Rosetta Daily · Jun 21, 2026
Generated automatically · ~20 sources scanned · 23 items selected
Collection note: assembled primarily via web search aggregation (sandbox/WebFetch provenance limits on several RSS/HTML feeds). RansomLook API and Bugcrowd CrowdStream fetched directly. Single-source failures listed at the bottom.
Critical Vulnerabilities
-
🔴🔥⚠️ "FortiBleed" mass exploitation of FortiGate — Fortinet FortiOS/FortiGate, CVE-2026-3055, CVSS 9.8 (out-of-bounds read)
CISA urged FortiGate owners to act against an ongoing campaign attributed to Russian-speaking actors; 86,644 devices compromised as of 2026-06-19 (SOCRadar). Generic admin (35%) and built-in Fortinet system accounts (28.3%) made up most stolen credentials. Patch + rotate credentials + hunt now.
source · Fortinet advisory -
🔴🔥⚠️ Check Point VPN zero-day exploited in the wild — Check Point Remote Access VPN / Mobile Access / Spark, CVE-2026-50751, CVSS 9.3 (auth bypass)
Exploited as a zero-day, abused by ransomware gangs; CISA added it to KEV and gave FCEB agencies a 3-day patch deadline. Disclosed 2026-06-08.
source · CISA -
🔴🔥 Windows Netlogon actively exploited — Microsoft Windows, CVE-2026-41089
Belgium's CCB issued an urgent warning that attacks are already underway. Domain-controller-adjacent risk — prioritize the June patch.
source -
🔴 Windows DHCP Client RCE — Microsoft Windows, CVE-2026-44815, CVSS 9.8
Critical unauthenticated RCE in the DHCP Client Service, fixed in June Patch Tuesday. Network-adjacent attackers can trigger.
source -
🔴⚠️ Everest Forms Pro unauth RCE actively exploited — WordPress plugin, CVE-2026-3300
Attackers abuse PHPeval()injection via the Complex Calculation feature for unauthenticated RCE. Commercial form-builder plugin — patch or disable immediately.
source
In-the-Wild Exploitation (CISA KEV)
-
🔥 CISA adds Joomla Content Editor flaw (2026-06-16) — CVE-2026-48907 (Widget Factory JCE, improper access control), evidence of active exploitation.
CISA alert -
🔥 Oracle PeopleSoft actively exploited — CVE-2026-35273, abused by the ShinyHunters group; patched in Oracle's June CPU.
source -
🔥 FortiBleed (CVE-2026-3055) and Check Point CVE-2026-50751 — both under confirmed active exploitation this cycle (see above).
source
Vendor Advisories
- Oracle— June 2026 Critical Patch Update: 243 CVEs / 245 patches, 122 critical; 12 JD Edwards flaws remotely exploitable without auth. link
- Veeam— critical Backup & Replication RCE on domain-joined backup servers; patch this cycle. link
- Microsoft— June Patch Tuesday, record ~200+ CVEs, 3 publicly-disclosed zero-days, 33 critical (largest ever). link
- Google Chrome— 74 CVEs incl. zero-day CVE-2026-11645(V8 OOB read/write, on KEV). link
Web Security Research
- PortSwigger / James Kettle — "HTTP/1.1 Must Die": new desync research expanding browser-powered desync and HTTP/2 downgrade attacks; real-world impact noted on major platforms. research
- HTTP Request Smuggling explained(Kettle × NahamSec): smuggling can steal plaintext passwords and poison caches to persistently compromise login pages. blog
AI Security
- GitHub Copilot prompt-injection → RCE— CVE-2025-53773, CVSS 9.6: hidden prompt injection embedded in PR descriptions achieves remote code execution via the AI coding assistant. source
- Prompt injection +340% YoY(OWASP 2026 LLM Security Report) — fastest-growing attack category; HackerOne disclosed reports show prompt injection +540%and AI issues +200%. source
