01CVE-2026-54420: LiteSpeed cPanel plugin root escalation on CloudLinux/CageFS shared hosting, exploited in the wild (CISA KEV). LiteSpeed user-end cPanel plugin CVE-2026-54420 lets a user with FTP or web-shell access escalate to root on CloudLinux/CageFS shared hosting and is actively exploited. LiteSpeed was alerted on 2026-05-31 (LiteSpeed, 2026-06-01). Added to CISA KEV on 2026-06-15 (CISA, 2026-06-15). Patch to WHM PlugIn 5.3.2.1 (cPanel plugin 2.4.8). →
02CVE-2026-20262, Cisco Catalyst SD-WAN Manager: authenticated arbitrary file write to root RCE (CISA KEV). Cisco Catalyst SD-WAN Manager actively exploited, CVE-2026-20262 (authenticated arbitrary file write → root RCE) added to the CISA KEV catalog on 2026-06-15; patch to the fixed train and review appserver upload logs. Full deep dive in § 5. (BleepingComputer, 2026-06-15) →
03WordPress supply-chain compromise via Awesome Motive's CDN backdoors ~1.2M sites. WordPress supply-chain compromise via Awesome Motive's shared CDN tampered OptinMonster / TrustPulse / PushEngage scripts on ~1.2M sites to auto-create rogue admins and a self-hiding backdoor plugin; "update your plugins" did not protect the exposure window. (Sansec, 2026-06-13) →
04PRC UNC6508 ran year-plus espionage through internet-facing REDCap servers and a Google Workspace BCC rule. PRC actor UNC6508 ran year-plus espionage through internet-facing REDCap research servers and abused a Google Workspace content-compliance rule to silently BCC research/defence email to attacker Gmail; REDCap is widely run at Swiss/EU academic medical centres. (Google GTIG, 2026-06-15) →
Google's Threat Intelligence Group attributes a September 2023 – November 2025 espionage campaign to UNC6508, a PRC-nexus cluster that compromised North American academic, medical and military-health organisations by exploiting externally-facing REDCap (Research Electronic Data Capture) servers, then dropping a bespoke PHP implant tracked as INFINITERED (Google GTIG, 2026-06-15). INFINITERED trojanises REDCap's own upgrade mechanism to survive platform updates, harvests credentials from the REDCap login page, and exposes a cookie-gated backdoor for shell, file, SQL and credential operations (Help Net Security, 2026-06-15). The exfiltration tradecraft is the notable part: after pivoting to a Workspace admin account, the actor created a Google Workspace content-compliance rule named "Patroit" that silently BCC-forwarded any message matching ~150 research/defence keywords to an attacker-controlled Gmail address, abusing a legitimate administrative feature rather than dropping exfiltration malware (T1114.003 Email Forwarding Rule), which evades most DLP that watches for new tooling (SecurityWeek, 2026-06-15). Initial access mapped to T1190; web-shell persistence to T1505.003; admin credential reuse to T1078.
Why it matters to us: REDCap is deployed across Swiss and EU university hospitals, cantonal research bodies and clinical-trial coordinators, and the Workspace BCC-rule technique is tenant-agnostic. Hunt now: Google Workspace admin audit logs for content-compliance/BCC rule creation by non-IT-admin accounts (especially rules with external Gmail recipients), and file-integrity-monitor the REDCap upgrade-staging directory and login handlers, standard web-root scanning misses the upgrade-path implant.
Proofpoint details UNK_DeadDrop, a North-Korea-aligned cluster (related to but distinct from Contagious Interview / Famous Chollima) that sent 250+ recruitment-themed phishing emails to ~100 finance, crypto, education and technology organisations over April–May 2026 (Proofpoint, 2026-06-15); the targeted geographies are a US majority followed by the UK, Australia, France, Germany and the Netherlands, among others (The Hacker News, 2026-06-16). The lure links to attacker-controlled GitHub/GitLab repositories carrying a .vscode/tasks.json with runOn: folderOpen; VS Code shows a workspace-trust prompt, but Cursor IDE executes the task silently with no prompt, dropping the open-source Overlord Go C2 that steals browser credentials and crypto wallets (The Hacker News, 2026-06-16). Mapped to T1566.002, T1195.001, T1059.004 and T1555.003.
Why it matters to us: public-sector and fintech development teams that have adopted Cursor are exposed to silent execution on repository open. Hunt for editor processes (code, cursor) spawning shell/script interpreters outside build directories (Sysmon EID 1 parent-image filter); enforce workspace-trust policy and restrict VSIX installation to an approved-publisher allowlist via enterprise policy.
Sansec Forensics found malicious JavaScript appended to the CDN-served api.min.js files shared by three Awesome Motive WordPress plugins, OptinMonster (1.2M+ installs), TrustPulse and PushEngage, injected on 12 June and served from CDN edges into 13 June (Sansec, 2026-06-13). The vendor confirmed the entry point was exploitation of an UpdraftPlus vulnerability on its own marketing server, which leaked the BunnyNet CDN API key used to tamper the scripts (OptinMonster, 2026-06-14). Because the tampering was at the CDN layer and not in the WordPress.org repository, "update your plugins" gave false assurance for the exposure window. The payload waited for a logged-in administrator, then created a hidden admin account and installed a self-hiding backdoor plugin masquerading as "Content Delivery Helper" or "Database Optimizer", concealed from the plugin list, update checks and API responses, beaconing harvested credentials to a tidio.cc lookalike domain (Patchstack, 2026-06-15). Mapped to T1195.002, T1136.001 (create account) and T1027.005 (indicator removal).
Cardiac-monitoring medtech firm iRhythm filed an SEC Form 8-K Item 1.05 on 2026-06-15 reporting that a threat actor used social engineering against business applications hosted by a third party, exfiltrated PHI, PII and proprietary data, and sent a ransom demand on 9 June; the company made its materiality determination on 10 June (SEC EDGAR, 2026-06-15). iRhythm states clinical and device-monitoring systems were unaffected. [SINGLE-SOURCE]; only the SEC primary is available; no independent corroboration yet.
The LiteSpeed user-end cPanel plugin before 2.4.8, bundled with the LiteSpeed WHM PlugIn and fixed in WHM PlugIn version 5.3.2.1, lets a user with FTP or web-shell access on a CloudLinux/CageFS shared-hosting server escalate to root. LiteSpeed says its WHM plugin itself was not affected, that the flaw "is being actively exploited", and that it was alerted on 2026-05-31 (LiteSpeed, 2026-06-01). The CVE description attributes the flaw to mishandled symlinks, and The Hacker News lists a CVSS score of 8.5 (The Hacker News, 2026-06-16). CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-15 (CISA, 2026-06-15).
This vulnerability is being actively exploited, and poses a risk for all user-end plugin versions prior to 2.4.8.
The main text above described cross-account file access and cited NVD for exploitation and a CVSS 8.5 score. LiteSpeed states that a user with FTP or web-shell access can escalate to root and that the flaw "is being actively exploited", fixed in cPanel plugin 2.4.8 and WHM plugin 5.3.2.1 (LiteSpeed, 2026-06-01). It says only its user-end cPanel plugin is affected, not its WHM plugin, and gives 2026-05-31 as the date it was alerted rather than a start of exploitation in May. The 8.5 score is now cited to The Hacker News (The Hacker News, 2026-06-16).
A path-traversal weakness in the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) lets an authenticated, remote attacker create or overwrite any file on the underlying OS because the file-upload handler fails to validate the supplied filename (NVD CVSS 6.5; Cisco PSIRT, 2026-06-15). Writing a JSP/WAR into the Tomcat deploy path yields a web shell and root-level execution, so the modest 6.5 base score understates impact on an exposed network-management plane. Cisco confirms active exploitation and CISA added it to the KEV catalog on 2026-06-15 (BleepingComputer, 2026-06-15). Patch to 20.9.9.2 / 20.12.7.2 / 20.15.4.5 / 20.15.5.3 / 20.18.3.1 / 26.1.1.2. Full kill-chain, hunt and hardening detail in § 5.
A path-traversal weakness in the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) lets an authenticated, remote attacker create or overwrite any file on the underlying OS because the file-upload handler fails to validate the supplied filename (NVD CVSS 6.5; Cisco PSIRT, 2026-06-15).
phpBB 3.3.17, released on 2026-06-06, fixes two authentication flaws disclosed by Pentest-Tools.com (Pentest-Tools.com, 2026-06-08). CVE-2026-48611 (CVSS 9.4 per Pentest-Tools) lets a single unauthenticated POST to the user control panel's login-link handler with auth_provider=apache route the login through phpBB's Apache provider, which checks only that the HTTP Basic username matches and that the password is non-empty, never comparing the password with the stored hash, and returns a valid session as any active user on default installations (Pentest-Tools.com, 2026-06-08). heise gives it CVSS 9.8 (heise online, 2026-06-15). A known username is enough, and a default board's public member list supplies it (Pentest-Tools.com, 2026-06-08). Sources disagree on whether the session also reaches the Administration Control Panel. Pentest-Tools first wrote that the panel's separate password prompt stops the attacker, then added on 2026-06-15 that an attacker can in fact directly access the panel after impersonating an administrator (Pentest-Tools.com, 2026-06-08). Aikido says a password check in front of the panel cannot be bypassed, which is why it rules out direct remote code execution even through the Extension Catalog (Aikido Security, 2026-06-10). Aikido reported the flaw to phpBB on 2026-06-02 and says it affects every version up to 3.3.16 and 4.0.0-a2 (Aikido Security, 2026-06-10), and heise reports that Aikido and Pentest-Tools' researcher found it independently (heise online, 2026-06-15).
CVE-2026-48612 (CVSS 8.3 per Pentest-Tools, 8.0 per heise (heise online, 2026-06-15)) affects only boards where an administrator has enabled OAuth login with a Google, Facebook or Bitly provider. Missing OAuth state validation and a missing CSRF check on the account-link endpoint let an attacker bind their own identity-provider account to a logged-in victim who opens a crafted link, which gives the attacker a permanent OAuth login to the victim's account (Pentest-Tools.com, 2026-06-08). Pentest-Tools added proof-of-concept requests for both flaws to its write-up on 2026-07-04 (Pentest-Tools.com, 2026-06-08). Neither CVE is in CISA's KEV catalog as of 2026-09-29 (CISA KEV catalog, 2026-09-29).
Triage: the bypass works by forcing the Apache provider instead of the configured one (Pentest-Tools.com, 2026-06-08), so on a board that uses database authentication, a login request naming the Apache provider is the exploit path, not a misconfigured client.
The main text above scored CVE-2026-48611 at 9.8 via NVD only and described it as an OAuth-implementation flaw with no public exploit code. Pentest-Tools.com scores it 9.4 and shows a single unauthenticated request through phpBB's Apache authentication provider that yields a valid session as any active user, administrators included, on default installations of phpBB 3.3.16 and earlier, fixed in 3.3.17 with no configuration workaround. It published proof-of-concept requests on 2026-07-04 (Pentest-Tools.com, 2026-06-08). Pentest-Tools is one of two independent discoverers, with Aikido (heise online, 2026-06-15). CVE-2026-48612 needs OAuth enabled and a victim who opens a crafted link, and it binds the attacker's OAuth identity to the victim's account rather than hijacking a session (Pentest-Tools.com, 2026-06-08). Disabling OAuth helps only against CVE-2026-48612. No cited source says phpBB is common at European universities or municipalities.
