Cybersecurity Intelligence Report — 11 June 2026

Written by

in

Critical Section — Zero-Day / RCE / Exploited in the Wild

The following threats represent the highest risk to organisations and require immediate attention:

[17] Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
Source: TheHackerNews

[17] Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert
Source: HelpNetSecurity | CVEs: CVE-2026-35273

[15] Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild – Patch Now
Source: TheHackerNews | CVEs: CVE-2026-11645

[12] Microsoft patches Exchange Server zero-day exploited in attacks
Source: BleepingComputer

[11] LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
Source: TheHackerNews | CVEs: CVE-2026-42271

[11] [RANSOMWARE] dragonforce leaked importservices.co.uk
Source: ransomware.live/dragonforce

[11] [RANSOMWARE] dragonforce leaked ukimportservices.com
Source: ransomware.live/dragonforce

[11] [RANSOMWARE] coinbasecartel leaked NGC Software
Source: ransomware.live/coinbasecartel

CISA Known Exploited Vulnerabilities (Last 14 Days)

The following vulnerabilities are being actively exploited and have been added to CISA’s Known Exploited Vulnerabilities catalogue:

CVEProductScoreAction Required
CVE-2026-28318SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerab8Apply mitigations per vendor instructions, follow applicable
CVE-2026-0257Palo Alto Networks PAN-OS Authentication Bypass Vulnerabilit8Apply mitigations per vendor instructions, follow applicable
CVE-2026-11645Google Chromium V8 Out-of-Bounds Read and Write Vulnerabilit5Apply mitigations per vendor instructions, follow applicable
CVE-2026-7473Arista Extensible Operating System Incomplete Comparison wit5Apply mitigations per vendor instructions, follow applicable
CVE-2026-20245Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping 5Apply mitigations per vendor instructions, follow applicable
CVE-2026-42271BerriAI LiteLLM Command Injection Vulnerability – BerriAI Li5Apply mitigations per vendor instructions, follow applicable
CVE-2026-50751Check Point Security Gateway Improper Authentication Vulnera5Apply mitigations per vendor instructions, follow applicable
CVE-2026-45247Mirasvit Full Page Cache Warmer Deserialization of Untrusted5Apply mitigations per vendor instructions, follow applicable
CVE-2022-0492Linux Kernel Improper Authentication Vulnerability – Linux K5Apply mitigations per vendor instructions, follow applicable
CVE-2025-48595Android Framework Integer Overflow Vulnerability – Android F5Apply mitigations per vendor instructions, follow applicable
CVE-2024-21182Oracle WebLogic Server Unspecified Vulnerability – Oracle We5Apply mitigations per vendor instructions, follow applicable

Ransomware Victims (DLS Monitoring)

Active ransomware groups with recent victims posted on data leak sites:

  • lockbit3 (2016): texline-global.com, fairfieldmemorial.org, inphenix.com, craigwire.com, tuttoperlufficio.eu (+2011 more)
  • qilin (1921): Erie Management Group, LLC, Town of Chatham, MASSACHUSETTS, ClearCare Periodontal & Implant Centre, Patterson Health Center, Marc Dorcel (+1916 more)
  • akira (1519): TSG Enterprises, Manhattan Broadcasting, Pipestone, ATF Aerospace, French Engineering (+1514 more)
  • play (1265): One Source Associates, Cortez Resources, Accounting Resource Group, The Rubber Resources, Lambda Energy Resources (+1260 more)
  • clop (1254): JAGGEDPEAK.COM, APTEAN.COM, OUTSOURCELOGISTICS.COM, JPWEST.COM, WORKFORCESOFTWARE.COM (+1249 more)
  • lockbit2 (1002): arcelormittal.h…, liceu.barcelon, liceu.barcelona, meritresources, meritresources…. (+997 more)
  • ransomhub (842): www.hexosys.com, www.townofbourne.com, www.obrienavocats.qc.ca, www.confabca.com, headcount.com (+837 more)
  • incransom (824): bayviewci.org, WellLife Network Inc., Pennsylvania Office of Attorney General, Darlington EMS, Mecanizados y Montajes Aeronáuticos (mymgroup.es) (+819 more)
  • alphv (731): James Group, ResultsCX | The result of many unknown breaches?, Petrus Resources Ltd, ANDFLA SRL, The Source (+726 more)
  • dragonforce (571): importservices.co.uk, ukimportservices.com, Gruenberg Kelly Della, sphvalue.com, Advanced Rehabilitation Technology (+566 more)
  • bianlian (552): Encompass Technologies, Northern Minerals Limited, Aspire Rural Health System, Saunders and Saunders, Legal Aid Society of Salt Lake (+547 more)
  • blackbasta (523): snatt.it, celo.com, memc.com, atlasoil.com, theshootingwarehouse.com (+518 more)
  • medusa (517): Macildowie Associates, Expert E-commerce GmbH, Philip Laney & Jolly, Prosolit, Resource Corporation of America (+512 more)
  • safepay (490): bootstransport.ca, briwaycarriers.com, gsglobalresources.com, 47club.jp, wachtmann.eu (+485 more)
  • thegentlemen (478): Paltrack, KlearNow.AI, Empty, FESCO Adecco, Internal Medicine (+473 more)

Additional Security News

[9] Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues — TheHackerNews

[9] Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer — TheHackerNews

[8] Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities — TheHackerNews

[8] Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code — TheHackerNews

[8] ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More — TheHackerNews

[7] CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog — TheHackerNews

[7] Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available — TheHackerNews

[7] Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks — SecurityWeek

Priority CVEs to Patch

CVEMentionsPriority
CVE-2026-202453CRITICAL
CVE-2026-352732HIGH
CVE-2026-116452HIGH
CVE-2026-422712HIGH
CVE-2026-283182HIGH

Full HTML Report (CSSLTD Dashboard)

Summary

  • New unique items: 28931
  • Critical alerts (score >= 10): 49
  • CISA KEV additions in last 14 days: 11
  • Active ransomware groups: 327
  • Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

Report generated automatically by Hermes AI. Data collected daily at 04:00 UTC.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *