2026-06-03: CISA adds Oracle WebLogic CVE-2024-21182 to KEV catalog after active exploitation with federal episode artwork

EPISODE · Jun 3, 2026 · 14 MIN

2026-06-03: CISA adds Oracle WebLogic CVE-2024-21182 to KEV catalog after active exploitation with federal

from Cyber Threat Brief

Show Notes - 2026-06-03 Stories Covered: - June 3, 2026 - Today: - Oracle WebLogic CVE-2024-21182 Actively Exploited (CVE-2024-21182) (https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-weblogic-flaw/) - Google Patches Exploited Android Zero-Day (CVE-2025-48595) (https://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/) - Linux Kernel Privilege Escalation Added to KEV (CVE-2022-0492) (https://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalog) - Unpatched NTLM Coercion in Windows Search URI Handler (No CVE) (https://www.huntress.com/blog/unpatched-ntlm-coercion-windows-search-uri-handler) - Microsoft Backtracks on Zero-Day Researcher Legal Threats (https://www.securityweek.com/microsoft-tries-to-calm-legal-threat-fears-after-zero-day-disclosure-backlash/) - VS Code Zero-Day Allows GitHub Token Theft via Link Click (https://www.bleepingcomputer.com/news/security/vs-code-zero-day-lets-hackers-steal-github-tokens-in-one-click/) - AI-Built Ransomware Toolkit Automates EDR Evasion (https://www.bleepingcomputer.com/news/security/ai-built-ransomware-toolkit-automates-edr-evasion-ad-discovery/) - DriveSurge Campaign Hijacks Thousands of Sites for Malware Delivery (https://www.darkreading.com/cyberattacks-data-breaches/drivesurge-hijacks-thousands-sites-clickfix-fakeupdate-attacks) - Exchange Online Outage Causes Email Delays and Failures (https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-causes-email-delays-failures/) - Gamaredon Exploits WinRAR to Deliver Malware Against Ukraine (https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html) - WordPress Kirki Plugin Privilege Escalation Exploited (CVE-2026-8206) (https://www.bleepingcomputer.com/news/security/critical-kirki-flaw-exploited-to-hijack-wordpress-admin-accounts/) - Microsoft Office Vulnerability (CVE-2026-21509) Used by APT28 (https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html) CVEs Referenced: CVE-2022-0492, CVE-2024-21182, CVE-2025-48595, CVE-2025-8088, CVE-2026-21509, CVE-2026-33825, CVE-2026-33829, CVE-2026-41091, CVE-2026-45498, CVE-2026-8206 Indicators of Compromise: IPs: 12.2.1.4, 14.1.1.0 Full brief: https://carolinacleartech.com/brief/2026-06-03/

Episode metadata supplied by the publisher feed · Published Jun 3, 2026

Embed this episode

Show Notes - 2026-06-03 Stories Covered: - June 3, 2026 - Today: - Oracle WebLogic CVE-2024-21182 Actively Exploited (CVE-2024-21182) (https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-weblogic-flaw/) - Google Patches Exploited Android Zero-Day (CVE-

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

2026-06-03: CISA adds Oracle WebLogic CVE-2024-21182 to KEV catalog after active exploitation with federal

0:00 14:58

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Cyber Threat Brief?

This episode is 14 minutes long.

When was this Cyber Threat Brief episode published?

This episode was published on June 3, 2026.

Can I download this Cyber Threat Brief episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!