Varonis Threat Labs disclosed SearchLeak, a three-stage chain in Microsoft 365 Copilot Enterprise Search that Microsoft patched server-side as CVE-2026-42824 (command-injection / information-disclosure, NVD CVSS 6.5) (Varonis, 2026-06-15; Microsoft MSRC). Stage 1: the q URL parameter is passed to Copilot as an executable instruction rather than a sanitised query (parameter-to-prompt injection). Stage 2: an injected <img> tag fires during a streaming-render race before the output sanitiser runs. Stage 3: the exfiltration request is relayed through Bing's server-side image-search fetch (*.bing.com is allowlisted in Copilot's CSP) bypassing the browser CSP and carrying mailbox content, calendar entries, SharePoint/OneDrive files and emailed MFA/OTP codes to an attacker domain, all from a single click on a genuine microsoft.com link (The Hacker News, 2026-06-15). No customer action is required for patched tenants and no in-the-wild exploitation was observed. Mapped to T1566.002 and T1071.001.
Why it matters to us: M365 Copilot Enterprise is in active Swiss-federal and EU public-sector rollouts. The vulnerability class (prompt injection via URL parameter, streaming-render race, and SSRF-relay CSP bypass) will recur in other AI-augmented enterprise apps; build CASB/DLP detection for Copilot search URLs carrying HTML-encoded payloads in the q parameter and for Copilot sessions fetching to non-Microsoft domains.
Obsidian Security published a privilege-escalation-to-RCE chain in LiteLLM (BerriAI), the widely self-hosted AI gateway that proxies 100+ LLM providers behind one OpenAI-compatible API (Obsidian Security, 2026-06-15; The Hacker News, 2026-06-15). The chain: CVE-2026-47101 (authorization bypass), the key-generation endpoint accepts a caller-supplied allowed_routes without checking the caller's role, so an internal_user can mint a key reaching admin routes; CVE-2026-47102 (privilege escalation); /user/update lacks field-level authorization, letting any authenticated user set their own user_role to proxy_admin; CVE-2026-40217 (RCE); the Custom Code Guardrails feature runs attacker-supplied Python via exec() with __builtins__ available, giving arbitrary code execution. VulnCheck scores CVE-2026-47102 at CVSS 8.8 (3.1), and Obsidian rates the chained impact CVSS 9.9; chained, a default low-privilege account reaches the master key, the salt key decrypting stored secrets, the database URL and every configured provider API key, and can rewrite responses delivered to downstream AI agents ("man-in-the-gateway"). Fixed in v1.83.14-stable, but Obsidian reports broad under-deployment of the fix. Mapped to T1078, T1548 and T1059.006.
Why it matters to us: Swiss/EU public-sector and research bodies increasingly centralise AI workflows on a gateway proxy; a compromised LiteLLM is both a credential-theft and an agent-manipulation vector. Pin LiteLLM to ≥1.83.14, keep admin endpoints off the internet, store provider keys in a secrets manager, and rotate all provider keys if any pre-1.83.14 instance was reachable by untrusted users.
UPDATE (originally covered 2026-06-13): Novo Nordisk published an incident update on 2026-06-15 clarifying the scope of the theft: clinical-trial data taken was pseudonymised (limited direct re-identification risk for trial subjects) (Novo Nordisk, 2026-06-15), but separately stolen healthcare-professional …
Novo Nordisk published an incident update on 2026-06-15 clarifying the scope of the theft: clinical-trial data taken was pseudonymised (limited direct re-identification risk for trial subjects) (Novo Nordisk, 2026-06-15), but separately stolen healthcare-professional (HCP) data was non-pseudonymised, names, registration numbers and contact details (Security Affairs, 2026-06-15).
The non-pseudonymised HCP records bring the incident within GDPR Article 33 breach-notification obligations and raise targeted-phishing risk against named medical professionals (Security Affairs, 2026-06-15). Healthcare and pharma defenders should expect HCP-impersonation and credential-phishing lures referencing the breach.
