EPISODE · Jun 9, 2026 · 30 MIN
2026-06-09: Check Point VPN users have three days to patch CVE-2026-50751
from Cyber Threat Brief
Show Notes - 2026-06-09 Stories Covered: - June 9, 2026 - Today: - Check Point VPN Zero-Day Exploited by Qilin Ransomware (CVE-2026-50751) (https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-check-point-flaw-exploited-by-ransomware-gangs/) - Gogs RCE Zero-Day Affects Default Configurations (https://www.bleepingcomputer.com/news/security/gogs-patches-critical-zero-day-enabling-remote-code-execution/) - Google Patches Fifth Chrome Zero-Day of 2026 (CVE-2026-11645) (https://www.bleepingcomputer.com/news/security/google-patches-fifth-chrome-zero-day-bug-exploited-in-attacks-this-year/) - LiteLLM RCE Exploited in the Wild (CVE-2026-42271) (https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html) - TeamPCP Supply Chain Campaign Continues with Hades PyPI Variant (https://isc.sans.edu/diary/rss/33060) - Silent Ransom Group Uses DNS Fast Flux in Attacks (https://www.securityweek.com/silent-ransom-group-uses-dns-fast-flux-in-attacks/) - Ransomware Closes Illinois High Schools (https://www.theregister.com/cyber-crime/2026/06/08/ransomware-attack-shuts-illinois-high-school-until-wednesday/5252322) - Qilin NHS Breach Tally Grows (https://www.theregister.com/cyber-crime/2026/06/09/qilin-nhs-breach-tally-grows-as-essex-trust-confirms-stolen-records/5252663) - Microsoft Teams Phishing Campaigns Bypass Email Defenses (https://unit42.paloaltonetworks.com/microsoft-teams-phishing/) - AI Brands Used as Social Engineering Lures (https://www.microsoft.com/en-us/security/blog/2026/06/08/ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineering/) - NSO Group Spyware Campaigns Defy Court Injunction (https://www.bleepingcomputer.com/news/security/whatsapp-says-it-disrupted-new-nso-spyware-phishing-attacks/) - Linux Kernel One-Character Flaw Enables Local Root (CVE-2026-23111) (https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html) - Android Framework Privilege Escalation Under Exploitation (CVE-2025-48595) (https://thehackernews.com/2026/06/weekly-recap-instagram-account-hacks.html) - Multiple MSRC CVE Publications (https://msrc.microsoft.com/update-guide/) - Instagram Recovery Tool Bug Exposed 20,225 Accounts (https://databreaches.net/2026/06/08/instagram-recovery-tool-bug-exposed-20225-accounts-to-password-reset-abuse/?pk_campaign=feed&pk_kwd=instagram-recovery-tool-bug-exposed-20225-accounts-to-password-reset-abuse) - Apple Announces AI-Powered Automatic Password Fixer (https://www.bleepingcomputer.com/news/apple/new-apple-feature-automatically-changes-your-compromised-passwords/) CVEs Referenced: CVE-2024-39930, CVE-2024-39932, CVE-2024-39933, CVE-2025-48595, CVE-2025-8110, CVE-2026-10879, CVE-2026-11463, CVE-2026-11645, CVE-2026-23111, CVE-2026-2441, CVE-2026-26194, CVE-2026-35429, CVE-2026-3909, CVE-2026-3910, CVE-2026-40930, CVE-2026-42208, CVE-2026-42271, CVE-2026-45321, CVE-2026-46250, CVE-2026-46272, CVE-2026-48027, CVE-2026-48710, CVE-2026-49975, CVE-2026-50031, CVE-2026-50256, CVE-2026-50260, CVE-2026-50262, CVE-2026-50292, CVE-2026-50751, CVE-2026-50752, CVE-2026-5281 Indicators of Compromise: Domains: ep6pheij[.]com, business-data-leaks[.]com., business-data-leaks[.]com, grupoconstat[.]bitrix24, com[.]br, ikhwancast[.]com, ghazacast[.]com, fr24cast[.]com., fr24cast[.]com Full brief: https://carolinacleartech.com/brief/2026-06-09/
Embed this episode
What this episode covers
Show Notes - 2026-06-09 Stories Covered: - June 9, 2026 - Today: - Check Point VPN Zero-Day Exploited by Qilin Ransomware (CVE-2026-50751) (https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-check-point-flaw-exploited-by-ransomware-gangs/) - Gogs RCE Zero-Day Affects Default C
NOW PLAYING
2026-06-09: Check Point VPN users have three days to patch CVE-2026-50751
No transcript for this episode yet
Similar Episodes
No similar episodes found.