Rosetta Daily · Jun 17, 2026
Generated automatically · 30 sources scanned · 28 items selected
Window: ~past 24h. Direct RSS/HTML feeds remain blocked (provenance/sandbox limits); assembled via WebSearch per category + RansomLook API. Feed-level timestamps are approximate.
Critical Vulnerabilities
-
Cisco Catalyst SD-WAN Controller — auth bypass, exploited as zero-day — Cisco Catalyst SD-WAN Controller/Manager, CVE-2026-20182, CVSS 10.0 🔴🔥⚠️
Flawed peering authentication in thevdaemonservice over DTLS (UDP 12346) lets a remote unauthenticated attacker become an authenticated peer and inject an attacker-controlled SSH key into thevmanage-adminaccount. Affects on-prem and cloud; Talos/Tenable report continued exploitation. Patch immediately.
BleepingComputer · Rapid7 · Tenable -
Check Point Security Gateway — improper auth, actively exploited — Remote Access VPN / Mobile Access (IKEv1), CVE-2026-50751 🔴🔥⚠️
Active exploitation against gateways still configured for the deprecated IKEv1 key exchange. Added to CISA KEV on June 8. Disable IKEv1 / migrate to IKEv2 and patch.
CISA KEV (June 8) -
Apache Flink — SQL injection → RCE in code-generation engine — Apache Flink, CVE-2026-35194 🔴
High-severity SQLi in Flink's code-generation engine exposes distributed data-processing clusters to remote code execution. Patch / restrict exposure of job-submission interfaces.
FreeBuf (via CSDN) -
Microsoft Win32K GRFX — Remote Code Execution — Windows, CVE-2026-44812 / CVE-2026-44803 🔴
Critical graphics-subsystem RCE reachable through browsers and content-rendering apps; part of the June Patch Tuesday set. Prioritise endpoint deployment.
Zecurit Patch Tuesday analysis -
cPanel — privilege escalation / RCE / DoS — cPanel, CVE-2026-29201 / -29202 / -29203 🔴
Three high-severity flaws (privesc, code execution, denial of service) in widely deployed hosting control panel; urgent patching recommended.
FreeBuf (via CSDN)
In-the-Wild Exploitation (CISA KEV)
- CVE-2026-50751— Check Point Security Gateway improper authentication (added June 8).
- CVE-2026-42271— BerriAI LiteLLM command injection (added June 8); underlies many agent frameworks.
- CVE-2026-7473— Arista EOS incomplete comparison / missing factors (added June 9).
- CVE-2026-11645— Google Chromium V8 out-of-bounds read/write (added June 9).
- CVE-2026-20245— Cisco Catalyst SD-WAN Manager improper output encoding (added June 9).
CISA KEV — June 8· June 9
Vendor Advisories
- Cisco — SD-WAN auth bypass advisory— Confirms exploitation of CVE-2026-20182; fixed releases available; review for injected SSH keys on
vmanage-admin.
Cisco Security Advisory - Microsoft — June 2026 Patch Tuesday— 198 CVEs (one of the largest single months): 32 Critical, 166 Important, 3 publicly disclosed zero-days. Fixes critical HTTP.sys RCE, Secure Boot/BitLocker firmware checks, plus dozens of Office/Exchange flaws. Prioritise internet-facing HTTP.sys/Exchange.
CyberPress· Help Net Security forecast
Web Security Research
- "CSS: the bomb inside your inbox" (PortSwigger)— Techniques weaving past CSS sanitization, hardened CSP and HTML-filtering libraries to deanonymize users of privacy-first encrypted mail and achieve end-to-end account takeover on multiple major (and enterprise) email providers.
PortSwigger Research - Can autonomous AI invent new attack techniques? (PortSwigger)— After a decade focused on bug detection, PortSwigger is probing whether agentic systems can synthesize genuinely novel web-exploitation primitives.
PortSwigger Research - Top 10 Web Hacking Techniques of 2025— Annual community list; 2025 marked the rise of side-channels as a core web-exploitation primitive.
PortSwigger Top 10
AI Security
- Prompt injection reframed as a permanent architectural flaw— The June 2026 OWASP LLM report has stopped cataloging hypotheticals and started cataloging CVEs; LLMs cannot separate trusted instructions from untrusted data in one token stream. Reported up ~340% YoY.
Help Net Security· TechTimes - Sysdig: first documented AI-driven intrusion— An attacker drove an LLM agent to generate commands in real time, exploited a marimo notebook-server flaw (CVE-2026-39987) and exfiltrated internal DB data — start-to-finish in ~22 minutes.
FreeBuf (via CSDN) - LiteLLM command-injection still in KEV— CVE-2026-42271 (added June 8) sits under CrewAI, DSPy, GraphRAG and other agent frameworks; the earlier
hackerbot-clawbackdoor (≈47k PyPI downloads) showed the blast radius.
Help Net Security
Threat Intelligence
- GitHub breached by "TeamPCP" (claimed)— Group claims theft of ~4,000 private repositories via stolen CI/CD credentials, offered for sale at ~$50,000. Audit CI/CD secrets and rotate tokens.
FreeBuf (via CSDN) - Screening Serpens (Iran-nexus APT)— Unit 42 details AppDomainManager hijacking and new RAT variants targeting tech and defense sectors in 2026 espionage campaigns.
Unit 42 - SHADOWBYT3$ — Nintendo breach claim resurfaces— Now posted on RansomLook ("nintendo.com"); unconfirmed, watch for follow-on leak/extortion.
RansomLook - ShinyHunters → Ralph Lauren— The year's most active extortion crew adds a fashion-retail victim to its leak site.
RansomLook
Chinese-Language Community Picks
- Apache Flink high-severity SQL injection (CVE-2026-35194)— injection in the code-generation engine can lead to RCE, threatening distributed data-processing environments.
FreeBuf (via CSDN) - cPanel triple patch (CVE-2026-29201/2/3)— privilege escalation, code execution and DoS; patch immediately.
FreeBuf (via CSDN) - Sysdig discloses the first AI-driven attack— an LLM agent generated attack commands in real time, completing the intrusion in 22 minutes (marimo CVE-2026-39987).
FreeBuf (via CSDN) - GitHub breached by TeamPCP— 4,000 private repositories stolen and listed for USD 50,000, carried out via CI/CD credential theft.
FreeBuf (via CSDN)
Ransomware Today
23 new RansomLook posts in the last 24h across 14 groups; most active: nightspire / cloak / aurora (3 each). ⭐ 4 watchlist hits — qilin (Golfview Developmental Center, healthcare), akira (Insite Architects), inc ransom (framesiprofessional.com, jasperplastics.info). High-profile victims claimed: Novo Nordisk (pharma, by fulcrumsec), Nintendo (shadowbyt3$), Ralph Lauren (shinyhunters), Sumitomo Electric Bordnetze (automotive mfg, aurora).
→ Full victim table
AI Frontier
OpenAI
- Continued product/IPO momentum; reporting notes ChatGPT advanced voice mode still runs on an older GPT-4o-era model. No major new model drop in the past 24h.
Anthropic
- Claude Fable 5 / Mythos 5(new Mythos-class tier, launched June 9) carry safety classifiers that auto-fall-back to Claude Opus 4.8 for flagged cyber/biorequests; refusals return
stop_reason: "refusal". On June 12 a US export-control directive forced Anthropic to suspend access to both models. New enterprise partnerships with TCS and DXC.
InfoQ· Anthropic Newsroom
Google DeepMind / AI
- Gemini 3.5 Proreleased this month; Gemini Robotics-ER 1.6integrated into Boston Dynamics' Spot and Orbit inspection platform for industrial spatial reasoning.
llm-stats
🛡 = security-relevant
Failed Sources (notes)
- Direct RSS/Atom/HTML fetching of
sources.yamlfeeds remains blocked (workspace web-fetch provenance + sandbox network). Assembled via WebSearchper category + RansomLook API(its URL is in the task message → fetchable). - Chinese-community sources (FreeBuf, 先知, 安全客) and HTML AI-security blogs (HiddenLayer, Lakera, Protect AI) available only via WebSearch summaries (US-region search).
Sources used: see intel/sources.yaml