PODCAST · technology
Cyber Threat Brief
by Carolina Clear Tech, LLC
Your daily cybersecurity briefing. Vulnerabilities, ransomware, threat actors, and patches that matter, explained for IT professionals and business leaders protecting small and mid-sized organizations. From Carolina Clear Tech.
-
0
2026-06-18: FortiBleed exposes 73,000 Fortinet VPN credentials to a Russian-speaking threat group targeting
Show Notes - 2026-06-18 Stories Covered: - June 18, 2026 - Today: - Joomla Content Editor Plugin Zero-Day (CVE-2026-48907) (https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-max-severity-joomla-plugin-flaw-by-friday/) - FortiBleed: 73,000 Fortinet VPN Credentials Exposed (https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/) - Fortinet FortiSandbox Vulnerabilities Under Active Exploitation (https://cyberscoop.com/fortinet-fortisandbox-vulnerabilities-exploits/) - Microsoft Defender Zero-Day RoguePlanet (CVE-2026-50656) (https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html) - INC Ransomware Reaches 800+ Victims Through Basic Tactics (https://www.darkreading.com/cyberattacks-data-breaches/inc-ransomware-thrives-by-mastering-the-basics) - DragonForce Ransomware Deploys Custom Backdoor Using Microsoft Teams Infrastructure (https://www.securityweek.com/microsoft-teams-relay-servers-abused-in-dragonforce-ransomware-attack/) - EdTech Sector Faces Escalating Ransomware and Data Breach Activity (https://databreaches.net/2026/06/17/cybercriminals-are-targeting-edtech-data-breaches-and-ransomware-attacks-on-the-rise/?pk_campaign=feed&pk_kwd=cybercriminals-are-targeting-edtech-data-breaches-and-ransomware-attacks-on-the-rise) - Mastra npm Supply Chain Attack Poisons 140+ Packages (https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/) - Account Takeover Attacks Rising Through Session Hijacking and MFA Bypass (https://www.bleepingcomputer.com/news/security/why-account-takeovers-are-rising-and-how-to-stop-them/) - CASB Blind Spot: QUIC Protocol Bypasses Web Traffic Inspection (https://isc.sans.edu/diary/rss/33084) - Crypto Clipper Malware Uses Tor and Worm-Like Propagation (https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/) - Office Apps Experiencing Launch Issues After June Updates (https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-office-apps-launch-issues-after-june-updates/) - Interpol: Cyber Offenses Account for One-Third of Crime in Asia-Pacific (https://www.theregister.com/cyber-crime/2026/06/18/cyber-offenses-now-account-for-around-a-third-of-all-crime-across-asia-and-south-pacific/5257716) - Junior Hacker Uses Tailscale and OpenSSH for Backup Persistence (https://thehackernews.com/2026/06/junior-hacker-used-tailscale-and.html) - CVE-2026-48854: Elixir gRPC Unbounded Request Body Memory Exhaustion (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48854) - Coordinated SSH Brute Force Attacks Over Three Months (https://isc.sans.edu/diary/rss/33086) CVEs Referenced: CVE-2023-3519, CVE-2023-48788, CVE-2024-57727, CVE-2025-5777, CVE-2026-25089, CVE-2026-33825, CVE-2026-39808, CVE-2026-39813, CVE-2026-41091, CVE-2026-45498, CVE-2026-48854, CVE-2026-48907, CVE-2026-50656 Indicators of Compromise: IPs: 2.9.99.6 Full brief: https://carolinacleartech.com/brief/2026-06-18/
-
-1
2026-06-17: CISA gives federal agencies until tomorrow to patch an actively exploited cPanel plugin
Show Notes - 2026-06-17 Stories Covered: - Today: - CISA Orders LiteSpeed cPanel Patch by June 18 (CVE-2026-54420) (https://www.bleepingcomputer.com/news/security/cisa-warns-of-another-actively-exploited-cpanel-plugin-flaw/) - Microsoft Working on RoguePlanet Defender Zero-Day Patch (CVE-2026-50656) (https://www.bleepingcomputer.com/news/microsoft/microsoft-working-on-defender-patch-for-rogueplanet-zero-day/) - Joomla JCE Plugin Flaw Under Active Exploitation (CVE-2026-48907) (https://thehackernews.com/2026/06/cisa-warns-of-actively-exploited-joomla.html) - Three Fortinet FortiSandbox Flaws Under Active Exploitation (https://www.securityweek.com/3-recently-patched-fortinet-fortisandbox-vulnerabilities-in-hacker-crosshairs/) - DragonForce Ransomware Abuses Microsoft Teams TURN Relays for Command-and-Control (https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/) - Kodak Confirms Data Breach, ShinyHunters Claims 2.2 Million Records (https://www.bleepingcomputer.com/news/security/kodak-confirms-data-breach-claimed-by-shinyhunters-extortion-gang/) - Lorem Ipsum Malware Pivots to ClickFix Delivery, Likely Linked to Vice Society (https://www.darkreading.com/cyberattacks-data-breaches/lorem-ipsum-malware-clickfix-delivery) - Novo Nordisk Hit by Two Separate Threat Actors Demanding $50M and $25M (https://databreaches.net/2026/06/16/one-threat-actor-demanded-50-million-from-novo-nordisk-another-one-demanded-25-million-neither-got-paid/?pk_campaign=feed&pk_kwd=one-threat-actor-demanded-50-million-from-novo-nordisk-another-one-demanded-25-million-neither-got-paid) - 144 Mastra npm Packages Compromised via Hijacked Contributor Account (https://thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html) - 15 Malicious JetBrains Plugins Steal AI API Keys from 70,000 Developers (https://www.bleepingcomputer.com/news/security/malicious-jetbrains-marketplace-plugins-steal-ai-api-keys-from-developers/) - Steam Workshop Abused to Spread Malware via Wallpaper Engine (https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/) - 30,000 Compromised Fortinet Firewalls Expose Corporate Networks (FortiBleed Campaign) (https://www.securityweek.com/3-recently-patched-fortinet-fortisandbox-vulnerabilities-in-hacker-crosshairs/) - ClickFix Campaigns Expand with BabaDeda, Lorem Ipsum, and Potemkin Loaders (https://thehackernews.com/2026/06/clickfix-campaigns-expand-malware.html) - GhostTree Attack Abuses Recursive Windows Junctions to Hide Malware from EDR (https://www.bleepingcomputer.com/news/security/ghosttree-attack-abused-recursive-windows-junctions-to-hide-malware/) - Google Vertex AI SDK Flaw Allowed Cross-Tenant Model Hijacking (Pickle in the Middle) (https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/) - China Arrests 67 Suspects Linked to Silver Fox Cybercrime Group (https://news.risky.biz/risky-bulletin-china-arrests-members-of-silver-fox-cybercrime-group/) - Chrome Extensions Steal AI Conversations (PromptSnatcher Campaign) (https://thehackernews.com/2026/06/malicious-jetbrains-plugins-steal-ai.html) - China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth (https://thehackernews.com/2026/06/china-linked-sprysocks-backdoor-expands.html) - New Rokarolla Android Malware Targets 217 Banking and Crypto Apps (https://www.bleepingcomputer.com/news/security/new-rokarolla-android-malware-targets-217-banking-crypto-apps/) - FTC Warns of Record $3.5 Billion Losses to Imposter Scams in 2025 (https://www.bleepingcomputer.com/news/security/ftc-warns-of-record-35-billion-losses-to-imposter-scams-in-2025/) - Rockwell Automation FLEX I/O EtherNet/IP Adapters (CVE-2026-0646, CVE-2026-0647) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-05) - Rockwell Automation RSLinx Classic (CVE-2020-1 ...
-
-2
2026-06-16: Cisco patches its eighth SD-WAN zero-day of the year
Show Notes - 2026-06-16 Stories Covered: - June 16, 2026 - Today: - Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262) (https://thehackernews.com/2026/06/cisco-releases-security-updates-for.html) - Google Chrome V8 Zero-Day (CVE-2026-11645) (https://thehackernews.com/2026/06/weekly-recap-chrome-0-day-unifi.html) - Oracle PeopleSoft Zero-Day Exploited by ShinyHunters (CVE-2026-35273) (https://thehackernews.com/2026/06/weekly-recap-chrome-0-day-unifi.html) - LiteSpeed cPanel Plugin Privilege Escalation (CVE-2026-54420) (https://thehackernews.com/2026/06/cisa-flags-litespeed-cpanel-plugin-flaw.html) - Mackay Sugar Ransomware Attack Shuts Down Mills (https://www.securityweek.com/ransomware-attack-shuts-down-mills-of-australias-second-largest-sugar-producer/) - FulcrumSec Leaks Novo Nordisk Data After $25M Demand Goes Unpaid (https://databreaches.net/2026/06/15/scoop-fulcrumsec-leaks-novo-nordisk-data-after-25m-demand-goes-unpaid/) - Conti Ransomware Developer Pleads Guilty (https://www.securityweek.com/ukrainian-man-pleads-guilty-in-us-to-conti-ransomware-charges/) - Microsoft 365 Copilot SearchLeak Vulnerability (CVE-2026-42824) (https://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html) - 1,500+ Arch Linux Packages Compromised With Malware (https://thehackernews.com/2026/06/weekly-recap-chrome-0-day-unifi.html) - FBI Takes Down Outsider PhaaS Enterprise (https://thehackernews.com/2026/06/weekly-recap-chrome-0-day-unifi.html) - ShinyHunters Claims Council of Europe Hack (https://www.bleepingcomputer.com/news/security/council-of-europe-investigates-shinyhunters-data-breach-claims/) - North Korean Hackers Target Developers With Malicious Tools (https://thehackernews.com/2026/06/north-korean-hackers-are-turning.html) - Chinese APT UNC6508 Targets US Medical and Academic Research (https://cloud.google.com/blog/topics/threat-intelligence/prc-targets-us-medical-research/) - Jaguar Land Rover Ordered 30,000 Staff Password Resets After Cyberattack (https://databreaches.net/2026/06/15/jlr-ordered-30000-staff-to-reset-passwords-in-person-after-cyberattack/) - VHDX File Delivers Remcos RAT (https://isc.sans.edu/diary/rss/33080) - Linux-PAM Timing Attack (CVE-2026-54411) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54411) - Microsoft Edge Chromium CVE Batch (https://msrc.microsoft.com/update-guide/) CVEs Referenced: CVE-2026-11640, CVE-2026-11645, CVE-2026-11662, CVE-2026-11668, CVE-2026-11677, CVE-2026-11684, CVE-2026-11685, CVE-2026-11688, CVE-2026-11693, CVE-2026-12010, CVE-2026-12012, CVE-2026-12016, CVE-2026-12019, CVE-2026-20262, CVE-2026-2441, CVE-2026-35273, CVE-2026-3909, CVE-2026-3910, CVE-2026-42824, CVE-2026-5281, CVE-2026-54411, CVE-2026-54420 Indicators of Compromise: IPs: 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1, 26.1.1.2, 5.3.2.0 Full brief: https://carolinacleartech.com/brief/2026-06-16/
-
-3
2026-06-15: Palo Alto GlobalProtect VPN suffers active exploitation with CISA KEV deadline passed
Show Notes - 2026-06-15 Stories Covered: - Today: - Palo Alto PAN-OS GlobalProtect VPN Authentication Bypass (CVE-2026-0257) (https://thehackernews.com/2026/06/palo-alto-warns-of-active-exploitation.html) - Arch Linux Supply Chain Attack Hijacks 1,900+ AUR Packages (https://news.risky.biz/risky-bulletin-arch-linux-supply-chain-attack-spreads-to-1-900-aur-packages/) - FBI Dismantles Chinese Phishing-as-a-Service Platform (Outsider Enterprise) (https://www.bleepingcomputer.com/news/security/fbi-disrupts-massive-ai-powered-phishing-service-using-a-million-urls/) - WordPress Plugin Supply Chain Attack (Awesome Motive) (https://news.risky.biz/risky-bulletin-arch-linux-supply-chain-attack-spreads-to-1-900-aur-packages/) - Maine Attorney General Disables Data Breach Portal Due to Fake Submissions (https://news.risky.biz/risky-bulletin-arch-linux-supply-chain-attack-spreads-to-1-900-aur-packages/) - Sniper Dz Phishing-as-a-Service Platform Targets MENA Region (https://thehackernews.com/2026/06/sniper-dz-scams-target-mena-users-via.html) - Hotel Chain Data Breach (BWH Hotels) (https://databreaches.net/2026/06/14/uk-hotel-guests-issued-urgent-check-alert-as-personal-details-stolen-from-major-chain/?pk_campaign=feed&pk_kwd=uk-hotel-guests-issued-urgent-check-alert-as-personal-details-stolen-from-major-chain) - Novo Nordisk Clinical Trial Patient Data Breach (https://databreaches.net/2026/06/14/novo-nordisk-reports-data-breach-tells-clinical-trial-patients-to-remain-vigilant/?pk_campaign=feed&pk_kwd=novo-nordisk-reports-data-breach-tells-clinical-trial-patients-to-remain-vigilant) - ShinyHunters Lists New Victims (https://news.risky.biz/risky-bulletin-arch-linux-supply-chain-attack-spreads-to-1-900-aur-packages/) - CVE-2026-11526 (Perl GD Library Command Injection) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11526) CVEs Referenced: CVE-2026-0257, CVE-2026-11526 Indicators of Compromise: IPs: 23.128.228.6, 104.207.144.154, 146.19.216.119, 146.19.216.120, 146.19.216.125, 179.43.172.213, 185.195.232.139, 198.12.106.60, 202.144.192.47 Full brief: https://carolinacleartech.com/brief/2026-06-15/
-
-4
2026-06-14: Anthropic disabled its two most advanced AI models after a US government export control order over
Show Notes - 2026-06-14 Stories Covered: - Today: - Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack (https://www.theregister.com/Security/Microsoft-patches-failed-to-fix-on-prem-SharePoint-which-is-now-under-zero-day-attack) - Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication (CVE-2026-20253) (https://thehackernews.com/2026/06/critical-splunk-enterprise-flaw-lets.html) - Chinese hackers hijack auth flow, spy on isolated network for a decade (https://www.bleepingcomputer.com/news/security/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade/) - Ex-school district employee jailed for hacks on former employer (https://www.bleepingcomputer.com/news/security/ex-school-district-employee-jailed-for-hacks-on-former-employer/) - NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks (https://www.securityweek.com/npm-12-will-change-script-execution-behavior-to-prevent-supply-chain-attacks/) - US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos (https://www.bleepingcomputer.com/news/security/us-gov-asks-anthropic-to-ban-foreign-national-access-to-fable-mythos/) - Russians are posing as Signal support to launch phishing attacks (https://www.theregister.com/Security/Russians-are-posing-as-Signal-support-to-launch-phishing-attacks) - Google fires sueball at alleged Chinese phishers over AI-powered fraud ops (https://www.theregister.com/security/Google-fires-sueball-at-alleged-Chinese-phishers-over-AI-powered-fraud-ops) - DEF CON Franklin project enlists hackers to harden critical infrastructure (https://www.theregister.com/Black-Hat-and-DEF-CON/DEF-CON-Franklin-project-enlists-hackers-to-harden-critical-infrastructure) - Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight (https://www.theregister.com/Malware-Month/Ten-years-since-the-first-corp-ransomware-Mikko-Hyppönen-sees-no-end-in-sight) - EQT buys majority share in Swiss cybersecurity biz Acronis (https://www.theregister.com/Security/EQT-buys-majority-share-in-Swiss-cybersecurity-biz-Acronis) - South Korea Hands Coupang a Record-Breaking $409 Million Data Privacy Fine (https://databreaches.net/2026/06/13/south-korea-hands-coupang-a-record-breaking-409-million-data-privacy-fine/) CVEs Referenced: CVE-2026-20253 Full brief: https://carolinacleartech.com/brief/2026-06-14/
-
-5
2026-06-13: ShinyHunters exploited Oracle PeopleSoft zero-day CVE-2026-35273 for two weeks
Show Notes - 2026-06-13 Stories Covered: - Today: - Oracle PeopleSoft Zero-Day Exploited (CVE-2026-35273) (https://www.darkreading.com/vulnerabilities-threats/shinyhunters-oracle-zero-day-higher-ed) - Conti Ransomware Member Pleads Guilty (https://www.bleepingcomputer.com/news/security/ukrainian-national-pleads-guilty-to-role-in-conti-ransomware-operation/) - Global Schools Foundation Ransomware Negotiation Failure (https://databreaches.net/2026/06/12/after-a-massive-hack-global-schools-groups-negotiator-acted-bizarrely-it-didnt-end-well-for-them/?pk_campaign=feed&pk_kwd=after-a-massive-hack-global-schools-groups-negotiator-acted-bizarrely-it-didnt-end-well-for-them) - China-Linked Group Backdoored Linux Login Systems for 9 Years (https://thehackernews.com/2026/06/china-linked-hackers-backdoored-linux.html) - Supply-Chain Attack Early Warning Signs on Dark Web (https://www.bleepingcomputer.com/news/security/early-warning-signs-of-supply-chain-attacks-live-in-the-dark-web/) - Insider Threat: Iowa School IT Worker Sentenced for Sabotage (https://databreaches.net/2026/06/12/former-saydel-schools-it-worker-sentenced-for-iowa-cyber-sabotage/?pk_campaign=feed&pk_kwd=former-saydel-schools-it-worker-sentenced-for-iowa-cyber-sabotage) - Maine Data Breach Portal Disabled After Fake Disclosures (https://www.bleepingcomputer.com/news/security/maine-disables-data-breach-notification-portal-after-fake-disclosures/) - KPMG AI Report Demonstrates AI Hallucinations (https://www.theregister.com/ai-and-ml/2026/06/12/kpmgs-ai-report-turns-into-a-demo-of-ai-hallucinations/5255029) - New macOS Tahoe 26 Forensic Artifact Discovered (https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/) - LabCorp Settles AMCA Breach for $35 Million (https://databreaches.net/2026/06/12/labcorp-reaches-35m-settlement-over-american-medical-collection-agency-breach/?pk_campaign=feed&pk_kwd=labcorp-reaches-35m-settlement-over-american-medical-collection-agency-breach) - DOJ: COVID-19 Relief Fraud Arrests (https://www.justice.gov/usao-nv/pr/coordinated-law-enforcement-actions-results-arrests-seven-men-connection-fraudulent) - phpBB Authentication Bypass (10 Years Old) (https://www.bleepingcomputer.com/news/security/phpbb-forum-fixes-auth-bypass-bug-lurking-for-a-decade/) - Microsoft Security Update Guide CVEs (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-9076) CVEs Referenced: CVE-2023-5678, CVE-2024-20399, CVE-2026-34180, CVE-2026-34181, CVE-2026-34182, CVE-2026-34183, CVE-2026-35273, CVE-2026-42764, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-44705, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447, CVE-2026-47162, CVE-2026-47167, CVE-2026-52859, CVE-2026-52860, CVE-2026-7383, CVE-2026-9076 Full brief: https://carolinacleartech.com/brief/2026-06-13/
-
-6
2026-06-12: CISA gives federal agencies until Sunday to patch an Ivanti Sentry vulnerability already exploited
Show Notes - 2026-06-12 Stories Covered: - June 12, 2026 - Today: - CISA Orders Ivanti Sentry Patching by June 14 (CVE-2026-10520) (https://www.bleepingcomputer.com/news/security/cisa-gives-feds-3-days-to-patch-ivanti-flaw-exploited-in-attacks/) - ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) (https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html) - The Gentlemen Ransomware Claims 478 Victims Since March 2025 (https://thehackernews.com/2026/06/the-gentlemen-ransomware-claims-478.html) - Europol Dismantles AudiA6 Crypto Laundering Service (https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html) - AI-Driven Threats Exposing Limits of MSP Security Stacks (https://www.bleepingcomputer.com/news/security/why-ai-driven-threats-are-exposing-the-limits-of-msp-security-stacks/) - Hackers Exploit Langflow Vulnerability for Remote Code Execution (CVE-2026-5027) (https://www.securityweek.com/hackers-exploit-langflow-vulnerability-for-remote-code-execution/) - LangGraph Flaw Chain Exposes Self-Hosted AI Agents to RCE (https://thehackernews.com/2026/06/langgraph-flaw-chain-exposes-self.html) - AI Agent Supply Chains Lack Integrity Verification (https://unit42.paloaltonetworks.com/ai-agent-supply-chain-risks/) - OpenClaw AI Agent Vulnerable to Hidden Command Injection and Phishing (https://thehackernews.com/2026/06/new-attacks-trick-openclaw-ai-agent.html) - French Government Tchap Messenger Breach Affects 73,000 Employees (https://www.bleepingcomputer.com/news/security/french-govt-says-tchap-breach-affected-over-73-000-accounts/) - GreatXML Exploit Bypasses BitLocker via Recovery Partition XML Files (CVE-2026-45585) (https://thehackernews.com/2026/06/new-greatxml-exploit-bypasses-windows.html) - CISA Issues New Binding Operational Directive 26-04 (https://news.risky.biz/risky-bulletin-in-the-age-of-ai-cisa-changes-federal-patching-rules/) - Alert Fatigue Becoming a Security Threat of Its Own (https://www.securityweek.com/alert-fatigue-is-becoming-a-security-threat-of-its-own/) - OceanLotus Shifts Focus to Domestic Espionage in Vietnam (https://thehackernews.com/2026/06/oceanlotus-hits-vietnam-investors-with.html) - North Korean Famous Chollima Accounts for 47% of Tech Sector Intrusions (https://thehackernews.com/2026/06/threatsday-bulletin-worm-code-leaked-ai.html) - IoT Platform Vulnerabilities Across Multiple Vendors (https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-02) - Siemens Desigo CC Patch Files Flagged as Malware by Security Engines (https://www.securityweek.com/siemens-says-desigo-cc-files-flagged-as-malware-by-security-engines/) CVEs Referenced: CVE-2025-67644, CVE-2026-10520, CVE-2026-10557, CVE-2026-27022, CVE-2026-28277, CVE-2026-28742, CVE-2026-35273, CVE-2026-42947, CVE-2026-45585, CVE-2026-50005, CVE-2026-50101, CVE-2026-50108, CVE-2026-50245, CVE-2026-5027, CVE-2026-7368 Indicators of Compromise: IPs: 176.120.22.24, 3.2.3.5 Full brief: https://carolinacleartech.com/brief/2026-06-12/
-
-7
2026-06-11: A new Windows zero-day exploit bypassing Microsoft Defender was released hours after Patch Tuesday
Show Notes - 2026-06-11 Stories Covered: - Today: - New Windows Zero-Day Exploit 'RoguePlanet' Released (https://www.securityweek.com/new-windows-zero-day-exploit-rogueplanet-released/) - 'GreatXML' Zero-Day Exploit Bypasses BitLocker (https://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/) - Microsoft Patches Exchange Server Zero-Day Exploited in Attacks (CVE-2026-42897) (https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-exchange-server-zero-day-exploited-in-attacks/) - CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog (https://thehackernews.com/2026/06/cisa-adds-cisco-chrome-and-arista-flaws.html) - Path Traversal Flaw in AI Dev Platform Langflow Exploited in Attacks (CVE-2026-5027) (https://www.bleepingcomputer.com/news/security/path-traversal-flaw-in-ai-dev-platform-langflow-exploited-in-attacks/) - Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs (https://thehackernews.com/2026/06/microsoft-patches-record-206-flaws.html) - Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities (https://thehackernews.com/2026/06/ivanti-fortinet-and-sap-release-patches.html) - Who Runs the Ransomware Group 'The Gentlemen?' (https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/) - WA: Chelan County Enters Third Week of Disruptions with No Recovery Timeline (https://databreaches.net/2026/06/10/wa-chelan-county-enters-third-week-of-disruptions-with-no-recovery-timeline/?pk_campaign=feed&pk_kwd=wa-chelan-county-enters-third-week-of-disruptions-with-no-recovery-timeline) - Infostealers Turn Millions of Devices Into Credential Theft Machines (https://www.securityweek.com/infostealers-turn-millions-of-devices-into-credential-theft-machines/) - Deceptive Installers: How Fake Apps Target macOS (https://www.huntress.com/blog/deceptive-installers-macos-infostealers) - GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks (https://thehackernews.com/2026/06/github-to-disable-npm-install-scripts.html) - Microsoft Fixes BitLocker Recovery Bug on Windows Server 2025 (https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bitlocker-recovery-bug-on-windows-server-2025/) - Microsoft: Some Windows PCs Fail to Install Latest Monthly Updates (https://www.bleepingcomputer.com/news/microsoft/microsoft-some-upgraded-windows-pcs-fail-to-install-monthly-updates/) CVEs Referenced: CVE-2026-10520, CVE-2026-10523, CVE-2026-11645, CVE-2026-20245, CVE-2026-22732, CVE-2026-25089, CVE-2026-27671, CVE-2026-33017, CVE-2026-40128, CVE-2026-42897, CVE-2026-44748, CVE-2026-44815, CVE-2026-45586, CVE-2026-45657, CVE-2026-47291, CVE-2026-49160, CVE-2026-5027, CVE-2026-50507, CVE-2026-7473 Full brief: https://carolinacleartech.com/brief/2026-06-11/
-
-8
2026-06-10: Microsoft patches 206 vulnerabilities in the largest Patch Tuesday on record
Show Notes - 2026-06-10 Stories Covered: - Today: - Veeam Backup & Replication RCE (CVE-2026-44963) (https://www.bleepingcomputer.com/news/security/new-veeam-vulnerability-exposes-backup-servers-to-rce-attacks/) - Cisco SD-WAN Zero-Day (CVE-2026-20245) (https://cyberscoop.com/cisco-sdwan-zero-day-vulnerability-exploited-cve202620245/) - Check Point VPN RCE (CVE-2026-50751) (https://databreaches.net/2026/06/09/cisa-gives-feds-3-days-to-patch-check-point-vpn-bug-exploited-as-zero-day/) - Chrome V8 Zero-Day (CVE-2026-11645) (https://thehackernews.com/2026/06/chrome-v8-zero-day-cve-2026-11645.html) - Microsoft June 2026 Patch Tuesday (206 Vulnerabilities) (https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-3-zero-day-200-flaws/) - Microsoft Defender RoguePlanet Zero-Day (https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/) - Microsoft Exchange Ghost-Sender Spoofing (https://www.darkreading.com/vulnerabilities-threats/exchange-flaw-attackers-spoof-email-address) - Windows 10 KB5094127 Extended Security Update (https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5094127-extended-security-update/) - Windows 11 KB5094126 & KB5093998 Updates (https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5094126-and-kb5093998-cumulative-updates-released/) - Microsoft AI Activity Investigation Playbook (https://www.microsoft.com/en-us/security/blog/2026/06/09/reconstructing-ai-activity-investigations/) - WinRAR Exploitation in Ukraine (https://thehackernews.com/2026/06/winrar-flaw-exploited-by-russia-aligned.html) - GitHub/Microsoft Repository Compromise (Miasma/Shai-Hulud) (https://www.bleepingcomputer.com/news/security/github-disables-microsoft-repos-pushing-password-stealing-malware/) - Hades PyPI Attack (37 Malicious Packages) (https://thehackernews.com/2026/06/hades-pypi-attack-19-packages-poisoned.html) - CISA KEV Additions (June 9) (https://www.cisa.gov/news-events/alerts/2026/06/09/cisa-adds-three-known-exploited-vulnerabilities-catalog) - ICS Patch Tuesday (https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-phoenix-contact/) CVEs Referenced: CVE-2025-15467, CVE-2025-40946, CVE-2025-8088, CVE-2026-11645, CVE-2026-20127, CVE-2026-20182, CVE-2026-20245, CVE-2026-2441, CVE-2026-26142, CVE-2026-32193, CVE-2026-3909, CVE-2026-3910, CVE-2026-41108, CVE-2026-41125, CVE-2026-42985, CVE-2026-42987, CVE-2026-44803, CVE-2026-44812, CVE-2026-44815, CVE-2026-44963, CVE-2026-45467, CVE-2026-45469, CVE-2026-45485, CVE-2026-45586, CVE-2026-45602, CVE-2026-45607, CVE-2026-45641, CVE-2026-45648, CVE-2026-45657, CVE-2026-47288, CVE-2026-47291, CVE-2026-47292, CVE-2026-47652, CVE-2026-48574, CVE-2026-49160, CVE-2026-50507, CVE-2026-50508, CVE-2026-50751, CVE-2026-5281, CVE-2026-7473 Full brief: https://carolinacleartech.com/brief/2026-06-10/
-
-9
2026-06-09: Check Point VPN users have three days to patch CVE-2026-50751
Show Notes - 2026-06-09 Stories Covered: - June 9, 2026 - Today: - Check Point VPN Zero-Day Exploited by Qilin Ransomware (CVE-2026-50751) (https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-check-point-flaw-exploited-by-ransomware-gangs/) - Gogs RCE Zero-Day Affects Default Configurations (https://www.bleepingcomputer.com/news/security/gogs-patches-critical-zero-day-enabling-remote-code-execution/) - Google Patches Fifth Chrome Zero-Day of 2026 (CVE-2026-11645) (https://www.bleepingcomputer.com/news/security/google-patches-fifth-chrome-zero-day-bug-exploited-in-attacks-this-year/) - LiteLLM RCE Exploited in the Wild (CVE-2026-42271) (https://thehackernews.com/2026/06/litellm-flaw-cve-2026-42271-exploited.html) - TeamPCP Supply Chain Campaign Continues with Hades PyPI Variant (https://isc.sans.edu/diary/rss/33060) - Silent Ransom Group Uses DNS Fast Flux in Attacks (https://www.securityweek.com/silent-ransom-group-uses-dns-fast-flux-in-attacks/) - Ransomware Closes Illinois High Schools (https://www.theregister.com/cyber-crime/2026/06/08/ransomware-attack-shuts-illinois-high-school-until-wednesday/5252322) - Qilin NHS Breach Tally Grows (https://www.theregister.com/cyber-crime/2026/06/09/qilin-nhs-breach-tally-grows-as-essex-trust-confirms-stolen-records/5252663) - Microsoft Teams Phishing Campaigns Bypass Email Defenses (https://unit42.paloaltonetworks.com/microsoft-teams-phishing/) - AI Brands Used as Social Engineering Lures (https://www.microsoft.com/en-us/security/blog/2026/06/08/ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineering/) - NSO Group Spyware Campaigns Defy Court Injunction (https://www.bleepingcomputer.com/news/security/whatsapp-says-it-disrupted-new-nso-spyware-phishing-attacks/) - Linux Kernel One-Character Flaw Enables Local Root (CVE-2026-23111) (https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html) - Android Framework Privilege Escalation Under Exploitation (CVE-2025-48595) (https://thehackernews.com/2026/06/weekly-recap-instagram-account-hacks.html) - Multiple MSRC CVE Publications (https://msrc.microsoft.com/update-guide/) - Instagram Recovery Tool Bug Exposed 20,225 Accounts (https://databreaches.net/2026/06/08/instagram-recovery-tool-bug-exposed-20225-accounts-to-password-reset-abuse/?pk_campaign=feed&pk_kwd=instagram-recovery-tool-bug-exposed-20225-accounts-to-password-reset-abuse) - Apple Announces AI-Powered Automatic Password Fixer (https://www.bleepingcomputer.com/news/apple/new-apple-feature-automatically-changes-your-compromised-passwords/) CVEs Referenced: CVE-2024-39930, CVE-2024-39932, CVE-2024-39933, CVE-2025-48595, CVE-2025-8110, CVE-2026-10879, CVE-2026-11463, CVE-2026-11645, CVE-2026-23111, CVE-2026-2441, CVE-2026-26194, CVE-2026-35429, CVE-2026-3909, CVE-2026-3910, CVE-2026-40930, CVE-2026-42208, CVE-2026-42271, CVE-2026-45321, CVE-2026-46250, CVE-2026-46272, CVE-2026-48027, CVE-2026-48710, CVE-2026-49975, CVE-2026-50031, CVE-2026-50256, CVE-2026-50260, CVE-2026-50262, CVE-2026-50292, CVE-2026-50751, CVE-2026-50752, CVE-2026-5281 Indicators of Compromise: Domains: ep6pheij[.]com, business-data-leaks[.]com., business-data-leaks[.]com, grupoconstat[.]bitrix24, com[.]br, ikhwancast[.]com, ghazacast[.]com, fr24cast[.]com., fr24cast[.]com Full brief: https://carolinacleartech.com/brief/2026-06-09/
-
-10
2026-06-08: SolarWinds Serv-U exploit is live in the wild with CISA adding CVE-2026-28318 to the KEV catalog
Show Notes - 2026-06-08 Stories Covered: - Date: - Today: - SolarWinds Serv-U Vulnerability Exploited in the Wild (CVE-2026-28318) (https://www.securityweek.com/solarwinds-patches-exploited-serv-u-vulnerability/) - UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign (https://thehackernews.com/2026/06/unc3753-used-vishing-and-physical.html) - Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse (https://www.securityweek.com/meta-says-20000-instagram-accounts-hacked-via-ai-tool-abuse/) - UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency (https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal) - C0XMO Botnet Spreads via DD-WRT Router Flaw, Kills Rival Malware (https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/) - RubyGems Adds Dependency Cooldowns to Counter Supply Chain Attacks (https://news.risky.biz/risky-bulletin-rubygems-adds-dependency-cooldowns-to-counter-supply-chain-attacks/) - VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks (https://thehackernews.com/2026/06/vs-code-adds-2-hour-extension-auto.html) - OpenAI Rolling Out ChatGPT Account Security Controls (https://www.securityweek.com/openai-rolling-out-chatgpt-account-security-controls/) CVEs Referenced: CVE-2021-27137, CVE-2026-28318 Indicators of Compromise: Domains: privnote[.]com, -itdesk[.]com, -it[.]com, -helpdesk[.]com. Full brief: https://carolinacleartech.com/brief/2026-06-08/
-
-11
2026-06-07: WordPress site takeovers are spreading via a critical Everest Forms Pro exploit that creates rogue
Show Notes - 2026-06-07 Stories Covered: - 2026-06-07 - Today: - Cisco SD-WAN Zero-Day Under Active Attack (https://www.theregister.com/personal-tech/2026/06/07/uk-exam-watchdog-frets-over-smart-specs-turning-gcses-into-google-searches/5251365) - Critical Everest Forms Pro Flaw Exploited to Take Over WordPress Sites (CVE-2026-3300) (https://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites/) - Exposed Fuel Tank Gauges Under Attack in the US (https://www.darkreading.com/cyberattacks-data-breaches/exposed-fuel-tank-gauges-attack-us) - Adaptive AI Worms Loom as Next Enterprise Threat (https://www.darkreading.com/cyber-risk/adaptive-agentic-ai-worms-enterprise-cyber-threat) - ChatGPT Lockdown Mode Limits Data Exfiltration Tools (https://thehackernews.com/2026/06/new-chatgpt-lockdown-mode-limits-tools.html) - CVE-2026-3300: Everest Forms Pro Unauthenticated RCE (https://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites/) - CVE-2026-50219: libexpat Use-After-Free Vulnerability (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50219) - CVE-2026-8643: pip Path Traversal in Script Installation (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8643) - CVE-2026-7774: Python tarfile Path Traversal Bypass (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-7774) - CVE-2026-11332: Ansible-core Argument Injection in ansible-galaxy (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11332) - CVE-2026-3276: Python DoS via Quadratic Complexity in unicodedata.normalize() (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-3276) - CVE-2026-43958: RRDtool Stack Buffer Overflow (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43958) - CVE-2026-10722: cilium eBPF Integer Overflow (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-10722) - CVE-2026-37460: FRRouting BGP DoS Vulnerability (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-37460) - CVE-2026-42504: Go mime Package Quadratic Complexity DoS (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42504) - CVE-2026-42507: Go net/textproto Unescaped Input in Errors (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42507) - CVE-2026-27145: Go Inefficient Hostname Parsing in crypto/x509 (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27145) - CVE-2026-8829: Perl HTML::Entities Use-After-Free (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8829) - CVE-2026-5419: GnuTLS Timing Side-Channel in PKCS#7 Padding (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5419) - Opal Security Raises $23 Million for AI-Native Identity Governance (https://www.securityweek.com/opal-security-raises-23-million-for-ai-native-identity-governance/) CVEs Referenced: CVE-2026-10722, CVE-2026-11332, CVE-2026-27145, CVE-2026-3276, CVE-2026-3300, CVE-2026-37460, CVE-2026-42504, CVE-2026-42507, CVE-2026-43958, CVE-2026-50219, CVE-2026-5419, CVE-2026-7774, CVE-2026-8643, CVE-2026-8829 Indicators of Compromise: IPs: 202.56.2.126, 209.146.60.26 Full brief: https://carolinacleartech.com/brief/2026-06-07/
-
-12
2026-06-06: SolarWinds Serv-U and Cisco SD-WAN vulnerabilities are being exploited in the wild with no patch
Show Notes - 2026-06-06 Stories Covered: - Today: - SolarWinds Serv-U CVE-2026-28318 Denial-of-Service Vulnerability (CISA KEV) (https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-solarwinds-serv-u-flaw-to-crash-servers/) - Cisco Catalyst SD-WAN Manager CVE-2026-20245 Actively Exploited (No Patch Available) (https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-manager-cve-2026.html) - Palo Alto PAN-OS CVE-2026-0257 GlobalProtect Authentication Bypass (https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/) - UNC3753 (Luna Moth, Chatty Spider) Vishing Campaign Targets US Law Firms (https://cloud.google.com/blog/topics/threat-intelligence/targeted-campaign-us-law-firms/) - Over 900 US Automatic Tank Gauge Systems Exposed to Attacks (https://www.bleepingcomputer.com/news/security/over-900-us-gas-station-tank-gauge-systems-exposed-to-attacks/) - IronWorm and Miasma Worm Hit npm Supply Chain (https://thehackernews.com/2026/06/ironworm-and-new-miasma-worm-variant.html) - Smart TV Apps Turn Devices Into Web-Scraping Proxies for AI (https://thehackernews.com/2026/06/free-apps-are-quietly-turning-smart-tvs.html) - Microsoft Claude Code GitHub Action Exposes CI/CD Secrets (https://www.microsoft.com/en-us/security/blog/2026/06/05/securing-ci-cd-in-agentic-world-claude-code-github-action-case/) - Chinese APT UNC5221 Deploys New Malware (Plenet, AgentPSD) for Persistent Access (https://www.bleepingcomputer.com/news/security/chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks/) - OP-512 Threat Cluster Targets Microsoft IIS Servers with Custom Web Shell Framework (https://thehackernews.com/2026/06/new-threat-cluster-op-512-targets.html) - Polyfill Service Reactivation Causes Login Prompts on Major Websites (https://www.bleepingcomputer.com/news/security/suspicious-polyfill-login-prompts-pop-up-on-toshiba-muji-websites/) - 2026 Verizon DBIR Highlights Browser-Based Attacks and Shadow AI (https://www.bleepingcomputer.com/news/security/what-2026-dbir-confirms-attacks-are-living-in-the-browser/) - Vulnerability Disclosure Dispute Between Microsoft and Nightmare Eclipse Researcher (https://cyberscoop.com/microsoft-coordinated-vulnerability-disclosure-debacle/) - AI Agent Discovers 21 Zero-Days in FFmpeg (https://thehackernews.com/2026/06/ai-agent-uncovers-21-zero-days-in.html) - Chrome 149 Patches Record 429 Vulnerabilities (https://thehackernews.com/2026/06/ai-agent-uncovers-21-zero-days-in.html) - Sound Blaster Katana V2X Speaker Remote Code Execution via Bluetooth (https://arstechnica.com/security/2026/06/highly-reviewed-speaker-can-be-hacked-over-the-air-to-infect-connected-devices/) CVEs Referenced: CVE-2021-35211, CVE-2022-20775, CVE-2024-28995, CVE-2026-0257, CVE-2026-10881, CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20133, CVE-2026-20182, CVE-2026-20245, CVE-2026-28318, CVE-2026-39210, CVE-2026-39218 Indicators of Compromise: Domains: lhlsjcb[.]com., polyfill[.]io IPs: 23.128.228.6, 104.207.144.154, 146.19.216.119, 146.19.216.120, 146.19.216.125, 179.43.172.213, 185.195.232.139, 198.12.106.60, 202.144.192.47 Full brief: https://carolinacleartech.com/brief/2026-06-06/
-
-13
2026-06-05: Cisco discloses seventh SD-WAN zero-day this year, now actively exploited for root escalation with
Show Notes - 2026-06-05 Stories Covered: - June 5, 2026 - Today: - Cisco SD-WAN Zero-Day Actively Exploited (CVE-2026-20245) (https://www.bleepingcomputer.com/news/security/new-cisco-sd-wan-flaw-exploited-in-zero-day-attacks-to-gain-root/) - Cisco Unified CM Critical SSRF with Public PoC (CVE-2026-20230) (https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-unified-cm-flaw-with-poc-exploit-code/) - Windows 11 Zero-Day (CVE-2026-0257) (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-23-7/) - AI Agents as Insider Threat (https://cyberscoop.com/ai-agent-insider-threat-cybersecurity-dtex/) - Claude Code GitHub Action Repository Takeover (https://thehackernews.com/2026/06/claude-code-github-action-flaw-let-one.html) - Microsoft Agentic AI Failure Modes v2.0 (https://www.microsoft.com/en-us/security/blog/2026/06/04/updating-taxonomy-failure-modes-agentic-ai-systems-year-red-teaming-taught-us/) - UN World Food Programme Gaza Breach (600,000 Households) (https://www.bleepingcomputer.com/news/security/un-world-food-programme-breach-affects-600-000-gaza-households/) - DentaQuest Breach (2.6 Million Accounts) (https://www.bleepingcomputer.com/news/security/dentaquest-data-breach-exposed-info-of-26-million-accounts/) - China-Linked TA4922 Expands to Europe (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-23-7/) - IronWorm npm Supply Chain Attack (36 Packages) (https://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/) - Russian Mobile Spyware Operation (https://thehackernews.com/2026/06/threatsday-bulletin-ai-agents-gone.html) - Microsoft M365 Copilot RCE (CVE-2026-45497) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45497) - Windows Driver Update Issue (https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-unexpected-windows-driver-updates-on-caching-issue/) - Chrome 149 Patches Record 429 Vulnerabilities (https://www.securityweek.com/chrome-149-patches-429-vulnerabilities/) - Hola Browser Supply Chain Compromise (https://www.bleepingcomputer.com/news/security/hola-browser-for-windows-compromised-to-deliver-cryptominer/) - Everest Forms Pro WordPress RCE Actively Exploited (CVE-2026-3300) (https://thehackernews.com/2026/06/hackers-exploit-critical-everest-forms.html) - Magecart Campaign Abuses Stripe API (https://www.bleepingcomputer.com/news/security/credit-card-theft-campaign-abuses-stripe-to-host-stolen-payment-info/) - VIP Keylogger via JavaScript Loaders (https://isc.sans.edu/diary/rss/33054) - FlutterShell macOS Malvertising (https://thehackernews.com/2026/06/fluttershell-backdoor-spreads-to-macos.html) - FIFA World Cup 2026 Scams (https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html) - Hitachi Energy ICS Vulnerabilities (https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-04) - B&R PPT30 OPC-UA DoS (CVE-2025-11482) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-03) CVEs Referenced: CVE-2024-8176, CVE-2025-11482, CVE-2025-20309, CVE-2025-59375, CVE-2026-0257, CVE-2026-10881, CVE-2026-10882, CVE-2026-10883, CVE-2026-20045, CVE-2026-20127, CVE-2026-20182, CVE-2026-20230, CVE-2026-20245, CVE-2026-25253, CVE-2026-3300, CVE-2026-45497, CVE-2026-7310 Indicators of Compromise: IPs: 202.56.2.126, 209.146.60.26, 15.235.166.18, 185.78.165.153 Full brief: https://carolinacleartech.com/brief/2026-06-05/
-
-14
Cyber Threat Brief for 2026-06-04
Show Notes - 2026-06-04 Stories Covered: - June 4, 2026 - CISA Adds Three Actively Exploited Vulnerabilities to KEV Catalog (https://www.cisa.gov/news-events/alerts/2026/06/03/cisa-adds-one-known-exploited-vulnerability-catalog) - Acer Wave 7 Routers Have Max-Severity Zero-Days Exposing Credentials (https://www.bleepingcomputer.com/news/security/acer-warns-of-max-severity-zero-days-affecting-wave-7-routers/) - Microsoft 365 Android Apps Leaked OAuth Tokens via Debug Flag (https://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html) - Attackers Build Automated EDR Evasion Labs Using AI (https://www.darkreading.com/endpoint-security/attackers-automate-edr-evasion-testing) - CISA Warns of Cyberattacks Targeting Fuel Tank Monitoring Systems (https://www.bleepingcomputer.com/news/security/cisa-warns-of-cyberattacks-targeting-fuel-tank-monitoring-systems/) - HTTP/2 Bomb DoS Attack Crashes Web Servers in Seconds (https://www.bleepingcomputer.com/news/security/new-http-2-bomb-dos-attack-crashes-web-servers-in-under-a-minute/) - Fake Sites Mimicking Open-Source Tools Deliver Malware via Traffic Distribution System (https://research.checkpoint.com/2026/impersonation-click-hijacking-and-tds-inside-a-malware-distribution-ecosystem/) - Stock Exchange Executive's Outlook Mailbox Compromised for Five Months (https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html) - TA4922 Chinese Cybercrime Group Expands to Europe with Atlas RAT (https://www.bleepingcomputer.com/news/security/chinese-hackers-use-new-atlas-rat-malware-in-european-cyberattacks/) - DesckVB RAT Campaign Abuses Google DoubleClick for Evasion (https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html) - U.S. Sanctions Nobitex Crypto Exchange Used by Iranian Ransomware Actors (https://www.bleepingcomputer.com/news/security/the-us-sanctions-nobitex-crypto-exchange-used-by-ransomware/) - Active Directory Description Fields Stored Passwords in Plaintext (https://www.theregister.com/security/2026/06/04/all-the-passwords-were-stored-in-active-directory-description-fields/5250820) - Unpatched Windows Search URI Vulnerability Leaks NTLMv2 Hashes (https://thehackernews.com/2026/06/unpatched-windows-search-uri.html) - One-Click GitHub.dev Attack Steals Full OAuth Tokens (https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html) - Autonomous AI Tool Finds 2-Year-Old Redis RCE (CVE-2026-23479) (https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html) - Google Gemini Prompt Injection via Android Notifications (https://www.darkreading.com/application-security/malicious-notifications-could-trick-google-gemini-users) - Open-Source AI Models Used to Build Self-Spreading Worms (https://www.theregister.com/research/2026/06/04/free-ai-model-powers-self-spreading-worm-in-enterprise-test-network/5250918) - Cyber Insurance Rates Drop but Exclusions Widen (https://www.darkreading.com/cyber-risk/cyber-insurance-rates-drop-exclusions-widen) - Police Dismantle 9 Crime Groups in Illegal Streaming Crackdown (https://www.bleepingcomputer.com/news/security/police-dismantles-9-crime-groups-in-illegal-streaming-crackdown/) CVEs Referenced: CVE-2022-0492, CVE-2023-35636, CVE-2025-48595, CVE-2026-23479, CVE-2026-33829, CVE-2026-41100, CVE-2026-41101, CVE-2026-41102, CVE-2026-42832, CVE-2026-45247, CVE-2026-49200, CVE-2026-49201, CVE-2026-49975 Indicators of Compromise: IPs: 10.0.1.100 Full brief: https://carolinacleartech.com/brief/2026-06-04/
-
-15
2026-06-03: CISA adds Oracle WebLogic CVE-2024-21182 to KEV catalog after active exploitation with federal
Show Notes - 2026-06-03 Stories Covered: - June 3, 2026 - Today: - Oracle WebLogic CVE-2024-21182 Actively Exploited (CVE-2024-21182) (https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-weblogic-flaw/) - Google Patches Exploited Android Zero-Day (CVE-2025-48595) (https://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/) - Linux Kernel Privilege Escalation Added to KEV (CVE-2022-0492) (https://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalog) - Unpatched NTLM Coercion in Windows Search URI Handler (No CVE) (https://www.huntress.com/blog/unpatched-ntlm-coercion-windows-search-uri-handler) - Microsoft Backtracks on Zero-Day Researcher Legal Threats (https://www.securityweek.com/microsoft-tries-to-calm-legal-threat-fears-after-zero-day-disclosure-backlash/) - VS Code Zero-Day Allows GitHub Token Theft via Link Click (https://www.bleepingcomputer.com/news/security/vs-code-zero-day-lets-hackers-steal-github-tokens-in-one-click/) - AI-Built Ransomware Toolkit Automates EDR Evasion (https://www.bleepingcomputer.com/news/security/ai-built-ransomware-toolkit-automates-edr-evasion-ad-discovery/) - DriveSurge Campaign Hijacks Thousands of Sites for Malware Delivery (https://www.darkreading.com/cyberattacks-data-breaches/drivesurge-hijacks-thousands-sites-clickfix-fakeupdate-attacks) - Exchange Online Outage Causes Email Delays and Failures (https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-causes-email-delays-failures/) - Gamaredon Exploits WinRAR to Deliver Malware Against Ukraine (https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html) - WordPress Kirki Plugin Privilege Escalation Exploited (CVE-2026-8206) (https://www.bleepingcomputer.com/news/security/critical-kirki-flaw-exploited-to-hijack-wordpress-admin-accounts/) - Microsoft Office Vulnerability (CVE-2026-21509) Used by APT28 (https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html) CVEs Referenced: CVE-2022-0492, CVE-2024-21182, CVE-2025-48595, CVE-2025-8088, CVE-2026-21509, CVE-2026-33825, CVE-2026-33829, CVE-2026-41091, CVE-2026-45498, CVE-2026-8206 Indicators of Compromise: IPs: 12.2.1.4, 14.1.1.0 Full brief: https://carolinacleartech.com/brief/2026-06-03/
-
-16
2026-06-02: Critical Alerts
Show Notes - 2026-06-02 Stories Covered: - CVE-2026-21182: Oracle WebLogic Server Added to CISA KEV (https://www.cisa.gov/news-events/alerts/2026/06/01/cisa-adds-one-known-exploited-vulnerability-catalog) - CVE-2026-41089: Windows Netlogon RCE Under Active Exploitation (https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/) - CVE-2026-0257: Palo Alto Networks GlobalProtect Authentication Bypass Exploited (https://www.securityweek.com/recent-palo-alto-networks-vulnerability-exploited-for-weeks/) - Gogs Remote Code Execution Zero-Day (No CVE Yet) (https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html) - Red Hat npm Packages Compromised in Supply Chain Attack (https://www.bleepingcomputer.com/news/security/red-hat-npm-packages-compromised-to-steal-developer-credentials/) - DriveSurge Campaign Hijacks Thousands of Sites for Malware Distribution (https://www.bleepingcomputer.com/news/security/hackers-hijack-thousands-of-sites-for-clickfix-and-fakeupdate-attacks/) - codexui-android npm Package Steals OpenAI Codex Tokens (https://thehackernews.com/2026/06/openai-codex-authentication-tokens.html) - Meta AI Support Bot Exploited for Instagram Account Takeover (https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts/) - WordPress Malware Hides C2 Data in Steam Profile Comments (https://www.bleepingcomputer.com/news/security/wordpress-malware-campaign-hides-payloads-in-steam-profiles/) - CVE-2026-45498, CVE-2026-33825, CVE-2026-41091: Additional Windows Zero-Days Under Exploitation (https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/) - Microsoft Outages Affecting MFA Setup and Office Apps (https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-outage-affecting-mfa-setup-mysignin-service/) - KB5089549 Windows 11 Security Update Installation Issues Resolved (https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-kb5089549-windows-security-update-install-issues/) - CVE-2026-26980: Ghost CMS SQL Injection Under Active Exploitation (https://research.checkpoint.com/2026/1st-june-threat-intelligence-report/) - CVE-2026-8732: WP Maps Pro WordPress Plugin Exploited for Site Takeover (https://www.securityweek.com/wp-maps-pro-vulnerability-exploited-to-take-over-wordpress-sites/) - Dashlane Brute-Force Attack Results in Limited Vault Downloads (https://www.bleepingcomputer.com/news/security/dashlane-password-manager-users-locked-out-by-brute-force-attacks/) - SVG Files Used in Phishing Campaigns (https://isc.sans.edu/diary/rss/33040) - GlassWorm C2 Infrastructure Taken Down (https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html) - Carnival Corporation, Charter Communications, Lithuania Data Breaches (https://research.checkpoint.com/2026/1st-june-threat-intelligence-report/) - Spain Arrests Doxer Targeting Government Employees (https://www.bleepingcomputer.com/news/security/spain-arrests-doxer-leaking-sensitive-data-of-govt-employees/) - Check Point Security Gateways: CVE-2026-48131, CVE-2026-48132 (https://research.checkpoint.com/2026/1st-june-threat-intelligence-report/) - China-Aligned Threat Activity Targeting Czech Republic, Taiwan, India (https://thehackernews.com/2026/06/china-aligned-groups-ramp-up-attacks.html) - Pakistan-Linked SideCopy Targets Afghanistan with Xeno RAT (https://thehackernews.com/2026/06/pakistan-linked-sidecopy-targets.html) CVEs Referenced: CVE-2026-0257, CVE-2026-21182, CVE-2026-26980, CVE-2026-33825, CVE-2026-41089, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-48131, CVE-2026-48132, CVE-2026-8732 Indicators of Compromise: IPs: 164.92.88.210 Full brief: https://carolinacleartech.com/brief/2026-06-02/
-
-17
2026-06-01: Critical WordPress plugin flaw under active exploitation allows unauthenticated admin account
Show Notes - 2026-06-01 Stories Covered: - Today: - Critical WP Maps Pro Flaw Actively Exploited (CVE-2026-8732) (https://thehackernews.com/2026/06/critical-wp-maps-pro-flaw-actively.html) - Dutch Authorities Dismantle 17 Million Device Botnet (https://thehackernews.com/2026/05/dutch-authorities-dismantle-botnet.html) - Container Attack Vectors Continue to Threaten Cloud Environments (CVE-2019-5736, CVE-2022-0492) (https://securelist.com/container-attack-vectors/120010/) - SmartApeSG ClickFix Campaign Delivers Multi-Stage RAT Infections (https://isc.sans.edu/diary/rss/33034) - Ransomware Group Claims HDFC AMC Data Theft (https://databreaches.net/2026/05/31/bombay-high-court-issues-injunction-prohibiting-hackers-from-publishing-allegedly-hacked-hdfc-investor-data/?pk_campaign=feed&pk_kwd=bombay-high-court-issues-injunction-prohibiting-hackers-from-publishing-allegedly-hacked-hdfc-investor-data) - Russia Expands SORM Surveillance Requirements (https://news.risky.biz/risky-bulletin-russia-greatly-expands-sorm-surveillance-requirements/) - 2026 Election Threats Target Campaign Infrastructure, Not Voting Systems (https://cyberscoop.com/2026-election-cyber-threats-campaign-systems/) - YARA-X 1.17.0 Released (https://isc.sans.edu/diary/rss/33032) - CVE-2026-8732 - WP Maps Pro Privilege Escalation (https://thehackernews.com/2026/06/critical-wp-maps-pro-flaw-actively.html) - CVE-2019-5736 - Container Runtime Escape (https://securelist.com/container-attack-vectors/120010/) - CVE-2022-0492 - Container Escape Vulnerability (https://securelist.com/container-attack-vectors/120010/) CVEs Referenced: CVE-2019-5736, CVE-2022-0492, CVE-2026-8732 Indicators of Compromise: IPs: 89.110.110.119, 185.163.47.217, 178.156.165.82, 178.156.173.194 Full brief: https://carolinacleartech.com/brief/2026-06-01/
-
-18
2026-05-31: Palo Alto GlobalProtect VPN suffers active exploitation of an authentication bypass (CVE-2026-0257
Show Notes - 2026-05-31 Stories Covered: - Today: - Palo Alto GlobalProtect VPN Authentication Bypass (CVE-2026-0257) (https://www.bleepingcomputer.com/news/security/palo-alto-globalprotect-vpn-auth-bypass-flaw-now-exploited-in-attacks/) - CIFSwitch Linux Privilege Escalation (https://www.bleepingcomputer.com/news/security/new-cifswitch-linux-flaw-gives-root-on-multiple-distributions/) - Flowise AI Platform RCE (CVE-2026-40933) (https://www.securityweek.com/exploit-code-published-for-critical-flowise-rce-vulnerability/) - Russian Intelligence Technology Procurement Escalation (https://www.securityweek.com/russian-spies-are-aggressively-seeking-western-technology-as-sanctions-bite-officials-say/) - GnuTLS Certificate Validation Bypass Flaws (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42012) - Additional Certificate Validation Flaws (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42790) - KubeVirt Security Flaws (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-7374) - Node.js Permission Model Flaws (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-36137) - Other Disclosed Vulnerabilities (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46242) - Microsoft Incident Response Criticized (https://databreaches.net/2026/05/30/microsofts-incident-response-is-getting-a-failing-grade-from-researchers/?pk_campaign=feed&pk_kwd=microsofts-incident-response-is-getting-a-failing-grade-from-researchers) CVEs Referenced: CVE-2024-22018, CVE-2024-36137, CVE-2025-15649, CVE-2025-23167, CVE-2026-0257, CVE-2026-40034, CVE-2026-40510, CVE-2026-40528, CVE-2026-40933, CVE-2026-42012, CVE-2026-42013, CVE-2026-42015, CVE-2026-42789, CVE-2026-42790, CVE-2026-44839, CVE-2026-46242, CVE-2026-48864, CVE-2026-48962, CVE-2026-5260, CVE-2026-7374, CVE-2026-9804 Full brief: https://carolinacleartech.com/brief/2026-05-31/
-
-19
2026-05-30: Palo Alto GlobalProtect bypass is now actively exploited with CISA adding CVE-2026-0257 to KEV
Show Notes - 2026-05-30 Stories Covered: - Today: - Gogs Zero-Day Exposes Servers to Remote Code Execution (CVE-2025-8110) (https://www.securityweek.com/gogs-zero-day-exposes-servers-to-remote-code-execution/) - PAN-OS GlobalProtect Authentication Bypass Under Active Exploitation (CVE-2026-0257) (https://thehackernews.com/2026/05/pan-os-globalprotect-authentication.html) - Marimo Post-Exploitation via LLM Agent (CVE-2026-39987) (https://thehackernews.com/2026/05/attackers-use-llm-agent-for-post.html) - Silent Ransom Group Escalates to Physical Intrusions (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-22-7/) - Russia-Linked GREYVIBE Targets Ukraine with AI-Powered Campaigns (https://thehackernews.com/2026/05/new-russian-linked-greyvibe-targets.html) - The Com Criminal Collective Funds Violence via Cybercrime (https://www.darkreading.com/threat-intelligence/the-com-cyberattacks-violence-sexploitation) - Malicious npm Packages Abuse Dependency Confusion to Profile Environments (https://www.microsoft.com/en-us/security/blog/2026/05/29/33-malicious-npm-packages-abuse-dependency-confusion-profile-developer-environments/) - Malicious Sicoob NuGet Package Steals Brazilian Banking Credentials (https://thehackernews.com/2026/05/malicious-sicoob-nuget-steals-banking.html) - 14 Malicious npm Packages Target AWS and CI/CD Secrets (https://thehackernews.com/2026/05/malicious-sicoob-nuget-steals-banking.html) - TrapDoor Supply Chain Campaign Hits 176 npm Packages (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-22-7/) - ChatGPT Share Links Abused for Malware Distribution (https://www.bleepingcomputer.com/news/security/chatgpt-share-links-abused-to-host-fake-outage-pages-to-deliver-malware/) - Shadow AI: 2,000+ Vibe-Coded Apps Exposed Corporate Data (https://thehackernews.com/2026/05/what-2000-exposed-vibe-coded-apps.html) - Zapier Nearly Compromised via Multi-Step Exploit Chain (https://www.darkreading.com/vulnerabilities-threats/complex-cloud-integrations-small-errors-compromises) - Dutch Authorities Disrupt 17 Million Device Botnet (https://www.bleepingcomputer.com/news/security/dutch-govt-disrupts-malware-botnet-with-17-million-infected-devices/) - Stark Industries Hosting Network Dismantled (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-22-7/) - Google Chrome Rolls Out Device Bound Session Credentials (https://www.bleepingcomputer.com/news/security/google-chrome-adds-session-cookie-theft-protection-for-all-users/) - California AG Sues 23andMe Over 2023 Breach (https://www.bleepingcomputer.com/news/security/california-ag-sues-23andme-over-2023-breach-exposing-health-data/) - DDoS-as-a-Service Market Evolves from Scripts to Polished Products (https://www.bleepingcomputer.com/news/security/from-5-attacks-to-botnet-powered-platforms-inside-the-ddos-as-a-service-market/) - Chrome 148 Patches 151 Vulnerabilities (https://www.securityweek.com/chrome-148-update-patches-151-vulnerabilities/) - VS Code Remote SSH Extension Vulnerability (https://www.securityweek.com/in-other-news-trump-mobile-data-breach-fifa-world-cup-phishing-cisa-responds-to-supply-chain-attacks/) - Veeam, Notepad++, Roundcube Patches (https://www.securityweek.com/in-other-news-trump-mobile-data-breach-fifa-world-cup-phishing-cisa-responds-to-supply-chain-attacks/) - CISA Expands KEV Catalog with Supply Chain Attack CVEs (https://www.securityweek.com/in-other-news-trump-mobile-data-breach-fifa-world-cup-phishing-cisa-responds-to-supply-chain-attacks/) - ChatGPhish Vulnerability in ChatGPT Web Summaries (https://thehackernews.com/2026/05/chatgphish-vulnerability-turns-chatgpt.html) - SymJack and TrustFall: AI Coding Agent Attacks (https://thehackernews.com/2026/05/chatgphish-vulnerability-turns-chatgpt.html) - CIFSwitch: Linux Local Root Vulnerability (https://www.sc ...
-
-20
2026-05-29: Gogs zero-day enables remote code execution on 2,400+ Internet-exposed servers
Show Notes - 2026-05-29 Stories Covered: - Today: - Gogs Zero-Day Allows Remote Code Execution (https://www.bleepingcomputer.com/news/security/new-gogs-zero-day-flaw-lets-hackers-get-remote-code-execution/) - DAEMON Tools Supply Chain Attack (CVE-2026-8398) (https://thehackernews.com/2026/05/threatsday-bulletin-claude-security.html) - Multiple Windows Zero-Days Under Active Exploitation (CVE-2026-33825, CVE-2026-41091, CVE-2026-45498) (https://thehackernews.com/2026/05/microsoft-slams-public-zero-day.html) - GitHub and Nx Console Supply Chain Intrusions (CVE-2026-48027) (https://www.cisa.gov/news-events/alerts/2026/05/28/supply-chain-compromises-impact-nx-console-and-github-repositories) - FortiClient EMS Vulnerability Exploited for Infostealer Deployment (CVE-2026-35616) (https://www.securityweek.com/critical-forticlient-ems-vulnerability-exploited-in-fresh-attacks/) - The Gentlemen Ransomware: Self-Propagating Go Encryptor (https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/) - 1,350 C2 Servers Across Middle East Infrastructure (https://thehackernews.com/2026/05/threatsday-bulletin-claude-security.html) - Azure Backup for AKS Privilege Escalation Flaw (https://thehackernews.com/2026/05/threatsday-bulletin-claude-security.html) - Romanian Cybercrime Operator Sentenced to 56 Months (https://thehackernews.com/2026/05/threatsday-bulletin-claude-security.html) - IBM and Red Hat Commit $5 Billion to "Project Lightwell" for Open Source Supply Chain Security (https://www.securityweek.com/ibm-and-red-hat-commit-5-billion-to-secure-open-source-supply-chains-under-project-lightwell/) - MacGregor Voyage Data Recorder (VDR) G4e (https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-01) - KMW CCTV Security Cameras (CVE-2026-5386) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-148-06) - Perl Archive::Tar Vulnerabilities (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42496) - Multiple Linux Kernel CVEs - bzip2 Off-by-One Vulnerability (CVE-2026-42250) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42250) CVEs Referenced: CVE-2024-39930, CVE-2024-39932, CVE-2024-39933, CVE-2025-8110, CVE-2026-33825, CVE-2026-35616, CVE-2026-40425, CVE-2026-41091, CVE-2026-42250, CVE-2026-42496, CVE-2026-42929, CVE-2026-42941, CVE-2026-42951, CVE-2026-44611, CVE-2026-45498, CVE-2026-45585, CVE-2026-46107, CVE-2026-46155, CVE-2026-46186, CVE-2026-46195, CVE-2026-46232, CVE-2026-48027, CVE-2026-5386, CVE-2026-8398, CVE-2026-9538 Full brief: https://carolinacleartech.com/brief/2026-05-29/
-
-21
2026-05-28: CISA added a critical LiteSpeed cPanel plugin flaw to the KEV catalog with a Friday midnight
Show Notes - 2026-05-28 Stories Covered: - May 28, 2026 - Today: - CISA Adds LiteSpeed cPanel Plugin Flaw to KEV Catalog (CVE-2026-48172) (https://www.bleepingcomputer.com/news/security/cisa-gives-feds-4-days-to-patch-actively-exploited-cpanel-plugin-flaw/) - CISA Adds Three Additional KEV Entries (CVE-2026-8398, CVE-2026-45321, CVE-2026-48027) (https://www.cisa.gov/news-events/alerts/2026/05/27/cisa-adds-three-known-exploited-vulnerabilities-catalog) - Silent Ransom Group Targets Law Firms with In-Person Data Theft (https://www.darkreading.com/cyberattacks-data-breaches/ransomware-actors-steal-law-firm-data) - Reconstructing Akira Ransomware Kill Chain from Logs (https://isc.sans.edu/diary/rss/33024) - CrowdStrike Disrupts Glassworm Botnet Targeting Developer Supply Chain (https://cyberscoop.com/crowdstrike-glassworm-botnet-takedown/) - SymJack Attack Hijacks AI Coding Agents for Supply Chain Attacks (https://www.securityweek.com/symjack-attack-turns-ai-coding-agents-into-supply-chain-attack-delivery-systems/) - Active Directory Password Policy Best Practices (https://www.bleepingcomputer.com/news/security/can-you-enforce-strong-active-directory-password-rules-without-frustrating-users/) - Gitea Private Container Image Exposure (CVE-2026-27771) (https://thehackernews.com/2026/05/gitea-vulnerability-exposes-private.html) - Microsoft Security Update Guide Linux CVE Publications (https://msrc.microsoft.com/update-guide/) - Lastwall Raises $11.5M for Quantum-Resilient Identity Platform (https://www.securityweek.com/lastwall-raises-11-5-million-for-quantum-resilient-identity-platform/) CVEs Referenced: CVE-2026-27771, CVE-2026-45321, CVE-2026-48027, CVE-2026-48172, CVE-2026-8398 Full brief: https://carolinacleartech.com/brief/2026-05-28/
-
-22
2026-05-27: CISA adds exploited LiteSpeed cPanel plugin zero-day to KEV catalog with May 29 patch deadline
Show Notes - 2026-05-27 Stories Covered: - Today: - LiteSpeed cPanel Plugin Privilege Escalation (CVE-2026-48172) (https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-litespeed-cpanel-plugin-zero-day/) - Microsoft SharePoint Remote Code Execution (CVE-2026-45659) (https://www.darkreading.com/vulnerabilities-threats/microsoft-issues-sharepoint-patch) - AI Threat Landscape: Criminal Deployment at Operational Scale (https://research.checkpoint.com/2026/ai-threat-landscape-digest-march-april-2026/) - MyPillow Appears on Play Ransomware Leak Site (https://www.theregister.com/cyber-crime/2026/05/26/mypillow-appears-on-play-ransomware-leak-site/5246513) - KnowledgeDeliver Zero-Day Exploited for Web Shell Deployment (CVE-2026-5426) (https://www.securityweek.com/hackers-exploited-knowledgedeliver-zero-day-for-web-shell-deployment/) - MFA Prompt Bombing: Push Notification Fatigue Attacks (https://thehackernews.com/2026/05/mfa-prompt-bombing-why-your-second.html) - Microsoft Defender Automatic Device Isolation (Preview) (https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-can-now-automatically-isolate-hacked-endpoints/) - Windows 11 KB5089573 Optional Preview Update (https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5089573-update-released-with-performance-improvements/) - Varonis Atlas Integrates Claude Compliance API for AI Governance (https://www.bleepingcomputer.com/news/security/how-varonis-atlas-integrates-claude-compliance-api-for-ai-governance/) - Industrial Control Systems (https://www.cisa.gov/news-events/ics-advisories/icsa-26-146-06) - Microsoft Update Guide CVE Disclosures (https://msrc.microsoft.com/update-guide) CVEs Referenced: CVE-2025-55182, CVE-2025-7745, CVE-2025-9970, CVE-2026-45495, CVE-2026-45498, CVE-2026-45659, CVE-2026-48172, CVE-2026-5426, CVE-2026-7251 Indicators of Compromise: IPs: 5.3.1.0, 1.4.9.22 Full brief: https://carolinacleartech.com/brief/2026-05-27/
-
-23
2026-05-26: Critical Alerts
Show Notes - 2026-05-26 Stories Covered: - May 26, 2026 - Drupal SQL Injection (CVE-2026-9082) (https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-drupal-vulnerability/) - Microsoft Defender Zero-Days (CVE-2026-41091, CVE-2026-45498) (https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html) - Trend Micro Apex One Directory Traversal (CVE-2026-34926) (https://research.checkpoint.com/2026/25th-may-threat-intelligence-report/) - Linux Kernel Privilege Escalation (CVE-2026-46333) (https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html) - GitHub Breach via Poisoned VS Code Extension (https://isc.sans.edu/diary/rss/33016) - Microsoft Azure Durable Functions SDK Trojanized (durabletask) (https://isc.sans.edu/diary/rss/33016) - Laravel-Lang Supply Chain Attack (https://www.securityweek.com/laravel-lang-packages-poisoned-for-malware-delivery/) - 7-Eleven Data Breach (ShinyHunters) (https://www.bleepingcomputer.com/news/security/7-eleven-data-breach-exposes-personal-information-of-185-000-people/) - Ghost CMS Mass Exploitation (CVE-2026-26980) (https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html) - Kali365 Phishing-as-a-Service (Microsoft 365 OAuth Abuse) (https://www.bleepingcomputer.com/news/security/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts/) - KnowledgeDeliver LMS Zero-Day (CVE-2026-5426) (https://thehackernews.com/2026/05/knowledgedeliver-lms-flaw-exploited-to.html) - Netherlands Seizes 800 Servers, Arrests Bulletproof Hosting Operators (https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/) - ACR Stealer via Fake Claude Download Pages (https://isc.sans.edu/diary/rss/33018) - Microsoft Fox Tempest Takedown (Rhysida Ransomware Enabler) (https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html) - Windows Server 2016 Domain Controller Lookup Failures (KB5087537) (https://www.bleepingcomputer.com/news/microsoft/microsoft-domain-controller-lookup-may-fail-on-windows-server-2016/) - ACR Stealer (Fake Claude Campaign) (https://isc.sans.edu/diary/rss/33018) - Ghost CMS Campaign (CVE-2026-26980) (https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html) - Lazarus RemotePE (https://thehackernews.com/2026/05/lazarus-deploys-remotepe-memory-only.html) - Nimbus Manticore (Iranian APT) (https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html) - Laravel-Lang Supply Chain Attack (https://www.securityweek.com/laravel-lang-packages-poisoned-for-malware-delivery/) - CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws (https://thehackernews.com/2026/05/cert-in-mandates-12-hour-patching-for.html) - Anthropic Mythos Detected 23,000 Vulnerabilities Across 1,000 OSS Projects (https://www.securityweek.com/anthropic-mythos-detected-23000-potential-vulnerabilities-across-1000-oss-projects/) - Check Point: AI-Driven Attacks Have Entered Routine Criminal Use (https://research.checkpoint.com/2026/25th-may-threat-intelligence-report/) - TeamPCP Supply Chain Campaign (CVE-2026-45321) (https://isc.sans.edu/diary/rss/33016) - CVE-2026-26980 (Ghost CMS SQL Injection) (https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html) - CVE-2026-5426 (KnowledgeDeliver LMS Hard-Coded Machine Keys) (https://thehackernews.com/2026/05/knowledgedeliver-lms-flaw-exploited-to.html) - Healthcare Data Breaches (https://www.securityweek.com/oncology-institute-discloses-third-party-data-breach/) CVEs Referenced: CVE-2026-26980, CVE-2026-34926, CVE-2026-41091, CVE-2026-45321, CVE-2026-45498, CVE-2026-46333, CVE-2026-5426, CVE-2026-9082 Indicators of Compromise: Domains: flipboxstudio[.]info, clo4shara[.]xyz, google[.]com, fairpoint29[.]com, enhanceblabber[.]cc, primemetricsa[.]com, creativecommunityinfo[.]art, ibb[.]co, en ...
