Oracle Critical Security Patch Update addresses 243 CVEs including 122 critical updates. Notable: MySQL Shell for VS Code (CVSS 9.9) allows complete takeover via HTTP with no user interaction; Oracle Solaris 11.4 Remote Administration Daemon (CVSS 10.0) permits unauthenticated remote exploit via HTTPS.
Apply Oracle June 2026 CSPU patches immediately across all affected products. Prioritize internet-facing MySQL and Solaris systems. Review and restrict remote administration access.
Source: Oracle • Published: 2026-06-11
Systemic architectural vulnerability in Anthropic MCP enables Arbitrary Command Execution (RCE) across all implementations. Design flaw affecting 150M+ downloads, 7,000+ public servers, up to 200,000 vulnerable instances. Includes CVE-2025-49596, CVE-2026-22252, CVE-2026-22688, CVE-2025-54994, CVE-2025-54136 affecting LiteLLM, LangChain, IBM LangFlow.
Block public IP access to sensitive MCP services. Implement authentication on all MCP servers (40% currently unauthenticated). Run MCP-enabled services in sandboxes. Treat external MCP configuration as untrusted input. Only install MCP servers from verified sources. Audit third-party MCP server dependencies.
Source: OX Security • Published: 2026-04-15
North Korean Sapphire Sleet (BlueNoroff) compromised 140+ npm packages in Mastra AI framework. Threat actors compromised npm maintainer account 'ehindero'. Includes easy-day-js typosquat with obfuscated postinstall dropper. 1.1M+ weekly downloads exposed. Microsoft attributes with high confidence to North Korean state actor targeting financial sector.
If any @mastra package installed June 16-17, treat environment as compromised. Scan for easy-day-js dependency in package.json. Rotate all credentials and tokens in affected environments. Implement SCA with real-time threat intelligence. Verify npm package maintainer authenticity.
Source: Microsoft • Published: 2026-06-17
VIPER-MCP scan of 40,000 MCP server repositories uncovered 106 zero-day vulnerabilities, producing 67 CVEs. Censys identified 12,520 Internet-accessible MCP services, 40% unauthenticated. 36.7% of 7,000+ servers vulnerable to SSRF. PoC against Microsoft MarkItDown retrieved AWS IAM credentials from EC2 metadata.
Implement authentication on all MCP servers immediately. Follow NSA guidance on MCP security including inverted client-server pattern risks and task propagation verification. Deploy VIPER-MCP scanning framework for vulnerability assessment.
Source: GTIG • Published: 2026-06-01
IDEsaster campaign uncovered 24 CVE-assigned vulnerabilities across AI IDEs. 100% of tested AI IDEs vulnerable to prompt injection. Includes CamoLeak in Copilot, case-sensitivity bypass in Cursor, RCE via config files in Claude Code. Rules Files Backdoor persists across project forks. 45% of AI-generated code contains security vulnerabilities (70%+ in Java).
Enable workspace trust and restrict to verified repositories only. Implement mandatory code review for all AI-generated code. Deploy application security scanning specifically for AI-generated code. Enable Privacy Mode to prevent vendor code storage. Configure rule file validation and sanitization.
Source: Veracode • Published: 2026-06-01
ShinyHunters (UNC6240) exploited CVE-2026-35273 zero-day compromising 100+ organizations (68% higher education) between May 27-June 9. 300 PeopleSoft instances targeted. University of Nottingham: 454,600 records published. Data published on ShinyHunters leak site.
Disable EMHub Service or block /PSEMHUB/* and /PSIGW/HttpListeningConnector at perimeter. Apply Oracle patches immediately. Hunt for README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT indicators. Review access logs for May 27-June 9 compromise period. Notify affected individuals per breach notification requirements.
Source: Mandiant • Published: 2026-06-10
ShinyHunters breached Canvas LMS twice (May 6-7, 2026) despite Instructure's resolution claim. Affects 30M active users at 8,000+ educational institutions (41% North American higher education market share). Ransom note posted May 3.
Force password resets for all Canvas LMS accounts. Review authentication logs for May 3-7 period. Implement MFA for all Canvas administrative accounts. Audit SSO and OAuth configurations for abuse. Monitor for credential stuffing attacks using exposed data.
Source: BleepingComputer • Published: 2026-05-07
ShinyHunters stole 409,000+ payslips for 10,000+ Council of Europe staff (2011-2026), 3,700+ personnel files, 14,000+ CVs. Exposed: names, DOB, addresses, phones, employee IDs, salaries, bank accounts, tax information, medical records.
Council of Europe must provide identity theft protection services to affected staff. Implement enhanced monitoring for financial fraud. Review and strengthen access controls on HR systems. Conduct forensic investigation of access methods. Notify data protection authorities per GDPR Article 33.
Source: BleepingComputer • Published: 2026-06-01
Q1 2026 ransomware activity plateaued at elevated 2025 levels. The Gentlemen expanded from 35 victims (Q4 2025) to 182 (Q1 2026). NightSpire claimed 175 victims across 28 industries, posting 74 on leak site. Trend: shift from encryption-based to data theft/extortion-only operations.
Implement immutable backups with air-gapped storage. Deploy EDR with ransomware-specific behavioral detection. Conduct tabletop exercises for extortion-without-encryption scenarios. Enhance data loss prevention (DLP) controls. Maintain offline emergency response runbooks.
Source: GuidePoint • Published: 2026-04-01
ORACLE-JUN-2026: Oracle Critical Security Patch Update addresses 243 CVEs including 122 critical updates. Notable: MySQL Shell for VS Code (CVSS 9.9) allows complete takeover via HTTP with no user interaction; Oracle Solaris 11.4 Remote Administration Daemon (CVSS 10.0) permits unauthenticated remote exploit via HTTPS.