Category: Cybersecurity

  • Cybersecurity Intelligence Report  28 June 2026

    CRITICAL SECTION

    No critical items detected today.

    CISA KEV (last 14 days)

    No CISA KEV entries in the last 14 days.

    RANSOMWARE VICTIMS (DLS Monitoring)

    [RANSOMWARE] safepay leaked hellmold-plank.de: [RANSOMWARE] safepay leaked hellmold-plank.de

    [RANSOMWARE] play leaked J&J Gaming: [RANSOMWARE] play leaked J&J Gaming

    [RANSOMWARE] play leaked Kuhnline: [RANSOMWARE] play leaked Kuhnline

    NEWS

    No additional scored news items today.

    SUMMARY

    Total new items: 7. Critical: 0. Ransomware victims today: 3. KEV entries: 0.

    Top CVEs to patch urgently: .

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Companion report: Download ZIP (HTML inside)

  • Cybersecurity Intelligence Report — 2026-06-27

    Attached companion report: Download HTML report (ZIP)


    [11] First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild (SecurityWeek)  CVEs: CVE-2026-12569

    [11] Ransomware gangs find Europe’s weakest link in third-party suppliers (HelpNetSecurity)

    [10] Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign (TheHackerNews)

    [10] CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue (TheHackerNews)

  • Cybersecurity Intelligence Report  2026-06-26

    Companion report attempted upload failed; local path: https://liberpulse.com/wp-content/uploads/cyber_report_latest.html

    CRITICAL SECTION

    [10] [RANSOMWARE] nightspire leaked Grupo Riquelme (ransomware.live/nightspire)
    Victim: Grupo Riquelme | Group: nightspire | Website: www.gruporiquelme.com | Country: PY | Details: – Full Database Backup- Banking & Financial Data- Accounting & Ledger Records- Customer Databases- HR / Workforce Data- User, Role & Permission data- ERP & Critical Business Application Data

    CISA KEV (last 14 days)

    CVE Vendor/Product Score Required Action
    CVE-2026-12569 See CISA Apply vendor patch / mitigations
    CVE-2026-20230 See CISA Apply vendor patch / mitigations

    RANSOMWARE VICTIMS (DLS Monitoring)

    nightspire: Grupo Riquelme

    AuditTeam: I-SYS

    incransom: Life Bridges, GSP Crop Science Pvt

    krybit: politur.gob.do, sansilvestre.edu.pe

    anubis: Nachlass Nord

    interlock: Clearview Eye Centre

    chaos: roofdepot.com

    insomnia: *************

    akira: JMS Southeast, Padget Technologies

    morpheus: Delegal Poindexter & Underkofler, P.A.

    qilin: ISOPLUS

    NEWS

    [7] Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root AccessTheHackerNews
    An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant.

    The vulnerability, tracked as CVE-2026-20245 (CVSS score: 7.8), allows an authenticated, local attacker to execute arbitrary commands with elevated privileges

    [7] Cisco SD-WAN Zero-Day Exploited Months Before PatchingSecurityWeek

    CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching.

    The post Cisco SD-WAN Zero-Day Exploited Months Before Patching appeared first on SecurityWeek.

    [7] ControlMonkey connects backup visibility with cloud recovery readinessHelpNetSecurity

    ControlMonkey announced its Data Backup Correlation, a new capability that extends its Cyber Resilience Platform by connecting data backup posture with cloud configuration recovery. The first release supports AWS Backup and Azure Backup. CISOs and cloud teams often lack full visibility into data backup coverage and available recovery points across critical data sources, including databases, storage accounts, and cloud data services, making it harder to understand what data assets are actually

    [5] Webinar: Why account takeovers remain one of the hardest threats to stopBleepingComputer
    Account takeover attacks continue to challenge security teams because attackers often operate through legitimate accounts and trusted services. This webinar explores how behavioral AI can help organizations identify compromised accounts faster and automate response workflows. […]

    [5] Cal Water Says No OT Systems Breached in Iranian Handala CyberattackSecurityWeek

    Mandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala.

