Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-06-21
Daily Brief·2026-06-21·23 Items

Rosetta Daily · Jun 21, 2026

Generated automatically · ~20 sources scanned · 23 items selected
Collection note: assembled primarily via web search aggregation (sandbox/WebFetch provenance limits on several RSS/HTML feeds). RansomLook API and Bugcrowd CrowdStream fetched directly. Single-source failures listed at the bottom.

Critical Vulnerabilities

  • 🔴🔥⚠️ "FortiBleed" mass exploitation of FortiGate — Fortinet FortiOS/FortiGate, CVE-2026-3055, CVSS 9.8 (out-of-bounds read)
    CISA urged FortiGate owners to act against an ongoing campaign attributed to Russian-speaking actors; 86,644 devices compromised as of 2026-06-19 (SOCRadar). Generic admin (35%) and built-in Fortinet system accounts (28.3%) made up most stolen credentials. Patch + rotate credentials + hunt now.
    source · Fortinet advisory

  • 🔴🔥⚠️ Check Point VPN zero-day exploited in the wild — Check Point Remote Access VPN / Mobile Access / Spark, CVE-2026-50751, CVSS 9.3 (auth bypass)
    Exploited as a zero-day, abused by ransomware gangs; CISA added it to KEV and gave FCEB agencies a 3-day patch deadline. Disclosed 2026-06-08.
    source · CISA

  • 🔴🔥 Windows Netlogon actively exploited — Microsoft Windows, CVE-2026-41089
    Belgium's CCB issued an urgent warning that attacks are already underway. Domain-controller-adjacent risk — prioritize the June patch.
    source

  • 🔴 Windows DHCP Client RCE — Microsoft Windows, CVE-2026-44815, CVSS 9.8
    Critical unauthenticated RCE in the DHCP Client Service, fixed in June Patch Tuesday. Network-adjacent attackers can trigger.
    source

  • 🔴⚠️ Everest Forms Pro unauth RCE actively exploited — WordPress plugin, CVE-2026-3300
    Attackers abuse PHP eval() injection via the Complex Calculation feature for unauthenticated RCE. Commercial form-builder plugin — patch or disable immediately.
    source

In-the-Wild Exploitation (CISA KEV)

  • 🔥 CISA adds Joomla Content Editor flaw (2026-06-16) — CVE-2026-48907 (Widget Factory JCE, improper access control), evidence of active exploitation.
    CISA alert

  • 🔥 Oracle PeopleSoft actively exploited — CVE-2026-35273, abused by the ShinyHunters group; patched in Oracle's June CPU.
    source

  • 🔥 FortiBleed (CVE-2026-3055) and Check Point CVE-2026-50751 — both under confirmed active exploitation this cycle (see above).
    source

Vendor Advisories

  • Oracle— June 2026 Critical Patch Update: 243 CVEs / 245 patches, 122 critical; 12 JD Edwards flaws remotely exploitable without auth. link
  • Veeam— critical Backup & Replication RCE on domain-joined backup servers; patch this cycle. link
  • Microsoft— June Patch Tuesday, record ~200+ CVEs, 3 publicly-disclosed zero-days, 33 critical (largest ever). link
  • Google Chrome— 74 CVEs incl. zero-day CVE-2026-11645(V8 OOB read/write, on KEV). link

Web Security Research

  • PortSwigger / James Kettle — "HTTP/1.1 Must Die": new desync research expanding browser-powered desync and HTTP/2 downgrade attacks; real-world impact noted on major platforms. research
  • HTTP Request Smuggling explained(Kettle × NahamSec): smuggling can steal plaintext passwords and poison caches to persistently compromise login pages. blog

AI Security

  • GitHub Copilot prompt-injection → RCE— CVE-2025-53773, CVSS 9.6: hidden prompt injection embedded in PR descriptions achieves remote code execution via the AI coding assistant. source
  • Prompt injection +340% YoY(OWASP 2026 LLM Security Report) — fastest-growing attack category; HackerOne disclosed reports show prompt injection +540%and AI issues +200%. source
  • MCP / agentic attack surface— Model Context Protocol expands tool-poisoning and credential-theft risks across agent systems. source
  • Claude-assisted real CVEs— FreeBSD CVE-2026-4747 (RPCSEC_GSS RCE) and Linux kernel CVE-2026-31402, both linked to Claude-assisted research. source

Threat Intelligence

  • Klue OAuth breach → "Icarus" extortion— attackers stole Salesforce CRM data from multiple orgs in an ongoing extortion campaign; Klue.com also named on the icarusleak site (see Ransomware section). source
  • SocGholish + Evil Corp takedown— international law enforcement cleaned ~15,000 malware-infected WordPress sites and seized 100+ servers tied to the SocGholish botnet and Evil Corp. source
  • Check Point — Iran-linked LA Metro wiper— destructive intrusion (wiped servers) attributed to "Ababil of Minab" persona; analysts link further transit/tech attacks to Black Shadow infrastructure. report
  • Stock-exchange exec mailbox espionage— months-long campaign siphoned a senior executive's Outlook mailbox at a major exchange via legitimate cloud storage + disguised update tasks; ~5 months undetected. report
  • Chinese APT "REDCap"— breached medical research institutions, exfiltrating clinical-trial and patient data. source

Chinese-Language Community Picks

  • This run did not fetch FreeBuf / Anquanke / Xianzhi Community RSS/HTML directly (sandbox / provenance restrictions), so there are no separately selected Chinese-community items today (see failed sources at the end).

Ransomware Today

RansomLook days=1 returned the same window as the 2026-06-20 brief (discovered 06-18 → 06-19; server still UTC 06-20), so net-new posts vs. yesterday = 0. Snapshot: 13 posts across 9 groups; most active qilin (3, all ⭐ watchlist hits), aurora (2), nightspire (2). Cross-link: icarus named Klue.com — same event as the Klue OAuth/Icarus extortion above (SaaS supply-chain double-extortion). Tomorrow: widen to days=2 or fetch after UTC rollover to avoid repeats.
Full victim table

Bug Bounty Today

No verifiable recent (within-30-day) individual disclosures retrieved today. Bugcrowd CrowdStream and HackerOne Hacktivity are both client-rendered; WebFetch returned only page shells and search/mirrors surfaced only older/curated reports. Per the no-stale-fill rule, the recent-disclosure table is empty. Project-level signals: HackerOne trimmed bounty rewards (The Register, 2026-05-21); AI vuln reports up +540% (prompt injection); OpenAI Safety Bug Bounty (~$1M, Bugcrowd) remains open.
Full notes


AI Frontier

OpenAI

  • Open-source gpt-oss-120b (single-GPU, ~o3/o4-mini class) and 20b (consumer laptop).
  • Safety Bug Bounty (since Mar 2026, Bugcrowd, ~$1M/yr) — prompt injection, jailbreaks, agentic/MCP, OWASP LLM Top 10.

Anthropic

  • Claude Fable 5 launched 2026-06-09 (1M-token reasoning model).
  • Claude-assisted real CVEs: FreeBSD CVE-2026-4747, Linux kernel CVE-2026-31402.

Google DeepMind / AI

  • Gemini 3.5 Flash GA (May 19 I/O 2026); 3.5 Pro in June.
  • AlphaEvolve expands into genomics, quantum, mathematics (e.g. -30% DNA-sequencing error detection).

Full roundup: ai-frontier/daily/2026-06-21.html


Failed / Not-Retrieved Sources

  • Bugcrowd CrowdStream, HackerOne Hacktivity — client-rendered; no verifiable recent per-item disclosures via WebFetch/WebSearch.
  • FreeBuf / 安全客 / 先知社区 (Chinese RSS/HTML) — not directly retrieved this run (provenance/sandbox limits); no Chinese-community items selected today.
  • PortSwigger / Project Zero / Mandiant native RSS — not fetched directly; covered via search aggregation, dates as noted.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jun 20, 2026
Next →
Rosetta Daily · Jun 22, 2026