Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-06-24
Daily Brief·2026-06-24·26 Items

Rosetta Daily · Jun 24, 2026

Generated automatically · ~22 sources scanned · 26 items selected

Critical Vulnerabilities

  • Squidbleed — Squid Proxy, CVE-2026-47729 ⚠️ 🔴
    29-year-old heap over-read in Squid's FTP directory-listing parser leaks other users' cleartext HTTP requests, including Authorization headers and session tokens (Heartbleed-style). Affects every version in default config; bug dates to a 1997 commit. Fix merged to v7/dev branch — mitigate by disabling FTP.
    Calif.io disclosure · The Hacker News

  • FortiBleed — Fortinet FortiGate / SSL VPN, credential leak 🔴 🔥
    Active campaign harvested a validated trove of 86,644 working SSL VPN credentials + plaintext passwords + config exports across 194 countries (~half of internet-facing FortiGate appliances). Attributed to a Russian-speaking actor; ~1.16B credential attempts against 320k targets. CISA issued a hardening alert (Jun 18) — reset all VPN/admin credentials now.
    SecurityWeek · CISA alert

  • Windows HTTP.sys RCE — Microsoft, CVSS 9.8 🔴
    Unauthenticated, network-triggerable RCE in the kernel-mode driver underpinning IIS and many Windows services — no privileges or user interaction required. Part of June Patch Tuesday (206 fixes, 39 Critical, 6 zero-days incl. 1 exploited).
    BleepingComputer

  • Apache Flink SQL Injection → RCE — CVE-2026-35194 🔴
    SQL injection in the platform's code-generation engine enables remote code execution in distributed data-processing environments.
    FreeBuf

In-the-Wild Exploitation (CISA KEV)

  • CVE-2026-7473— Arista EOS; CVE-2026-11645— Google Chromium V8; CVE-2026-20245— Cisco Catalyst SD-WAN Manager (added Jun 9).
    CISA
  • CVE-2026-20262— Cisco Catalyst SD-WAN Manager path traversal; CVE-2026-54420— LiteSpeed cPanel plugin symlink-following (added Jun 15).
    CISA
  • CVE-2026-48907— Widget Factory Joomla Content Editor improper access control (added Jun 16).
    CISA

Vendor Advisories

  • Microsoft Patch Tuesday — June 2026: largest ever at 206 CVEs (39 Critical, 6 zero-days). Notables: HTTP.sys RCE (9.8), CVE-2026-50507 BitLocker bypass.
    ZDI review
  • Apple: iOS/iPadOS 26.5 fixes 50+ flaws; macOS Tahoe 26.5 ~70 fixes. Background Security Improvement now shipping auto-patches between releases.
    Apple security releases
  • CISAFortinet hardening guidance following FortiBleed credential exposure.
    CISA

Web Security Research

  • Squidbleed technical write-up— Calif Security Research details how a null-terminator mishandling in strchrwalks off the heap buffer; discovered with AI assistance.
    Calif.io
  • PortSwigger: LLM excessive agency— recent lab reframes LLM integration as an architecture (not just prompt-injection) problem; over-permissioned models become a proxy for privileged internal operations, analogous to SSRF.
    PortSwigger Research
  • Pwn2Own Berlin 2026sold out for the first time in 19 years; rejected researchers launched a "retaliatory disclosure" wave.
    FreeBuf

AI Security

  • OpenAI GPT-5.5-Cyber (Daybreak)— billed as OpenAI's "strongest model yet for finding and patching software vulnerabilities"; scored a record 85.6% on CyberGym. Restricted to verified defenders via Trusted Access for Cyber; 30 vendors join the Daybreak Cyber Partner Program (Jun 23).
    The Hacker News· OpenAI
  • EchoLeak— documented as the first real-world zero-click prompt-injection exploit in a production LLM system.
    arXiv
  • codexui-android npm supply-chain attack— popular npm package was actually a supply-chain implant stealing credentials (disclosed by Aikido Security).
    FreeBuf

Threat Intelligence

  • Screening Serpens (Iran-nexus)— Unit 42 details AppDomainManager hijacking and new RAT variants targeting tech and defense sectors.
    Unit 42
  • Boggy Serpens— Apr 2025–Feb 2026 campaigns adopt AI-generated code and a Rust-based BlackBeard backdoor for rapid custom implant deployment.
    Unit 42
  • Credential-sniffer campaign— a custom sniffer harvested 110M+ credentials since Feb 2026, in parallel with the FortiBleed brute-force wave.
    The Hacker News

Chinese-Language Community Picks

  • Apache Flink CVE-2026-35194— SQL injection in the code-generation engine leading to RCE, affecting distributed data-processing environments.
    FreeBuf
  • codexui-android npm supply-chain attack— a malicious npm package disclosed by Aikido Security that steals credentials.
    FreeBuf
  • Pwn2Own Berlin 2026 at capacity + retaliatory disclosure— full for the first time in 19 years, with rejected researchers releasing a batch of 0-days.
    FreeBuf

Ransomware Today

30 new leak-site posts across 15 groups (RansomLook, last 24h). Most active: icarus (~9), akira (3), eraleign/APT73 (3). Watchlist hits (~6): akira ×3, qilin (Schumacher Homes), INC Ransom (belpointe), plus education (Reynella East College / interlock) and medical (EON Meditech). Notable: a brand-new prinz eugen leak site appeared; eraleign/APT73 posted gov.br and Vienna Airport.
Full victim table

Bug Bounty Today

5 recent disclosures selected (data window 2026-05-25 → 06-24), led by Bugcrowd CrowdStream (NASA & FCC VDPs, dated). Highlights: a P1 unauthenticated blind SQL injection enumerating NASA's DB (12 Jun) and a P1 RCE via insecure deserialization on NASA GSFC (29 May). HackerOne's live list was not API-retrievable this run (SPA/GraphQL); one SSRF report added via search with an approximate date.
Full disclosures


AI Frontier

OpenAI

  • GPT-5.5-Cyber + Daybreak Cyber Partner Program (30 vendors) for defender-side vuln finding/patching; CyberGym 85.6%.

Anthropic

  • Claude Fable 5 (1M context). Project Glasswing expands Claude Mythos Preview to ~150 orgs; reportedly helped early partners surface 10,000+ high-severity vulnerabilities.

Google DeepMind / AI

  • Gemini 3.5 Pro positioned as the major June release (Gemini 3.5 Flash shipped May 19). Genie 3 world model generates interactive 3D environments; Gemini Robotics-ER 1.6 integrated into Boston Dynamics Spot.

🛡 = security-relevant


Failed Sources (if any)

  • Direct RSS/Atom/HTML feed fetch is blocked in this environment (web_fetch provenance gate + sandbox network) — categories assembled via WebSearch. Feed-level timestamps are approximate.
  • HackerOne Hacktivity — live disclosure list not retrievable (client-rendered SPA; data behind POST GraphQL / token-gated API).

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jun 23, 2026
Next →
Rosetta Daily · Jun 25, 2026