Cybersecurity Intelligence Report — 15 June 2026

Written by

in

Daily cybersecurity intelligence dispatch for 15 June 2026. We analyse the most significant exploited vulnerabilities, active ransomware operations and notable security developments, drawing on credible primary sources.

1. Critical Section

[10] Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack (HelpNetSecurity)

Last week was dominated by an actively exploited Check Point VPN zero-day and a wave of attacks against unpatched Oracle PeopleSoft servers. Organisations running these platforms should prioritise emergency patching and review logs for signs of compromise, as both flaws are being weaponised in the wild.

2. CISA Known Exploited Vulnerabilities (last 14 days)

CVE Vendor / Product Score Required Action
CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools KEV (2026-06-12) Remediate by 2026-06-15 per vendor guidance
CVE-2026-10520 Ivanti Sentry KEV (2026-06-11) Remediate by 2026-06-14 per vendor guidance
CVE-2026-11645 Google Chromium V8 KEV (2026-06-09) Remediate by 2026-06-23 per vendor guidance
CVE-2026-7473 Arista Extensible Operating System KEV (2026-06-09) Remediate by 2026-06-23 per vendor guidance
CVE-2026-20245 Cisco Catalyst SD-WAN Manager KEV (2026-06-09) Remediate by 2026-06-23 per vendor guidance
CVE-2026-42271 BerriAI LiteLLM KEV (2026-06-08) Remediate by 2026-06-22 per vendor guidance
CVE-2026-50751 Check Point Security Gateway KEV (2026-06-08) Remediate by 2026-06-11 per vendor guidance
CVE-2026-28318 SolarWinds Serv-U KEV (2026-06-05) Remediate by 2026-06-19 per vendor guidance
CVE-2026-45247 Mirasvit Mirasvit Full Page Cache Warmer KEV (2026-06-03) Remediate by 2026-06-06 per vendor guidance
CVE-2022-0492 Linux Kernel KEV (2026-06-02) Remediate by 2026-06-05 per vendor guidance
CVE-2025-48595 Android Framework KEV (2026-06-02) Remediate by 2026-06-05 per vendor guidance
CVE-2024-21182 Oracle WebLogic Server KEV (2026-06-01) Remediate by 2026-06-04 per vendor guidance

3. Ransomware Victims (DLS Monitoring)

AuditTeam: I-***YS (RU)

dragonforce: Ink (GB)

krybit: frey.com (CH)

nightspire: Silsbee Police Department (US), K****** County. Mi**e**ta, WaxWorks Inc (US), Blue Nile Medical Center (US)

nova: Bandung (ID)

4. News Section

FBI disrupts massive AI-powered phishing service using a million URLs (BleepingComputer) — The FBI, working with Google and Black Lotus Labs, has dismantled a sprawling Chinese phishing-as-a-service operation known as Outsider Enterprise, which leveraged AI to generate over a million malicious URLs harvesting card and credential data.

5. Summary

Total new items analysed: 10 · Critical-tier: 1 · Active ransomware groups: 5 (AuditTeam, dragonforce, krybit, nightspire, nova) · KEV additions tracked: 12.

Prioritise patching: CVE-2026-35273, CVE-2026-10520, CVE-2026-11645, CVE-2026-7473, CVE-2026-20245. The Oracle PeopleSoft (CVE-2026-35273), Ivanti Sentry (CVE-2026-10520) and Check Point Security Gateway (CVE-2026-50751) flaws are past or imminent on their CISA remediation deadlines and warrant immediate attention.

📊 View the full interactive HTML intelligence dashboard →

Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *