CVE-2025-67644, CVE-2026-10520, CVE-2026-10557, CVE-2026-27022, CVE-2026-28277, CVE-2026-28742, CVE-2026-35273, CVE-2026-42947, CVE-2026-45585, CVE-2026-50005, CVE-2026-50101, CVE-2026-50108, CVE-2026-50245, CVE-2026-5027, CVE-2026-7368
IP Addresses:
176.120.22.24, 3.2.3.5
Get tomorrow's brief in your inbox
June 12, 2026
Today: CISA gives federal agencies until Sunday to patch an Ivanti Sentry vulnerability already exploited in the wild. ShinyHunters abused an Oracle PeopleSoft zero-day to breach over 100 organizations in higher education, primarily targeting U.S. universities. Europol dismantled AudiA6, a crypto laundering service that washed $389 million for ransomware gangs. The Gentlemen ransomware operation claims 478 victims since March 2025 and has worm-like spreading capabilities.
CISA Orders Ivanti Sentry Patching by June 14 (CVE-2026-10520)
CISA added the Ivanti Sentry command injection flaw to its Known Exploited Vulnerabilities catalog Thursday and ordered federal agencies to patch within three days under new Binding Operational Directive 26-04. The vulnerability, rated 10.0 CVSS, allows unauthenticated remote code execution with root privileges. Ivanti released patches Tuesday claiming no evidence of exploitation, but Shadowserver reported backdoored systems within 24 hours. Attackers are now using a public proof-of-concept to compromise exposed instances. CISA's enrichment data shows low EPSS score (0.033, 87th percentile), but active exploitation makes this high priority. About 50 Sentry admin portals remain exposed online. Shadowserver warns that any unpat ched system is likely compromised. The vulnerability affects Ivanti Sentry (formerly MobileIron Sentry) versions prior to R10.5.2, R10.6.2, and R10.7.1.
ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273)
ShinyHunters exploited an Oracle PeopleSoft zero-day between May 27 and June 9 to breach over 100 organizations, primarily targeting U.S. higher education institutions. Oracle published an advisory June 10, so the entire exploitation window was zero-day. The flaw, CVE-2026-35273, is a 9.8 CVSS remote code execution bug in PeopleSoft Enterprise PeopleTools 8.61 and 8.62. It requires no authentication and no user interaction, just network access over HTTP to the Environment Management Hub. Mandiant notified over 100 at-risk organizations; 68% were in higher education. The University of Nottingham confirmed a breach affecting 455,000 email addresses with names, addresses, phone numbers, passport numbers, ethnicity, and disability details. Attackers left staging infrastructure exposed, revealing custom MeshCentral agents disguised as Azure binaries, lateral movement scripts, and command histories showing data compressed with zstd and exfiltrated via SSH. ShinyHunters claims 300 PeopleSoft instances across 100 organizations compromised.
/PSEMHUB/* and /PSIGW/HttpListeningConnector at the perimeter. Hunt for signs of compromise: WebLogic access logs with external POST requests to /PSEMHUB/hub, unexpected .jsp files under PSEMHUB.war directories, recently changed .xml files under envmetadata/data/environment, outbound connections to azurenetfiles.net, SSH connections to 176.120.22.24, and README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT marker files in PeopleSoft directories. Mandiant warns WAF body-inspection rules are not enough since they can be bypassed. This matters because PeopleSoft is an ERP platform managing HR, payroll, finance, supply chain, and campus operations for large organizations.4 new claims tracked from direwolf group in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| direwolf | Jewelex | Retail | Unknown |
| direwolf | Clínica Vida | Healthcare | Unknown |
| direwolf | Did Asia | Unknown | Asia |
| direwolf | Nueva Pescanova Group | Food/Seafood | Spain |
The Gentlemen Ransomware Claims 478 Victims Since March 2025
The Gentlemen ransomware operation has claimed 478 victims since launching in March 2025, according to Ransomware.Live. PRODAFT analysis reveals the group initially operated as an affiliate for LockBit, Qilin, and Medusa before launching its own independent partnership program in July 2025. The group is led by a Russian-speaking actor identified as Alexander Andreevich Yapaev from Izhevsk, Russia, who uses aliases hastalamuerte, ArmCorp, zeta88, nobody0, and santamuerte. The operation relies heavily on AI for ransomware development, tool maintenance, and post-exploitation procedures. The ransomware has worm-like spreading capabilities and can propagate across networks using GPO manipulation, privileged account compromise, and custom EDR bypass methods. Only 13% of victims are U.S.-based; most are in Thailand, U.K., Brazil, Germany, and India. The group accounted for 10% of ransomware activity in April 2026. The operation split from Qilin after a payment dispute where Qilin allegedly defrauded them of $48,000. The group uses The Gentlemen IM app for affiliate support, provides EDR killers to bypass security, and follows an enterprise-focused attack chain beginning with vulnerable internet-facing services or stolen credentials.