-
-24
2026-05-25: Supply chain attacks hit developer ecosystems with 34 malicious packages stealing credentials
Show Notes - 2026-05-25 Stories Covered: - Today: - Ghost CMS SQL Injection (CVE-2026-26980) (https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/) - KnowledgeDeliver LMS ViewState Deserialization (CVE-2026-5426) (https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/) - TrapDoor Supply Chain Attack (npm, PyPI, Crates.io) (https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html) - Megalodon GitHub Actions Attack (5,500+ Repositories) (https://www.securityweek.com/over-5500-github-repositories-infected-in-megalodon-supply-chain-attack/) - DocketWise Data Breach (143,000 Affected) (https://www.securityweek.com/docketwise-data-breach-impacts-143000/) - Chinese-Language Phishing-as-a-Service Ecosystem (https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services/) - Anthropic Mythos Finds 23,000 Vulnerabilities (https://news.risky.biz/risky-bulletin-mythos-found-thousands-of-critical-bugs/) - Linus Torvalds Cracks Down on AI-Generated Pull Requests (https://www.theregister.com/oses/2026/05/25/linus-torvalds-to-start-being-more-hardnosed-about-pointless-pull-requests-some-of-which-come-from-ais/5245549) - Wireshark 4.6.6 (https://isc.sans.edu/diary/rss/33010) - CVE-2026-43029 (mptcp soft lockup) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43029) - CVE-2026-43414 (qla2xxx fcport double free) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43414) CVEs Referenced: CVE-2026-26980, CVE-2026-43029, CVE-2026-43414, CVE-2026-5426 Full brief: https://carolinacleartech.com/brief/2026-05-25/
-
-25
2026-05-24: Multiple PHP package supply chain attacks hit Laravel and Composer ecosystems with cross-platform
Show Notes - 2026-05-24 Stories Covered: - Today: - Laravel Lang Package Compromise (https://www.bleepingcomputer.com/news/security/laravel-lang-packages-hijacked-to-deploy-credential-stealing-malware/) - Packagist Supply Chain Attack (Second Wave) (https://thehackernews.com/2026/05/packagist-supply-chain-attack-infects-8.html) - Underminr CDN Vulnerability (https://www.securityweek.com/underminr-vulnerability-lets-attackers-hide-malicious-connections-behind-trusted-domains/) - WolfSSL Certificate Forgery (CVE-2026-5194) (https://thehackernews.com/2026/05/claude-mythos-ai-finds-10000-high.html) - npm Adds Staged Publishing + 2FA Requirement (https://thehackernews.com/2026/05/npm-adds-2fa-gated-publishing-and.html) - Italian Authorities Disrupt CINEMAGOAL Piracy Network (https://www.bleepingcomputer.com/news/legal/italy-disrupts-cinemagoal-piracy-app-that-stole-streaming-auth-codes/) - UK Water Utility Data Breach Victims Report Impact (https://databreaches.net/2026/05/23/uk-victims-feel-violated-after-water-firms-data-breach/) - UK Secures £355,880 Confiscation Order in Motor Insurance Data Theft (https://databreaches.net/2026/05/23/uk-355880-10-confiscation-order-secured-following-proceeds-of-crime-hearing/) - Rhode Island Workers' Compensation Vendor Breach Affects 131,000 (https://databreaches.net/2026/05/23/rhode-islands-workers-compensation-notifies-those-affected-by-january-data-breach/) CVEs Referenced: CVE-2026-5194 Indicators of Compromise: Domains: flipboxstudio[.]info., flipboxstudio[.]info, github[.]com Full brief: https://carolinacleartech.com/brief/2026-05-24/
-
-26
2026-05-23: Drupal Core SQL injection (CVE-2026-9082) and Trend Micro Apex One directory traversal
Show Notes - 2026-05-23 Stories Covered: - Today: - Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV (CVE-2026-9082) (https://thehackernews.com/2026/05/drupal-core-sql-injection-bug-actively.html) - Trend Micro Apex One Zero-Day Exploited in the Wild (CVE-2026-34926) (https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-apex-one-zero-day-exploited-in-attacks/) - LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root (https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html) - FBI Warns About Fast-Growing Phishing Kit Targeting Microsoft 365 Users (Kali365) (https://cyberscoop.com/fbi-phishing-kali365-microsoft365-access-tokens/) - First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups (https://thehackernews.com/2026/05/first-vpn-dismantled-in-global-takedown.html) - Four-Faith Industrial Router Vulnerability Exploited by Botnets (CVE-2024-9643) (https://www.securityweek.com/in-other-news-industrial-router-exploitation-cisa-kev-nomination-form-gas-station-hacking/) - Multi-Stage Linux Intrusion via F5 and Confluence Edge Appliance Compromise (https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluence/) - Iranian Hackers Suspected in US Gas Station Tank Monitor Breaches (https://www.securityweek.com/in-other-news-industrial-router-exploitation-cisa-kev-nomination-form-gas-station-hacking/) - CISA Contractor Exposes Credentials on Public GitHub Repository (https://www.securityweek.com/in-other-news-industrial-router-exploitation-cisa-kev-nomination-form-gas-station-hacking/) - Hugging Face Hiding Second-Stage Malware for npm Supply Chain Attack (https://databreaches.net/2026/05/22/hugging-face-hiding-second-stage-malware-for-npm-supply-chain-attack/?pk_campaign=feed&pk_kwd=hugging-face-hiding-second-stage-malware-for-npm-supply-chain-attack) - New macOS Stealer Variant Masquerades as Apple, Google & Microsoft (Reaper) (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-21-7/) - Interpol Operation Ramz Rounds Up 200+ Cybercrime Suspects Across Middle East and North Africa (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-21-7/) - Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks (https://www.darkreading.com/cyber-risk/verizon-dbir-healthcare-fends-off-increased-social-engineering-attacks) - CVE-2026-41091 (CISA-KEV, EPSS 0.066, 91st percentile) - CVE-2026-45401 (EPSS 0.000, 12th percentile) - CVE-2025-14575 (Qt Network OpenSSL TLS backend, EPSS 0.000, 1st percentile) - CVE-2026-3593 (BIND 9 DNS-over-HTTPS, EPSS 0.000, 5th percentile) - CVE-2026-42009 (GnuTLS DTLS, EPSS 0.001, 31st percentile) - CVE-2026-3039 (BIND 9, EPSS 0.001, 16th percentile) - CVE-2026-3592 (BIND 9, EPSS 0.000, 4th percentile) - CVE-2026-5946 (BIND 9, EPSS 0.000, 11th percentile) - CVE-2026-5950 (BIND 9, EPSS 0.001, 21st percentile) - CVE-2026-41054 (haveged, EPSS 0.000, 0th percentile) - CVE-2026-8723 (qs.stringify, EPSS 0.000, 14th percentile) - CVE-2026-5947 (BIND 9, EPSS 0.000, 6th percentile) - CVE-2026-8711 (NGINX JavaScript, EPSS 0.002, 47th percentile) - CVE-2025-51480 (ONNX 1.17.0, EPSS 0.004, 59th percentile) - CVE-2023-6606 (Linux kernel SMB, EPSS 0.000, 1st percentile) - CVE-2025-39932 (Linux SMB client, EPSS 0.000, 2nd percentile) - Multiple Linux kernel CVEs CVEs Referenced: CVE-2022-40139, CVE-2023-41179, CVE-2023-6606, CVE-2024-9643, CVE-2025-14575, CVE-2025-39901, CVE-2025-39905, CVE-2025-39927, CVE-2025-39932, CVE-2025-39940, CVE-2025-39990, CVE-2025-40003, CVE-2025-40064, CVE-2025-40065, CVE-2025-40074, CVE-2025-51480, CVE-2025-54948, CVE-2026-3039, CVE-2026-34926, CVE-2026-3592, CVE-2026-3593, CVE-2026-41054, CVE-2026-41091, CVE-2026-41940, CVE-2026-42009, CVE-2026-45401 ...
-
-27
2026-05-22: Microsoft patched two actively exploited Defender zero-days with CISA deadline June 3
Show Notes - 2026-05-22 Stories Covered: - 2026-05-22 - Today: - Microsoft Defender Actively Exploited Zero-Days (CVE-2026-41091, CVE-2026-45498) (https://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html) - Trend Micro Apex One Zero-Day Exploitation (CVE-2026-34926) (https://www.securityweek.com/trendai-patches-apex-one-zero-day-exploited-in-the-wild/) - Drupal Highly Critical SQL Injection (CVE-2026-9082) (https://www.securityweek.com/drupal-patches-highly-critical-vulnerability-exposing-websites-to-hacking/) - Langflow Code Execution Vulnerability Exploited by MuddyWater (CVE-2025-34291) (https://thehackernews.com/2026/05/cisa-adds-exploited-langflow-and-trend.html) - CISA Adds Legacy Microsoft Vulnerabilities to KEV (https://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html) - The Gentlemen Ransomware Defense Evasion TTPs (https://www.huntress.com/blog/the-gentlemen-ransomware-defense-evasion-ttps) - First VPN Cybercrime Service Dismantled (https://www.bleepingcomputer.com/news/security/police-seize-first-vpn-service-used-in-ransomware-data-theft-attacks/) - Cloud Atlas APT Returns with New Tools and SSH Tunnels (https://securelist.com/cloud-atlas-2026/119895/) - GitHub Breached via Compromised VS Code Extension (https://news.risky.biz/risky-bulletin-microsoft-ends-sms-mfa-for-personal-accounts/) - Cross-Platform NPM Stealer Targets Windows, macOS, Linux (https://isc.sans.edu/diary/rss/33006) - ABB Industrial Control Systems Vulnerabilities (https://www.cisa.gov/news-events/ics-advisories/icsa-26-141-03) - Hitachi Energy GMS600 OpenSSL Timing Attack (CVE-2022-4304) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-141-01) - Microsoft Linux Kernel CVEs in MSRC Update Guide (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26944) - Pwn2Own Berlin 2026: 47 Zero-Days Exploited (https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html) - Microsoft Ends SMS MFA for Personal Accounts (https://news.risky.biz/risky-bulletin-microsoft-ends-sms-mfa-for-personal-accounts/) - UK NCSC Issues Agentic AI Security Guidance (https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html) - Poland Urges Officials to Switch from Signal to mSzyfr (https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html) - Dutch Police Unmasked 74 Fraud Suspects via Game Over?! Campaign (https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html) - Trump Postpones AI Security Executive Order (https://cyberscoop.com/trump-postpones-executive-order-focused-on-ai-security/) - US-China Cyber Espionage Acknowledgment (https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html) CVEs Referenced: CVE-2008-4250, CVE-2009-1537, CVE-2009-3459, CVE-2010-0249, CVE-2010-0806, CVE-2018-0802, CVE-2022-35737, CVE-2022-4304, CVE-2023-7104, CVE-2024-26944, CVE-2024-55591, CVE-2025-10504, CVE-2025-12142, CVE-2025-12143, CVE-2025-3277, CVE-2025-34291, CVE-2025-6965, CVE-2026-0968, CVE-2026-33825, CVE-2026-34926, CVE-2026-41091, CVE-2026-43303, CVE-2026-43331, CVE-2026-43465, CVE-2026-43494, CVE-2026-43495, CVE-2026-43496, CVE-2026-43497, CVE-2026-43499, CVE-2026-43501, CVE-2026-43502, CVE-2026-45498, CVE-2026-45584, CVE-2026-9082 Indicators of Compromise: Hashes: 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9 Full brief: https://carolinacleartech.com/brief/2026-05-22/
-
-28
2026-05-21: Microsoft patched two actively exploited Defender zero-days that CISA added to KEV with a June 3
Show Notes - 2026-05-21 Stories Covered: - 2026-05-21 - Today: - Microsoft Defender Zero-Days (CVE-2026-41091, CVE-2026-45498) (https://www.securityweek.com/microsoft-patches-exploited-undefend-and-redsun-defender-zero-days/) - RaaS Ecosystem Tradecraft Analysis (https://www.huntress.com/blog/raas-ecosystem-ransomware-tradecraft) - Microsoft Disrupts Fox Tempest Malware-Signing Service (https://thehackernews.com/2026/05/microsoft-takes-down-malware-signing.html) - Mini Shai-Hulud npm Supply Chain Attack (https://www.microsoft.com/en-us/security/blog/2026/05/20/mini-shai-hulud-compromised-antv-npm-packages-enable-ci-cd-credential-theft/) - SonicWall VPN MFA Bypass via CVE-2024-12802 (https://www.bleepingcomputer.com/news/security/hackers-bypass-sonicwall-vpn-mfa-due-to-incomplete-patching/) - TamperedChef Trojanized Productivity Software (https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/) - Typosquatting Embedded in Third-Party Scripts (https://thehackernews.com/2026/05/typosquatting-is-no-longer-user-problem.html) - AI Coding Agents and Credential Leakage (https://www.securityweek.com/1password-teams-with-openai-to-stop-ai-coding-agents-from-leaking-credentials/) - CISA Exposed GitHub Repo with Secrets (https://www.theregister.com/security/2026/05/19/americas-top-cyber-defense-agency-left-a-github-repo-open-with-passwords-keys-tokens-and-incredibly-obvious-filenames/5242915) - 9-Year-Old Linux Kernel Privilege Escalation (CVE-2026-46333) (https://thehackernews.com/2026/05/9-year-old-linux-kernel-flaw-enables.html) - PinTheft Linux Privilege Escalation (Arch Linux) (https://www.bleepingcomputer.com/news/linux/exploit-released-for-new-pintheft-arch-linux-root-escalation-flaw/) - Identity and Device Security Integration (https://www.bleepingcomputer.com/news/security/identity-alone-isnt-enough-why-device-security-has-to-share-the-load/) - Supply Chain Vulnerability Crisis (https://www.securityweek.com/supply-chain-security-crisis-too-many-vulnerabilities-too-little-visibility/) - Drupal Core SQL Injection (CVE-2026-9082) (https://thehackernews.com/2026/05/highly-critical-drupal-core-flaw.html) - Memcached SASL Timing Side Channel (CVE-2026-47784) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47784) - DNS Software Vulnerabilities (Multiple CVEs) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32792) - Rsync Vulnerabilities (CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-29518, CVE-2026-45232) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43619) - GitHub CLI Terminal Escape Sequence Injection (CVE-2026-45803) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45803) - Cowboy SPDY Decompression Bomb (CVE-2026-43970) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43970) - WebSocket Uninitialized Memory Disclosure (CVE-2026-45736) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45736) CVEs Referenced: CVE-2008-4250, CVE-2009-1537, CVE-2009-3459, CVE-2010-0249, CVE-2010-0806, CVE-2024-12802, CVE-2026-29518, CVE-2026-32792, CVE-2026-33278, CVE-2026-40622, CVE-2026-41091, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42944, CVE-2026-42959, CVE-2026-42960, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-43970, CVE-2026-44390, CVE-2026-44608, CVE-2026-45232, CVE-2026-45498, CVE-2026-45736, CVE-2026-45803, CVE-2026-46333, CVE-2026-47784, CVE-2026-9082 Full brief: https://carolinacleartech.com/brief/2026-05-21/
-
-29
2026-05-20: Microsoft faces a sixth zero-day disclosure in six weeks as researcher "Nightmare Eclipse" releases
Show Notes - 2026-05-20 Stories Covered: - May 20, 2026 - Today: - YellowKey BitLocker Bypass (CVE-2026-45585) - Action: (https://www.darkreading.com/cyberattacks-data-breaches/windows-zero-day-barrage-continues-after-patch-tuesday) - Drupal Core Security Release Tonight - Action: (https://thehackernews.com/2026/05/drupal-to-release-urgent-core-security.html) - CISA Credentials Exposed in Public GitHub Repository - Action: (https://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repo/) - GreenPlasma Windows Privilege Escalation - Action: (https://www.darkreading.com/cyberattacks-data-breaches/windows-zero-day-barrage-continues-after-patch-tuesday) - MiniPlasma: Six-Year-Old Vulnerability Still Exploitable - Action: (https://www.darkreading.com/cyberattacks-data-breaches/windows-zero-day-barrage-continues-after-patch-tuesday) - Microsoft Teams macOS Location Prompt Issue - Action: (https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-undismissible-teams-location-prompts-on-macos-update/) - ABB CoreSense Path Traversal (CVE-2025-3465) - Action: (https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-06) - Kieback & Peter DDC Building Controllers XSS (CVE-2026-4293) - Action: (https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-05) - ZKTeco CCTV Cameras Authentication Bypass (CVE-2026-8598) - Action: (https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-04) - ExifTool macOS Vulnerability (CVE-2026-3102) - Action: (https://securelist.com/exiftool-compromise-mac/119866/) - Microsoft CVE Disclosures - Action: (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43493) - Sophos Firewall Update Bricking Devices - Action: (https://www.bleepingcomputer.com/news/security/sophos-pulls-buggy-firewall-update-bricking-devices-with-boot-loop/) - PAN-OS GlobalProtect Portal Command Injection (CVE-2026-47612) - Action: (https://www.bleepingcomputer.com/news/security/palo-alto-networks-warns-of-pan-os-globalprotect-portal-bug/) - Ivanti Endpoint Manager Mobile (EPMM) Critical Vulnerabilities - Action: (https://www.bleepingcomputer.com/news/security/ivanti-fixes-new-critical-endpoint-manager-mobile-flaws/) - Adobe ColdFusion Patches Critical Pre-Auth RCE - Action: (https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-coldfusion-rce-flaw-exploited-in-the-wild/) - AI Vulnerability Discovery Accelerates (https://www.recordedfuture.com/blog/ai-vulnerability-playbook) - SentinelOne Announces Prompt Security for Agentic AI (https://www.sentinelone.com/blog/prompt-security-for-agentic-ai/) - Ransomware Tracker API Disruptions CVEs Referenced: CVE-2020-17103, CVE-2025-3465, CVE-2026-3102, CVE-2026-4293, CVE-2026-43491, CVE-2026-43492, CVE-2026-43493, CVE-2026-45585, CVE-2026-47612, CVE-2026-8598 Indicators of Compromise: IPs: 1.4.1.12 Full brief: https://carolinacleartech.com/brief/2026-05-20/
-
-30
2026-05-19: Microsoft Exchange zero-day CVE-2026-42897 is under active attack with no patch available
Show Notes - 2026-05-19 Stories Covered: - Today: - Microsoft Exchange Zero-Day Under Attack (CVE-2026-42897) (https://www.darkreading.com/vulnerabilities-threats/microsoft-exchange-zero-day-no-patch) - Cisco SD-WAN Controller Under Exploitation (CVE-2026-20182) (https://thehackernews.com/2026/05/weekly-recap-exchange-0-day-npm-worm.html) - Ivanti Xtraction RCE (CVE-2026-8043) (https://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html) - TeamPCP Supply Chain Campaign Reaches Peak Intensity (https://thehackernews.com/2026/05/weekly-recap-exchange-0-day-npm-worm.html) - CISA Contractor Leaked AWS GovCloud Keys on GitHub (https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/) - Threat Actors Disabling Antivirus and EDR (https://www.huntress.com/blog/how-attackers-disable-av-edr) - Developer Workstations Are Part of the Software Supply Chain (https://thehackernews.com/2026/05/developer-workstations-are-now-part-of.html) - Storm-2949 Turned Compromised Identity into Cloud-Wide Breach (https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/) - BitLocker Zero-Day Exploit (YellowKey) (https://www.schneier.com/blog/archives/2026/05/zero-day-exploit-against-windows-bitlocker.html) - macOS Stealer SHub Reaper Spoofs Apple, Google, and Microsoft (https://www.sentinelone.com/blog/shub-reaper-macos-stealer-spoofs-apple-google-and-microsoft-in-a-single-attack-chain/) - Microsoft Security Focus on Small Business (https://www.microsoft.com/en-us/security/blog/2026/05/18/how-to-better-protect-your-growing-business-in-an-ai-powered-world/) - Fortinet Critical RCE Vulnerabilities (https://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html) - SAP Critical SQL Injection and Authentication Bypass (https://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html) - VMware Fusion Privilege Escalation (CVE-2026-41702) (https://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html) - n8n Critical Prototype Pollution and RCE (https://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html) - Azure Local Disconnected Operations Privilege Escalation (CVE-2026-42822) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42822) CVEs Referenced: CVE-2026-20127, CVE-2026-20182, CVE-2026-26083, CVE-2026-34260, CVE-2026-34263, CVE-2026-41702, CVE-2026-42231, CVE-2026-42232, CVE-2026-42822, CVE-2026-42897, CVE-2026-44277, CVE-2026-44791, CVE-2026-45321, CVE-2026-8043 Indicators of Compromise: Domains: m-kosche[.]com, mlcrosoft[.]co Full brief: https://carolinacleartech.com/brief/2026-05-19/
-
-31
2026-05-18: Windows zero-day MiniPlasma grants SYSTEM privileges on fully patched systems with PoC released
