Rosetta Daily · Jun 22, 2026
Generated automatically · ~20 sources scanned · 22 items selected
Collection note: assembled primarily via web search aggregation (some RSS/HTML feeds not fetched directly due to sandbox / WebFetch provenance limits); RansomLook API and Bugcrowd CrowdStream fetched directly. Failed sources at end.
Critical Vulnerabilities
-
🔴🔥⚠️ "FortiBleed" — mass credential compromise of internet-facing FortiGate — Fortinet FortiGate / FortiOS SSL-VPN
Threat actors (assessed Russian-speaking) systematically pulled config files from internet-facing FortiGate devices and cracked stored hashes, yielding a verified database of 86,644 working admin credentials across 194 countries (as of 2026-06-19). CISA issued a hardening alert on 2026-06-18. Terminate all SSL-VPN + admin sessions, reset all Fortinet passwords, enforce PBKDF2 + phishing-resistant MFA, and hunt for unauthorized access now.
The Hacker News · CISA alert · Arctic Wolf -
🔴⚠️ AutoJack — a single malicious web page → host-level RCE via AI browsing agent — Microsoft AutoGen Studio
Microsoft's Defender research team disclosed (2026-06-18) a chained exploit: a malicious page rendered by a local AI browsing agent reaches the AutoGen Studio MCP WebSocket and executes arbitrary host processes — no credentials, no interaction beyond visiting the page. Chains an origin-allowlist bypass (agents run as localhost), missing MCP auth, and unsafe shell parameter handling. Pre-release builds 0.4.3.dev1 / 0.4.3.dev2 (on PyPI, unyanked) are vulnerable; stable 0.4.2.2 is not. Fix in GitHub main (PR #7362), no stable patched release yet. No in-the-wild exploitation observed.
Microsoft Security Blog · The Hacker News -
🔴🔥 Windows Netlogon RCE actively exploited — Microsoft Windows, CVE-2026-41089
Stack-based buffer overflow in Netlogon; a crafted network request to a domain controller yields RCE. Now exploited in the wild — prioritize the June rollup on DCs.
Help Net Security · BleepingComputer -
🔴🔥 Oracle PeopleSoft RCE exploited as 0-day — Oracle PeopleSoft Enterprise PeopleTools, CVE-2026-35273
Confirmed exploited in the wild as a zero-day by extortion group ShinyHunters (UNC6240); fixed in Oracle's June CPU (243 CVEs / 245 patches).
Tenable -
🔴 Cisco Identity Services Engine — RCE + information disclosure — Cisco ISE (advisory 2026-06-17)
Cisco patched RCE and info-disclosure vulnerabilities in ISE; patch management-plane appliances promptly.
Cisco Security Advisories · SecurityWeek
In-the-Wild Exploitation (CISA KEV)
- CISA adds Joomla Content Editor flaw (2026-06-16)— CVE-2026-48907(Widget Factory JCE improper access control), evidence of active exploitation.
CISA alert - CISA KEV additions (2026-06-09)— CVE-2026-11645(Chromium V8 OOB read/write), CVE-2026-7473(Arista EOS), CVE-2026-20245(Cisco Catalyst SD-WAN Manager).
CISA alert - FortiBleed + Windows Netlogon (CVE-2026-41089) + Oracle PeopleSoft (CVE-2026-35273)— all confirmed exploited this cycle (see above).
