Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-06-16
Daily Brief·2026-06-16·30 Sources·31 Items

Rosetta Daily · Jun 16, 2026

Generated automatically · 30 sources scanned · 31 items selected
Window: trailing ~24h, items dated 2026-06-14 → 2026-06-15. Yesterday's brief covered the June Patch Tuesday cycle; today leads with fresh disclosures.

Critical Vulnerabilities

  • Wazuh Manager 5.0 — agent-to-SIEM bulk-injection (silent evidence destruction) — Wazuh 5.0, GHSA-ff9g-85jq-r3g3, CVSS 10.0 🔴⚠️
    Any enrolled agent can smuggle arbitrary OpenSearch _bulk operations through an unsanitized DataValue.index flatbuffer field in the new inventory_sync subsystem (does not exist in 4.x). No auth, no user interaction, network-exploitable — lets an attacker delete alerts, destroy forensic evidence, and tamper SIEM data across the whole deployment. Affects 5.0.0-beta1 → beta2; fixed in 5.0.0-beta3.
    Cybersecurity News · Cyber Press

  • PAN-OS GlobalProtect authentication bypass — actively exploited — Palo Alto Networks PAN-OS, CVE-2026-0257, CVSS 7.8 (revised up from 4.7) 🔴🔥⚠️
    Remote unauthenticated attackers forge authentication-override cookies to establish VPN sessions without credentials. Unit 42 published a threat brief confirming in-the-wild exploitation; in CISA KEV with a June 19 federal patch deadline.
    Unit 42 threat brief · Rapid7

  • Everest Forms Pro — unauthenticated RCE (still exploited) — WordPress plugin, CVE-2026-3300 🔴⚠️
    Unauthenticated remote code execution via PHP eval() injection; opportunistic exploitation continues against WordPress sites — patch/disable the plugin.
    The Hacker News

In-the-Wild Exploitation (CISA KEV)

  • CVE-2026-0257— Palo Alto GlobalProtect auth bypass; remediate by June 19(see above).
  • CVE-2026-7473— Arista EOS incomplete comparison / missing factors (added Jun 9).
  • CVE-2026-11645— Google Chromium V8 out-of-bounds read & write (added Jun 9).
  • CVE-2026-20245— Cisco Catalyst SD-WAN Manager improper output encoding (added Jun 9).
    CISA KEV — Jun 9 additions

Vendor Advisories

  • Palo Alto Networks — CVE-2026-0257 advisory— Score revised to 7.8 after confirmed exploitation; fixed PAN-OS releases available; review GlobalProtect auth-override config.
    security.paloaltonetworks.com
  • Microsoft June Patch Tuesday aftermath— Record cycle (~200–206 CVEs, 33–39 critical, 3 publicly-disclosed zero-days incl. CTFMON EoP, HTTP.sys DoS, BitLocker bypass). Prioritize internet-facing Exchange/HTTP.sys.
    BleepingComputer· Talos

Web Security Research

  • "CSS: the bomb inside your inbox" (PortSwigger)— Upcoming-talk research on novel CSS/HTML techniques that slip past CSS sanitization and hardened CSP to achieve end-to-end email account takeover on multiple major providers.
    PortSwigger Research
  • Top 10 Web Hacking Techniques of 2025 — nominations / write-ups— Community shortlist including a complete SAML authentication-bypass class; useful pen-test reference.
    PortSwigger Top 10

AI Security

  • PromptSnatcher — covert interception of AI conversations (~90k users)— Newly uncovered data-collection operation silently intercepts private AI chats of roughly 90,000 browser users.
    Cybersecurity News Daily Recap (Jun 13)
  • Prompt injection reframed as a permanent architectural flaw— OWASP's June 2026 LLM report and follow-on coverage argue LLMs can't separate trusted commands from untrusted data in one token stream — not a patchable bug; production systems at Microsoft/Google/GitHub/OpenAI have all been hit.
    Help Net Security· TechTimes
  • AI-infra supply chain — LiteLLM still in KEV— hackerbot-clawautonomous bot backdoored LiteLLM via misconfigured GitHub Actions (sat on PyPI ~3h, ~47k downloads); LiteLLM sits under CrewAI, DSPy, GraphRAG.
    Help Net Security

