Microsoft released June 2026 patches and more - Jun 14, 2026 Weekly Roundup Jun 14 Written By RF Wave Featured Microsoft Released June 2026 Software Updates The updates fix 200 security vulnerabilities in total, with 6 zero-day vulnerabilities disclosed This Week’s Updates Breaches Oxford University discloses data breach after attackers compromised its CareerConnect careers platform, exposing names, email addresses, and encrypted passwords of students, alumni, research staff, and employer users ServiceNow confirms security incident after attackers exploited an unauthenticated API endpoint to query customer instance data University of Nottingham confirms ShinyHunters breach exposing financial and personal data of 454,600 current and former students French government confirms Tchap encrypted messaging platform breach affecting over 73,000 public sector employees, with messages and account metadata stolen Novo Nordisk discloses breach of internal IT systems exposing pseudonymized clinical trial patient data and healthcare professional contact information Vulnerabilities Google releases emergency update to patch Chrome zero-day CVE-2026-11645, an out-of-bounds read/write flaw in the V8 JavaScript engine actively exploited in the wild Oracle releases emergency mitigations for CVE-2026-35273, a critical PeopleSoft zero-day (CVSS 9.8) actively exploited by ShinyHunters against over 100 organizations CISA orders federal agencies to patch Ivanti Sentry CVE-2026-10520, a max-severity OS command injection flaw actively exploited in the wild, within three days phpBB releases version 3.3.17 to fix a 10-year-old authentication bypass vulnerability allowing attackers to log in as any user including administrators vulnerabilitydata breachMicrosoftPatch TuesdayOxford UniversityServiceNowUniversity of NotthinghamFrench governmentNovo NordiskGoogleChromeOracleIvantiphpBB RF Wave
Microsoft released June 2026 patches and more - Jun 14, 2026 Weekly Roundup Jun 14 Written By RF Wave Featured Microsoft Released June 2026 Software Updates The updates fix 200 security vulnerabilities in total, with 6 zero-day vulnerabilities disclosed This Week’s Updates Breaches Oxford University discloses data breach after attackers compromised its CareerConnect careers platform, exposing names, email addresses, and encrypted passwords of students, alumni, research staff, and employer users ServiceNow confirms security incident after attackers exploited an unauthenticated API endpoint to query customer instance data University of Nottingham confirms ShinyHunters breach exposing financial and personal data of 454,600 current and former students French government confirms Tchap encrypted messaging platform breach affecting over 73,000 public sector employees, with messages and account metadata stolen Novo Nordisk discloses breach of internal IT systems exposing pseudonymized clinical trial patient data and healthcare professional contact information Vulnerabilities Google releases emergency update to patch Chrome zero-day CVE-2026-11645, an out-of-bounds read/write flaw in the V8 JavaScript engine actively exploited in the wild Oracle releases emergency mitigations for CVE-2026-35273, a critical PeopleSoft zero-day (CVSS 9.8) actively exploited by ShinyHunters against over 100 organizations CISA orders federal agencies to patch Ivanti Sentry CVE-2026-10520, a max-severity OS command injection flaw actively exploited in the wild, within three days phpBB releases version 3.3.17 to fix a 10-year-old authentication bypass vulnerability allowing attackers to log in as any user including administrators vulnerabilitydata breachMicrosoftPatch TuesdayOxford UniversityServiceNowUniversity of NotthinghamFrench governmentNovo NordiskGoogleChromeOracleIvantiphpBB RF Wave