Daily Briefing

CyberGeoDigest

Geopolitical cyber intelligence in 5 minutes
Friday, June 12, 2026 · 20 stories
Share this digest:

OceanLotus Hits Vietnam Investors, Infrastructure Firms via SPECTRALVIPER Backdoor (1 minute read)

Vietnam-linked OceanLotus ran two campaigns from mid-2024 to February 2026, deploying SPECTRALVIPER against a Vietnamese infrastructure corporation and stock investors via a supply chain attack.

The Hacker News · 22h ago · Read full article →

Russia's Void Blizzard Operative Denis Obrezko Charged Over 11-Company U.S. Breach (1 minute read)

Russian national Denis Obrezko was charged for orchestrating Void Blizzard cyberattacks that compromised at least 11 U.S. companies in a Kremlin-linked espionage campaign. The indictment names a specific GRU-affiliated operator, extending the U.S.

CyberScoop · 15h ago · Read full article →

🇷🇺 GRU · Russia

Russia and Taliban Formalize Security Alliance, Reshaping Central Asian Dynamics (1 minute read)

Russia and the Taliban have reached a security agreement that serves both parties' immediate interests in countering shared threats in Central Asia. The pact legitimizes Taliban governance through a major-power partnership and complicates U.S. and Chinese strategic calculations in the region.

The Diplomat · 17h ago · Read full article →

U.S.-Iran Truce Collapses as Israel-Hizballah Fighting Escalates (3 minute read)

Hostilities between the U.S. and Iran intensified in early June 2026, effectively ending a truce held since April, as Israel-Hizballah clashes complicated nuclear negotiations. Iran's insistence on linking the two tracks threatens to collapse diplomatic channels entirely.

War on the Rocks · 12h ago · Read full article →

China's PLA Rapidly Expands Special Mission Aircraft Fleet in Quantity and Quality (1 minute read)

The Chinese military has significantly grown its special mission aircraft inventory over the past decade, advancing both capability and numbers. The expansion signals Beijing hardening its ISR, electronic warfare, and command functions ahead of potential high-intensity regional conflict.

The Diplomat · 17h ago · Read full article →

🇨🇳 PLA · China

Trump Pulls Back Iran Strike Orders Citing Deal Progress; Tehran Disputes Agreement (1 minute read)

Trump reversed planned military strikes on Iran, citing progress toward a nuclear deal, but Iranian state media reported no agreement has been reached. The public contradiction between Washington and Tehran exposes negotiating fragility and raises escalation risk if talks collapse.

Foreign Policy · 11h ago · Read full article →

Ukraine Ditches Insurgency Script, Builds Tech-Driven Hybrid Force (3 minute read)

Four years into the Russia-Ukraine war, Ukraine's resistance evolved beyond predicted insurgency tactics into a sophisticated drone-and-conventional hybrid model. The shift signals a new template for asymmetric warfare against a peer adversary occupying national territory.

War on the Rocks · 16h ago · Read full article →

Unpatched Brickcom Cameras Expose Live Video Feeds to Remote Attackers (3 minute read)

Multiple Brickcom camera models running firmware 3.2.3.5.6 carry vulnerabilities scoring 7.7 CVSS that allow unauthenticated remote access to live video and full administrative control.

CISA Alerts · 20h ago · Read full article →

CISA Issues 72-Hour Mandate to Patch Actively Exploited Ivanti Sentry Flaw (1 minute read)

CISA's Binding Operational Directive 26-04 ordered federal agencies to patch an actively exploited Ivanti Sentry vulnerability within three days. Active in-the-wild exploitation against a product with a history of targeted abuse makes delayed patching untenable for any networked federal environment.

BleepingComputer · just now · Read full article →

CISA BOD 26-04 Forces Federal Agencies to Patch Critical Flaws in 3 Days (1 minute read)

CISA's new Binding Operational Directive 26-04 compresses remediation windows for critical exploited vulnerabilities to 3 days for Federal Civilian Executive Branch agencies. The directive institutionalizes emergency-tempo patching, reflecting CISA's assessment that dwell-time gaps are actively enabling intrusions.

