Skip to content
Marcus Reed | CISO Intel

Daily Threat Intelligence  ·  CVE & Zero-Day Tracking  ·  APT & Ransomware Analysis

Go back

CISO Intel Brief — Sunday, 21-06-2026

🛡️ CISO Intel — Sunday, 21-06-2026

Blog generation failed — API error. Presenting Discord briefing as fallback.

The wire is not quiet. Let’s get to it.

🔴 Critical Threats & Active Exploitation

Splunk EnterpriseCVE-2026-20253 (CISA KEV, no CVSS yet but “Critical”) — unauthenticated file create/truncate via PostgreSQL sidecar endpoint; enables unauthenticated remote code execution. CISA confirmed active exploitation. Patch today. 📌 Source: Threat-Modeling.com — https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHQnXQITpTrscrkakdTFWB0TBSyb0OkRCdDJtCuoEVJOkUEx2oL-OoGbSxYdnwZRrAA38830JA_g-TsyOv93wUComMBR1mg9O8fBXiopq8jPwknSL3Z_ybjLj54ILQLHgvr4QEKFJypqaEWrNdvZPajhqU5fCQe_AZ_xXwzrK4gYGeVFmU= Gravity SMTP (WordPress Plugin)CVE-2026-4020 (CVSS 5.3, but actively exploited) — information disclosure allowing unauthenticated attackers to extract sensitive data like API keys and OAuth tokens. This is being actively exploited in the wild. Rotate credentials immediately if you’re running a vulnerable version. 📌 Source: The Hacker News · Threat-Modeling.com — https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEPJBuumTzZ3VLkf5woGtr8S3VaMTbLycOv3QkGXwEX04MgNbwcX8tFV1Q9V8Xd-c6qWCLZu_psvIApBK1lm2gC0cQ1KnxUoJY7QjdzvpPwC-CAZK1uMZG0__xmvgcNQDv6d7z9dOLZ0i6-2ynjvwmFhkpp6p9ReDTI7Nax3M7eAwJ2K2UFfA= Ivanti SentryCVE-2026-50751 (Critical) — command injection flaw. Exploitation observed within 24 hours of public PoC availability. Patch immediately. 📌 Source: Tenable — https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEFzaT8pSJvTqnjKwmbbaxKffzZNlNcMId4Qp1n1kJBXiaYtFMSwjuUPjxmpYLmGPDUgLg1B-fPmziD_pZ3EHARQRh6aCNLNj5-qhpfBcEpgmbtg6w= Cisco SD-WAN ManagerCVE-2026-35273 (Critical) — zero-day exploited in the wild. Requires credentials for exploitation, but still critical. Patch available. 📌 Source: Tenable — https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEFzaT8pSJvTqnjKwmbbaxKffzZNlNcMId4Qp1n1kJBXiaYtFMSwjuUPjxmpYLmGPDUgLg1B-fPmziD_pZ3EHARQRh6aCNLNj5-qhpfBcEpgmbtg6w= Check Point Remote Access VPNCVE-2026-48907 (Critical) — authentication bypass vulnerability. Reports indicate exploitation. Immediate patching is recommended. 📌 Source: Tenable — https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQEFzaT8pSJvTqnjKwmbbaxKffzZNlNcMId4Qp1n1kJBXiaYtFMSwjuUPjxmpYLmGPDUgLg1B-fPmziD_pZ3EHARQRh6aCNLNj5-qhpfBcEpgmbtg6w= Microsoft DefenderCVE-2026-50656 (CVSS 7.8) — “RoguePlanet” zero-day, local privilege escalation via race condition. Microsoft is working on a patch; previously disclosed by researcher Nightmare Eclipse. Affects Windows 10/11. 📌 Source: The Hacker News · Help Net Security — https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHS65HjjAu1kSEqAumaFU_lBnIeXNDz9-tF0foaNyKCvTRechRedv4owsf5taGtLCvYutSpaG597F1sc9Gv9bWguOpDkhoAGQW0j3hvJn6TWu-z6p0sfC7atVHeVcSEHehqoXcEVBuRyJMFsXS0iN_ESBrPUsp9i_lAFt5tpwHDmAASb9KQFRd3

