Cyber Threat Brief
SHOW NOTES - 2026-06-03 STORIES COVERED * June 3, 2026 * Today: * Oracle WebLogic CVE-2024-21182 Actively Exploited (CVE-2024-21182) [https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-oracle-weblogic-flaw/] [Critical Alerts] * Google Patches Exploited Android Zero-Day (CVE-2025-48595) [https://www.bleepingcomputer.com/news/security/google-fixes-one-actively-exploited-android-zero-day-124-flaws/] [Critical Alerts] * Linux Kernel Privilege Escalation Added to KEV (CVE-2022-0492) [https://www.cisa.gov/news-events/alerts/2026/06/02/cisa-adds-two-known-exploited-vulnerabilities-catalog] [Critical Alerts] * Unpatched NTLM Coercion in Windows Search URI Handler (No CVE) [https://www.huntress.com/blog/unpatched-ntlm-coercion-windows-search-uri-handler] [Windows / AD Security] * Microsoft Backtracks on Zero-Day Researcher Legal Threats [https://www.securityweek.com/microsoft-tries-to-calm-legal-threat-fears-after-zero-day-disclosure-backlash/] [General Security News] * VS Code Zero-Day Allows GitHub Token Theft via Link Click [https://www.bleepingcomputer.com/news/security/vs-code-zero-day-lets-hackers-steal-github-tokens-in-one-click/] [General Security News] * AI-Built Ransomware Toolkit Automates EDR Evasion [https://www.bleepingcomputer.com/news/security/ai-built-ransomware-toolkit-automates-edr-evasion-ad-discovery/] [General Security News] * DriveSurge Campaign Hijacks Thousands of Sites for Malware Delivery [https://www.darkreading.com/cyberattacks-data-breaches/drivesurge-hijacks-thousands-sites-clickfix-fakeupdate-attacks] [General Security News] * Exchange Online Outage Causes Email Delays and Failures [https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-causes-email-delays-failures/] [General Security News] * Gamaredon Exploits WinRAR to Deliver Malware Against Ukraine [https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html] [Ransomware & Extortion] * WordPress Kirki Plugin Privilege Escalation Exploited (CVE-2026-8206) [https://www.bleepingcomputer.com/news/security/critical-kirki-flaw-exploited-to-hijack-wordpress-admin-accounts/] [Vulnerability Disclosures] * Microsoft Office Vulnerability (CVE-2026-21509) Used by APT28 [https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html] [Vulnerability Disclosures] CVES REFERENCED CVE-2022-0492, CVE-2024-21182, CVE-2025-48595, CVE-2025-8088, CVE-2026-21509, CVE-2026-33825, CVE-2026-33829, CVE-2026-41091, CVE-2026-45498, CVE-2026-8206 INDICATORS OF COMPROMISE IP Addresses: 12.2.1.4, 14.1.1.0 Read the full brief [https://carolinacleartech.com/brief/2026-06-03/]
90 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Cyber Threat Brief!