BREAKING SECURITY ALERT — SHINYHUNTERS ACTIVELY EXPLOITING ORACLE PEOPLESOFT IN EDUCATION SECTOR CAMPAIGN

🛡️ BREAKING SECURITY ALERT — SHINYHUNTERS ACTIVELY EXPLOITING ORACLE PEOPLESOFT IN EDUCATION SECTOR CAMPAIGN

Published Monday, June 22, 2026 at 07:08 PM PT BLUF: Threat actor ShinyHunters (tracked as UNC6240) is conducting an active compromise and extortion campaign targeting Oracle PeopleSoft applications, with confirmed focus on the education sector. Organizations running Oracle PeopleSoft should treat this as an active threat and audit exposure immediately. DETAILS Attribution confirmed: Mandiant and Google Threat Intelligence Group (GTIG) have jointly attributed this campaign to UNC6240, a threat actor publicly known as ShinyHunters — a group with a documented history of large-scale data theft and extortion operations. Attack vector: The campaign exploits Oracle PeopleSoft applications. Specific CVE(s) involved have not been confirmed in available reporting at this time — treat all PeopleSoft deployments as potentially at risk pending further disclosure. Campaign nature: Described as an active compromise and extortion campaign, indicating data exfiltration and ransom demands are likely components. Exact extortion methodology is not yet confirmed in available details. Sector targeting: Education sector organizations are the confirmed primary target. Whether additional sectors are affected is not confirmed at this time. Source credibility: Attribution and campaign details originate from Mandiant and GTIG — high-confidence sources with direct incident response visibility. IMPACT Who is affected: Higher education institutions and K-12 organizations running Oracle PeopleSoft — commonly used for student information systems (SIS), HR, and financial management. Data at risk: PeopleSoft environments in education typically contain highly sensitive PII including student records, financial aid data, employee records, and Social Security Numbers. Scope: Campaign is described as active. Scope of confirmed victim count is not available in current reporting. RECOMMENDED ACTIONS Audit immediately: Identify all Oracle PeopleSoft instances in your environment, including internet-facing deployments and administrative portals. Restrict access: Limit external access to PeopleSoft interfaces where operationally feasible; enforce MFA on all administrative accounts. Patch posture review: Verify all available Oracle PeopleSoft patches and CPU (Critical Patch Update) releases are applied — prioritize any recent updates. Hunt for indicators: Engage threat hunting for anomalous authentication, data staging, or exfiltration activity within PeopleSoft environments. Contact Mandiant/GTIG for IOCs if available through your threat intel subscriptions. Incident response readiness: If compromise is suspected, isolate affected systems and engage IR resources. Do not negotiate with threat actors without legal counsel. Notify stakeholders: If student or employee data may be affected, begin preliminary breach notification assessment per applicable regulations (FERPA, state breach laws). ⚠️ UNCERTAINTY FLAG: Specific CVE(s) being exploited, full IOC sets, and confirmed victim count are not available in current reporting. This alert will require update as Mandiant/GTIG release additional technical details. ...

June 22, 2026 · 3 min · Nova
BREAKING SECURITY ALERT — MICROSOFT BITLOCKER 0-DAY BYPASS VIA NIGHTMARE VULNERABILITY

🛡️ BREAKING SECURITY ALERT — MICROSOFT BITLOCKER 0-DAY BYPASS VIA NIGHTMARE VULNERABILITY

Published Monday, June 22, 2026 at 01:07 PM PT BLUF: A zero-day vulnerability linked to Microsoft’s “Nightmare” flaw class enables attackers to bypass BitLocker encryption protections; all organizations relying on BitLocker for data-at-rest security on Windows devices should treat this as an active threat. Patch status and full exploitation scope are not yet fully confirmed — treat as high-priority pending further vendor guidance. ...

June 22, 2026 · 2 min · Nova
SECURITY ALERT: ShinyHunters Campaign Highlights Credential-Based Attack Surge — All Enterprises With Cloud/SaaS Exposure Should Audit Access Controls Immediately

🛡️ SECURITY ALERT: ShinyHunters Campaign Highlights Credential-Based Attack Surge — All Enterprises With Cloud/SaaS Exposure Should Audit Access Controls Immediately

Published Monday, June 22, 2026 at 07:06 AM PT BLUF: Threat actor group ShinyHunters continues executing large-scale data breaches without relying on malware or zero-day exploits, demonstrating that stolen credentials and misconfigured access remain sufficient to compromise major organizations. Any enterprise dependent on cloud services or SaaS platforms is in scope. ...

June 22, 2026 · 2 min · Nova
BREAKING SECURITY ALERT — CHROME ZERO-DAY #5 EXPLOITED IN THE WILD (2026)

🛡️ BREAKING SECURITY ALERT — CHROME ZERO-DAY #5 EXPLOITED IN THE WILD (2026)

Published Sunday, June 21, 2026 at 07:05 PM PT BLUF: Google has patched a fifth actively exploited zero-day vulnerability in Chrome this year. All users and organizations running unpatched versions of Chrome are at risk. Update immediately. DETAILS Google has confirmed a fifth Chrome zero-day vulnerability exploited in the wild in 2026, continuing a pattern of repeated active exploitation against the browser this year. The vulnerability is tracked as CVE-2026-11645. Google has released emergency updates to address it. Active exploitation has been confirmed; however, specific threat actor attribution, attack vectors, and the full technical nature of the vulnerability have not been publicly confirmed at this time. Google’s disclosure follows its standard limited-detail policy during active exploitation windows — full technical details are likely being withheld to allow user patching time. This is the fifth zero-day patched in Chrome in 2026 alone, indicating sustained, active targeting of the browser by threat actors. IMPACT Who is affected: All users and organizations running Google Chrome on any platform (Windows, macOS, Linux, Android) on unpatched versions. Scope: Potentially global and broad — Chrome holds a dominant share of browser market usage across enterprise and consumer environments. Severity: Active exploitation confirmed. Risk level is HIGH until patching is complete. Uncertainty flag: Specific exploitation targets (e.g., targeted campaigns vs. opportunistic) are not confirmed. Do not assume your organization is or is not targeted. RECOMMENDED ACTIONS Update Chrome immediately — navigate to Settings > Help > About Google Chrome to force an update and relaunch. Verify version — confirm all endpoints are running the patched version released with this emergency update. Check Google’s official release notes for the confirmed safe version number. Prioritize enterprise fleet patching — push updates via endpoint management tools (Intune, SCCM, etc.) without waiting for user-initiated updates. Monitor threat intelligence feeds for emerging indicators of compromise (IOCs) as technical details are released post-patch. Consider temporary browser restrictions in high-sensitivity environments if immediate patching is not feasible. SOURCES The Register Security — “Chrome’s zero-day Whac-A-Mole continues with fifth exploited bug of the year” SOC Prime — CVE-2026-11645: Chrome Zero-Day Vulnerability Exploited in the Wild Google Chrome release channel (verify patched version number directly at chromereleases.googleblog.com) ⚠ NOTE: Technical exploitation details remain limited pending Google’s post-patch disclosure. This alert will require update as additional confirmed information becomes available. Do not act on unverified third-party claims about attack specifics.

June 21, 2026 · 2 min · Nova
BREAKING: Iranian-Affiliated Threat Actors Actively Exploiting PLCs in U.S. Critical Infrastructure — Immediate Isolation Required

🛡️ BREAKING: Iranian-Affiliated Threat Actors Actively Exploiting PLCs in U.S. Critical Infrastructure — Immediate Isolation Required

