← Carolina Clear Tech

Cyber Threat Brief

2026-06-10

Listen to this brief (30:41)

Download MP3
Show Notes

Show Notes - 2026-06-10

Stories Covered

CVEs Referenced

CVE-2025-15467, CVE-2025-40946, CVE-2025-8088, CVE-2026-11645, CVE-2026-20127, CVE-2026-20182, CVE-2026-20245, CVE-2026-2441, CVE-2026-26142, CVE-2026-32193, CVE-2026-3909, CVE-2026-3910, CVE-2026-41108, CVE-2026-41125, CVE-2026-42985, CVE-2026-42987, CVE-2026-44803, CVE-2026-44812, CVE-2026-44815, CVE-2026-44963, CVE-2026-45467, CVE-2026-45469, CVE-2026-45485, CVE-2026-45586, CVE-2026-45602, CVE-2026-45607, CVE-2026-45641, CVE-2026-45648, CVE-2026-45657, CVE-2026-47288, CVE-2026-47291, CVE-2026-47292, CVE-2026-47652, CVE-2026-48574, CVE-2026-49160, CVE-2026-50507, CVE-2026-50508, CVE-2026-50751, CVE-2026-5281, CVE-2026-7473

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief - June 10, 2026

Today: Microsoft patches 206 vulnerabilities in the largest Patch Tuesday on record, including three zero-days. Veeam releases emergency fix for critical backup server RCE. Cisco SD-WAN faces seventh actively exploited zero-day this year with no patch available. Chrome patches fifth exploited zero-day of 2026. Check Point VPN added to CISA KEV catalog with 3-day federal deadline.

Critical Alerts

Veeam Backup & Replication RCE (CVE-2026-44963)

Veeam patched a critical remote code execution flaw affecting domain-joined backup servers. Any domain user with low privileges can exploit CVE-2026-44963 to gain RCE on Veeam Backup & Replication 12.3.2.4465 and all earlier version 12 builds. The vulnerability only impacts installations joined to a Windows domain, a common but discouraged configuration. Ransomware gangs including Akira, Fog, and Frag have previously weaponized Veeam flaws. While no active exploitation is reported, Veeam warns attackers will reverse-engineer the patch immediately.

Cisco SD-WAN Zero-Day (CVE-2026-20245)

Cisco SD-WAN Manager has an actively exploited zero-day with no patch or workaround available. CVE-2026-20245 is a command injection flaw allowing authenticated or local attackers to execute commands as root. Exploitation requires valid credentials or privileged access, typically achieved by chaining with CVE-2026-20182 or CVE-2026-20127 (both previously disclosed Cisco zero-days). Mandiant discovered the flaw. Cisco observed limited cases where exploitation resulted in configuration changes pushed to edge devices. This is the seventh actively exploited zero-day affecting Cisco SD-WANs this year. CISA added CVE-2026-20245 to the KEV catalog with a June 23 deadline.

Check Point VPN RCE (CVE-2026-50751)

CISA ordered federal agencies to patch a critical Check Point Remote Access VPN and Mobile Access authentication bypass exploited by Qilin ransomware affiliates. CVE-2026-50751 allows unauthenticated remote attackers to bypass authentication and establish a VPN connection. CISA KEV due date is June 11 (3 days). EPSS score 0.177 (95th percentile) and ransomware-linked flag confirm active targeting.

Chrome V8 Zero-Day (CVE-2026-11645)

Google patched the fifth actively exploited Chrome zero-day of 2026. CVE-2026-11645 is an out-of-bounds memory access vulnerability in V8 (Chrome's JavaScript and WebAssembly engine) with a CVSS score of 8.8. A remote attacker can execute arbitrary code inside a sandbox via a crafted HTML page. Researcher 303f06e3 received a $55,000 bug bounty. Google confirmed exploit exists in the wild but provided no additional details. CISA added CVE-2026-11645 to the KEV catalog with a June 23 deadline.

Windows / AD Security

Microsoft June 2026 Patch Tuesday (206 Vulnerabilities)

Microsoft released 206 patches in the largest Patch Tuesday on record, including 32 critical vulnerabilities and three publicly disclosed zero-days. This exceeds the previous record of 175 CVEs set in October 2025. Microsoft VP Tom Gallagher warned last month that AI tools are accelerating vulnerability discovery and releases of this scale will become the norm. The current 2026 total already exceeds the entire 2018 total. Additionally, Microsoft patched 360 Chromium/Edge vulnerabilities this month, excluded from the official count.

