Adobe Campaign Classic contains two CVSS 10.0 vulnerabilities in single security bulletin. Extremely rare severity rating indicates complete system compromise potential. Adobe reports no active exploitation but expects heavy research into weaponization.
Deploy Adobe Campaign Classic updates as Priority 1 immediately. Also prioritize ColdFusion and Acrobat Reader patches. Monitor systems for unusual activity. Implement network segmentation to isolate Campaign Classic servers.
Source: Adobe • Published: 2026-06-24
Supply chain attack compromised 32 packages under @redhat-cloud-services namespace via compromised GitHub account. Miasma worm deployed within 72-second window using automation. Packages have 80,000 weekly downloads and 10 million cumulative downloads. Affects Red Hat Hybrid Cloud Console.
Audit all dependencies using @redhat-cloud-services packages immediately. Rotate all developer GitHub credentials and access tokens. Scan development and production environments for Miasma indicators. Review Red Hat security advisory RHSB-2026-006 for affected package versions.
Source: Red Hat • Published: 2026-06-01
Mini Shai-Hulud supply chain attack by TeamPCP compromised TanStack packages to steal GitHub credentials, cloud secrets, SSH keys, and CI/CD tokens. Two OpenAI employee devices compromised. Limited credential exfiltration and source code repository access occurred. OpenAI signing keys for all platforms affected.
Rotate all GitHub PATs, AWS credentials, and CI/CD secrets immediately. Scan developer workstations for compromise indicators. Organizations must revoke and reissue code signing certificates. Update all TanStack dependencies to verified clean versions. Implement software bill of materials (SBOM) monitoring.
Source: OpenAI • Published: 2026-05-11
Breach of Tchap, France's government-exclusive messaging app built by DINUM and ANSSI. Threat actor 'misere' claims theft of 13.5GB including 73,467 government user accounts, 643,459 messages, 876 chat rooms with history, and 59,386 shared media files. Used exclusively by French government since 2025 foreign chat app ban.
French government personnel should assume all Tchap communications compromised. Conduct immediate threat assessment for exposed sensitive government discussions. Rotate all government credentials. Investigate breach vector and implement enhanced security controls. Consider all chat room participants potentially exposed to surveillance. Assess operational security impact of message exposure.
Source: SharkStriker • Published: 2026-06-24
ShinyHunters (UNC6240) exploited CVE-2026-35273 affecting 100+ organizations, 68% in higher education. Targeted Illinois Central College, Oxford career services (Salesforce breach), and Infinite Campus K-12 system affecting 137,000+ staff accounts.
Educational institutions must patch PeopleSoft immediately and conduct forensic analysis. Monitor for data exfiltration indicators. Implement enhanced monitoring on Salesforce and student information systems. Review access logs for unauthorized activity. Notify affected individuals per breach notification requirements.
Source: GTIG • Published: 2026-06-24
ShinyHunters claims theft of 409,000+ documents including 10+ years of payslips for 10,000+ staff, 3,700+ personnel files, and 14,000+ CVs. Exposed data includes names, DOB, addresses, phone numbers, employee IDs, salaries, bank accounts, tax/Social Security info, and medical records.
Affected Council of Europe staff should monitor for identity theft and place fraud alerts on credit files. Watch for targeted phishing campaigns leveraging stolen personal information. Consider credit monitoring services. Council should provide breach notification and support services to affected individuals.
Source: BleepingComputer • Published: 2026-06-24
Data breach through Texas Parks & Wildlife hunting/fishing license system exposed driver's license information and passport numbers of 3+ million people. Government-issued ID document breach affects Texas residents statewide.
Texas residents should monitor credit reports closely and place security freezes with all three credit bureaus. Watch for identity theft indicators and fraudulent account openings. Consider identity theft protection services. Monitor for phishing attempts using exposed personal information.
Source: BleepingComputer • Published: 2026-06-24
Breach affecting clinical trial patient data including patient IDs, trial participation, demographics, biomarkers, health/immunogenicity data, and lifestyle factors. Healthcare professional data exposed includes names, registration numbers, contact information. Threat actors demanding $25 million ransom.
Clinical trial participants should monitor for targeted phishing leveraging exposed health information. Healthcare providers should watch for social engineering attempts. Novo Nordisk should provide breach notification and monitoring services. Do not pay ransom; engage law enforcement and forensic incident response.
Source: BleepingComputer • Published: 2026-06-24
Klue OAuth breach enabled new 'Icarus' threat actor to steal Salesforce CRM data from multiple organizations in ongoing extortion campaign. Compromised OAuth tokens provided access to customer data. LastPass confirmed their sales data exposed via Klue compromise. Icarus first spotted April 2026.
Organizations using Klue must revoke all OAuth tokens immediately and rotate Salesforce credentials. Conduct forensic analysis of CRM data access and exfiltration. Review OAuth application permissions and implement least-privilege access. Monitor for extortion attempts from Icarus threat actor. Enable MFA on all Salesforce accounts.
Source: BleepingComputer • Published: 2026-06-24
Meta disclosed password reset exploit via vulnerable HTS tool code path. Number of affected users not disclosed. Meta disabled tool, removed vulnerable code, and invalidated all password-reset links. Affected accounts placed behind mandatory security checkpoint requiring password reset and re-authentication.
Instagram users should enable two-factor authentication immediately. Review account activity and connected sessions for unauthorized access. Monitor email account associated with Instagram for suspicious password reset attempts. Update Instagram password using strong, unique credentials.
Source: Meta • Published: 2026-06-05
M-Trends 2026 reports attackers exploit vulnerabilities average 7 days before public disclosure. Threefold increase in software supply chain attacks over past year targeting open-source libraries and critical infrastructure. Traditional patch lifecycle functionally inverted with vendor exposure occurring before fixes exist.
Implement zero-day vulnerability monitoring and threat intelligence feeds. Deploy runtime application self-protection (RASP) and virtual patching capabilities. Maintain comprehensive software bill of materials (SBOM) for all applications. Implement supply chain security scanning in CI/CD pipelines. Establish vendor risk management program with continuous monitoring.
Source: Mandiant • Published: 2026-06-24
Microsoft reports security engineers and researchers increasingly using AI tools for vulnerability discovery, with surveys showing 90% AI usage among security professionals. Record-breaking vulnerability volumes, particularly browser and Linux kernel CVEs, attributed to AI-assisted discovery. Microsoft no longer enumerates Chromium CVEs in Security Update Guide due to volume.
Security teams should integrate AI-assisted vulnerability scanning tools into security testing workflows. Increase patch management capacity to handle higher vulnerability volumes. Prioritize vulnerabilities based on exploitability and exposure rather than volume. Implement continuous monitoring for emerging CVEs across all technology stacks.
Source: MSRC • Published: 2026-06-24
ADOBE-2026-JUN: Adobe Campaign Classic contains two CVSS 10.0 vulnerabilities in single security bulletin. Extremely rare severity rating indicates complete system compromise potential. Adobe reports no active exploitation but expects heavy research into weaponization.