<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>kyber.today</title><description>Daily recaps of the top cybersecurity and AI news.</description><link>https://kyber.today/</link><item><title>ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot &quot;SearchLeak&quot; Shows AI Is the New Exfil Channel</title><link>https://kyber.today/issues/2026-06-18-shinyhunters-burns-a-peoplesoft-zero-day-through-higher-ed-a/</link><guid isPermaLink="true">https://kyber.today/issues/2026-06-18-shinyhunters-burns-a-peoplesoft-zero-day-through-higher-ed-a/</guid><description>A critical vulnerability blitz dominates this digest: Oracle PeopleSoft CVE-2026-35273, Splunk CVE-2026-20253, and an unpatched Microsoft Defender RoguePlanet zero-day are actively exploited, with ShinyHunters and other threat actors targeting higher education and enterprise networks. The AI/security layer has emerged as a major attack surface, exemplified by Microsoft 365 Copilot SearchLeak (one-click data exfiltration), Google Vertex AI cross-tenant RCE, and the Novo Nordisk breach that exposed proprietary AI model checkpoints and training infrastructure as ransomware extortion payload—underscoring that AI IP is now a strategic target.</description><pubDate>Thu, 18 Jun 2026 07:39:57 GMT</pubDate><category>zero-day</category><category>rce</category><category>remote-code-execution</category><category>privilege-escalation</category><category>authentication-bypass</category><category>prompt-injection</category><category>ai-security</category><category>llm-security</category><category>supply-chain-attack</category><category>data-breach</category><category>ransomware</category><category>malware-analysis</category><category>credential-harvesting</category><category>ai-exfiltration</category></item><item><title>Microsoft 365 Copilot &apos;SearchLeak&apos; Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists</title><link>https://kyber.today/issues/2026-06-17-microsoft-365-copilot-searchleak-enables-one-click-data-thef/</link><guid isPermaLink="true">https://kyber.today/issues/2026-06-17-microsoft-365-copilot-searchleak-enables-one-click-data-thef/</guid><description>A critical day for AI and enterprise security: Microsoft 365 Copilot was patched for the &quot;SearchLeak&quot; one-click exfiltration vulnerability (CVE-2026-42824), while Novo Nordisk confirmed a breach exposing trained AI models and proprietary training data to extortionists. Multiple actively-exploited flaws emerged in Fortinet FortiSandbox, Joomla JCE, Cisco Catalyst SD-WAN Manager, LiteSpeed cPanel, and Palo Alto GlobalProtect, alongside supply-chain compromises affecting Arch Linux AUR, JetBrains Marketplace, and npm packages. Major APTs including UNC6508, SprySOCKS (FishMonger), ScarCruft, and SideCopy expanded targeting of medical research, defense, and developer communities.</description><pubDate>Wed, 17 Jun 2026 11:23:10 GMT</pubDate><category>zero-day</category><category>prompt-injection</category><category>data-breach</category><category>supply-chain-attack</category><category>llm-security</category><category>ransomware</category><category>privilege-escalation</category><category>lateral-movement</category><category>ai-model-theft</category><category>malware-distribution</category><category>extortion</category></item></channel></rss>