Rosetta Daily · Jun 29, 2026
Generated automatically · ~22 sources scanned · 21 items selected
Critical Vulnerabilities
-
D-Link legacy DSL routers — unauthenticated command-injection RCE — D-Link, CVE-2026-0625, CVSS 9.3 🔴 ⚠️
Command injection in thednscfg.cgiDNS-settings endpoint lets a remote attacker run arbitrary code; exploited in the wild since late Nov 2025 for RCE + DNSChanger/botnet behavior. Affects EOL DSL-2740R/2640B/2780B/526B — D-Link will NOT patch; retire and replace.
SecurityWeek · BleepingComputer -
Cisco Unified Communications Manager — SSRF — Cisco, CVE-2026-20230, CVSS 8.6 🔴 🔥
Unauthenticated SSRF via improper HTTP-request validation; attacker can write files to the OS and escalate toward root. No workarounds. In CISA KEV (added 6/25); federal patch deadline was 6/28 — treat UC infra as exposed and confirm patched.
CISA alert · Windows Forum -
PTC Windchill / FlexPLM — RCE (improper input validation) — PTC, CVE-2026-12569, CVSS 9.3 🔴 🔥 ⚠️
PTC confirmed on 6/25 it continues to receive reports of heightened threat activity despite last week's patch. In CISA KEV. After patching, still hunt for the 16-hex JSP webshell (POST /Windchill/login/[0-9a-f]{16}.jsp). (carryover, still hot)
The Hacker News -
Microsoft Defender "RoguePlanet" — SYSTEM privilege escalation — Microsoft, CVE-2026-50656, CVSS 7.8 ⚠️
Public PoC grants local SYSTEM on fully-patched Win10/11 via a Defender race condition. High-quality patch still in development, no date. Released by researcher "Nightmare Eclipse" (who has dumped a string of Windows 0days). Treat endpoints as actively exposed. (carryover)
BleepingComputer -
Apache Flink — SQL injection → RCE — Apache, CVE-2026-35194 🔴
Flaw in the platform's code-generation engine lets SQL injection reach remote code execution in distributed data-processing environments. Inventory and patch Flink deployments.
FreeBuf
In-the-Wild Exploitation (CISA KEV)
- Cisco CUCM SSRF CVE-2026-20230— federal deadline 6/28; confirm Unified CM / CM-SME are patched (no workaround).
CISA alert - PTC Windchill/FlexPLM CVE-2026-12569— exploitation continuing past the patch; hunt for webshells.
The Hacker News - D-Link DSL routers CVE-2026-0625— active RCE/botnet recruitment of EOL gateways; no fix coming, replace hardware.
Cybernews
Vendor Advisories
- Cisco— CUCM SSRF (CVE-2026-20230, CVSS 8.6) rated high, no workarounds; patch immediately.
Cisco Security Advisories - D-Link— confirms it will notrelease a fix for CVE-2026-0625 (devices EOL 5+ years); urges retirement/replacement.
SecurityWeek - Microsoft— June Patch Tuesday recap stands: 206 CVEs, 39 Critical, six 0-days (five publicly disclosed, one actively exploited). RoguePlanet patch still pending. (carryover)
Cisco Talos
Web Security Research
- HTTP/1.1 Must Die: the desync endgame(PortSwigger) — desync research keeps escalating; timeout-based detection is now heavily WAF-fingerprinted, pushing researchers to malformed-chunk and structural techniques. Core reference for request-smuggling defense. (reference)
PortSwigger - Smuggling Requests with Chunked Extensions(Imperva) — malformed chunk extensions desync front/back-end on request boundaries; a 2025 top-10 web technique still worth auditing. (carryover)
PortSwigger Top 10 2025
AI Security
- First AI-driven intrusion observed end-to-end(Sysdig) — an attacker used an LLM agent to generate exploit commands in real time, breaking in via an exposed marimo notebook server (CVE-2026-39987) and completing the intrusion in ~22 minutes. Concrete proof that agentic offense compresses the attack lifecycle.