Europol Dismantles AudiA6 Crypto Laundering Service
Europol disrupted AudiA6, a cryptocurrency laundering service that processed over $389 million (€336 million) for ransomware gangs and cybercriminals since 2021. The operation arrested two administrators in Georgia, a Ukrainian and Russian national identified as Ruslan Igorevich Tkachuk (37) and Alexander Vladimirovich Ledenev (25). Authorities seized 25 domains, 30+ servers, 80 vehicles, multiple properties, and froze €692,000 in cryptocurrency. The service laundered approximately 10,333 bitcoin, with 393.39 BTC (worth $19.2 million) received directly from darknet markets, ransomware organizations, and cybercrime services. AudiA6 operated using thousands of fraudulent exchange accounts opened with stolen or purchased identities, many connected to Russian-speaking intermediaries. The operators also ran the Dark2Web underground forum where cybercriminals advertised illicit services. Authorities retrieved 6,000 KYC records linked to money mule accounts. The service charged 3-10% commission and guaranteed cleaned funds within an hour through complex transaction chains designed to conceal origins. AudiA6 is linked to more than 15 international ransomware investigations. Both arrested individuals face up to 20 years in prison. The U.S. DOJ filed charges for conspiracy to launder monetary instruments and sting money laundering.
AI-Driven Threats Exposing Limits of MSP Security Stacks
Gartner predicts AI agents will cut the time to exploit account exposures by 50% by 2027. Verizon's 2026 Data Breach Investigations Report found threat actors are deploying generative AI across reconnaissance, initial access, and malware development. MSPs running fragmented security stacks struggle to respond at the speed AI-powered attacks require. Alert fires in EDR, backup status requires separate login, patching data lives in RMM, and remediation steps must be manually validated across platforms. Every minute spent switching between tools gives attackers time to escalate privileges and move laterally. The operational cost inflates technician workloads, slows incident response, and makes it harder to scale cybersecurity services without adding headcount and tools. Modern endpoint security depends on three capabilities: speed of detection, coordinated response, and fast recovery. Most MSP tools use lightweight integrations where data syncs but response workflows remain disconnected, making real-time threat correlation difficult. When ransomware activity is detected, a deeply integrated environment can isolate the device, alert technicians, verify backup integrity, trigger remediation, and surface recovery progress from a single interface. Automation closes response gaps by continuously patching vulnerabilities, enforcing security policies, detecting anomalies earlier, and triggering remediation without waiting for manual intervention.
Hackers Exploit Langflow Vulnerability for Remote Code Execution (CVE-2026-5027)
Threat actors are exploiting CVE-2026-5027, a high-severity path traversal flaw in Langflow, a popular low-code AI development platform. The vulnerability, rated 8.8 CVSS, allows unauthenticated remote code execution because Langflow enables unauthenticated auto-login by default. Attackers send a single unauthenticated request to obtain a valid session token, then exploit the path traversal to write files to arbitrary locations on the filesystem. The vulnerable endpoint is POST /api/v2/files, which does not sanitize the filename parameter from multipart form data. VulnCheck observed in-the-wild exploitation successfully dropping test files on victim systems. Approximately 7,000 Langflow instances are accessible from the internet, most in North America. EPSS score is 0.041 (89th percentile). Tenable disclosed the vulnerability publicly on March 27 after failed disclosure attempts. This is part of a growing trend of attackers targeting the infrastructure and tooling organizations use to build and deploy AI applications.