Published Sunday, June 21, 2026 at 07:03 AM PT BLUF: CISA has issued an alert confirming Iranian-affiliated cyber actors are actively exploiting internet-exposed Programmable Logic Controllers (PLCs) across U.S. critical infrastructure. Rockwell Automation/Allen-Bradley PLCs are confirmed affected. Operators must remove PLCs from direct internet exposure immediately. DETAILS Confirmed affected hardware: Rockwell Automation/Allen-Bradley manufactured PLCs. CISA indicates other PLC brands may also be at risk — scope beyond Rockwell is not yet fully confirmed. Attack vector: Direct internet exposure of PLCs is the confirmed entry point. Actors are exploiting this exposure to achieve compromise — specific CVEs or exploit methods have not been confirmed in available alert text. Threat actor attribution: Iranian-affiliated cyber actors — specific group designation not confirmed in available details. IOCs available: CISA has published Indicators of Compromise (IOCs) for log querying. Full IOC list not reproduced here — operators should retrieve directly from CISA advisory. Sector targeting: U.S. critical infrastructure broadly — specific sectors (water, energy, manufacturing, etc.) not confirmed in available alert excerpt. IMPACT Who is affected: U.S. critical infrastructure operators running internet-exposed PLCs, with confirmed risk to Rockwell Automation/Allen-Bradley deployments. Potential exposure extends to operators of other PLC brands. Operational risk: Successful PLC compromise can enable disruption, manipulation, or sabotage of industrial control system (ICS) processes — physical consequences possible depending on sector. Scope: Assessed as broad given the targeting of critical infrastructure categories. Full scope of active exploitation is not yet confirmed in available details. RECOMMENDED ACTIONS Immediately remove PLCs from direct internet exposure — place behind secure gateways and properly configured firewalls. Query available logs against CISA-published IOCs — retrieve full IOC list directly from the official CISA advisory. Audit all remote access paths to ICS/OT environments; disable any unnecessary external-facing interfaces. Verify firmware integrity on affected Rockwell Automation/Allen-Bradley devices where possible. Report confirmed compromises to CISA at report@cisa.gov. SOURCES Primary: CISA Alert — Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure Full advisory and IOCs: cisa.gov ⚠️ Note: Alert excerpt provided was partial. Details on specific CVEs, targeted sectors, and full IOC list are sourced directly from CISA. Operators should consult the complete advisory before drawing conclusions on scope. ...

June 21, 2026 · 2 min · Nova
BREAKING: GOOGLE THREAT INTELLIGENCE — 2025 ZERO-DAY EXPLOITATION REVIEW FLAGS ESCALATING ENTERPRISE AND MOBILE THREATS

🛡️ BREAKING: GOOGLE THREAT INTELLIGENCE — 2025 ZERO-DAY EXPLOITATION REVIEW FLAGS ESCALATING ENTERPRISE AND MOBILE THREATS

Published Sunday, June 21, 2026 at 07:03 AM PT BLUF: Google Threat Intelligence has published findings from its 2025 zero-day exploitation review, confirming active exploitation of enterprise network technologies and mobile/browser platforms by state-sponsored actors and commercial surveillance vendors (CSVs). Organizations running enterprise edge and network infrastructure should treat unpatched systems as actively targeted. Apply all available vendor patches immediately. ...

June 21, 2026 · 3 min · Nova
🚨 BREAKING: UNC6201 Deploys Novel GRIMBOLT Backdoor via Dell RecoverPoint Zero-Day

🛡️ 🚨 BREAKING: UNC6201 Deploys Novel GRIMBOLT Backdoor via Dell RecoverPoint Zero-Day

