Rosetta Daily · Jun 16, 2026
Generated automatically · 30 sources scanned · 31 items selected
Window: trailing ~24h, items dated 2026-06-14 → 2026-06-15. Yesterday's brief covered the June Patch Tuesday cycle; today leads with fresh disclosures.
Critical Vulnerabilities
-
Wazuh Manager 5.0 — agent-to-SIEM bulk-injection (silent evidence destruction) — Wazuh 5.0, GHSA-ff9g-85jq-r3g3, CVSS 10.0 🔴⚠️
Any enrolled agent can smuggle arbitrary OpenSearch_bulkoperations through an unsanitizedDataValue.indexflatbuffer field in the newinventory_syncsubsystem (does not exist in 4.x). No auth, no user interaction, network-exploitable — lets an attacker delete alerts, destroy forensic evidence, and tamper SIEM data across the whole deployment. Affects 5.0.0-beta1 → beta2; fixed in 5.0.0-beta3.
Cybersecurity News · Cyber Press -
PAN-OS GlobalProtect authentication bypass — actively exploited — Palo Alto Networks PAN-OS, CVE-2026-0257, CVSS 7.8 (revised up from 4.7) 🔴🔥⚠️
Remote unauthenticated attackers forge authentication-override cookies to establish VPN sessions without credentials. Unit 42 published a threat brief confirming in-the-wild exploitation; in CISA KEV with a June 19 federal patch deadline.
Unit 42 threat brief · Rapid7 -
Everest Forms Pro — unauthenticated RCE (still exploited) — WordPress plugin, CVE-2026-3300 🔴⚠️
Unauthenticated remote code execution via PHPeval()injection; opportunistic exploitation continues against WordPress sites — patch/disable the plugin.
The Hacker News
In-the-Wild Exploitation (CISA KEV)
- CVE-2026-0257— Palo Alto GlobalProtect auth bypass; remediate by June 19(see above).
- CVE-2026-7473— Arista EOS incomplete comparison / missing factors (added Jun 9).
- CVE-2026-11645— Google Chromium V8 out-of-bounds read & write (added Jun 9).
- CVE-2026-20245— Cisco Catalyst SD-WAN Manager improper output encoding (added Jun 9).
CISA KEV — Jun 9 additions
Vendor Advisories
- Palo Alto Networks — CVE-2026-0257 advisory— Score revised to 7.8 after confirmed exploitation; fixed PAN-OS releases available; review GlobalProtect auth-override config.
security.paloaltonetworks.com - Microsoft June Patch Tuesday aftermath— Record cycle (~200–206 CVEs, 33–39 critical, 3 publicly-disclosed zero-days incl. CTFMON EoP, HTTP.sys DoS, BitLocker bypass). Prioritize internet-facing Exchange/HTTP.sys.
BleepingComputer· Talos
Web Security Research
- "CSS: the bomb inside your inbox" (PortSwigger)— Upcoming-talk research on novel CSS/HTML techniques that slip past CSS sanitization and hardened CSP to achieve end-to-end email account takeover on multiple major providers.
PortSwigger Research - Top 10 Web Hacking Techniques of 2025 — nominations / write-ups— Community shortlist including a complete SAML authentication-bypass class; useful pen-test reference.
PortSwigger Top 10
AI Security
- PromptSnatcher — covert interception of AI conversations (~90k users)— Newly uncovered data-collection operation silently intercepts private AI chats of roughly 90,000 browser users.
Cybersecurity News Daily Recap (Jun 13) - Prompt injection reframed as a permanent architectural flaw— OWASP's June 2026 LLM report and follow-on coverage argue LLMs can't separate trusted commands from untrusted data in one token stream — not a patchable bug; production systems at Microsoft/Google/GitHub/OpenAI have all been hit.
Help Net Security· TechTimes - AI-infra supply chain — LiteLLM still in KEV—
hackerbot-clawautonomous bot backdoored LiteLLM via misconfigured GitHub Actions (sat on PyPI ~3h, ~47k downloads); LiteLLM sits under CrewAI, DSPy, GraphRAG.
