Isometric network nodes highlighting widespread zero-day vulnerabilities and security fixes.

Daily Cybersecurity News - June 10, 2026

Microsoft Patches Exchange XSS Zero Day

Microsoft just fixed an actively exploited zero-day in Exchange Server. Attackers used it for XSS against Outlook Web Access users.

The flaw lets unauthenticated attackers run arbitrary JavaScript in victims' browsers. CVE-2025-42897 carried CVSS 8.1 and was actively exploited before the patch.

It affects on-premises Exchange 2016 and 2019. Cloud-hosted Outlook escapes the issue entirely.

Public PoC appeared days after disclosure.

Microsoft Patches YellowKey GreenPlasma MiniPlasma Zero Days

Microsoft fixed three zero days that give attackers SYSTEM access on patched Windows boxes and read access to BitLocker drives.

CVE-2026-XXXXX flaws in the kernel and related components let unprivileged users escalate to SYSTEM. CVSS 7.8 and zero-day status until the patch.

Affects all supported Windows versions including 10, 11, and Server editions. Hits standard user accounts on domain-joined and standalone machines alike.

The three bugs shipped in the same update cycle as YellowKey, GreenPlasma, and MiniPlasma names.

Ivanti Sentry Flaw Gives Root Execution

Ivanti Sentry just shipped a max-severity flaw that hands remote attackers root code execution on the gateway.

CVE-2025-XXXXX lets unauthenticated users trigger the bug over the network. CVSS 9.8 and zero-day before the patch.

Affects Sentry secure mobile gateway deployments in enterprise environments.

Patch available now from Ivanti.

Microsoft Defender RoguePlanet Zero Day Grants System

Microsoft Defender just shipped a zero day that hands SYSTEM privileges to low-privilege users.

The flaw lives in the product's antimalware engine. Researchers chained it with a prior bypass to reach full system access. Microsoft patched two related issues in the June 2026 Patch Tuesday release.

Any Windows endpoint running Microsoft Defender is exposed until the latest engine update lands.

Public PoC dropped hours after the official fix.

ServiceNow API Flaw Exposes Customer Data

ServiceNow disclosed a breach where attackers accessed customer instance data through a vulnerable API endpoint.

The flaw allowed unauthenticated queries against customer data. ServiceNow confirmed the incident and notified affected customers.

Attackers targeted production environments holding sensitive records. The vector was a straightforward API misconfiguration rather than advanced persistence.

ServiceNow has not disclosed the exact number of affected instances or data volume.

China-Linked JDY Botnet Expands Targeting of US Military Networks

Volt Typhoon linked operators are growing the JDY botnet and scanning US military networks.

The crew added fresh targets in defense and government sectors while running broader reconnaissance. They rely on compromised routers for C2 and blend into residential ISP traffic.

This is the same living-off-the-land approach they have used for years, now applied at larger scale with more focus on military assets.

Activity ramped up sharply in early 2026 after months of quieter expansion.

NSO Group Still Phishing WhatsApp Users

WhatsApp caught NSO Group running phishing campaigns against its users again.

The activity violates an existing court order. WhatsApp identified the attempts and blocked them before any widespread compromise.

This is theatre. The operators continue working from safe jurisdictions while low-level campaigns get disrupted.

The group previously lost a similar case in US courts two years ago.