SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 101

2026-06-14T20:51:45Z07fa255f6cf6ea10a414153786801e0b26ba72e35ae30c4100e6adeb6b5365a0
AnthropicCISA KEVCVE-2026-10520CVE-2026-35273ContiGafgytHandalaIoT exposureIvanti SentryMiasmaOracle PeopleSoftShinyHuntersdata leakexploitationnpm wormransomwareremote code executionunsecured cameraswater utility breachzero-day

What happened

Security Affairs roundup covering multiple high-impact incidents: U.S. CISA added Ivanti Sentry (CVE-2026-10520, CVSS 10.0) and Oracle PeopleSoft/PeopleTools (CVE-2026-35273, CVSS 9.8) to its Known Exploited Vulnerabilities catalog; CVE-2026-10520 is being actively exploited to compromise internet-exposed Ivanti gateways. ShinyHunters exploited the PeopleSoft zero-day to breach over 100 organisations. Iran-linked Handala claimed a breach of California Water Service and published a 5GB data dump. A Ukrainian defendant pleaded guilty for involvement in Conti ransomware operations. Analysis also呼

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
07fa255f6cf6ea10a414153786801e0b26ba72e35ae30c4100e6adeb6b5365a0
Enrichment time
2026-06-14T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.