    The post Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack appeared first on SecurityWeek.

    [5] runZero 5.0 unifies exposure management to accelerate risk reductionHelpNetSecurity

    runZero has announced runZero 5.0, a major platform evolution designed to help organizations defend their expanding attack surfaces against high-velocity, AI-fueled threats. The new release unifies the exposure management lifecycle into an automated workflow that enables security teams to seamlessly discover assets and network connections, identify and prioritize critical risks, and initiate and validate remediation to proactively reduce exposure and achieve operational resilience. For years,

    SUMMARY

    Total new items: 50. Critical count: 1. Ransomware groups active: 11. Top CVEs to patch: CVE-2026-12569, CVE-2026-20230.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

  • Cybersecurity Intelligence Report — 25 June 2026

    CRITICAL SECTION

    • [13] Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks (TheHackerNews)
      Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains.
    • [11] Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) (HelpNetSecurity) — CVEs: CVE-2026-20230

      CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. “Our honeypots are seeing automated sweeps dropping webshells, all via Tor,” threat intelligence firm Defused warned today, after observing initial attacks over the weekend. “The observed chain abuses the WebDialer SSRF to deploy a rog

    • [10] CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited (TheHackerNews) — CVEs: CVE-2025-67038
      The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 26, 2026.
    • [10] Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered (TheHackerNews)
      A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC.
    • [10] LastPass customer data exposed through Klue supply chain attack (HelpNetSecurity)

      LastPass disclosed that attackers used OAuth tokens compromised in a supply chain attack on Klue, a market intelligence platform that integrates with CRM and sales tools across organizations, to access customer data stored in its Salesforce environment. “On June 12th LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market intelligence platform utilized by our go-to-market teams which integrates with our Salesforce and Gong systems,“ LastPass said. “We imm

    CISA KEV SECTION

    CVE Vendor/Product Score Required Action

    RANSOMWARE VICTIMS (DLS Monitoring)

    • anubis: Quest Health Solutions
    • stormous: mlit.com.my UPDATE-FULL DATA DUMP NEW LINK 10GB, jaggroup.com UPDATE-FULL DATA DUMP NEW LINK, maglificioliliana.com, lorenzoni-store.com, montechiaro-store.com, impulso-store.com
    • shinyhunters: Adapt******
    • nova: lpgroup, alejandria, transvill, transvill.com.pe, alejandria.biz, lpgroup.pt
    • akira: Jit Ex, Miami Machine
    • qilin: Cash Canada

    NEWS

    • [9] Law enforcement hits StealC and Amadey malware networks (HelpNetSecurity) —

      Operation Endgame, the largest international law enforcement operation aimed at disrupting ransomware and cybercrime infrastructure across the world, has claimed its latest targets: StealC and Amadey. The notice on disrupted websites (Source: Microsoft) While developed by separate criminal groups, those two malware families work in tandem to compromise devices and harvest sensitive data. Law enforcement and private sector partners, including Microsoft and Proofpoint, coordinated action agains

    • [8] Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking (SecurityWeek) —

      The security defects allow unauthenticated users to take control of the open source software supply chain.

    • [7] Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access (BleepingComputer) — New details have been revealed on how hackers exploited a Cisco Catalyst SD-WAN vulnerability tracked as CVE-2026-20245 in zero-day attacks to create rogue root accounts on targeted devices. […]
    • [6] Brinqa BYOAI lets organizations use any AI platform with trusted risk data (HelpNetSecurity) —

      Brinqa BYOAI (Bring Your Own AI), a capability that enables organizations to connect any AI agent, large language model (LLM), or automation platform to Brinqa’s exposure intelligence layer. As enterprises adopt AI, they need to ensure that AI systems use accurate, up-to-date risk data. BYOAI connects existing AI tools to a common source of exposure intelligence, providing a consistent foundation for analysis and decision-making. For enterprises, the difference between AI that delivers meanin

