Rosetta Daily · Jun 28, 2026
Generated automatically · ~22 sources scanned · 21 items selected
Critical Vulnerabilities
-
Oracle PeopleSoft Enterprise PeopleTools — unauthenticated RCE — CVE-2026-35273, CVSS 9.8 🔴 🔥 ⚠️
Missing authentication for a critical function → full server takeover with no login and no user interaction, just HTTP network access. ShinyHunters chained it to steal data and extort; Mandiant/GTIG observed exploitation May 27–Jun 9, hitting universities hardest. Already in CISA KEV.
The Hacker News · SecurityWeek -
Check Point Remote Access VPN — authentication bypass — CVE-2026-50751 🔴 🔥 ⚠️
Unauthenticated attackers bypass auth and establish a VPN session on Mobile Access / Remote Access / Spark gateways configured for the deprecated IKEv1 protocol. Exploited in the wild since ~May 7 by a Qilin ransomware affiliate across dozens of orgs; CISA issued an emergency directive (BOD 22-01) to patch.
BleepingComputer · Check Point hotfix -
Microsoft Defender "RoguePlanet" — SYSTEM privilege escalation — CVE-2026-50656, CVSS 7.8 ⚠️
Race condition / improper link resolution in the Malware Protection Engine. Public PoC achieves local SYSTEM on fully June-2026-patched Windows 10/11, no user interaction. Released by researcher "Nightmare Eclipse"; patch still in development with no committed date — treat as live exposure on endpoints.
BleepingComputer · Help Net Security -
Cisco Unified Communications Manager — SSRF — CVE-2026-20230 🔥
Server-side request forgery in CUCM; added to CISA KEV on 6/25 alongside the PTC Windchill flaw due to in-the-wild activity. Audit UC infrastructure exposure.
CISA alert -
Chrome V8 — out-of-bounds memory access — CVE-2026-11645, CVSS 8.8 🔴 🔥 ⚠️ (carryover)
OOB read/write in the V8 JS/WASM engine; Google confirms an exploit exists in the wild. In CISA KEV — push the Chrome/Chromium update fleet-wide if not done.
The Hacker News
In-the-Wild Exploitation (CISA KEV)
- Check Point VPN CVE-2026-50751— emergency directive; Qilin ransomware affiliate exploitation observed since early May. Patch immediately if IKEv1 remote access is enabled.
Cybersecurity Dive - 6/25 KEV batch— PTC Windchill/FlexPLM (CVE-2026-12569) + Cisco CUCM SSRF (CVE-2026-20230) added for active exploitation / webshell activity.
CISA alert - Oracle PeopleSoft CVE-2026-35273— ShinyHunters extortion campaign, university-heavy targeting; confirm PeopleTools assets are patched.
SecurityWeek
Vendor Advisories
- Microsoft— Confirms RoguePlanet (CVE-2026-50656) Defender EoP; high-quality patch "in development," no date. June Patch Tuesday remains a record-breaker (~200+ CVEs); finish rollout.
SecurityWeek - Check Point— Hotfix released for the deprecated-IKEv1 VPN auth-bypass; disable IKEv1 remote access / require machine certificates where possible.
Check Point - PTC— Windchill/FlexPLM RCE (CVE-2026-12569): after patching, still hunt for 16-hex-named JSP webshells (
POST /Windchill/login/[0-9a-f]{16}.jsp). (carryover)
PTC
Web Security Research
- HTTP.sys / Windows Kernel RCE (CVSS 9.8)— among June's headline server-side flaws: remote, unauthenticated code execution with no user interaction; ZDI's June review walks the most impactful network-reachable bugs.
ZDI June Review - Smuggling Requests with Chunked Extensions(Imperva) — malformed chunk extensions desync front-end vs back-end on request boundaries → a fresh HTTP/1.1 request-smuggling variant. (carryover, still relevant)
Imperva - XSS Cheat Sheet — 2026 Edition(PortSwigger) — vectors/payloads refreshed for current browsers. (reference)
PortSwigger
AI Security
- Prompt injection still drives most agentic-AI failures in production(OWASP, via Help Net) — 2026 report catalogs CVEs, supply-chain breaches and advisories across nearly every agentic-risk category; re-centers the "lethal trifecta"(private data + untrusted content + outbound comms = exfil path). Reported ~340% YoY rise in attacks.
Help Net Security - "When prompts become shells: RCE in AI agent frameworks"(Microsoft Security) — demonstrates how injected prompts reach code-execution sinks inside popular agent frameworks; argues for hardened tool boundaries and sandboxing.
Microsoft Security Blog - Prompt injection may be a permanent flaw, not a patchable bug— LLMs process system prompts, user input and retrieved content as one token stream with no privilege boundary; filtering/least-privilege reduces but cannot eliminate the risk.
TechTimes
Threat Intelligence
- ShinyHunters → Oracle PeopleSoft— Mandiant/GTIG tie the extortion crew to PeopleTools zero-day exploitation (CVE-2026-35273), data theft + extortion, universities hit hardest.
The Hacker News - Qilin → Check Point VPN— ransomware affiliate weaponized CVE-2026-50751 for initial access; activity since early May across several dozen orgs.
Help Net Security - M-Trends 2026 (carryover)— attacker tempo ~4× faster; some cases exfiltrate within 1 hour. Treat low-impact/commodity-malware alerts as high-priority precursors.
Google Cloud
Chinese Community
- 宝塔 WAF (Baota WAF) latest-version RCE 0-day— FreeBuf reports an unauthenticated RCE in the newest build that yields root; widely deployed on CN web stacks, audit/segment exposed panels.
FreeBuf - n8n workflow automation — chainable RCE— CVE-2026-44789~44791 chain to remote code execution. (carryover)
FreeBuf - cPanel three critical fixes— CVE-2026-29201/2/3 (privesc, code execution, DoS). (carryover)
FreeBuf
Ransomware Today
RansomLook's 24h window still returns the same 20 leak-site posts across 15 groups (newest discovered 2026-06-26T15:57) — the public feed hasn't advanced past 06-26, so treat as a continuation of the 06-27 batch. Watchlist hits: akira → Precise Forms, inc ransom → GSP Crop Science + Life Bridges. Notable manual flags: leaknet → MagMutual (cyber-insurer, claimed 7.3M records), the gentlemen → Atlas Elektronik (German naval/defense electronics), healthcare cluster (interlock → Clearview Eye Centre, payload → Clínica La Sabana), and government/emergency (krybit → politur.gob.do, nova → NSW Rural Fire Service).
Full victim table
Bug Bounty
Bug Bounty has its own daily track now (deep-dive + theme-grouped recent disclosures).
Open the Bug Bounty daily track
AI Frontier
OpenAI
- IPO timing reshuffle (carryover)— OpenAI now expects rival Anthropic to list first; both have filed confidentially with the SEC. OpenAI had eyed an autumn listing.
Anthropic
- "Largest known distillation attack" allegation— Anthropic told the Senate Banking Committee that operators tied to Alibaba's Qwenlab ran ~25,000 fraudulent accounts generating 28.8M Claude exchanges(Apr 22–Jun 5) to distill its models; calls the conduct "brazen" and "illicit." A model-theft / IP-exfil story with direct AI-security relevance.
Bloomberg - Claude Tag on Slack (beta)— @Claude in channels for delegated, async tasks with controlled access to tools/data; Enterprise & Team.
- Fable 5moved off included plans to usage-credit billing (6/23); senior Google researchers (Adler, Pritzel, reportedly Shazeer) departing toward Anthropic/OpenAI.
Google DeepMind / AI
- Gemini 3.5 Pro imminent— promised "next month" at I/O (May 19); Gemini 3.5 Flash already shipped. Positioned for agentic/coding workloads.
- Talent churn— Google losing several senior AI researchers to Anthropic and OpenAI.
🛡 = security-relevant
Failed / Degraded Sources
- RansomLook API — reachable but feed stale(latest post 06-26T15:57; no 06-27/06-28 entries).
- FreeBuf — mobile pages are JS-rendered; only partial titles retrievable via search (content not fully fetchable).
Sources used: see intel/sources.yaml