CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (10 June 2026)

Published: Loading…

At a Glance

  • Microsoft Patch Tuesday June 2026 fixes 206 vulnerabilities including 33 critical and three zero-days across Windows, Office and BitLocker.
  • Google patched Chrome zero-day CVE-2026-11645 exploited in the wild affecting V8 out-of-bounds memory access across Windows, macOS and Linux.
  • LiteLLM CVE-2026-42271 command injection is under active exploitation while Check Point VPN authentication bypass is exploited in Qilin ransomware attacks.
  • French government Tchap messaging platform was breached through hijacked accounts enabling access to public chat rooms and exfiltration claims of 13.5GB data.
  • Miasma supply chain attacks affected npm packages using binding.gyp install-time execution techniques and spreading credential theft across registries and developer environments.

Summary

Microsoft released June 2026 Patch Tuesday addressing 206 vulnerabilities across Windows, Office and BitLocker, including three publicly disclosed zero-days in multiple components. Google Chrome update 149.0.7827.102/103 patched CVE-2026-11645, a V8 out-of-bounds flaw exploited in the wild affecting Windows, macOS and Linux systems. SAP fixed critical NetWeaver and Commerce Cloud vulnerabilities while Veeam released patches for a Backup & Replication RCE flaw affecting domain-joined servers.

LiteLLM command injection vulnerability CVE-2026-42271 is actively exploited, allowing authenticated users to execute arbitrary commands on affected AI gateway deployments. Check Point VPN authentication bypass flaw is exploited in the wild by Qilin ransomware affiliates to establish unauthorised remote VPN sessions. ServiceNow disclosed a security incident where attackers exploited an unauthenticated API endpoint enabling queries against customer instances and access to stored data across environments.

France Tchap messaging platform was compromised after attackers hijacked a user account gaining access to public chat rooms within government communications system. Attackers claimed exfiltration of 13.5GB of files and 650,000 messages from Tchap accounts following account hijacking and LDAP credential compromise. Jupyter Enterprise Gateway vulnerabilities enable unauthenticated remote code execution and full Kubernetes cluster takeover through YAML injection and template injection flaws.

Miasma supply chain campaign affected npm ecosystems using binding.gyp install-time execution to steal credentials and compromise developer environments across globally. npm tooling bug incorrectly marked single-character packages as security-holder versions temporarily altering dist-tags while leaving underlying package versions unchanged intact. Microsoft removed 73 compromised GitHub repositories after malware injection into open-source projects across Azure, microsoft, Azure-Samples, and MicrosoftDocs organisations, disrupting CI pipelines.

Highlights of the Day

Residential Proxy Traffic Reaches Most Enterprise Networks

Infoblox reported that more than 65% of its Threat Defense Cloud customers queried domains linked to residential proxy services in 2026, with monthly DNS requests rising from nearly 400 billion to over 500 billion between January 2025 and April 2026. The company observed residential proxy activity across multiple sectors, including government, banking, healthcare and pharmaceuticals, and found Bright Data-related domains in more than half of customer environments. Infoblox also recorded a 265% single-day increase in customer networks querying an IPIDEA-related domain during January 2026, around the period when Google disrupted the IPIDEA residential proxy service.

Source: Infoblox

China and DPRK Drive Technology Sector Intrusions

More than 58% of state-sponsored intrusions against technology organisations were attributed to China-nexus actors Murky Panda and Warp Panda targeting intellectual property and AI development. FAMOUS CHOLLIMA accounted for 47% of state-sponsored hands-on-keyboard operations conducting IT worker infiltration campaigns against technology organisations across North America Europe and Asia. eCrime activity accounted for 65% of hands-on-keyboard operations with initial access brokers advertising access to 277 technology organisations and BGH actors naming 572 organisations.

Critical Jupyter Gateway Flaws Enable Kubernetes Cluster Takeover

Three critical vulnerabilities (CVE-2026-44182, CVE-2026-44181, CVE-2026-44180) in Jupyter Enterprise Gateway (CVSS 10.0, 10.0, 9.8) allow unauthenticated remote code execution and full Kubernetes cluster takeover through YAML injection and server-side template injection during Kubernetes manifest rendering. Flaws in the Jinja2-based rendering pipeline permit unsafe environment variable interpolation (KERNEL_XXX), enabling privileged pod creation, UID/GID enforcement bypass, and service account token theft, affecting Enterprise Gateway versions prior to 3.3.0 across Kubernetes deployments.