Council of Europe breached via the Oracle PeopleSoft zero-day (CVE-2026-35273), ShinyHunters claims 297 GB / ~429,000 files and set a 16 June leak deadline; the first European intergovernmental victim named in the 100+-organisation PeopleSoft campaign (§ 4 update). (SecurityWeek, 2026-06-15)
ShinyHunters listed the Council of Europe (the 46-member Strasbourg human-rights body, of which Switzerland is a member) claiming 297 GB across ~429,000 files taken via the Oracle PeopleSoft Environment Management Hub zero-day CVE-2026-35273, and set a 16 June leak deadline (SecurityWeek, 2026-06-15). This is the first European intergovernmental institution named in the 100+-organisation PeopleSoft campaign previously covered as an education-sector wave.
The claimed dataset spans payroll for 10,000+ current and former staff (2011–2026), 14,000+ CVs, and HR records with names, dates of birth, addresses, bank-account, tax/social-security and medical data. The Council of Europe confirmed it "is currently investigating the matter and assessing the situation" and has not confirmed exfiltration (The Register, 2026-06-15; BleepingComputer, 2026-06-15). The vector, unauthenticated HTTP to the /PSEMHUB/hub servlet (T1190), is unchanged; treat any externally-reachable PeopleSoft Environment Management Hub as compromised pending forensic review and block perimeter access to /PSEMHUB/*. Confidence on the victim claim is MEDIUM pending Council of Europe confirmation (extortion-site claim).
Vulnerable component. The flaw lives in the web UI of Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage), the centralised controller/management plane that pushes policy and configuration to every WAN-edge router in an SD-WAN fabric. The file-upload path in the management UI does not validate the user-supplied filename, so an authenticated request can traverse out of the intended directory and create or overwrite an arbitrary file on the appliance OS (NVD, CVSS 6.5; Cisco PSIRT, 2026-06-15). The vulnerability affects on-premises, Cloud-hosted and FedRAMP deployment models. The 6.5 base score reflects the authentication requirement (a low-privilege/single-task account), but the consequence (arbitrary write into a path the application server reads) is what makes it a root-RCE primitive rather than a simple integrity bug.
Exploitation chain. Reporting describes the practical path as: (1) Initial access with valid low-privilege SD-WAN Manager credentials, obtained through prior phishing, credential reuse, or chaining an earlier auth-affecting SD-WAN bug (T1078.004 Valid Accounts: Cloud Accounts); (2) Execution by abusing the upload endpoint to write a .jsp/.war artefact into the Tomcat deployment directory, turning the file-write into a web shell (T1190 Exploit Public-Facing Application for the upload primitive, T1505.003 Server Software Component: Web Shell for the planted shell); (3) Privilege escalation / impact because the SD-WAN Manager application services run with high privilege, the web shell yields root-equivalent control of the management plane (T1059 Command and Scripting Interpreter). Control of SD-WAN Manager is control of every managed edge device's configuration, a single-pivot path to the entire WAN. Cisco Talos tracks a highly capable cluster it designates UAT-8616 behind a 2026 wave of Cisco Catalyst SD-WAN exploitation (notably CVE-2026-20127, with software-downgrade post-compromise tradecraft) (Cisco Talos, 2026); whether or not that cluster is behind CVE-2026-20262 specifically, the pattern means defenders should treat any SD-WAN Manager as a high-value target even where they believe an earlier intrusion was contained.
Affected and patched versions. Cisco has released fixed trains 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1 and 26.1.1.2; consult the PSIRT advisory for the exact mapping of your running train to its fixed build (Cisco PSIRT, 2026-06-15). CISA added CVE-2026-20262 to the Known Exploited Vulnerabilities catalog on 2026-06-15, confirming exploitation in the wild (BleepingComputer, 2026-06-15).
