Quiet 48 Hours: Oracle PeopleSoft RCE, Microsoft Exchange Zero-Day, and Defender ‘RoguePlanet’ Still Active

This brief covers the trailing ~48 hours (June 18–20, 2026). No new vulnerabilities, advisories, or KEV entries surfaced from authoritative primary sources inside that window — a quiet stretch following last week’s heavy Patch Tuesday cycle. Rather than pad with unverified or stale items, the section below tracks the most significant campaigns from the preceding days that remain active, each presented with its true disclosure date and traced to its primary source.

Still developing

Oracle PeopleSoft zero-day exploited for unauthenticated RCE (CVE-2026-35273)

Oracle Security Alert · June 11, 2026

Oracle issued an out-of-cycle Security Alert for CVE-2026-35273, a critical flaw in PeopleSoft Enterprise PeopleTools (versions 8.61 and 8.62) carrying a CVSS base score of 9.8. The bug is remotely exploitable without authentication and can result in remote code execution. It was exploited as a zero-day in ShinyHunters data-theft attacks; Mandiant (Google Threat Intelligence) confirmed exploitation and notified more than 100 organizations, 68% of them in the higher-education sector. Oracle released emergency mitigations with a full patch to follow. Not yet listed in CISA KEV at the time of writing.

“This vulnerability is remotely exploitable without authentication. If successfully exploited, this vulnerability may result in remote code execution.” — Oracle Security Alert advisory

Source: Oracle Security Alert (CPU187) · Mandiant / Google Threat Intelligence · BleepingComputer

Microsoft June Patch Tuesday: Exchange Server zero-day exploited in the wild (CVE-2026-42897)

Microsoft (MSRC) · June 9, 2026

Microsoft’s June 2026 Patch Tuesday addressed 200 flaws, including six zero-days — five publicly disclosed and one exploited in attacks. The actively exploited issue is CVE-2026-42897, a Microsoft Exchange Server spoofing vulnerability affecting Exchange 2016, 2019, and Subscription Edition that lets an attacker execute JavaScript in a target’s browser via Outlook Web Access. The publicly disclosed zero-days include BitLocker bypasses (“YellowKey,” “bitskrieg”) and the “GreenPlasma” and “Mini-Plasma” elevation-of-privilege flaws. Administrators should prioritize the Exchange update.

“Today is Microsoft’s June 2026 Patch Tuesday, with security updates for 200 flaws, including five publicly disclosed zero-day vulnerabilities and one actively exploited in attacks.” — BleepingComputer

Source: Microsoft MSRC advisory (CVE-2026-42897) · BleepingComputer

Microsoft Defender “RoguePlanet” PoC grants SYSTEM on fully patched Windows (no patch)

BleepingComputer / Nightmare Eclipse · June 9, 2026

Hours after Patch Tuesday, the researcher known as Nightmare Eclipse released a proof-of-concept exploit dubbed “RoguePlanet” targeting a Microsoft Defender race-condition flaw. It spawns a command prompt with SYSTEM privileges on fully patched Windows 10 and Windows 11 systems. No CVE has been assigned and no patch was available at disclosure; Microsoft says it is investigating. Cybersecurity firm ThreatLocker independently reproduced the exploit against fully patched Windows 11 (build with KB5094126). Application allowlisting is cited as an effective mitigation.

“Our initial analysis confirms that the RoguePlanet exploit is viable and performs as described. Organizations using application allowlisting can prevent the exploit from executing, providing an effective layer of protection against this attack.” — Danny Jenkins, CEO, ThreatLocker

Source: BleepingComputer

CISA adds Joomla Content Editor flaw to KEV (CVE-2026-48907)

CISA · June 16, 2026

CISA added CVE-2026-48907, an improper access control vulnerability in the Widget Factory Joomla Content Editor (JCE) extension, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The addition sets a remediation deadline for federal civilian agencies under BOD 22-01 and is a strong signal for any organization running the affected Joomla extension to patch or mitigate. KEV status: listed.

Source: CISA alert · CISA KEV catalog


This brief covers the trailing ~48 hours (June 18–20, 2026).

Primary sources:

OpenAI Upgrades ChatGPT Health, Surfaces Rare-Disease Diagnoses, and Brings Grok to Databricks

This brief covers the trailing ~72 hours (June 18–20, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. It was a concentrated window: the verified developments all landed on June 18, led by OpenAI’s health work and xAI’s enterprise expansion.

OpenAI says GPT-5.5 Instant brings frontier-level health responses to free users

OpenAI · June 18, 2026

OpenAI detailed how GPT-5.5 Instant improves ChatGPT’s health and wellness responses, citing better recognition of when urgent care is needed, more context-seeking, and clearer communication of uncertainty. The company says the model now matches its frontier “Thinking” models on its hardest health evaluations, and that the rate of responses flagged for a potential factuality issue in production health traffic fell by 71% over two months. OpenAI notes more than 230 million people ask health and wellness questions on ChatGPT each week.

“On our most challenging health evaluations, GPT-5.5 Instant now performs at a level comparable to our frontier Thinking models. Because it is available to all free users in ChatGPT, more people can benefit from these improvements.” — OpenAI

Source: Improving health intelligence in ChatGPT

An OpenAI reasoning model helps surface 18 new diagnoses in unsolved rare-disease cases

OpenAI · June 18, 2026

In a study published in NEJM AI, researchers from Boston Children’s Hospital’s Manton Center for Orphan Disease Research, Harvard University, and OpenAI used the OpenAI o3 Deep Research model to reanalyze 376 previously unsolved cases. After expert review, additional testing, and clinical confirmation, physicians established diagnoses in 18 cases — an added diagnostic yield of 4.8%. OpenAI emphasizes the model produced evidence-linked hypotheses for specialists to review and did not diagnose any patient or make clinical decisions.

“The bottleneck is time. An expert can devote only so much of their day to any one particular person.” — Dr. Catherine Brownstein, Boston Children’s Hospital’s Manton Center for Orphan Disease Research

Source: Using AI to help physicians diagnose rare genetic diseases affecting children

Grok models go live on Databricks Agent Bricks

xAI · June 18, 2026

Announced alongside the Databricks 2026 Data + AI Summit, Grok models are now natively available on Databricks Agent Bricks, the company’s developer agent platform. The integration lets engineering teams build agents that operate over Lakehouse data alongside other frontier and open-source models in a single governed platform, extending recent availability on Amazon Bedrock.

“We’re excited to share that Grok models are now natively available on Databricks Agent Bricks, Databricks’ developer agent platform.” — xAI

Source: Grok on Databricks

OpenAI adds usage analytics and spend controls for ChatGPT Enterprise

OpenAI · June 18, 2026

OpenAI introduced credit usage analytics and updated spend controls for ChatGPT Enterprise, giving admins a unified view of ChatGPT and Codex consumption across users, products, and models. Admins can now set default workspace limits, configure group-level limits, and create individual overrides, while employees can track usage against their budget and request more credits with context.

“We asked the team at OpenAI to build usage analytics to help find and train-up folks who haven’t adopted Codex, and for granular usage controls to keep spend predictable. These new tools are helping us faster scale productivity of our employees while keeping safeguards in place.” — Ryan Oksenhorn, Co-Founder, Zipline

Source: New usage analytics and updated spend controls for enterprises


This brief covers the trailing ~72 hours (June 18–20, 2026).

Primary sources:

Anthropic Opens Seoul Office; xAI Ships Grok Imagine Video 1.5 and a PowerPoint Add-In

This brief covers the trailing ~72 hours (June 15–18, 2026). Every item below was confirmed against the originating organization’s own announcement page, with a published date inside the window. It was a relatively quiet stretch dominated by xAI shipping product updates and Anthropic expanding internationally.

Anthropic opens a Seoul office and expands across the Korean AI ecosystem

Anthropic · June 17, 2026

Anthropic opened its Seoul office and announced a wave of partnerships across Korean enterprises, startups, and research institutions. Among the deployments named: NAVER has rolled out Claude Code across its entire engineering organization, Samsung SDS is deploying Claude (including Claude Code and Claude Cowork) to employees across Samsung Electronics, and LG CNS is rolling Claude out to thousands of staff. Anthropic also said it will provide Claude access to up to 60 researchers affiliated with Korea’s National AI Research Lab (NAIRL).

“What I see in Korea are teams who understand that innovation and safety are two sides of the same coin. Korean organizations are building with Claude to bring the benefits of AI to millions around the world. Opening an office in Seoul gives a long-term home to our work alongside the people shaping Korean leadership in AI.” — KiYoung Choi, Representative Director of Korea at Anthropic

Source: anthropic.com/news/seoul-office-partnerships-korean-ai-ecosystem

xAI ships Grok Imagine Video 1.5, its best image-to-video model yet

xAI · June 16, 2026

xAI made Grok Imagine Video 1.5 generally available on its Imagine API and rolled out a “Fast” variant on grok.com and the iOS and Android apps. The model generates synchronized audio, speech, and ambience in the same pass as the video, and improves motion and physics consistency. xAI also introduced Projects, parallel multi-agent generation, and library search to the Imagine workflow.

