What Business Owners Need to Know This Week

Week 25 (7–14 June 2026) combined a live SA private-sector incident with a record-breaking patch cycle. AVBOB Mutual Assurance, South Africa’s largest funeral insurer with 350+ branches, was struck by external malicious actors on or around 7–8 June — digital platforms went offline, branches reverted to manual operations, and the Information Regulator was notified. The 9 June Patch Tuesday was the largest in Microsoft’s history at 208 CVEs (38 Critical), headlined by CVE-2026-45657, a wormable Windows kernel TCP/IP RCE at CVSS 9.8, and by the long-awaited Exchange OWA permanent patch (KB5094139), closing a four-week patchless window. SAPS Western Cape confirmed a POPIA breach exposing diagnostic medical records of 2,978 officers. Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) was mass-exploited as a zero-day by ShinyHunters/UNC6240 across 300+ instances, and Ivanti Sentry CVE-2026-10520 (CVSS 10.0) was weaponised within 24 hours of patch release.

The Bottom Line: The FLAT ransomware count (111, now a fifth consecutive week) again masks real activity outside the trackers — a live incident at SA’s largest funeral insurer, a police medical-records breach, and a cluster of actively-exploited critical vulnerabilities. The dominant operational driver is the 9 June Patch Tuesday: the wormable kernel RCE (CVE-2026-45657) plus the PeopleSoft and Ivanti emergency responses must be the primary change-window focus for every SA organisation this week.

The Week in Numbers

  • 111 cumulative SA ransomware victims — FLAT for the fifth consecutive week.
  • 350+ branches — AVBOB, SA’s largest funeral insurer, offline and reverted to manual operations after the 7–8 June attack.
  • 208 CVEs (38 Critical) — record-breaking Microsoft June Patch Tuesday, the largest in program history.
  • CVSS 9.8 — CVE-2026-45657, wormable Windows kernel TCP/IP RCE; the #1 June patch for every SA estate.
  • 2,978 SAPS officers — diagnostic medical records exposed in the SAPS Western Cape POPIA breach.
  • 300+ instances / 100+ organisations — Oracle PeopleSoft CVE-2026-35273 zero-day mass-compromise by ShinyHunters/UNC6240, including the University of Nottingham (454,600 records).
  • <24 hours — time for Ivanti Sentry CVE-2026-10520 (CVSS 10.0) to be weaponised after patch release.
  • 18 CVEs — companion OpenSSL advisory, including the critical PKCS7_verify() heap UAF (CVE-2026-45447).
  • 4,466 CVEs — exposed on non-SITA gov.za infrastructure per GroundUp’s Part 2 investigation; 1-in-5 hosts vulnerable.

Major Incidents: Who Was Hit and How

AVBOB — SA’s Largest Funeral Insurer Knocked Offline

AVBOB Mutual Assurance was struck by external malicious actors on or around 7–8 June. Digital platforms went offline, 350+ branches reverted to manual operations, and the Information Regulator was notified. As of 14 June no group has claimed credit on indexed leak sites; ransomware versus extortion-only remains unconfirmed and the forensic audit is in progress. This is the highest-profile SA private-sector disruption since the current cycle began.

Record 208-CVE Patch Tuesday — Wormable Kernel RCE + Exchange OWA Fix

The 9 June Patch Tuesday was the largest in Microsoft’s program history at 208 CVEs (38 Critical). The standout fixes: CVE-2026-42897 — the Exchange OWA permanent patch finally shipped via KB5094139, closing the four-week patchless window since the KEV deadline — and CVE-2026-45657, a wormable Windows kernel TCP/IP RCE (CVSS 9.8) that should be every SA estate’s #1 June patch, alongside companion HTTP.sys fix CVE-2026-47291 (9.8). The same-day OpenSSL advisory shipped 18 CVEs including CVE-2026-45447, a critical heap use-after-free in PKCS7_verify() — rebuild container images and restart TLS services.

SAPS Western Cape — 2,978 Officers’ Medical Records Exposed

SAPS Western Cape confirmed a POPIA breach affecting 2,978 officers after an HR email circulated an attachment exposing diagnostic medical records — including PTSD, bipolar disorder, alcoholism, and cancer diagnoses. Beyond the acute privacy harm to serving officers, the incident is a textbook internal-handling failure: no external attacker was required. Every organisation handling special personal information should treat this as a prompt to review internal distribution controls and DLP rules.

Oracle PeopleSoft Zero-Day — ShinyHunters Mass-Compromise

Oracle PeopleSoft CVE-2026-35273 (CVSS 9.8) was exploited as a zero-day by ShinyHunters/UNC6240 from 27 May, compromising 300+ instances across 100+ organisations including the University of Nottingham (454,600 records). The CISA KEV deadline is 15 June. SA relevance is HIGH — PeopleSoft is present in SA universities, public-sector HCM, and large enterprise. Disable PSEMHUB, block /PSEMHUB/hub at the perimeter, and audit web-server logs from 27 May onward.

Ivanti Sentry (CVSS 10.0) Weaponised in Under 24 Hours

Ivanti Sentry CVE-2026-10520 (CVSS 10.0) and companion CVE-2026-10523 (9.9) were weaponised within 24 hours of patch release — KEV deadline 14 June. Patch to R10.5.2/R10.6.2/R10.7.1 immediately. Also this week: Check Point Security Gateway CVE-2026-50751 (IKEv1 auth bypass) landed on the KEV with a 3-day window, and a Chrome V8 zero-day (CVE-2026-11645) is under active exploitation — force-update all Chromium browsers.

POPIA and Regulatory

Two POPIA notifications dominated the week: AVBOB’s Information Regulator notification following the attack, and the SAPS Western Cape medical-records breach — the latter involving special personal information of serving police officers. GroundUp’s Part 2 investigation into government attack surface found 4,466 CVEs exposed on non-SITA gov.za infrastructure with roughly 1-in-5 hosts vulnerable, extending the W24 SITA findings. The SuppCenter MSSP (Xcitium/Comodo) listing on M3RX (11 June) raises supply-chain risk questions for SA public-sector customers.

Full Intelligence Report

The complete Week 25 technical report covers the AVBOB incident timeline, the full 208-CVE Patch Tuesday priority matrix, the SAPS Western Cape breach analysis, the PeopleSoft emergency-response playbook, the Ivanti Sentry / Check Point / Chrome V8 exploitation guidance, the GroundUp gov.za attack-surface data, and structured hunt missions with full IOC tables.

What Your Business Should Do Right Now

  • Patch the wormable kernel RCE first (CVE-2026-45657): Deploy the full Windows June security rollup as the #1 priority — the wormable kernel TCP/IP RCE (CVSS 9.8) plus companion HTTP.sys CVE-2026-47291 are the standout fixes. Apply the Exchange OWA permanent patch (KB5094139) in the same change window; Exchange 2016/2019 estates require ESU enrolment.
  • Rebuild for OpenSSL: The 18-CVE OpenSSL advisory includes a critical PKCS7_verify() heap use-after-free (CVE-2026-45447). Rebuild container images and restart TLS services after updating.
  • Oracle PeopleSoft emergency response (KEV 15 June): Disable PSEMHUB, block /PSEMHUB/hub at the perimeter, and audit web-server logs from 27 May onward. ShinyHunters mass-exploited this 9.8 zero-day across 300+ instances — SA universities and public-sector HCM estates are directly in scope.
  • Patch Ivanti Sentry (CVSS 10.0, KEV 14 June): Update to R10.5.2/R10.6.2/R10.7.1 — exploits were deployed within 24 hours of release. Remediate Check Point Security Gateway CVE-2026-50751 within its 3-day window, and force-update all Chromium browsers for the V8 zero-day.
  • Review internal data-handling controls: The SAPS Western Cape breach came from an HR email attachment, not an external attacker. Audit who can distribute special personal information internally, and configure DLP rules for medical and HR data.
  • Test manual-operations fallback: AVBOB’s branches reverted to manual processing. If your digital platforms went down tomorrow, could your branches or service desks operate? Validate the downtime procedures and communication templates now.