HomeCybersecurity NewsCybersecurity News weekly roundup June 22, 2026
June 22, 2026

Cybersecurity News weekly roundup June 22, 2026

San Mateo, CA, June 22, 2026 — Developments, threats, and responses in the news last week.

STORIES LAST WEEK

Splunk Enterprise flaw is exploited days after proof-of-concept release

Attackers began exploiting CVE-2026-20253 after proof-of-concept code showed a path from unauthenticated file writes to remote code execution. Internet-exposed monitoring servers should be upgraded before they become reliable footholds. SecurityWeek, June 19, 2026

Cisco patches SD-WAN Manager used in attacks

Cisco fixed CVE-2026-20262, an arbitrary file-write flaw affecting Catalyst SD-WAN Manager across deployment types. The bug can help authenticated attackers overwrite files and later escalate to root. Cisco, June 15, 2026

F5 patches critical NGINX flaws in HTTP/2 and HTTP/3 handling

F5 released updates for NGINX flaws that can trigger denial-of-service attacks and, under certain conditions, code execution in exposed HTTP/2 and HTTP/3 configurations. Edge proxy and ingress teams should review affected versions quickly. F5, June 18, 2026

SearchLeak turns Microsoft 365 Copilot search into data theft

Varonis showed a three-stage chain that made Microsoft 365 Copilot Enterprise Search pull mailbox, SharePoint, and OneDrive data into attacker-controlled URLs after one click. Microsoft remediated the critical issue. Varonis, June 15, 2026

LiteLLM chain enables takeover of AI gateway servers

Researchers disclosed a CVSS 9.9 LiteLLM chain that lets a default low-privilege user become admin and run code on AI gateway servers, exposing model provider keys, stored secrets, prompts, and responses. The Hacker News, June 15, 2026

ShinyHunters exploits PeopleSoft zero-day against education targets

Google confirmed ShinyHunters exploited CVE-2026-35273 as a zero-day against PeopleSoft systems, with higher education heavily represented among notified organizations. Exposed ERP infrastructure should be treated as an active data-theft target. SecurityWeek, June 12, 2026

Klue OAuth compromise exposes Salesforce CRM data

Attackers abused Klue Battlecards OAuth access to query Salesforce through the REST API for hours, showing how trusted SaaS integrations can bypass direct credential theft and still drain CRM records. ReliaQuest, June 17, 2026

GitHub rejected reports on flaws later tied to Shai-Hulud variants

Researchers said GitHub rejected reports on trust-model gaps later abused by Shai-Hulud variants. Deep Specter counted credential-staging repositories and active payload repositories still live on June 16. The Record, June 16, 2026

SocGholish takedown cleans nearly 15,000 infected websites

Authorities and private partners disrupted SocGholish infrastructure, taking down 106 servers and cleaning nearly 15,000 infected websites. The FakeUpdates malware gave ransomware crews and spies an initial-access pipeline. CyberScoop, June 18, 2026

DragonForce backdoor hides command traffic in Microsoft Teams relays

Symantec researchers found DragonForce using Backdoor.Turn, a Go-based RAT that routes command traffic through legitimate Microsoft Teams TURN relays. Blocking it without disrupting collaboration traffic will require sharper network telemetry. Broadcom, June 16, 2026

FortiBleed leak exposes Fortinet VPN credentials at scale

A leaked Fortinet credential trove exposed apparent VPN usernames and plaintext passwords for 73,932 firewall URLs. Attackers allegedly combined massive FortiGate and MSSQL credential attacks with GPU-assisted hash cracking. BleepingComputer, June 18, 2026

China-linked UNC6508 abuses REDCap and Workspace rules for espionage

GTIG attributed a research-sector espionage campaign to UNC6508, including REDCap compromises and a Google Workspace compliance rule that silently BCC-forwarded matched emails to an attacker Gmail account. Google Cloud, June 15, 2026

Cisco patches ISE flaw that can give admins root access

Cisco patched CVE-2026-20181 in ISE and ISE-PIC, allowing authenticated remote attackers with admin credentials to execute OS commands and escalate to root. Identity control planes need urgent maintenance windows. Cisco, June 18, 2026

More cybersecurity news

About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles