Rosetta Daily · Jul 2, 2026
Generated automatically · ~22 sources scanned · 19 items selected
Critical Vulnerabilities
-
Progress Kemp LoadMaster — unauthenticated command injection — Progress, CVE-2026-8037, CVSS 9.8 🔴
A crafted request to the appliance's management API lets an unauthenticated attacker execute arbitrary commands as root. LoadMaster sits at the network edge as a load balancer/ADC — treat any exposed management interface as compromised until patched. Apply the fixed release and restrict API access to trusted management networks.
The Hacker News -
Citrix NetScaler ADC / Gateway — multiple flaws — Citrix, CVE-2026-8451 / CVE-2026-8452 / CVE-2026-8655, CVSS 8.8 🔴
Citrix shipped fixes for arbitrary file read and denial-of-service issues in NetScaler ADC and Gateway. NetScaler has a long track record as a mass-exploitation target (CitrixBleed lineage) — patch on an emergency cadence and hunt for pre-patch access.
The Hacker News -
SimpleHelp OIDC bypass now delivers Djinn Stealer / TaskWeaver — SimpleHelp RMM, CVE-2026-48558, CVSS 10.0, KEV-listed 🔴 🔥 ⚠️
New detail on the RMM auth-bypass: attackers use the forged technician session to run TaskWeaver, an obfuscated Node.js loader, which drops Djinn Stealer — a previously undocumented cross-platform (Windows/macOS/Linux) infostealer that harvests cloud, source-control, package-registry, infrastructure, and AI coding-assistant credentials, plus SSH keys and crypto wallets. CISA KEV federal remediation deadline is today, 2026-07-02 — patch to 5.5.16 / 6.0 RC2 or pull the console offline now.
BleepingComputer · Help Net Security
In-the-Wild Exploitation (CISA KEV)
- SimpleHelp OIDC auth bypass (CVE-2026-48558)— actively exploited to deploy Djinn Stealer; KEV deadline 2026-07-02.
CISA KEV - Ubiquiti UniFi OS (CVE-2026-34908 / -34909 / -34910)— access-control, path-traversal and input-validation flaws added to KEV on 2026-06-23; patch UniFi OS consoles exposed to the internet. (carryover)
CISA KEV
Vendor Advisories
- Microsoft — quantum-safe roadmap accelerated— Microsoft says advances in quantum computing are pulling forward the need to replace today's encryption; it is speeding its post-quantum cryptography migration. Begin crypto-agility inventory and PQC pilot planning now rather than treating it as a 2030s problem.
BleepingComputer - Kali Linux 2026.2 released— second release of the year: 9 new tools and numerous Kali NetHunter improvements. Update offensive-tooling images.
BleepingComputer
Web Security Research
- ClickFix grows an API-driven "back office"— the paste-and-run social-engineering technique now uses API-backed servers that hand each visitor a different disguise of the same malware. Researcher Bert-Jan Pals analyzed ~3,000 live payloads; expect polymorphic delivery that defeats naive IOC blocking. Detect on behaviour (clipboard→run→LOLBin), not on static hashes.
The Hacker News - PortSwigger 2026 direction — LLM-assisted web hacking— James Kettle's Black Hat USA preview points to LLMs/agents reshaping black-box research, alongside 2025's carryover reading list (HTTP desync via malformed chunks, new SAML bypasses, three web-timing techniques, CSS/HTML-only email compromise).
PortSwigger Research
AI Security
- Djinn Stealer explicitly targets AI developer credentials— the new stealer (see Critical Vulns) specifically loots AI coding-assistantand cloud/API keys, confirming AI toolchains are now a first-class credential-theft target. Rotate any keys reachable from developer endpoints; scope AI-assistant tokens tightly.
