Cyber Threat Brief
SHOW NOTES - 2026-06-17 STORIES COVERED * Today: * CISA Orders LiteSpeed cPanel Patch by June 18 (CVE-2026-54420) [https://www.bleepingcomputer.com/news/security/cisa-warns-of-another-actively-exploited-cpanel-plugin-flaw/] [Critical Alerts] * Microsoft Working on RoguePlanet Defender Zero-Day Patch (CVE-2026-50656) [https://www.bleepingcomputer.com/news/microsoft/microsoft-working-on-defender-patch-for-rogueplanet-zero-day/] [Critical Alerts] * Joomla JCE Plugin Flaw Under Active Exploitation (CVE-2026-48907) [https://thehackernews.com/2026/06/cisa-warns-of-actively-exploited-joomla.html] [Critical Alerts] * Three Fortinet FortiSandbox Flaws Under Active Exploitation [https://www.securityweek.com/3-recently-patched-fortinet-fortisandbox-vulnerabilities-in-hacker-crosshairs/] [Critical Alerts] * DragonForce Ransomware Abuses Microsoft Teams TURN Relays for Command-and-Control [https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/] [Ransomware & Extortion] * Kodak Confirms Data Breach, ShinyHunters Claims 2.2 Million Records [https://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/] [Ransomware & Extortion] * Lorem Ipsum Malware Pivots to ClickFix Delivery, Likely Linked to Vice Society [https://www.darkreading.com/cyberattacks-data-breaches/lorem-ipsum-malware-clickfix-delivery] [Ransomware & Extortion] * Novo Nordisk Hit by Two Separate Threat Actors Demanding $50M and $25M [https://databreaches.net/2026/06/16/one-threat-actor-demanded-50-million-from-novo-nordisk-another-one-demanded-25-million-neither-got-paid/?pk_campaign=feed&pk_kwd=one-threat-actor-demanded-50-million-from-novo-nordisk-another-one-demanded-25-million-neither-got-paid] [Ransomware & Extortion] * 144 Mastra npm Packages Compromised via Hijacked Contributor Account [https://thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html] [Business & Infrastructure Threats] * 15 Malicious JetBrains Plugins Steal AI API Keys from 70,000 Developers [https://www.bleepingcomputer.com/news/security/malicious-jetbrains-marketplace-plugins-steal-ai-api-keys-from-developers/] [Business & Infrastructure Threats] * Steam Workshop Abused to Spread Malware via Wallpaper Engine [https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/] [Business & Infrastructure Threats] * 30,000 Compromised Fortinet Firewalls Expose Corporate Networks (FortiBleed Campaign) [https://www.securityweek.com/3-recently-patched-fortinet-fortisandbox-vulnerabilities-in-hacker-crosshairs/] [Business & Infrastructure Threats] * ClickFix Campaigns Expand with BabaDeda, Lorem Ipsum, and Potemkin Loaders [https://thehackernews.com/2026/06/clickfix-campaigns-expand-malware.html] [General Security News] * GhostTree Attack Abuses Recursive Windows Junctions to Hide Malware from EDR [https://www.bleepingcomputer.com/news/security/ghosttree-attack-abused-recursive-windows-junctions-to-hide-malware/] [General Security News] * Google Vertex AI SDK Flaw Allowed Cross-Tenant Model Hijacking (Pickle in the Middle) [https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/] [General Security News] * China Arrests 67 Suspects Linked to Silver Fox Cybercrime Group [https://news.risky.biz/risky-bulletin-china-arrests-members-of-silver-fox-cybercrime-group/] [General Security News] * Chrome Extensions Steal AI Conversations (PromptSnatcher Campaign) [https://thehackernews.com/2026/06/malicious-jetbrains-plugins-steal-ai.html] [General Security News] * China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth [https://thehackernews.com/2026/06/china-linked-sprysocks-backdoor-expands.html] [General Security News] * New Rokarolla Android Malware Targets 217 Banking and Crypto Apps [https://www.bleepingcomputer.com/news/security/new-rokarolla-android-malware-targets-217-banking-crypto-apps/] [General Security News] * FTC Warns of Record $3.5 Billion Losses to Imposter Scams in 2025 [https://www.bleepingcomputer.com/news/security/ftc-warns-of-record-35-billion-losses-to-imposter-scams-in-2025/] [General Security News] * Rockwell Automation FLEX I/O EtherNet/IP Adapters (CVE-2026-0646, CVE-2026-0647) [https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05] [Vulnerability Disclosures] * Rockwell Automation RSLinx Classic (CVE-2020-13573) [https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-02] [Vulnerability Disclosures] * Rockwell Automation Logix 5370 & 5570 Controllers (CVE-2026-11317) [https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-03] [Vulnerability Disclosures] * Rockwell Automation FactoryTalk Analytics PavilionX (CVE-2025-14272) [https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-01] [Vulnerability Disclosures] * Chrome and Firefox Memory Safety Updates [https://www.securityweek.com/chrome-and-firefox-updated-to-patch-critical-high-severity-vulnerabilities/] [Vulnerability Disclosures] CVES REFERENCED CVE-2020-13573, CVE-2023-52271, CVE-2025-1055, CVE-2025-14272, CVE-2025-61155, CVE-2026-0646, CVE-2026-0647, CVE-2026-11317, CVE-2026-25089, CVE-2026-39808, CVE-2026-39813, CVE-2026-48907, CVE-2026-50656, CVE-2026-54420 INDICATORS OF COMPROMISE IP Addresses: 2.9.99.4, 2.9.99.5, 39.107.60.51 Read the full brief [https://carolinacleartech.com/brief/2026-06-17/]
90 jaksot
Kommentit
0Ole ensimmäinen kommentoija
Rekisteröidy nyt ja liity Cyber Threat Brief-yhteisöön!