CVE-2026-11640, CVE-2026-11645, CVE-2026-11662, CVE-2026-11668, CVE-2026-11677, CVE-2026-11684, CVE-2026-11685, CVE-2026-11688, CVE-2026-11693, CVE-2026-12010, CVE-2026-12012, CVE-2026-12016, CVE-2026-12019, CVE-2026-20262, CVE-2026-2441, CVE-2026-35273, CVE-2026-3909, CVE-2026-3910, CVE-2026-42824, CVE-2026-5281, CVE-2026-54411, CVE-2026-54420
IP Addresses:
20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2, 5.3.2.0
Get tomorrow's brief in your inbox
June 16, 2026
Today: Cisco patches its eighth SD-WAN zero-day of the year, CISA adds two more KEV entries by June 29th deadline, and Microsoft fixes a critical Copilot flaw that allowed one-click data theft. Oracle PeopleSoft exploits hit higher education, LiteSpeed cPanel escalates to root, and Chrome patches another actively exploited V8 zero-day.
Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262)
Cisco patched a medium-severity arbitrary file write vulnerability in Catalyst SD-WAN Manager that was exploited in limited attacks during June 2026. CVE-2026-20262 (CVSS 6.5) stems from inadequate validation during file uploads to an affected API endpoint, allowing authenticated attackers with write access to create or overwrite any file on the underlying OS and escalate to root. The flaw impacts all deployment types including on-prem, Cloud-Pro, Cloud (Cisco Managed), and Government (FedRAMP).
/var/log/nms/vmanage-server.log for suspicious WAR file uploads, /var/log/nms/vmanage-appserver.log for deployment of suspicious.war, and /var/log/nms/containers/service-proxy/serviceproxy-access.log for POST requests to /suspicious/index.jsp. This is the eighth Cisco SD-WAN vulnerability exploited in 2026. Upgrade to fixed versions: 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, or 26.1.1.2 depending on your release branch.Google Chrome V8 Zero-Day (CVE-2026-11645)
Google patched an actively exploited zero-day in Chrome's V8 JavaScript engine. CVE-2026-11645 (CVSS 8.8) is an out-of-bounds memory access flaw that Google acknowledged is being exploited in the wild. CISA added it to the KEV catalog with a June 23, 2026 deadline. EPSS score 0.007 (49th percentile). This is the fifth Chrome zero-day Google has addressed in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, and CVE-2026-5281.
Oracle PeopleSoft Zero-Day Exploited by ShinyHunters (CVE-2026-35273)
ShinyHunters (UNC6240) exploited an unpatched authentication bypass in Oracle PeopleSoft Enterprise PeopleTools between May 27 and June 9, 2026. CVE-2026-35273 (CVSS 9.8) is a missing authentication flaw that allows unauthenticated attackers to take over PeopleSoft systems. The campaign primarily targeted higher education (68% of 100+ notified organizations were universities and colleges). Attackers used MeshCentral for reconnaissance, conducted lateral movement, and exfiltrated data published on the ShinyHunters leak site June 9. CISA added this to KEV with a June 15, 2026 deadline (now past). EPSS 0.007 (49th percentile). Exploitation targeted PSEMHUB endpoints.
LiteSpeed cPanel Plugin Privilege Escalation (CVE-2026-54420)
CISA added CVE-2026-54420 (CVSS 8.5) to the KEV catalog with a June 18, 2026 deadline. The vulnerability affects LiteSpeed cPanel Plugin before 2.4.8 (distributed in LiteSpeed WHM Plugin before 5.3.2.0) and allows users with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux or CageFS through symlink manipulation. EPSS 0.003 (26th percentile). Namecheap reported the issue May 31, 2026.