    SUMMARY

    Total new items: 51. Critical items: 5. Ransomware victims today: 17. Top CVEs to patch: CVE-2026-20230, CVE-2025-67038, CVE-2026-20245.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Companion report: Cyber report (HTML)

    Companion HTML report: Download report

  • Cybersecurity Intelligence Report  23 June 2026

    Companion HTML report (zipped): https://liberpulse.com/wp-content/uploads/2026/06/cyber_report_latest-1.zip

    CRITICAL SECTION

    No items scoring 10 today.

    CISA KEV (Known Exploited Vulnerabilities)

    No CISA KEV items in the last 14 days.

    RANSOMWARE VICTIMS (DLS Monitoring)

    Unknown: Huntress, HDS (Hdscorp), Gms-net, Cqcrm, Cbassociations, bits-pilani.ac.in, mihana-v.com, belpointeasset.com \ belpointe.com, ehg.bayern, Schumacher Homes, EON Meditech Pvt, graymont.com, eggetttax.ca, sterlinggloballtd.com, Ntd Apparel, NEW PRINZ EUGEN SITE [NOT A CASE FILE], Aerospace & Advanced Composites GmbH, Central Bank of Libya, Union Tractor, NTP B.V. Civil Engineering Construction, Kochs GmbH, NationsBuilders Insurance Services

    NEWS

    [8] What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks (SecurityWeek) 14 <p>Groups like ShinyHunters are demonstrating that attackers do not necessarily need malware or zero-day exploits to cause massive damage.</p>
    <p>The post <a href="https://www.securityweek.com/what-the-latest-shinyhunters-breaches-reveal-about-modern-cyberattacks/">What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

    [7] North Korean Hackers Blamed for Mastra NPM Supply Chain Attack (SecurityWeek) 14 <p>A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions.</p>
    <p>The post <a href="https://www.securityweek.com/north-korean-hackers-blamed-for-mastra-npm-supply-chain-attack/">North Korean Hackers Blamed for Mastra NPM Supply Chain Attack</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

    [6] ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack (TheHackerNews) 14 Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code.

    "Attackers compromised the vendor's build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels," Wordfence said in an analysis

    [6] Hundreds of AI-powered iOS apps found exposing credentials (HelpNetSecurity) 14 <p>Mobile app developers are packing AI features into everything from writing assistants to productivity tools and lifestyle apps. New research shows that securing access to those services remains a challenge. LLM API credential leakage via network traffic interception (Source: Research paper) Researchers from Wake Forest University analyzed 444 iOS applications with LLM features and found 282 that exposed exploitable credentials or backend access mechanisms. The affected apps covered 13 categor

    [5] ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More (TheHackerNews) 14 It’s Monday again.

    This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control.

    The annoying part is how little of this feels new. Weak credentials, sketchy downloads, browser extensions with too much access, and WordPress sites are used to push more

    SUMMARY

    Total new items: 53; Critical: 0; Ransomware groups active: 1; Top CVEs to patch urgently: None.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

  • Cybersecurity Daily — 2026-06-22

    Companion HTML report: Download report

    CRITICAL SECTION — score ≥ 10

    No items scoring 10 or higher today.

    CISA KEV SECTION (last 14 days)

    No CISA KEV items in the collected data.

    RANSOMWARE VICTIMS (DLS Monitoring) — today

    qilin: Taiwan Sintong Machinery Co., Ltd (Victim: Taiwan Sintong Machinery Co., Ltd | Group: qilin | Website: www.twsinto.com.tw | Country: TW | Details: N/A), Sivatel Bangkok (Victim: Sivatel Bangkok | Group: qilin | Website: www.sivatelbangkok.com | Country: TH | Details: N/A), Tri-tec (Victim: Tri-tec | Group: qilin | Website: www.tri-tec.com | Country: US | Details: N/A), Florida Engineering Services (Victim: Florida Engineering Services | Group: qilin | Website: www.florida-engineering-services.com | Country: US | Details: N/A)

