2026-06-11: A new Windows zero-day exploit bypassing Microsoft Defender was released hours after Patch Tuesday
SHOW NOTES - 2026-06-11
STORIES COVERED
* Today:
* New Windows Zero-Day Exploit 'RoguePlanet' Released [https://www.securityweek.com/new-windows-zero-day-exploit-rogueplanet-released/] [Critical Alerts]
* 'GreatXML' Zero-Day Exploit Bypasses BitLocker [https://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/] [Critical Alerts]
* Microsoft Patches Exchange Server Zero-Day Exploited in Attacks (CVE-2026-42897) [https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-exchange-server-zero-day-exploited-in-attacks/] [Critical Alerts]
* CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog [https://thehackernews.com/2026/06/cisa-adds-cisco-chrome-and-arista-flaws.html] [Critical Alerts]
* Path Traversal Flaw in AI Dev Platform Langflow Exploited in Attacks (CVE-2026-5027) [https://www.bleepingcomputer.com/news/security/path-traversal-flaw-in-ai-dev-platform-langflow-exploited-in-attacks/] [Critical Alerts]
* Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs [https://thehackernews.com/2026/06/microsoft-patches-record-206-flaws.html] [Vulnerability Disclosures]
* Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities [https://thehackernews.com/2026/06/ivanti-fortinet-and-sap-release-patches.html] [Vulnerability Disclosures]
* Who Runs the Ransomware Group 'The Gentlemen?' [https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/] [Ransomware & Extortion]
* WA: Chelan County Enters Third Week of Disruptions with No Recovery Timeline [https://databreaches.net/2026/06/10/wa-chelan-county-enters-third-week-of-disruptions-with-no-recovery-timeline/?pk_campaign=feed&pk_kwd=wa-chelan-county-enters-third-week-of-disruptions-with-no-recovery-timeline] [Ransomware & Extortion]
* Infostealers Turn Millions of Devices Into Credential Theft Machines [https://www.securityweek.com/infostealers-turn-millions-of-devices-into-credential-theft-machines/] [Business & Infrastructure Threats]
* Deceptive Installers: How Fake Apps Target macOS [https://www.huntress.com/blog/deceptive-installers-macos-infostealers] [Business & Infrastructure Threats]
* GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks [https://thehackernews.com/2026/06/github-to-disable-npm-install-scripts.html] [General Security News]
* Microsoft Fixes BitLocker Recovery Bug on Windows Server 2025 [https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bitlocker-recovery-bug-on-windows-server-2025/] [General Security News]
* Microsoft: Some Windows PCs Fail to Install Latest Monthly Updates [https://www.bleepingcomputer.com/news/microsoft/microsoft-some-upgraded-windows-pcs-fail-to-install-monthly-updates/] [General Security News]
CVES REFERENCED
CVE-2026-10520, CVE-2026-10523, CVE-2026-11645, CVE-2026-20245, CVE-2026-22732, CVE-2026-25089, CVE-2026-27671, CVE-2026-33017, CVE-2026-40128, CVE-2026-42897, CVE-2026-44748, CVE-2026-44815, CVE-2026-45586, CVE-2026-45657, CVE-2026-47291, CVE-2026-49160, CVE-2026-5027, CVE-2026-50507, CVE-2026-7473
Read the full brief [https://carolinacleartech.com/brief/2026-06-11/]