RECAP
June 2026
2incidents investigated
20entered active exploitation · 3 used by ransomware
20ransomware victims · 20 in Brazil
14active groups
7,964new vulnerabilities · 938 critical
What we investigated
Each case with its confidence seal and verdict — not rumors.
8x8 perde dados de clientes em ataque à cadeia de suprimentos KlueReal
A 8x8 foi uma das vítimas downstream do comprometimento do fornecedor Klue: um ator explorou a integração Klue Battlecards conectada ao Salesforce da 8x8 e exfiltrou dados de CRM de clientes atuais, antigos e prospectivos entre 11 e 12 de junho de 2026. O incidente é real e confirmado pela própria 8x8 via 8-K; nosso registro estava incompleto ao marcar 'ator não identificado' — o grupo Icarus reivindicou a campanha, e os dados exfiltrados são de contato comercial e informações fragmentadas de vendas, não dados de assinantes ou sistemas de produção da 8x8.
tecnologia · 23 Jun 2026
iRhythm confirma exfiltração de dados em ataque de engenharia socialReal
A iRhythm Holdings (IRTC) confirmou, via 8-K Item 1.05 aceito pela SEC em 15/06/2026, que sofreu exfiltração de dados de aplicações de negócio hospedadas por terceiros após um ataque de engenharia social, seguido de extorsão por um ator não identificado. Incidente real e confirmado pela própria vítima. O volume e o número de afetados permanecem indeterminados; o número '12 milhões' que circula na imprensa é métrica de marketing da empresa (pacientes atendidos desde a fundação), não contagem de vítimas, e não deve ser tratado como escopo do vazamento.
saúde · 15 Jun 2026
What actually came under attack
Vulnerabilities added to CISA's KEV catalog during the month: confirmed active exploitation.
CVE-2026-35273 ⚠
Oracle PeopleSoft Enterprise PeopleTools
CRITICAL · 9.8 · EPSS 95%
CVE-2026-50751 ⚠Check Point Security Gateway
CRITICAL · 9.3 · EPSS 84%
CVE-2026-12569 ⚠PTC Windchill and FlexPLM
CRITICAL · 9.3 · EPSS 41%
CVE-2026-20253Splunk Enterprise
CRITICAL · 9.8 · EPSS 97%
CVE-2026-34910Ubiquiti UniFi OS
CRITICAL · 10.0 · EPSS 87%
CVE-2026-34908Ubiquiti UniFi OS
CRITICAL · 10.0 · EPSS 85%
CVE-2026-42271BerriAI LiteLLM
HIGH · 8.7 · EPSS 84%
CVE-2026-48907Widget Factory Joomla Content Editor
CRITICAL · 10.0 · EPSS 78%
CVE-2024-21182Oracle WebLogic Server
HIGH · 7.5 · EPSS 74%
CVE-2026-34909Ubiquiti UniFi OS
CRITICAL · 10.0 · EPSS 64%
CVE-2026-28318SolarWinds Serv-U
HIGH · 7.5 · EPSS 40%
CVE-2026-20262Cisco Catalyst SD-WAN Manager
MEDIUM · 6.5 · EPSS 28%
CVE-2026-45247Mirasvit Mirasvit Full Page Cache Warmer
CRITICAL · 9.3 · EPSS 28%
CVE-2026-20245Cisco Catalyst SD-WAN Manager
HIGH · 7.8 · EPSS 25%
CVE-2025-67038Lantronix EDS5000
CRITICAL · 9.3 · EPSS 19%
CVE-2022-0492Linux Kernel
HIGH · 7.8 · EPSS 6%
CVE-2026-11645Google Chromium V8
HIGH · 8.8 · EPSS 2%
CVE-2025-48595Android Framework
HIGH · 8.4 · EPSS 2%
CVE-2026-54420LiteSpeed cPanel Plugin
HIGH · 8.5 · EPSS 1%
CVE-2026-7473Arista Extensible Operating System
MEDIUM · 6.9 · EPSS 1%
Who attacked most
Victims in Brazil
Organizations listed on extortion sites. Appearing there is the criminal's CLAIM, not a confirmation.
paipharma.com
BrainCipher · Healthcare · 30 Jun 2026
agroprime
dragonforce · Agriculture and Food Production · 28 Jun 2026
acilab.com
settra · Technology · 24 Jun 2026
Meta
bravox · Technology · 23 Jun 2026
gov.br
apt73 · Government & Defense · 23 Jun 2026
Editora Irmãos Vitale
payload · Education · 20 Jun 2026
Super Finishing
worldleaks · Manufacturing · 20 Jun 2026
www.mupras.com
krybit · Professional Services · 19 Jun 2026
coemi.com.br
krybit · Financial Services · 19 Jun 2026
saude.mt.gov.br
lockbit5 · Public Sector · 17 Jun 2026
Chebib Control
spacebears · Professional Services · 14 Jun 2026
paipharma.com
BrainCipher · Healthcare · 13 Jun 2026
5deagosto.com.br
lockbit5 · Consumer Services · 13 Jun 2026
MHE9 Logística Ltda
gunra · Transportation · 12 Jun 2026
Clínica Vida
direwolf · Healthcare · 12 Jun 2026
Silmquinas e Equipamentos
thegentlemen · Manufacturing · 10 Jun 2026
sweetome.com
lockbit5 · Consumer Services · 10 Jun 2026
schultz.com.br
krybit · Professional Services · 05 Jun 2026
Eat Salad
qilin · Agriculture and Food Production · 03 Jun 2026
Sicol
spacebears · Manufacturing · 02 Jun 2026
Bulletins of the month
FOSSBilling Auth Bypass and Router Hardcoded Keys Headline 9 Critical CVEs on June 23
23 Jun 2026
Ten KEV Vulnerabilities in Active Exploitation Demand Immediate Attention Across Enterprise and Consumer Stacks
24 Jun 2026
Three CVSS 10.0 Flaws Lead a Heavy Day: Apache Kvrocks, Flowise, and WordPress Under Fire
25 Jun 2026
10 Actively Exploited CVEs Dominate: Joomla RCE, Splunk File Write, and PeopleSoft Takeover Lead Critical Wave
26 Jun 2026
Ten KEV-Confirmed Vulnerabilities Dominate the Spotlight: Joomla, PeopleSoft, Splunk, and More Under Active Exploitation
27 Jun 2026
Five Tenda Router Buffer Overflows Lead a Day of 47 New CVEs, All with Public Exploits
28 Jun 2026
Unauthenticated RCE in Joomla Extension Leads Monday's Batch of Six Critical CVEs
29 Jun 2026
Massive Critical Surge: ColdFusion, Storage Concentrator, and Langflow All Hit With CVSS 10 Flaws on June 30
30 Jun 2026