    cmdorganization: Wall ISD (Victim: Wall ISD | Group: cmdorganization | Website: www.wallisd.net | Country: US | Details: Wall ISD is an educational institution that serves students in the Wall, Texas area, providing a range of programs and activities for elementary, middle, and high school students. The district emphasizes inclusivity and equal access to education, ensuring that all students, regardless of their backg)

    stormous: jaggroup.com UPDATE-FULL DATA DUMP (Victim: jaggroup.com UPDATE-FULL DATA DUMP | Group: stormous | Details: Full database containing corporate emails (⁠@jaggroup.com⁠), Active Directory domain logins, and clear plain-text passwords.Complete Microsoft Dynamics GP databases, software license keys, financial reports, and system configuration Multiple compressed archives (⁠zBackups.zip⁠, ⁠wetransfer⁠ packages)

    incransom: jktornel (Victim: jktornel | Group: incransom | Country: MX | Details: Unauthorized access has been gained to the company’s confidential files, including client data, proprietary R&D, and financial documentation.)

    nova: Lockers IT (Victim: Lockers IT | Group: nova | Details: LockersIT is a self-owned Bangladeshi IT company founded in 2013, headquartered in Chandpur, that specializes in custom software development with a team of 11-50 employees – allcashdealer.com dealmart24.com dev1.lockersit.com erp.lockersit.com sales.lockersit.com brm.lockersit.com debnathashu.com de)

    nightspire: Artistic Smiles (Victim: Artistic Smiles | Group: nightspire | Website: artisticsmiles.org | Country: US | Details: Data is not available now.)

    NEWS SECTION — other scored items (score ≥ 5)

    SUMMARY

    Total new items: 12. Critical count: 0. Ransomware victims today: 9. Top CVEs to patch: None.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

  • Cybersecurity Intelligence Report  21 June 2026

    CRITICAL SECTION

    No items meeting critical threshold today.

    CISA KEV

    No KEV items in the last 14 days.

    RANSOMWARE VICTIMS (DLS Monitoring)

    [RANSOMWARE]: [RANSOMWARE] lockbit5 leaked utb.edu.vn, [RANSOMWARE] thegentlemen leaked SGS Malaysia, [RANSOMWARE] thegentlemen leaked Sertrans, [RANSOMWARE] nova leaked Nhà Thành Phố, [RANSOMWARE] incransom leaked Newspaper Media Group, [RANSOMWARE] qilin leaked Pacific Lamp & Supply, [RANSOMWARE] worldleaks leaked L'Archevque & Rivest Ltée, [RANSOMWARE] worldleaks leaked Super Finishing, [RANSOMWARE] payload leaked ENB Versicherungen | myenb.ch, [RANSOMWARE] payload leaked Editora Irmãos Vitale, [RANSOMWARE] payload leaked Qualiflex Solutions | qualiflex.solutions, [RANSOMWARE] payload leaked Preferred Properties, [RANSOMWARE] ransomexx leaked Go2Joy (go2joy.vn), [RANSOMWARE] nova leaked Dosab, [RANSOMWARE] nova leaked Hosab, [RANSOMWARE] nova leaked MIT HJERTE, [RANSOMWARE] nova leaked One Believing Interiors, [RANSOMWARE] cmdorganization leaked Pinnacle Re-Tec, [RANSOMWARE] lockbit5 leaked probat.ag, [RANSOMWARE] lockbit5 leaked eternal.hk, [RANSOMWARE] lockbit5 leaked 5deagosto.com.br, [RANSOMWARE] lockbit5 leaked abandw.com, [RANSOMWARE] lockbit5 leaked ag-360.ca, [RANSOMWARE] lockbit5 leaked elematic.com, [RANSOMWARE] lockbit5 leaked amc.co.th, [RANSOMWARE] lockbit5 leaked casaandina.com.co, [RANSOMWARE] lockbit5 leaked bvi.co.bw, [RANSOMWARE] lockbit5 leaked comta.com.tw, [RANSOMWARE] lockbit5 leaked daikyonishikawa.co.jp, [RANSOMWARE] lockbit5 leaked rubbercompounding.com, [RANSOMWARE] lockbit5 leaked drwu.com, [RANSOMWARE] lockbit5 leaked felizhotelboracay.com, [RANSOMWARE] lockbit5 leaked greyhighschool.com, [RANSOMWARE] lockbit5 leaked idefeey.yucatan.gob.mx, [RANSOMWARE] lockbit5 leaked inspeqingenieria.com, [RANSOMWARE] lockbit5 leaked majorcineplex.com, [RANSOMWARE] lockbit5 leaked parkviewtaipei.com, [RANSOMWARE] lockbit5 leaked ponce-benzo.com, [RANSOMWARE] lockbit5 leaked parampackaging.com, [RANSOMWARE] lockbit5 leaked primelinkbio.com, [RANSOMWARE] lockbit5 leaked saico.co.th, [RANSOMWARE] lockbit5 leaked sanatoriodelta.com, [RANSOMWARE] lockbit5 leaked saude.mt.gov.br, [RANSOMWARE] lockbit5 leaked sparkinter.com, [RANSOMWARE] lockbit5 leaked sra.nl, [RANSOMWARE] lockbit5 leaked teleton.org.hn, [RANSOMWARE] lockbit5 leaked union-chemical.co.th, [RANSOMWARE] lockbit5 leaked venelectronics.com, [RANSOMWARE] lockbit5 leaked weinwurm.cc, [RANSOMWARE] lockbit5 leaked nundungopee.mu, [RANSOMWARE] thegentlemen leaked hiddenn, [RANSOMWARE] thegentlemen leaked Vera Chimie Management, [RANSOMWARE] thegentlemen leaked Alexander Buch Bilanzbuchhalter, [RANSOMWARE] thegentlemen leaked TERRIO Therapy Fitness, [RANSOMWARE] thegentlemen leaked Ty Thac Co, [RANSOMWARE] thegentlemen leaked Amigest, [RANSOMWARE] thegentlemen leaked Yudu Technology, [RANSOMWARE] thegentlemen leaked Burris MacOmber, [RANSOMWARE] thegentlemen leaked Cofaq, [RANSOMWARE] thegentlemen leaked Al Khaja Holding, [RANSOMWARE] cmdorganization leaked Southern design RV, [RANSOMWARE] thegentlemen leaked Athens Orthopedic Clinic

    NEWS

    Microsoft links Mastra AI supply chain attack to North Korean hackers  Microsoft has attributed a recent Mastra AI supply chain attack that compromised more than 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. […]

    SUMMARY

    Total new items: 66. Critical: 0. Ransomware victims today: 62. Top CVEs to patch: CVE-2026-4020.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Companion HTML report (zipped): https://liberpulse.com/wp-content/uploads/2026/06/cyber_report_latest.zip

  • Cybersecurity Daily — 2026-06-20

    Daily cybersecurity intelligence summary. Companion report: HTML report

    CRITICAL SECTION

    • [16] Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) (HelpNetSecurity) — CVEs: CVE-2026-20253

    Companion report: https://liberpulse.com/wp-content/uploads/2026/06/cyber_report_latest-2.html

  • Cybersecurity Intelligence Report – 19 June 2026

    Companion HTML report: Download the HTML report

    Cybersecurity Intelligence Report – 19 June 2026

    Cybersecurity Intelligence Report – 19 June 2026

    CRITICAL SECTION

    No critical items identified today.

    CISA KEV

    No recent CISA KEV entries in the past 14 days.

    RANSOMWARE VICTIMS

    No new ransomware victims reported today.

    NEWS

    No other scored news items today.

