@joshua_saxe I don't think it is negligence or under-resourced security. It is the balance between security and velocity. With AI and business pressures to move fast, the tilt towards velocity used to be a bit high. Now the tilt towards velocity is way too high.
β οΈ CVE-2026-65667 | Microsoft Teams | CVSS 10.0
Critical Elevation of Privilege caused by CWE-862: Missing Authorization. Remote, unauthenticated, and zero-click exploitation is possible.
Microsoft deployed a server-side fix. No public PoC or observed exploitation so far.
Action: Verify tenant remediation and hunt for anomalous privilege escalation or unauthorized Teams access.
Full Advisory: https://t.co/ka9ey7suXR
β οΈ CVE-2026-65667 | Microsoft Teams | CVSS 10.0
Critical Elevation of Privilege caused by CWE-862: Missing Authorization. Remote, unauthenticated, and zero-click exploitation is possible.
Microsoft deployed a server-side fix. No public PoC or observed exploitation so far.
Action: Verify tenant remediation and hunt for anomalous privilege escalation or unauthorized Teams access.
Full Advisory: https://t.co/ka9ey7suXR
Baselining cloud has been historically tricky. With LLMs understanding the cloud operations at a business level is possible. Here are the open source skills that @transilienceai made.
https://t.co/bssggGj7HV
A link that points to https://t.co/Vq0qkUy0iZ shouldn't be able to empty your inbox. SearchLeak (CVE-2026-42824) did exactly that, with a single click.
The trick: the search query in the URL gets run as a prompt, telling Copilot to pull your email, files, calendar, even MFA codes. An image tag in the reply fires before the sanitizer catches it, and the data slips out through a Bing fetch that's already on the allowlist. No payload, no fake domain, so nothing trips your filters.
Patched now, but it's the 3rd bug of this shape in 2 years, we have done a full analysis of this pattern and curated a report.
Link: https://t.co/Zhk26ngwm7
A link that points to https://t.co/Vq0qkUy0iZ shouldn't be able to empty your inbox. SearchLeak (CVE-2026-42824) did exactly that, with a single click.
The trick: the search query in the URL gets run as a prompt, telling Copilot to pull your email, files, calendar, even MFA codes. An image tag in the reply fires before the sanitizer catches it, and the data slips out through a Bing fetch that's already on the allowlist. No payload, no fake domain, so nothing trips your filters.
Patched now, but it's the 3rd bug of this shape in 2 years, we have done a full analysis of this pattern and curated a report.
Link: https://t.co/Zhk26ngwm7
A Qilin ransomware affiliate was logging into Check Point VPNs with no valid credentials for a month before a patch existed.
CVE-2026-50751: a CVSS 9.3 auth bypass, a logic flaw in IKEv1 certificate validation. It only hits gateways running IKEv1 with legacy clients allowed and no mandatory machine certificate; IKEv2-only is safe.
Exploitation goes back to May 7 and Checkpoint didn't ship the fix until June 8, and it's now on CISA's KEV. The bypass is just the front door, Qilin's follow-through is data theft, encryption, then a leak-site threat.
Patch and then hunt your VPN logs back to May 7 for certificate-only logins with no password event.
We have curated all of the details of zero day on one place, link in comments π
Unpatched zero-day in Microsoft Defender, public PoC out now.
"RoguePlanet" escalates any local user to SYSTEM on fully patched Win 10/11. No CVE. No patch. (MITRE T1068)
Mitigate: app allowlisting + EDR.
Full advisory π
You patched Chrome on every laptop. Did you patch the headless Chrome in your CI pipeline?
CVE-2026-11645: a V8 zero-day already exploited in the wild : the 5th Chrome 0-day this year. Same engine renders untrusted HTML in your CI runners, where secrets live.
Patch now. Full detailed advisory in comments.
You opened the repo. That was enough.
On June 5, the Miasma worm hit 73 Microsoft GitHub repos. No npm install, just opening the folder in Claude Code, Cursor, Gemini CLI or VS Code fired the payload.
The full breakdown π
A full-stack security OS has to do one thing before any other: take the operator role out of the human seat.
The interface was a screen and a keyboard. Today it becomes a conversation.
Voice mode is live in Transilience Full Stack Security OS.
My favorite morning routine these days is to correlate alerts to vulnerabilities, to asset configurations, prioritize the activity for the customer, fire off report to the remediation teams of the customer. Its my favorite because talking to the security stack is fun.