Google’s Mandiant/GTIG confirmed active exploitation of CVE-2026-35273, a critical unauthenticated RCE in PeopleSoft PeopleTools’ Environment Management, as a zero-day prior to Oracle’s June 10 advisory. The campaign, concentrated in higher education, used MeshCentral agents masquerading as Azure services for lateral movement and exfiltration, with data later posted to the ShinyHunters leak site. Defenders should immediately block external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector, audit web logs, hunt for webshells, and apply Oracle’s fixes without delay.
Source: Google Threat Intelligence (Mandiant)
CISA tells federal agencies to “patch smarter” with risk-based vulnerability management
CISA’s new Binding Operational Directive (BOD 26-04) shifts federal patching to a risk-based model centered on exploitability and the Known Exploited Vulnerabilities catalog. The move aims to tame unmanageable patch volumes as AI accelerates both vulnerability discovery and exploitation, requiring agencies to update policies, inventories, and prioritization workflows.
Source: Help Net Security
New ‘GreatXML’ exploit bypasses BitLocker via Defender offline scan artifacts
A researcher released “GreatXML,” a zero-day technique that abuses Microsoft Defender’s Offline Scan to spawn a SYSTEM shell in Windows Recovery Mode, effectively bypassing BitLocker protections on affected systems. With no official patch yet, organizations should restrict Recovery Environment access, enforce pre-boot authentication, and harden incident response around recovery workflows.
Source: SecurityWeek
Ivanti Sentry critical RCE (CVE-2026-10520) under active attack
A maximum-severity OS command injection in Ivanti Sentry allows unauthenticated remote code execution as root, with exploitation attempts already observed against honeypots soon after patches dropped. Admins should urgently upgrade to R10.5.2, R10.6.2, or R10.7.1, restrict management interfaces from the internet, and monitor for anomalous process activity on gateways.
Source: SecurityWeek
LangGraph flaws expose AI agents to RCE and data theft
Check Point Research disclosed a critical vulnerability chain in LangGraph—an open-source framework with ~46.5 million monthly downloads—that can lead to SQL injection and remote code execution on agent servers. A compromised instance can spill LLM API keys, customer data, CRM credentials, conversation history, and internal assets; patching and rigorous AI governance are strongly advised.
Source: Check Point Blog
FBI seizes 13 ‘consulting’ sites tied to alleged Chinese intelligence recruitment
Federal authorities seized domains that posed as consulting firms to entice current and former U.S. government and military personnel with clearances into sharing sensitive information. The takedown highlights persistent social-engineering campaigns targeting human trust; agencies and contractors should reinforce verification of unsolicited job offers and consulting outreach.
Source: SecurityWeek
Europol dismantles ‘AudiA6’ crypto laundering service used by ransomware gangs
An international operation took down AudiA6, a laundering service suspected of washing more than €336 million in illicit funds tied to ransomware and other cybercrime, and linked its operators to a dark web forum. The disruption strikes at the financial backbone of extortion ecosystems and underscores the importance of AML/KYC controls and blockchain tracing.
Source: Help Net Security
You May Also Be Interested In...
Threat Actors Weaponize AI Hype to Deliver AsyncRAT (Fortinet)Fake Spotify Premium tutorials on TikTok/Instagram Reels spread Vidar malware (Help Net Security)
OceanLotus: From external espionage to domestic targeting (ESET)