/api/v2/files endpoint, and hunt for unexpected files written via path traversal sequences. This matters because AI development platforms often have privileged access to production systems, credentials, and sensitive data.LangGraph Flaw Chain Exposes Self-Hosted AI Agents to RCE
Check Point disclosed three patched vulnerabilities in LangGraph that can be chained to achieve remote code execution on self-hosted AI agent deployments. CVE-2025-67644 (CVSS 7.3) is a SQL injection in LangGraph's SQLite checkpoint implementation allowing manipulation of SQL queries through metadata filter keys. CVE-2026-28277 (CVSS 6.8) is an unsafe msgpack deserialization vulnerability that triggers object reconstruction when a checkpoint is loaded. CVE-2026-27022 (CVSS 6.5) is a RediSearch query injection allowing access control bypass. The attack chain works when the application exposes the get_state_history() endpoint. An attacker prepares a msgpack payload with instructions to execute arbitrary code, sends a malicious filter parameter exploiting the SQL injection to return a fake checkpoint row where the checkpoint column contains attacker-controlled serialized data, and when the application processes query results it deserializes the malicious checkpoint, executing the payload. This gives remote code execution on the server with potential access to runtime secrets and other systems the runtime can reach. The vulnerability chain is exploitable in self-hosted deployments using SQLite or Redis checkpointer with user-controlled filter input. LangChain's managed platform (LangSmith Deployment) is not affected. Patches are available in langgraph-checkpoint-sqlite 3.0.1+, langgraph 1.0.10+, and @langchain/langgraph-checkpoint-redis 1.0.1+.
AI Agent Supply Chains Lack Integrity Verification
Palo Alto Networks Unit 42 research reveals that AI agents now extend capabilities by installing third-party skills the way smartphones install apps, but no automated tool verifies what a skill does before it gains privileged access to credentials, files, and shell commands. Unit 42 introduced Behavioral Integrity Verification (BIV), an audit primitive comparing what a skill claims to do against what it does across metadata, executable code, and natural-language instructions. Applied at registry scale, BIV finds most skills deviate from declared behavior. The vast majority of gaps are sloppy documentation, but a smaller slice carries multi-stage attack chains where individually benign-looking capabilities combine into credential theft, remote code execution, or silent data exfiltration. Once installed, a skill runs inside the agent's privileged context with access to environment variables, external services, file writes, and shell commands. Public agent-skill registries now host tens of thousands of packages. Anyone can publish, anyone can install. The platforms that came before (package managers, mobile app stores, browser extension marketplaces) all eventually grew automated audit ecosystems after attackers turned openness against users. The agent-skill ecosystem has not.
OpenClaw AI Agent Vulnerable to Hidden Command Injection and Phishing
Two security teams published separate research showing OpenClaw, the popular self-hosted AI agent, can be tricked into running attacker-controlled code or leaking sensitive data. Imperva found that OpenClaw flattens message objects (shared contacts, vCards, location pins) into the prompt text inline with no boundary marking them as untrusted. A shared contact sends just the name field serialized as <contact: name, number>. Since angle brackets are legal in a name, the model cannot tell where the real name ends and an injected instruction begins. The contact name is truncated where it shows on screen, so the victim does not see the payload. In Imperva's tests against Gemini 3.1 Pro, hidden text told the agent to download and run a script from a controlled server. It did. OpenClaw shipped a fix in version 2026.4.23 moving contact names, vCard fields, and location labels into a separate untrusted-metadata channel. Varonis ran a separate test where a normal email posing as a team lead asked for staging access during a fake production incident. The agent found and forwarded mock AWS IAM access keys, database connection strings, and SSH credentials in plaintext. A second test requested a customer export for a QBR deck; the agent shipped a synthetic dataset of 247 enterprise customers. Both attacks succeeded on Google Gemini 3.1 Pro and OpenAI Codex GPT-5.4.
French Government Tchap Messenger Breach Affects 73,000 Employees
A threat actor breached France's Tchap encrypted messaging platform using a compromised user account, affecting 73,467 employees (9% of 825,000 registered users). Tchap is the default work communications app for French civil servants, based on the Matrix protocol. While private conversations are encrypted and protected, the attacker scraped all data shared in public chat rooms, which are not encrypted. Stolen data includes names, email addresses, avatar images, and public sector organization affiliation. The threat actor claims to have scraped nearly 650,000 messages, information from 73,000 accounts including email addresses, meeting links, organization information, account and device metadata, over 13.5GB of documents and media files, and hardcoded LDAP credentials leaked via a PowerShell script. The attacker claims the initial access was via social engineering. DINUM, France's digital affairs directorate, notified the data protection authority (CNIL) and immediately blocked the compromised account. Tchap reached over 300,000 monthly users and has over 500,000 downloads on Google Play Store. This follows a separate breach in May where French authorities arrested a 15-year-old suspected of selling data stolen from ANTS, France's agency for issuing official identity and registration documents.
