EPISODE · Jun 3, 2026 · 14 MIN
2026-06-03: CISA adds Oracle WebLogic CVE-2024-21182 to KEV catalog after active exploitation with federal
from Cyber Threat Brief
Show Notes - 2026-06-03 Stories Covered: - June 3, 2026 - Today: - Oracle WebLogic CVE-2024-21182 Actively Exploited (CVE-2024-21182) (https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-weblogic-flaw/) - Google Patches Exploited Android Zero-Day (CVE-2025-48595) (https://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/) - Linux Kernel Privilege Escalation Added to KEV (CVE-2022-0492) (https://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalog) - Unpatched NTLM Coercion in Windows Search URI Handler (No CVE) (https://www.huntress.com/blog/unpatched-ntlm-coercion-windows-search-uri-handler) - Microsoft Backtracks on Zero-Day Researcher Legal Threats (https://www.securityweek.com/microsoft-tries-to-calm-legal-threat-fears-after-zero-day-disclosure-backlash/) - VS Code Zero-Day Allows GitHub Token Theft via Link Click (https://www.bleepingcomputer.com/news/security/vs-code-zero-day-lets-hackers-steal-github-tokens-in-one-click/) - AI-Built Ransomware Toolkit Automates EDR Evasion (https://www.bleepingcomputer.com/news/security/ai-built-ransomware-toolkit-automates-edr-evasion-ad-discovery/) - DriveSurge Campaign Hijacks Thousands of Sites for Malware Delivery (https://www.darkreading.com/cyberattacks-data-breaches/drivesurge-hijacks-thousands-sites-clickfix-fakeupdate-attacks) - Exchange Online Outage Causes Email Delays and Failures (https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-causes-email-delays-failures/) - Gamaredon Exploits WinRAR to Deliver Malware Against Ukraine (https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html) - WordPress Kirki Plugin Privilege Escalation Exploited (CVE-2026-8206) (https://www.bleepingcomputer.com/news/security/critical-kirki-flaw-exploited-to-hijack-wordpress-admin-accounts/) - Microsoft Office Vulnerability (CVE-2026-21509) Used by APT28 (https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html) CVEs Referenced: CVE-2022-0492, CVE-2024-21182, CVE-2025-48595, CVE-2025-8088, CVE-2026-21509, CVE-2026-33825, CVE-2026-33829, CVE-2026-41091, CVE-2026-45498, CVE-2026-8206 Indicators of Compromise: IPs: 12.2.1.4, 14.1.1.0 Full brief: https://carolinacleartech.com/brief/2026-06-03/
Embed this episode
What this episode covers
Show Notes - 2026-06-03 Stories Covered: - June 3, 2026 - Today: - Oracle WebLogic CVE-2024-21182 Actively Exploited (CVE-2024-21182) (https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-weblogic-flaw/) - Google Patches Exploited Android Zero-Day (CVE-
NOW PLAYING
2026-06-03: CISA adds Oracle WebLogic CVE-2024-21182 to KEV catalog after active exploitation with federal
No transcript for this episode yet
Similar Episodes
No similar episodes found.