Daily cybersecurity intelligence digest for 14 June 2026. Our automated collection pipeline processed feeds from BleepingComputer, The Hacker News, SecurityWeek, Help Net Security, KrebsOnSecurity, the CISA Known Exploited Vulnerabilities catalogue and ransomware.live data-leak-site monitoring. Below is today’s prioritised analysis.
1. Critical alerts (score ≥ 10)
- [11] [RANSOMWARE] lapsus$ leaked INGKA GROUP (ransomware.live)
A major data-leak event affecting INGKA GROUP (SE). This represents a high-severity breach with substantial organisational exposure and should be treated as a priority for affected supply chains.
2. CISA Known Exploited Vulnerabilities (last 14 days)
No new CISA KEV catalogue additions were recorded in today’s collection window.
3. Ransomware victims — data-leak-site monitoring
- lapsus$: INGKA GROUP (SE); GITHUB INTERNAL (US)
- shinyhunters: coe.int (FR)
- krybit: www.mbt-energy.com (DE)
- securotrop: Charisma Media (US)
- Black X: Daechang Solution (KR)
- Triple X: Bni.co.id bank of indonesia free data. (ID); Law Offices US immigrationonline.com (US)
Listings reflect claims published on criminal data-leak sites and have not been independently verified. Organisations named should treat these as alleged compromises pending confirmation.
4. Security news (score ≥ 5)
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication (CVE-2026-20253) — TheHackerNews. Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked
5. Summary
- Total new items analysed: 15
- Critical items (score ≥ 10): 1
- CISA KEV additions: 0
- Ransomware data-leak victims: 8 across 6 active group(s)
- CVEs to prioritise for patching: CVE-2026-20253
The most pressing patching priority today is CVE-2026-20253 — organisations running affected software should apply the vendor update without delay given the unauthenticated remote-code-execution risk.
Active ransomware operators today: Black X, Triple X, krybit, lapsus$, securotrop, shinyhunters. Defenders should review external attack surface, enforce multi-factor authentication, and validate offline backups.
Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live
Leave a Reply