Oracle issued an out-of-band fix for a critical PeopleSoft PeopleTools flaw (CVSS 9.8) that was exploited as a zero-day between May 27 and June 9, primarily against higher education. Rapid7 and Mandiant report the SSRF-to-RCE chain hit PSEMHUB and PSIGW endpoints, with data theft and MeshCentral backdoors observed; 68% of more than 100 notified victims were universities. Admins should patch PeopleTools 8.61/8.62 immediately, disable EMHub where possible, block access to /PSEMHUB/* and /PSIGW/HttpListeningConnector, and hunt for IOCs even after remediation. Expect continued opportunistic scanning as details propagate.
Source: Rapid7
PoC released for actively exploited Check Point VPN auth bypass (CVE-2026-50751)
WatchTowr published technical details and a “Detection Artefact Generator” for an authentication bypass in Check Point Remote Access VPN and Mobile Access that the vendor confirmed was already under limited, in-the-wild exploitation. With public artifacts now available, a broader wave of attacks is likely. Organizations should apply Check Point’s June 8 fixes without delay, review VPN gateway logs for anomalous sessions, and rotate credentials where compromise is suspected.
Source: Help Net Security
Over 400 Arch Linux AUR packages hijacked to deploy infostealer and eBPF rootkit
Attackers compromised more than 400 Arch User Repository packages by altering build scripts to install a Rust-based credential stealer, with the capability to load an eBPF rootkit when run as root. The campaign targets developer secrets and supply chains by abusing the trust model of community-maintained packages. Teams should audit recent AUR installs/updates, verify maintainers and checksums, rebuild from trusted sources, and revoke/rotate any exposed tokens or keys.
Source: The Hacker News
China-linked group hid in Linux login stack for nearly a decade via PAM/OpenSSH backdoors
Sygnia uncovered a long-running operation in which a China-nexus threat actor backdoored core Linux authentication components (PAM and OpenSSH), enabling stealthy, durable access that evaded typical cleanup. Because the implants lived inside the login pipeline itself, standard EDR and remediation playbooks often missed them. Defenders should verify package integrity from trusted repos, compare binaries against known-good hashes, rebuild compromised systems, and rotate credentials.
Source: The Hacker News
CISA orders rapid remediation of maximum-severity Ivanti Sentry flaw
The U.S. Cybersecurity and Infrastructure Security Agency added an Ivanti Sentry vulnerability to its Known Exploited Vulnerabilities catalog and urged patching on an accelerated timeline. The directive underscores active threat activity and the risk posed by internet-facing management gateways. Agencies and enterprises should apply vendor updates immediately and restrict external access where feasible until remediation is complete.
Source: Security Affairs
Splunk Enterprise pre-auth RCE detailed (CVE-2026-20253); patch now
WatchTowr analyzed Splunk’s June 10 advisory for CVE-2026-20253, a pre-authentication remote code execution issue in Splunk Enterprise, explaining how weak assumptions in component authentication enable code execution. Given Splunk’s ubiquity in SIEM and logging pipelines, compromise could provide high-privilege access and log tampering. Apply Splunk’s fixes immediately, limit network exposure to Splunk services, and monitor for suspicious queries or process launches from the platform.
Source: WatchTowr Labs
Google sues China-based “Outsider Enterprise” for AI-powered phishing at scale
Google filed suit against Outsider Enterprise, alleging the China-based network abused AI tools, including Gemini, to build phishing kits and infrastructure tied to hundreds of thousands of victims. The company links the operation to more than 9,000 fake websites and 1 million fraudulent URLs, highlighting how AI is accelerating scam creation and localization. Legal action aims to disrupt infrastructure and deter AI-enabled cybercrime.
Source: Help Net Security
You May Also Be Interested In...
Anthropic Says It Has Taken Its Latest AI Models Offline to Comply With New Export Controls
Chrome 149 Update Patches 28 Vulnerabilities
LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution