Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-06-25
Daily Brief·2026-06-25·24 Items

Rosetta Daily · Jun 25, 2026

Generated automatically · ~22 sources scanned · 24 items selected

Critical Vulnerabilities

  • Cisco Unified CM / SME SSRF → Root — CVE-2026-20230, CVSS 8.6 🔴 🔥 ⚠️
    Unauthenticated SSRF via improper HTTP input validation lets an attacker write files to the OS and escalate to root. Now actively exploited (webshell drops via file:// payloads); public PoC available. Patched Jun 3 — requires WebDialer (commonly enabled).
    Help Net Security · Cisco advisory

  • Lantronix EDS5000 Code Injection — CVE-2025-67038, CVSS 9.8 🔴 🔥
    Root-level command injection: username is concatenated into a shell command without sanitization (firmware 2.1.0.0R3). Added to CISA KEV Jun 23.
    SecurityAffairs

  • Ubiquiti UniFi OS — three exploited flaws — CVE-2026-34908 (improper access control), CVE-2026-34909 (path traversal), CVE-2026-34910 (improper input validation) 🔴 🔥
    Max-severity, actively exploited; CISA mandates patching by Jun 26 (BOD 26-04).
    BleepingComputer

  • QNAP NAS multiple flaws — arbitrary command execution and security-control bypass across several QNAP products.
    CVEFeed

In-the-Wild Exploitation (CISA KEV)

  • CISA added 4 KEV entries (Jun 23): CVE-2025-67038 (Lantronix EDS5000), CVE-2026-34908 / -34909 / -34910 (Ubiquiti UniFi OS). Remediation due Jun 26.
    CISA alert
  • CVE-2026-20230(Cisco Unified CM SSRF→root) — exploitation observed over the weekend from a single IP; PoC public.
    SecurityWeek

Vendor Advisories

  • Cisco— Unified CM/SME SSRF advisory (cisco-sa-cucm-ssrf); apply fixes or disable WebDialer.
    Cisco
  • Ubiquiti— UniFi OS security updates for the three exploited CVEs.
    BleepingComputer
  • Carryover: Microsoft June Patch Tuesday (206 CVEs) and Apple iOS/macOS 26.5 remain the patch priorities from earlier this week.

Web Security Research

  • Cisco Unified CM SSRF-to-root chain— write-ups detail how a file://SSRF primitive becomes OS file-write then root; a clean real-world study of SSRF impact escalation.
    Threat-Modeling.com
  • Hugging Face typosquatting supply-chain— HiddenLayer details malicious repos impersonating official OpenAI projects to poison the AI dev community.
    FreeBuf

AI Security

  • APT28 weaponizes a Microsoft Office 1-day within 24h— Trellix tracks a multi-stage campaign abusing CVE-2026-21509 with cloud-based C2 against European military/government — a stark reminder of shrinking patch windows.
    Trellix
  • Hugging Face supply-chain poisoning(HiddenLayer) — typosquatted repos impersonating OpenAI; ML supply chain remains a soft target.
    FreeBuf

Threat Intelligence

  • Screening Serpens (Iran-nexus)— six new RATs deployed Feb–Apr 2026, including a new family MiniUpdateand evolved MiniJunk V2, against US/Israel/UAE targets.
    Unit 42
  • Silver Fox APT— Intel 471 reports spear-phishing of Taiwan government/tech using Gh0stCringe and HoldingHands RATs.
    Industrial Cyber
  • Black Basta remnantsresurface under CACTUS / BlackSuit affiliations, targeting finance and construction.
    Industrial Cyber

Chinese Community Picks

  • Hugging Face 仿冒投毒— HiddenLayer 披露 typosquatting 仿冒 OpenAI 项目的恶意仓库。 FreeBuf
  • 微软 Office 0day RCE 在黑客论坛交易— 出售针对 Office/Windows 的 0day RCE。 FreeBuf/CSDN
  • Apache Flink CVE-2026-35194— code-gen SQLi → RCE (carryover, still relevant). FreeBuf

Ransomware Today

28 new leak-site posts across 7 groups (RansomLook, last 24h). Most active: the gentlemen (11 — manufacturing/construction/retail across EU + Kuwait + China), stormous (6 — e-commerce stores + two full-data dumps), nova (6, ~3 unique victims re-posted). Watchlist hits (~6): akira ×2, qilin (Cash Canada / financial), INC Ransom (horizoneye), anubis → Quest Health Solutions (healthcare), and CHIFENG GOLD SEPON (China / gold mining, via the gentlemen).
Full victim table

Bug Bounty Today

12 recent disclosures (window 2026-05-26 → 06-25), all NASA / GLOBE government VDPs (no cash) — 3 Critical (P1): unauthenticated blind SQLi, deserialization RCE, and unauthenticated path traversal. Today's deep dive: a reflected DOM XSS escalated into authenticated-user PII theft via same-origin XHR ("don't stop at alert(1)"). HackerOne returned no verifiable recent items this run.
Full disclosures


AI Frontier

OpenAI

  • Getty Images partnership(Jun 21): multi-year deal to surface Getty's 400M licensed assets inside ChatGPT search — display-only, no training rights.

Anthropic

  • Claude Tag— evolution of Claude Code: multiplayer, proactive, embedded in Slack; @-mention to break tasks into stages and act in-thread (ambient mode, hours/days planning). ~65% of Anthropic's own product code is now agent-generated.
  • Continues hiring DeepMind talent (Jonas Adler, Alexander Pritzel; earlier John Jumper).

Google DeepMind / AI

  • Gemini 3.5 Pro still not launched; further high-profile researcher departures to Anthropic reported.

🛡 = security-relevant


Failed Sources (if any)

  • Direct RSS/Atom/HTML feed fetch blocked in this environment (web_fetch provenance gate + sandbox network) — categories assembled via WebSearch; feed timestamps approximate.
  • HackerOne Hacktivity — live disclosure list not retrievable (client-rendered SPA; POST GraphQL / token-gated API).

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jun 24, 2026
Next →
Rosetta Daily · Jun 26, 2026