EPISODE · Jun 8, 2026 · 13 MIN
2026-06-08: SolarWinds Serv-U exploit is live in the wild with CISA adding CVE-2026-28318 to the KEV catalog
from Cyber Threat Brief
Show Notes - 2026-06-08 Stories Covered: - Date: - Today: - SolarWinds Serv-U Vulnerability Exploited in the Wild (CVE-2026-28318) (https://www.securityweek.com/solarwinds-patches-exploited-serv-u-vulnerability/) - UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign (https://thehackernews.com/2026/06/unc3753-used-vishing-and-physical.html) - Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse (https://www.securityweek.com/meta-says-20000-instagram-accounts-hacked-via-ai-tool-abuse/) - UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency (https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal) - C0XMO Botnet Spreads via DD-WRT Router Flaw, Kills Rival Malware (https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/) - RubyGems Adds Dependency Cooldowns to Counter Supply Chain Attacks (https://news.risky.biz/risky-bulletin-rubygems-adds-dependency-cooldowns-to-counter-supply-chain-attacks/) - VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks (https://thehackernews.com/2026/06/vs-code-adds-2-hour-extension-auto.html) - OpenAI Rolling Out ChatGPT Account Security Controls (https://www.securityweek.com/openai-rolling-out-chatgpt-account-security-controls/) CVEs Referenced: CVE-2021-27137, CVE-2026-28318 Indicators of Compromise: Domains: privnote[.]com, -itdesk[.]com, -it[.]com, -helpdesk[.]com. Full brief: https://carolinacleartech.com/brief/2026-06-08/
Embed this episode
What this episode covers
Show Notes - 2026-06-08 Stories Covered: - Date: - Today: - SolarWinds Serv-U Vulnerability Exploited in the Wild (CVE-2026-28318) (https://www.securityweek.com/solarwinds-patches-exploited-serv-u-vulnerability/) - UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign (
NOW PLAYING
2026-06-08: SolarWinds Serv-U exploit is live in the wild with CISA adding CVE-2026-28318 to the KEV catalog
No transcript for this episode yet
Similar Episodes
No similar episodes found.