Rosetta Daily · Jun 20, 2026
Generated automatically · ~20 sources scanned · 24 items selected
Collection note: assembled primarily via web search aggregation (sandbox/WebFetch provenance limits on several RSS/HTML feeds). Single-source failures listed at the bottom.
Critical Vulnerabilities
-
🔴⚠️ F5 patches critical NGINX flaws — F5 NGINX Open Source, CVE-2026-42530, CVSS v4 9.2
Use-after-free inngx_http_v3_module, triggerable by a remote unauthenticated attacker when the HTTP/3 QUIC module is enabled → code execution. Second critical flaw also fixed. Patch NGINX OSS immediately if HTTP/3 is in use.
source -
🔴🔥⚠️ Splunk Enterprise flaw actively exploited — Splunk Enterprise, CVE-2026-20253
CISA confirmed active abuse and ordered FCEB agencies to patch by Sunday. RCE-class issue in widely deployed log platform.
source -
🔥⚠️ Fortinet FortiSandbox under active exploitation — Fortinet FortiSandbox
Threat actors observed exploiting three CVEs over the past 24 hours. Network security appliance — prioritize patching/isolation.
source -
⚠️ Microsoft June 2026 Patch Tuesday — 198 vulnerabilities, 3 zero-days, 32 Critical
Three flaws were publicly disclosed before patching. 166 Important-rated. Roll out promptly.
source · ZDI review -
Apple patches Beats Studio Buds — high-severity flaw letting nearby attackers eavesdrop on users; firmware update pushed.
source
In-the-Wild Exploitation (CISA KEV)
-
🔥 CISA adds 3 KEV (2026-06-09): CVE-2026-7473 (Arista EOS — incomplete comparison), CVE-2026-11645 (Chromium V8 OOB read/write), CVE-2026-20245 (Cisco Catalyst SD-WAN Manager — improper output encoding). Evidence of active exploitation.
CISA alert -
🔥⚠️ Splunk CVE-2026-20253 — added to KEV with active exploitation; federal patch deadline issued.
source -
🔥 Interlock ransomware exploiting CVE-2026-20131 — critical flaw in Cisco Secure Firewall Management Center (FMC), disclosed 2026-03-04; AWS threat intel tracked an active campaign.
source
Vendor Advisories
- Microsoft— June 2026 Patch Tuesday, 198 fixes (3 zero-days). link
- F5— critical NGINX OSS security updates (CVE-2026-42530, CVSS 9.2). link
- Apple— Beats Studio Buds eavesdropping fix. link
Web Security Research
- PortSwigger — side-channels as a core exploitation primitive(2025 retrospective): the year's standout theme, alongside novel HTTP request smuggling/desync via malformed chunks. research
- New SAML exploitation → full authentication bypassand browser-redirect-stalling chains feature in recent PortSwigger work. research
- Compromising email accounts via CSS/HTML trust-boundary abuse— techniques weaving past CSS sanitization, hardened CSP, and HTML filtering. research
AI Security
- Prompt injection +340% YoY— now the fastest-growing attack category globally (OWASP 2026 LLM Security Report). source
- IEEE S&P 2026: prompt injection in third-party AI chatbot plugins— study of 17 plugins across 10,000+ websites; plugin security posture against injection remains poorly understood. paper
- OWASP Top 10 for Agents & AI (2026)published — agentic risks (incl. MCP) now first-class. cheat sheet
- Claude-assisted CVE discovery— FreeBSD CVE-2026-4747 (RPCSEC_GSS RCE) credited "Nicholas Carlini using Claude"; Linux kernel CVE-2026-31402 linked to Claude-assisted work. source
Threat Intelligence
- Mandiant M-Trends 2026— grounded in 500,000+ hours of frontline IR from 2025; notes divergence in adversary pacing. report
- Unit 42 2026 Global IR Report— attacks 4× faster; data exfiltration in <1 hour in some cases; identity-based techniques drive 65% of initial access. report
- Unit 42 — Screening Serpens (Iran APT)— AppDomainManager hijacking + new RAT variants targeting tech and defense. report
Chinese-Language Community Picks
- This run did not fetch FreeBuf / Anquanke / Xianzhi Community RSS/HTML directly (sandbox / provenance restrictions), so there are no separately selected Chinese-community items today (see failed sources at the end).
Ransomware Today
13 new posts in the last 24h (RansomLook), across 9 groups. Most active: qilin (3), aurora (2), nightspire (2). Watchlist: 3 ⭐ hits, all qilin (Homes By J Anthony, ATCOM Outsourcing, THL Project Management). Sensitive-sector victims this round: a dental clinic, an electric utility, and a mortgage lender (1 each — notable but not a cluster).
Full victim table
Bug Bounty Today
No verifiable recent (within-30-day) individual disclosures retrieved today. Bugcrowd CrowdStream and HackerOne Hacktivity are both client-rendered; WebFetch returned only page shells and search surfaced only older reports. Per the no-stale-fill rule, the recent-disclosure table is empty today. Project-level signal worth tracking: OpenAI's Safety Bug Bounty (Bugcrowd, ~$1M pool, AI/prompt-injection scope) and HackerOne's +210% YoY growth in AI vuln reports.
Full notes
AI Frontier
OpenAI
- Safety Bug Bounty (Mar 2026, Bugcrowd, ~$1M/yr) — scope incl. prompt injection, jailbreaks, agentic/MCP risks, OWASP LLM Top 10.
- Open-source gpt-oss-120b (single-GPU) and 20b (consumer laptop).
Anthropic
- Claude Mythos 1 / Project Glasswing preview (from Apr 2026).
- Claude-assisted real CVEs: FreeBSD CVE-2026-4747, Linux kernel CVE-2026-31402.
Google DeepMind / AI
- Gemini 3.5 Flash GA at I/O 2026 (May 19); 3.5 Pro alongside.
- AlphaEvolve expands into genomics, quantum, mathematics.
Full roundup: ai-frontier/daily/2026-06-20.html
Failed / Not-Retrieved Sources
- Bugcrowd CrowdStream, HackerOne Hacktivity — client-rendered; no verifiable recent per-item disclosures via WebFetch/WebSearch.
- FreeBuf / 安全客 / 先知社区 (Chinese RSS/HTML) — not directly retrieved this run (provenance/sandbox limits); no Chinese-community items selected today.
- PortSwigger / Project Zero / Mandiant native RSS — not fetched directly; covered via search aggregation, dates as noted.
Sources used: see intel/sources.yaml