EPISODE · Jun 4, 2026 · 32 MIN
Cyber Threat Brief for 2026-06-04
from Cyber Threat Brief
Show Notes - 2026-06-04 Stories Covered: - June 4, 2026 - CISA Adds Three Actively Exploited Vulnerabilities to KEV Catalog (https://www.cisa.gov/news-events/alerts/2026/06/03/cisa-adds-one-known-exploited-vulnerability-catalog) - Acer Wave 7 Routers Have Max-Severity Zero-Days Exposing Credentials (https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/) - Microsoft 365 Android Apps Leaked OAuth Tokens via Debug Flag (https://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html) - Attackers Build Automated EDR Evasion Labs Using AI (https://www.darkreading.com/endpoint-security/attackers-automate-edr-evasion-testing) - CISA Warns of Cyberattacks Targeting Fuel Tank Monitoring Systems (https://www.bleepingcomputer.com/news/security/cisa-warns-of-cyberattacks-targeting-fuel-tank-monitoring-systems/) - HTTP/2 Bomb DoS Attack Crashes Web Servers in Seconds (https://www.bleepingcomputer.com/news/security/new-http-2-bomb-dos-attack-crashes-web-servers-in-under-a-minute/) - Fake Sites Mimicking Open-Source Tools Deliver Malware via Traffic Distribution System (https://research.checkpoint.com/2026/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystem/) - Stock Exchange Executive's Outlook Mailbox Compromised for Five Months (https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html) - TA4922 Chinese Cybercrime Group Expands to Europe with Atlas RAT (https://www.bleepingcomputer.com/news/security/chinese-hackers-use-new-atlas-rat-malware-in-european-cyberattacks/) - DesckVB RAT Campaign Abuses Google DoubleClick for Evasion (https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html) - U.S. Sanctions Nobitex Crypto Exchange Used by Iranian Ransomware Actors (https://www.bleepingcomputer.com/news/security/the-us-sanctions-nobitex-crypto-exchange-used-by-ransomware/) - Active Directory Description Fields Stored Passwords in Plaintext (https://www.theregister.com/security/2026/06/04/all-the-passwords-were-stored-in-active-directory-description-fields/5250820) - Unpatched Windows Search URI Vulnerability Leaks NTLMv2 Hashes (https://thehackernews.com/2026/06/unpatched-windows-search-uri.html) - One-Click GitHub.dev Attack Steals Full OAuth Tokens (https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html) - Autonomous AI Tool Finds 2-Year-Old Redis RCE (CVE-2026-23479) (https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html) - Google Gemini Prompt Injection via Android Notifications (https://www.darkreading.com/application-security/malicious-notifications-could-trick-google-gemini-users) - Open-Source AI Models Used to Build Self-Spreading Worms (https://www.theregister.com/research/2026/06/04/free-ai-model-powers-self-spreading-worm-in-enterprise-test-network/5250918) - Cyber Insurance Rates Drop but Exclusions Widen (https://www.darkreading.com/cyber-risk/cyber-insurance-rates-drop-exclusions-widen) - Police Dismantle 9 Crime Groups in Illegal Streaming Crackdown (https://www.bleepingcomputer.com/news/security/police-dismantles-9-crime-groups-in-illegal-streaming-crackdown/) CVEs Referenced: CVE-2022-0492, CVE-2023-35636, CVE-2025-48595, CVE-2026-23479, CVE-2026-33829, CVE-2026-41100, CVE-2026-41101, CVE-2026-41102, CVE-2026-42832, CVE-2026-45247, CVE-2026-49200, CVE-2026-49201, CVE-2026-49975 Indicators of Compromise: IPs: 10.0.1.100 Full brief: https://carolinacleartech.com/brief/2026-06-04/
Embed this episode
What this episode covers
Show Notes - 2026-06-04 Stories Covered: - June 4, 2026 - CISA Adds Three Actively Exploited Vulnerabilities to KEV Catalog (https://www.cisa.gov/news-events/alerts/2026/06/03/cisa-adds-one-known-exploited-vulnerability-catalog) - Acer Wave 7 Routers Have Max-Severity Zero-Days Exposing Credentials
NOW PLAYING
Cyber Threat Brief for 2026-06-04
No transcript for this episode yet
Similar Episodes
No similar episodes found.