Cyber Threat Brief

2026-06-07: WordPress site takeovers are spreading via a critical Everest Forms Pro exploit that creates rogue

15 min · 7. juni 2026
episode 2026-06-07: WordPress site takeovers are spreading via a critical Everest Forms Pro exploit that creates rogue cover

Description

SHOW NOTES - 2026-06-07 STORIES COVERED * 2026-06-07 * Today: * Cisco SD-WAN Zero-Day Under Active Attack [https://www.theregister.com/personal-tech/2026/06/07/uk-exam-watchdog-frets-over-smart-specs-turning-gcses-into-google-searches/5251365] [Critical Alerts] * Critical Everest Forms Pro Flaw Exploited to Take Over WordPress Sites (CVE-2026-3300) [https://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites/] [Critical Alerts] * Exposed Fuel Tank Gauges Under Attack in the US [https://www.darkreading.com/cyberattacks-data-breaches/exposed-fuel-tank-gauges-attack-us] [Critical Alerts] * Adaptive AI Worms Loom as Next Enterprise Threat [https://www.darkreading.com/cyber-risk/adaptive-agentic-ai-worms-enterprise-cyber-threat] [Business & Infrastructure Threats] * ChatGPT Lockdown Mode Limits Data Exfiltration Tools [https://thehackernews.com/2026/06/new-chatgpt-lockdown-mode-limits-tools.html] [Business & Infrastructure Threats] * CVE-2026-3300: Everest Forms Pro Unauthenticated RCE [https://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites/] [Vulnerability Disclosures] * CVE-2026-50219: libexpat Use-After-Free Vulnerability [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50219] [Vulnerability Disclosures] * CVE-2026-8643: pip Path Traversal in Script Installation [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8643] [Vulnerability Disclosures] * CVE-2026-7774: Python tarfile Path Traversal Bypass [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-7774] [Vulnerability Disclosures] * CVE-2026-11332: Ansible-core Argument Injection in ansible-galaxy [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-11332] [Vulnerability Disclosures] * CVE-2026-3276: Python DoS via Quadratic Complexity in unicodedata.normalize() [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-3276] [Vulnerability Disclosures] * CVE-2026-43958: RRDtool Stack Buffer Overflow [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43958] [Vulnerability Disclosures] * CVE-2026-10722: cilium eBPF Integer Overflow [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-10722] [Vulnerability Disclosures] * CVE-2026-37460: FRRouting BGP DoS Vulnerability [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-37460] [Vulnerability Disclosures] * CVE-2026-42504: Go mime Package Quadratic Complexity DoS [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42504] [Vulnerability Disclosures] * CVE-2026-42507: Go net/textproto Unescaped Input in Errors [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42507] [Vulnerability Disclosures] * CVE-2026-27145: Go Inefficient Hostname Parsing in crypto/x509 [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27145] [Vulnerability Disclosures] * CVE-2026-8829: Perl HTML::Entities Use-After-Free [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8829] [Vulnerability Disclosures] * CVE-2026-5419: GnuTLS Timing Side-Channel in PKCS#7 Padding [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-5419] [Vulnerability Disclosures] * Opal Security Raises $23 Million for AI-Native Identity Governance [https://www.securityweek.com/opal-security-raises-23-million-for-ai-native-identity-governance/] [General Security News] CVES REFERENCED CVE-2026-10722, CVE-2026-11332, CVE-2026-27145, CVE-2026-3276, CVE-2026-3300, CVE-2026-37460, CVE-2026-42504, CVE-2026-42507, CVE-2026-43958, CVE-2026-50219, CVE-2026-5419, CVE-2026-7774, CVE-2026-8643, CVE-2026-8829 INDICATORS OF COMPROMISE IP Addresses: 202.56.2.126, 209.146.60.26 Read the full brief [https://carolinacleartech.com/brief/2026-06-07/]

Comments

0

Be the first to comment

Sign up now and become a member of the Cyber Threat Brief community!

Get Started

1 month for 9 kr.

Then 99 kr. / month · Cancel anytime.