Threat Intelligence

  • SHADOWBYT3$ claims Nintendo breach (~859 MB)— Extortion-as-a-service group publicly claims theft of ~859 MB of sensitive data from Nintendo; unverified, but watch for follow-on leak/extortion.
    Cyber Press
  • SearchJack — 23 malicious Chrome extensions hijack default search— Large campaign of deceptive extensions silently overriding users' default search engines.
    Cybersecurity News Daily Recap (Jun 13)
  • NarwhalRAT — Python RAT via spear-phishing— Advanced Python-based malware delivered through spear-phishing emails posing as urgent security notifications.
    Cyber Press
  • Screening Serpens (Iran-nexus APT)— Unit 42 details AppDomainManager hijacking and new RAT variants targeting aerospace, defense manufacturing, and telecom.
    Unit 42
  • Miasma / Shai-Hulud supply-chain worm (ongoing)— Self-propagating npm/PyPI campaign since Jun 1 (57+ npm packages, 300+ malicious versions) steals AWS/GCP/Azure/K8s creds via preinstall hooks; pivots delivery every 48–72h.
    SecurityWeek· Unit 42

Chinese-Language Community Picks

  • BitUnlocker — a BitLocker downgrade attack— exploits the gap between patch rollout and certificate revocation to physically crack the encrypted volume of an already-patched Windows 11 device in five minutes.
    FreeBuf (via CSDN)
  • npm codexui-androidsupply-chain poisoning— disguised as a legitimate package, with hidden code that steals identity credentials (including permanent refresh tokens) and exfiltrates them through Sentry traffic.
    FreeBuf (via CSDN)
  • Pwn2Own Berlin 2026 "retaliatory disclosure"— the ZDI-run contest saw record registrations, and dozens of rejected researchers published vulnerability details themselves, sparking controversy over "retaliatory disclosure".
    FreeBuf (via CSDN)
  • Microsoft Office 0-day RCE traded on hacker forums— someone is selling a 0-day remote code execution flaw affecting Microsoft Office and Windows.
    FreeBuf (via CSDN)

Ransomware Today

29 new RansomLook posts in the trailing 24h across 5 groups. "the gentlemen" dominated with 21 posts (72%) batch-published within a ~1h window on Jun 15 — likely automated listing/backlog dumping. nova (4), krybit (2), audit team (1), bavacai (1) round out the rest. Zero watchlist hits today (no lockbit/akira/qilin/play/medusa). API payload lacks victim/sector/geo.
→ Full victim table


AI Frontier

OpenAI

  • "Built to benefit everyone: our plan" (Altman & Pachocki, Jun 8); confidentially filed for a US IPO (Jun 8); agreed to acquire Ona (Jun 11); ChatGPT shipped a new "Dreaming" memory system (Jun 4).

Anthropic

  • US Commerce Secretary Lutnick ordered Anthropic to suspend access to its newest models (Claude Fable 5 / Mythos 5) for all foreign nationals (Jun 12) — a notable export-control / access-restriction event. Anthropic also filed a confidential S-1 with the SEC (Jun 1) and launched Fable 5 (safer general-use) and Mythos 5 (trusted-access).

Google DeepMind / AI

  • Gemini 3.5 Flash reached GA; Managed Agents launched in public preview (stateful agents in isolated Google-hosted Linux sandboxes); Antigravity Agent in public preview; File Search gained multimodal search via gemini-embedding-2.

Failed Sources / Notes

  • Direct RSS/Atom/HTML feed fetch was blockedthis run by the workspace web-fetch provenance restriction (feed URLs came from sources.yaml, not a user message). Brief was assembled via WebSearch+ the RansomLook API(URLs present in the task message). Coverage is solid but feed-level recency (exact entry timestamps) is approximate.
  • Chinese-community sources(FreeBuf, 先知社区, 安全客) and HTML AI-security blogs(HiddenLayer, Lakera, Protect AI) were reachable only via WebSearch summaries (US-only search) — see the ZH brief for the Chinese picks.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jun 15, 2026
Next →
Rosetta Daily · Jun 17, 2026