Show Notes - 2026-05-18 Stories Covered: - May 18, 2026 - Today: - MiniPlasma Windows Zero-Day Enables SYSTEM Privilege Escalation (CVE-2025-62221, CVE-2020-17103) (https://thehackernews.com/2026/05/miniplasma-windows-0-day-enables-system.html) - NGINX CVE-2026-42945 Exploited in the Wild (https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html) - openDCIM Critical Vulnerabilities Exploited (https://thehackernews.com/2026/05/nginx-cve-2026-42945-exploited-in-wild.html) - Tycoon2FA Hijacks Microsoft 365 Accounts via Device-Code Phishing (https://www.bleepingcomputer.com/news/security/tycoon2fa-hijacks-microsoft-365-accounts-via-device-code-phishing/) - Grafana Labs Confirms Breach After Source Code Theft (https://www.securityweek.com/grafana-confirms-breach-after-hackers-claim-they-stole-data/) - First Shai-Hulud Worm Clones Emerge (https://www.securityweek.com/first-shai-hulud-worm-clones-emerge/) - Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations (https://thehackernews.com/2026/05/pre-stuxnet-fast16-malware-tampered.html) - Indonesia Emerges as New Hub for Cyber Scam Operations (https://news.risky.biz/risky-bulletin-indonesia-emerges-as-a-new-hub-for-cyber-scams/) - Microsoft Confirms Windows 11 Security Update Install Issues (KB5089549) (https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-kb5089549-windows-11-security-update-install-issues/) - DirtyDecrypt Linux Root Escalation Flaw (CVE-2026-31635) (https://www.bleepingcomputer.com/news/security/exploit-available-for-new-dirtydecrypt-linux-root-escalation-flaw/) - Pwn2Own Berlin 2026 Results (https://www.bleepingcomputer.com/news/security/hackers-earn-1-298-250-for-47-zero-days-at-pwn2own-berlin-2026/) - Linus Torvalds: AI-Powered Bug Hunters Have Made Linux Security Mailing List 'Almost Entirely Unmanageable' (https://www.theregister.com/security/2026/05/18/linus-torvalds-says-ai-powered-bug-hunters-have-made-linux-security-mailing-list-almost-entirely-unmanageable/5241633) - Former CISA Nominee Sean Plankey Named US CEO of Defense Startup (https://cyberscoop.com/former-cisa-nominee-sean-plankey-named-us-ceo-of-defense-startup/) - South Korea Tests Deepfake Laws in June Local Elections (https://www.darkreading.com/vulnerabilities-threats/can-laws-stop-deepfakes-south-korea) CVEs Referenced: CVE-2020-17103, CVE-2025-62221, CVE-2026-28515, CVE-2026-28516, CVE-2026-28517, CVE-2026-31635, CVE-2026-33825, CVE-2026-42945 Full brief: https://carolinacleartech.com/brief/2026-05-18/
-
-32
2026-05-17: WordPress e-commerce stores face active skimmer attacks via unpatched Funnel Builder plugin
Show Notes - 2026-05-17 Stories Covered: - Today: - Funnel Builder Plugin Skimming Campaign (Active Exploitation) (https://thehackernews.com/2026/05/funnel-builder-flaw-under-active.html) - NGINX Heap Overflow (CVE-2026-42945) (https://www.securityweek.com/poc-code-published-for-critical-nginx-vulnerability/) - Azure Kubernetes Privilege Escalation (Silent Fix) (https://www.bleepingcomputer.com/news/security/microsoft-rejects-critical-azure-vulnerability-report-no-cve-issued/) - BlackFile Vishing Extortion Campaign (UNC6671) (https://databreaches.net/2026/05/16/welcome-to-blackfile-inside-a-vishing-extortion-operation/) - Grafana GitHub Token Compromise and Extortion (https://thehackernews.com/2026/05/grafana-github-token-breach-led-to.html) - Instructure-ShinyHunters Payment Debate (https://databreaches.net/2026/05/16/another-detail-emerges-about-instructures-agreement-with-shinyhunters-debate-continues-about-whether-to-pay/) - Illuminate Education Data Breach Lawsuit (https://databreaches.net/2026/05/16/illuminate-wins-another-round-in-court-but-it-may-not-all-be-over/) - Russian Kazuar Backdoor Evolves to P2P Botnet (https://www.bleepingcomputer.com/news/security/russian-hackers-turn-kazuar-backdoor-into-modular-p2p-botnet/) - Medicare Fraud Using Stolen Patient Records (https://databreaches.net/2026/05/16/michigan-nurse-convicted-in-1-6m-medicare-fraud-scheme-using-stolen-patient-records/) - CVE-2026-46483 (Vim Command Injection) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46483) - CVE-2026-44283 (etcd RBAC Bypass) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44283) - CVE-2026-8368 (Perl LWP::UserAgent Header Leak) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8368) - CVE-2026-8328 (Perl FTP PASV SSRF) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8328) CVEs Referenced: CVE-2026-42945, CVE-2026-44283, CVE-2026-46483, CVE-2026-8328, CVE-2026-8368 Indicators of Compromise: Domains: protect-wss[.]com IPs: 3.15.0.3 Full brief: https://carolinacleartech.com/brief/2026-05-17/
-
-33
2026-05-16: Cisco drops its seventh SD-WAN zero-day in three months as attackers exploit a CVSS 10
Show Notes - 2026-05-16 Stories Covered: - 2026-05-16 - Today: - Cisco SD-WAN Authentication Bypass Zero-Day (CVE-2026-20182) (https://cyberscoop.com/cisco-sd-wan-zero-day-exploited/) - Microsoft Exchange Server Zero-Day (CVE-2026-42897) (https://www.securityweek.com/microsoft-warns-of-exchange-server-zero-day-exploited-in-the-wild/) - BlackFile (UNC6671) Targets Microsoft 365 and Okta via Vishing (https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/) - node-ipc npm Package Compromised with Credential Stealer (https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/) - OpenClaw Vulnerabilities Allow Data Theft and Privilege Escalation (https://thehackernews.com/2026/05/four-openclaw-flaws-enable-data-theft.html) - TanStack Supply Chain Attack Hits OpenAI (https://thehackernews.com/2026/05/tanstack-supply-chain-attack-hits-two.html) - Pwn2Own Berlin 2026: Microsoft Exchange, Windows 11 Hacked (https://www.bleepingcomputer.com/news/security/pwn2own-day-two-hackers-demo-microsoft-exchange-windows-11-red-had-enterprise-linux-zero-days/) - REMUS Infostealer Malware-as-a-Service Operation (https://www.bleepingcomputer.com/news/security/inside-the-remus-infostealer-session-theft-maas-and-rapid-evolution/) - AI Agents Used to Discover and Exploit Zero-Days (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-20-7/) - Microsoft Edge to Stop Loading Passwords into Memory on Startup (https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-to-stop-loading-cleartext-passwords-in-memory-on-startup/) - WordPress Avada Builder Plugin Flaws (https://www.bleepingcomputer.com/news/security/avada-builder-wordpress-plugin-flaws-allow-site-credential-theft/) - WordPress Funnel Builder Plugin Exploited for Credit Card Theft (https://www.bleepingcomputer.com/news/security/funnel-builder-wordpress-plugin-bug-exploited-to-steal-credit-cards/) - PostgreSQL Multiple Vulnerabilities (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6478) - Additional CVEs (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43490) CVEs Referenced: CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20133, CVE-2026-20182, CVE-2026-40460, CVE-2026-42897, CVE-2026-43490, CVE-2026-44112, CVE-2026-44113, CVE-2026-44115, CVE-2026-44118, CVE-2026-44431, CVE-2026-44662, CVE-2026-44673, CVE-2026-46333, CVE-2026-4782, CVE-2026-4798, CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6637, CVE-2026-6638 Indicators of Compromise: Domains: enrollms[.]com, passkeyms[.]com, setupsso[.]com, setupsso[.]com., sh[.]azurestaticprovider, bt[.]node, azurestaticprovider[.]net, node[.]js, analytics-reports[.]com, protect-wss[.]com IPs: 3.15.0.3 Full brief: https://carolinacleartech.com/brief/2026-05-16/
-
-34
2026-05-15: Cisco SD-WAN faces its sixth exploited zero-day of 2026 with CVE-2026-20182 granting attackers
Show Notes - 2026-05-15 Stories Covered: - Today: - Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20182) (https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-critical-sd-wan-flaw-exploited-in-zero-day-attacks/) - Windows Zero-Day BitLocker Bypass (YellowKey) (https://thehackernews.com/2026/05/windows-zero-days-expose-bitlocker.html) - Microsoft Exchange Zero-Day (CVE-2026-42897) (https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-exchange-zero-day-flaw-exploited-in-attacks/) - Foxconn North American Facilities Hit by Nitrogen Ransomware (https://www.darkreading.com/cyberattacks-data-breaches/foxconn-attack-manufacturing-cyber-crisis) - KongTuke Pivots to Microsoft Teams for Social Engineering (https://www.bleepingcomputer.com/news/security/kongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches/) - Widespread Cisco SD-WAN Exploitation by Multiple Threat Clusters (https://blog.talosintelligence.com/sd-wan-ongoing-exploitation/) - OpenAI Supply Chain Breach via TanStack Attack (https://www.bleepingcomputer.com/news/security/openai-confirms-security-breach-in-tanstack-supply-chain-attack/) - AI Application Misconfigurations Create Exploitable Attack Paths (https://www.microsoft.com/en-us/security/blog/2026/05/14/configuration-becomes-vulnerability-exploitable-misconfigurations-ai-apps/) - Windows Privilege Escalation Zero-Day (GreenPlasma) (https://thehackernews.com/2026/05/windows-zero-days-expose-bitlocker.html) - Federal Identity Security Critical in Age of AI (https://cyberscoop.com/white-house-federal-identity-security-ai-risks/) - Pwn2Own Berlin 2026 Day 1: $523,000 in Rewards for 24 Zero-Days (https://www.bleepingcomputer.com/news/security/windows-11-and-microsoft-edge-hacked-on-first-day-of-pwn2own-berlin-2026/) - Linux Kernel Privilege Escalation Vulnerability (Fragnesia - CVE-2026-46300) (https://www.securityweek.com/new-linux-kernel-vulnerability-fragnesia-allows-root-privilege-escalation/) - Secret Blizzard's Kazuar Evolves into Modular P2P Botnet (https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/) - Siemens Industrial Control Systems (Multiple Products) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-10) - GnuTLS Authentication Bypass and Name Constraint Issues (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42011) - Twisted DNS Denial of Service (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42304) CVEs Referenced: CVE-2024-4367, CVE-2024-54017, CVE-2025-12659, CVE-2025-22871, CVE-2025-40833, CVE-2025-40949, CVE-2025-48804, CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20133, CVE-2026-20182, CVE-2026-25786, CVE-2026-25787, CVE-2026-25789, CVE-2026-27446, CVE-2026-33825, CVE-2026-33862, CVE-2026-33893, CVE-2026-40175, CVE-2026-41551, CVE-2026-42010, CVE-2026-42011, CVE-2026-42304, CVE-2026-42897, CVE-2026-44411, CVE-2026-44412, CVE-2026-46300 Full brief: https://carolinacleartech.com/brief/2026-05-15/
-
-35
2026-05-14: Microsoft patched 138 vulnerabilities including critical RCE flaws in DNS and Netlogon
Show Notes - 2026-05-14 Stories Covered: - May 14, 2026 - Today: - Windows BitLocker Zero-Day Bypasses Encryption (YellowKey) (https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/) - Windows Privilege Escalation Zero-Day (GreenPlasma) (https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/) - Critical Outlook Zero-Click RCE (CVE-2026-40361) (https://www.securityweek.com/microsoft-patches-critical-zero-click-outlook-vulnerability-threatening-enterprises/) - The Gentlemen RaaS Internal Database Leaked (https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/) - Foxconn Confirms Nitrogen Ransomware Attack (https://www.bleepingcomputer.com/news/security/electronics-giant-foxconn-confirms-cyberattack-on-north-american-factories/) - Device Code Phishing Campaigns Surge (https://www.proofpoint.com/us/blog/threat-insight/device-code-phishing-evolution-identity-takeover) - Iranian APT Targets South Korean Electronics Manufacturer (https://www.bleepingcomputer.com/news/security/iranian-hackers-targeted-major-south-korean-electronics-maker/) - China-Linked FamousSparrow Targets Azerbaijani Energy Sector (https://www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-apt-south-caucasus-energy-firm) - Microsoft May 2026 Patch Tuesday: 138 Vulnerabilities (https://thehackernews.com/2026/05/microsoft-patches-138-vulnerabilities.html) - Microsoft Fixes BitLocker Recovery Issue on Windows 11 Only (https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bitlocker-recovery-issue-only-for-windows-11-users/) - Fragnesia Linux Kernel Privilege Escalation (CVE-2026-46300) (https://www.bleepingcomputer.com/news/security/new-fragnesia-linux-flaw-lets-attackers-gain-root-privileges/) - Critical Exim Mail Server RCE (CVE-2026-45185) (https://www.bleepingcomputer.com/news/security/new-critical-exim-mailer-flaw-allows-remote-code-execution/) - Google Pixel 10 Zero-Click Exploit Chain (https://projectzero.google/2026/05/pixel-10-exploit.html) - RubyGems Abused as Data Dead Drop (https://www.darkreading.com/application-security/attackers-weaponize-rubygems-data-dead-drops) - Healthcare Lab Fined for Security Failures Before Cyberattack (https://databreaches.net/2026/05/13/nl-dutch-watchdog-says-healthcare-lab-failed-data-security-rules-before-cyberattack-affecting-850000/) - UK Regulator Fines Water Company for Cybersecurity Failures (https://databreaches.net/2026/05/13/uk-regulator-fines-water-company-almost-1m-for-cybersecurity-failures/) CVEs Referenced: CVE-2015-6172, CVE-2024-55591, CVE-2025-32433, CVE-2025-33073, CVE-2025-54957, CVE-2026-33109, CVE-2026-33825, CVE-2026-40361, CVE-2026-40402, CVE-2026-41089, CVE-2026-41096, CVE-2026-42826, CVE-2026-42898, CVE-2026-43284, CVE-2026-43500, CVE-2026-45185, CVE-2026-46300 Full brief: https://carolinacleartech.com/brief/2026-05-14/
-
-36
2026-05-13: Microsoft ships 137 patches with no zero-days for the first time in two years
Show Notes - 2026-05-13 Stories Covered: - May 13, 2026 - Today: - Microsoft Windows Netlogon RCE (CVE-2026-41089) (https://www.darkreading.com/application-security/patch-tuesday-microsoft-zero-day-sight) - Microsoft Windows DNS Client RCE (CVE-2026-41096) (https://www.darkreading.com/application-security/patch-tuesday-microsoft-zero-day-sight) - Exim Mail Server Use-After-Free (CVE-2026-45185) (https://thehackernews.com/2026/05/new-exim-bdat-vulnerability-exposes.html) - Microsoft Entra ID Credential Bypass (CVE-2026-41103) (https://krebsonsecurity.com/2026/05/patch-tuesday-may-2026-edition/) - Foxconn Confirms Ransomware Attack, Nitrogen Gang Claims Data Theft (https://www.theregister.com/cyber-crime/2026/05/12/foxconn-confirms-cyberattack-after-nitrogen-claims-apple-nvidia-data-theft/5239144) - Instructure Pays Ransom to Restore Canvas Platform (https://news.risky.biz/risky-bulletin-rubygems-disables-sign-ups-after-attack-on-staff/) - Supply Chain Attack on npm TanStack Packages (https://news.risky.biz/risky-bulletin-rubygems-disables-sign-ups-after-attack-on-staff/) - RubyGems Disables Sign-Ups After Staff-Targeted Attack (https://news.risky.biz/risky-bulletin-rubygems-disables-sign-ups-after-attack-on-staff/) - Best Western International Data Breach (https://news.risky.biz/risky-bulletin-rubygems-disables-sign-ups-after-attack-on-staff/) - UK Water Utility Fined for 2-Year Breach Detection Failure (https://news.risky.biz/risky-bulletin-rubygems-disables-sign-ups-after-attack-on-staff/) - Microsoft Office Word Preview Pane RCE Vulnerabilities (https://www.darkreading.com/application-security/patch-tuesday-microsoft-zero-day-sight) - Microsoft Dynamics 365 Code Injection (CVE-2026-42898) (https://www.darkreading.com/application-security/patch-tuesday-microsoft-zero-day-sight) - Windows GDI RCE via Malicious EMF Files (CVE-2026-35421) (https://blog.talosintelligence.com/microsoft-patch-tuesday-may-2026/) - Microsoft SharePoint RCE (CVE-2026-40365) (https://blog.talosintelligence.com/microsoft-patch-tuesday-may-2026/) - Azure Critical Vulnerabilities Remediated by Microsoft (https://cyberscoop.com/microsoft-patch-tuesday-may-2026/) - Windows 11 May 2026 Updates (https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5089549-and-kb5087420-cumulative-updates-released/) - Windows 10 Extended Security Update (KB5087544) (https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5087544-extended-security-update/) - AI-Driven Vulnerability Discovery Accelerating Patch Volumes (https://www.darkreading.com/application-security/patch-tuesday-microsoft-zero-day-sight) - CISA Releases SBOM Guidance for AI Systems (https://www.cisa.gov/resources-tools/resources/software-bill-materials-ai-minimum-elements) - Intel and AMD Chipmaker Vulnerabilities (https://www.securityweek.com/chipmaker-patch-tuesday-intel-and-amd-patch-70-vulnerabilities/) - ABB Industrial Control System Vulnerabilities (https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-03) - Siemens, Schneider Electric, and ICS Vendors Publish Patch Tuesday Advisories (https://www.securityweek.com/ics-patch-tuesday-new-security-advisories-from-siemens-schneider-cisa/) CVEs Referenced: CVE-2024-41975, CVE-2025-15467, CVE-2025-2595, CVE-2025-41659, CVE-2025-41691, CVE-2025-4676, CVE-2026-0481, CVE-2026-20794, CVE-2026-26289, CVE-2026-33109, CVE-2026-33570, CVE-2026-33844, CVE-2026-35421, CVE-2026-35504, CVE-2026-35555, CVE-2026-40361, CVE-2026-40364, CVE-2026-40365, CVE-2026-41089, CVE-2026-41096, CVE-2026-41103, CVE-2026-42823, CVE-2026-42826, CVE-2026-42898, CVE-2026-45185 Indicators of Compromise: IPs: 127.0.0.1 Full brief: https://carolinacleartech.com/brief/2026-05-13/
-
-37
2026-05-12: Linux systems face a second privilege escalation exploit in two weeks with Dirty Frag working
Show Notes - 2026-05-12 Stories Covered: - Today: - Linux Dirty Frag Vulnerability (CVE-2026-43284, CVE-2026-43500) (https://arstechnica.com/security/2026/05/linux-bitten-by-second-severe-vulnerability-in-as-many-weeks/) - Active Directory Certificate Services Exploitation (https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/) - Instructure Pays Ransom to ShinyHunters (https://www.bleepingcomputer.com/news/security/instructure-reaches-agreement-with-shinyhunters-to-stop-data-leak/) - The Gentlemen Ransomware Group Suffers Data Breach (https://databreaches.net/2026/05/11/the-gentlemen-ransomware-group-becomes-a-victim/) - State of Ransomware in 2026 (https://securelist.com/state-of-ransomware-in-2026/119761/) - Checkmarx Jenkins Plugin Compromised by TeamPCP (https://www.bleepingcomputer.com/news/security/official-checkmarx-jenkins-package-compromised-with-infostealer/) - Mini Shai-Hulud Worm Spreads Across npm and PyPI (https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html) - GhostLock Tool Abuses Windows API for File Access Denial (https://www.bleepingcomputer.com/news/security/new-ghostlock-tool-abuses-windows-api-to-block-file-access/) - FleetWave Data Breach Confirmed (https://www.theregister.com/cyber-crime/2026/05/12/fleetwave-outage-takes-another-turn-chevin-confirms-crooks-accessed-customer-data/) - State-Sponsored Actors: Long-Term Covert Access (https://blog.talosintelligence.com/state-sponsored-actors-better-known-as-the-friends-you-dont-want/) - FCC Extends Foreign Router Support Deadline (https://www.darkreading.com/endpoint-security/fcc-softens-foreign-router-ban) - OpenAI Launches Daybreak AI Security Platform (https://thehackernews.com/2026/05/openai-launches-daybreak-for-ai-powered.html) - CrowdStrike Automated Leads: AI-Powered Threat Detection (https://www.crowdstrike.com/en-us/blog/ai-threat-detection-with-automated-leads/) - GM Settles California CCPA Violation for $12.75M (https://www.bleepingcomputer.com/news/legal/gm-agrees-to-1275m-california-settlement-over-sale-of-drivers-data/) - Apple and Google Launch Cross-Platform E2EE RCS (https://thehackernews.com/2026/05/ios-265-brings-default-end-to-end.html) - DOJ Charges Premium Home Service with Fake Review Scheme (https://www.justice.gov/opa/pr/department-justice-files-complaint-against-best-gdr-llc-doing-business-premium-home-service) - Fake Claude Code Installers Deliver Credential Stealers (https://www.theregister.com/security/2026/05/11/cookie-thieves-caught-stealing-dev-secrets/) CVEs Referenced: CVE-2022-26923, CVE-2026-43284, CVE-2026-43500, CVE-2026-45321 Full brief: https://carolinacleartech.com/brief/2026-05-12/
-
-38
2026-05-11: Google catches the first confirmed AI-developed zero-day before mass exploitation