    SUMMARY

    Total new items: 0
    Critical count: 0
    Ransomware groups active: 0
    Top CVEs to patch urgently: –

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

  • Cybersecurity Intelligence Report — 17 June 2026

    Cybersecurity Intelligence Report — 17 June 2026

    Executive signal: Today’s collection produced 65 new unique items, including 2 critical signals, 1 CISA Known Exploited Vulnerability update and 1 ransomware DLS victim entries. Prioritise remote access tooling, exploited web-management flaws and exposed identity paths.

    1. Critical section

    [12] SimpleHelp RMM flaw could give attackers full access to managed endpoints (CVE-2026-48558) (HelpNetSecurity)

    A critical vulnerability (CVE-2026-48558) in SimpleHelp, a popular remote monitoring and management (RMM) tool, can be exploited remotely by unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, and more. Maliciously “forged” Technician account (Source: Horizon3.ai) The vulnerability CVE-2026-48558 is an authentication bypass flaw affecting…


    CVEs: CVE-2026-48558

    [11] Software supply chains are heading for a transparency test (HelpNetSecurity)

    Software supply chain visibility is becoming part of product security work as the EU Cyber Resilience Act (CRA) moves toward application in December 2027. ENISA’s SBOM Adoption State of Play 2026 shows organizations preparing for CRA obligations through SBOM tooling, automation, and changes to software development practices. Level of SBOM adoption based on organisation size (Source: ENISA) SBOMs move from best…

    2. CISA KEV section

    CVEVendor/ProductScoreRequired action
    CVE-2026-48907CVE-2026-48907: Widget Factory Joomla Content Editor Improper Access Control Vulnerability – Widget Factory Joomla Content Editor 6Widget Factory Joomla Content Editor Improper Access Control Vulnerability – Widget Factory Joomla Content Editor . Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in…

    3. Ransomware victims (DLS monitoring)

    shinyhunters: Service Notice: Scheduled Maintenance and Infrastructure Upgrades

    4. News section

    [7] CISA warns of another cPanel plugin flaw exploited in attacks (BleepingComputer)
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin. CVEs: CVE-2026-54420.

    [7] Ransomware gang abuses Microsoft Teams relays to hide malicious traffic (BleepingComputer)
    DragonForce ransomware used a custom malware named 'Backdoor.Turn' to hide command-and-control traffic inside Microsoft Teams relay infrastructure.

    [7] Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw (TheHackerNews)
    Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0. "A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to… CVEs: CVE-2026-20262.

    [7] Attackers are exploiting FortiSandbox vulnerabilities (HelpNetSecurity)
    Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from threat intelligence company Defused, which said that the exploit for one of… CVEs: CVE-2026-39808, CVE-2026-25089, CVE-2026-39813.

    [7] Cybercriminals mask malicious communications through Microsoft Teams relays (HelpNetSecurity)
    The DragonForce ransomware group used a custom malware called Backdoor.Turn to hide command-and-control traffic inside Microsoft Teams relay infrastructure during an intrusion at a U.S. services company, according to Symantec. DragonForce is a ransomware-as-a-service operation that has been active since 2023. The group provides affiliates with ransomware tools and supporting…

    [5] CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation (TheHackerNews)
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026. The vulnerability in question is CVE-2026-54420 (CVSS score: 8.5), which has been described as a case… CVEs: CVE-2026-54420.

    [5] iRhythm Confirms Data Stolen in Hack (SecurityWeek)
    The digital health company said it learned of the breach on June 8 and the attackers demanded a ransom. The post iRhythm Confirms Data Stolen in Hack appeared first on SecurityWeek

    5. Summary

    Total new items: 65. Critical count: 2. Active ransomware groups observed: 1. Top CVEs to patch urgently: CVE-2026-54420, CVE-2026-20262, CVE-2026-39808, CVE-2026-25089, CVE-2026-39813, CVE-2026-48558, CVE-2026-48907.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Companion dashboard: open the CSSLTD HTML intelligence dashboard.