# Threat Intel Brief — 11 June 2026
TL;DR
- Critical zero-days patched: Microsoft addressed three actively exploited zero-days (YellowKey, GreenPlasma, MiniPlasma) enabling SYSTEM privilege escalation and BitLocker bypass; Chrome V8 flaw (CVE-2026-11645) under active exploitation.
- AI platform under attack: Langflow AI development platform (CVE-2026-5027) exploited for unauthenticated remote code execution; no patch available.
- China-nexus reconnaissance escalates: JDY botnet expands to 1,500+ devices targeting U.S. military networks; Volt Typhoon-linked infrastructure intensifies reconnaissance operations.
- Enterprise infrastructure at risk: Actively exploited flaws in Check Point VPN, ServiceNow, Cisco SD-WAN (CVE-2026-20245), and SolarWinds Serv-U demand immediate patching.
- Supply chain compromises: Microsoft's GitHub repositories infiltrated with password-stealing malware; PyPI Hades campaign deploys credential stealers via 19 poisoned packages.
---
Critical Threats
Langflow AI Platform Path Traversal (CVE-2026-5027)
What happened: Attackers are actively exploiting CVE-2026-5027, an unpatched path traversal vulnerability in Langflow, an open-source AI development platform. The flaw allows unauthenticated attackers to write arbitrary files to exposed servers, enabling remote code execution. CVSS score: 8.8.
Impact: Organizations running internet-facing Langflow instances face immediate compromise risk. Arbitrary file write capabilities enable webshell deployment, privilege escalation, and persistence mechanisms. AI development environments often contain sensitive training data, API keys, and intellectual property, making them high-value targets for data exfiltration and supply chain attacks.
Recommendations:
- Remove all Langflow instances from internet exposure immediately or place behind VPN/authentication
- Audit file systems on exposed servers for unauthorized files, particularly in web-accessible directories
- Monitor Langflow GitHub and security advisories for patch availability and apply immediately upon release
- Review authentication logs and network traffic for indicators of compromise since disclosure
- Implement network segmentation isolating AI development platforms from production systems
---
Microsoft Zero-Days: YellowKey, GreenPlasma, MiniPlasma
What happened: Microsoft patched three zero-day vulnerabilities exploited in the wild. YellowKey and GreenPlasma enable SYSTEM privilege escalation on fully patched Windows systems. MiniPlasma grants unauthorized access to BitLocker-protected drives. CVE identifiers not yet publicly assigned.
Impact: Critical impact across all Windows environments. Attackers with initial access can escalate to SYSTEM privileges, achieving full host control. MiniPlasma undermines BitLocker encryption protections, exposing encrypted data on lost or stolen devices. Zero-day status confirms threat actors possess operational exploits.
Recommendations:
- Deploy Microsoft security updates immediately via WSUS, SCCM, or Windows Update
- Review Windows Security Event Logs (Event IDs 4672, 4688) for unexpected SYSTEM-level process creation in past 30 days
- Audit BitLocker-protected systems for unauthorized physical access; review TPM and BitLocker event logs (Event IDs 851, 854)
- Implement application whitelisting and restrict local administrator rights to limit post-exploitation opportunities
- Monitor EDR telemetry for SYSTEM-level anomalies and privilege escalation indicators
---
Chrome V8 Zero-Day Under Active Exploitation (CVE-2026-11645)
What happened: Google patched CVE-2026-11645, a high-severity out-of-bounds memory access flaw in Chrome's V8 JavaScript engine, actively exploited in the wild. CVSS score: 8.8. Affects Chrome versions prior to 149.0.7827.103.
Impact: Memory corruption in V8 enables remote code execution via malicious web content. Users visiting compromised or attacker-controlled sites face immediate risk of browser compromise, credential theft, or lateral movement. Active exploitation means drive-by attacks are occurring now.
Recommendations:
- Deploy Chrome version 149.0.7827.103 or later immediately via enterprise update mechanisms
- Verify auto-update is enabled for end-user Chrome installations and confirm version compliance
- Monitor for and deploy security updates for Chromium-based browsers (Edge, Brave, Opera, Vivaldi)
- Review web proxy and endpoint logs for unusual JavaScript execution patterns
- Consider temporary network restrictions on high-risk user groups accessing untrusted websites until patching is complete
---
Microsoft Defender RoguePlanet Zero-Day
What happened: Security researcher Chaotic Eclipse released a proof-of-concept exploit for RoguePlanet, a Microsoft Defender zero-day enabling SYSTEM privilege escalation on updated Windows systems. The exploit leverages a race condition vulnerability with reported 100% success rate. No CVE assigned.
Impact: Attackers with local access can escalate to SYSTEM level, achieving complete endpoint control. This bypasses security controls enforced by the very product designed to protect the system. Particularly severe as Defender runs with high privileges by default and is present on most Windows environments.
Recommendations:
- Monitor Microsoft Security Response Center for emergency patch release and deploy immediately
- Enable enhanced logging for Microsoft Defender operations; monitor for unusual process spawning from MsMpEng.exe
- Review recent Defender activity logs and Windows Security Event IDs 4672, 4673, 4688 for unexpected SYSTEM-level token creation
- Implement application control policies (AppLocker/WDAC) to restrict execution of unauthorized binaries
- Audit systems for signs of compromise, particularly new SYSTEM-level scheduled tasks, services, or persistence mechanisms
---
Check Point VPN Authentication Bypass
What happened: A critical vulnerability in Check Point VPN affecting user authentication is being actively exploited in the wild. CERT.BE issued urgent patching guidance. CVE identifier not yet assigned.
Impact: Authentication bypass enables unauthorized remote access to corporate networks. Check Point solutions are widely deployed across critical infrastructure, defense contractors, and government agencies. Active exploitation increases likelihood of compromise.
Recommendations:
- Identify all Check Point VPN deployments and apply vendor security patches immediately
- Review VPN authentication logs for suspicious login attempts or anomalous access patterns
- Implement additional monitoring on Check Point VPN gateways for unauthorized access
- Consider temporary compensating controls such as IP allowlisting or MFA enforcement if patching is delayed
- Restrict network access to VPN management interfaces to trusted IP ranges only
---
Cisco SD-WAN Manager Actively Exploited (CVE-2026-20245)
What happened: CISA added CVE-2026-20245 to its Known Exploited Vulnerabilities catalog following reports of active exploitation. The vulnerability affects Cisco Catalyst SD-WAN Manager with CVSS score 7.8, related to improper encoding or escaping of output.
Impact: Organizations using Cisco Catalyst SD-WAN Manager face immediate risk. SD-WAN infrastructure is critical for branch connectivity; compromise could enable lateral movement, traffic interception, or service disruption. CISA KEV listing mandates patching for federal agencies and signals threat actor interest.
Recommendations:
- Identify all Cisco Catalyst SD-WAN Manager instances and verify versions immediately
- Apply Cisco security patches for CVE-2026-20245 as soon as available
- Review SD-WAN Manager access logs for suspicious authentication attempts or unexpected configuration changes
- Restrict network access to SD-WAN Manager to trusted management networks and enforce MFA
- Monitor CISA KEV catalog and Cisco advisories for additional IOCs and updated remediation guidance
---
Threat Actor Activity
China-Nexus JDY Botnet Expansion
The JDY botnet, previously linked to Volt Typhoon and other Chinese state-sponsored actors, has expanded to over 1,500 compromised SOHO routers and IoT devices. The botnet operates as a centrally controlled, high-performance scanner conducting systematic reconnaissance against U.S. military networks and exposed services globally. This represents an escalation in APT activity targeting critical U.S. defense infrastructure.
Defensive actions:
- Monitor for anomalous outbound scanning activity from SOHO routers and IoT devices
- Implement network segmentation isolating IoT devices from critical infrastructure
- Deploy threat intelligence feeds containing known JDY botnet C2 infrastructure
- Enforce firmware updates and strong authentication on all SOHO routers and IoT devices
- Establish baseline traffic profiles for IoT/SOHO devices and alert on deviations
---
Russia-Aligned Groups Target Ukraine via WinRAR
Earth Dahu (Gamaredon) and SHADOW-EARTH-066 (UAC-0226), Russia-aligned threat actors, are actively exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR, to target Ukrainian organizations and deploy stealer malware. The exploitation occurs nearly a year after patches were released, indicating targeting of organizations with delayed patch cycles.
Defensive actions:
- Update WinRAR to the latest version immediately on all endpoints
- Block or quarantine unsolicited RAR archives at email gateways
- Deploy endpoint detection rules monitoring for WinRAR spawning suspicious child processes
- Monitor for stealer malware indicators including access to credential stores and browser data directories
- Hunt for indicators of compromise associated with Earth Dahu and SHADOW-EARTH-066 campaigns
---
ShinyHunters Targets Oracle PeopleSoft
The ShinyHunters extortion gang is conducting ongoing data theft attacks against Oracle PeopleSoft servers, claiming to have stolen data from over 100 organizations. The campaign demonstrates systematic exploitation of enterprise resource planning platforms.
Defensive actions:
- Apply latest Oracle PeopleSoft security patches immediately
- Implement network segmentation to isolate PeopleSoft servers from direct internet exposure
- Enable comprehensive logging for PeopleSoft application servers and monitor for unusual authentication attempts
- Deploy data loss prevention controls to detect large-scale database exports
- Review PeopleSoft access controls and implement least-privilege principles
---
The Gentlemen Ransomware Surge
The Gentlemen ransomware group has emerged as the second most active ransomware gang by victim count, operating an aggressive affiliate recruitment model offering 90% ransom splits. This favorable revenue-sharing structure has enabled rapid scaling of operations.
Defensive actions:
- Monitor for double extortion indicators including large-scale data exfiltration preceding encryption events
- Implement behavioral detection for ransomware execution patterns
- Strengthen initial access controls by enforcing MFA on all remote access services
- Deploy network segmentation to limit lateral movement
- Maintain offline, immutable backups and regularly test restoration procedures
---
Geopolitical Context
U.S.-China Cyber Tensions Escalate
The expansion of the JDY botnet's reconnaissance operations against U.S. military networks occurs amid heightened U.S.-China strategic competition across the Indo-Pacific. The targeting of defense and military sectors suggests intelligence collection priorities aligned with understanding U.S. force posture, operational capabilities, and potential response mechanisms. This activity may accelerate allied efforts to harden critical infrastructure and expand threat intelligence sharing through frameworks like the Quad and AUKUS.
Russia-Ukraine Cyber Operations Continue
Russia-aligned threat actors maintain sustained cyber operations against Ukrainian targets, exploiting known vulnerabilities in widely deployed software. The continued exploitation of CVE-2025-8088 nearly a year post-patch reflects persistent challenges in cybersecurity hygiene within resource-constrained environments and demonstrates Moscow's strategic use of cyber capabilities to maintain intelligence collection and disruptive pressure on Ukrainian infrastructure.
European Critical Infrastructure Under Pressure
Multiple advisories from European CERTs (Belgium, EU) highlight active exploitation of vulnerabilities in Check Point VPN, VMware virtualization platforms, SolarWinds Serv-U, and MISP threat intelligence platforms. These warnings reflect heightened vigilance regarding vulnerabilities that could be leveraged for strategic intelligence gathering against NATO and EU institutional networks.
---
Recommended Actions
Immediate (0-24 hours)
1. Patch actively exploited vulnerabilities: Deploy updates for CVE-2026-5027 (Langflow, when available), CVE-2026-11645 (Chrome), CVE-2026-20245 (Cisco SD-WAN), Microsoft zero-days (YellowKey, GreenPlasma, MiniPlasma), Check Point VPN, and SolarWinds Serv-U
2. Isolate Langflow instances: Remove all internet-facing Langflow deployments from public exposure immediately
3. Audit Microsoft GitHub dependencies: Review all repositories, CI/CD pipelines, and build systems for dependencies on compromised Microsoft GitHub organizations
4. Hunt for JDY botnet activity: Scan for compromised SOHO routers and IoT devices exhibiting reconnaissance behavior
5. Review ServiceNow access logs: Audit ServiceNow instances for anomalous unauthenticated access attempts from May-June 2026
Within 24-72 hours
1. Deploy Microsoft Patch Tuesday updates: Prioritize the 36 critical-severity vulnerabilities from June 2026 Patch Tuesday, focusing on internet-facing systems
2. Patch Veeam Backup & Replication: Apply security updates for CVE-2026-44963 (CVSS 9.4) to all Backup & Replication servers
3. Update SAP systems: Apply SAP June 2026 Security Patch package addressing 15 vulnerabilities, including four critical flaws in NetWeaver and Commerce Cloud
4. Remediate Ivanti Sentry: Apply patches for two critical vulnerabilities enabling unauthenticated remote code execution
5. Scan for PyPI supply chain compromise: Audit Python environments for 19 compromised PyPI packages from Hades campaign
This week
1. Fortify AI development environments: Implement network segmentation, enhanced logging, and access controls for AI platforms
2. Review WinRAR deployments: Update all WinRAR installations to latest version addressing CVE-2025-8088
3. Assess protobuf.js exposure: Identify Node.js applications using protobuf.js and update to patched versions
4. Strengthen VPN security: Review all VPN solutions for authentication bypass vulnerabilities and enforce MFA
5. Conduct supply chain security review: Implement dependency scanning and software composition analysis in CI/CD pipelines
---
Watch List
- Microsoft Defender RoguePlanet: Monitor for emergency patch release; public PoC available
- BerriAI LiteLLM (CVE-2026-42271): CISA KEV-listed command injection under active exploitation
- Windows Server domain controller RCE: Critical unauthenticated RCE under active exploitation (CVE not assigned)
- MISP platform: Critical vulnerability disclosed by CERT.BE requiring immediate patching
- OpenClaw AI agent: Phishing vulnerability in AI email processing systems
- FROST attack: Novel SSD timing-based tracking technique; monitor for browser vendor mitigations
---
Sources
This report synthesizes intelligence from BleepingComputer, The Hacker News, Krebs on Security, CERT-EU, CERT.BE (Belgium), and CERT.PL (Poland). Full source citations available in the detailed analysis sections above.