Show Notes - 2026-05-11 Stories Covered: - Today: - cPanel CVE-2026-41940 Under Active Exploitation to Deploy Filemanager Backdoor (https://thehackernews.com/2026/05/cpanel-cve-2026-41940-under-active.html) - Google Detects First AI-Developed Zero-Day Exploit (2FA Bypass) (https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access/) - EtherRat and TukTuk C2 End in The Gentlemen Ransomware (https://thedfirreport.com/2026/05/11/flash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/) - The State of Ransomware Q1 2026: Consolidation and The Gentlemen's Breakout (https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/) - Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack (https://www.securityweek.com/checkmarx-jenkins-ast-plugin-compromised-in-supply-chain-attack/) - Build Application Firewalls Aim to Stop Supply Chain Attacks (https://www.securityweek.com/build-application-firewalls-aim-to-stop-the-next-supply-chain-attack/) - Why Changing Passwords Doesn't End an Active Directory Breach (https://www.bleepingcomputer.com/news/security/why-changing-passwords-doesnt-end-an-active-directory-breach/) - AI-Augmented Threat Operations: Autonomous Malware and Defense Evasion (https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access/) - FCC Relaxes Foreign Router Ban to Allow Security Updates Until 2029 (https://news.risky.biz/risky-bulletin-fcc-relaxes-foreign-router-ban-to-allow-for-security-updates/) - ShinyHunters Disrupts US Schools via Instructure Canvas Platform (https://news.risky.biz/risky-bulletin-fcc-relaxes-foreign-router-ban-to-allow-for-security-updates/) - Microsoft Security Update Guide - Linux Kernel CVEs (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-31706) CVEs Referenced: CVE-2025-55182, CVE-2026-31706, CVE-2026-31707, CVE-2026-31709, CVE-2026-31712, CVE-2026-41940, CVE-2026-42246, CVE-2026-43338 Full brief: https://carolinacleartech.com/brief/2026-05-11/
-
-39
2026-05-09: Palo Alto Networks is patching CVE-2026-0300, a critical zero-day in PAN-OS being actively
Show Notes - 2026-05-09 Stories Covered: - May 9, 2026 - Today: - Palo Alto Networks PAN-OS Zero-Day (CVE-2026-0300) (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-19-7/) - Ivanti EPMM Zero-Day Exploited (CVE-2026-6973) (https://www.bleepingcomputer.com/news/security/cisa-gives-feds-four-days-to-patch-ivanti-flaw-exploited-as-zero-day/) - Dirty Frag Linux Privilege Escalation Under Active Exploitation (https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/) - BerriAI LiteLLM SQL Injection (CVE-2026-42208) (https://www.cisa.gov/news-events/alerts/2026/05/08/cisa-adds-one-known-exploited-vulnerability-catalog) - Karakurt Extortion Negotiator Sentenced to 9 Years (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-19-7/) - North Korean IT Worker Laptop Farm Operators Sentenced (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-19-7/) - RansomHouse Claims Trellix Source Code Breach (https://www.bleepingcomputer.com/news/security/trellix-source-code-breach-claimed-by-ransomhouse-hackers/) - ShinyHunters Second Breach of Instructure Canvas (https://www.darkreading.com/cyberattacks-data-breaches/shinyhunters-second-attack-instructure) - PCPJack Cloud Worm Evicts TeamPCP, Harvests Credentials (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-19-7/) - Poland Documents ICS Breaches at Five Water Treatment Plants (https://www.securityweek.com/polish-security-agency-reports-ics-breaches-at-five-water-treatment-plants/) - Zara Breach Exposes 197,000 Customer Records (https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/) - NVIDIA GeForce NOW Armenian Partner Breach (https://www.bleepingcomputer.com/news/security/nvidia-confirms-geforce-now-data-breach-affecting-armenian-users/) - AI Platform Braintrust Breach Exposes Customer API Keys (https://www.securityweek.com/ai-firm-braintrust-prompts-api-key-rotation-after-data-breach/) - TCLBANKER Banking Trojan Spreads via WhatsApp and Outlook (https://thehackernews.com/2026/05/tclbanker-banking-trojan-targets.html) - Quasar Linux RAT Targets Developer Credentials for Supply Chain Attacks (https://thehackernews.com/2026/05/quasar-linux-rat-steals-developer.html) - PamDOORa Linux Backdoor Advertised for $900 (https://thehackernews.com/2026/05/new-linux-pamdoora-backdoor-uses-pam.html) - SOC Alert Backlogs Hiding Real Threats (https://thehackernews.com/2026/05/one-missed-threat-per-week-what-25m.html) - Fake Android Call History Apps Steal $7.3M in Subscriptions (https://thehackernews.com/2026/05/fake-call-history-apps-stole-payments.html) - cPanel and WHM Patch Three Vulnerabilities (https://thehackernews.com/2026/05/cpanel-whm-patch-3-new-vulnerabilities.html) CVEs Referenced: CVE-2026-0300, CVE-2026-1281, CVE-2026-1340, CVE-2026-29201, CVE-2026-29202, CVE-2026-29203, CVE-2026-41940, CVE-2026-42208, CVE-2026-43284, CVE-2026-43500, CVE-2026-6973 Indicators of Compromise: IPs: 12.8.0.0, 12.6.1.1, 12.7.0.1, 12.8.0.1, 11.136.0.9 Full brief: https://carolinacleartech.com/brief/2026-05-09/
-
-40
2026-05-08: Ivanti ships its third EPMM zero-day patch of 2026 (CVE-2026-6973, active exploitation confirmed)
Show Notes - 2026-05-08 Stories Covered: - Today: - Ivanti EPMM Zero-Day (CVE-2026-6973) (https://cyberscoop.com/ivanti-epmm-zero-day-vulnerability-exploited/) - Palo Alto Networks Firewall Zero-Day (CVE-2026-0300) (https://www.bleepingcomputer.com/news/security/pan-os-firewall-rce-zero-day-exploited-in-attacks-since-april-9/) - Linux Dirty Frag Zero-Day (No CVE Assigned) (https://www.bleepingcomputer.com/news/security/new-linux-dirty-frag-zero-day-with-poc-exploit-gives-root-privileges/) - RansomHouse Claims Trellix Breach (https://www.securityweek.com/ransomware-group-takes-credit-for-trellix-hack/) - TCLBanker Malware Spreads via WhatsApp and Outlook (https://www.bleepingcomputer.com/news/security/new-tclbanker-malware-self-spreads-over-whatsapp-and-outlook/) - Microsoft Expands Passkey Support (https://www.microsoft.com/en-us/security/blog/2026/05/07/world-passkey-day-advancing-passwordless-authentication/) - AI Agent Framework RCE Vulnerabilities (https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/) - Android ADB Authentication Bypass (CVE-2026-0073) (https://news.risky.biz/risky-bulletin-google-patches-android-remote-takeover-bug/) - Microsoft May 2026 Security Updates (https://msrc.microsoft.com/update-guide/) CVEs Referenced: CVE-2026-0073, CVE-2026-0300, CVE-2026-1281, CVE-2026-1340, CVE-2026-23631, CVE-2026-25243, CVE-2026-25592, CVE-2026-26030, CVE-2026-26164, CVE-2026-31431, CVE-2026-33109, CVE-2026-40379, CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, CVE-2026-6973, CVE-2026-7821, CVE-2026-7973, CVE-2026-7982, CVE-2026-7988, CVE-2026-7995, CVE-2026-8013, CVE-2026-8016, CVE-2026-8017, CVE-2026-8019, CVE-2026-8021, CVE-2026-8022 Indicators of Compromise: IPs: 12.6.1.1, 12.7.0.1, 12.8.0.1 Full brief: https://carolinacleartech.com/brief/2026-05-08/
-
-41
2026-05-07: Iranian state-sponsored actors are masquerading ransomware attacks to hide espionage operations
Show Notes - 2026-05-07 Stories Covered: - Today: - Palo Alto PAN-OS Zero-Day Exploitation (CVE-2026-0300) (https://cyberscoop.com/palo-alto-networks-pan-os-firewall-zero-day-vulnerability-exploited/) - MuddyWater Uses Chaos Ransomware Brand as False Flag (https://thehackernews.com/2026/05/muddywater-uses-microsoft-teams-to.html) - Why Backups Fail During Ransomware Attacks (https://www.bleepingcomputer.com/news/security/why-ransomware-attacks-succeed-even-when-backups-exist/) - Threat Activity Enablers: Infrastructure Backbone for Ransomware and Botnets (https://www.recordedfuture.com/blog/threat-activity-enablers) - Real Estate Giant Confirms Vishing Incident as ShinyHunters and Qilin Claim Involvement (https://www.theregister.com/security/2026/05/05/cushman-wakefield-confirms-vishing-cyberattack/5228718) - Vendor Breach Litigation: Banks Face Lawsuits After Third-Party Provider Incidents (https://databreaches.net/2026/05/06/when-your-vendors-breach-becomes-your-lawsuit-privacy-risk-lessons-from-recent-bank-litigation/?pk_campaign=feed&pk_kwd=when-your-vendors-breach-becomes-your-lawsuit-privacy-risk-lessons-from-recent-bank-litigation) - AI Agent Identity Governance Gap (https://thehackernews.com/2026/05/your-ai-agents-are-already-inside.html) - CopyFail Linux Flaw Under Active Exploitation (https://www.theregister.com/security/2026/05/05/copyfail-attackers-start-cashing-in-on-linux-flaw/5226930) - GnuTLS Certificate and DTLS Vulnerabilities (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-3832) - CoreDNS Authentication and DoS Vulnerabilities (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33190) - Prometheus Configuration and DoS Issues (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42151) - Additional CVE Disclosures (https://msrc.microsoft.com/update-guide/) CVEs Referenced: CVE-2020-13949, CVE-2026-0300, CVE-2026-32934, CVE-2026-32936, CVE-2026-33190, CVE-2026-33489, CVE-2026-33845, CVE-2026-3832, CVE-2026-3833, CVE-2026-42151, CVE-2026-42154, CVE-2026-43185, CVE-2026-43868, CVE-2026-6383 Full brief: https://carolinacleartech.com/brief/2026-05-07/
-
-42
2026-05-06: Palo Alto Networks firewalls face active zero-day exploitation targeting exposed authentication
Show Notes - 2026-05-06 Stories Covered: - Today: - Palo Alto Networks PAN-OS Zero-Day Exploited (CVE-2026-0300) (https://www.securityweek.com/palo-alto-networks-to-patch-zero-day-exploited-to-hack-firewalls/) - Apache HTTP Server Double-Free Leads to DoS and RCE (CVE-2026-23918) (https://thehackernews.com/2026/05/critical-apache-http2-flaw-cve-2026.html) - Android Critical RCE Patched (CVE-2026-0073) (https://www.securityweek.com/critical-remote-code-execution-vulnerability-patched-in-android-2/) - Karakurt Ransomware Negotiator Sentenced to 8.5 Years (https://cyberscoop.com/latvian-russia-ransomware-conti-sentenced/) - CloudZ RAT Abuses Windows Phone Link to Steal OTPs (https://thehackernews.com/2026/05/windows-phone-link-exploited-by-cloudz.html) - DAEMON Tools Supply Chain Attack Delivers Signed Backdoor (https://thehackernews.com/2026/05/daemon-tools-supply-chain-attack.html) - Microsoft Warns of Sophisticated AiTM Phishing Campaign (https://www.securityweek.com/microsoft-warns-of-sophisticated-phishing-campaign-targeting-us-organizations/) - Microsoft Edge Stores All Passwords in Cleartext Memory (https://www.darkreading.com/cyber-risk/microsoft-edge-passwords-enterprise-risk) - OAuth Grants Create Persistent Backdoor in Enterprise Environments (https://thehackernews.com/2026/05/the-back-door-attackers-know-about-and.html) - MetInfo CMS Remote Code Execution Exploited (CVE-2026-29014) (https://thehackernews.com/2026/05/metinfo-cms-cve-2026-29014-exploited.html) - Google Expands Binary Transparency for Android Apps (https://thehackernews.com/2026/05/android-apps-get-public-verification.html) - Quasar Linux Malware Targets Software Developers (https://www.bleepingcomputer.com/news/security/new-stealthy-quasar-linux-malware-targets-software-developers/) - DarkSword iOS Exploit Chain (https://www.schneier.com/blog/archives/2026/05/darksword-malware.html) - Trellix Source Code Breach (https://www.darkreading.com/cyberattacks-data-breaches/trellix-source-code-breach-supply-chain-threats) - Instructure Breach Claims 280M Records (https://www.bleepingcomputer.com/news/security/instructure-hacker-claims-data-theft-from-8-800-schools-universities/) - Copy Fail Linux Kernel Vulnerability (CVE-2026-31431) (https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/) - ICS Vulnerabilities (https://www.cisa.gov/news-events/ics-advisories/) - SSL.com Root Certificate Rotation (https://isc.sans.edu/diary/rss/32956) - Microsoft CVE Disclosures (https://msrc.microsoft.com/update-guide/) CVEs Referenced: CVE-2018-1002208, CVE-2024-43093, CVE-2024-50302, CVE-2025-11043, CVE-2025-38352, CVE-2025-48543, CVE-2026-0073, CVE-2026-0300, CVE-2026-0936, CVE-2026-21661, CVE-2026-23918, CVE-2026-29014, CVE-2026-31431, CVE-2026-43037, CVE-2026-43964 Indicators of Compromise: Domains: daemontools[.]cc, daemontools[.]cc. Full brief: https://carolinacleartech.com/brief/2026-05-06/
-
-43
2026-05-05: cPanel exploitation reaches thousands of servers with Mirai and ransomware payloads
Show Notes - 2026-05-05 Stories Covered: - May 5, 2026 - Today: - cPanel Authentication Bypass (CVE-2026-41940) Exploited at Scale (https://thehackernews.com/2026/05/critical-cpanel-vulnerability.html) - Copy Fail Linux Privilege Escalation (CVE-2026-31431) Under Active Exploitation (https://www.bleepingcomputer.com/news/security/cisa-says-copy-fail-flaw-now-exploited-to-root-linux-systems/) - Karakurt Member Sentenced to 102 Months (https://databreaches.net/2026/05/04/latvian-national-involved-with-karakurt-and-other-ransomware-gangs-sentenced-for-his-role-in-ransomware-organization/) - RMM Tools Abused in VENOMOUS#HELPER Phishing Campaign (https://www.darkreading.com/cyberattacks-data-breaches/rmm-tools-stealthy-phishing-campaign) - Vishing Groups Operate Within SaaS Environments (https://thehackernews.com/2026/05/weekly-recap-ai-powered-phishing.html) - TeamPCP Mini Shai-Hulud Worm Campaign (Week of April 27-May 3) (https://isc.sans.edu/diary/rss/32950) - DigiCert Revokes 60 Certificates After Support Portal Compromise (https://www.securityweek.com/digicert-revokes-certificates-after-support-portal-hack/) - Amazon SES Abused for Phishing at Scale (https://www.bleepingcomputer.com/news/security/amazon-ses-increasingly-abused-in-phishing-to-evade-detection/) - Trellix Discloses Source Code Repository Breach (https://www.bleepingcomputer.com/news/security/trellix-discloses-data-breach-after-source-code-repository-hack/) - Code of Conduct Phishing Campaign Targets 35,000 Users with AiTM Token Theft (https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/) - April Windows Updates Cause Backup Failures (https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-backup-failures-caused-by-vulnerable-driver-block/) - Weaver E-cology RCE (CVE-2026-22679) Exploited Since March (https://thehackernews.com/2026/05/weaver-e-cology-rce-flaw-cve-2026-22679.html) - ScarCruft Deploys BirdCall Android Malware via Supply Chain Attack (https://www.bleepingcomputer.com/news/security/scarcruft-hackers-push-birdcall-android-malware-via-game-platform/) - Cisco Acquires Astrix Security for Non-Human Identity Management (https://www.securityweek.com/cisco-moves-to-acquire-astrix-security-to-tackle-non-human-identity-risks/) - MOVEit Automation Critical Authentication Bypass (CVE-2026-4670) (https://www.bleepingcomputer.com/news/security/moveit-automation-customers-warned-to-patch-critical-auth-bypass-flaw/) - Microsoft CVEs Published with Minimal Details (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42798) CVEs Referenced: CVE-2023-43896, CVE-2024-1708, CVE-2026-22679, CVE-2026-31431, CVE-2026-32202, CVE-2026-37457, CVE-2026-40170, CVE-2026-41940, CVE-2026-42798, CVE-2026-4670, CVE-2026-5174 Indicators of Compromise: IPs: 95.111.250.175 Full brief: https://carolinacleartech.com/brief/2026-05-05/
-
-44
2026-05-04: cPanel zero-day exploitation hits over 40,000 servers with CISA KEV deadline this week
Show Notes - 2026-05-04 Stories Covered: - Today: - cPanel Zero-Day Exploitation (CVE-2026-41940) (https://www.securityweek.com/over-40000-servers-compromised-in-ongoing-cpanel-exploitation/) - Instructure Canvas Data Breach (ShinyHunters Claims) (https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/) - DigiCert Code Signing Certificate Theft (https://news.risky.biz/risky-bulletin-digicert-hacked-with-a-malicious-screensaver-file/) - Microsoft Defender False Positive on DigiCert Certificates (https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/) - Telegram Mini Apps Used for Crypto Scams and Malware (https://www.bleepingcomputer.com/news/security/telegram-mini-apps-abused-for-crypto-scams-android-malware-delivery/) - Public Voter Records as Re-identification Attack Surface (https://go.theregister.com/feed/www.theregister.com/2026/05/04/public_voter_records_weaponized_for_privacy_violation/) - Five Eyes Agencies Warn on Agentic AI Risks (https://go.theregister.com/feed/www.theregister.com/2026/05/04/five_eyes_agentic_ai_recommendations/) - OpenAI Advanced Account Security for High-Risk Users (https://www.securityweek.com/openai-rolls-out-advanced-security-for-chatgpt-accounts/) - Global Crypto Scam Center Crackdown (276 Arrests) (https://thehackernews.com/2026/05/global-crackdown-arrests-276-shuts-9.html) - Wireshark 4.6.5 Released (https://isc.sans.edu/diary/rss/32944) CVEs Referenced: CVE-2026-41940 Indicators of Compromise: IPs: 11.86.0.41, 11.110.0.97, 11.118.0.63, 11.124.0.35, 11.126.0.54, 11.130.0.19, 11.132.0.29, 11.134.0.20, 11.136.0.5 Full brief: https://carolinacleartech.com/brief/2026-05-04/
-
-45
2026-05-02: Linux kernel privilege escalation vulnerability CVE-2026-31431 hits CISA's KEV catalog with a May
Show Notes - 2026-05-02 Stories Covered: - May 2, 2026 - Today: - CVE-2026-31431: Linux Kernel Copy Fail Privilege Escalation (CISA KEV) (https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/) - CVE-2026-41940: Critical cPanel Remote Code Execution Under Active Exploitation (https://go.theregister.com/feed/www.theregister.com/2026/05/01/critical_cpanel_vuln_hits_cisa/) - Two Cybersecurity Professionals Sentenced for BlackCat Ransomware Deployment (https://thehackernews.com/2026/05/two-cybersecurity-professionals-get-4.html) - Cordial Spider and Snarky Spider: Rapid SaaS Extortion Through Vishing and SSO Abuse (https://thehackernews.com/2026/05/cybercrime-groups-using-vishing-and-sso.html) - New York DFS Secures $2.25 Million Settlement from Delta Dental Over MOVEit Breach (https://databreaches.net/2026/05/01/nysdfs-secures-2-25-million-cybersecurity-settlement-with-delta-dental/?pk_campaign=feed&pk_kwd=nysdfs-secures-2-25-million-cybersecurity-settlement-with-delta-dental) - ClickFix Campaign Delivers CastleLoader and NetSupportRAT via Fake Background Removal Sites (https://www.huntress.com/blog/clickfix-castleloader-backgroundfix) - MacSync Stealer Distributed Through Malicious Homebrew Ads (https://isc.sans.edu/diary/rss/32942) - 30,000 Facebook Accounts Compromised in Vietnamese Google AppSheet Phishing Operation (https://thehackernews.com/2026/05/30000-facebook-accounts-hacked-via.html) - China-Aligned Espionage Campaign Targets Asian Governments, NATO Member, Journalists (https://thehackernews.com/2026/05/china-linked-hackers-target-asian.html) - Instructure (Canvas LMS) Discloses Cybersecurity Incident (https://www.bleepingcomputer.com/news/security/edu-tech-firm-instructure-discloses-cyber-incident-probes-impact/) - Trellix Confirms Source Code Breach With Unauthorized Repository Access (https://thehackernews.com/2026/05/trellix-confirms-source-code-breach.html) - AI Coding Agents Deleting Production Databases (https://www.darkreading.com/cloud-security/ais-so-smart-keep-deleting-production-databases) - Microsoft Agent 365 Now Generally Available for Agent Security and Governance (https://www.microsoft.com/en-us/security/blog/2026/05/01/microsoft-agent-365-now-generally-available-expands-capabilities-and-integrations/) - Microsoft Allows Dynamic Removal of Pre-Installed Store Apps via GPO (https://www.bleepingcomputer.com/news/microsoft/microsoft-now-lets-admins-choose-pre-installed-store-apps-to-uninstall/) - Microsoft Fixes Remote Desktop Security Warning Display Bug (https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-remote-desktop-warnings-displaying-incorrectly/) - CISA and International Partners Release Agentic AI Security Guidance (https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services) - UK NCSC Warns of AI-Driven Patch Tsunami (https://go.theregister.com/feed/www.theregister.com/2026/05/02/ncsc_brace_for_patch_tsunami/) - OpenAI Restricts GPT-5.5-Cyber Access After Criticizing Anthropic for Same Approach (https://go.theregister.com/feed/www.theregister.com/2026/05/01/openai_locks_gpt55cyber_behind_velvet/) - Social Engineering Evolves Beyond Traditional Phishing (https://www.huntress.com/blog/device-code-phishing-cyber-resilience-strategy) - 15-Year-Old Detained Over French Government Agency Data Breach (https://www.bleepingcomputer.com/news/security/15-year-old-detained-over-french-govt-agency-data-breach/) - Cisco Releases Open Source Model Provenance Kit (https://www.securityweek.com/cisco-releases-open-source-tool-for-ai-model-provenance/) - CVE-2026-4948: Firewalld D-Bus Authorization Bypass (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-4948) - CVE-2026-28532: FRRouting Integer Overflow in OSPF TLV Parser (https://msrc.microsoft.com/update-guide/vulnerability/CVE-202 ...