Three zero-days fixed today (none actively exploited): - CVE-2026-45586: Privilege escalation in Windows Collaborative Translation Framework (CTFMON), allowing low-privilege local attackers to gain SYSTEM permissions. Publicly disclosed by Nightmare Eclipse as "GreenPlasma." CVSS 7.8, exploitation rated more likely. - CVE-2026-50507: BitLocker security feature bypass allowing unauthenticated attackers with physical access to view encrypted data on Windows 11 and Server 2022/2025. Publicly disclosed as "YellowKey." CVSS 6.8, proof-of-concept exists, exploitation rated more likely. - CVE-2026-49160: HTTP/2 denial of service vulnerability in HTTP.sys, exploiting HPACK compression to create a "compression bomb" that consumes excessive memory. Publicly disclosed as "HTTP/2 Bomb" by researchers at Calif. CVSS 7.5. Microsoft added a new "MaxHeadersCount" registry setting to limit header counts in HTTP/2 and HTTP/3 requests.

Critical vulnerabilities flagged as more likely to be exploited: - CVE-2026-47291: RCE in Windows HTTP.sys due to integer overflow and heap-based buffer overflow (CVSS 9.8). Unauthenticated remote attackers can send a specially crafted packet to trigger exploitation. Systems using the default MaxRequestBytes registry value of 16,384 bytes are not impacted. Pre-patch mitigation: set MaxRequestBytes to no higher than 65,534 bytes. - CVE-2026-42985: RCE in Remote Desktop Client due to heap-based buffer overflow (CVSS 8.1). Unauthorized attacker can execute code over a network. - CVE-2026-44803 and CVE-2026-44812: RCE in Windows Graphics component due to integer overflow in Win32K GRFX subsystem (both CVSS 7.8). Local exploitation. - CVE-2026-45657: RCE in Windows kernel due to use-after-free and heap-based buffer overflow (CVSS 9.8). Unauthenticated remote attackers can send specially crafted network traffic to trigger a flaw in TCP/IP processing, enabling SYSTEM-level code execution without authentication. - CVE-2026-44815: RCE in Windows DHCP Client service (CVSS 9.8). Unauthenticated remote attackers can achieve full compromise without user interaction, potentially wormable. Runs on virtually every Windows endpoint.

Additional critical vulnerabilities: - CVE-2026-45607, CVE-2026-45641, CVE-2026-47652: RCE in Windows Hyper-V due to out-of-bounds reads. Authenticated attacker on a guest VM can send specially crafted file operation requests to hardware resources, resulting in RCE on the host server. - CVE-2026-42987: RCE in Windows Deployment Services due to use-after-free (CVSS 8.1). - CVE-2026-48574: RCE in Windows Media due to heap-based buffer overflow. - CVE-2026-47288: RCE in Windows Kerberos KDC due to integer overflow. Authorized attacker can execute code over an adjacent network. - CVE-2026-26142: RCE in Nuance PowerScribe due to deserialization of untrusted data (CVSS 9.8). Nuance PowerScribe is a radiology reporting platform widely used in healthcare. Unauthenticated remote exploitation.

Other notable vulnerabilities: - CVE-2026-45648: Stack-based buffer overflow in Active Directory Domain Services. Requires authentication, Microsoft considers exploit development unlikely. - CVE-2026-50508: NTLM spoofing vulnerability allowing unauthorized attackers to perform spoofing over a network. - CVE-2026-45469: Excel RCE due to integer underflow. - CVE-2026-45467: SharePoint Server XSS spoofing vulnerability. - CVE-2026-47292: Visual Studio Code MSSQL Extension RCE allowing unauthorized attackers to elevate privileges locally. - CVE-2026-32193: Azure Kubernetes Service (AKS) RCE due to path traversal. Authorized attacker can execute code locally. - CVE-2026-41108: Windows DNS Client heap-based buffer overflow allowing privilege escalation. - CVE-2026-45485: Microsoft Office out-of-bounds read information disclosure. - CVE-2026-45602: Windows DHCP tampering vulnerability.

Known issues: BitLocker recovery prompts may trigger on some systems after installing updates. Affects devices with Group Policy explicitly including PCR7 in the TPM validation profile and certain Secure Boot/Windows Boot Manager configurations related to Windows UEFI CA 2023 certificate. Temporary workaround: remove the Group Policy setting and suspend/resume BitLocker to regenerate default PCR bindings.

Microsoft Defender RoguePlanet Zero-Day

Nightmare Eclipse released another Microsoft Defender zero-day hours after June Patch Tuesday. The "RoguePlanet" exploit is a race condition allowing attackers to spawn a command prompt with SYSTEM privileges on fully patched Windows 10 and Windows 11 (including systems with KB5094126 installed). ThreatLocker confirmed the exploit works against fully patched Windows 11. The researcher says RoguePlanet was originally a remote code execution vulnerability exploiting Defender's handling of files on remote SMB shares, but Microsoft silently hardened Defender in mid-May by patching "mpengine!SysIO*" API. The researcher rewrote it as a local privilege escalation. This is part of an ongoing dispute with Microsoft over vulnerability disclosure practices. Nightmare Eclipse has released multiple zero-days (BlueHammer, RedSun, GreenPlasma, YellowKey) and plans a "bone shattering" drop on July 14.

Microsoft Exchange Ghost-Sender Spoofing

InfoGuard disclosed a spoofing vulnerability in Microsoft Exchange configurations using Exchange Online or on-premises in hybrid mode with a third-party mail server or spam filter as the MX record. Attackers can send emails from any user (internal or external) to vulnerable organizations, bypassing SPF, DKIM, and DMARC policies. For internal senders, Outlook resolves the sender's profile picture. Attackers can send fake bills from official billing emails or conduct phishing using the CEO's actual email address. InfoGuard says fewer than half of organizations with external-facing MX records have mitigations applied. Microsoft deployed and rolled back a mitigation, and support confirmed active abuse. By default, Exchange Online accepts any incoming emails if an external MX record is used. No CVE assigned. Microsoft closed the initial report as a non-MSRC case.

Windows 10 KB5094127 Extended Security Update

Microsoft released Windows 10 KB5094127 extended security update fixing June 2026 Patch Tuesday vulnerabilities. The update includes new functionality to monitor the rollout of updated Secure Boot certificates replacing those expiring this month. Windows 10 will be updated to build 19045.7417, and Windows 10 Enterprise LTSC 2021 to build 19044.7417. The update enables dynamic status reporting for Secure Boot states in Windows Security App, adds LimitSecureBootRequiredServiceData policy setting, and includes high-confidence device targeting data for automatic Secure Boot certificate rollout. Known issue: BitLocker recovery prompts on devices with specific Group Policy and Secure Boot configurations.

Windows 11 KB5094126 & KB5093998 Updates

Microsoft released cumulative updates for Windows 11 25H2/24H2 (KB5094126) and 23H2 (KB5093998). Build numbers change to 26200.8457 (25H2), 26100.8457 (24H2), and 22631.7079 (23H2). New features include Shared Audio (Bluetooth LE Audio broadcast for two people to listen simultaneously), improved Magnifier with screen reader announcements and protected content support, Task Manager NPU usage visibility and AppContainer isolation column, Multi-App Camera and Basic Camera mode with Group Policy support, and custom user folder names during Windows Setup.

Microsoft AI Activity Investigation Playbook

Microsoft published an investigator playbook for reconstructing AI activity involving Microsoft 365 Copilot and Azure AI services. The playbook uses telemetry across Microsoft Purview, Defender, and Sentinel to investigate prompt injection attempts, unexpected data access, and anomalous usage patterns. The methodology follows a scope-context-signal sequence: identifying who interacted with AI systems, what resources were accessed, and evaluating detection signals. The playbook covers schema references, KQL queries, detection logic, and extends to agent-based systems. Available at https://aka.ms/AIIRplaybook.

Business & Infrastructure Threats

WinRAR Exploitation in Ukraine

Russia-aligned groups Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226) continue exploiting CVE-2025-8088, a WinRAR path traversal flaw patched in July 2025, to target Ukrainian organizations. The vulnerability allows attackers to write files outside the extraction directory via NTFS Alternate Data Streams. SHADOW-EARTH-066 uses crafted RAR archives with decoy PDFs and hidden ADS payloads to deliver GIFTEDCROOK information stealer. Payloads placed in the Startup folder execute automatically on login, launching a PowerShell loader that performs in-memory DLL loading. GIFTEDCROOK targets passwords and cookies from Chromium browsers and Firefox, plus documents. Exfiltration shifted from Telegram to dedicated C2 servers after Russia blocked Telegram in February. Earth Dahu uses HTA-to-VBScript infection chains delivering espionage modules including GammaPhish, GammaLoad, and GammaSteal. The vulnerability chain remained active through at least April 10, 2026. EPSS score 0.116 (94th percentile), CISA KEV due date was September 2, 2025.

GitHub/Microsoft Repository Compromise (Miasma/Shai-Hulud)

Microsoft temporarily removed 73 repositories across Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub on June 5 due to potential malicious content from a Miasma/Shai-Hulud supply chain campaign. The incident was contained in 105 seconds. The repositories were restored after review, though some remain offline. Microsoft notified a small number of customers who may have pulled down content. The compromise included the "durabletask" Python package (previously compromised in May) and Azure functions-action, causing workflow outages. The attack targeted AI coding tools (Claude Code, Gemini CLI, VS Code, Cursor). The worm initially struck @redhat-cloud-services npm namespace by compromising a Red Hat employee's GitHub account, pushing unreviewed orphan commits with workflows requesting GitHub's OIDC tokens, then pivoting to Microsoft resources.

