// CIO Briefings
68 briefings — page 1 of 4
About CIO Briefings
CIO Briefings translate technical security events into business language for executives and board members. Each briefing covers the financial and operational impact, relevant regulatory obligations, and prioritised actions — without requiring deep technical knowledge to act on.
iRhythm Cardiac Data Breach — 12 Million Patients' Health Records Exposed, HIPAA Notification Triggered
iRhythm Technologies, the maker of the Zio continuous cardiac monitoring patch, has disclosed a data breach affecting approximately 12 million patients after social engineering granted attackers access to third-party-hosted systems containing protected health information. Healthcare providers that refer patients to iRhythm may carry independent HIPAA breach notification obligations and should urgently assess whether their patient populations are within scope.
CRITICAL: PAN-OS VPN Flaw CVE-2026-0257 Actively Exploited — Attackers Gaining Silent Network Access
A critical vulnerability in Palo Alto Networks GlobalProtect VPN — the primary remote access gateway for thousands of enterprises — allows attackers to bypass login controls entirely and gain access to internal corporate networks without credentials. Exploitation is confirmed and ongoing, with government agencies and critical infrastructure operators among identified victims. Immediate patching is required.
CRITICAL: Ivanti Sentry CVE-2026-10523 + CVE-2026-10520 Chain Enables Complete MDM Gateway Compromise
Two critical Ivanti Sentry vulnerabilities — CVE-2026-10523 (CVSS 9.9, auth bypass) and CVE-2026-10520 (CVSS 10.0, pre-auth RCE) — chain to enable complete unauthenticated takeover of the Sentry MDM gateway. Organisations that applied the initial patch for CVE-2026-10520 remain exposed through CVE-2026-10523. Immediate upgrade to 9.19.0 required.
CIO Brief: Ivanti Sentry CVE-2026-10520 (CVSS 10.0) — Mobile Management Gateway Actively Under Attack
Ivanti Sentry carries a CVSS 10.0 pre-authentication remote code execution vulnerability being actively exploited in the wild. Ivanti Sentry is deployed as an internet-facing mobile device management gateway — any organisation using Sentry for mobile email and application access is exposed. Upgrade to Sentry 9.19.1 immediately.
CIO Brief: Microsoft June 2026 Patch Tuesday — Three CVSS 9.8 Flaws Require Emergency Response
Microsoft's June 2026 Patch Tuesday includes three CVSS 9.8 remote code execution vulnerabilities — including a wormable HTTP.sys flaw — plus a Kerberos KDC RCE targeting domain controllers. This is the most critical single Microsoft patch event of 2026 and requires emergency-tier prioritisation across all Windows Server infrastructure.
Check Point VPN Authentication Bypass CVE-2026-50751 — Ransomware Groups Actively Exploiting
A critical vulnerability in Check Point Security Gateway allows attackers to bypass VPN authentication entirely without any credentials, gaining direct access to internal networks. Ransomware groups are actively using this technique. CISA has issued an emergency three-day remediation deadline. All organisations running Check Point Security Gateways must act immediately.
Gentelman Ransomware Surges Against Healthcare — 15 Victims in 72 Hours
A ransomware group known as Gentelman (Storm-2697) has recorded at least 15 confirmed victims in healthcare and professional services between 1 and 3 June 2026. The attack chain exploits unpatched remote management tools. Healthcare organisations with internet-exposed remote access software should audit and patch immediately.
CRITICAL: Oracle WebLogic CVE-2024-21182 on CISA KEV — Ransomware Delivery Confirmed, Federal Deadline June 4
CISA added CVE-2024-21182 to the KEV on 1 June as honeypots confirm ransomware delivery via Oracle WebLogic T3/IIOP unauthenticated code execution. Despite a patch being available since January 2024, unpatched WebLogic deployments are being actively targeted. Organisations running WebLogic 12.2.1.4.0 or 14.1.1.0.0 must patch immediately.
CRITICAL: Windows Netlogon CVE-2026-41089 — Unauthenticated Domain Controller RCE, Active Exploitation Confirmed
CVE-2026-41089 (CVSS 9.8) allows an unauthenticated attacker to execute code as SYSTEM on Windows domain controllers via a stack overflow in the Netlogon service. Belgium's CCB confirmed active exploitation on 29 May. A successful exploit provides full Active Directory domain compromise. Patch all domain controllers immediately.