Microsoft June Patch Tuesday Fixes 206 Vulnerabilities and Zero-Days

Microsoft June 2026 Patch Tuesday addresses 206 vulnerabilities, including 33 critical, 167 important, and three publicly disclosed zero-days, with Edge Chromium fixes excluded from this release. Zero-days include CVE-2026-49160 HTTP.sys denial of service, CVE-2026-45586 CTFMON elevation of privilege, and CVE-2026-50507 BitLocker security bypass affecting Windows components and physical attack scenarios. The release spans Windows, Office, Hyper-V, BitLocker, and networking components, alongside Adobe updates covering 123 vulnerabilities, including 47 rated critical.

Source: Qualys

npm Bug Marks One-Character Packages as Security Holders

npm tooling incorrectly applied security-holder metadata (0.0.1-security and 0.0.1-security.0) to multiple one-character packages, including single letters, numbers, and symbol-based package names, while shifting the latest dist-tag to placeholder versions across affected registry entries. Socket reported that npm attributed the behaviour to a tooling bug and said it is being rolled back, with no evidence of package compromise and older versions still available in the registry. During the affected window, dependency resolution could surface placeholder versions in lockfiles where dist-tags were updated, despite underlying package versions remaining unchanged.

Source: Socket

npm Miasma Campaign Exploits binding.gyp for Install-Time Execution

Miasma supply chain malware affecting npm packages leverages binding.gyp and node-gyp to trigger install-time execution, enabling credential theft and system compromise during installation. Attack surface includes gyp command expansion syntax, actions, rules, compiler configuration, and includes or dependencies, all capable of executing arbitrary code during npm install. Analysis also highlights Python eval-based sandbox escape paths within binding.gyp, allowing arbitrary code execution even without standard package.json lifecycle hooks.

Hijacked Account Breaches French Government Tchap Messaging Service

France’s DINUM reported a breach of the Tchap Matrix-based government messaging platform after ANSSI detected access via a hijacked user account on Sunday. Attackers claiming responsibility said they used social engineering and accessed LDAP credentials, exfiltrating 13.5GB of files and scraping 650,000 messages from 73,000 accounts. Officials said investigation continues into exposed data noting public Tchap chat rooms are unencrypted and media files may be accessed via message links.

CISA Adds LiteLLM and Check Point Exploited Vulnerabilities

CISA added CVE-2026-42271, a BerriAI LiteLLM command injection vulnerability, and CVE-2026-50751, a Check Point Security Gateway improper authentication vulnerability, to its Known Exploited Vulnerabilities Catalog following evidence of active exploitation in the wild. The KEV Catalog is maintained under Binding Operational Directive 22-01 for US federal civilian agencies and tracks vulnerabilities identified through observed exploitation activity.

Source: CISA

Chrome Patches 74 Vulnerabilities Including Active V8 Exploit

Google released Chrome Stable channel update 149.0.7827.102/.103 addressing 74 security vulnerabilities across Windows, macOS, and Linux, including multiple critical use-after-free issues in components such as Ozone, Aura, Bluetooth, TabStrip, and File Input. The update includes CVE-2026-11645, a high-severity V8 out-of-bounds memory access vulnerability for which Google confirmed an exploit is active in the wild. Additional fixes cover integer overflows in libyuv and GPU components, along with numerous high-severity memory safety issues across rendering, media, and extension subsystems.

Daily Coverage

Developments
Patch Tuesday SurgeChrome Zero-DayLitellm ExploitationCheck Point Vpn Abuse
Vulnerabilities
CVE-2026-10520CVE-2026-50507CVE-2026-5027CVE-2026-10523CVE-2026-20245Cisco Catalyst Sd-Wan Controller 20.6.4 (High)CVE-2026-25089Fortisandbox 5.0.0 (Critical)CVE-2026-44180CVE-2026-45586CVE-2026-50751Quantum Security Gateway R82.10 With Jumbo Hotfix Take 19 Or Below (Critical)CVE-2026-49160
Threat Groups
CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.