🚨 ACTIVE EXPLOITS & INCIDENTS
- LastPass Confirms Data Breach in Klue Supply Chain Attack — BleepingComputer Hackers accessed LastPass customer data via stolen OAuth tokens from its Salesforce environment following the Klue supply chain compromise earlier this month. Immediate review of OAuth token usage and Salesforce integrations recommended.
- Canadian Electricity Provider London Hydro Discloses Data Breach — SecurityWeek Customer PII including names, addresses, emails, phone numbers, and account info was stolen in a breach. Energy sector orgs should verify exposure and monitor for follow-on attacks.
- Russian Initial Access Broker Behind FortiBleed Campaign — SecurityWeek A threat actor using a custom sniffer has harvested over 110 million credentials since Feb 2026 through FortiBleed exploits. Organizations using vulnerable Fortinet devices must urgently patch and audit for compromise.
🔓 VULNERABILITIES & CVEs
- CVE-2026-9082: Highly Critical SQL Injection in Drupal Core — Tenable Unauthenticated attackers can exploit this SQLi in Drupal’s database abstraction layer on PostgreSQL sites. Public PoC available; patches released across six supported branches. Immediate patching required for affected Drupal instances.
- CVE-2026-20182: Critical Cisco Catalyst SD-WAN Authentication Bypass Under Active Exploitation — Tenable Multiple threat groups actively exploiting this 10.0 CVSS auth bypass zero-day since May 2026. Patches available; CISA has mandated remediation. Urgent patch and network segmentation advised for Cisco SD-WAN deployments.
- Dirty Frag (CVE-2026-43284, CVE-2026-43500): Linux Kernel Local Privilege Escalation — Tenable Public exploit code released for chained kernel LPE vulnerabilities affecting multiple Linux distros. Patch releases expected imminently; mitigations currently limited. Linux hosts should prioritize kernel updates.
- Fragnesia (CVE-2026-46300): New Linux Kernel Privilege Escalation — Tenable Follow-up local LPE targeting Linux kernel XFRM ESP-in-TCP subsystem with public PoC. Patch released May 13; existing Dirty Frag patches do not cover this flaw. Linux admins must apply latest kernel updates.
- Microsoft June 2026 Patch Tuesday: 198 CVEs, Including 3 Zero-Days — Tenable Largest Patch Tuesday ever with 32 critical and 166 important CVEs fixed. Notable patches include .NET, Active Directory, Azure services, and Copilot Chat. Immediate prioritization of zero-day patches CVE-2026-49160, CVE-2026-50507 advised.
- Oracle June 2026 Critical Patch Update: 243 CVEs, 122 Critical — Tenable Oracle Fusion Middleware hardest hit with 106 patches. Monthly CSPU introduced for faster high-severity fixes. Critical patching recommended for Oracle environments to reduce exposure.
🕵️ THREAT RESEARCH & DEEP DIVES
- Mini Shai-Hulud: Self-Propagating Worm Compromises 170+ npm and PyPI Packages — Tenable TeamPCP’s worm bypassed SLSA Build Level 3 provenance attestations, stealing developer and cloud credentials, including from OpenAI and Mistral AI. Any system with affected packages must be treated as fully compromised. Supply chain security controls need reassessment.
- Weaponizing Vulnerabilities Before Public Exploits Exist — BleepingComputer Picus Security highlights how attackers rapidly weaponize disclosed vulnerabilities and how defenders can validate exploitability pre-exploit release. Emphasizes proactive vulnerability management and exploit simulation.
- FFmpeg PixelSmash Flaw Enables RCE via Crafted Media Files — SecurityWeek Critical RCE in libavcodec affects video players, media servers, NAS appliances. Attackers can execute arbitrary code by sending malicious media files. Patch or mitigate vulnerable FFmpeg versions immediately.
📋 VENDOR BULLETINS & ADVISORIES
- GitHub Updates actions/checkout to Block Pwn Request Attack Patterns — The Hacker News GitHub patched “actions/checkout” to prevent abuse of the “pull_request_target” workflow trigger, which could allow malicious code execution with full workflow privileges. DevSecOps teams should upgrade to the latest action version to mitigate supply chain risks.
- Verizon DBIR 2026: Vulnerability Exploitation Surges as Patching Slows — Tenable Vulnerability exploitation is now the top initial access vector (31% of breaches). Median patch time increased by 11 days. Highlights urgent need for continuous exposure management and automated remediation orchestration.
📰 LESSER-KNOWN / UNDER-REPORTED
- Hacker Hijacks Brazil’s National Alert System, Sends False Emergency Messages — Graham Cluley Attack on Brazil’s emergency alert system undermines public trust by sending false “misanthropy” alerts to millions. Highlights risks in critical infrastructure alerting systems and the need for hardened access controls.
🔍 2 new social source(s) auto-discovered:
- [twitter] @jonasLyk — from Microsoft June 2026 Patch Tuesday coverage
- [twitter] @fabian_bader — from Microsoft June 2026 Patch Tuesday coverage