2026-06-06: SolarWinds Serv-U and Cisco SD-WAN vulnerabilities are being exploited in the wild with no patch episode artwork

EPISODE · Jun 6, 2026 · 33 MIN

2026-06-06: SolarWinds Serv-U and Cisco SD-WAN vulnerabilities are being exploited in the wild with no patch

from Cyber Threat Brief

Show Notes - 2026-06-06 Stories Covered: - Today: - SolarWinds Serv-U CVE-2026-28318 Denial-of-Service Vulnerability (CISA KEV) (https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-solarwinds-serv-u-flaw-to-crash-servers/) - Cisco Catalyst SD-WAN Manager CVE-2026-20245 Actively Exploited (No Patch Available) (https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html) - Palo Alto PAN-OS CVE-2026-0257 GlobalProtect Authentication Bypass (https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/) - UNC3753 (Luna Moth, Chatty Spider) Vishing Campaign Targets US Law Firms (https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/) - Over 900 US Automatic Tank Gauge Systems Exposed to Attacks (https://www.bleepingcomputer.com/news/security/over-900-us-gas-station-tank-gauge-systems-exposed-to-attacks/) - IronWorm and Miasma Worm Hit npm Supply Chain (https://thehackernews.com/2026/06/ironworm-and-new-miasma-worm-variant.html) - Smart TV Apps Turn Devices Into Web-Scraping Proxies for AI (https://thehackernews.com/2026/06/free-apps-are-quietly-turning-smart-tvs.html) - Microsoft Claude Code GitHub Action Exposes CI/CD Secrets (https://www.microsoft.com/en-us/security/blog/2026/06/05/securing-ci-cd-in-agentic-world-claude-code-github-action-case/) - Chinese APT UNC5221 Deploys New Malware (Plenet, AgentPSD) for Persistent Access (https://www.bleepingcomputer.com/news/security/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks/) - OP-512 Threat Cluster Targets Microsoft IIS Servers with Custom Web Shell Framework (https://thehackernews.com/2026/06/new-threat-cluster-op-512-targets.html) - Polyfill Service Reactivation Causes Login Prompts on Major Websites (https://www.bleepingcomputer.com/news/security/suspicious-polyfill-login-prompts-pop-up-on-toshiba-muji-websites/) - 2026 Verizon DBIR Highlights Browser-Based Attacks and Shadow AI (https://www.bleepingcomputer.com/news/security/what-2026-dbir-confirms-attacks-are-living-in-the-browser/) - Vulnerability Disclosure Dispute Between Microsoft and Nightmare Eclipse Researcher (https://cyberscoop.com/microsoft-coordinated-vulnerability-disclosure-debacle/) - AI Agent Discovers 21 Zero-Days in FFmpeg (https://thehackernews.com/2026/06/ai-agent-uncovers-21-zero-days-in.html) - Chrome 149 Patches Record 429 Vulnerabilities (https://thehackernews.com/2026/06/ai-agent-uncovers-21-zero-days-in.html) - Sound Blaster Katana V2X Speaker Remote Code Execution via Bluetooth (https://arstechnica.com/security/2026/06/highly-reviewed-speaker-can-be-hacked-over-the-air-to-infect-connected-devices/) CVEs Referenced: CVE-2021-35211, CVE-2022-20775, CVE-2024-28995, CVE-2026-0257, CVE-2026-10881, CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20133, CVE-2026-20182, CVE-2026-20245, CVE-2026-28318, CVE-2026-39210, CVE-2026-39218 Indicators of Compromise: Domains: lhlsjcb[.]com., polyfill[.]io IPs: 23.128.228.6, 104.207.144.154, 146.19.216.119, 146.19.216.120, 146.19.216.125, 179.43.172.213, 185.195.232.139, 198.12.106.60, 202.144.192.47 Full brief: https://carolinacleartech.com/brief/2026-06-06/

Episode metadata supplied by the publisher feed · Published Jun 6, 2026

Embed this episode

Show Notes - 2026-06-06 Stories Covered: - Today: - SolarWinds Serv-U CVE-2026-28318 Denial-of-Service Vulnerability (CISA KEV) (https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-solarwinds-serv-u-flaw-to-crash-servers/) - Cisco Catalyst SD-WAN Manager CVE-2026-20245 Actively

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

2026-06-06: SolarWinds Serv-U and Cisco SD-WAN vulnerabilities are being exploited in the wild with no patch

0:00 33:21

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Cyber Threat Brief?

This episode is 33 minutes long.

When was this Cyber Threat Brief episode published?

This episode was published on June 6, 2026.

Can I download this Cyber Threat Brief episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!