Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Daily Brief2026-07-01
Daily Brief·2026-07-01·20 Items

Rosetta Daily · Jul 1, 2026

Generated automatically · ~22 sources scanned · 20 items selected

Critical Vulnerabilities

  • SimpleHelp — OIDC authentication bypass — SimpleHelp RMM, KEV-listed 🔴 🔥 ⚠️
    When OIDC auth is configured, identity tokens submitted at login are accepted without verifying their cryptographic signature — a remote, unauthenticated attacker can forge a token and obtain a fully authenticated technician session. RMM software is a high-value ransomware foothold. In CISA KEV with a federal remediation deadline of 2026-07-02 — patch now or pull the console off the internet.
    CISA KEV

  • Splunk Enterprise — missing authentication for critical function — Splunk, KEV-listed 🔴 🔥
    An unauthenticated user can create or truncate arbitrary files through a PostgreSQL sidecar service endpoint, enabling tampering and potential follow-on code execution. Added to CISA KEV; patch affected Splunk Enterprise deployments and restrict the sidecar endpoint.
    CISA KEV

  • Oracle PeopleSoft PeopleTools — missing authentication — Oracle, KEV-listed 🔴 🔥
    Missing authentication for a critical function lets an unauthenticated attacker reach full takeover of PeopleSoft Enterprise PeopleTools. Added to CISA KEV; PeopleSoft remains a recurring extortion target (see ShinyHunters/CVE-2026-35273 wave). Apply Oracle CPU fixes and audit for unauthorized access.
    CISA KEV

  • libssh2 — client-side memory corruption — libssh2, CVE-2026-55200 ⚠️
    A public PoC is now available: a malicious or compromised SSH server can trigger memory corruption on a connecting client, with possible code execution. libssh2 is embedded in curl, Git, PHP, backup agents, firmware updaters and a long tail of appliances — patch the library and rebuild dependents; treat outbound SSH from sensitive hosts as risky.
    The Hacker News

  • Linux kernel "DirtyClone" — local privilege escalation — Linux, CVE-2026-43503 🔴
    Local users can gain root via cloned packets; the exploit works on Debian, Ubuntu and Fedora with default namespace configurations. Prioritize kernel updates on multi-user and container hosts where local code execution is plausible.
    BleepingComputer

In-the-Wild Exploitation (CISA KEV)

  • SimpleHelp OIDC auth bypass— KEV remediation deadline 2026-07-02; forged-token → technician session on an RMM console.
    CISA KEV
  • Splunk Enterprise missing-auth file write— unauthenticated file create/truncate via PostgreSQL sidecar; patch now.
    CISA KEV
  • Oracle PeopleSoft PeopleTools missing-auth takeover— unauthenticated full takeover; PeopleSoft remains under active extortion pressure.
    CISA KEV

Vendor Advisories

  • Microsoft— June Patch Tuesday recap still stands: ~198–208 CVEs, ~39 Critical, multiple 0-days (incl. Windows Kernel CVE-2026-45657and HTTP.sys CVE-2026-47291, both CVSS 9.8 unauth RCE). Largest single Patch Tuesday on record. (carryover)
    ZDI· CIS
  • Google / Android— CVE-2026-0073in the adbddaemon lets a nearby attacker obtain a full remote shell with no user interaction; ensure devices are on the latest Android security patch level.
    Android Security Bulletin
  • CISA ICS— advisory covering three vulnerabilities in Daktronics controllers; review exposure of display/OT controllers and apply vendor mitigations.
    CISA Advisories

Web Security Research

  • PortSwigger Top 10 Web Hacking Techniques of 2025— community-ranked: malformed-chunk HTTP desync, browser-redirect stalling for exploit chaining, novel SAMLauth bypasses, three new web-timingtechniques, and CSS/HTML-only email-account compromise. Core reading list for AppSec teams. (reference)
    PortSwigger Research
  • "GhostLock" PoC— abuses the legitimate Windows CreateFileWAPI and its share-mode parameter to lock filesso other users/apps (local or over SMB) can't open them — an anti-forensics / denial primitive rather than an RCE. Useful detection-engineering case study.
    FreeBuf