“Grok Imagine Video 1.5 Fast almost doubles generation speed: it produces 6-second, 720p videos in about 25 seconds, down from 40+ seconds in our previous model.” — xAI

Source: x.ai/news/grok-imagine-video-1-5

Grok comes to Microsoft PowerPoint

xAI · June 16, 2026

xAI launched a free Microsoft 365 add-in that runs Grok inside PowerPoint, letting users turn an outline into a full deck, generate individual slides, and restructure sections from a single instruction. The add-in can pull in web and X searches as well as a user’s Grok connectors (such as SharePoint or Google Drive), and companion add-ins for Word and Excel are also available.

“Grok now works inside Microsoft PowerPoint — turn outlines into slides, expand the deck, and tighten the narrative without leaving the app.” — xAI

Source: x.ai/news/introducing-powerpoint-addin

xAI adds an Agent Dashboard to Grok Build

xAI · June 15, 2026

xAI shipped an Agent Dashboard for its Grok Build coding agent that puts every active session on a single screen, sorts them by state so blockers needing input rise to the top, and lets developers peek at output, reply inline, and dispatch new sessions in parallel without losing context. It runs via grok dashboard from the shell or /dashboard inside a session.

“The Agent Dashboard puts every Grok Build session on one screen. See what each is doing, run them in parallel, and step in only when input is needed.” — xAI

Source: x.ai/news/agent-dashboard

Still developing

A notable item that falls just outside the 72-hour window but is worth flagging: on June 10, 2026, Google DeepMind released DiffusionGemma, an experimental open-weights (Apache 2.0) model built on the Gemma 4 architecture that generates text in parallel blocks — denoising up to 256 tokens per step rather than one at a time — for roughly 4x faster single-user generation. Confirmed via Google DeepMind’s announcement and NVIDIA’s optimization post. Source: blog.google.


This brief covers the trailing ~72 hours (June 15–18, 2026).

Primary sources:

RoguePlanet Defender Zero-Day, a Max-Severity Joomla Flaw on CISA’s KEV, and 140+ Hijacked Mastra npm Packages

A roundup of notable cyber security developments from roughly the trailing 48 hours (June 15–17, 2026). Every item below was traced to a primary source — a vendor advisory, the CVE record, the CISA KEV catalog, or the original research writeup.

Microsoft confirms unpatched “RoguePlanet” zero-day in Defender (CVE-2026-50656)

Microsoft MSRC · June 17, 2026

Microsoft published an advisory acknowledging a publicly disclosed elevation-of-privilege flaw in the Microsoft Malware Protection Engine used by Microsoft Defender, tracked as CVE-2026-50656 (CVSS 7.8) and nicknamed “RoguePlanet.” A public proof-of-concept from researcher “Nightmare Eclipse” abuses a race condition to spawn a command prompt with SYSTEM privileges, and reportedly works whether or not Defender’s real-time protection is enabled. No patch is available yet; Microsoft says one is in progress.

“Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as ‘RoguePlanet’… We are working to provide a high-quality security update that addresses this vulnerability.” — Microsoft

Source: Microsoft MSRC advisory (CVE-2026-50656) · SecurityWeek

CISA adds a maximum-severity Joomla Content Editor flaw to its KEV catalog (CVE-2026-48907)

CISA · June 16, 2026

CISA added CVE-2026-48907 — a critical (CVSS 10.0) improper-access-control flaw in the Widget Factory Joomla Content Editor (JCE) extension — to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. The flaw can let unauthenticated attackers upload and execute PHP code by creating new editor profiles, and the KEV listing sets a federal remediation deadline under the current directive.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.” — CISA

Source: CISA alert (June 16, 2026) · KEV catalog

Supply-chain attack hijacks a contributor account to poison 140+ Mastra npm packages

Socket / The Hacker News · June 17, 2026

In a roughly 80-minute window early on June 17 (UTC), attackers used a hijacked legitimate former-contributor account (“ehindero”) to publish malicious versions of more than 140 packages in the @mastra/* npm scope — the popular open-source AI-agent framework. Per Socket’s analysis, the compromised packages themselves were unmodified; the malware was delivered through an injected typosquatted dependency (easy-day-js) carrying an obfuscated postinstall payload that runs automatically on npm install. Affected packages include @mastra/core, which sees hundreds of thousands of weekly downloads.

Source: Socket research · The Hacker News

Still developing: Oracle PeopleSoft zero-day fuels ShinyHunters extortion of universities (CVE-2026-35273)

Oracle / Mandiant · disclosed June 10, 2026 (ongoing)

The ShinyHunters group has been exploiting CVE-2026-35273, an unauthenticated remote-code-execution flaw in Oracle PeopleSoft PeopleTools, in attacks dating to at least late May. Google/Mandiant say 100+ organizations — about two-thirds in higher education — were notified, and the University of Nottingham confirmed student data was stolen. Oracle issued an out-of-band advisory with mitigations but, as of reporting, no full patch.

