likely CI/CD + GitHub Actions OIDC abuse.
Wiz· SecurityWeek- Arch User Repository (AUR) mass-hijack (June 11)— 400+ community packages turned into a malware-delivery network.
PrivacyGuides roundup - 33 malicious npm packages abuse dependency confusion— Microsoft: packages profile developer environments. (late May, still circulating)
Microsoft Security - Europol disrupts "AudiA6" laundering service (June 12)— Crypto-laundering service used by ransomware gangs taken down.
CYFIRMA weekly
Chinese-Language Community Picks
- Pwn2Own Berlin 2026 capacity crisis + "retaliatory disclosure"— for the first time in 19 years, the ZDI-run contest turned away a large number of researchers because it was full; those rejected then publicly disclosed vulnerability details in NVIDIA, Docker, Linux KVM, PyTorch and others.
FreeBuf / SecRSS - Notepad++ vulnerability can lead to full system control— a local privilege-escalation / takeover issue reported by FreeBuf.
FreeBuf (CSDN mirror) - npm
codexui-androidsupply-chain attack— a "utility" with roughly 27,000 weekly downloads turned out to be a stealer carrying hidden credential-theft and exfiltration code.
FreeBuf
Ransomware Today
RansomLook recent-posts feed shows ~32 new leak-site posts in the latest batch (discovered 2026-06-08→09). Most active groups: lockbit5 (bulk of posts), qilin, akira, plus ransomhouse, termite, stormous, nova. Watchlist hits: ⭐ lockbit / akira / qilin. Separately, The Gentlemen (worm-capable, 478 claimed victims) and fresh leak-site listings (Brain Cipher → The Adviser, ~350 GB; Kairos → Gregory Jewellers, ~574 GB) stand out.
→ Full victim table
AI Frontier
OpenAI
- GPT-5.5family shipped (Pro, Instant) — pitched as OpenAI's strongest yet for coding/research/data. Personalization improvements rolled to ChatGPT Go & Free (June 9). GPT-5.2 retired in ChatGPT (June 12); o3 sunsets Aug 26.
GPT-5.5 Instant - Published its TanStack npm supply-chainincident response (see AI Security).
Anthropic
- Claude Fable 5announced (June 9) — safer general-use model with stronger coding, vision, memory, long-context; Claude Mythos 5for trusted-access users.
Releasebot - Billing split (effective June 15)— Claude Agent SDK /
claude -pusage moves to a separate dollar-denominated credit at API list prices, no longer counting against plan limits.
Codersera writeup - Project Glasswingexpanded to ~150 orgs with Claude Mythos preview; partners reportedly surfaced 10,000+ high-risk vulnerabilities, now with patch-writing/pentest support.
Google DeepMind / AI
- Gemini 3.5 Flashlaunched at I/O 2026; Ultra cut to $200/mo, new Developer tier at $100/mo; ~900M monthly Gemini users; hired 20+ Contextual AI researchers under an ~$80–90M licensing deal.
I/O 2026 recap· DeepMind blog
Failed / Degraded Sources
- Direct RSS/Atom fetch unavailable in this run (fetch tool requires in-context URLs; sandbox network blocked). Coverage gathered via web search + RansomLook public API. Per-feed deep extraction (PortSwigger, Project Zero, DFIR Report, FreeBuf, anquanke) approximated from search results rather than raw feeds.
- RansomLook
days=1API returned its latest available batch dated 2026-06-08/09 (no 06-14/15 posts surfaced); victim/sector fields absent in this payload — only group_name + discovered timestamps.
Sources used: see intel/sources.yaml