CRITICAL: Citrix NetScaler CVE-2026-3055 Mass Exploitation — Thousands of SAML IDP Appliances Compromised
Fortinet confirmed large-scale active exploitation of CVE-2026-3055 (CVSSv4 9.3) in Citrix NetScaler ADC and Gateway on 28 May. Despite a patch being available since 24 March, thousands of internet-facing appliances remain unpatched after 65+ days. The SAML IDP memory overread can leak session tokens and SAML signing keys. Patch and investigate immediately.
Three Maximum-Severity Security Flaws Discovered in Ubiquiti Network Management Software — Update Required Immediately
Ubiquiti has disclosed three maximum-severity (CVSS 10.0) security vulnerabilities in UniFi OS — the management software that controls Ubiquiti Wi-Fi access points, switches, and network gateways. Attackers with network access to the management interface can gain full administrative control without any password. Organisations using Ubiquiti UniFi equipment must apply updates immediately.
VPN Security Alert: Attackers Bypassing Palo Alto Networks VPN Passwords in Second Active Exploitation Wave
Attackers are actively bypassing password authentication on Palo Alto Networks GlobalProtect VPN systems without needing valid credentials. CISA has added the vulnerability to its mandatory patch list. Organisations using GlobalProtect VPN must apply patches immediately; all systems that have been internet-facing while on vulnerable software versions should be forensically reviewed for prior access.
AI Knowledge Base Software Has a Maximum-Severity Security Flaw — No Fix Available
A maximum-severity vulnerability has been disclosed in ChromaDB, one of the most widely used software components for building AI systems that access company knowledge bases and documents. Attackers can gain full control of the ChromaDB server without any login credentials, accessing all documents stored for the AI system. No fix is currently available. 73% of internet-exposed ChromaDB instances are affected.
Microsoft Exchange Server Has an Unpatched SYSTEM-Level Remote Code Execution Vulnerability — Here Is What That Means for Your Organisation
Security researchers publicly demonstrated an unpatched three-bug exploit chain against Microsoft Exchange Server at Pwn2Own Berlin 2026, achieving the highest possible privilege level (SYSTEM) on a fully updated Exchange Server without any password or user account. The patch will arrive within 90 days. Organisations must prepare defensive measures immediately and plan for emergency patching when it arrives.
VMware ESXi Zero-Day: Attacker in One Virtual Machine Can Execute Code in a Neighbouring Tenant's VM
Security researchers at Pwn2Own Berlin 2026 demonstrated a vulnerability in VMware ESXi that allows an attacker with code execution inside one virtual machine to execute code inside a completely separate virtual machine on the same physical host. No patch is available. The bug has been disclosed to Broadcom under the 90-day Pwn2Own coordinated disclosure process.
Microsoft Exchange Zero-Day: Attackers Hijacking Employee Email Sessions Without Passwords via OWA Exploit
Microsoft disclosed an actively exploited zero-day in Exchange Server's Outlook Web App that allows attackers to hijack authenticated email sessions and read all email without knowing passwords. No patch is available. Microsoft has deployed an automatic mitigation but on-premises Exchange customers must verify it has applied. Nation-state targeting of government and finance sectors has been confirmed.
Cisco SD-WAN CVSS 10.0 Zero-Day: Unauthenticated Attackers Can Compromise Your Entire Wide-Area Network
Cisco disclosed and patched a CVSS 10.0 zero-day vulnerability (CVE-2026-20182) in Catalyst SD-WAN Manager that was actively exploited before the patch was released. Attackers bypassed authentication to inject rogue devices into the SD-WAN fabric, enabling interception of all WAN traffic. Any organisation running Cisco Catalyst SD-WAN must patch and hunt for indicators of compromise immediately.
Foxconn Ransomware Attack: Apple, NVIDIA, and Intel Supply Chain Data Stolen in 8 TB Exfiltration
Foxconn, the world's largest electronics contract manufacturer, confirmed a ransomware attack on its North American factories that exfiltrated 8 TB of supply chain data including documentation for Apple, NVIDIA, and Intel products. Manufacturing disruptions affected multiple facilities. Customers with sensitive product data in Foxconn's systems should assess notification obligations and consider supply chain intelligence exposure.