“This campaign is still active. We have observed ShinyHunters sending extortions as recently as today.” — Charles Carmakal, CTO, Mandiant Consulting

Source: Oracle security alert · Google Threat Intelligence · CyberScoop


This brief covers the trailing ~48 hours (June 15–17, 2026).

Primary sources: msrc.microsoft.com · cisa.gov · socket.dev · oracle.com

OpenAI Simulates Deployments, Google’s AMIE Matches Doctors, and Anthropic’s Fable 5 Is Pulled by Government Order

A roundup of notable AI/LLM developments from roughly the trailing 72 hours (June 14–17, 2026). Every item below was confirmed against the originating organization’s own announcement.

OpenAI details “Deployment Simulation” to predict model behavior before release

OpenAI · June 16, 2026

OpenAI published a method for forecasting how a new model will behave in the real world before it ships. The technique replays recent, de-identified user conversations through a candidate model and measures how often undesired behaviors appear, giving a deployment-like preview rather than relying solely on synthetic red-team prompts. OpenAI says it analyzed roughly 1.3 million de-identified conversations spanning GPT-5 Thinking through GPT-5.4 deployments, and that the approach surfaced a novel misbehavior (“calculator hacking”) before release while making models far less able to tell they were being tested.

“Deployment Simulation is a method for simulating a future deployment before it happens. We do so by replaying previous conversations in a privacy-preserving manner with a new candidate model.” — OpenAI

Source: Predicting model behavior before release by simulating deployment (OpenAI) · paper (PDF)

Google’s medical AI, AMIE, matches primary-care doctors on disease management in a Nature study

Google Research / Google DeepMind · June 17, 2026

New research published in Nature extends AMIE (the Articulate Medical Intelligence Explorer) from one-off diagnostic conversations to longitudinal disease management — tracking symptoms across visits and cross-referencing drug formularies and clinical guidelines. In a blinded study using patient actors, specialist physicians compared AMIE against 21 primary-care doctors.

“AMIE matched clinicians in overall management reasoning and scored significantly higher in plan preciseness and guideline alignment, which suggests AI could someday support medical care, giving physicians more time to spend with patients.” — Google

Source: New research shows how AMIE could help manage health conditions (The Keyword) · paper in Nature

Still developing: US government orders Anthropic to suspend Fable 5 and Mythos 5

Anthropic · June 12, 2026 (ongoing)

Slightly older than the 72-hour window but still unfolding: citing national-security export-control authority, the US government directed Anthropic to suspend all access to its Fable 5 and Mythos 5 models by foreign nationals. To comply, Anthropic disabled both models for all customers; access to its other models was unaffected. Anthropic says the directive stems from a narrow, non-universal “jailbreak,” disputes that this warrants recalling a widely deployed commercial model, and says it is working to restore access.

“We are complying with the government’s legal directive and are removing access to Fable 5 and Mythos 5 for all users. However, we disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people.” — Anthropic

Source: Statement on the US government directive to suspend access to Fable 5 and Mythos 5 (Anthropic)


This brief covers the trailing ~72 hours (June 14–17, 2026).

Primary sources: openai.com · blog.google · anthropic.com

Bluetooth Vulnerability in Apple Beats Studio Buds

Vulnerability Analysis: Bluetooth Eavesdropping in Apple Beats Studio Buds

Overview
A security vulnerability was discovered in the Apple Beats Studio Buds that could allow a remote attacker to eavesdrop on users by accessing the device’s microphone via Bluetooth.

Technical Impact

  • Attack Vector: The vulnerability allows an attacker within Bluetooth wireless range to intercept audio.
  • Specific Condition: According to detailed reports, the flaw specifically targets devices that are unpaired and actively seeking connections, making them susceptible to unauthorized access.
  • Risk: If exploited, an attacker could listen to the environment around the user through the earbuds’ microphone without the user’s knowledge, leading to a significant privacy breach.

Mitigation
Apple has addressed this issue by releasing a firmware update.

  • Fix: Users are urged to update their Beats Studio Buds to firmware version 1B211 or later to close this security gap.

High-Quality Sources

  1. Absolute Geeks: Confirms the flaw allows attackers in range to listen through the microphone on unpaired devices actively seeking connections. Link
  2. MacRumors: Reports on the release of firmware 1B211 specifically to address this Bluetooth vulnerability. Link
  3. NerdyInfo: Highlights that the bug could let an attacker within Bluetooth range listen through the earbuds’ microphone. Link