Vendor Advisories
- Microsoft— Record June Patch Tuesday: ~200+ CVEs, 33 Critical, multiple zero-days (incl. actively-exploited Netlogon CVE-2026-41089). CrowdStrike
- Oracle— June CPU: 243 CVEs / 245 patches, incl. exploited PeopleSoft CVE-2026-35273. Tenable
- Cisco— ISE RCE + info-disclosure advisory (2026-06-17); also patched IOS / IOS XR high-severity flaws. SecurityWeek
- Google Chrome— V8 zero-day CVE-2026-11645 (now in KEV) patched. Zero Day Initiative
Web Security Research
- PortSwigger — compromising email accounts with nothing but CSS + HTML: novel technique weaving vectors past CSS sanitization, hardened CSP, and HTML filtering libraries. PortSwigger Research
- Side-channels as a core exploitation primitive: PortSwigger flags 2025's shift toward side-channels in web exploitation; nominations now open for Top 10 Web Hacking Techniques of 2025. PortSwigger
AI Security
- AutoJack— malicious page → host RCE via AI browsing agent / AutoGen Studio MCP (see Critical Vulnerabilities). Poster child for agentic/MCP auth + parameter-handling gaps. Microsoft
- Prompt injection +340% YoY(OWASP 2026 LLM report) — fastest-growing attack category; 73% of production AI deploymentsassessed vulnerable. Securance
- First large-scale indirect prompt injection in the wild— Unit 42 documented (March 2026) ad-review evasion + system-prompt leakage on live commercial platforms; a financial-services AI agent leaked internal pricing for three weeks. SombraInc
Threat Intelligence
- Gentlemen RaaS shipping EDR killers— the Gentlemen ransomware-as-a-service operation hands affiliates a suite of EDR-killer tools (HexKiller, ThrottleBlood, HavocKiller) that impersonate security vendors with fake version info and copied certs/icons. The Hacker News
- Unit 42 — Screening Serpens (Iran-nexus APT)targeting US / Israel / UAE entities; six new RAT variants observed (mid-Feb → April 2026). Unit 42
- Unit 42 2026 Global IR Report— attacks ~4× faster (exfil <1h in some cases); identity weaknesses in ~90% of investigations; 87% spanned multiple attack surfaces. RH-ISAC
Chinese-Language Community Picks
- Pwn2Own Berlin 2026 registration full(the first sell-out in 19 years); the rejected xchglabs team, which had prepared 86 vulnerabilities, turned to "retaliatory disclosure" against vendors. FreeBuf
- codexui-android npm supply-chain attack(disclosed by Aikido): disguised as Sentry traffic while stealing and exfiltrating identity credentials. FreeBuf
- GhostLock PoC: demonstrates abusing the Windows file interface to block file access on SMB shares. FreeBuf
Ransomware Today
6 new RansomLook posts in the last 24h (4 groups; net-new vs. yesterday). Most active: nova (2), inc ransom (2). 2 watchlist hits, both INC Ransom — including a media/publishing victim (Newspaper Media Group). nightspire again hit a dental clinic; nova added a Vietnam (VN) target.
Full victim table
Bug Bounty Today
0 verifiable recent (≤30-day) individual disclosures today — both Bugcrowd CrowdStream and HackerOne Hacktivity returned client-rendered shells with no date-verifiable per-report items, so the recent-disclosures table is intentionally empty (no padding with old cases). Background only: Google VRP 2025 paid $17.1M (AI VRP $350K); Bugcrowd 2026 shows broken-access-control criticals up 36%.
Full disclosures file
AI Frontier
OpenAI
- Pushing hard in the June 2026 model wave (coding + agentic the main battleground vs. Google/Anthropic/xAI). OpenAI Safety Bug Bounty (Bugcrowd, ~$1M pool) covers prompt injection, jailbreaks, agentic/MCP risks. CNBC
Anthropic
- Claude Fable 5launched 2026-06-09 — 1M-token context, $10/$50 per M tokens. llm-stats
Google DeepMind / AI
- Gemini 3.5 Proimminent ("give us until next month"); Gemini 3.5 Flash GA since May 19. AlphaEvolve expanding across genomics/quantum/math. Google AI VRP pays up to $30K for AI-product flaws. WaveSpeed
🛡 = security-related
Failed / Unfetched Sources
- Direct RSS/Atom/HTML feeds (PortSwigger, Project Zero, MSRC, The Hacker News, FreeBuf, etc.) — not fetched directly (sandbox network blocked + WebFetch provenance gate); content sourced via web search instead.
- Bugcrowd CrowdStream / HackerOne Hacktivity — client-rendered; only page shells retrieved, no per-report dated items.
Sources used: see intel/sources.yaml