Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (10 June 2026)
Published: Loading…
At a Glance
- Microsoft Patch Tuesday June 2026 fixes 206 vulnerabilities including 33 critical and three zero-days across Windows, Office and BitLocker.
- Google patched Chrome zero-day CVE-2026-11645 exploited in the wild affecting V8 out-of-bounds memory access across Windows, macOS and Linux.
- LiteLLM CVE-2026-42271 command injection is under active exploitation while Check Point VPN authentication bypass is exploited in Qilin ransomware attacks.
- French government Tchap messaging platform was breached through hijacked accounts enabling access to public chat rooms and exfiltration claims of 13.5GB data.
- Miasma supply chain attacks affected npm packages using binding.gyp install-time execution techniques and spreading credential theft across registries and developer environments.
Summary
Microsoft released June 2026 Patch Tuesday addressing 206 vulnerabilities across Windows, Office and BitLocker, including three publicly disclosed zero-days in multiple components. Google Chrome update 149.0.7827.102/103 patched CVE-2026-11645, a V8 out-of-bounds flaw exploited in the wild affecting Windows, macOS and Linux systems. SAP fixed critical NetWeaver and Commerce Cloud vulnerabilities while Veeam released patches for a Backup & Replication RCE flaw affecting domain-joined servers.
LiteLLM command injection vulnerability CVE-2026-42271 is actively exploited, allowing authenticated users to execute arbitrary commands on affected AI gateway deployments. Check Point VPN authentication bypass flaw is exploited in the wild by Qilin ransomware affiliates to establish unauthorised remote VPN sessions. ServiceNow disclosed a security incident where attackers exploited an unauthenticated API endpoint enabling queries against customer instances and access to stored data across environments.
France Tchap messaging platform was compromised after attackers hijacked a user account gaining access to public chat rooms within government communications system. Attackers claimed exfiltration of 13.5GB of files and 650,000 messages from Tchap accounts following account hijacking and LDAP credential compromise. Jupyter Enterprise Gateway vulnerabilities enable unauthenticated remote code execution and full Kubernetes cluster takeover through YAML injection and template injection flaws.
Miasma supply chain campaign affected npm ecosystems using binding.gyp install-time execution to steal credentials and compromise developer environments across globally. npm tooling bug incorrectly marked single-character packages as security-holder versions temporarily altering dist-tags while leaving underlying package versions unchanged intact. Microsoft removed 73 compromised GitHub repositories after malware injection into open-source projects across Azure, microsoft, Azure-Samples, and MicrosoftDocs organisations, disrupting CI pipelines.
Highlights of the Day
Residential Proxy Traffic Reaches Most Enterprise Networks
Infoblox reported that more than 65% of its Threat Defense Cloud customers queried domains linked to residential proxy services in 2026, with monthly DNS requests rising from nearly 400 billion to over 500 billion between January 2025 and April 2026. The company observed residential proxy activity across multiple sectors, including government, banking, healthcare and pharmaceuticals, and found Bright Data-related domains in more than half of customer environments. Infoblox also recorded a 265% single-day increase in customer networks querying an IPIDEA-related domain during January 2026, around the period when Google disrupted the IPIDEA residential proxy service.
China and DPRK Drive Technology Sector Intrusions
More than 58% of state-sponsored intrusions against technology organisations were attributed to China-nexus actors Murky Panda and Warp Panda targeting intellectual property and AI development. FAMOUS CHOLLIMA accounted for 47% of state-sponsored hands-on-keyboard operations conducting IT worker infiltration campaigns against technology organisations across North America Europe and Asia. eCrime activity accounted for 65% of hands-on-keyboard operations with initial access brokers advertising access to 277 technology organisations and BGH actors naming 572 organisations.
Critical Jupyter Gateway Flaws Enable Kubernetes Cluster Takeover
Three critical vulnerabilities (CVE-2026-44182, CVE-2026-44181, CVE-2026-44180) in Jupyter Enterprise Gateway (CVSS 10.0, 10.0, 9.8) allow unauthenticated remote code execution and full Kubernetes cluster takeover through YAML injection and server-side template injection during Kubernetes manifest rendering. Flaws in the Jinja2-based rendering pipeline permit unsafe environment variable interpolation (KERNEL_XXX), enabling privileged pod creation, UID/GID enforcement bypass, and service account token theft, affecting Enterprise Gateway versions prior to 3.3.0 across Kubernetes deployments.
Microsoft June Patch Tuesday Fixes 206 Vulnerabilities and Zero-Days
Microsoft June 2026 Patch Tuesday addresses 206 vulnerabilities, including 33 critical, 167 important, and three publicly disclosed zero-days, with Edge Chromium fixes excluded from this release. Zero-days include CVE-2026-49160 HTTP.sys denial of service, CVE-2026-45586 CTFMON elevation of privilege, and CVE-2026-50507 BitLocker security bypass affecting Windows components and physical attack scenarios. The release spans Windows, Office, Hyper-V, BitLocker, and networking components, alongside Adobe updates covering 123 vulnerabilities, including 47 rated critical.
npm Bug Marks One-Character Packages as Security Holders
npm tooling incorrectly applied security-holder metadata (0.0.1-security and 0.0.1-security.0) to multiple one-character packages, including single letters, numbers, and symbol-based package names, while shifting the latest dist-tag to placeholder versions across affected registry entries. Socket reported that npm attributed the behaviour to a tooling bug and said it is being rolled back, with no evidence of package compromise and older versions still available in the registry. During the affected window, dependency resolution could surface placeholder versions in lockfiles where dist-tags were updated, despite underlying package versions remaining unchanged.
npm Miasma Campaign Exploits binding.gyp for Install-Time Execution
Miasma supply chain malware affecting npm packages leverages binding.gyp and node-gyp to trigger install-time execution, enabling credential theft and system compromise during installation. Attack surface includes gyp command expansion syntax, actions, rules, compiler configuration, and includes or dependencies, all capable of executing arbitrary code during npm install. Analysis also highlights Python eval-based sandbox escape paths within binding.gyp, allowing arbitrary code execution even without standard package.json lifecycle hooks.
Hijacked Account Breaches French Government Tchap Messaging Service
France’s DINUM reported a breach of the Tchap Matrix-based government messaging platform after ANSSI detected access via a hijacked user account on Sunday. Attackers claiming responsibility said they used social engineering and accessed LDAP credentials, exfiltrating 13.5GB of files and scraping 650,000 messages from 73,000 accounts. Officials said investigation continues into exposed data noting public Tchap chat rooms are unencrypted and media files may be accessed via message links.
CISA Adds LiteLLM and Check Point Exploited Vulnerabilities
CISA added CVE-2026-42271, a BerriAI LiteLLM command injection vulnerability, and CVE-2026-50751, a Check Point Security Gateway improper authentication vulnerability, to its Known Exploited Vulnerabilities Catalog following evidence of active exploitation in the wild. The KEV Catalog is maintained under Binding Operational Directive 22-01 for US federal civilian agencies and tracks vulnerabilities identified through observed exploitation activity.
Chrome Patches 74 Vulnerabilities Including Active V8 Exploit
Google released Chrome Stable channel update 149.0.7827.102/.103 addressing 74 security vulnerabilities across Windows, macOS, and Linux, including multiple critical use-after-free issues in components such as Ozone, Aura, Bluetooth, TabStrip, and File Input. The update includes CVE-2026-11645, a high-severity V8 out-of-bounds memory access vulnerability for which Google confirmed an exploit is active in the wild. Additional fixes cover integer overflows in libyuv and GPU components, along with numerous high-severity memory safety issues across rendering, media, and extension subsystems.
Daily Coverage