AI Security

  • LiteLLM backdoored package— the compromised LiteLLMgateway underpins CrewAI, DSPy, Microsoft GraphRAGand dozens of agent frameworks; a backdoored build delivering an attack bot was downloaded ~47,000 times. Pin and verify LLM-gateway dependencies; treat the agent supply chain as a first-class attack surface.
    Help Net Security
  • Prompt injection still OWASP's #1 LLM risk— 2026 reporting puts it in a large share of production deployments with a reported +340% YoY. Architectural, not a patchable bug: system prompt, user input, retrieved docs and tool output share one context window. Least-privilege + I/O isolation reduce, don't eliminate. (carryover)
    Help Net Security· Kunal Ganglani
  • Indirect injection in agentic LLMs— fresh academic work shows tool-using agents are highly susceptible to indirectinjection via retrieved content/tool output ("forward all conversations to attacker@…"-style tool redirection). Scope tool permissions and treat all tool I/O as untrusted.
    arXiv 2604.03870

Threat Intelligence

  • "The Gentlemen" RaaS surges— now the second most activegroup by public claims (182 distinct victims), and actively building a suite of EDR killers around a framework dubbed GentleKiller. Validate EDR tamper-protection and monitor for driver-based defense evasion.
    The Hacker News· BleepingComputer
  • Mandiant M-Trends 2026— grounded in 500,000+ hoursof frontline IR; the throughline is that the vast majority of intrusions still stem from fundamental human and systemic failures, not AI. Fundamentals (identity, patching, exposure) still decide outcomes.
    Google Cloud / Mandiant
  • Screening Serpens (Iran-nexus APT)(Unit 42) — AppDomainManager hijacking + new RAT variants against tech/defense and aerospace; continued 2026 espionage activity. (carryover)
    Unit 42

Chinese-Language Community Picks

  • GhostLock PoC— a proof of concept published by researcher Kim Dvash showing how to abuse the CreateFileWshare-mode parameter to stop a file from being opened by other users or programs.
    FreeBuf
  • Pwn2Own Berlin 2026 selling out triggers "retaliatory disclosure"— the world's best-known hacking contest hit capacity for the first time in its 19-year history, and dozens of rejected researchers launched a so-called "retaliatory disclosure" campaign, publishing their findings themselves.
    FreeBuf
  • Android adbd CVE-2026-0073— disclosed in the May Android Security Bulletin; a proximate attacker gains full shell access with no interaction required.
    Android Security Bulletin
  • Anthropic Project Glasswing expands— roughly 150 additional organisations gain Claude Mythos preview access; the project says it has already helped early partners find over 10,000 high-severity vulnerabilities.
    Anthropic News

Ransomware Today

RansomLook's 24h API is still stalled — same 6 posts / 5 groups as 06-28→06-30, latest discovered frozen at 2026-06-28T12:52Z (3rd consecutive day; treat as no fresh feed data). Watchlist hits unchanged: play → Kuhnline, play → J&J Gaming. Manually-flagged sensitive carryovers: redact → Hologic (medical, US), redact → FCCI Insurance Group (insurance, US). Notable from open reporting today: The Gentlemen climbing to #2 by victim count, and Qilin → KUNERT Fashion.
Full victim table

Bug Bounty

Bug Bounty has its own daily deep-dive (themed recent disclosures + one analysis per day).
Open the Bug Bounty daily section


AI Frontier

OpenAI

  • GPT-5.6 (Sol / Terra / Luna)— three variants released as a limited previewto companies, tied to a U.S. government engagement; positioned above the GPT-5.5 line.
  • GPT-5.5 Instant— latest low-latency tier in general circulation; release cadence across labs is now ~one new model every ~2 days.

Anthropic

  • Claude Fable 5(shipped 6/9) — public model in the "Mythos" family; strong on software engineering, knowledge work and visual benchmarks; 1M-token context.
  • Project Glasswing expanded— ~150 more orgsgranted Claude Mythos preview access for cyber-defense; the program reports helping early partners find 10,000+ high-severity vulnerabilities.

Google DeepMind / AI

  • Gemini 3.5 Pro— promised "next month" at I/O 2026 and now imminent; 3.5 Flashalready GA (default in the Gemini app and AI Mode in Search). Positioned for agentic/coding work.
  • Coding-model push— Microsoft and Google moving directly against Anthropic and OpenAI on coding-focused models.

🛡 = security-relevant


Failed / Degraded Sources

  • RansomLook API— days=1window frozen at 2026-06-28T12:52Z for a third day (identical payload); no fresh ransomware posts via the API.
  • FreeBuf / 安全客 / 先知— Chinese feeds are JS-rendered; titles captured via search, full bodies not fully scrapable.
  • Several feeds not fetched directly (provenance/sandbox limits) — assembled via WebSearch per category; feed-level timestamps are approximate.

Sources used: see intel/sources.yaml

← Prev
Rosetta Daily · Jun 30, 2026
Next →
Rosetta Daily · Jul 2, 2026