Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-06-22
Daily Brief·2026-06-22·22 Items

Rosetta Daily · Jun 22, 2026

Generated automatically · ~20 sources scanned · 22 items selected
Collection note: assembled primarily via web search aggregation (some RSS/HTML feeds not fetched directly due to sandbox / WebFetch provenance limits); RansomLook API and Bugcrowd CrowdStream fetched directly. Failed sources at end.

Critical Vulnerabilities

  • 🔴🔥⚠️ "FortiBleed" — mass credential compromise of internet-facing FortiGate — Fortinet FortiGate / FortiOS SSL-VPN
    Threat actors (assessed Russian-speaking) systematically pulled config files from internet-facing FortiGate devices and cracked stored hashes, yielding a verified database of 86,644 working admin credentials across 194 countries (as of 2026-06-19). CISA issued a hardening alert on 2026-06-18. Terminate all SSL-VPN + admin sessions, reset all Fortinet passwords, enforce PBKDF2 + phishing-resistant MFA, and hunt for unauthorized access now.
    The Hacker News · CISA alert · Arctic Wolf

  • 🔴⚠️ AutoJack — a single malicious web page → host-level RCE via AI browsing agent — Microsoft AutoGen Studio
    Microsoft's Defender research team disclosed (2026-06-18) a chained exploit: a malicious page rendered by a local AI browsing agent reaches the AutoGen Studio MCP WebSocket and executes arbitrary host processes — no credentials, no interaction beyond visiting the page. Chains an origin-allowlist bypass (agents run as localhost), missing MCP auth, and unsafe shell parameter handling. Pre-release builds 0.4.3.dev1 / 0.4.3.dev2 (on PyPI, unyanked) are vulnerable; stable 0.4.2.2 is not. Fix in GitHub main (PR #7362), no stable patched release yet. No in-the-wild exploitation observed.
    Microsoft Security Blog · The Hacker News

  • 🔴🔥 Windows Netlogon RCE actively exploited — Microsoft Windows, CVE-2026-41089
    Stack-based buffer overflow in Netlogon; a crafted network request to a domain controller yields RCE. Now exploited in the wild — prioritize the June rollup on DCs.
    Help Net Security · BleepingComputer

  • 🔴🔥 Oracle PeopleSoft RCE exploited as 0-day — Oracle PeopleSoft Enterprise PeopleTools, CVE-2026-35273
    Confirmed exploited in the wild as a zero-day by extortion group ShinyHunters (UNC6240); fixed in Oracle's June CPU (243 CVEs / 245 patches).
    Tenable

  • 🔴 Cisco Identity Services Engine — RCE + information disclosure — Cisco ISE (advisory 2026-06-17)
    Cisco patched RCE and info-disclosure vulnerabilities in ISE; patch management-plane appliances promptly.
    Cisco Security Advisories · SecurityWeek

In-the-Wild Exploitation (CISA KEV)

  • CISA adds Joomla Content Editor flaw (2026-06-16)— CVE-2026-48907(Widget Factory JCE improper access control), evidence of active exploitation.
    CISA alert
  • CISA KEV additions (2026-06-09)— CVE-2026-11645(Chromium V8 OOB read/write), CVE-2026-7473(Arista EOS), CVE-2026-20245(Cisco Catalyst SD-WAN Manager).
    CISA alert
  • FortiBleed + Windows Netlogon (CVE-2026-41089) + Oracle PeopleSoft (CVE-2026-35273)— all confirmed exploited this cycle (see above).

Vendor Advisories

  • Microsoft— Record June Patch Tuesday: ~200+ CVEs, 33 Critical, multiple zero-days (incl. actively-exploited Netlogon CVE-2026-41089). CrowdStrike
  • Oracle— June CPU: 243 CVEs / 245 patches, incl. exploited PeopleSoft CVE-2026-35273. Tenable
  • Cisco— ISE RCE + info-disclosure advisory (2026-06-17); also patched IOS / IOS XR high-severity flaws. SecurityWeek
  • Google Chrome— V8 zero-day CVE-2026-11645 (now in KEV) patched. Zero Day Initiative

