← Carolina Clear Tech

Cyber Threat Brief

2026-06-13

Listen to this brief (17:37)

Download MP3
Show Notes

Show Notes - 2026-06-13

Stories Covered

CVEs Referenced

CVE-2023-5678, CVE-2024-20399, CVE-2026-34180, CVE-2026-34181, CVE-2026-34182, CVE-2026-34183, CVE-2026-35273, CVE-2026-42764, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-44705, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447, CVE-2026-47162, CVE-2026-47167, CVE-2026-52859, CVE-2026-52860, CVE-2026-7383, CVE-2026-9076

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - 2026-06-13

Today: ShinyHunters exploited Oracle PeopleSoft zero-day CVE-2026-35273 for two weeks, stealing data from 100+ organizations, mostly universities. CISA added it to KEV catalog. A Conti ransomware member pleaded guilty and faces 20 years. China-linked Velvet Ant spent nine years backdooring Linux PAM and OpenSSH login systems.

Critical Alerts

Oracle PeopleSoft Zero-Day Exploited (CVE-2026-35273)

ShinyHunters exploited CVE-2026-35273, a critical 9.8 CVSS authentication bypass in Oracle PeopleSoft Environment Management Hub, from May 27 through June 9, 2026. The vulnerability allowed unauthenticated remote code execution across 300+ PeopleSoft instances at 100+ organizations. 68% of victims were higher education institutions, including University of Nottingham which confirmed a significant data breach affecting current and former students. Attackers used MeshCentral for C2, disguised agents as Azure services, deployed SSH credential spraying scripts, and exfiltrated data using Zstandard compression. Oracle patched the flaw June 10 after TrendAI identified it. CISA added CVE-2026-35273 to the Known Exploited Vulnerabilities catalog June 12. EPSS score is 0.000 (7th percentile), but active exploitation in the wild makes this critical.

Ransomware Claims (Last 48h)

16 claims tracked across 1 group on 2026-06-12. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
3am jetmachprod.com (Jet Machined Products) Aerospace/Manufacturing USA
3am jastrebarsko.hr (Town of Jastrebarsko) Government/Municipal Croatia
3am palmero.com (Palmero) Manufacturing/Energy Argentina
3am insamani.com.ar (INSA INDELMA) Agriculture/Food Processing Argentina
3am bsynchro.com (BSynchro Holding) Insurance/Insurtech Unknown
3am molinoscabodi.com.ar (Molinos Cabodi Hnos.) Food Processing Argentina
3am ws.com.br (WS Group Brasil) Logistics/Business Services Brazil
3am consultic.be (ConsulTIC) IT Services Belgium
3am amc.org.au (Australian Medical Council) Healthcare/Medical Accreditation Australia
3am agroexportavocados.com (Agro Industrial Exportadora) Food Processing/Agriculture Mexico
3am hoplongtech.com (Hợp Long Tech) Industrial Automation Vietnam
3am mgrlaw.com (Mogren, Glessner & Ahrens) Legal Services USA
3am aceforwarding.com (Ace Forwarding) Logistics USA
3am ic-controls.com (Industrial Controls SAC) Industrial Automation Peru
3am bun.nl (Bun) Real Estate/Construction Netherlands
3am hsjlawyers.com (HSJ Lawyers) Legal Services Australia

Ransomware & Extortion

Conti Ransomware Member Pleads Guilty

Oleksii Oleksiyovych Lytvynenko, 44, pleaded guilty to conspiracy to commit wire fraud for his role in the Conti ransomware operation. He admitted to joining Conti in September 2021, holding stolen data from 12 victims (8 in the U.S.), and developing malware loaders used in attacks. Conti targeted over 1,000 victims globally and collected $150+ million in ransom payments between 2021 and 2022. Lytvynenko and co-conspirators extorted $634,000 in Bitcoin from two Tennessee victims, including a government entity that led to compromise of a sheriff's department, EMS, and police department. They also leaked data from a Tennessee victim that refused a $3 million ransom demand. He faces up to 20 years in prison at sentencing on September 10. Lytvynenko was arrested in Ireland in July 2023 while "asleep but within arms' reach of an open laptop running Cobalt Strike" and extradited to the U.S. in October 2025. Conti disbanded in 2022 after internal chat leaks and splintered into BlackCat, Black Basta, ZEON, Hive, Quantum, BlackByte, Karakurt, and Silent Ransom Group. Four co-conspirators remain indicted.

