Multiple breaches announced, vulnerabilities exploited ITW, attacks in Italy
Breaches: University of Oxford, World Food Programme (WFP), Tchap and ServiceNow targeted
Third-party provider Group GTI, responsible for the CareerConnect platform used by the University of Oxford, informed the institution that the system had been subjected to unauthorized access. Group GTI stated that it had remediated the vulnerability and implemented security measures. Subsequently, on June 2, 2026, the United Nations World Food Programme (WFP) confirmed a data breach affecting the Self-Registration Application (SRA), a platform used by Palestinian beneficiaries to register for food and financial assistance programs. According to the organization, unauthorized actors gained access to the personal information of approximately 600,000 families in the Gaza Strip. The WFP clarified that the incident did not affect any other organizational systems, including SCOPE, its global beneficiary data management program. On June 7, 2026, a threat actor identified as “misere” claimed on an underground forum to have exfiltrated a large dataset from the Tchap platform (tchap[.]gouv[.]fr), the official institutional messaging system of the French Government developed by the Direction Interministérielle du Numérique (DINUM) and used by public officials from ministries such as the Interior, Finance, Defense, ANSSI, Foreign Affairs, Justice, and the Prime Minister’s Office. The actor published samples of internal conversations, highlighting the platform’s use for informal communications and non-institutional content, while the full archive was placed behind a paywall on the forum. The exposure of metadata, conversations, and credentials belonging to senior public officials, including references to restricted classifications, therefore represents a potentially severe breach of French national security. Finally, on June 10, 2026, California-based software company ServiceNow published an official advisory regarding a security incident involving an issue that could, under certain circumstances, allow an unauthenticated user to gain unintended access to information stored within platform instances. The company is evaluating, in accordance with its internal policies, the possibility of assigning a CVE identifier to the issue. The impact was limited to a subset of hosted instances, but the security update was also distributed to partners and self-hosted customers.
Vulnerabilities: Google, Cisco, Check Point, SolarWinds, Microsoft Defender and Oracle flaws exploited ITW
Google patched several vulnerabilities, including the zero-day tracked as CVE-2026-11645, an Out-of-Bounds Memory Access flaw in V8 that allows a remote attacker to execute arbitrary code within a sandbox through a specially crafted HTML page. The vendor stated that it is aware of an in-the-wild (ITW) exploit. The vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. Cisco released a security advisory for a high-impact vulnerability in Cisco Catalyst SD-WAN Manager that is being exploited ITW and has also been included in the KEV catalog. Tracked as CVE-2026-20245 (CVSS 7.8), the flaw is an Improper Encoding or Escaping of Output vulnerability in the Command Line Interface (CLI), caused by insufficient validation of user-supplied input, which could allow a local authenticated attacker to execute arbitrary commands with root privileges by uploading a specially crafted file to the affected system. Check Point released security updates for Security Gateways and Spark Firewall addressing two vulnerabilities, one of which is being exploited ITW. The flaw, tracked as CVE-2026-50751 (CVSS 9.3), is an Authentication Bypass vulnerability that allows a remote unauthenticated attacker to bypass user authentication by exploiting a weakness in the certificate validation logic during IKEv1 key exchange, thereby establishing a remote-access VPN connection without a valid user password. According to reports, exploitation has been limited to a few dozen targeted organizations worldwide. One confirmed post-compromise case has been associated with Qilin Team. CISA added CVE-2026-50751 to its KEV catalog on June 8, 2026, requiring U.S. Federal Civilian Executive Branch (FCEB) agencies to remediate the vulnerability by June 11, 2026. Furthermore, on June 5, 2026, CISA added SolarWinds Serv-U vulnerability CVE-2026-28318 to its KEV catalog. This Uncontrolled Resource Consumption flaw allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication. U.S. Federal Civilian Executive Branch (FCEB) agencies have been instructed to remediate the vulnerability by June 19, 2026. On June 9, 2026, just hours after the release of Patch Tuesday