FreeBuf - LiteLLM supply-chain backdoor pushed by an autonomous bot— a bot ("hackerbot-claw") self-described as LLM-powered abused a misconfigured GitHub Actions setup to push two backdoored LiteLLM releasesto PyPI — the gateway under CrewAI, DSPy, Microsoft GraphRAG and others. Tracks with KEV entry CVE-2026-42271 (BerriAI LiteLLM command injection).
Help Net Security - Prompt injection: architectural, not a patchable bug— OWASP's 2026 report keeps prompt injection at the center of agentic risk (attacks reportedly +340% YoY); LLMs can't separate trusted commands from untrusted data in one token stream. Filtering + least-privilege reduce, don't eliminate. (carryover)
Help Net Security· TechTimes
Threat Intelligence
- Operation Endgame — Amadey + StealC infostealers disrupted— coordinated takedown seized 326 servers, froze $47Min crypto, recovered 27M credentialsfrom ~385,000 systems; >200 C2s dropped in a single action. Europol targets the cybercrime "assembly line," not single families.
The Hacker News· Infosecurity - Screening Serpens (Iran-nexus APT)(Unit 42) — AppDomainManager hijacking + new RAT variants targeting aerospace, defense manufacturing and telecom, expanded into Western Europe.
Unit 42 - ShinyHunters extortion wave— Kodak confirmed a breach (group claims 2.2M records); the same crew is linked to 100+ orgsvia the Oracle PeopleSoft 0day (CVE-2026-35273). Pattern: access + data theft + extortion, not encryption.
Malwarebytes· tech-insider
Chinese-Language Community Picks
- Apache Flink SQL injection RCE (CVE-2026-35194)— a SQL injection flaw in the code-generation engine reaches remote code execution, affecting distributed data-processing environments.
FreeBuf - Claude Code deep-link parsing RCE— Anthropic's Claude Code CLI carries a critical RCE; an attacker can execute arbitrary commands via a crafted deep link, and it can be weaponised.
FreeBuf weekly - Sysdig's first AI-driven attack / marimo CVE-2026-39987— an LLM agent generated instructions in real time and completed the intrusion in 22 minutes; see AI Security above.
FreeBuf
Ransomware Today
RansomLook's 24h window finally advanced: 6 new leak-site posts across 5 groups (latest discovered 2026-06-28T12:52). Watchlist hits: play → Kuhnline and play → J&J Gaming. Manually-flagged sensitive targets: redact → Hologic (medical diagnostics, US) and redact → FCCI Insurance Group (insurance, US); safepay → hellmold-plank.de (Germany). Quiet day after the prior week's backlog dump.
Full victim table
Bug Bounty
Bug Bounty has its own daily deep-dive (themed recent disclosures + one analysis per day).
Open the Bug Bounty daily section
AI Frontier
OpenAI
- Model arms race continues— June saw simultaneous moves from OpenAI, Anthropic, Google and xAI; OpenAI's IPO timing remains a watch item (Anthropic expected to list first; both filed confidentially). (carryover)
Anthropic
- Claude Mythos 1 shipped; Sonnet 4.8 rumored— Anthropic among the labs pushing new models this cycle.
- Colossus 1 compute deal— Anthropic secured all capacity at SpaceX/xAI's Colossus 1 (Tennessee): 300+ MW, 220,000+ Nvidia GPUs.
- Talent inflow— AlphaFold's John Jumperis leaving Google for Anthropic (after a break), part of a broader senior-researcher migration.
Google DeepMind / AI
- Gemini 3.5 Pro nearing release— promised "next month" at I/O; Flash already shipped; positioned for agentic/coding.
- Boston Dynamics × DeepMind— integrating Gemini Robotics-ER 1.6into the Spot robot dog and Orbit visual-inspection platform.
- Talent outflow— losing Shazeer (to OpenAI) and Jumper (to Anthropic) in the same window.
🛡 = security-relevant
Failed / Degraded Sources
- None this run — RansomLook API returned fresh data (advanced past the multi-day stall noted on 06-27/06-28).
- FreeBuf — mobile pages are JS-rendered; item titles captured via search, full bodies not fully scrapable.
Sources used: see intel/sources.yaml