Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-06-28
Daily Brief·2026-06-28·21 Items

Rosetta Daily · Jun 28, 2026

Generated automatically · ~22 sources scanned · 21 items selected

Critical Vulnerabilities

  • Oracle PeopleSoft Enterprise PeopleTools — unauthenticated RCE — CVE-2026-35273, CVSS 9.8 🔴 🔥 ⚠️
    Missing authentication for a critical function → full server takeover with no login and no user interaction, just HTTP network access. ShinyHunters chained it to steal data and extort; Mandiant/GTIG observed exploitation May 27–Jun 9, hitting universities hardest. Already in CISA KEV.
    The Hacker News · SecurityWeek

  • Check Point Remote Access VPN — authentication bypass — CVE-2026-50751 🔴 🔥 ⚠️
    Unauthenticated attackers bypass auth and establish a VPN session on Mobile Access / Remote Access / Spark gateways configured for the deprecated IKEv1 protocol. Exploited in the wild since ~May 7 by a Qilin ransomware affiliate across dozens of orgs; CISA issued an emergency directive (BOD 22-01) to patch.
    BleepingComputer · Check Point hotfix

  • Microsoft Defender "RoguePlanet" — SYSTEM privilege escalation — CVE-2026-50656, CVSS 7.8 ⚠️
    Race condition / improper link resolution in the Malware Protection Engine. Public PoC achieves local SYSTEM on fully June-2026-patched Windows 10/11, no user interaction. Released by researcher "Nightmare Eclipse"; patch still in development with no committed date — treat as live exposure on endpoints.
    BleepingComputer · Help Net Security

  • Cisco Unified Communications Manager — SSRF — CVE-2026-20230 🔥
    Server-side request forgery in CUCM; added to CISA KEV on 6/25 alongside the PTC Windchill flaw due to in-the-wild activity. Audit UC infrastructure exposure.
    CISA alert

  • Chrome V8 — out-of-bounds memory access — CVE-2026-11645, CVSS 8.8 🔴 🔥 ⚠️ (carryover)
    OOB read/write in the V8 JS/WASM engine; Google confirms an exploit exists in the wild. In CISA KEV — push the Chrome/Chromium update fleet-wide if not done.
    The Hacker News

In-the-Wild Exploitation (CISA KEV)

  • Check Point VPN CVE-2026-50751— emergency directive; Qilin ransomware affiliate exploitation observed since early May. Patch immediately if IKEv1 remote access is enabled.
    Cybersecurity Dive
  • 6/25 KEV batch— PTC Windchill/FlexPLM (CVE-2026-12569) + Cisco CUCM SSRF (CVE-2026-20230) added for active exploitation / webshell activity.
    CISA alert
  • Oracle PeopleSoft CVE-2026-35273— ShinyHunters extortion campaign, university-heavy targeting; confirm PeopleTools assets are patched.
    SecurityWeek

Vendor Advisories

  • Microsoft— Confirms RoguePlanet (CVE-2026-50656) Defender EoP; high-quality patch "in development," no date. June Patch Tuesday remains a record-breaker (~200+ CVEs); finish rollout.
    SecurityWeek
  • Check Point— Hotfix released for the deprecated-IKEv1 VPN auth-bypass; disable IKEv1 remote access / require machine certificates where possible.
    Check Point
  • PTC— Windchill/FlexPLM RCE (CVE-2026-12569): after patching, still hunt for 16-hex-named JSP webshells (POST /Windchill/login/[0-9a-f]{16}.jsp). (carryover)
    PTC

Web Security Research

  • HTTP.sys / Windows Kernel RCE (CVSS 9.8)— among June's headline server-side flaws: remote, unauthenticated code execution with no user interaction; ZDI's June review walks the most impactful network-reachable bugs.
    ZDI June Review
  • Smuggling Requests with Chunked Extensions(Imperva) — malformed chunk extensions desync front-end vs back-end on request boundaries → a fresh HTTP/1.1 request-smuggling variant. (carryover, still relevant)
    Imperva
  • XSS Cheat Sheet — 2026 Edition(PortSwigger) — vectors/payloads refreshed for current browsers. (reference)
    PortSwigger