Help Net Security
Threat Intelligence
- SHADOWBYT3$ claims Nintendo breach (~859 MB)— Extortion-as-a-service group publicly claims theft of ~859 MB of sensitive data from Nintendo; unverified, but watch for follow-on leak/extortion.
Cyber Press - SearchJack — 23 malicious Chrome extensions hijack default search— Large campaign of deceptive extensions silently overriding users' default search engines.
Cybersecurity News Daily Recap (Jun 13) - NarwhalRAT — Python RAT via spear-phishing— Advanced Python-based malware delivered through spear-phishing emails posing as urgent security notifications.
Cyber Press - Screening Serpens (Iran-nexus APT)— Unit 42 details AppDomainManager hijacking and new RAT variants targeting aerospace, defense manufacturing, and telecom.
Unit 42 - Miasma / Shai-Hulud supply-chain worm (ongoing)— Self-propagating npm/PyPI campaign since Jun 1 (57+ npm packages, 300+ malicious versions) steals AWS/GCP/Azure/K8s creds via preinstall hooks; pivots delivery every 48–72h.
SecurityWeek· Unit 42
Chinese-Language Community Picks
- BitUnlocker — a BitLocker downgrade attack— exploits the gap between patch rollout and certificate revocation to physically crack the encrypted volume of an already-patched Windows 11 device in five minutes.
FreeBuf (via CSDN) - npm
codexui-androidsupply-chain poisoning— disguised as a legitimate package, with hidden code that steals identity credentials (including permanent refresh tokens) and exfiltrates them through Sentry traffic.
FreeBuf (via CSDN) - Pwn2Own Berlin 2026 "retaliatory disclosure"— the ZDI-run contest saw record registrations, and dozens of rejected researchers published vulnerability details themselves, sparking controversy over "retaliatory disclosure".
FreeBuf (via CSDN) - Microsoft Office 0-day RCE traded on hacker forums— someone is selling a 0-day remote code execution flaw affecting Microsoft Office and Windows.
FreeBuf (via CSDN)
Ransomware Today
29 new RansomLook posts in the trailing 24h across 5 groups. "the gentlemen" dominated with 21 posts (72%) batch-published within a ~1h window on Jun 15 — likely automated listing/backlog dumping. nova (4), krybit (2), audit team (1), bavacai (1) round out the rest. Zero watchlist hits today (no lockbit/akira/qilin/play/medusa). API payload lacks victim/sector/geo.
→ Full victim table
AI Frontier
OpenAI
- "Built to benefit everyone: our plan" (Altman & Pachocki, Jun 8); confidentially filed for a US IPO (Jun 8); agreed to acquire Ona (Jun 11); ChatGPT shipped a new "Dreaming" memory system (Jun 4).
Anthropic
- US Commerce Secretary Lutnick ordered Anthropic to suspend access to its newest models (Claude Fable 5 / Mythos 5) for all foreign nationals (Jun 12) — a notable export-control / access-restriction event. Anthropic also filed a confidential S-1 with the SEC (Jun 1) and launched Fable 5 (safer general-use) and Mythos 5 (trusted-access).
Google DeepMind / AI
- Gemini 3.5 Flash reached GA; Managed Agents launched in public preview (stateful agents in isolated Google-hosted Linux sandboxes); Antigravity Agent in public preview; File Search gained multimodal search via gemini-embedding-2.
Failed Sources / Notes
- Direct RSS/Atom/HTML feed fetch was blockedthis run by the workspace web-fetch provenance restriction (feed URLs came from
sources.yaml, not a user message). Brief was assembled via WebSearch+ the RansomLook API(URLs present in the task message). Coverage is solid but feed-level recency (exact entry timestamps) is approximate. - Chinese-community sources(FreeBuf, 先知社区, 安全客) and HTML AI-security blogs(HiddenLayer, Lakera, Protect AI) were reachable only via WebSearch summaries (US-only search) — see the ZH brief for the Chinese picks.
Sources used: see intel/sources.yaml