  • Podcasts kun på Podimo
  • 20 lydbogstimer pr. måned
  • Gratis podcasts

All episodes

90 episodes

episode 2026-06-14: Anthropic disabled its two most advanced AI models after a US government export control order over artwork

2026-06-14: Anthropic disabled its two most advanced AI models after a US government export control order over

SHOW NOTES - 2026-06-14 STORIES COVERED * Today: * Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack [https://www.theregister.com/Security/Microsoft-patches-failed-to-fix-on-prem-SharePoint-which-is-now-under-zero-day-attack] [Critical Alerts] * Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication (CVE-2026-20253) [https://thehackernews.com/2026/06/critical-splunk-enterprise-flaw-lets.html] [Business & Infrastructure Threats] * Chinese hackers hijack auth flow, spy on isolated network for a decade [https://www.bleepingcomputer.com/news/security/chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade/] [Business & Infrastructure Threats] * Ex-school district employee jailed for hacks on former employer [https://www.bleepingcomputer.com/news/security/ex-school-district-employee-jailed-for-hacks-on-former-employer/] [Business & Infrastructure Threats] * NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks [https://www.securityweek.com/npm-12-will-change-script-execution-behavior-to-prevent-supply-chain-attacks/] [Business & Infrastructure Threats] * US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos [https://www.bleepingcomputer.com/news/security/us-gov-asks-anthropic-to-ban-foreign-national-access-to-fable-mythos/] [General Security News] * Russians are posing as Signal support to launch phishing attacks [https://www.theregister.com/Security/Russians-are-posing-as-Signal-support-to-launch-phishing-attacks] [General Security News] * Google fires sueball at alleged Chinese phishers over AI-powered fraud ops [https://www.theregister.com/security/Google-fires-sueball-at-alleged-Chinese-phishers-over-AI-powered-fraud-ops] [General Security News] * DEF CON Franklin project enlists hackers to harden critical infrastructure [https://www.theregister.com/Black-Hat-and-DEF-CON/DEF-CON-Franklin-project-enlists-hackers-to-harden-critical-infrastructure] [General Security News] * Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight [https://www.theregister.com/Malware-Month/Ten-years-since-the-first-corp-ransomware-Mikko-Hyppönen-sees-no-end-in-sight] [General Security News] * EQT buys majority share in Swiss cybersecurity biz Acronis [https://www.theregister.com/Security/EQT-buys-majority-share-in-Swiss-cybersecurity-biz-Acronis] [General Security News] * South Korea Hands Coupang a Record-Breaking $409 Million Data Privacy Fine [https://databreaches.net/2026/06/13/south-korea-hands-coupang-a-record-breaking-409-million-data-privacy-fine/] [General Security News] CVES REFERENCED CVE-2026-20253 Read the full brief [https://carolinacleartech.com/brief/2026-06-14/]

14. juni 202612 min
episode 2026-06-13: ShinyHunters exploited Oracle PeopleSoft zero-day CVE-2026-35273 for two weeks artwork

2026-06-13: ShinyHunters exploited Oracle PeopleSoft zero-day CVE-2026-35273 for two weeks

SHOW NOTES - 2026-06-13 STORIES COVERED * Today: * Oracle PeopleSoft Zero-Day Exploited (CVE-2026-35273) [https://www.darkreading.com/vulnerabilities-threats/shinyhunters-oracle-zero-day-higher-ed] [Critical Alerts] * Conti Ransomware Member Pleads Guilty [https://www.bleepingcomputer.com/news/security/ukrainian-national-pleads-guilty-to-role-in-conti-ransomware-operation/] [Ransomware & Extortion] * Global Schools Foundation Ransomware Negotiation Failure [https://databreaches.net/2026/06/12/after-a-massive-hack-global-schools-groups-negotiator-acted-bizarrely-it-didnt-end-well-for-them/?pk_campaign=feed&pk_kwd=after-a-massive-hack-global-schools-groups-negotiator-acted-bizarrely-it-didnt-end-well-for-them] [Ransomware & Extortion] * China-Linked Group Backdoored Linux Login Systems for 9 Years [https://thehackernews.com/2026/06/china-linked-hackers-backdoored-linux.html] [Business & Infrastructure Threats] * Supply-Chain Attack Early Warning Signs on Dark Web [https://www.bleepingcomputer.com/news/security/early-warning-signs-of-supply-chain-attacks-live-in-the-dark-web/] [Business & Infrastructure Threats] * Insider Threat: Iowa School IT Worker Sentenced for Sabotage [https://databreaches.net/2026/06/12/former-saydel-schools-it-worker-sentenced-for-iowa-cyber-sabotage/?pk_campaign=feed&pk_kwd=former-saydel-schools-it-worker-sentenced-for-iowa-cyber-sabotage] [Business & Infrastructure Threats] * Maine Data Breach Portal Disabled After Fake Disclosures [https://www.bleepingcomputer.com/news/security/maine-disables-data-breach-notification-portal-after-fake-disclosures/] [Business & Infrastructure Threats] * KPMG AI Report Demonstrates AI Hallucinations [https://www.theregister.com/ai-and-ml/2026/06/12/kpmgs-ai-report-turns-into-a-demo-of-ai-hallucinations/5255029] [General Security News] * New macOS Tahoe 26 Forensic Artifact Discovered [https://unit42.paloaltonetworks.com/new-macos-artifact-discovered/] [General Security News] * LabCorp Settles AMCA Breach for $35 Million [https://databreaches.net/2026/06/12/labcorp-reaches-35m-settlement-over-american-medical-collection-agency-breach/?pk_campaign=feed&pk_kwd=labcorp-reaches-35m-settlement-over-american-medical-collection-agency-breach] [General Security News] * DOJ: COVID-19 Relief Fraud Arrests [https://www.justice.gov/usao-nv/pr/coordinated-law-enforcement-actions-results-arrests-seven-men-connection-fraudulent] [General Security News] * phpBB Authentication Bypass (10 Years Old) [https://www.bleepingcomputer.com/news/security/phpbb-forum-fixes-auth-bypass-bug-lurking-for-a-decade/] [Vulnerability Disclosures] * Microsoft Security Update Guide CVEs [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-9076] [Vulnerability Disclosures] CVES REFERENCED CVE-2023-5678, CVE-2024-20399, CVE-2026-34180, CVE-2026-34181, CVE-2026-34182, CVE-2026-34183, CVE-2026-35273, CVE-2026-42764, CVE-2026-42766, CVE-2026-42767, CVE-2026-42768, CVE-2026-42769, CVE-2026-44705, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447, CVE-2026-47162, CVE-2026-47167, CVE-2026-52859, CVE-2026-52860, CVE-2026-7383, CVE-2026-9076 Read the full brief [https://carolinacleartech.com/brief/2026-06-13/]