AI Security

  • Prompt injection still drives most agentic-AI failures in production(OWASP, via Help Net) — 2026 report catalogs CVEs, supply-chain breaches and advisories across nearly every agentic-risk category; re-centers the "lethal trifecta"(private data + untrusted content + outbound comms = exfil path). Reported ~340% YoY rise in attacks.
    Help Net Security
  • "When prompts become shells: RCE in AI agent frameworks"(Microsoft Security) — demonstrates how injected prompts reach code-execution sinks inside popular agent frameworks; argues for hardened tool boundaries and sandboxing.
    Microsoft Security Blog
  • Prompt injection may be a permanent flaw, not a patchable bug— LLMs process system prompts, user input and retrieved content as one token stream with no privilege boundary; filtering/least-privilege reduces but cannot eliminate the risk.
    TechTimes

Threat Intelligence

  • ShinyHunters → Oracle PeopleSoft— Mandiant/GTIG tie the extortion crew to PeopleTools zero-day exploitation (CVE-2026-35273), data theft + extortion, universities hit hardest.
    The Hacker News
  • Qilin → Check Point VPN— ransomware affiliate weaponized CVE-2026-50751 for initial access; activity since early May across several dozen orgs.
    Help Net Security
  • M-Trends 2026 (carryover)— attacker tempo ~4× faster; some cases exfiltrate within 1 hour. Treat low-impact/commodity-malware alerts as high-priority precursors.
    Google Cloud

Chinese Community

  • 宝塔 WAF (Baota WAF) latest-version RCE 0-day— FreeBuf reports an unauthenticated RCE in the newest build that yields root; widely deployed on CN web stacks, audit/segment exposed panels.
    FreeBuf
  • n8n workflow automation — chainable RCE— CVE-2026-44789~44791 chain to remote code execution. (carryover)
    FreeBuf
  • cPanel three critical fixes— CVE-2026-29201/2/3 (privesc, code execution, DoS). (carryover)
    FreeBuf

Ransomware Today

RansomLook's 24h window still returns the same 20 leak-site posts across 15 groups (newest discovered 2026-06-26T15:57) — the public feed hasn't advanced past 06-26, so treat as a continuation of the 06-27 batch. Watchlist hits: akira → Precise Forms, inc ransom → GSP Crop Science + Life Bridges. Notable manual flags: leaknet → MagMutual (cyber-insurer, claimed 7.3M records), the gentlemen → Atlas Elektronik (German naval/defense electronics), healthcare cluster (interlock → Clearview Eye Centre, payload → Clínica La Sabana), and government/emergency (krybit → politur.gob.do, nova → NSW Rural Fire Service).
Full victim table

Bug Bounty

Bug Bounty has its own daily track now (deep-dive + theme-grouped recent disclosures).
Open the Bug Bounty daily track


AI Frontier

OpenAI

  • IPO timing reshuffle (carryover)— OpenAI now expects rival Anthropic to list first; both have filed confidentially with the SEC. OpenAI had eyed an autumn listing.

Anthropic

  • "Largest known distillation attack" allegation— Anthropic told the Senate Banking Committee that operators tied to Alibaba's Qwenlab ran ~25,000 fraudulent accounts generating 28.8M Claude exchanges(Apr 22–Jun 5) to distill its models; calls the conduct "brazen" and "illicit." A model-theft / IP-exfil story with direct AI-security relevance.
    Bloomberg
  • Claude Tag on Slack (beta)— @Claude in channels for delegated, async tasks with controlled access to tools/data; Enterprise & Team.
  • Fable 5moved off included plans to usage-credit billing (6/23); senior Google researchers (Adler, Pritzel, reportedly Shazeer) departing toward Anthropic/OpenAI.

Google DeepMind / AI

  • Gemini 3.5 Pro imminent— promised "next month" at I/O (May 19); Gemini 3.5 Flash already shipped. Positioned for agentic/coding workloads.
  • Talent churn— Google losing several senior AI researchers to Anthropic and OpenAI.

🛡 = security-relevant


Failed / Degraded Sources

  • RansomLook API — reachable but feed stale(latest post 06-26T15:57; no 06-27/06-28 entries).
  • FreeBuf — mobile pages are JS-rendered; only partial titles retrievable via search (content not fully fetchable).

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jun 27, 2026
Next →
Rosetta Daily · Jun 29, 2026