STORIES LAST WEEK
Ivanti Sentry flaw is exploited against exposed gateways
CVE-2026-10520 lets attackers run root commands on Ivanti Sentry gateways and Shadowserver says unpatched exposed systems are likely compromised. CISA gave federal teams three days to secure affected appliances. BleepingComputer, June 12, 2026
ShinyHunters exploited Oracle PeopleSoft zero-day in education attacks
ShinyHunters exploited CVE-2026-35273 before Oracle’s advisory, targeting PeopleSoft in mostly U.S. higher education environments. Mandiant says attackers used disguised MeshCentral agents for reconnaissance, command execution, and lateral movement. Google Cloud, June 11, 2026
ServiceNow bug exposed customer instance data to the internet
A ServiceNow bug let unauthenticated internet users access some customer instance data before a June 5 patch. Admins should review logs for exposed support tickets, credentials, keys, and asset records. TechCrunch, June 10, 2026
Microsoft fixes exploited Exchange flaw in record Patch Tuesday
Microsoft patched 200 flaws, including six zero-days and one exploited Exchange Server spoofing bug. The release also covers critical Office, Azure Kubernetes Service, Active Directory, and HTTP.sys vulnerabilities. BleepingComputer, June 9, 2026
SAP patches critical NetWeaver and Commerce Cloud flaws
Splunk fixed CVE-2026-20253, an unauthenticated file creation flaw in Splunk Enterprise’s PostgreSQL sidecar service. The bug matters because logging and search platforms often hold sensitive telemetry, credentials, and incident data. SecurityWeek, June 11, 2026
Splunk Enterprise bug allows unauthenticated file creation
Splunk fixed CVE-2026-20253, an unauthenticated file creation flaw in Splunk Enterprise’s PostgreSQL sidecar service. Palo Alto also patched Cortex XSOAR and XSIAM credential validation bugs that affect restricted resources. SecurityWeek, June 11, 2026
LangGraph flaws enable remote code execution in AI agent deployments
Check Point showed how LangGraph SQLite and Redis checkpointer flaws can chain SQL injection, unsafe deserialization, and state persistence into remote code execution on self-hosted AI agent deployments. Check Point Research, June 11, 2026
Fake Sentry reports can hijack AI coding agents
Tenet demonstrated Agentjacking, where forged Sentry error reports make coding agents run attacker-controlled npm packages. Testing found 2,388 exposed organizations and agent execution across enterprises, startups, and developers. Tenet Security, June 9, 2026
Google lawsuit ties Gemini abuse to phishing infrastructure
Google sued Outsider Enterprise, alleging Gemini-assisted phishing infrastructure generated 9,000 fake sites and 1 million URLs. The case ties AI abuse to Telegram distribution, smishing, and credential theft. Help Net Security, June 12, 2026
CISA orders risk-based patch deadlines for federal agencies
BOD 26-04 gives federal agencies three days to remediate the riskiest flaws when exposure, KEV status, automation, and asset control line up. The directive formalizes risk-based patch prioritization. Cybersecurity Dive, June 10, 2026
FBI seizes fake recruiting sites tied to Chinese intelligence
The FBI seized 13 fake consulting websites allegedly used to recruit current and former cleared U.S. workers. Investigators said the operators relied on stolen identities, sham LinkedIn postings, and cryptocurrency payments. SecurityWeek, June 11, 2026
Cyberattack halts two Australian sugar mills during harvest
A cyberattack halted two Mackay Sugar mills in Queensland, forcing growers to stop harvesting during crushing season. The outage shows how IT disruption can quickly hit industrial operations and supply chains. The Record, June 10, 2026
Britain weakens telecom security rules after industry objections
Britain softened Salt Typhoon-era telecom guidance after industry objections, dropping independent signaling detection, untrusted-by-default signaling, and monthly restart requirements. Service account security deadlines also moved to 2029. The Record, June 9, 2026
More cybersecurity news
- Last week’s news roundup
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