Yesterday17 min
episode 2026-06-12: CISA gives federal agencies until Sunday to patch an Ivanti Sentry vulnerability already exploited artwork

2026-06-12: CISA gives federal agencies until Sunday to patch an Ivanti Sentry vulnerability already exploited

SHOW NOTES - 2026-06-12 STORIES COVERED * June 12, 2026 * Today: * CISA Orders Ivanti Sentry Patching by June 14 (CVE-2026-10520) [https://www.bleepingcomputer.com/news/security/cisa-gives-feds-3-days-to-patch-ivanti-flaw-exploited-in-attacks/] [Critical Alerts] * ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) [https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html] [Critical Alerts] * The Gentlemen Ransomware Claims 478 Victims Since March 2025 [https://thehackernews.com/2026/06/the-gentlemen-ransomware-claims-478.html] [Ransomware & Extortion] * Europol Dismantles AudiA6 Crypto Laundering Service [https://thehackernews.com/2026/06/europol-disrupts-audia6-crypto.html] [Ransomware & Extortion] * AI-Driven Threats Exposing Limits of MSP Security Stacks [https://www.bleepingcomputer.com/news/security/why-ai-driven-threats-are-exposing-the-limits-of-msp-security-stacks/] [Business & Infrastructure Threats] * Hackers Exploit Langflow Vulnerability for Remote Code Execution (CVE-2026-5027) [https://www.securityweek.com/hackers-exploit-langflow-vulnerability-for-remote-code-execution/] [Business & Infrastructure Threats] * LangGraph Flaw Chain Exposes Self-Hosted AI Agents to RCE [https://thehackernews.com/2026/06/langgraph-flaw-chain-exposes-self.html] [Business & Infrastructure Threats] * AI Agent Supply Chains Lack Integrity Verification [https://unit42.paloaltonetworks.com/ai-agent-supply-chain-risks/] [Business & Infrastructure Threats] * OpenClaw AI Agent Vulnerable to Hidden Command Injection and Phishing [https://thehackernews.com/2026/06/new-attacks-trick-openclaw-ai-agent.html] [Business & Infrastructure Threats] * French Government Tchap Messenger Breach Affects 73,000 Employees [https://www.bleepingcomputer.com/news/security/french-govt-says-tchap-breach-affected-over-73-000-accounts/] [Business & Infrastructure Threats] * GreatXML Exploit Bypasses BitLocker via Recovery Partition XML Files (CVE-2026-45585) [https://thehackernews.com/2026/06/new-greatxml-exploit-bypasses-windows.html] [Windows / AD Security] * CISA Issues New Binding Operational Directive 26-04 [https://news.risky.biz/risky-bulletin-in-the-age-of-ai-cisa-changes-federal-patching-rules/] [General Security News] * Alert Fatigue Becoming a Security Threat of Its Own [https://www.securityweek.com/alert-fatigue-is-becoming-a-security-threat-of-its-own/] [General Security News] * OceanLotus Shifts Focus to Domestic Espionage in Vietnam [https://thehackernews.com/2026/06/oceanlotus-hits-vietnam-investors-with.html] [General Security News] * North Korean Famous Chollima Accounts for 47% of Tech Sector Intrusions [https://thehackernews.com/2026/06/threatsday-bulletin-worm-code-leaked-ai.html] [General Security News] * IoT Platform Vulnerabilities Across Multiple Vendors [https://www.cisa.gov/news-events/ics-advisories/icsa-26-162-02] [Vulnerability Disclosures] * Siemens Desigo CC Patch Files Flagged as Malware by Security Engines [https://www.securityweek.com/siemens-says-desigo-cc-files-flagged-as-malware-by-security-engines/] [Vulnerability Disclosures] CVES REFERENCED CVE-2025-67644, CVE-2026-10520, CVE-2026-10557, CVE-2026-27022, CVE-2026-28277, CVE-2026-28742, CVE-2026-35273, CVE-2026-42947, CVE-2026-45585, CVE-2026-50005, CVE-2026-50101, CVE-2026-50108, CVE-2026-50245, CVE-2026-5027, CVE-2026-7368 INDICATORS OF COMPROMISE IP Addresses: 176.120.22.24, 3.2.3.5 Read the full brief [https://carolinacleartech.com/brief/2026-06-12/]

