Cybersecurity Daily: News & Threats
(00:00:00) OceanLotus Supply Chain, Defender Zero-Day & Ivanti CVSS 10 Exploited (00:01:18) OceanLotus Infrastructure Campaign (00:01:41) Windows Defender RoguePlanet Zero-Day (00:02:30) Ivanti Sentry CVSS Ten Exploitation (00:03:07) Microsoft Patch Tuesday and CISA Directive (00:03:54) VRChat Breach Notice Dispute (00:04:29) Watchpoints and Close Today's cybersecurity briefing opens with one of the most structurally dangerous supply chain attacks in recent memory. OceanLotus — the Vietnam-aligned APT group — spent five months silently poisoning the FireAnt Metakit update mechanism, delivering the SPECTRALVIPER backdoor to tens of thousands of retail stock investors without a single suspicious click required. The same group maintained 15 months of persistent access to an unnamed Vietnamese infrastructure firm via SQL Server exploitation. From nation-state patience to immediate exploitation urgency: researcher Nightmare Eclipse dropped a working proof-of-concept for RoguePlanet, a TOCTOU race condition in Windows Defender enabling full privilege escalation on fully patched Windows 10 and 11 machines. Real-world detections via tools BlueHammer and RedSun are already confirmed. Microsoft has not yet issued a patch. The speed problem compounds with Ivanti. Two CVSS 10.0 vulnerabilities in Ivanti Sentry — CVE-2026-10520 and CVE-2026-10523 — were confirmed exploited within 24 hours of public PoC release, with Shadowserver detecting backdoored instances by June 11. Ivanti Sentry serves over 40,000 enterprise customers. Microsoft's June Patch Tuesday delivered 206 updates including 33 critical CVEs and patches for three zero-days across Windows, Office, and Exchange. CISA simultaneously issued a new risk-based patching directive replacing BOD 22-01, setting a three-day remediation deadline for internet-exposed assets with fully exploitable flaws — a timeline critics say is unrealistic for legacy-burdened agencies. Finally, a disputed breach notice filed with the Maine Attorney General claims 2.4 million VRChat accounts were compromised. VRChat denies any incident or filing, raising serious questions about the integrity of the breach disclosure infrastructure itself. This episode includes AI-generated content.
72 episodes
Comments
0Be the first to comment
Sign up now and become a member of the Cybersecurity Daily: News & Threats community!