Cyber Threat Brief
SHOW NOTES - 2026-06-20 STORIES COVERED * Today: * CISA: Splunk Enterprise flaw actively exploited, patch by Sunday (CVE-2026-20253) [https://www.bleepingcomputer.com/news/security/cisa-splunk-enterprise-flaw-actively-exploited-patch-by-sunday/] [Critical Alerts] * FortiBleed: 86,000 Fortinet Device Credentials Compromised [https://www.securityweek.com/fortibleed-86000-fortinet-device-credentials-compromised/] [Critical Alerts] * The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes [https://thehackernews.com/2026/06/the-gentlemen-raas-uses-gentlekiller.html] [Ransomware & Extortion] * DragonForce Abuses Microsoft Teams Relays to Conceal Backdoor Traffic [https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-25-7/] [Ransomware & Extortion] * Klue OAuth breach victim list grows as Icarus hackers claim attack [https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/] [Ransomware & Extortion] * Threat Brief: Mitigating Large-Scale Credential Attacks (FortiBleed) [https://unit42.paloaltonetworks.com/large-scale-credential-attacks/] [Business & Infrastructure Threats] * CryptoBandits Malware Doubles as a Backdoor, Abuses Tor [https://www.securityweek.com/cryptobandits-malware-doubles-as-a-backdoor-abuses-tor/] [Business & Infrastructure Threats] * Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites [https://thehackernews.com/2026/06/operation-endgame-disrupts-socgholish.html] [Business & Infrastructure Threats] * Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin (CVE-2026-4020) [https://www.bleepingcomputer.com/news/security/hackers-exploit-info-disclosure-bug-in-gravity-smtp-wordpress-plugin/] [Business & Infrastructure Threats] * 1.2 million WordPress sites compromised in OptinMonster supply chain attack [https://www.securityweek.com/in-other-news-apple-patches-beats-eavesdropping-flaw-dot-closes-delta-crowdstrike-probe-aws-continuum/] [Business & Infrastructure Threats] * Texas govt data breach exposes over 3 million driver's licenses [https://www.bleepingcomputer.com/news/security/texas-govt-data-breach-exposes-over-3-million-drivers-licenses/] [Business & Infrastructure Threats] * Authorities Dismantle PhaaS Network & Clean Sites Infected with SocGholish [https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-25-7/] [General Security News] * MaXSS and Spyder flaws expose 10 million Chrome users to hacking [https://www.securityweek.com/in-other-news-apple-patches-beats-eavesdropping-flaw-dot-closes-delta-crowdstrike-probe-aws-continuum/] [General Security News] * 10-year-old phpBB flaw enables session hijacking [https://www.securityweek.com/in-other-news-apple-patches-beats-eavesdropping-flaw-dot-closes-delta-crowdstrike-probe-aws-continuum/] [General Security News] * JetBrains Marketplace plugins steal developer AI keys [https://www.securityweek.com/in-other-news-apple-patches-beats-eavesdropping-flaw-dot-closes-delta-crowdstrike-probe-aws-continuum/] [General Security News] * AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution (CVE-2026-25592, CVE-2026-26030) [https://thehackernews.com/2026/06/autojack-attack-lets-one-web-page.html] [General Security News] * Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain [https://thehackernews.com/2026/06/unpatchable-usbliter8-exploit-breaks.html] [General Security News] * Avada Builder WordPress plugin (CVE-2026-8713) [https://www.bleepingcomputer.com/news/security/hackers-exploit-info-disclosure-bug-in-gravity-smtp-wordpress-plugin/] [Vulnerability Disclosures] * Microsoft: June 2026 Windows updates break Recycle Bin prompts [https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-recycle-bin-bug-on-all-supported-windows-releases/] [Vulnerability Disclosures] * Chromium CVEs (CVE-2026-12446, CVE-2026-12458, CVE-2026-12439, CVE-2026-12447, CVE-2026-12453, CVE-2026-12459, CVE-2026-12460, CVE-2026-12454) [https://msrc.microsoft.com/update-guide/] [Vulnerability Disclosures] CVES REFERENCED CVE-2026-12439, CVE-2026-12446, CVE-2026-12447, CVE-2026-12453, CVE-2026-12454, CVE-2026-12458, CVE-2026-12459, CVE-2026-12460, CVE-2026-20253, CVE-2026-25592, CVE-2026-26030, CVE-2026-4020, CVE-2026-8713 INDICATORS OF COMPROMISE IP Addresses: 0.4.2.2 Read the full brief [https://carolinacleartech.com/brief/2026-06-20/]
90 afleveringen
Reacties
0Wees de eerste die een reactie plaatst
Meld je nu aan en word lid van de Cyber Threat Brief community!