🛡️ CVEs Worth Your Attention

CVE-2026-12048 | pgAdmin 4 | CVSS 9.3 | Stored XSS in error/plan-node rendering. Attacker controlling database content can execute JS in pgAdmin user’s browser. PoC: Yes (implied by advisory details). CVE-2026-12046 | pgAdmin 4 | CVSS 9.0 | Impact not fully detailed, likely privilege escalation or RCE. PoC: Yes (implied). CVE-2026-12045 | pgAdmin 4 | CVSS 9.0 | Impact not fully detailed, likely privilege escalation or RCE. PoC: Yes (implied). CVE-2026-12044 | pgAdmin 4 | CVSS 8.8 | SQL injection. PoC: Yes (implied). CVE-2026-12772 | BerriAI litellm up to 1.82.2 | CVSS N/A (Exploitability difficult) | Session expiration via authenticate_user in login_utils.py. Remote attack. PoC: Yes. CVE-2026-12771 | BerriAI litellm up to 1.82.2 | CVSS N/A (Exploitability difficult) | Improper authorization in user_api_key_auth.py M2M JWT Handler. Remote attack. PoC: Yes. CVE-2026-12770 | BerriAI litellm up to 1.63.1 | CVSS N/A | Improper authorization in key_management_endpoints.py Admin Key Handler. Remote attack. PoC: Yes. CVE-2026-42945 | NGINX | Critical | New critical vulnerability affecting NGINX. Details scarce, but flagged as critical. PoC: No (not explicitly stated as public). 📌 Sources: Threat-Modeling.com · Tenable · The Stack — https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHQnXQITpTrscrkakdTFWB0TBSyb0OkRCdDJtCuoEVJOkUEx2oL-OoGbSxYdnwZRrAA38830JA_g-TsyOv93wUComMBR1mg9O8fBXiopq8jPwknSL3Z_ybjLj54ILQLHgvr4QEKFJypqaEWrNdvZPajhqU5fCQe_AZ_xXwzrK4gYGeVFmU=

⚡ New TTPs & Attack Research

AI-Augmented Fraud & Democratization of Cybercrime — Phishing-as-a-Service ecosystem “Outsider Enterprise” dismantled. This platform enabled low-skill actors to create convincing phishing sites using automated tooling and AI-assisted content generation (T1589.002, T1566.001). This lowers the bar for entry into cybercrime significantly. Ransomware Shift to Data Brokering — Modern ransomware groups increasingly operate as data brokers, extortion specialists, and information traders, focusing on IP theft and sensitive data exfiltration beyond just operational disruption. (T1560.001, T1567.002). ClickOnce Framework Abuse — An actively researched technique bypasses email filters and EDR behavioral rules by abusing the ClickOnce framework. No patch available, requiring detection engineering and hardening. (T1566.001, T1059.001). BitLocker Bypass with YellowKey — A zero-day exploit “YellowKey” allows bypassing BitLocker protections on Windows 11. Requires physical access, but poses a significant threat to encrypted data confidentiality. (T1529, T1070.004). Microsoft has patched this in the June updates. 📌 Sources: Balasubramaniam · Tech Jacks Solutions · The Stack · Bleeping Computer — https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQF4-Dvgl10lon51cob4dKDo-szzP110ThYCMca7dtftEWuKpfXjlMRkCBfJKp0wehnjdFSEqUVMMmirCWAMdU76AHyc8n-QuEzSTclxDuB5UM6NYfg4alJMwB5gMxJ0Kka-8W5cxopVTHTNLzGfstOi5zfATfcSNZ1qOb0TlcedvbKBYMqWPfI=

🏗️ DevSecOps & Cloud Security

Malicious npm/PyPI/RubyGems packages: [Clear — enjoy it] Developer Toolchain as Attack Surface: Microsoft is now shipping fixes for its editor (Visual Studio Code) and AI assistant (GitHub Copilot) on the same advisory sheet as the OS. CVE-2026-47281 (VS Code EoP) and CVE-2026-45482 (Copilot Chat extension bypass) highlight that cloning a repo can now hand an attacker your AI session. This is a significant shift in initial access tactics. (T1195.002, T1566.001). 📌 Source: Automox — https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQFbqCTimyzsFSHigJ7A3wG_rnv1xwkmvdQJacZU32ppewlrdzQycgzpb04hv1EM8d3AlGXROLoyiFsWHxswTIGMiRzX1R8dGNvnnf8XYRD2CG_oH9-dacu4kx5H3r5tD2Pg_Oh2mIUXbEtwwnkt7C4Q1w=

🔧 Patches & Vendor Releases

Microsoft June 2026 Patch Tuesday: A record 206 CVEs addressed, including three publicly disclosed zero-days and one actively exploited. Includes critical RCEs in HTTP.sys and Windows Kernel TCP/IP stack. (Note: These were released earlier in June, but the implications and ongoing exploitation are still relevant).

🧪 Threat Intel & Malware

Payload Ransomware Group: Emerged in early 2026, using Babuk-derived source code. Targets Windows and ESXi with double-extortion tactics against healthcare, energy, real estate, and agriculture. Claimed 12 victims across seven countries within hours of launching its leak site. Last discovered victim: 2026-06-20. Nova Ransomware Group (formerly RALord): Active ransomware-as-a-service (RaaS) group using double-extortion. Last discovered victim: 2026-06-21. “Icarus” Threat Actor / Klue OAuth Breach: Victim list continues to expand, with new claims of Salesforce data theft. This highlights ongoing supply chain risk and credential compromise. 📌 Sources: Ransomware.live · Threat-Modeling.com — https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQGv1bHwuICT8FyPZqfxavwfRk6AJUVaMURiA_Yi_NI3HxqJLvhiTifGIe5-81nXfacXZ32LrqsMgpTQLZ34JrKAB5aO2kkp6LygS31oL2PPX9niwVaECxbQSU8R5U7XUNiH_A==

