CVE-2023-5678, CVE-2024-20399, CVE-2026-34180, CVE-2026-34181, CVE-2026-34182, CVE-2026-34183, CVE-2026-35273, CVE-2026-42764, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-44705, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447, CVE-2026-47162, CVE-2026-47167, CVE-2026-52859, CVE-2026-52860, CVE-2026-7383, CVE-2026-9076
Get tomorrow's brief in your inbox
Today: ShinyHunters exploited Oracle PeopleSoft zero-day CVE-2026-35273 for two weeks, stealing data from 100+ organizations, mostly universities. CISA added it to KEV catalog. A Conti ransomware member pleaded guilty and faces 20 years. China-linked Velvet Ant spent nine years backdooring Linux PAM and OpenSSH login systems.
Oracle PeopleSoft Zero-Day Exploited (CVE-2026-35273)
ShinyHunters exploited CVE-2026-35273, a critical 9.8 CVSS authentication bypass in Oracle PeopleSoft Environment Management Hub, from May 27 through June 9, 2026. The vulnerability allowed unauthenticated remote code execution across 300+ PeopleSoft instances at 100+ organizations. 68% of victims were higher education institutions, including University of Nottingham which confirmed a significant data breach affecting current and former students. Attackers used MeshCentral for C2, disguised agents as Azure services, deployed SSH credential spraying scripts, and exfiltrated data using Zstandard compression. Oracle patched the flaw June 10 after TrendAI identified it. CISA added CVE-2026-35273 to the Known Exploited Vulnerabilities catalog June 12. EPSS score is 0.000 (7th percentile), but active exploitation in the wild makes this critical.
16 claims tracked across 1 group on 2026-06-12. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| 3am | jetmachprod.com (Jet Machined Products) | Aerospace/Manufacturing | USA |
| 3am | jastrebarsko.hr (Town of Jastrebarsko) | Government/Municipal | Croatia |
| 3am | palmero.com (Palmero) | Manufacturing/Energy | Argentina |
| 3am | insamani.com.ar (INSA INDELMA) | Agriculture/Food Processing | Argentina |
| 3am | bsynchro.com (BSynchro Holding) | Insurance/Insurtech | Unknown |
| 3am | molinoscabodi.com.ar (Molinos Cabodi Hnos.) | Food Processing | Argentina |
| 3am | ws.com.br (WS Group Brasil) | Logistics/Business Services | Brazil |
| 3am | consultic.be (ConsulTIC) | IT Services | Belgium |
| 3am | amc.org.au (Australian Medical Council) | Healthcare/Medical Accreditation | Australia |
| 3am | agroexportavocados.com (Agro Industrial Exportadora) | Food Processing/Agriculture | Mexico |
| 3am | hoplongtech.com (Hợp Long Tech) | Industrial Automation | Vietnam |
| 3am | mgrlaw.com (Mogren, Glessner & Ahrens) | Legal Services | USA |
| 3am | aceforwarding.com (Ace Forwarding) | Logistics | USA |
| 3am | ic-controls.com (Industrial Controls SAC) | Industrial Automation | Peru |
| 3am | bun.nl (Bun) | Real Estate/Construction | Netherlands |
| 3am | hsjlawyers.com (HSJ Lawyers) | Legal Services | Australia |
Conti Ransomware Member Pleads Guilty
Oleksii Oleksiyovych Lytvynenko, 44, pleaded guilty to conspiracy to commit wire fraud for his role in the Conti ransomware operation. He admitted to joining Conti in September 2021, holding stolen data from 12 victims (8 in the U.S.), and developing malware loaders used in attacks. Conti targeted over 1,000 victims globally and collected $150+ million in ransom payments between 2021 and 2022. Lytvynenko and co-conspirators extorted $634,000 in Bitcoin from two Tennessee victims, including a government entity that led to compromise of a sheriff's department, EMS, and police department. They also leaked data from a Tennessee victim that refused a $3 million ransom demand. He faces up to 20 years in prison at sentencing on September 10. Lytvynenko was arrested in Ireland in July 2023 while "asleep but within arms' reach of an open laptop running Cobalt Strike" and extradited to the U.S. in October 2025. Conti disbanded in 2022 after internal chat leaks and splintered into BlackCat, Black Basta, ZEON, Hive, Quantum, BlackByte, Karakurt, and Silent Ransom Group. Four co-conspirators remain indicted.
Global Schools Foundation Ransomware Negotiation Failure
Global Schools Foundation (GSF), a Singapore-based K-12 education organization operating 12 international school brands, suffered a ransomware attack where their negotiator "acted bizarrely," leading to a failed negotiation. The incident highlights how poor negotiation tactics can result in worse outcomes for breach victims.