grep -rE 'cpanel_jsonapi_func=(generateEcCert|packageUserSize)|cert_action_entry .*geneccert' /usr/local/cpanel/logs/ /var/cpanel/logs/ 2>/dev/null. If output appears, look for generateEcCert followed by packageUserSize for the same user and 7-10 concurrent calls per attempt (legitimate UI does one at a time).Deadlock ransomware group posted 75 claims in the last 30 days. Recent victims from June 15-16 include:
| Group | Victim | Sector | Country |
|---|---|---|---|
| Deadlock | Zhangjiagang Fortune Chemical Co. Ltd. | Chemicals/Manufacturing | Singapore |
| Deadlock | SUMMA 4 Asesores Legales y Tributarios | Legal/Tax Advisory | Spain |
| Deadlock | Hornavan Hotell | Hospitality | Sweden |
| Deadlock | TeleFinity | Telecom/CTI Software | Global |
| Deadlock | Donjon Pte Ltd | Engineering (M&E) | Singapore |
| Deadlock | Cheng Heng Paper Products Co | Manufacturing/Packaging | Singapore/Malaysia |
| Deadlock | Nobani & Co | Financial Services | Jordan |
| Deadlock | Fidelity Pension Managers | Financial Services/Pensions | Nigeria |
| Deadlock | C.A.D. 93 S.r.l. | Customs Brokerage | Italy |
| Gentlemen | Mackay Sugar | Agriculture/Food Production | Australia |
Deadlock group continues high-volume claims activity targeting diverse sectors globally. 75 claims tracked across the last 30 days.
Mackay Sugar Ransomware Attack Shuts Down Mills
Gentlemen ransomware group (Storm-2697) targeted Mackay Sugar, Australia's second-largest raw sugar producer, shutting down two of three mills in Queensland. The attack was disclosed June 10, 2026 and forced the company to halt cane processing. Limited manual crushing resumed June 12 at one mill for cane harvested before the incident. Steam trials were underway as of June 15 with staged restart of crushing operations planned for later in the week. Gentlemen named Mackay Sugar on its leak site June 15 but has not yet leaked data. The group has listed 500+ alleged victims and is known for worm-like lateral movement capabilities.
FulcrumSec Leaks Novo Nordisk Data After $25M Demand Goes Unpaid
FulcrumSec leaked data from Danish pharma giant Novo Nordisk after a $25 million ransom demand went unpaid. Novo Nordisk disclosed the incident June 11. The company produces insulin and semaglutide (marketed as Wegovy for weight loss and Ozempic for Type 2 diabetes).
Conti Ransomware Developer Pleads Guilty
Ukrainian national Oleksii Oleksiyovych Lytvynenko, 44, pleaded guilty in US court to wire fraud conspiracy for his role in the Conti ransomware group. Lytvynenko joined Conti in September 2021 and developed a malware loader for the group. He possessed data from 12 victims including eight in the US and continued cybercriminal activity after Conti shut down in May 2022. Lytvynenko faces up to 20 years in prison and is scheduled for sentencing September 10, 2026. Conti attacked over 1,000 organizations between 2020-2022 and received at least $150 million in ransom payments by January 2022.
Microsoft 365 Copilot SearchLeak Vulnerability (CVE-2026-42824)
Researchers at Varonis disclosed SearchLeak, a critical vulnerability chain in Microsoft 365 Copilot Enterprise that allowed attackers to exfiltrate sensitive data through a crafted URL. CVE-2026-42824 (CVSS 6.5 Microsoft, 7.5 NVD) chains three bugs: parameter-to-prompt (P2P) injection, HTML rendering race condition, and a Bing SSRF that bypasses Content Security Policy. An attacker sends a victim a Copilot link with a malicious prompt in the 'q' parameter that instructs Copilot to search the victim's mailbox, extract data (MFA codes, passwords, email subjects), and embed it in an image URL. While Copilot is streaming its response, a race condition allows an attacker-controlled image tag to execute before sanitization completes. The image tag points to Bing's "search by image" endpoint, which makes a server-side request to the attacker's server with the stolen data in the URL path. Bing is whitelisted in the CSP, so the request succeeds. The victim sees only Copilot "thinking" with no indication of data theft. Microsoft patched the flaw at the beginning of June 2026. No user action required.