12. juni 202631 min
episode 2026-06-11: A new Windows zero-day exploit bypassing Microsoft Defender was released hours after Patch Tuesday artwork

2026-06-11: A new Windows zero-day exploit bypassing Microsoft Defender was released hours after Patch Tuesday

SHOW NOTES - 2026-06-11 STORIES COVERED * Today: * New Windows Zero-Day Exploit 'RoguePlanet' Released [https://www.securityweek.com/new-windows-zero-day-exploit-rogueplanet-released/] [Critical Alerts] * 'GreatXML' Zero-Day Exploit Bypasses BitLocker [https://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/] [Critical Alerts] * Microsoft Patches Exchange Server Zero-Day Exploited in Attacks (CVE-2026-42897) [https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-exchange-server-zero-day-exploited-in-attacks/] [Critical Alerts] * CISA Adds Cisco, Chrome, and Arista Flaws to KEV Catalog [https://thehackernews.com/2026/06/cisa-adds-cisco-chrome-and-arista-flaws.html] [Critical Alerts] * Path Traversal Flaw in AI Dev Platform Langflow Exploited in Attacks (CVE-2026-5027) [https://www.bleepingcomputer.com/news/security/path-traversal-flaw-in-ai-dev-platform-langflow-exploited-in-attacks/] [Critical Alerts] * Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs [https://thehackernews.com/2026/06/microsoft-patches-record-206-flaws.html] [Vulnerability Disclosures] * Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities [https://thehackernews.com/2026/06/ivanti-fortinet-and-sap-release-patches.html] [Vulnerability Disclosures] * Who Runs the Ransomware Group 'The Gentlemen?' [https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/] [Ransomware & Extortion] * WA: Chelan County Enters Third Week of Disruptions with No Recovery Timeline [https://databreaches.net/2026/06/10/wa-chelan-county-enters-third-week-of-disruptions-with-no-recovery-timeline/?pk_campaign=feed&pk_kwd=wa-chelan-county-enters-third-week-of-disruptions-with-no-recovery-timeline] [Ransomware & Extortion] * Infostealers Turn Millions of Devices Into Credential Theft Machines [https://www.securityweek.com/infostealers-turn-millions-of-devices-into-credential-theft-machines/] [Business & Infrastructure Threats] * Deceptive Installers: How Fake Apps Target macOS [https://www.huntress.com/blog/deceptive-installers-macos-infostealers] [Business & Infrastructure Threats] * GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks [https://thehackernews.com/2026/06/github-to-disable-npm-install-scripts.html] [General Security News] * Microsoft Fixes BitLocker Recovery Bug on Windows Server 2025 [https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bitlocker-recovery-bug-on-windows-server-2025/] [General Security News] * Microsoft: Some Windows PCs Fail to Install Latest Monthly Updates [https://www.bleepingcomputer.com/news/microsoft/microsoft-some-upgraded-windows-pcs-fail-to-install-monthly-updates/] [General Security News] CVES REFERENCED CVE-2026-10520, CVE-2026-10523, CVE-2026-11645, CVE-2026-20245, CVE-2026-22732, CVE-2026-25089, CVE-2026-27671, CVE-2026-33017, CVE-2026-40128, CVE-2026-42897, CVE-2026-44748, CVE-2026-44815, CVE-2026-45586, CVE-2026-45657, CVE-2026-47291, CVE-2026-49160, CVE-2026-5027, CVE-2026-50507, CVE-2026-7473 Read the full brief [https://carolinacleartech.com/brief/2026-06-11/]