-
-46
2026-05-01: cPanel's CVE-2026-41940 authentication bypass is being actively exploited after months as a
Show Notes - 2026-05-01 Stories Covered: - Today: - cPanel and WHM Authentication Bypass (CVE-2026-41940) (https://www.cisa.gov/news-events/alerts/2026/04/30/cisa-adds-one-known-exploited-vulnerability-catalog) - Linux Copy Fail Local Privilege Escalation (CVE-2026-31431) (https://www.bleepingcomputer.com/news/security/new-linux-copy-fail-flaw-gives-hackers-root-on-major-distros/) - Former Incident Responders Sentenced for BlackCat Attacks (https://www.bleepingcomputer.com/news/security/us-ransomware-negotiators-get-4-years-in-prison-over-blackcat-attacks/) - New Scattered Spider-Affiliated Extortion Groups (https://cyberscoop.com/crowdstrike-cordial-spider-snarky-spider-extortion-attacks/) - PyTorch Lightning Supply Chain Attack (https://thehackernews.com/2026/04/pytorch-lightning-compromised-in-pypi.html) - SAP npm Packages Compromised in Mini Shai-Hulud Campaign (https://go.theregister.com/feed/www.theregister.com/2026/04/30/supply_chain_attacks_sap_npm_packages/) - Ruby Gems and Go Modules Supply Chain Attack (https://thehackernews.com/2026/05/poisoned-ruby-gems-and-go-modules.html) - Intercom-client npm Package Compromised (https://go.theregister.com/feed/www.theregister.com/2026/04/30/supply_chain_attacks_sap_npm_packages/) - AI Phishing Campaigns Dominate Threat Landscape (https://go.theregister.com/feed/www.theregister.com/2026/04/30/modern_phishing_campaigns_ai/) - 18 AI Browser Extensions Deliver RATs and Infostealers (https://unit42.paloaltonetworks.com/high-risk-gen-ai-browser-extensions/) - Gemini CLI Vulnerability Enabled Supply Chain Attacks (https://www.securityweek.com/critical-gemini-cli-flaw-enabled-host-code-execution-supply-chain-attacks/) - Windows 11 KB5083631 Optional Update Released (https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5083631-update-released-with-34-changes-and-fixes/) - April KB5083769 Update Breaks Backup Software (https://www.bleepingcomputer.com/news/microsoft/april-kb5083769-windows-11-update-causes-backup-software-failures/) - SonicWall Firewall Vulnerabilities (https://www.securityweek.com/sonicwall-urges-immediate-patching-of-firewall-vulnerabilities/) - ABB Ability Symphony Plus PostgreSQL Vulnerabilities (https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-06) - ABB Ability OPTIMAX Azure AD Authentication Bypass (https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-04) - Versus Project Marketplace Operator Extradited (https://databreaches.net/2026/04/30/versus-project-marketplace-creator-and-operator-extradited-from-colombia-to-the-united-states/) - Transnational Business Email Compromise Scheme (https://www.justice.gov/usao-sdfl/pr/transnational-email-fraud-scheme-nets-prison-terms-four-defendants) - 15-Year-Old Arrested in French Government Data Leak (https://databreaches.net/2026/04/30/15-year-old-arrested-in-massive-french-government-data-leak/) - DPRK IT Worker Fraud and Insider Risk (https://databreaches.net/2026/04/30/the-human-element-dprk-it-worker-fraud-and-insider-risk/) CVEs Referenced: CVE-2023-39417, CVE-2023-5869, CVE-2024-30098, CVE-2025-14510, CVE-2026-0204, CVE-2026-0205, CVE-2026-0206, CVE-2026-31431, CVE-2026-41940 Indicators of Compromise: IPs: 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5, 11.136.1.7, 6.5.5.2, 6.5.5.1 Full brief: https://carolinacleartech.com/brief/2026-05-01/
-
-47
2026-04-30: Microsoft's February patch for a Russian zero-day fell short
Show Notes - 2026-04-30 Stories Covered: - Today: - Microsoft Windows CVE-2026-32202: Incomplete Patch Creates Zero-Click Credential Theft Flaw (https://go.theregister.com/feed/www.theregister.com/2026/04/29/microsoft_zero_click_exploit/) - GitHub CVE-2026-3854: Critical RCE Allowed Access to Millions of Private Repos (https://www.bleepingcomputer.com/news/security/github-fixes-rce-flaw-that-gave-access-to-millions-of-private-repos/) - Linux CVE-2026-31431 (Copy Fail): Root Privilege Escalation in All Distributions Since 2017 (https://thehackernews.com/2026/04/new-linux-copy-fail-vulnerability.html) - Vect 2.0 Ransomware Functions as Wiper Due to Design Flaw (https://www.darkreading.com/threat-intelligence/vect-ransomware-wiper-design-error) - Sandhills Medical Foundation Breach Affects 170,000 (https://www.securityweek.com/sandhills-medical-says-ransomware-breach-affects-170000/) - Pine Bluff School District Loses $3.2 Million in Business Email Compromise (https://databreaches.net/2026/04/29/ar-pine-bluff-school-district-loses-3-2-million-in-business-email-compromise-attack/) - TeamPCP Supply Chain Attack Targets SAP npm Packages with Credential Stealer (https://thehackernews.com/2026/04/sap-npm-packages-compromised-by-mini.html) - Checkmarx Data Stolen in TeamPCP Supply Chain Attack (https://www.securityweek.com/checkmarx-confirms-data-stolen-in-supply-chain-attack/) - Claude Mythos Finds 271 Zero-Days in Firefox (https://www.schneier.com/blog/archives/2026/04/claude-mythos-has-found-271-zero-days-in-firefox.html) - GitHub Apologizes as Uptime Drops Below 85% (https://go.theregister.com/feed/www.theregister.com/2026/04/29/github_says_sorry_and_says/) - AWS Engineers: AI Development Requires Human Review for Everything (https://go.theregister.com/feed/www.theregister.com/2026/04/29/aws_keynote_hypes_ai_magic/) - CISA Releases Zero Trust Guidance for Operational Technology (https://www.cisa.gov/resources-tools/resources/adapting-zero-trust-principles-operational-technology) - AI Agent Identity Security Gap Emerging (https://cyberscoop.com/ai-agent-identity-security-anthropic-mythos/) - Microsoft to Block TLS 1.0/1.1 on Exchange Online POP3/IMAP4 in July 2026 (https://go.theregister.com/feed/www.theregister.com/2026/04/29/exchange_online_blocks_old_versions/) - CVE-2026-32202: Windows Shell Authentication Coercion (Zero-Day) - CVE-2026-3854: GitHub Remote Code Execution (Critical) - CVE-2026-31431: Linux Copy Fail Privilege Escalation (High) - Apache Thrift, Log4j, Python, and PostCSS Vulnerabilities CVEs Referenced: CVE-2022-0847, CVE-2024-41045, CVE-2024-41067, CVE-2024-41932, CVE-2024-57974, CVE-2024-57976, CVE-2025-48431, CVE-2026-21510, CVE-2026-21513, CVE-2026-31431, CVE-2026-31499, CVE-2026-31508, CVE-2026-31540, CVE-2026-31545, CVE-2026-31546, CVE-2026-32202, CVE-2026-3298, CVE-2026-34477, CVE-2026-3854, CVE-2026-41305, CVE-2026-41602, CVE-2026-41603, CVE-2026-41604, CVE-2026-41607, CVE-2026-41636, CVE-2026-6238, CVE-2026-6357 Full brief: https://carolinacleartech.com/brief/2026-04-30/
-
-48
2026-04-29: CISA adds exploited ConnectWise and Windows flaws to KEV catalog
Show Notes - 2026-04-29 Stories Covered: - Today: - CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV (CVE-2024-1708, CVE-2026-32202) (https://thehackernews.com/2026/04/cisa-adds-actively-exploited.html) - Critical GitHub Vulnerability Exposed Millions of Repositories (CVE-2026-3854) (https://thehackernews.com/2026/04/researchers-discover-critical-github.html) - LiteLLM SQL Injection Exploited Within 36 Hours (CVE-2026-42208) (https://thehackernews.com/2026/04/litellm-cve-2026-42208-sql-injection.html) - VECT 2.0 Ransomware Acts as Data Wiper for Large Files (https://thehackernews.com/2026/04/vect-20-ransomware-irreversibly.html) - Feuding Ransomware Groups Leak Each Other's Data (https://www.darkreading.com/threat-intelligence/feuding-ransomware-groups-leak-data) - Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain (https://www.darkreading.com/application-security/fresh-glassworm-vs-code-extensions-supply-chain) - Cyber Insurance Data Highlights MFA Misconfiguration as Top Loss Driver (https://www.securityweek.com/cyber-insurance-data-gives-cisos-new-ammo-for-budget-talks/) - Microsoft Outlook for iOS Still Down After Service Change (https://go.theregister.com/feed/www.theregister.com/2026/04/28/a_service_change_takes_down/) - Microsoft Teams Free Backend Change Broke Chat and Calls (https://www.bleepingcomputer.com/news/security/microsoft-says-backend-change-broke-teams-free-chat-and-calls/) - OpenAI Models Now Available on AWS Bedrock (https://go.theregister.com/feed/www.theregister.com/2026/04/28/openai_climbs_into_amazons_bedrock/) - Critical Unpatched Flaw in Hugging Face LeRobot (CVE-2026-25874) (https://thehackernews.com/2026/04/critical-cve-2026-25874-leaves-hugging.html) - Microsoft to Deprecate Legacy TLS in Exchange Online Starting July (https://www.bleepingcomputer.com/news/microsoft/microsoft-to-deprecate-legacy-tls-in-exchange-online-starting-july/) CVEs Referenced: CVE-2024-1708, CVE-2024-1709, CVE-2026-21510, CVE-2026-21513, CVE-2026-25874, CVE-2026-32202, CVE-2026-3854, CVE-2026-42208 Indicators of Compromise: IPs: 65.111.27.132 Full brief: https://carolinacleartech.com/brief/2026-04-29/
-
-49
2026-04-28: Supply chain attacks accelerate with a 26-day pause ending in coordinated compromises across npm
Show Notes - 2026-04-28 Stories Covered: - Today: - Windows Shell Credential Theft (CVE-2026-32202) (https://thehackernews.com/2026/04/microsoft-confirms-active-exploitation.html) - ASP.NET Core Privilege Escalation (CVE-2026-40372) (https://research.checkpoint.com/2026/27th-april-threat-intelligence-report/) - D-Link Router Botnet Exploitation (CVE-2025-29635) (https://research.checkpoint.com/2026/27th-april-threat-intelligence-report/) - React2Shell Exploitation (CVE-2025-55182) (https://research.checkpoint.com/2026/27th-april-threat-intelligence-report/) - LMDeploy SSRF Under Active Exploitation (CVE-2026-33626) (https://research.checkpoint.com/2026/27th-april-threat-intelligence-report/) - OpenSSH 15-Year-Old Root Access Flaw (CVE-2026-35414) (https://www.securityweek.com/openssh-flaw-allowing-full-root-shell-access-lurked-for-15-years/) - Akira Dominates Cyber Insurance Claims via SonicWall (https://databreaches.net/2026/04/27/one-ransomware-crew-now-drives-half-of-all-cyber-claims-at-bay/) - TeamPCP Supply Chain Campaign Resumes After 26-Day Pause (https://isc.sans.edu/diary/rss/32926) - Elementary-Data PyPI Package Compromised (https://www.bleepingcomputer.com/news/security/pypi-package-with-11m-monthly-downloads-hacked-to-push-infostealer/) - GlassWorm v2 Targets OpenVSX with 73 Sleeper Extensions (https://www.bleepingcomputer.com/news/security/glassworm-malware-attacks-return-via-73-openvsx-sleeper-extensions/) - ShinyHunters Breaches ADT and Medtronic (https://www.bleepingcomputer.com/news/security/home-security-giant-adt-data-breach-affects-55-million-people/) - FIRESTARTER Backdoor on Federal Cisco ASA (https://thehackernews.com/2026/04/weekly-recap-fast16-malware-xchat.html) - UNC6692 Deploys Custom Snow Malware Suite via Teams Impersonation (https://thehackernews.com/2026/04/weekly-recap-fast16-malware-xchat.html) - PhantomCore Exploits TrueConf for Russian Network Breaches (https://thehackernews.com/2026/04/phantomcore-exploits-trueconf.html) - Cursor-Opus AI Agent Deletes Production Database (https://go.theregister.com/feed/www.theregister.com/2026/04/27/cursoropus_agent_snuffs_out_pocketos/) - Robinhood Account Creation Exploited for Phishing (https://www.bleepingcomputer.com/news/security/robinhood-account-creation-flaw-abused-to-send-phishing-emails/) - Silk Typhoon Hacker Extradited to US (https://www.bleepingcomputer.com/news/security/alleged-silk-typhoon-hacker-extradited-to-us-for-cyberespionage/) - Microsoft Entra ID Agent ID Administrator Privilege Escalation (https://thehackernews.com/2026/04/microsoft-patches-entra-id-role-flaw.html) - Unpatched PhantomRPC Windows Privilege Escalation (https://www.darkreading.com/vulnerabilities-threats/unpatched-phantomrpc-flaw-windows-privilege-escalation) - Microsoft Remote Desktop Warning Display Issue (https://www.bleepingcomputer.com/news/microsoft/microsoft-new-remote-desktop-warnings-may-display-incorrectly/) - Outlook.com Outage Causes Sign-In Failures (https://www.bleepingcomputer.com/news/microsoft/microsoft-says-outlookcom-outage-is-causing-sign-in-failures/) - Canada Arrests Three for SMS Blaster Device (https://www.bleepingcomputer.com/news/security/canada-arrests-three-for-operating-sms-blaster-device-in-toronto/) - FTC Warns of $2.1 Billion in Social Media Scam Losses (https://www.bleepingcomputer.com/news/security/ftc-americans-lost-over-21-billion-to-social-media-scams-in-2025/) - Deepfake Voice Attacks Outpacing Defenses (https://www.bleepingcomputer.com/news/security/deepfake-voice-attacks-are-outpacing-defenses-what-security-leaders-should-know/) - Cybersecurity Professionals Face Pay Stagnation (https://go.theregister.com/feed/www.theregister.com/2026/04/27/from_a_massive_skills_gap/) - Fast16 Malware Predates Stuxnet by Five Years (https://thehackernews.com/2026/04/weekly-recap-fast16-malware-xchat.html) - Apple iOS Notification Services (CVE-20 ...
We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.
No matches for "" in this podcast's transcripts.
No topics indexed yet for this podcast.
Loading reviews...
ABOUT THIS SHOW
Your daily cybersecurity briefing. Vulnerabilities, ransomware, threat actors, and patches that matter, explained for IT professionals and business leaders protecting small and mid-sized organizations. From Carolina Clear Tech.
HOSTED BY
Carolina Clear Tech, LLC
CATEGORIES
Loading similar podcasts...