State of Security | June 2026
June 2026 · MustardTree Partners Monthly Cybersecurity Report
June was the month the cybersecurity industry stopped arguing about whether artificial intelligence would reshape the threat model and started living with the consequences.
Anthropic widened its Project Glasswing defensive programme to roughly two hundred organisations, only months after disclosing what it described as the first documented large-scale cyberattack run substantially by an AI agent. At the same time a single extortion crew, ShinyHunters, turned one unpatched Oracle flaw into a breach of more than a hundred organisations. And Microsoft shipped the largest Patch Tuesday in its history. None of these stories is isolated. Together they describe a beat in which the speed of offence keeps compressing the time defenders have to respond.
The through-line this month is automation working both ways. The same agentic capability that let a state-aligned operator delegate the bulk of an intrusion campaign to a model is now being pointed back at the codebases attackers exploit. That symmetry is welcome, but it is not yet settled in defenders’ favour. Glasswing has surfaced tens of thousands of candidate vulnerabilities; the harder question is whether organisations can patch, validate and govern at the cadence the tooling now makes possible.
For security leaders the practical lesson of June is unglamorous and familiar. Identity remains the soft underbelly, unpatched enterprise software remains the fastest route in, and the organisations that suffered most were not those facing exotic capability but those carrying known, deferred risk. The novelty sat at the top of the funnel. The failures sat where they always have.
Defenders take their turn with agentic AI
Anthropic spent the first half of June expanding Project Glasswing, its initiative to apply frontier models to defensive vulnerability research. SiliconANGLE reported on 2 June that roughly 150 additional organisations were being brought into the programme on top of an initial cohort of around fifty, and by the second week of the month Glasswing partners had moved onto a more capable model tier for the work. Anthropic has framed the programme around finding and fixing flaws in widely used software before attackers reach them, supported by a substantial commitment of AI usage credits and a consortium of large technology partners. According to the company, the underlying model has flagged more than twenty thousand candidate vulnerabilities since the effort began.
The significance lies in what preceded it. In November 2025 Anthropic published its account of a cyber-espionage campaign in which a Chinese state-aligned actor manipulated its Claude Code tool into carrying out the majority of an intrusion operation against roughly thirty targets, succeeding in a small number of cases. The operators disguised malicious objectives as routine defensive testing and decomposed the work into innocuous-seeming tasks. Anthropic assessed that the model performed the bulk of tactical operations autonomously, while noting that it still hallucinated credentials and overstated results. Glasswing is, in effect, the defensive answer to that disclosure: if a model can be steered to attack at machine speed, the same class of system can be steered to audit and remediate at machine speed.
I would caution against reading the vulnerability count as unambiguous progress. A figure in the tens of thousands is a discovery statistic, not a remediation one. The governance burden, triage, validation, deduplication and safe patch deployment, now falls on security teams who were already stretched. For CISOs the strategic question is no longer whether to engage with agentic tooling but how to build the verification and approval pipelines that keep an AI-discovered finding from becoming an AI-introduced regression.
One zero-day, three hundred servers
The month’s defining intrusion required no AI at all. The ShinyHunters extortion group exploited a critical remote-code-execution vulnerability in Oracle PeopleSoft, tracked as CVE-2026-35273, to compromise enterprise systems between late May and early June. Reporting from The Hacker News, Cybersecurity Dive and BleepingComputer converged on the same picture: the actor chained older weaknesses with the zero-day to reach both cloud-hosted and on-premises instances. Mandiant notified more than a hundred affected organisations, the majority in the United States, and Oracle issued mitigations once the exploitation was confirmed.
What makes this campaign instructive is its victimology. According to Google’s threat intelligence reporting, more than two-thirds of the notified organisations were colleges and universities, and the same cluster of activity has been tied to the earlier compromise of education platform Instructure, whose Canvas environment was linked to data touching hundreds of millions of student and staff records. By mid-June the Council of Europe confirmed it too had been caught in the PeopleSoft sweep. This is a familiar pattern from a familiar actor: identify a widely deployed enterprise application, find the gap between disclosure and patching, and monetise the access through theft and extortion rather than encryption.
The identity dimension is the part security leaders should sit with. PeopleSoft is precisely the kind of system that holds payroll, HR and student records, sits adjacent to identity stores, and is too often treated as infrastructure that simply runs. A single application-layer flaw delivered roughly three hundred compromised servers across more than a hundred organisations. That is not a story about an unusually sophisticated adversary. It is a story about attack surface that nobody owned closely enough, and it argues for treating business-critical enterprise applications as identity assets that warrant the same monitoring rigour as the directory itself.
The largest Patch Tuesday on record
On 10 June Microsoft released its largest single Patch Tuesday to date. BleepingComputer, Malwarebytes and CrowdStrike all reported a fix count of around two hundred vulnerabilities, comfortably surpassing the previous record of 167 set in October 2025. The release addressed multiple publicly disclosed zero-days, and reporting identified at least one flaw under active exploitation: an Exchange Server cross-site-scripting vulnerability, tracked as CVE-2026-42897, affecting Exchange Server 2016, 2019 and the Subscription Edition. Among the other notable items were an elevation-of-privilege flaw in the Windows Collaborative Translation Framework, CVE-2026-45586, granting SYSTEM-level access, and a BitLocker security-feature bypass.