🌐 Industry, Brand & Internet Security

Texas Government Data Breach: Over 3 million Texas hunting and fishing license holders had their driver’s license information, passport numbers, email addresses, phone numbers, and home addresses exposed. Attributed to a breach at a third-party licensing vendor. No SSNs or financial info reportedly accessed. Coupang Data Breach Fine: South Korean e-commerce company Coupang fined ₩624.68 billion (US$408 million) for a data breach exposing personal data from millions of user accounts. Malaysian NRD Data Leak Claims: National Registration Department (NRD) of Malaysia denies recent social media claims of a data leak, stating the claims refer to older incidents (2021-2022) involving an external agency. They emphasize continuous monitoring and enhanced cybersecurity. 📌 Sources: Threat-Modeling.com · CBS Broadcasting Inc. · Wikipedia · The Star — https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHRxa94b_bwCflp_j8I2duYN23KbjoA3aOUdCrXRBsggnYgxRgRY_xcffwKIOgwJQPl7gdS_x7nzW9FfE95yX9TNrUQrpqhKZWbBfx95l87FxBy3IQxF1-fKaS9VZ8fRC-fhL5OYs7Xp0Rk6RbNDgZyTPtzC0qbstSbED51fSTyASaL_ZlMH4lQG_VBkPdsGEI=

🤖 AI & LLM Security

US Executive Order on AI Security: White House issued an EO on June 2, 2026, “Promoting Advanced Artificial Intelligence Innovation and Security.” It establishes a voluntary framework for AI model developers to provide federal government access for cybersecurity and national security assessments prior to public release. Directs agencies to strengthen cyber defenses, establish an AI cybersecurity clearinghouse, and prioritize enforcement against AI-enabled cyberattacks. 2026 Cybersecurity Awareness Month Theme: “Navigating Trust in an AI World.” Focuses on employees recognizing deepfakes, voice-cloning, AI-powered phishing, and applying digital trust strategies. Highlights the increasing sophistication of AI-driven deception. AI-Native Threat Intelligence: Vendors like Cyble are branding themselves as “AI-native” for autonomous threat detection and analysis, mapping IOCs to MITRE ATT&CK. This indicates a market shift towards AI in defensive tools. AI-Driven Fraud Reshaping Identity: Threat Intelligence Report 2026 highlights deepfakes and injection attacks as reshaping identity fraud. Real-time deepfakes are defeating human verification. 📌 Sources: Holland & Knight · Living Security · Flare · iProov — https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQH7VYSxJgykUM0iniXxFBo_ljRQT1Ztmsop9epounsNu0jAHDfc8XUf6eg_Z4QZ7fQi0xtGnBg3QHrLhCCYJYbY15zFYkwSQAS0s45tyPMhvEDOT7FB3U2O2VYZ1SblYnsBRDT6de9DJqVKahVHP8H9EOe5g9BKV7X64425hvsbH4wOC3_SM0wLbLu0u_fo1Tq5ZLaBxvUuRZzCXzCDjaYM0wHGZtDk1jA27YfcdZvrWg==

📋 Compliance & Regulatory

CISA BOD 26-04 Enforcement: The deadline for Splunk Enterprise CVE-2026-20253 (now actively exploited) is today, Sunday, June 21, 2026. Federal Civilian Executive Branch (FCEB) agencies must prioritize remediation for KEV catalog vulnerabilities. All organizations should follow suit. 📌 Source: Threat-Modeling.com — https://vertexaisearch.cloud.google.com/grounding-api-redirect/AUZIYQHQnXQITpTrscrkakdTFWB0TBSyb0OkRCdDJtCuoEVJOkUEx2oL-OoGbSxYdnwZRrAA38830JA_g-TsyOv93wUComMBR1mg9O8fBXiopq8jPwknSL3Z_ybjLj54ILQLHgvr4QEKFJypqaEWrNdvZPajhqU5fCQe_AZ_xXwzrK4gYGeVFmU=

💡 Marcus’s Take

Another Sunday, another reminder that threat actors don’t take weekends. The Splunk KEV deadline today, now confirmed actively exploited, is a gut punch. It’s not just the vulnerability; it’s the timing and the potential blast radius across every SOC using it.

Beyond the critical patches, the shift in ransomware tactics to data brokering and the sheer accessibility of AI-powered fraud tools are changing the game. We’re not just fighting skilled hackers; we’re fighting an industrialized criminal ecosystem. Your developers are now frontline targets, and your security awareness programs need to evolve to counter AI-driven deception. Stop chasing CVSS scores in a vacuum; focus on what’s actually being exploited and where your data lives.


Share this post on:

Previous Post
CISO Intel Brief — Monday, 22-06-2026
Next Post
CISO Intel Brief — Saturday, 20-06-2026