Hunt and detection concepts. Because exploitation is authenticated and post-foothold, the highest-value telemetry is on the appliance itself, not the perimeter. Review the SD-WAN Manager appserver and service-proxy logs for HTTP uploads referencing index.jsp, *.jsp or *.war filenames or path-traversal sequences, and for newly written files in the Tomcat webapps/deploy directories that do not correspond to a vendor update. Correlate file-write events with the authenticating account; single-task/low-privilege accounts performing uploads are anomalous. Watch for unexpected outbound connections from the SD-WAN Manager host (a web shell beaconing) and for new processes spawned by the application-server user. Because the attacker needs valid credentials first, surface authentication anomalies for management-plane accounts: logins from new source ranges, off-hours admin activity, and use of service/automation accounts interactively. No IOCs are reproduced here, hunt on the behaviour.
Hardening / mitigation. Patch to the fixed train as the only durable fix. Until patched: restrict management-plane reachability so SD-WAN Manager's web UI is never internet-exposed and is reachable only from a hardened management network or jump host; enforce MFA on all SD-WAN Manager accounts and prune low-privilege/single-task accounts that retain upload capability; rotate credentials for any account that could authenticate during the exposure window; and validate the integrity of the Tomcat deploy directory against a known-good baseline before returning a controller to service. Given the management plane's blast radius across the WAN fabric, treat a suspected compromise of SD-WAN Manager as a fabric-wide event and review pushed configurations for tampering.
Patch every Oracle PeopleSoft instance to a supported PeopleTools release or disable/remove PSEMHUB now (CVE-2026-35273); a WAF rule alone no longer stops this. UNC6240 (ShinyHunters) bypasses literal-string /PSEMHUB/ WAF blocks with the URL-encoded /%50SEMHUB/ path, so a perimeter block that has not been reconfigured to match on the normalized path is not a control. Treat any instance that was internet-reachable and unpatched at any point since 27 May 2026 as compromised until proven clean, and rotate every credential reachable from the PeopleSoft tier.
Hunt for the post-exploitation toolkit on any PeopleSoft host. Search WebLogic access logs for /PSEMHUB/ and its encoded/mixed-case variants; scan PSEMHUB.war/PORTAL.war for unexpected .jsp/.jspx/.exe files (including Ple64.exe); check for MeshAgent/MeshCentral agents and SSH credential-spraying against hosts in /etc/hosts; and review for ransom-note markers in PeopleSoft directories.
Patch the LiteSpeed cPanel plugin (CVE-2026-54420) by upgrading to LiteSpeed WHM PlugIn version 5.3.2.1, which bundles cPanel plugin 2.4.8, or uninstall the user-end plugin until then. It is actively exploited on shared CloudLinux/CageFS hosting. Prioritise any public-sector tenant on shared hosting.
Patch Cisco Catalyst SD-WAN Manager now (CVE-2026-20262), actively exploited, CISA KEV. Move to a fixed train (20.9.9.2 / 20.12.7.2 / 20.15.4.5 / 20.15.5.3 / 20.18.3.1 / 26.1.1.2), take the management UI off the internet, enforce MFA, and review appserver upload/deploy logs and the Tomcat deploy directory for planted .jsp/.war web shells.
Confirm M365 Copilot tenants are on the patched build (CVE-2026-42824) and add CASB/DLP detection for Copilot search URLs carrying HTML-encoded q parameters or fetching to non-Microsoft domains.
Pin LiteLLM to version ≥ 1.83.14 and keep admin endpoints off the internet (CVE-2026-47101/-47102/-40217), rotate all provider API keys if any pre-1.83.14 instance was reachable by untrusted users; move keys into a secrets manager.
Upgrade every internet-reachable phpBB board to 3.3.17: CVE-2026-48611 gives a session as any user on default installations from one unauthenticated request, proof-of-concept requests are public, and no configuration change closes it.
2026-06-16-38d638e1· Claude Opus 4.8 · 12 entries published
Items dropped:
CVE-2026-20251, Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8): did not clear a § 2 inclusion gate, no in-the-wild exploitation, post-auth/low-privilege, surfaced only via an NCSC-NL advisory. Holding for a future brief if exploitation emerges.