Global Schools Foundation Ransomware Negotiation Failure

Global Schools Foundation (GSF), a Singapore-based K-12 education organization operating 12 international school brands, suffered a ransomware attack where their negotiator "acted bizarrely," leading to a failed negotiation. The incident highlights how poor negotiation tactics can result in worse outcomes for breach victims.

Business & Infrastructure Threats

China-Linked Group Backdoored Linux Login Systems for 9 Years

Sygnia reports that Velvet Ant, a China-nexus threat group, maintained persistent access to air-gapped Linux networks by backdooring PAM (Pluggable Authentication Modules) and OpenSSH components from 2016 to present. The attackers replaced legitimate PAM login modules and OpenSSH binaries with backdoored versions that allowed authentication with hardcoded passwords, logged real credentials as users logged in, and captured all typed commands. Nine separate backdoor versions were discovered. The group accessed air-gapped networks by compromising internet-facing web servers as pivot points, then using hidden tunnels to reach isolated segments. Because the login system itself was compromised, normal containment measures like password resets and session kills were ineffective. Velvet Ant previously exploited Cisco NX-OS CVE-2024-20399 (patched July 2024, CISA KEV same day, EPSS 0.007 72nd percentile) to backdoor switches and turned F5 BIG-IP appliances into internal command servers in 2024. The group targets infrastructure components that are trusted by default and rarely monitored.

Supply-Chain Attack Early Warning Signs on Dark Web

Flare researchers identified underground forum posts advertising GitHub access, private repositories, source code, API keys, OAuth tokens, cloud credentials, and CI/CD data that represent early warning signs of supply-chain attacks before they become public incidents. A recent post advertised GitHub-related access including developer accounts, private repositories, and source code that could enable attacks against downstream customers. The Vercel incident in April 2026 demonstrated how compromised OAuth-connected SaaS access can create wider security concerns. Posts mentioning OAuth access, SaaS tools, environment variables, or developer platforms deserve attention even when claims are unverified. The Sportradar case linked to TeamPCP supply-chain campaign involved a compromised Trivy scanner.

Insider Threat: Iowa School IT Worker Sentenced for Sabotage

Former Saydel Community School District IT worker Ezekiel Dean Potter was sentenced June 11 for disrupting school technology systems used by students and staff after he left employment. The disruptions affected classroom technology, staff accounts, and district-managed devices.

Maine Data Breach Portal Disabled After Fake Disclosures

Maine disabled its public data breach reporting portal after fraudulent breach disclosures were published on the state's website. The state is reviewing procedures to prevent abuse of the portal in the future.

General Security News

KPMG AI Report Demonstrates AI Hallucinations

GPTZero claims only 5 of 45 citations in KPMG's AI report matched their sources, raising questions about how the Big Four firm's AI study was assembled. The report became an accidental demonstration of AI hallucination problems.

New macOS Tahoe 26 Forensic Artifact Discovered

Unit 42 discovered a new macOS Tahoe 26 forensic artifact that tracks user menu selections across the operating system. This provides additional forensic evidence for incident investigations on macOS systems.

LabCorp Settles AMCA Breach for $35 Million

LabCorp reached a $35 million settlement over the 2019 American Medical Collection Agency (AMCA/Retrieval-Masters Creditors Bureau) breach that affected 10,251,784 patients. AMCA was a third-party billing collections company used by LabCorp.

DOJ: COVID-19 Relief Fraud Arrests

Seven men were arrested in coordinated law enforcement actions across three states for submitting fraudulent COVID-19 relief loan applications (PPP and EIDL programs) totaling $205,639. A Suffolk County woman also pleaded guilty to conspiracy to commit bank fraud and aggravated identity theft, facing up to 30 years and a $1 million fine.

Patch Priority

Vulnerability Disclosures

phpBB Authentication Bypass (10 Years Old)

A 10-year-old authentication bypass vulnerability in phpBB forum software allows attackers to log in as any user, including administrators. The flaw has been fixed in the latest release.

Microsoft Security Update Guide CVEs

Microsoft published information for 18 CVEs in its Security Update Guide, primarily affecting OpenSSL, Vim, and cryptographic components bundled in Windows and other Microsoft products. Notable CVEs include:

All have low EPSS scores indicating low probability of exploitation in the wild currently.

Trends & Context

Zero-day exploitation continues to be a critical threat vector with ShinyHunters' two-week exploitation window on PeopleSoft demonstrating the real-world damage before patches arrive. Higher education institutions remain high-value targets due to large volumes of personal data with relatively weaker security compared to enterprise. The Velvet Ant campaign shows advanced persistent threat actors are focusing on infrastructure components that defenders trust by default and rarely verify, making integrity monitoring of core system components essential defensive practice.