Cyber Threat Brief
SHOW NOTES - 2026-06-05 STORIES COVERED * June 5, 2026 * Today: * Cisco SD-WAN Zero-Day Actively Exploited (CVE-2026-20245) [https://www.bleepingcomputer.com/news/security/new-cisco-sd-wan-flaw-exploited-in-zero-day-attacks-to-gain-root/] [Critical Alerts] * Cisco Unified CM Critical SSRF with Public PoC (CVE-2026-20230) [https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-unified-cm-flaw-with-poc-exploit-code/] [Critical Alerts] * Windows 11 Zero-Day (CVE-2026-0257) [https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-23-7/] [Critical Alerts] * AI Agents as Insider Threat [https://cyberscoop.com/ai-agent-insider-threat-cybersecurity-dtex/] [Business & Infrastructure Threats] * Claude Code GitHub Action Repository Takeover [https://thehackernews.com/2026/06/claude-code-github-action-flaw-let-one.html] [Business & Infrastructure Threats] * Microsoft Agentic AI Failure Modes v2.0 [https://www.microsoft.com/en-us/security/blog/2026/06/04/updating-taxonomy-failure-modes-agentic-ai-systems-year-red-teaming-taught-us/] [Business & Infrastructure Threats] * UN World Food Programme Gaza Breach (600,000 Households) [https://www.bleepingcomputer.com/news/security/un-world-food-programme-breach-affects-600-000-gaza-households/] [Business & Infrastructure Threats] * DentaQuest Breach (2.6 Million Accounts) [https://www.bleepingcomputer.com/news/security/dentaquest-data-breach-exposed-info-of-26-million-accounts/] [Business & Infrastructure Threats] * China-Linked TA4922 Expands to Europe [https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-23-7/] [Ransomware & Extortion] * IronWorm npm Supply Chain Attack (36 Packages) [https://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/] [Ransomware & Extortion] * Russian Mobile Spyware Operation [https://thehackernews.com/2026/06/threatsday-bulletin-ai-agents-gone.html] [Ransomware & Extortion] * Microsoft M365 Copilot RCE (CVE-2026-45497) [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45497] [Windows / AD Security] * Windows Driver Update Issue [https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-unexpected-windows-driver-updates-on-caching-issue/] [Windows / AD Security] * Chrome 149 Patches Record 429 Vulnerabilities [https://www.securityweek.com/chrome-149-patches-429-vulnerabilities/] [General Security News] * Hola Browser Supply Chain Compromise [https://www.bleepingcomputer.com/news/security/hola-browser-for-windows-compromised-to-deliver-cryptominer/] [General Security News] * Everest Forms Pro WordPress RCE Actively Exploited (CVE-2026-3300) [https://thehackernews.com/2026/06/hackers-exploit-critical-everest-forms.html] [General Security News] * Magecart Campaign Abuses Stripe API [https://www.bleepingcomputer.com/news/security/credit-card-theft-campaign-abuses-stripe-to-host-stolen-payment-info/] [General Security News] * VIP Keylogger via JavaScript Loaders [https://isc.sans.edu/diary/rss/33054] [General Security News] * FlutterShell macOS Malvertising [https://thehackernews.com/2026/06/fluttershell-backdoor-spreads-to-macos.html] [General Security News] * FIFA World Cup 2026 Scams [https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html] [General Security News] * Hitachi Energy ICS Vulnerabilities [https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-04] [Vulnerability Disclosures] * B&R PPT30 OPC-UA DoS (CVE-2025-11482) [https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-03] [Vulnerability Disclosures] CVES REFERENCED CVE-2024-8176, CVE-2025-11482, CVE-2025-20309, CVE-2025-59375, CVE-2026-0257, CVE-2026-10881, CVE-2026-10882, CVE-2026-10883, CVE-2026-20045, CVE-2026-20127, CVE-2026-20182, CVE-2026-20230, CVE-2026-20245, CVE-2026-25253, CVE-2026-3300, CVE-2026-45497, CVE-2026-7310 INDICATORS OF COMPROMISE IP Addresses: 202.56.2.126, 209.146.60.26, 15.235.166.18, 185.78.165.153 Read the full brief [https://carolinacleartech.com/brief/2026-06-05/]
90 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Cyber Threat Brief!