EPISODE · Jun 2, 2026 · 22 MIN
2026-06-02: Critical Alerts
from Cyber Threat Brief
Show Notes - 2026-06-02 Stories Covered: - CVE-2026-21182: Oracle WebLogic Server Added to CISA KEV (https://www.cisa.gov/news-events/alerts/2026/06/01/cisa-adds-one-known-exploited-vulnerability-catalog) - CVE-2026-41089: Windows Netlogon RCE Under Active Exploitation (https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/) - CVE-2026-0257: Palo Alto Networks GlobalProtect Authentication Bypass Exploited (https://www.securityweek.com/recent-palo-alto-networks-vulnerability-exploited-for-weeks/) - Gogs Remote Code Execution Zero-Day (No CVE Yet) (https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html) - Red Hat npm Packages Compromised in Supply Chain Attack (https://www.bleepingcomputer.com/news/security/red-hat-npm-packages-compromised-to-steal-developer-credentials/) - DriveSurge Campaign Hijacks Thousands of Sites for Malware Distribution (https://www.bleepingcomputer.com/news/security/hackers-hijack-thousands-of-sites-for-clickfix-and-fakeupdate-attacks/) - codexui-android npm Package Steals OpenAI Codex Tokens (https://thehackernews.com/2026/06/openai-codex-authentication-tokens.html) - Meta AI Support Bot Exploited for Instagram Account Takeover (https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/) - WordPress Malware Hides C2 Data in Steam Profile Comments (https://www.bleepingcomputer.com/news/security/wordpress-malware-campaign-hides-payloads-in-steam-profiles/) - CVE-2026-45498, CVE-2026-33825, CVE-2026-41091: Additional Windows Zero-Days Under Exploitation (https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/) - Microsoft Outages Affecting MFA Setup and Office Apps (https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-outage-affecting-mfa-setup-mysignin-service/) - KB5089549 Windows 11 Security Update Installation Issues Resolved (https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-kb5089549-windows-security-update-install-issues/) - CVE-2026-26980: Ghost CMS SQL Injection Under Active Exploitation (https://research.checkpoint.com/2026/1st-june-threat-intelligence-report/) - CVE-2026-8732: WP Maps Pro WordPress Plugin Exploited for Site Takeover (https://www.securityweek.com/wp-maps-pro-vulnerability-exploited-to-take-over-wordpress-sites/) - Dashlane Brute-Force Attack Results in Limited Vault Downloads (https://www.bleepingcomputer.com/news/security/dashlane-password-manager-users-locked-out-by-brute-force-attacks/) - SVG Files Used in Phishing Campaigns (https://isc.sans.edu/diary/rss/33040) - GlassWorm C2 Infrastructure Taken Down (https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html) - Carnival Corporation, Charter Communications, Lithuania Data Breaches (https://research.checkpoint.com/2026/1st-june-threat-intelligence-report/) - Spain Arrests Doxer Targeting Government Employees (https://www.bleepingcomputer.com/news/security/spain-arrests-doxer-leaking-sensitive-data-of-govt-employees/) - Check Point Security Gateways: CVE-2026-48131, CVE-2026-48132 (https://research.checkpoint.com/2026/1st-june-threat-intelligence-report/) - China-Aligned Threat Activity Targeting Czech Republic, Taiwan, India (https://thehackernews.com/2026/06/china-aligned-groups-ramp-up-attacks.html) - Pakistan-Linked SideCopy Targets Afghanistan with Xeno RAT (https://thehackernews.com/2026/06/pakistan-linked-sidecopy-targets.html) CVEs Referenced: CVE-2026-0257, CVE-2026-21182, CVE-2026-26980, CVE-2026-33825, CVE-2026-41089, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-48131, CVE-2026-48132, CVE-2026-8732 Indicators of Compromise: IPs: 164.92.88.210 Full brief: https://carolinacleartech.com/brief/2026-06-02/
Embed this episode
What this episode covers
Show Notes - 2026-06-02 Stories Covered: - CVE-2026-21182: Oracle WebLogic Server Added to CISA KEV (https://www.cisa.gov/news-events/alerts/2026/06/01/cisa-adds-one-known-exploited-vulnerability-catalog) - CVE-2026-41089: Windows Netlogon RCE Under Active Exploitation (https://www.bleepingcomputer
NOW PLAYING
2026-06-02: Critical Alerts
No transcript for this episode yet
Similar Episodes
No similar episodes found.