🚨 ACTIVE EXPLOITS & INCIDENTS
- Critical Gitea Flaw Under Active Exploitation — SecurityWeek Attackers are actively exploiting CVE-2026-20896, a critical Gitea authentication bypass vulnerability (CVSS 9.8) that allows unauthorized access to repositories and secrets via a single HTTP header. Immediate patching is strongly advised to prevent compromise of source code and credentials.
- Chinese Hackers Develop LONGLEASH Malware to Expand ORB Network — BleepingComputer Chinese threat group UAT-7810 is evolving LONGLEASH malware to compromise unpatched internet-facing Ruckus routers, expanding their Operational Relay Box (ORB) network for stealthy command and control. Network device hardening and patching are critical to disrupt this active campaign.
- Continued Exploitation of Cisco Catalyst SD-WAN Vulnerabilities (CVE-2026-20182) — Tenable Multiple critical authentication bypass flaws in Cisco Catalyst SD-WAN Controller/Manager (CVSS 10.0) are under active exploitation by sophisticated threat actor UAT-8616 and others. Patches are available; urgent remediation is mandated by CISA to prevent full network compromise.
- County Government Paid $1 Million Ransom to Cyber Extortion Group — SecurityWeek A small Ohio county reportedly paid $1M to prevent public release of stolen sensitive data. This incident underscores the ongoing risk of ransomware/extortion impacting local governments and the importance of incident response readiness.
🔓 VULNERABILITIES & CVEs
- CVE-2026-9082: Highly Critical SQL Injection in Drupal Core — Tenable A critical SQL injection (CVSS 9.8) affects Drupal core’s database abstraction layer on PostgreSQL sites, exploitable by unauthenticated attackers. Exploitation attempts observed; patches available across six supported branches. Immediate patching required for affected Drupal deployments.
- Dirty Frag Linux Kernel Privilege Escalation (CVE-2026-43284, CVE-2026-43500) — Tenable A chained local privilege escalation vulnerability with public exploit code targets Linux kernels, enabling root access. Patches forthcoming; affected systems should apply updates promptly and monitor for exploitation attempts.
- Fragnesia (CVE-2026-46300): New Linux Kernel Privilege Escalation — Tenable A new local privilege escalation exploit with public PoC affects the Linux kernel’s XFRM ESP-in-TCP subsystem. Patch released May 13; existing Dirty Frag patches do not cover this flaw. Ubuntu systems confirmed vulnerable; immediate patching recommended.
🕵️ THREAT RESEARCH & DEEP DIVES
- Mini Shai-Hulud: Self-Propagating Supply Chain Worm in npm & PyPI — Tenable TeamPCP’s Mini Shai-Hulud worm compromised 170+ npm and PyPI packages, bypassing SLSA Build Level 3 provenance attestations and stealing developer/cloud credentials, including from OpenAI and Mistral AI. Any system installing affected packages should be treated as fully compromised.
- Verizon DBIR 2026: Vulnerability Exploitation Surges as Patch Times Lag — Tenable Vulnerability exploitation is now the top initial access vector (31% of breaches), while median patch times increased by 11 days year-over-year. AI-powered discovery accelerates exploit availability, emphasizing the need for continuous exposure management and automated remediation.
- RedWing MaaS: Android Bank Fraud Offered as Telegram Rental Service — The Hacker News RedWing, a new Android malware-as-a-service, enables low-skill criminals to hijack phones, steal banking credentials, and intercept OTPs. Resembling the Oblivion malware, it rents for ~$300/month on Telegram, lowering the barrier for mobile banking fraud.
- Rogue Agent Flaw in Google Dialogflow CX Could Hijack Chatbots — The Hacker News A critical flaw allows attackers with edit rights on one Code Block-enabled Dialogflow CX agent to compromise others in the same Google Cloud project, reading live conversations and injecting malicious messages. Fixes have been deployed; review permissions and patch immediately.
📋 VENDOR BULLETINS & ADVISORIES
- Microsoft June 2026 Patch Tuesday: 198 CVEs, Including 3 Zero-Days — Tenable Largest Patch Tuesday ever with 198 CVEs fixed (32 critical), including three zero-days. Key patches cover .NET, ASP.NET Core, Active Directory, Azure services, and Copilot Chat. Immediate deployment advised to mitigate active threats.
- Oracle June 2026 CSPU: 243 CVEs, 122 Critical — Tenable Oracle’s June CSPU delivers 245 patches addressing 243 CVEs, nearly half critical. Fusion Middleware is heavily impacted (106 patches). Organizations should prioritize patching to reduce exposure.
- AWS Enforces Zero Data Retention on Amazon Bedrock — AWS Security Blog Amazon Bedrock introduces controls to enforce zero data retention on AI inference requests, critical for compliance when using third-party AI models like Claude Fable 5. Security teams should review and apply service control policies accordingly.
📰 LESSER-KNOWN / UNDER-REPORTED
- Hidden Backdoor in Tenda Router Firmware Grants Admin Access — BleepingComputer Multiple Tenda router firmware versions contain a hidden authentication backdoor allowing attackers admin web panel access. Given widespread deployment, affected devices should be updated or isolated to prevent compromise.
- More Odd DNS Records: NIMLOC — SANS ISC Technical deep dive into NIMLOC DNS records, an uncommon but significant DNS record type observed in logs. Useful for SOC analysts monitoring unusual DNS activity or investigating RCS-related infrastructure.