GreatXML Exploit Bypasses BitLocker via Recovery Partition XML Files (CVE-2026-45585)
Security researcher Chaotic Eclipse released GreatXML, a BitLocker bypass exploiting XML files in the recovery partition. The exploit requires copying unattend.xml and Recovery/WindowsRE/ReAgent.xml to the recovery partition root, then rebooting to Windows Recovery Environment by holding Shift while clicking Restart. If Windows Defender Offline Scan was ever initiated, the system boots into WinRE in offline scan state and spawns a shell with unrestricted access to the BitLocker volume. The researcher discovered this accidentally in 4 hours. Security researcher Will Dormann disputes the severity, noting that triggering Microsoft Defender Offline Scan requires a user to be logged in to Windows with admin credentials, at which point turning off BitLocker is trivial anyway. Dormann tested on three Windows 11 lineages and could not reproduce the automatic offline scan mode that the writeup describes. GreatXML follows YellowKey (CVE-2026-45585), which Microsoft patched this week, and RoguePlanet, a zero-day in Microsoft Defender facilitating local privilege escalation to SYSTEM. EPSS score for CVE-2026-45585 is 0.001 (31st percentile).
CISA Issues New Binding Operational Directive 26-04
CISA issued Binding Operational Directive 26-04 this week, updating federal civilian agency patching rules. The new order cites AI-automated attacks as the main reason to prioritize bugs based on risk and shorten patching deadlines. The order introduces a decision tree prioritizing vulnerabilities that are exploited in the wild, easy to exploit and automate, and grant broad system access. Patching deadlines can go down to three days for high-priority vulnerabilities. Agencies can extend deadlines if they take the system offline or disconnect it from the network until it can be updated. CISA has been applying these new rules for over a month; recent KEV entries have had three-day patching deadlines. BOD 26-04 supersedes and revokes BOD 19-02 and BOD 22-01. The change comes after a funding lapse ruined the NIST NVD vulnerability database, which has been swamped by new entries that have yet to be enriched. The new CISA strategy only cares about bugs that directly impact U.S. government networks, what CISA calls "patch smarter, not harder."
Alert Fatigue Becoming a Security Threat of Its Own
SOC analysts are inundated with continuous high-volume alerts generated by security tools. Each alert is often meaningless absent correlation with other alerts, but finding relationships is time-consuming and might be irrelevant to business security. Security tools are great at detecting alert signals but poor at prioritizing them. Alerts arrive with scores (e.g., "32 out of 100") that are meaningless without context. An alert might suggest an urgent vulnerability, but full context might indicate the device has no outgoing connectivity and zero relevance to business continuity. Criminal use of AI is increasing the pace, sophistication, and stealth of attacks. Attackers are using AI to analyze stolen data faster, generate more convincing phishing campaigns, and automate parts of the intrusion process. Defensive use of AI simultaneously increases the attack surface bad actors can target. AI systems themselves are becoming part of the attack surface, introducing new risks around model manipulation, data exposure, and misuse. Human analysts cannot triage and investigate every signal at the pace modern environments produce them. This has two effects: continuous high stress leading to burnout, and business suffers from reduced security. Alert fatigue is caused by continuous long hours and continuous stress with no escape. If it is not prevented, the effect on the analyst could begin with missed false negatives and grow into full business compromise. The solution must be a business solution rather than analyst reaction.
OceanLotus Shifts Focus to Domestic Espionage in Vietnam
Vietnam-aligned threat actor OceanLotus conducted two distinct campaigns targeting domestic entities. The first was a prolonged cyber espionage operation aimed at a Vietnamese infrastructure and transport construction corporation between mid-2024 and February 2026. The second was a supply chain attack leveraging FireAnt Metakit, a popular stock investor software platform in Vietnam, from October 2025 to March 2026. The campaigns represent a shift in operational focus, with the group placing increasing emphasis on domestic espionage rather than external targets. OceanLotus has been active since 2012 and previously targeted China. The FireAnt Metakit attack leveraged the software's legitimate update URL to serve SPECTRALVIPER backdoor to a small subset of stock investors. The update configuration file lacks integrity validation, so the malware was executed as a legitimate update. The backdoor contacts a C2 server at financemachinelearning.com to send encrypted host information. Meta linked OceanLotus to Vietnamese IT company CyberOne Group in December 2020. Although the company denied allegations, public exposure led to the group going off the grid for nearly three years. ESET said it has not observed further malicious updates through the compromised channel since March 9, 2026, raising the possibility that threat actors completed their objectives or shifted tactics.