Dark Reading - Prompt injection remains OWASP LLM #1— 2026 reporting reiterates it as the fastest-growing attack class (reported +340% YoY); Unit 42 documented the first large-scale indirectinjection in the wild (ad-review evasion, system-prompt leakage on live platforms) earlier this year. Architectural mitigation, not a patch. (carryover)
Securance
Threat Intelligence
- Aflac Japan breach — 4.38M customers— an unauthorized third party accessed Aflac Japan systems between 2026-06-15 and 06-25; stolen data includes names, DOB, phone numbers, policy details and ~230,000 bank-account numbers. US Aflac systems unaffected. A reminder that subsidiary/regional environments remain a soft entry to large enterprises.
BleepingComputer· SecurityWeek - Signal Backup Recovery Key phishing (FBI/CISA)— a Russia-linked phishing campaign against Signal users has evolved to steal Signal Backup Recovery Keys, granting attackers access to victims' historical messages. Warn high-risk users; never enter recovery keys into web prompts.
BleepingComputer - Chinese APT breaching REDCap medical-research servers— state-sponsored actors are exfiltrating clinical-trial and patient datafrom Research Electronic Data Capture (REDCap) servers at medical institutions; a Windows port of the SprySOCKSbackdoor was also seen against government targets. Audit exposed REDCap instances and research data stores.
NJCCIC - FIFA World Cup 2026 sponsor spoofing risk— more than a third of official FIFA World Cup 2026 partners lack sufficient DMARC enforcement, leaving their domains open to email spoofing during a high-interest event. Verify DMARC/DKIM/SPF on partner and vendor domains.
The Hacker News
Chinese Community Picks
- FreeBuf / 安全客 / 先知— recent community coverage centers on WAF upload-bypasstechniques, BitLocker downgrade attacks, and the GhostLockfile-lock PoC; feeds are JS-rendered so items are surfaced via search rather than full-text scrape.
FreeBuf
Ransomware Today
RansomLook's 24h API is still returning an empty payload (sandbox network blocked; 4th consecutive day of no fresh API data) — figures below are cross-checked from ransomware.live open reporting. ~5+ fresh victims posted for 2026-06-30, most active groups: The Gentlemen (Pou Sheng International — Nike/adidas/PUMA distributor; SDEZ, France), Brain Cipher (PAI Pharma), Anubis (ESMS Global, UK). ⭐ Watchlist hit: Horizon Eye Care (healthcare, US). Also notable: Blackfield demanding $2M from Nidec (manufacturing, Japan).
Full victim table
Bug Bounty
Bug Bounty has its own daily deep-dive (themed recent disclosures + one analysis per day).
Open the Bug Bounty daily section
AI Frontier
OpenAI
- GPT-5.6 Preview System Card(6/26) and a preview of GPT-5.6 "Sol", a next-generation model.
- OpenAI × Broadcomunveiled an LLM-optimized inference chip(6/25); OpenAI also published research on "core dump epidemiology: fixing an 18-year-old bug" (6/30).
Anthropic
- Claude Sonnet 5— most agentic Sonnet yet (stronger reasoning, tool use, coding), available across plans, Claude Code and the Claude Platform with higher rate limits.
- Seoul office + Korean AI partnerships(6/17); statement on the US directive to suspend access to Fable 5 / Mythos 5(6/12).
Google DeepMind / AI
- Gemini 3.5 Flash— frontier agentic/coding performance, beats 3.1 Pro on key benchmarks at often <½ the cost; Ultra subscription cut $250 → $200/mo, new $100/mo Developer tier.
- Managed Agents in the Gemini API(public preview) — build stateful autonomous agents in isolated Google-hosted Linux sandboxes.
🛡 = security-relevant
Failed / Degraded Sources
- RansomLook API—
days=1window returned an empty body from the sandbox for a 4th day; ransomware figures assembled from ransomware.live open reporting. - FreeBuf / 安全客 / 先知— Chinese feeds are JS-rendered; titles captured via search, full bodies not fully scrapable.
- Several feeds not fetched directly (provenance/sandbox limits) — assembled via WebSearch per category; feed-level timestamps are approximate.
Sources used: see intel/sources.yaml