BleepingComputer · 19h ago · Read full article →

ShinyHunters Exploits CVE-2026-35273 in Oracle PeopleSoft Education Attacks (3 minute read)

UNC6240 (ShinyHunters) exploited CVE-2026-35273, a CVSS 9.8 RCE flaw in Oracle PeopleSoft, in an active extortion campaign observed May 27–June 9, 2026. The education sector's reliance on legacy ERP infrastructure makes it a systemic soft target for financially motivated actors wielding critical zero-days.

Google Threat Intelligence · 18h ago · Read full article →

Supply Chain Attack Kit, $5K Browser-Cloning RAT Surface in Weekly Threat Roundup (2 minute read)

A supply chain attack toolkit appeared in a public repository, a $5,000-per-month RAT capable of cloning browser sessions was identified, and research confirmed AI agents can be manipulated into exfiltrating real credentials.

The Hacker News · 19h ago · Read full article →

ShinyHunters Exploits Oracle PeopleSoft Zero-Day CVE-2026-35273 for Data Theft (1 minute read)

ShinyHunters exploited CVE-2026-35273, a critical unauthenticated RCE flaw in Oracle PeopleSoft, in active data theft attacks before Oracle issued mitigations. A zero-day in PeopleSoft—widely used for HR and finance data—puts sensitive enterprise records across sectors at immediate risk.

BleepingComputer · 12h ago · Read full article →

Cyberattack Forces 1,428-Student UK School Great Marlow to Close (1 minute read)

Great Marlow School in the UK shut down operations for 1,428 students following a cyberattack, engaging specialist IT and cybersecurity responders. The closure illustrates how attacks on under-resourced educational institutions now carry immediate real-world disruption equivalent to critical-infrastructure incidents.

The Record · 17h ago · Read full article →

Yarbo Robot Fleet Exposed via Hard-Coded Credentials, CVSS 9.8 Flaws (3 minute read)

CISA disclosed CVSS 9.8 vulnerabilities in Yarbo's Android/iOS app and cloud MQTT infrastructure, allowing attackers to extract hard-coded credentials and issue operational commands to robot fleets.

CISA Alerts · 20h ago · Read full article →

Naxclow IoT Platform Flaws Allow Device Impersonation, Mass Credential Harvest (3 minute read)

CISA flagged CVSS 9.8 authorization bypass and missing authentication vulnerabilities across Naxclow's Smart Doorbell X3, V720, ix cam, and X Smart Home platforms, enabling device impersonation and large-scale credential harvesting.

CISA Alerts · 20h ago · Read full article →

CISA Adds CVE-2026-10520 Ivanti Sentry Command Injection to KEV Catalog (3 minute read)

CISA flagged CVE-2026-10520, an OS command injection flaw in Ivanti Sentry, as actively exploited and mandated federal remediation under BOD 26-04. Ivanti vulnerabilities have anchored multiple nation-state intrusion campaigns, making active exploitation a high-confidence escalation signal.

CISA Alerts · 20h ago · Read full article →

Google Confirms ShinyHunters Exploited Oracle PeopleSoft CVE-2026-35273 In-Wild (1 minute read)

Google confirmed ShinyHunters exploited CVE-2026-35273 in the wild while Oracle declined to publicly acknowledge active exploitation. The divergence between vendor transparency and third-party confirmation exposes a disclosure gap that leaves defenders without authoritative guidance.

SecurityWeek · 1h ago · Read full article →

Oracle Quietly Mitigates CVE-2026-35273 Amid ShinyHunters Zero-Day Reports (1 minute read)

Oracle released mitigations for CVE-2026-35273 in PeopleSoft without confirming it was actively exploited by ShinyHunters. Oracle's silence on exploitation status delays enterprise risk prioritization while attacks are reportedly ongoing.

SecurityWeek · 18h ago · Read full article →

'GreatXML' Zero-Day PoC Abuses Microsoft Defender to Bypass BitLocker (1 minute read)

A proof-of-concept exploit dubbed GreatXML leverages Microsoft Defender's offline scan to spawn a SYSTEM shell during Recovery Mode reboot, bypassing BitLocker. The technique targets a trusted Windows security component, undermining full-disk encryption as a last-line physical-access control.

SecurityWeek · 22h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now