Rosetta Daily · Jul 1, 2026
Generated automatically · ~22 sources scanned · 20 items selected
Critical Vulnerabilities
-
SimpleHelp — OIDC authentication bypass — SimpleHelp RMM, KEV-listed 🔴 🔥 ⚠️
When OIDC auth is configured, identity tokens submitted at login are accepted without verifying their cryptographic signature — a remote, unauthenticated attacker can forge a token and obtain a fully authenticated technician session. RMM software is a high-value ransomware foothold. In CISA KEV with a federal remediation deadline of 2026-07-02 — patch now or pull the console off the internet.
CISA KEV -
Splunk Enterprise — missing authentication for critical function — Splunk, KEV-listed 🔴 🔥
An unauthenticated user can create or truncate arbitrary files through a PostgreSQL sidecar service endpoint, enabling tampering and potential follow-on code execution. Added to CISA KEV; patch affected Splunk Enterprise deployments and restrict the sidecar endpoint.
CISA KEV -
Oracle PeopleSoft PeopleTools — missing authentication — Oracle, KEV-listed 🔴 🔥
Missing authentication for a critical function lets an unauthenticated attacker reach full takeover of PeopleSoft Enterprise PeopleTools. Added to CISA KEV; PeopleSoft remains a recurring extortion target (see ShinyHunters/CVE-2026-35273 wave). Apply Oracle CPU fixes and audit for unauthorized access.
CISA KEV -
libssh2 — client-side memory corruption — libssh2, CVE-2026-55200 ⚠️
A public PoC is now available: a malicious or compromised SSH server can trigger memory corruption on a connecting client, with possible code execution. libssh2 is embedded in curl, Git, PHP, backup agents, firmware updaters and a long tail of appliances — patch the library and rebuild dependents; treat outbound SSH from sensitive hosts as risky.
The Hacker News -
Linux kernel "DirtyClone" — local privilege escalation — Linux, CVE-2026-43503 🔴
Local users can gain root via cloned packets; the exploit works on Debian, Ubuntu and Fedora with default namespace configurations. Prioritize kernel updates on multi-user and container hosts where local code execution is plausible.
BleepingComputer
In-the-Wild Exploitation (CISA KEV)
- SimpleHelp OIDC auth bypass— KEV remediation deadline 2026-07-02; forged-token → technician session on an RMM console.
CISA KEV - Splunk Enterprise missing-auth file write— unauthenticated file create/truncate via PostgreSQL sidecar; patch now.
CISA KEV - Oracle PeopleSoft PeopleTools missing-auth takeover— unauthenticated full takeover; PeopleSoft remains under active extortion pressure.
CISA KEV
Vendor Advisories
- Microsoft— June Patch Tuesday recap still stands: ~198–208 CVEs, ~39 Critical, multiple 0-days (incl. Windows Kernel CVE-2026-45657and HTTP.sys CVE-2026-47291, both CVSS 9.8 unauth RCE). Largest single Patch Tuesday on record. (carryover)
ZDI· CIS - Google / Android— CVE-2026-0073in the
adbddaemon lets a nearby attacker obtain a full remote shell with no user interaction; ensure devices are on the latest Android security patch level.
Android Security Bulletin - CISA ICS— advisory covering three vulnerabilities in Daktronics controllers; review exposure of display/OT controllers and apply vendor mitigations.
CISA Advisories
Web Security Research
- PortSwigger Top 10 Web Hacking Techniques of 2025— community-ranked: malformed-chunk HTTP desync, browser-redirect stalling for exploit chaining, novel SAMLauth bypasses, three new web-timingtechniques, and CSS/HTML-only email-account compromise. Core reading list for AppSec teams. (reference)
PortSwigger Research - "GhostLock" PoC— abuses the legitimate Windows
CreateFileWAPI and its share-mode parameter to lock filesso other users/apps (local or over SMB) can't open them — an anti-forensics / denial primitive rather than an RCE. Useful detection-engineering case study.
FreeBuf
AI Security
- LiteLLM backdoored package— the compromised
LiteLLMgateway underpins CrewAI, DSPy, Microsoft GraphRAGand dozens of agent frameworks; a backdoored build delivering an attack bot was downloaded ~47,000 times. Pin and verify LLM-gateway dependencies; treat the agent supply chain as a first-class attack surface.