China-Linked Group Backdoored Linux Login Systems for 9 Years
Sygnia reports that Velvet Ant, a China-nexus threat group, maintained persistent access to air-gapped Linux networks by backdooring PAM (Pluggable Authentication Modules) and OpenSSH components from 2016 to present. The attackers replaced legitimate PAM login modules and OpenSSH binaries with backdoored versions that allowed authentication with hardcoded passwords, logged real credentials as users logged in, and captured all typed commands. Nine separate backdoor versions were discovered. The group accessed air-gapped networks by compromising internet-facing web servers as pivot points, then using hidden tunnels to reach isolated segments. Because the login system itself was compromised, normal containment measures like password resets and session kills were ineffective. Velvet Ant previously exploited Cisco NX-OS CVE-2024-20399 (patched July 2024, CISA KEV same day, EPSS 0.007 72nd percentile) to backdoor switches and turned F5 BIG-IP appliances into internal command servers in 2024. The group targets infrastructure components that are trusted by default and rarely monitored.
/lib/security/pam_*.so, /usr/sbin/sshd, and related binaries against known-good copies. Alert on any modification. If compromised, remove backdoors before resetting passwords or new credentials will be stolen immediately. Test replacements in lab first to avoid lockout on production systems. Patch Cisco Nexus gear for CVE-2024-20399. Watch F5 appliances for unexpected outbound connections. This is a verification problem, not a patching problem.Supply-Chain Attack Early Warning Signs on Dark Web
Flare researchers identified underground forum posts advertising GitHub access, private repositories, source code, API keys, OAuth tokens, cloud credentials, and CI/CD data that represent early warning signs of supply-chain attacks before they become public incidents. A recent post advertised GitHub-related access including developer accounts, private repositories, and source code that could enable attacks against downstream customers. The Vercel incident in April 2026 demonstrated how compromised OAuth-connected SaaS access can create wider security concerns. Posts mentioning OAuth access, SaaS tools, environment variables, or developer platforms deserve attention even when claims are unverified. The Sportradar case linked to TeamPCP supply-chain campaign involved a compromised Trivy scanner.
Insider Threat: Iowa School IT Worker Sentenced for Sabotage
Former Saydel Community School District IT worker Ezekiel Dean Potter was sentenced June 11 for disrupting school technology systems used by students and staff after he left employment. The disruptions affected classroom technology, staff accounts, and district-managed devices.
Maine Data Breach Portal Disabled After Fake Disclosures
Maine disabled its public data breach reporting portal after fraudulent breach disclosures were published on the state's website. The state is reviewing procedures to prevent abuse of the portal in the future.
KPMG AI Report Demonstrates AI Hallucinations
GPTZero claims only 5 of 45 citations in KPMG's AI report matched their sources, raising questions about how the Big Four firm's AI study was assembled. The report became an accidental demonstration of AI hallucination problems.
New macOS Tahoe 26 Forensic Artifact Discovered
Unit 42 discovered a new macOS Tahoe 26 forensic artifact that tracks user menu selections across the operating system. This provides additional forensic evidence for incident investigations on macOS systems.
LabCorp Settles AMCA Breach for $35 Million
LabCorp reached a $35 million settlement over the 2019 American Medical Collection Agency (AMCA/Retrieval-Masters Creditors Bureau) breach that affected 10,251,784 patients. AMCA was a third-party billing collections company used by LabCorp.
DOJ: COVID-19 Relief Fraud Arrests
Seven men were arrested in coordinated law enforcement actions across three states for submitting fraudulent COVID-19 relief loan applications (PPP and EIDL programs) totaling $205,639. A Suffolk County woman also pleaded guilty to conspiracy to commit bank fraud and aggravated identity theft, facing up to 30 years and a $1 million fine.
phpBB Authentication Bypass (10 Years Old)
A 10-year-old authentication bypass vulnerability in phpBB forum software allows attackers to log in as any user, including administrators. The flaw has been fixed in the latest release.
Microsoft Security Update Guide CVEs
Microsoft published information for 18 CVEs in its Security Update Guide, primarily affecting OpenSSL, Vim, and cryptographic components bundled in Windows and other Microsoft products. Notable CVEs include:
All have low EPSS scores indicating low probability of exploitation in the wild currently.
Zero-day exploitation continues to be a critical threat vector with ShinyHunters' two-week exploitation window on PeopleSoft demonstrating the real-world damage before patches arrive. Higher education institutions remain high-value targets due to large volumes of personal data with relatively weaker security compared to enterprise. The Velvet Ant campaign shows advanced persistent threat actors are focusing on infrastructure components that defenders trust by default and rarely verify, making integrity monitoring of core system components essential defensive practice.