updates, the researcher known as Nightmare Eclipse published a Proof-of-Concept (PoC) exploit on GitHub for a new Microsoft Defender zero-day vulnerability dubbed RoguePlanet. Specifically, the issue is a Time-of-Check Time-of-Use (TOCTOU) Race Condition in Microsoft Defender’s mpengine that allows local privilege escalation to the NT AUTHORITY\SYSTEM level. At present, Microsoft has not released an official patch for this vulnerability, and the exploit continues to function successfully on systems updated with the June 2026 Patch Tuesday release. The only effective workaround is application allowlisting, namely the implementation of application control policies to prevent the execution of unauthorized binaries. Finally, Oracle released a security advisory for a high-impact vulnerability in Oracle PeopleSoft PeopleTools that is being exploited ITW. Tracked as CVE-2026-35273 (CVSS 9.8), the flaw is a Missing Authentication for Critical Function vulnerability that allows an unauthenticated attacker with HTTP network access to compromise the target system, potentially resulting in remote code execution. The ShinyHunters group claimed responsibility for compromising PeopleSoft servers belonging to more than 100 organizations, the majority of which operate in the education sector. It should also be noted that the following vulnerabilities were added to the KEV catalog this week: CVE-2026-42271 (OS Command Injection/Command Injection) affecting BerriAI LiteLLM, CVE-2026-7473 (Incomplete Comparison with Missing Factors) affecting Arista Extensible Operating System (EOS), and CVE-2026-10520 (OS Command Injection) affecting Ivanti Sentry. A Proof-of-Concept (PoC) also appears to be available for the latter.
Italy: multiple malicious activities observed
Over the past week, several offensive activities targeted Italian organizations. A new INPS-themed smishing campaign was identified, accessible exclusively from mobile devices. The pro-Russian hacktivist collective NoName057(16) claimed responsibility for DDoS attacks against 21 Italian targets, including: Europa Verde; the Municipality of Potenza; the Regional Council of Valle d’Aosta; the Lazio Region; the Municipality of Giugliano; Tiscali Italia S.p.A.; HeraBit S.p.A.; the Municipality of Parma; the Municipality of Reggio Emilia; the Italian Union of Public Administration Workers (UILPA); the Port Authority of Olbia and Golfo Aranci; the Municipality of Palermo; the Sicilian Regional Assembly; the Province of Padua; the Municipality of Arzignano; CoopVoce; Terminal Napoli S.p.A.; the Port System Authority of the Central Tyrrhenian Sea; the Port Authority of the Strait of Messina; the Unione Sindacale di Base (USB); and the Centre for the Study of Socio-Economic Transformations (CESTES). The same actor also claimed a purported compromise of the CCTV system of an Italian gaming hall equipped with numerous slot machines. According to the claim, the group obtained full access to the CCTV infrastructure, including real-time monitoring of customers, employees, and activities within the facility. Remaining within the hacktivist landscape, the Dark Storm Team collective claimed DDoS attacks against Veneto Sviluppo S.p.A.; the Italian Customs and Monopolies Agency (Change Request Service); CRP Technology S.r.l.; Aidro S.r.l.; NiEW Design S.r.l.; and Sagewill S.r.l. Turning to the ransomware landscape, Nova claimed on its leak site the compromise of Trevi; Space Bears affecting Cattani S.p.A.; and NightSpire affecting Pattono S.r.l. Finally, Eataly detected a cyberattack against the infrastructure hosting its Italian e-commerce platform. Unauthorized access may have exposed personal and contact information (first name, last name, date of birth, tax identification number, addresses, contact details), as well as the order history of certain users. No credit card data or plaintext passwords appear to have been exposed. The company explicitly stated that there is no evidence of data downloads or theft and that, at this time, no threat actor has claimed responsibility for the attack.
Weekly Threats Report is Telsy’s weekly update featuring the main developments on cyber attacks and threat actors worldwide, produced by our Threat Intelligence & Response team.
The team is composed of analysts and security researchers with technical and investigative skills and internationally recognized experience.
Through continuous monitoring of cyber threats and geopolitical events, it produces and provides organizations with useful information to anticipate attacks and understand their scope, with the support of a trusted partner in the event of a cyber incident.
Learn more about our Cyber Threat Intelligence solution.