New PyPI wave (23 packages) includes bioinformatics libraries, AI/MCP-themed packages, and typosquats (rsquests, tlask, rlask). The latest cluster uses new payload delivery mechanisms: trojanized native .abi3.so extensions executing on import, and .pth startup hook loaders searching sys.path for "_index.js" payload separately from the package. The malware targets developer workstations and CI/CD environments, harvesting secrets from GitHub, npm, PyPI, RubyGems, JFrog, CircleCI, Anthropic, AWS, GCP, Azure, Kubernetes, Docker, Vault, SSH keys, shell histories, .env files, Claude/MCP configurations, and local credentials. Exfiltration occurs to public GitHub repositories.

Hades PyPI Attack (37 Malicious Packages)

A new Miasma-related attack wave called Hades compromised 37 malicious wheel artifacts across 19 packages in PyPI. The compromised releases shipped *-setup.pth files that execute automatically during Python startup, download the Bun JavaScript runtime, and run an obfuscated JavaScript payload (_index.js). The stealer harvests secrets from GitHub, npm, PyPI, RubyGems, JFrog, CircleCI, Anthropic, AWS, GCP, Azure, Kubernetes, Docker, Vault, SSH keys, shell histories, .env files, .npmrc, .pypirc, Claude/MCP configurations, and other credentials. Exfiltration goes to public GitHub repositories with descriptions "Hades - The End for the Damned" and "Hades * The End for the Damned." The campaign includes a cluster targeting computational biology, bioinformatics, and genotype-phenotype analysis packages using obfuscated single-line import hooks in init.py files. The payload checks for Russian locale before executing.

Affected packages: bramin 0.0.2/0.0.3/0.0.4, cmd2func 0.2.2/0.2.3, coolbox 0.4.1/0.4.2, dynamo-release 1.5.4, executor-engine 0.3.4/0.3.5, executor-http 0.1.3/0.1.4, funcdesc 0.2.2/0.2.3, magique 0.6.8/0.6.9, magique-ai 0.4.4/0.4.5, mrbios 0.1.1/0.1.2, napari-ufish 0.0.2/0.0.3, nucbox 0.1.2/0.1.3, okite 0.0.7/0.0.8, pantheon-agents 0.6.1/0.6.2, pantheon-toolsets 0.5.5/0.5.6, spateo-release 1.1.2, synago 0.1.1/0.1.2, ufish 0.1.2/0.1.3, uprobe 0.1.3/0.1.4, plus bioinformatics cluster: embiggen 0.11.97, ensmallen 0.8.101, gpsea 0.9.14, mflux-streamlit 0.0.3/0.0.4, nhmpy 2.4.7, ppkt2synergy 0.1.1, pyphetools 0.9.120.

Patch Priority

Vulnerability Disclosures

CISA KEV Additions (June 9)

CISA added three vulnerabilities to the Known Exploited Vulnerabilities catalog: - CVE-2026-7473: Arista Extensible Operating System incomplete comparison vulnerability. EPSS 0.000 (9th percentile). Federal agencies must remediate by June 23. - CVE-2026-11645: Google Chromium V8 out-of-bounds read and write (Chrome zero-day). EPSS 0.001 (24th percentile). Federal agencies must remediate by June 23. - CVE-2026-20245: Cisco Catalyst SD-WAN Manager improper encoding or escaping of output (command injection). EPSS 0.001 (24th percentile). Federal agencies must remediate by June 23.

ICS Patch Tuesday

Siemens published four advisories covering authenticated command execution, information disclosure, privilege escalation, and password exposure in Sinec INS; DoS and potential code execution in Siprotec 5; sensitive information exposure in WinCC Certificate Manager; and CVE-2025-15467 (OpenSSL RCE, EPSS 0.029 87th percentile) in Scalance, Simatic, Sinamics, Sinec, and other products. Schneider Electric published three advisories covering DoS and command execution in PowerLogic P7, credential exposure in EasyLogic T150 and Saitel DP RTU/Controller, and information disclosure in EcoStruxure IT Data Center Expert. Phoenix Contact disclosed unauthenticated log download vulnerability in CHARX SEC-3xxx charging controller firmware. CISA published two Siemens KACO Blueplanet Inverters advisories: CVE-2025-40946 (CRC16-based Technical Service credential derivation from serial number) and CVE-2026-41125 (SQL injection in KACO Meteor server). Both EPSS 0.000 (7th percentile). Fixes available for some models, no fix planned for others.

Trends & Context

AI-accelerated vulnerability discovery is the new normal. Microsoft's 206 CVEs exceed the entire 2018 total, and researchers say 100+ CVE Patch Tuesdays are now baseline. Attackers are weaponizing supply chain access at scale, with Miasma/Shai-Hulud/Hades campaigns targeting developer workstations and CI/CD pipelines through PyPI, npm, and GitHub. Russia-aligned groups exploit year-old WinRAR flaws against Ukraine. Cisco faces its seventh SD-WAN zero-day this year with no end in sight.