Daily cybersecurity intelligence dispatch for 15 June 2026. We analyse the most significant exploited vulnerabilities, active ransomware operations and notable security developments, drawing on credible primary sources.
1. Critical Section
[10] Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack (HelpNetSecurity)
Last week was dominated by an actively exploited Check Point VPN zero-day and a wave of attacks against unpatched Oracle PeopleSoft servers. Organisations running these platforms should prioritise emergency patching and review logs for signs of compromise, as both flaws are being weaponised in the wild.
2. CISA Known Exploited Vulnerabilities (last 14 days)
| CVE | Vendor / Product | Score | Required Action |
|---|---|---|---|
| CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools | KEV (2026-06-12) | Remediate by 2026-06-15 per vendor guidance |
| CVE-2026-10520 | Ivanti Sentry | KEV (2026-06-11) | Remediate by 2026-06-14 per vendor guidance |
| CVE-2026-11645 | Google Chromium V8 | KEV (2026-06-09) | Remediate by 2026-06-23 per vendor guidance |
| CVE-2026-7473 | Arista Extensible Operating System | KEV (2026-06-09) | Remediate by 2026-06-23 per vendor guidance |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager | KEV (2026-06-09) | Remediate by 2026-06-23 per vendor guidance |
| CVE-2026-42271 | BerriAI LiteLLM | KEV (2026-06-08) | Remediate by 2026-06-22 per vendor guidance |
| CVE-2026-50751 | Check Point Security Gateway | KEV (2026-06-08) | Remediate by 2026-06-11 per vendor guidance |
| CVE-2026-28318 | SolarWinds Serv-U | KEV (2026-06-05) | Remediate by 2026-06-19 per vendor guidance |
| CVE-2026-45247 | Mirasvit Mirasvit Full Page Cache Warmer | KEV (2026-06-03) | Remediate by 2026-06-06 per vendor guidance |
| CVE-2022-0492 | Linux Kernel | KEV (2026-06-02) | Remediate by 2026-06-05 per vendor guidance |
| CVE-2025-48595 | Android Framework | KEV (2026-06-02) | Remediate by 2026-06-05 per vendor guidance |
| CVE-2024-21182 | Oracle WebLogic Server | KEV (2026-06-01) | Remediate by 2026-06-04 per vendor guidance |
3. Ransomware Victims (DLS Monitoring)
AuditTeam: I-***YS (RU)
dragonforce: Ink (GB)
krybit: frey.com (CH)
nightspire: Silsbee Police Department (US), K****** County. Mi**e**ta, WaxWorks Inc (US), Blue Nile Medical Center (US)
nova: Bandung (ID)
4. News Section
FBI disrupts massive AI-powered phishing service using a million URLs (BleepingComputer) — The FBI, working with Google and Black Lotus Labs, has dismantled a sprawling Chinese phishing-as-a-service operation known as Outsider Enterprise, which leveraged AI to generate over a million malicious URLs harvesting card and credential data.
5. Summary
Total new items analysed: 10 · Critical-tier: 1 · Active ransomware groups: 5 (AuditTeam, dragonforce, krybit, nightspire, nova) · KEV additions tracked: 12.
Prioritise patching: CVE-2026-35273, CVE-2026-10520, CVE-2026-11645, CVE-2026-7473, CVE-2026-20245. The Oracle PeopleSoft (CVE-2026-35273), Ivanti Sentry (CVE-2026-10520) and Check Point Security Gateway (CVE-2026-50751) flaws are past or imminent on their CISA remediation deadlines and warrant immediate attention.
📊 View the full interactive HTML intelligence dashboard →
Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live
Leave a Reply