Sysdig Blog
Read post

Security briefing: June 2026

June 2026's security briefing covers several notable incidents and research findings. The French government's Tchap messaging app was breached via social engineering, exposing data from 73,000 accounts. Novo Nordisk suffered a cloud extortion attack by FulcrumSec, which exfiltrated 1.3 TB of data including clinical trial data and AI models after gaining access through exposed credentials. Sysdig's Threat Research Team documented an agentic threat actor performing a fully automated container escape and Kubernetes cluster compromise, attackers jailbreaking LLMs using CTF-framing to generate CVE exploits, and an evolution of LLMjacking toward building autonomous offensive hacking tools. A Langflow CVSS 9.9 IDOR vulnerability was found to be less exploited than a lower-scored RCE, challenging CVSS-based prioritization. Additional news includes the named Cordyceps GitHub Actions abuse pattern, a supply chain breach via Klue affecting LastPass and others, and a new Linux kernel privilege escalation flaw (DirtyClone).

    #security
Jul 07•6m read time•From webflow.sysdig.com
Post cover image
Table of contents
June 8: Breach of messaging app built for privacyJune 11: Incidental cloud exposure leads to massive data leak
154 Impressions
Sysdig Blog's image
Sysdig Blog

2 Followers

•

3 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard