The Canadian Centre for Cyber Security (CCCS) published a daily digest on June 10, 2026, highlighting security advisories for OpenSSL, HPE, Spring, Mozilla, FreeBSD, and AMD. Organizations are advised to review the specific product advisories and apply necessary patches to mitigate potential vulnerabilities.
OpenSSL
3 posts
Cyber Centre Daily Advisory Digest — 2026-06-10 (6 advisories) The AI Threat Multiplier: Why Architectural Flaws Are the New Frontier Security researchers identified a signal-reentrancy weakness in a signed macOS OpenSSL wrapper binary. The vulnerability arises from the intersection of legacy TLS capabilities and async-unsafe POSIX functions, which can be exploited via race conditions and forced TLS downgrades to cause Denial of Service (DoS) or potential memory corruption.
TeamPCP Compromises Telnyx Python SDK to Deliver Credential-Stealing Malware The official Telnyx Python SDK on PyPI was compromised by the threat actor TeamPCP, who published malicious versions (4.87.1 and 4.87.2) containing credential-harvesting malware. The malware executes upon module import, utilizing audio steganography to deliver OS-specific payloads: a fileless in-memory harvester for Linux/macOS and a persistent binary for Windows, with exfiltrated data secured via hybrid encryption.