Velvet Ant "Operation Highland" (Sygnia, 2026-06-08): already covered in the 2026-W24 weekly summary (long-running campaigns) with the 2026-06-13 daily deep dive on the related Linux-authentication-stack subversion; no in-window (14–16 June) delta, so excluded per PD-8.
FileFix / KongTuke MotW-bypass transition (Intel 471, 2026-06-03): outside the 36 h recency window; the underlying FileFix research predates June 2026. Not pursued.
Astral (Russia) service disruption; Mackay Sugar (AU) incident; Grafana breach claim; Infinite Campus 137k school-staff breach: lower Swiss/EU public-sector relevance; not pursued this run.
Single-source items: iRhythm Holdings breach (§ 1), SEC Form 8-K Item 1.05 primary only; no independent corroboration yet (national-disclosure carve-out does not apply; flagged inline).
Reduced-confidence items: Council of Europe breach (§ 4), extortion-site (ShinyHunters) claim; the Council confirms an investigation but not exfiltration. Confidence MEDIUM pending victim confirmation; the 16 June leak deadline should resolve it by the next cycle.
Contradictions: phpBB CVE-2026-48611 CVSS, Pentest-Tools.com rated it 9.4; NVD assigns 9.8. Brief reports the NVD value. LiteLLM fix timing, sources gave differing fix dates (25 April vs 2 May 2026); brief cites the fixed version (v1.83.14-stable), not a date, to avoid the discrepancy. LiteSpeed CVE-2026-54420 fixed-version, NVD describes the vulnerable range as "before WHM PlugIn 5.3.2.0", while the LiteSpeed vendor advisory states the fix shipped in WHM PlugIn 5.3.2.1 (bundled with cPanel plugin 2.4.8); the brief uses the vendor's 5.3.2.1 as the safe patch target. CVE-2026-48612 CVSS; NVD has not yet scored it; the 8.0 used here is a third-party (HackerOne) score (Pentest-Tools.com assigned 8.3).
Sub-agents: all four research sub-agents (S1–S4, Claude Sonnet 4.6) returned within the wall-clock cap. S2 and S3 completed their research but their findings-YAML writes did not persist on first return; the main agent recovered both files verbatim from the sub-agent transcripts and the run's URL-liveness ledger before composition (no content was fabricated). Verifier: 4 iterations with model rotation (iterations 1 and 3 Claude Opus 4.8; iterations 2 and 4 Claude Sonnet 4.6); verdict CLEAN at iteration 4 after three remediation rounds (phpBB PoC claim, LiteLLM per-CVE CVSS phrasing, LiteSpeed fixed-version 5.3.2.1, UAT-8616 Talos citation, LiteSpeed KEV citation, DPRK targeted-geography attribution, Novo Nordisk HCP-clause citation).
Coverage gaps: inside-it-ch (bridge 403, no unique in-window content); databreaches-net (bridge returned no output); ncsc-ch-weekly-week24 (HTTP 404; Week 24 report not yet published as of run time); anssi-fr-actu (CERT-FR actualité feed stale, no 2026 bulletins); sophos-xops (no new X-Ops research post in-window); rapid7-research (RSS feed returned empty); cnil-fr (no in-window enforcement notices).
Unmatched action items (migrated)
Audit WordPress sites running OptinMonster / TrustPulse / PushEngage active during 12–13 June UTC, hunt for unexpected admin accounts and for plugins present on disk but hidden from the admin list; pin external CDN scripts to Subresource Integrity hashes. See § 1.
Hunt Google Workspace for rogue content-compliance / BCC rules with external Gmail recipients created by non-IT-admin accounts, and file-integrity-monitor the REDCap upgrade-staging directory and login handlers (UNC6508). See § 1.
Hunt editor-spawned shells: code/cursor processes launching shell or script interpreters outside build directories, and enforce VS Code workspace-trust + VSIX allowlist policy (UNK_DeadDrop). See § 1.