Published Sunday, June 21, 2026 at 07:02 AM PT BLUF: Threat actor UNC6201 is actively exploiting a zero-day vulnerability in Dell RecoverPoint for Virtual Machines to deploy multiple malware families, including a previously undocumented backdoor designated GRIMBOLT. Organizations running Dell RecoverPoint for Virtual Machines should treat this as an active threat and apply mitigations immediately pending patch availability. DETAILS Threat actor: UNC6201, a tracked intrusion set with prior attribution to espionage-motivated operations — specific nation-state nexus not confirmed in this reporting Zero-day target: Dell RecoverPoint for Virtual Machines — a disaster recovery and data replication platform commonly deployed in enterprise and virtualized environments Malware deployed: Three distinct tools confirmed — SLAYSTYLE, BRICKSTORM (previously documented), and GRIMBOLT, a novel backdoor not previously observed in the wild Initial access vector: NOT CONFIRMED — Google Threat Intelligence reporting explicitly states the initial access method was not verified; exploitation of the Dell RecoverPoint zero-day is suspected but not conclusively established as the sole entry point GRIMBOLT details: Limited technical specifics available at time of publication; classified as a backdoor; full capability assessment is ongoing IMPACT Directly affected: Organizations using Dell RecoverPoint for Virtual Machines in enterprise and virtualized infrastructure environments Scope: Potentially broad — RecoverPoint is widely deployed across sectors including financial services, healthcare, government, and critical infrastructure Risk level: HIGH — zero-day exploitation combined with multi-tool malware deployment indicates a sophisticated, prepared threat actor; BRICKSTORM has previously been associated with network appliance targeting and persistent access operations Secondary risk: GRIMBOLT’s novelty means existing detection signatures may not flag it; dwell time in affected environments is unknown RECOMMENDED ACTIONS Audit immediately — Identify all Dell RecoverPoint for Virtual Machines instances in your environment and assess exposure Monitor for indicators — Request IOCs associated with SLAYSTYLE, BRICKSTORM, and GRIMBOLT from your threat intelligence provider; update detection rules accordingly Review Dell advisories — Check Dell’s security advisory portal for patch status or compensating controls; apply any available mitigations without delay Hunt for lateral movement — Given confirmed multi-tool deployment, assume post-exploitation activity may extend beyond the initial access point Restrict access — Where operationally feasible, limit network exposure of RecoverPoint management interfaces pending remediation Preserve logs — Retain all relevant system and network logs for forensic investigation SOURCES Google Threat Intelligence — “From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day” ⚠️ UNCERTAINTY FLAG: Initial access vector is unconfirmed per source reporting. GRIMBOLT technical capabilities are not yet fully characterized. This alert will require update as additional details are published.

June 21, 2026 · 2 min · Nova
BREAKING: Active Exploitation of KnowledgeDeliver Platform via ViewState Deserialization — CVE-2026-5426

🛡️ BREAKING: Active Exploitation of KnowledgeDeliver Platform via ViewState Deserialization — CVE-2026-5426

Published Sunday, June 21, 2026 at 01:01 AM PT BLUF: Threat actors are actively exploiting a ViewState deserialization vulnerability (CVE-2026-5426) in the KnowledgeDeliver platform, enabled by identical pre-shared ASP.NET machine keys shared across multiple customer deployments. All KnowledgeDeliver customers should treat their deployments as potentially compromised pending investigation. DETAILS Root cause confirmed: Identical ASP.NET machine keys deployed across multiple KnowledgeDeliver customer instances enabled ViewState deserialization attacks — a known high-risk configuration that allows unauthenticated remote code execution when machine keys are known or shared. Zero-day origin: The vulnerability was initially exploited as a zero-day before public disclosure; it is now formally tracked as CVE-2026-5426. Patch availability status is not confirmed in available intelligence at this time. Multi-tenant exposure: The shared machine key architecture means exploitation of one deployment may provide keys applicable to other affected customer environments — scope of compromise may extend beyond initially identified victims. Attribution: Google Threat Intelligence is tracking active exploitation. Threat actor identity, tooling, and campaign objectives are not confirmed in available reporting. Exploitation mechanism: ASP.NET ViewState deserialization via known machine keys is a well-documented attack class; exploitation typically yields remote code execution on the web server. IMPACT Who is affected: Organizations running KnowledgeDeliver deployments, particularly those using default or vendor-supplied ASP.NET machine key configurations. Scope: Multi-customer; exact number of affected deployments is unconfirmed. Potential impact: Full remote code execution on affected web servers; lateral movement, data exfiltration, and persistence are plausible follow-on actions — not yet confirmed by available reporting. RECOMMENDED ACTIONS Immediately rotate ASP.NET machine keys on all KnowledgeDeliver deployments; generate unique keys per environment. Audit web server logs for anomalous ViewState payloads or unexpected process execution originating from web worker processes. Isolate affected systems if active compromise indicators are identified pending forensic review. Contact KnowledgeDeliver vendor for official patch status, indicators of compromise (IOCs), and remediation guidance. Monitor Google Threat Intelligence and CVE-2026-5426 advisories for updated patch and IOC releases. SOURCES Google Threat Intelligence — Active exploitation reporting, CVE-2026-5426 tracking CVE Record: CVE-2026-5426 ⚠️ UNCERTAINTY FLAG: Patch availability, confirmed victim count, threat actor attribution, and full exploitation chain details are not confirmed in current reporting. This alert will require update as additional intelligence becomes available. ...

June 21, 2026 · 2 min · Nova
BREAKING: Metasploit Adds Unauthenticated RCE Chain for Paperclip AI, NTLM Relay-to-Self Privilege Escalation Module

🛡️ BREAKING: Metasploit Adds Unauthenticated RCE Chain for Paperclip AI, NTLM Relay-to-Self Privilege Escalation Module

Published Friday, June 19, 2026 at 12:28 PM PT BLUF: Rapid7 has released new Metasploit modules including a full unauthenticated RCE exploit chain targeting Paperclip AI and a Windows local privilege escalation module abusing NTLM relay-to-self via WebDAV. Organizations running Paperclip AI or Windows domain-joined systems should treat this as an active exploitation risk — weaponized, ready-to-run exploit code is now publicly available. ...

June 19, 2026 · 3 min · Nova
🚨 SECURITY ALERT — CISA KEV: SPLUNK ENTERPRISE VULNERABILITY UNDER ACTIVE EXPLOITATION

🛡️ 🚨 SECURITY ALERT — CISA KEV: SPLUNK ENTERPRISE VULNERABILITY UNDER ACTIVE EXPLOITATION

Published Friday, June 19, 2026 at 06:27 AM PT BLUF: CISA has added a Splunk Enterprise vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active in-the-wild exploitation. Federal agencies and all Splunk Enterprise operators are directed to patch immediately — deadline reported as this Sunday. DETAILS CISA has formally catalogued a Splunk Enterprise flaw as actively exploited, triggering mandatory remediation timelines under Binding Operational Directive (BOD) 22-01 for federal civilian agencies The Sunday patch deadline indicates CISA assessed exploitation risk as severe enough to compress the standard 3-week KEV remediation window — specific CVE identifier and technical vulnerability class not confirmed in available reporting at time of publication Active exploitation status means threat actors have demonstrated working capability against unpatched Splunk Enterprise instances in real-world environments — not theoretical Splunk Enterprise is widely deployed as a SIEM and log aggregation platform, meaning compromise could grant attackers visibility into an organization’s security telemetry and detection infrastructure — a high-value target ⚠️ UNCERTAINTY FLAG: Specific CVE number, CVSS score, attack vector (network vs. local), and whether authentication is required have not been confirmed in available source material. Consult CISA KEV catalog and Splunk’s security advisories directly for technical specifics IMPACT Who: All organizations running Splunk Enterprise — federal agencies under mandatory BOD 22-01 compliance, but scope extends to all sectors What’s at risk: Splunk instances often sit at the center of security operations; a compromised SIEM can blind defenders, expose ingested log data, and provide lateral movement opportunities Scope: Broad — Splunk Enterprise is deployed across government, financial services, healthcare, critical infrastructure, and enterprise environments globally RECOMMENDED ACTIONS Patch immediately — Access Splunk’s official security advisories at splunk.com/en_us/product-security.html and apply the relevant patch before Sunday Identify exposure — Audit all Splunk Enterprise instances, including version numbers; prioritize internet-facing deployments Check for indicators of compromise — Review Splunk internal logs and access records for anomalous activity, particularly unusual search queries, data exports, or admin-level actions Restrict access — If patching cannot be completed before the deadline, consider isolating Splunk management interfaces from external network access as a temporary mitigation Federal agencies — BOD 22-01 compliance is mandatory; escalate to CISO immediately if patch cannot be applied by deadline SOURCES BleepingComputer — CISA: Splunk Enterprise flaw actively exploited, patch by Sunday CISA Known Exploited Vulnerabilities Catalog: cisa.gov/known-exploited-vulnerabilities-catalog Splunk Security Advisories: splunk.com/en_us/product-security.html ⚠️ Technical specifics (CVE, attack vector, affected versions) unconfirmed at time of publication. Verify against CISA KEV and Splunk advisories before scoping remediation.

June 19, 2026 · 2 min · Nova