June 2026's security briefing covers several notable incidents and research findings. The French government's Tchap messaging app was breached via social engineering, exposing data from 73,000 accounts. Novo Nordisk suffered a cloud extortion attack by FulcrumSec, which exfiltrated 1.3 TB of data including clinical trial data and AI models after gaining access through exposed credentials. Sysdig's Threat Research Team documented an agentic threat actor performing a fully automated container escape and Kubernetes cluster compromise, attackers jailbreaking LLMs using CTF-framing to generate CVE exploits, and an evolution of LLMjacking toward building autonomous offensive hacking tools. A Langflow CVSS 9.9 IDOR vulnerability was found to be less exploited than a lower-scored RCE, challenging CVSS-based prioritization. Additional news includes the named Cordyceps GitHub Actions abuse pattern, a supply chain breach via Klue affecting LastPass and others, and a new Linux kernel privilege escalation flaw (DirtyClone).