1,500+ Arch Linux Packages Compromised With Malware
Unknown threat actors compromised hundreds of abandoned packages in the Arch User Repository (AUR) and modified them with preinstall scripts that download and execute a malicious npm package called atomic-lockfile. The campaign, codenamed Atomic Arch by Sonatype, started with 400 affected packages but rose to over 1,500. The payload includes credential harvesting, stealth, anti-debugging, and potential data exfiltration capabilities. Arch Linux developers deleted all known malicious commits as of June 12, 2026.
FBI Takes Down Outsider PhaaS Enterprise
The FBI took down domains linked to Outsider, a Chinese phishing-as-a-service (PhaaS) software kit. Outsider is estimated to have compromised 3,870,000 credit cards with $1.9 billion in losses since July 2023. Google is pursuing legal action in parallel.
ShinyHunters Claims Council of Europe Hack
The Council of Europe, the continent's oldest intergovernmental body, is investigating claims of a data breach made by ShinyHunters extortion group over the weekend.
North Korean Hackers Target Developers With Malicious Tools
Contagious Interview (Famous Chollima, HexagonalRodent, Void Dokkaebi), a North Korean threat cluster, is orchestrating phishing campaigns using developer role recruitment or code review themes. The campaigns turn developer tools into malware delivery channels.
Chinese APT UNC6508 Targets US Medical and Academic Research
Google Threat Intelligence Group identified a sophisticated campaign by UNC6508, a PRC-nexus threat actor, targeting North American academic, medical, and military research institutions. The threat actor remained undetected for over a year while compromising externally facing web applications, deploying bespoke malware, pivoting to sensitive internal systems, and abusing enterprise admin tools. The campaign pursues AI, cyber, medical, and national defense research.
Jaguar Land Rover Ordered 30,000 Staff Password Resets After Cyberattack
Jaguar Land Rover required all 30,000 employees to physically verify their identity and reset passwords in person following a cyberattack that raised concerns about compromised staff credentials. Former CISO Ashish Shrestha disclosed this at Infosecurity Europe.
VHDX File Delivers Remcos RAT
SANS ISC reported a malicious ZIP archive (SHA256: a0104921...) containing a VHDX file that discloses malicious JavaScript after automatic mounting on modern Windows systems. The JavaScript delivers Remcos RAT.
Linux-PAM Timing Attack (CVE-2026-54411)
Linux-PAM through 1.7.2 contains a timing discrepancy in the pam_userdb module's plaintext password comparison (CWE-208) in modules/pam_userdb/pam_userdb.c. A local or network-adjacent attacker can recover plaintext passwords by measuring response-timing differences when the module is configured with crypt=none. The comparison uses strncmp() preceded by a length-equality check, leaking password length and individual prefix bytes. EPSS 0.003 (24th percentile).
crypt=none in pam_userdb modules. Reconfigure to use proper password hashing. This vulnerability only applies to plaintext password storage configurations.Microsoft Edge Chromium CVE Batch
Microsoft published multiple Edge Chromium CVE advisories for vulnerabilities addressed in upstream Chrome releases. CVEs include: CVE-2026-12012 (use after free in Network), CVE-2026-12019 (out of bounds write in Codecs), CVE-2026-12016 (insufficient validation in DevTools), CVE-2026-11640 (integer overflow in libyuv), CVE-2026-11662 (type confusion in Bindings), CVE-2026-11668 (uninitialized use in Codecs), CVE-2026-11677 (race in Network), CVE-2026-11684 (insufficient policy enforcement in Network), CVE-2026-11688 (object lifecycle issue in SVG), CVE-2026-11685 (insufficient data validation in MediaCapture), CVE-2026-11693 (inappropriate implementation in Plugins), CVE-2026-12010 (heap buffer overflow in GPU).
Cisco SD-WAN continues to be a high-value target for advanced threat actors, with this being the eighth exploited vulnerability in 2026. The steady stream of exploitation against this platform suggests targeted campaigns by sophisticated groups. The Microsoft Copilot SearchLeak vulnerability demonstrates how AI systems create new attack surfaces for old bug classes like SSRF and race conditions. Parameter-to-prompt injection is emerging as a distinct threat category that defenders need to monitor. Chrome's fifth zero-day of the year reinforces the importance of rapid browser patching in enterprise environments.