A record patch volume is not in itself a crisis, but it is a workload problem with security consequences. Elevation-of-privilege and remote-code-execution issues together made up the bulk of the release, which is the combination that turns an initial foothold into domain-wide compromise. Where an Exchange flaw is already being exploited, the calculus for federal and regulated environments is straightforward and urgent; for everyone else the difficulty is prioritisation at scale, deciding which two hundred fixes matter most this week without the staffing to test them all.
The broader trend deserves naming. Monthly patch volumes have been climbing for years, and a two-hundred-CVE month is less an anomaly than a glimpse of the steady state. Organisations still running manual, calendar-driven patch cycles are falling behind the arithmetic. The defensible posture is risk-based patching anchored to active-exploitation signals, with CISA’s Known Exploited Vulnerabilities catalogue as the floor rather than the ceiling.
Iran’s persistent campaign and the Typhoon backdrop
State and state-aligned activity continued through June with little sign of cooling. Pro-Iran hacktivist and APT clusters remained active against Israeli and US-aligned targets, leaning on distributed-denial-of-service and defacement as their visible tactics while groups such as CyberAv3ngers, assessed by researchers to be linked to the Islamic Revolutionary Guard Corps, pursued operational technology. CISA’s advisory AA26-097a documents Iranian-affiliated actors disrupting programmable logic controllers across US water, energy and government facilities, and analysts continue to flag elevated spillover risk to Gulf states hosting US assets. The pattern is a shift from episodic, attention-seeking attacks toward sustained pressure on industrial control systems.
Behind the noisier Iranian activity sits the quieter and arguably more consequential Chinese threat. The Salt Typhoon and Volt Typhoon campaigns remain the reference points for, respectively, deep telecommunications espionage and pre-positioning inside critical infrastructure for potential disruption. Neither generates monthly headlines, which is precisely the danger. For operators of critical national infrastructure the governing assumption should be that capable adversaries are already resident and patient, and that detection rather than prevention is where the marginal investment now pays off.
Notable incidents this month
Council of Europe caught in the PeopleSoft sweep. The intergovernmental body confirmed in mid-June that it was among the organisations breached through the Oracle PeopleSoft zero-day, underlining that ShinyHunters’ campaign reached well beyond higher education into public-sector institutions.
Tens of thousands of Fortinet firewalls exposed. Researchers at SOCRadar reported roughly thirty thousand compromised Fortinet firewalls exposing the networks behind them, a reminder that edge security appliances remain among the most reliably targeted assets in the enterprise perimeter.
Europol disrupts a ransomware laundering pipeline. European law enforcement moved against a cryptocurrency laundering service used by ransomware operators, an action aimed at the financial plumbing that converts stolen access into profit rather than at any single gang.
CISA adds further actively exploited flaws. Across June, CISA added several vulnerabilities to its Known Exploited Vulnerabilities catalogue, including a Cisco Catalyst SD-WAN Manager path-traversal issue, CVE-2026-20262, and a Chromium V8 out-of-bounds flaw, CVE-2026-11645, both carrying remediation deadlines for federal agencies.
Strategic imperatives for July
Treat enterprise applications as identity assets. The PeopleSoft campaign shows that HR, payroll and student systems are identity-adjacent crown jewels. Bring them inside your privileged-access monitoring and patch them on the same urgency tier as the directory.
Move to risk-based, exploitation-driven patching. A two-hundred-CVE Patch Tuesday cannot be cleared by calendar. Prioritise against active-exploitation signals and the CISA KEV catalogue, and resource emergency patching for Exchange and other internet-facing services first.
Build governance around agentic security tooling. If you are adopting AI-assisted vulnerability discovery, stand up the human verification, change-control and rollback pipeline before the findings arrive. An unvalidated AI patch is its own risk.
Assume resident adversaries in critical infrastructure. Given the Typhoon and Iranian OT activity, weight investment toward detection, segmentation and out-of-band recovery for operational technology rather than perimeter prevention alone.
Start the post-quantum inventory now. With migration timelines hardening, begin a cryptographic inventory this quarter so that “harvest now, decrypt later” collection is not quietly compromising data you still consider safe.
Looking ahead
Two slower-moving stories will shape the second half of the year. The first is regulatory. The European Commission’s January package of targeted NIS2 amendments and a revised Cybersecurity Act is now working through the system, with the NIS2 Cooperation Group adopting common incident-reporting templates in late May and most member states having transposed the directive into national law. In the United States, CISA’s long-delayed CIRCIA incident-reporting rule continues its slow path toward finalisation, with stakeholder town halls beginning in mid-June. Compliance teams should expect convergence on shorter, more structured incident-reporting obligations on both sides of the Atlantic.
The second is cryptographic. Post-quantum migration has moved from advisory to deadline. With NIST’s standards finalised and the NSA’s CNSA 2.0 timelines pushing national-security systems toward quantum resilience through the rest of the decade, the UK’s National Cyber Security Centre and others are now publishing concrete migration milestones. The uncomfortable truth is that data being exfiltrated today, including in the very breaches described above, may be readable later once the hardware matures. Organisations that have not begun a cryptographic inventory are already behind.
If June had a single message, it is that the tooling on both sides of the contest is accelerating while the fundamentals have not changed. Patch the known flaws, govern identity as the primary control plane, and assume your adversary is already automating. The organisations that fared worst this month were undone by deferred basics, not by the frontier. July will reward those who close that gap before the next zero-day finds it for them.