- MCP / agentic attack surface— Model Context Protocol expands tool-poisoning and credential-theft risks across agent systems. source
- Claude-assisted real CVEs— FreeBSD CVE-2026-4747 (RPCSEC_GSS RCE) and Linux kernel CVE-2026-31402, both linked to Claude-assisted research. source
Threat Intelligence
- Klue OAuth breach → "Icarus" extortion— attackers stole Salesforce CRM data from multiple orgs in an ongoing extortion campaign; Klue.com also named on the
icarusleak site (see Ransomware section). source - SocGholish + Evil Corp takedown— international law enforcement cleaned ~15,000 malware-infected WordPress sites and seized 100+ servers tied to the SocGholish botnet and Evil Corp. source
- Check Point — Iran-linked LA Metro wiper— destructive intrusion (wiped servers) attributed to "Ababil of Minab" persona; analysts link further transit/tech attacks to Black Shadow infrastructure. report
- Stock-exchange exec mailbox espionage— months-long campaign siphoned a senior executive's Outlook mailbox at a major exchange via legitimate cloud storage + disguised update tasks; ~5 months undetected. report
- Chinese APT "REDCap"— breached medical research institutions, exfiltrating clinical-trial and patient data. source
Chinese-Language Community Picks
- This run did not fetch FreeBuf / Anquanke / Xianzhi Community RSS/HTML directly (sandbox / provenance restrictions), so there are no separately selected Chinese-community items today (see failed sources at the end).
Ransomware Today
RansomLook days=1 returned the same window as the 2026-06-20 brief (discovered 06-18 → 06-19; server still UTC 06-20), so net-new posts vs. yesterday = 0. Snapshot: 13 posts across 9 groups; most active qilin (3, all ⭐ watchlist hits), aurora (2), nightspire (2). Cross-link: icarus named Klue.com — same event as the Klue OAuth/Icarus extortion above (SaaS supply-chain double-extortion). Tomorrow: widen to days=2 or fetch after UTC rollover to avoid repeats.
Full victim table
Bug Bounty Today
No verifiable recent (within-30-day) individual disclosures retrieved today. Bugcrowd CrowdStream and HackerOne Hacktivity are both client-rendered; WebFetch returned only page shells and search/mirrors surfaced only older/curated reports. Per the no-stale-fill rule, the recent-disclosure table is empty. Project-level signals: HackerOne trimmed bounty rewards (The Register, 2026-05-21); AI vuln reports up +540% (prompt injection); OpenAI Safety Bug Bounty (~$1M, Bugcrowd) remains open.
Full notes
AI Frontier
OpenAI
- Open-source gpt-oss-120b (single-GPU, ~o3/o4-mini class) and 20b (consumer laptop).
- Safety Bug Bounty (since Mar 2026, Bugcrowd, ~$1M/yr) — prompt injection, jailbreaks, agentic/MCP, OWASP LLM Top 10.
Anthropic
- Claude Fable 5 launched 2026-06-09 (1M-token reasoning model).
- Claude-assisted real CVEs: FreeBSD CVE-2026-4747, Linux kernel CVE-2026-31402.
Google DeepMind / AI
- Gemini 3.5 Flash GA (May 19 I/O 2026); 3.5 Pro in June.
- AlphaEvolve expands into genomics, quantum, mathematics (e.g. -30% DNA-sequencing error detection).
Full roundup: ai-frontier/daily/2026-06-21.html
Failed / Not-Retrieved Sources
- Bugcrowd CrowdStream, HackerOne Hacktivity — client-rendered; no verifiable recent per-item disclosures via WebFetch/WebSearch.
- FreeBuf / 安全客 / 先知社区 (Chinese RSS/HTML) — not directly retrieved this run (provenance/sandbox limits); no Chinese-community items selected today.
- PortSwigger / Project Zero / Mandiant native RSS — not fetched directly; covered via search aggregation, dates as noted.
Sources used: see intel/sources.yaml