North Korean Famous Chollima Accounts for 47% of Tech Sector Intrusions
CrowdStrike revealed that Famous Chollima, a North Korean threat actor behind the IT worker and Contagious Interview campaigns, accounted for 47% of all state-sponsored hands-on-keyboard operations against the tech sector between April 2025 and March 2026. Hands-on intrusions refer to cyber attacks where a human operator controls and interacts with a system rather than relying solely on malware. In their IT worker infiltration campaigns, they sought fraudulent employment at tech companies across North America, Europe, and Asia. Flashpoint analysis revealed more than 11.1 million devices were infected with infostealers last year, fueling a supply of over 3.3 billion stolen credentials, session cookies, cloud tokens, and other identity data now circulating across illicit markets. Over 30 unique infostealer strains are actively listed for sale across illicit marketplaces. Lumma, Acreed, Rhadamanthys, Vidar, and StealC were the most prolific stealers in 2025. India, Brazil, Indonesia, Vietnam, the Philippines, and the U.S. were the top six countries affected by stealer malware. A new RAT named SilabRAT is sold under a malware-as-a-service model for $5,000/month, advertised since September 2025. It uses Hidden Virtual Network Computing (HVNC) for remote control and employs Browser Profile Cloning to replicate a user's browser profile to the attacker's system. The U.S. DOJ seized 13 internet domains masquerading as consulting companies used to target U.S. persons, including security clearance holders with access to classified information.
IoT Platform Vulnerabilities Across Multiple Vendors
CISA published advisories for critical vulnerabilities in IoT platforms from Chinese manufacturers. Naxclow IoT Platform (smart doorbells, home cameras, security cameras) has six vulnerabilities allowing attackers to impersonate devices, intercept communications, harvest credentials at scale, and gain unauthorized access. CVE-2026-42947 allows silent device reassignment to arbitrary accounts. CVE-2026-50108 exposes persistent relay credentials without owner verification. CVE-2026-50101 uses server-side per-device relay credentials that never rotate and survive factory resets. CVE-2026-28742 uses platform-wide hardcoded salt for request signing combined with plain HTTP for control-plane traffic, enabling broad request forgery. Naxclow did not respond to CISA coordination attempts. Brickcom cameras (cube, dome, bullet, box models running firmware 3.2.3.5.6) have two vulnerabilities. CVE-2026-50245 allows unauthenticated access to live snapshot images via the /ONVIF endpoint. CVE-2026-50005 ships with default credentials allowing any unauthenticated remote attacker to access camera feeds. Brickcom did not respond to CISA coordination. Yarbo Android/iOS app and cloud MQTT infrastructure has two vulnerabilities. CVE-2026-10557 contains hardcoded MQTT broker credentials identical for all users and devices, allowing wildcard subscription to all robot telemetry topics and publishing to any robot's command topic using only the serial number. CVE-2026-7368 does not enforce per-device or per-user authorization, so a single compromised credential provides fleet-wide access. Yarbo recommends updating mobile app to 3.17.4 or later; server-side broker authorization enforced automatically in May 2026 update.
Siemens Desigo CC Patch Files Flagged as Malware by Security Engines
Siemens notified customers that patch files for Desigo CC building management system versions 7 through 9 are being erroneously flagged as malware by multiple antivirus engines. Desigo CC integrates HVAC, lighting, security, fire safety, power, and other building subsystems into a single platform. Tests on VirusTotal confirmed the false-positive detections. Siemens is working with cybersecurity vendors to address the issue. The company suspects the false positives are caused by a PowerShell script compiled as an executable included in a patchHelper shipped with Desigo CC patches. File system operations, registry modifications, and execution with elevated privileges in the script are considered suspicious by security engines. The script has been the same for several months but only recently started triggering detections. Siemens manually compared all relevant files to development repositories and found no differences or malicious modifications. Digital signatures were verified as valid with no indications of manipulation.
Three major themes today: zero-day exploitation windows are shrinking to hours, not days; AI agent security is moving from theoretical to actively exploited; and cryptocurrency laundering infrastructure is becoming a high-value law enforcement target. The Ivanti vulnerability went from patch release to active exploitation within 24 hours based on a public proof-of-concept. ShinyHunters exploited Oracle PeopleSoft as a zero-day for two weeks before Oracle published an advisory, and the attackers left staging infrastructure exposed showing exactly how they moved laterally and exfiltrated data. AI agent platforms (OpenClaw, Langflow, LangGraph) are now being exploited or have exploitable vulnerability chains that were not theoretical research but actual working attacks. The AudiA6 takedown shows law enforcement is successfully following cryptocurrency flows back to operators and seizing physical assets, not just domains.