EPISODE · Jun 12, 2026 · 31 MIN
2026-06-12: CISA gives federal agencies until Sunday to patch an Ivanti Sentry vulnerability already exploited
from Cyber Threat Brief
Show Notes - 2026-06-12 Stories Covered: - June 12, 2026 - Today: - CISA Orders Ivanti Sentry Patching by June 14 (CVE-2026-10520) (https://www.bleepingcomputer.com/news/security/cisa-gives-feds-3-days-to-patch-ivanti-flaw-exploited-in-attacks/) - ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) (https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html) - The Gentlemen Ransomware Claims 478 Victims Since March 2025 (https://thehackernews.com/2026/06/the-gentlemen-ransomware-claims-478.html) - Europol Dismantles AudiA6 Crypto Laundering Service (https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html) - AI-Driven Threats Exposing Limits of MSP Security Stacks (https://www.bleepingcomputer.com/news/security/why-ai-driven-threats-are-exposing-the-limits-of-msp-security-stacks/) - Hackers Exploit Langflow Vulnerability for Remote Code Execution (CVE-2026-5027) (https://www.securityweek.com/hackers-exploit-langflow-vulnerability-for-remote-code-execution/) - LangGraph Flaw Chain Exposes Self-Hosted AI Agents to RCE (https://thehackernews.com/2026/06/langgraph-flaw-chain-exposes-self.html) - AI Agent Supply Chains Lack Integrity Verification (https://unit42.paloaltonetworks.com/ai-agent-supply-chain-risks/) - OpenClaw AI Agent Vulnerable to Hidden Command Injection and Phishing (https://thehackernews.com/2026/06/new-attacks-trick-openclaw-ai-agent.html) - French Government Tchap Messenger Breach Affects 73,000 Employees (https://www.bleepingcomputer.com/news/security/french-govt-says-tchap-breach-affected-over-73-000-accounts/) - GreatXML Exploit Bypasses BitLocker via Recovery Partition XML Files (CVE-2026-45585) (https://thehackernews.com/2026/06/new-greatxml-exploit-bypasses-windows.html) - CISA Issues New Binding Operational Directive 26-04 (https://news.risky.biz/risky-bulletin-in-the-age-of-ai-cisa-changes-federal-patching-rules/) - Alert Fatigue Becoming a Security Threat of Its Own (https://www.securityweek.com/alert-fatigue-is-becoming-a-security-threat-of-its-own/) - OceanLotus Shifts Focus to Domestic Espionage in Vietnam (https://thehackernews.com/2026/06/oceanlotus-hits-vietnam-investors-with.html) - North Korean Famous Chollima Accounts for 47% of Tech Sector Intrusions (https://thehackernews.com/2026/06/threatsday-bulletin-worm-code-leaked-ai.html) - IoT Platform Vulnerabilities Across Multiple Vendors (https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-02) - Siemens Desigo CC Patch Files Flagged as Malware by Security Engines (https://www.securityweek.com/siemens-says-desigo-cc-files-flagged-as-malware-by-security-engines/) CVEs Referenced: CVE-2025-67644, CVE-2026-10520, CVE-2026-10557, CVE-2026-27022, CVE-2026-28277, CVE-2026-28742, CVE-2026-35273, CVE-2026-42947, CVE-2026-45585, CVE-2026-50005, CVE-2026-50101, CVE-2026-50108, CVE-2026-50245, CVE-2026-5027, CVE-2026-7368 Indicators of Compromise: IPs: 176.120.22.24, 3.2.3.5 Full brief: https://carolinacleartech.com/brief/2026-06-12/
Embed this episode
What this episode covers
Show Notes - 2026-06-12 Stories Covered: - June 12, 2026 - Today: - CISA Orders Ivanti Sentry Patching by June 14 (CVE-2026-10520) (https://www.bleepingcomputer.com/news/security/cisa-gives-feds-3-days-to-patch-ivanti-flaw-exploited-in-attacks/) - ShinyHunters Exploits Oracle PeopleSoft Zero-Day (C
NOW PLAYING
2026-06-12: CISA gives federal agencies until Sunday to patch an Ivanti Sentry vulnerability already exploited
No transcript for this episode yet
Similar Episodes
No similar episodes found.