2026-06-17: CISA gives federal agencies until tomorrow to patch an actively exploited cPanel plugin episode artwork

EPISODE · Jun 17, 2026 · 35 MIN

2026-06-17: CISA gives federal agencies until tomorrow to patch an actively exploited cPanel plugin

from Cyber Threat Brief

Show Notes - 2026-06-17 Stories Covered: - Today: - CISA Orders LiteSpeed cPanel Patch by June 18 (CVE-2026-54420) (https://www.bleepingcomputer.com/news/security/cisa-warns-of-another-actively-exploited-cpanel-plugin-flaw/) - Microsoft Working on RoguePlanet Defender Zero-Day Patch (CVE-2026-50656) (https://www.bleepingcomputer.com/news/microsoft/microsoft-working-on-defender-patch-for-rogueplanet-zero-day/) - Joomla JCE Plugin Flaw Under Active Exploitation (CVE-2026-48907) (https://thehackernews.com/2026/06/cisa-warns-of-actively-exploited-joomla.html) - Three Fortinet FortiSandbox Flaws Under Active Exploitation (https://www.securityweek.com/3-recently-patched-fortinet-fortisandbox-vulnerabilities-in-hacker-crosshairs/) - DragonForce Ransomware Abuses Microsoft Teams TURN Relays for Command-and-Control (https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/) - Kodak Confirms Data Breach, ShinyHunters Claims 2.2 Million Records (https://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/) - Lorem Ipsum Malware Pivots to ClickFix Delivery, Likely Linked to Vice Society (https://www.darkreading.com/cyberattacks-data-breaches/lorem-ipsum-malware-clickfix-delivery) - Novo Nordisk Hit by Two Separate Threat Actors Demanding $50M and $25M (https://databreaches.net/2026/06/16/one-threat-actor-demanded-50-million-from-novo-nordisk-another-one-demanded-25-million-neither-got-paid/?pk_campaign=feed&pk_kwd=one-threat-actor-demanded-50-million-from-novo-nordisk-another-one-demanded-25-million-neither-got-paid) - 144 Mastra npm Packages Compromised via Hijacked Contributor Account (https://thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html) - 15 Malicious JetBrains Plugins Steal AI API Keys from 70,000 Developers (https://www.bleepingcomputer.com/news/security/malicious-jetbrains-marketplace-plugins-steal-ai-api-keys-from-developers/) - Steam Workshop Abused to Spread Malware via Wallpaper Engine (https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/) - 30,000 Compromised Fortinet Firewalls Expose Corporate Networks (FortiBleed Campaign) (https://www.securityweek.com/3-recently-patched-fortinet-fortisandbox-vulnerabilities-in-hacker-crosshairs/) - ClickFix Campaigns Expand with BabaDeda, Lorem Ipsum, and Potemkin Loaders (https://thehackernews.com/2026/06/clickfix-campaigns-expand-malware.html) - GhostTree Attack Abuses Recursive Windows Junctions to Hide Malware from EDR (https://www.bleepingcomputer.com/news/security/ghosttree-attack-abused-recursive-windows-junctions-to-hide-malware/) - Google Vertex AI SDK Flaw Allowed Cross-Tenant Model Hijacking (Pickle in the Middle) (https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/) - China Arrests 67 Suspects Linked to Silver Fox Cybercrime Group (https://news.risky.biz/risky-bulletin-china-arrests-members-of-silver-fox-cybercrime-group/) - Chrome Extensions Steal AI Conversations (PromptSnatcher Campaign) (https://thehackernews.com/2026/06/malicious-jetbrains-plugins-steal-ai.html) - China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth (https://thehackernews.com/2026/06/china-linked-sprysocks-backdoor-expands.html) - New Rokarolla Android Malware Targets 217 Banking and Crypto Apps (https://www.bleepingcomputer.com/news/security/new-rokarolla-android-malware-targets-217-banking-crypto-apps/) - FTC Warns of Record $3.5 Billion Losses to Imposter Scams in 2025 (https://www.bleepingcomputer.com/news/security/ftc-warns-of-record-35-billion-losses-to-imposter-scams-in-2025/) - Rockwell Automation FLEX I/O EtherNet/IP Adapters (CVE-2026-0646, CVE-2026-0647) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05) - Rockwell Automation RSLinx Classic (CVE-2020-1 ...

Episode metadata supplied by the publisher feed · Published Jun 17, 2026

Embed this episode

Show Notes - 2026-06-17 Stories Covered: - Today: - CISA Orders LiteSpeed cPanel Patch by June 18 (CVE-2026-54420) (https://www.bleepingcomputer.com/news/security/cisa-warns-of-another-actively-exploited-cpanel-plugin-flaw/) - Microsoft Working on RoguePlanet Defender Zero-Day Patch (CVE-2026-50656

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

2026-06-17: CISA gives federal agencies until tomorrow to patch an actively exploited cPanel plugin

0:00 35:54

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Cyber Threat Brief?

This episode is 35 minutes long.

When was this Cyber Threat Brief episode published?

This episode was published on June 17, 2026.

Can I download this Cyber Threat Brief episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!