Rosetta Daily · Jun 19, 2026
Generated automatically · ~30 sources scanned · 28 items selected
Window: past ~24h. Direct RSS/HTML feed fetching remains blocked (provenance / sandbox limits); this edition is assembled via WebSearch per category + RansomLook API. Feed-level timestamps are approximate.
Critical Vulnerabilities
-
Joomla Content Editor (JCE) — Improper Access Control → RCE — Widget Factory JCE, CVE-2026-48907, CVSS 10.0 🔴🔥
Maximum-severity improper access control enabling arbitrary code execution; added to CISA KEV. Patch any Joomla site running JCE immediately.
The Hacker News · CISA KEV -
Check Point Remote Access VPN — Authentication Bypass (actively exploited) — Check Point, CVE-2026-50751, CVSS 9.3 🔴🔥⚠️
IKEv1 certificate-validation logic flaw lets an unauthenticated attacker establish a VPN session. Exploited since May 7, increasing in early June; one incident tied (medium confidence) to a Qilin ransomware affiliate. In KEV since 6/8.
Rapid7 · Check Point -
Windows Kernel — TCP/IP Remote Code Execution — Windows 11 / Server, CVE-2026-45657, CVSS 9.8 🔴
Remote, unauthenticated, no-interaction SYSTEM-level RCE via the kernel's TCP/IP handling; characterized as wormable. Fixed in June Patch Tuesday — prioritize.
TechTimes -
Windows HTTP.sys — Remote Code Execution — Windows / Server, CVE-2026-47291, CVSS 9.8 🔴
Unauthenticated, no-interaction RCE in the HTTP.sys kernel driver. Prioritize internet-facing HTTP.sys workloads.
Absolute Security -
Windows DHCP Client — Stack Overflow → RCE — Windows, CVE-2026-44815, CVSS 9.8 🔴
Stack-based buffer overflow in the DHCP Client Service permitting unauthenticated remote code execution. Patch via June updates.
Security Affairs
In-the-Wild Exploitation (CISA KEV)
- CVE-2026-48907— Joomla Content Editor (JCE) improper access control (CVSS 10.0).
- CVE-2026-50751— Check Point VPN authentication bypass; Qilin-linked (added 6/8).
- CVE-2026-41091— Microsoft Defender Elevation of Privilege; "Exploitation Detected / Weaponized / Publicly Aware."
- CVE-2026-20245— Cisco Catalyst SD-WAN Manager improper output encoding/escaping (added 6/9).
- CVE-2026-11645— Google Chromium V8 out-of-bounds read/write (added 6/9).
CISA KEV — 6/9· Catalog
Vendor Advisories
- Microsoft — June 2026 Patch Tuesday (record ~200–211 CVEs)— Largest release on record: ~33–37 critical, 28 critical-RCE, plus 6 zero-days (incl. actively exploited Defender EoP CVE-2026-41091). Publicly disclosed: BitLocker bypass "YellowKey," Defender "RoguePlanet" (CVE-2026-50656, 7.8, patch in progress), "Mini-Plasma." Prioritize HTTP.sys / kernel RCEs.
BleepingComputer· ZDI Review - Apple — June 2026 OS updates— iOS/iPadOS 26.5 fixes 60+ CVEs (20 WebKit, sandboxed-data leaks/crashes); macOS Tahoe 26.5 closes ~80 flaws incl. arbitrary code execution and root escalation.
TechRepublic - Oracle — June 2026 Critical Patch Update— Quarterly CPU fixing Communications, EBS, Enterprise Manager and more.
Help Net Security - Atlassian — Security Bulletin (June 16, 2026)— Monthly bulletin covering multiple products.
Atlassian
Web Security Research
- PortSwigger — Email account takeover via CSS/HTML alone— New techniques tear through trust boundaries using only CSS and HTML, weaving past CSS sanitization, hardened CSP and HTML filtering; includes deanonymizing privacy-email users and end-to-end ATO on multiple major providers (Black Hat USA).
PortSwigger Blog - Top 10 Web Hacking Techniques of 2025 — nominations open— Annual community vote for the most innovative web research of the year.
PortSwigger Research
AI Security
- Prompt injection declared a permanent architectural flaw— LLMs cannot separate trusted instructions from untrusted data in one token stream. OWASP's #1 LLM risk; reportedly +340% YoY and present in 73% of production AI deployments. "Resource amplification" lets one injection trigger thousands of agent actions.
TechTimes· ECCU - First AI-driven network attack (Sysdig)— An LLM agent generated attack commands in real time, exploiting an exposed marimo notebook server (CVE-2026-39987) to complete intrusion and exfiltrate database data in ~22 minutes.
FreeBuf (via CSDN) - Mastra npm supply-chain compromise— 140+ Mastra npm packages compromised on June 18, 2026; latest in a run of AI-tooling supply-chain attacks (cf. backdoored LiteLLM pushed to PyPI via misconfigured GitHub Actions).
The Hacker News
Threat Intelligence
- Qilin = most active ransomware operator— Dec 2025–Feb 2026 assessment ranks Qilin top, alongside LockBit5, Everest and Safepay; ransomware incidents +48% YoY (May 2026), averaging ~2,055 weekly attacks per org.
Bitsight· Check Point Research — 15 June - Check Point VPN zero-day → Qilin— Active exploitation of CVE-2026-50751 tied (medium confidence) to a Qilin affiliate; CISA gave federal agencies 3 days to patch.
BleepingComputer - Global APT campaigns escalate (Intel 471)— Coordinated APT activity increasingly targets critical sectors; Singapore highlighted as a prime regional target (Cyfirma).
Industrial Cyber - ShinyHunters claims NAIC + Amazon's One Medical— Per RansomLook, ShinyHunters listed NAIC.org (US insurance regulator) and Amazon-owned OneMedical.com (healthcare) in the latest window.
Chinese-Language Community Picks
- The first AI-driven cyberattack (Sysdig)— an LLM agent generated commands in real time and, exploiting a marimo notebook (CVE-2026-39987), completed the intrusion and data theft in 22 minutes.
FreeBuf (via CSDN) - Apache Flink high-severity SQL injection (CVE-2026-35194)— injection in the code-generation engine can lead to RCE, threatening distributed data-processing environments.
FreeBuf (via CSDN) - Claude Mythos / Project Glasswing commercialisation— reportedly, since the accidental leak in March it has surfaced 10,000+ high-severity vulnerabilities for 40+ organisations.
FreeBuf (via CSDN) - npm supply-chain poisoning spreads— codexui-android (Aikido, May) stole permanent refresh tokens and exfiltrated them disguised as Sentry traffic; 140+ Mastra packages were poisoned on 6/18.
FreeBuf (via CSDN)
Ransomware Today
RansomLook window (06-17 20:46 → 06-18 14:45 UTC) shows 67 new posts across 11 groups; most active lockbit5 (34) · the gentlemen (12) · safepay (5). ⭐ Watchlist highlights: inc ransom → Horizon Family Medical Group (healthcare), shinyhunters → One Medical / NAIC.org, akira → Apptricity (logistics), lockbit5 → delano.k12.mn.us / eternal.hk / comta.com.tw. Notable: lockbit5 dumped 34 victims at once (heavy APAC/LatAm spread) — watch for re-listed/recycled data.
→ Full victim table
Bug Bounty Today
No date-verifiable recent (≤30d) single disclosures retrievable today — Bugcrowd CrowdStream and HackerOne Hacktivity are client-rendered (WebFetch returns shells; search surfaces only old classic reports). Per playbook rule, nothing is padded with old cases. Trend signal worth noting: OpenAI's Bugcrowd-run Safety Bug Bounty ($1M annual pool) covering prompt injection / jailbreaks / OWASP LLM Top 10 is the most active AI-bounty channel.
→ Full notes
AI Frontier
OpenAI
- Safety Bug Bounty ($1M/yr via Bugcrowd) continues — prompt injection / jailbreaks / training-data leakage / OWASP LLM Top 10, $500–$15K per finding. Open-weight gpt-oss (120b/20b) remains in the lineup.
Wraith
Anthropic
- Claude Fable 5 (6/10) shipped to broader product lines; Claude Mythos limited to Glasswing partners. Project Glasswing reportedly surfaced 10,000+ high-risk vulns for 40+ orgs. Locked SpaceX/xAI Colossus 1 compute (300+ MW, 220K+ GPUs).
Superhuman
Google DeepMind / AI
- Gemini 3.5 Pro slated for June; Gemini 3.5 Flash now GA and default in the app + Search AI Mode. AlphaEvolve expanded into genomics/quantum/math; Genie 3 world model generates minutes of interactive 720p/24fps 3D scenes.
llm-stats· WaveSpeed
🛡 = security-relevant
Failed / Notes
- Direct fetching of RSS/Atom/HTML feeds in
sources.yamlremains blocked (workspace web-fetch provenance + sandbox network). This edition uses WebSearch per category + the RansomLook API (its URL is in the task message → fetchable). - Bug-bounty sources (CrowdStream / Hacktivity) are client-rendered → WebFetch shells only; no date-verifiable recent disclosures today.
- Chinese-community sources (FreeBuf / Xianzhi / Anquanke) and HTML AI-security blogs available via WebSearch summaries only (US-region search).
Sources used: see intel/sources.yaml