Help Net Security - Prompt injection still OWASP's #1 LLM risk— 2026 reporting puts it in a large share of production deployments with a reported +340% YoY. Architectural, not a patchable bug: system prompt, user input, retrieved docs and tool output share one context window. Least-privilege + I/O isolation reduce, don't eliminate. (carryover)
Help Net Security· Kunal Ganglani - Indirect injection in agentic LLMs— fresh academic work shows tool-using agents are highly susceptible to indirectinjection via retrieved content/tool output ("forward all conversations to attacker@…"-style tool redirection). Scope tool permissions and treat all tool I/O as untrusted.
arXiv 2604.03870
Threat Intelligence
- "The Gentlemen" RaaS surges— now the second most activegroup by public claims (182 distinct victims), and actively building a suite of EDR killers around a framework dubbed GentleKiller. Validate EDR tamper-protection and monitor for driver-based defense evasion.
The Hacker News· BleepingComputer - Mandiant M-Trends 2026— grounded in 500,000+ hoursof frontline IR; the throughline is that the vast majority of intrusions still stem from fundamental human and systemic failures, not AI. Fundamentals (identity, patching, exposure) still decide outcomes.
Google Cloud / Mandiant - Screening Serpens (Iran-nexus APT)(Unit 42) — AppDomainManager hijacking + new RAT variants against tech/defense and aerospace; continued 2026 espionage activity. (carryover)
Unit 42
Chinese-Language Community Picks
- GhostLock PoC— a proof of concept published by researcher Kim Dvash showing how to abuse the
CreateFileWshare-mode parameter to stop a file from being opened by other users or programs.
FreeBuf - Pwn2Own Berlin 2026 selling out triggers "retaliatory disclosure"— the world's best-known hacking contest hit capacity for the first time in its 19-year history, and dozens of rejected researchers launched a so-called "retaliatory disclosure" campaign, publishing their findings themselves.
FreeBuf - Android adbd CVE-2026-0073— disclosed in the May Android Security Bulletin; a proximate attacker gains full shell access with no interaction required.
Android Security Bulletin - Anthropic Project Glasswing expands— roughly 150 additional organisations gain Claude Mythos preview access; the project says it has already helped early partners find over 10,000 high-severity vulnerabilities.
Anthropic News
Ransomware Today
RansomLook's 24h API is still stalled — same 6 posts / 5 groups as 06-28→06-30, latest discovered frozen at 2026-06-28T12:52Z (3rd consecutive day; treat as no fresh feed data). Watchlist hits unchanged: play → Kuhnline, play → J&J Gaming. Manually-flagged sensitive carryovers: redact → Hologic (medical, US), redact → FCCI Insurance Group (insurance, US). Notable from open reporting today: The Gentlemen climbing to #2 by victim count, and Qilin → KUNERT Fashion.
Full victim table
Bug Bounty
Bug Bounty has its own daily deep-dive (themed recent disclosures + one analysis per day).
Open the Bug Bounty daily section
AI Frontier
OpenAI
- GPT-5.6 (Sol / Terra / Luna)— three variants released as a limited previewto companies, tied to a U.S. government engagement; positioned above the GPT-5.5 line.
- GPT-5.5 Instant— latest low-latency tier in general circulation; release cadence across labs is now ~one new model every ~2 days.
Anthropic
- Claude Fable 5(shipped 6/9) — public model in the "Mythos" family; strong on software engineering, knowledge work and visual benchmarks; 1M-token context.
- Project Glasswing expanded— ~150 more orgsgranted Claude Mythos preview access for cyber-defense; the program reports helping early partners find 10,000+ high-severity vulnerabilities.
Google DeepMind / AI
- Gemini 3.5 Pro— promised "next month" at I/O 2026 and now imminent; 3.5 Flashalready GA (default in the Gemini app and AI Mode in Search). Positioned for agentic/coding work.
- Coding-model push— Microsoft and Google moving directly against Anthropic and OpenAI on coding-focused models.
🛡 = security-relevant
Failed / Degraded Sources
- RansomLook API—
days=1window frozen at 2026-06-28T12:52Z for a third day (identical payload); no fresh ransomware posts via the API. - FreeBuf / 安全客 / 先知— Chinese feeds are JS-rendered; titles captured via search, full bodies not fully scrapable.
- Several feeds not fetched directly (provenance/sandbox limits) — assembled via WebSearch per category; feed-level timestamps are approximate.
Sources used: see intel/sources.yaml