Web Security Research

  • PortSwigger — compromising email accounts with nothing but CSS + HTML: novel technique weaving vectors past CSS sanitization, hardened CSP, and HTML filtering libraries. PortSwigger Research
  • Side-channels as a core exploitation primitive: PortSwigger flags 2025's shift toward side-channels in web exploitation; nominations now open for Top 10 Web Hacking Techniques of 2025. PortSwigger

AI Security

  • AutoJack— malicious page → host RCE via AI browsing agent / AutoGen Studio MCP (see Critical Vulnerabilities). Poster child for agentic/MCP auth + parameter-handling gaps. Microsoft
  • Prompt injection +340% YoY(OWASP 2026 LLM report) — fastest-growing attack category; 73% of production AI deploymentsassessed vulnerable. Securance
  • First large-scale indirect prompt injection in the wild— Unit 42 documented (March 2026) ad-review evasion + system-prompt leakage on live commercial platforms; a financial-services AI agent leaked internal pricing for three weeks. SombraInc

Threat Intelligence

  • Gentlemen RaaS shipping EDR killers— the Gentlemen ransomware-as-a-service operation hands affiliates a suite of EDR-killer tools (HexKiller, ThrottleBlood, HavocKiller) that impersonate security vendors with fake version info and copied certs/icons. The Hacker News
  • Unit 42 — Screening Serpens (Iran-nexus APT)targeting US / Israel / UAE entities; six new RAT variants observed (mid-Feb → April 2026). Unit 42
  • Unit 42 2026 Global IR Report— attacks ~4× faster (exfil <1h in some cases); identity weaknesses in ~90% of investigations; 87% spanned multiple attack surfaces. RH-ISAC

Chinese-Language Community Picks

  • Pwn2Own Berlin 2026 registration full(the first sell-out in 19 years); the rejected xchglabs team, which had prepared 86 vulnerabilities, turned to "retaliatory disclosure" against vendors. FreeBuf
  • codexui-android npm supply-chain attack(disclosed by Aikido): disguised as Sentry traffic while stealing and exfiltrating identity credentials. FreeBuf
  • GhostLock PoC: demonstrates abusing the Windows file interface to block file access on SMB shares. FreeBuf

Ransomware Today

6 new RansomLook posts in the last 24h (4 groups; net-new vs. yesterday). Most active: nova (2), inc ransom (2). 2 watchlist hits, both INC Ransom — including a media/publishing victim (Newspaper Media Group). nightspire again hit a dental clinic; nova added a Vietnam (VN) target.
Full victim table

Bug Bounty Today

0 verifiable recent (≤30-day) individual disclosures today — both Bugcrowd CrowdStream and HackerOne Hacktivity returned client-rendered shells with no date-verifiable per-report items, so the recent-disclosures table is intentionally empty (no padding with old cases). Background only: Google VRP 2025 paid $17.1M (AI VRP $350K); Bugcrowd 2026 shows broken-access-control criticals up 36%.
Full disclosures file


AI Frontier

OpenAI

  • Pushing hard in the June 2026 model wave (coding + agentic the main battleground vs. Google/Anthropic/xAI). OpenAI Safety Bug Bounty (Bugcrowd, ~$1M pool) covers prompt injection, jailbreaks, agentic/MCP risks. CNBC

Anthropic

  • Claude Fable 5launched 2026-06-09 — 1M-token context, $10/$50 per M tokens. llm-stats

Google DeepMind / AI

  • Gemini 3.5 Proimminent ("give us until next month"); Gemini 3.5 Flash GA since May 19. AlphaEvolve expanding across genomics/quantum/math. Google AI VRP pays up to $30K for AI-product flaws. WaveSpeed

🛡 = security-related


Failed / Unfetched Sources

  • Direct RSS/Atom/HTML feeds (PortSwigger, Project Zero, MSRC, The Hacker News, FreeBuf, etc.) — not fetched directly (sandbox network blocked + WebFetch provenance gate); content sourced via web search instead.
  • Bugcrowd CrowdStream / HackerOne Hacktivity — client-rendered; only page shells retrieved, no per-report dated items.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jun 21, 2026
Next →
Rosetta Daily · Jun 23, 2026