Rosetta Daily · Jun 26, 2026
Generated automatically · ~22 sources scanned · 24 items selected
Critical Vulnerabilities
-
Cisco Catalyst SD-WAN Manager — CLI command injection — CVE-2026-20245, CVSS 7.8 🔥 ⚠️
An authenticated, local attacker can execute arbitrary commands as root by supplying a crafted file. In CISA KEV (added Jun 9) and actively exploited; Tenable tracks ongoing exploitation of the broader Cisco SD-WAN chain (UAT-8616, incl. CVE-2026-20182).
The Hacker News · Tenable -
Splunk Enterprise — actively exploited flaw 🔥 ⚠️
CISA confirmed in-the-wild exploitation and ordered FCEB agencies to patch by Sunday. One of five CVEs (alongside Lantronix and Ubiquiti) with confirmed active exploitation this week.
BleepingComputer -
Lantronix EDS5000 Code Injection — CVE-2025-67038, CVSS 9.8 🔴 🔥
Root-level command injection (firmware 2.1.0.0R3). KEV remediation deadline is today, Jun 26 — verify FCEB compliance.
CISA KEV alert -
Ubiquiti UniFi OS — three exploited flaws — CVE-2026-34908 / -34909 / -34910 🔴 🔥
Improper access control, path traversal, and improper input validation; actively exploited. CISA remediation deadline also today, Jun 26.
Cybersecurity News -
Cisco Unified CM SSRF → Root — CVE-2026-20230, CVSS 8.6 🔴 🔥 ⚠️
New reporting: the SSRF→root flaw was exploited as a zero-day at least two months before disclosure. Unauthenticated SSRF via improper HTTP input validation; public PoC, webshell drops observed. (Carryover, escalated.)
BleepingComputer
In-the-Wild Exploitation (CISA KEV)
- Splunk Enterprise— added to KEV with a patch-by-Sunday deadline; active exploitation confirmed.
BleepingComputer - Jun 23 batch — deadline TODAY (Jun 26): CVE-2025-67038 (Lantronix EDS5000) + CVE-2026-34908/-34909/-34910 (Ubiquiti UniFi OS).
CISA alert - SolarWinds Serv-U— CISA warns the flaw is now being exploited to crash servers (DoS).
BleepingComputer
Vendor Advisories
- Cisco— Catalyst SD-WAN Manager (CVE-2026-20245) and Unified CM SSRF advisories; patch or restrict CLI/file upload access.
The Hacker News - Google— patched Chrome's first zero-day exploited in attacks this year; update Chrome/Chromium-based browsers immediately.
BleepingComputer - Carryover: Microsoft June Patch Tuesday (206 CVEs / 6 zero-days) and the Jun 23 KEV batch remain this week's patch priorities.
Web Security Research
- Pwn2Own Berlin 2026 hits max capacity— for the first time in 19 years the contest filled up. Team xchglabs, rejected after preparing 86 vulnerabilities(NVIDIA, Docker, Linux KVM, PyTorch), opted to disclose details directly to vendors.
FreeBuf - PortSwigger — Top 10 Web Hacking Techniques of 2025— 19th edition results published; community + expert panel ranked the year's most innovative web research (HTTP request smuggling and cache poisoning featured heavily).
PortSwigger Research
AI Security
- Prompt injection remains OWASP's #1 LLM risk in 2026— OWASP's 2026 report cites a 340% YoY surge, present in 73% of production AI deployments; MCP and agentic/tool-using workflows widen blast radius.
Kunal Ganglani· Radware - Weaponized AI 2026 (Group-IB)— jailbreak-framework "as-a-service" sold for $50–200/monthon dark-web forums; commoditized guardrail bypass.
Group-IB - IEEE S&P 2026— accepted paper maps prompt-injection risks in third-party AI chatbot plugins ("When AI Meets the Web").
arXiv
Threat Intelligence
- Mistic backdoor— new, stealthy backdoor in suspected financially-motivated attacks against insurance, education, IT and professional-services orgs since Apr 2026; linked to initial-access broker KongTuke.
BleepingComputer - APT41 (Mandiant / Google TAG)— sustained campaign compromising global shipping, logistics, media/entertainment, technology and automotive organizations.
Google Cloud - M-Trends 2026— grounded in 500,000+ hours of IR; advises treating low-impact and routine malware alerts as high-priority indicators of impending intrusion.
Google Cloud - APT42 (Iran)— enhanced social-engineering against Western/Middle-East NGOs, media, academia and legal services, including cloud environments.
Google Cloud
Chinese Community Picks
- Pwn2Own Berlin 2026 容量爆满— xchglabs 团队备好 86 个漏洞(NVIDIA / Docker / Linux KVM / PyTorch)被拒赛后选择直接向厂商披露。 FreeBuf
- Android adbd 零点击 RCE — CVE-2026-0073— 邻近攻击者无需交互即可获得完整 shell(carryover,仍在热议)。 FreeBuf
- Apache Flink CVE-2026-35194— 代码生成引擎 SQL 注入 → RCE(carryover,仍相关)。 FreeBuf
Ransomware Today
RansomLook's 24h window returned 28 leak-site posts across 7 groups — the same window as yesterday (newest post 2026-06-25T00:22; no fresher posts available this run). Most active: the gentlemen (11 — manufacturing/construction/retail across EU + Kuwait + China), stormous (6 — e-commerce stores + two full-data dumps), nova (6, ~3 unique victims re-posted). Watchlist hits: akira ×2, qilin (Cash Canada / financial), INC Ransom (horizoneye), anubis → Quest Health Solutions (healthcare), and CHIFENG GOLD SEPON (China / gold mining, via the gentlemen).
Full victim table
Bug Bounty
Bug Bounty now has its own daily deep-dive feature (themed recent disclosures + one detailed write-up per day).
Open the Bug Bounty daily feature
AI Frontier
OpenAI
- Broadcom inference chip(Jun 25) — OpenAI and Broadcom unveiled an LLM-optimized inference chip, pushing OpenAI's custom-silicon strategy to reduce reliance on third-party GPUs.
Anthropic
- Continued Google talent raid— Gemini contributors Jonas Adler(AI coding) and Alexander Pritzel(model training) are leaving Google for Anthropic, following Nobel laureate John Jumper(→ Anthropic) and Noam Shazeer(→ OpenAI). Pre-IPO equity is cited as the pull.
Google DeepMind / AI
- Gemini 3.5 Prostill not shipped ("give us until next month"); the repeated researcher departures are raising investor doubts about Google's pace.
Also notable
- MiniMax M2.5released — part of a June wave of Chinese labs approaching frontier performance at significantly lower API cost.
🛡 = security-relevant
Failed Sources (if any)
- Direct RSS/Atom/HTML feed fetch blocked in this environment (web_fetch provenance gate + sandbox network) — categories assembled via WebSearch; feed timestamps approximate.
- RansomLook
?days=1returned the same window as the 2026-06-25 run (no posts newer than 06-25T00:22 this run).
Sources used: see intel/sources.yaml