11. juni 202627 min
episode 2026-06-10: Microsoft patches 206 vulnerabilities in the largest Patch Tuesday on record artwork

2026-06-10: Microsoft patches 206 vulnerabilities in the largest Patch Tuesday on record

SHOW NOTES - 2026-06-10 STORIES COVERED * Today: * Veeam Backup & Replication RCE (CVE-2026-44963) [https://www.bleepingcomputer.com/news/security/new-veeam-vulnerability-exposes-backup-servers-to-rce-attacks/] [Critical Alerts] * Cisco SD-WAN Zero-Day (CVE-2026-20245) [https://cyberscoop.com/cisco-sdwan-zero-day-vulnerability-exploited-cve202620245/] [Critical Alerts] * Check Point VPN RCE (CVE-2026-50751) [https://databreaches.net/2026/06/09/cisa-gives-feds-3-days-to-patch-check-point-vpn-bug-exploited-as-zero-day/] [Critical Alerts] * Chrome V8 Zero-Day (CVE-2026-11645) [https://thehackernews.com/2026/06/chrome-v8-zero-day-cve-2026-11645.html] [Critical Alerts] * Microsoft June 2026 Patch Tuesday (206 Vulnerabilities) [https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-3-zero-day-200-flaws/] [Windows / AD Security] * Microsoft Defender RoguePlanet Zero-Day [https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/] [Windows / AD Security] * Microsoft Exchange Ghost-Sender Spoofing [https://www.darkreading.com/vulnerabilities-threats/exchange-flaw-attackers-spoof-email-address] [Windows / AD Security] * Windows 10 KB5094127 Extended Security Update [https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5094127-extended-security-update/] [Windows / AD Security] * Windows 11 KB5094126 & KB5093998 Updates [https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5094126-and-kb5093998-cumulative-updates-released/] [Windows / AD Security] * Microsoft AI Activity Investigation Playbook [https://www.microsoft.com/en-us/security/blog/2026/06/09/reconstructing-ai-activity-investigations/] [Windows / AD Security] * WinRAR Exploitation in Ukraine [https://thehackernews.com/2026/06/winrar-flaw-exploited-by-russia-aligned.html] [Business & Infrastructure Threats] * GitHub/Microsoft Repository Compromise (Miasma/Shai-Hulud) [https://www.bleepingcomputer.com/news/security/github-disables-microsoft-repos-pushing-password-stealing-malware/] [Business & Infrastructure Threats] * Hades PyPI Attack (37 Malicious Packages) [https://thehackernews.com/2026/06/hades-pypi-attack-19-packages-poisoned.html] [Business & Infrastructure Threats] * CISA KEV Additions (June 9) [https://www.cisa.gov/news-events/alerts/2026/06/09/cisa-adds-three-known-exploited-vulnerabilities-catalog] [Vulnerability Disclosures] * ICS Patch Tuesday [https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-phoenix-contact/] [Vulnerability Disclosures] CVES REFERENCED CVE-2025-15467, CVE-2025-40946, CVE-2025-8088, CVE-2026-11645, CVE-2026-20127, CVE-2026-20182, CVE-2026-20245, CVE-2026-2441, CVE-2026-26142, CVE-2026-32193, CVE-2026-3909, CVE-2026-3910, CVE-2026-41108, CVE-2026-41125, CVE-2026-42985, CVE-2026-42987, CVE-2026-44803, CVE-2026-44812, CVE-2026-44815, CVE-2026-44963, CVE-2026-45467, CVE-2026-45469, CVE-2026-45485, CVE-2026-45586, CVE-2026-45602, CVE-2026-45607, CVE-2026-45641, CVE-2026-45648, CVE-2026-45657, CVE-2026-47288, CVE-2026-47291, CVE-2026-47292, CVE-2026-47652, CVE-2026-48574, CVE-2026-49160, CVE-2026-50507, CVE-2026-50508, CVE-2026-50751, CVE-2026-5281, CVE-2026-7473 Read the full brief [https://carolinacleartech.com/brief/2026-06-10/]

10. juni 202630 min