Post

Cybersecurity Newsfeed - 06/10/26

Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.

Cybersecurity Newsfeed - 06/10/26

Cybersecurity Newsfeed

📅 06/10/26

🛡️ Vulnerabilities

  • Rejetto HFS RCE Vulnerability (CVE-2026-61500): Threat actors are actively scanning for a critical flaw in Rejetto HTTP File Server (HFS). Discovered by Anthropic’s Mythos AI model, the issue stems from weak pseudorandom number generation used for key signing, allowing unauthenticated attackers to forge administrative session tokens and achieve remote code execution. More infoMore info
  • Microsoft Exchange Server Elevation of Privilege (CVE-2026-96940): Microsoft issued an out-of-band security update for a high-severity flaw (CVSS 8.8) in Exchange Server 2016, 2019, and Subscription Edition. Weak authorization mechanisms allow an authenticated internal network attacker to elevate privileges and gain unauthorized access to other users’ mailboxes and attachments. More infoMore info
  • Dell System Update Local Privilege Escalation: Dell warned of a critical vulnerability in its System Update (DSU) CLI tool. The flaw enables local unprivileged attackers to execute arbitrary commands with root privileges, affecting enterprise endpoints and servers. More info

  • Active Exploitation of Realtek Jungle SDK (CVE-2021-35394): Threat actors continue to target internet-exposed routers and IoT devices running vulnerable Realtek Jungle SDK code, leveraging the unauthenticated RCE vulnerability to deploy Mirai botnet variants. More info

🎯 Adversaries

  • ClingSTUN Linux Backdoor Converts IoT to Proxies: FortiGuard Labs identified ClingSTUN, a novel Linux backdoor targeting IoT assets across 24 known vulnerabilities. It leverages STUN and ICE servers to bypass NAT/firewalls, turning infected devices into remotely controlled proxies to obfuscate malicious C2 traffic. More info

  • CloudSyncD macOS Backdoor Poses as Zoom Installer: A stealthy macOS backdoor called CloudSyncD uses fake Zoom installers to establish long-term persistence. It displays a fake password prompt, embeds credentials using zero-width Unicode characters, and covertly polls C2 servers. More info

  • SMTP-Based Linux Backdoors Target Security Gateways: A campaign targeting Secure Email Gateways (SEGs) deploys custom implants (such as BPFdoor and Rekoobe variants) disguised as legitimate processes. C2 communications are disguised over TCP Port 25 (SMTP) to blend into regular mail traffic. More info

  • Milk Dragon Phishing Kit Abuse on Social Platforms: Attackers are using the “Milk Dragon” kit across TikTok and Facebook, pushing fake discount ads that send victims to fraudulent storefronts. A custom plugin named BytePress steals payment details and intercepts MFA tokens in real time. More info

  • OpenAI Integrates Invisible Watermarks in EU: OpenAI is rolling out invisible text watermarking for ChatGPT and Codex in the EU. Utilizing Google DeepMind’s SynthID and open C2PA standards, cryptographic signatures are embedded directly into outputs to improve content provenance. More info

  • Proposed Federal “Anti-Flock” LPR Legislation: Proposed US federal laws aim to restrict automated license plate reader (ALPR) technology by limiting cross-jurisdiction data sharing, retention periods, and real-time tracking to address privacy concerns. More info

  • Malwarebytes Launches Free Link Checker: Malwarebytes introduced a real-time link verification tool that analyzes domain reputation and threat telemetry to catch phishing schemes, drive-by downloads, and malicious sites before navigation. More info

💥 Breaches & Leaks

  • IQVIA Fined €7M ($7.8M) for GDPR Anonymization Failures: Italy’s GPDP penalized health data provider IQVIA after an investigation showed its 1-million-patient database included metadata that enabled re-identification, violating GDPR rules. More info

  • Denmark Population Register Breach Exposes 8.8M Records: Unauthorized access via a third-party contractor resulted in the exfiltration of 8.8 million personal records from Denmark’s Central Population Register (CPR), including names, addresses, and social security numbers. More info

  • South Korean Banks Targeted in AI-Assisted Attacks: South Korea’s Financial Services Commission launched emergency investigations following breaches at major commercial banks (including Shinhan Bank and KB Kookmin Bank) involving AI-driven penetration-testing tools. More info

📚 Others

  • Ploutus ATM Malware Developer Appears in US Court: The alleged developer of the Ploutus ATM jackpotting malware was presented in U.S. federal court following an international law enforcement arrest. More info

⬅ Back to Archive

This post is licensed under CC BY 4.0 by the author.