← Carolina Clear Tech

Cyber Threat Brief

2026-06-01

Listen to this brief (12:32)

Download MP3
Show Notes

Show Notes - 2026-06-01

Stories Covered

CVEs Referenced

CVE-2019-5736, CVE-2022-0492, CVE-2026-8732

Indicators of Compromise

IP Addresses: 89.110.110.119, 185.163.47.217, 178.156.165.82, 178.156.173.194

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief - June 1, 2026

Today: Critical WordPress plugin flaw under active exploitation allows unauthenticated admin account creation. Dutch authorities dismantle massive 17 million device botnet. Container escape vulnerabilities continue to threaten cloud infrastructure.

Critical Alerts

Critical WP Maps Pro Flaw Actively Exploited (CVE-2026-8732)

WP Maps Pro, a WordPress plugin with over 15,000 sales on Envato Market, has a critical privilege escalation vulnerability (CVSS 9.8, EPSS 0.001/22%ile) that allows unauthenticated attackers to create administrator accounts and take over WordPress sites. The flaw exists in the plugin's "temporary access" feature, designed for support staff troubleshooting. The AJAX endpoint wpgmp_temp_access_ajax is accessible to unauthenticated users and protected only by a nonce check embedded in frontend JavaScript via wp_localize_script, making the protection useless. Attackers can invoke wpgmp_temp_access_support with check_temp=false to unconditionally create an administrator user and receive a magic login URL that authenticates them without a password.

Business & Infrastructure Threats

Dutch Authorities Dismantle 17 Million Device Botnet

Dutch police and NCSC dismantled a botnet controlling at least 17 million infected devices including computers, smartphones, tablets, and IoT devices. Over 200 servers in the Netherlands provided backend infrastructure. The service is reportedly Asocks, a residential proxy provider offering corporate, residential, and mobile proxies for $5-15 monthly subscriptions. The botnet enslaved devices by exploiting access vulnerabilities to install remote control malware. While residential proxies have legitimate privacy uses, the ecosystem is shadowy with providers catering to attackers who purchase access to compromised devices to route malicious traffic and execute cyber attacks.

Container Attack Vectors Continue to Threaten Cloud Environments (CVE-2019-5736, CVE-2022-0492)

Kaspersky research documents the evolution of container attacks into multi-stage scenarios involving supply chain compromises, Kubernetes secrets theft, orchestration API abuse, and container escape attempts. Recent attacks include APT group TeamPCP compromising Checkmarx KICS by poisoning a Docker Hub repository to steal Kubernetes secrets. Primary attack vectors include exploiting host system and container runtime vulnerabilities, malicious activity inside compromised containers, container escapes followed by host compromise, exploiting misconfigurations in containerization and orchestration APIs, and supply chain attacks including container image poisoning and CI/CD pipeline compromise. CVE-2019-5736 (EPSS 0.592/98%ile) is highlighted as one of the most prominent containerization vulnerabilities. CVE-2022-0492 (EPSS 0.052/90%ile) also poses risks. Because containers share the host kernel, vulnerabilities affecting Linux kernel or runtime components remain critical when exploited from within containers.

SmartApeSG ClickFix Campaign Delivers Multi-Stage RAT Infections

SANS ISC documented an unidentified RAT infection originating from the SmartApeSG ClickFix campaign on May 27, 2026, followed by deployment of malicious NetSupport Manager RAT. The initial RAT generates encoded (non-HTTPS) traffic to C2 server at 89.110.110.119 over TCP port 443. After initial infection, follow-up files for NetSupport RAT are delivered through the RAT's C2 channel. The campaign uses fake verification pages with ClickFix instructions to trick users into running malicious scripts. NetSupport RAT C2 communicates with 185.163.47.217:443. The attack chain includes processor.vbs, token.bat, and setup.cab files, with the batch script extracting and making the NetSupport RAT persistent before deleting installation artifacts.

Ransomware Group Claims HDFC AMC Data Theft

Bombay High Court granted interim relief to HDFC AMC after ransomware group "Morpheus" allegedly stole over 680 GB of sensitive company and investor data. The court issued an injunction barring unidentified hackers from publishing or sharing the information, warning that any leak could lead to identity theft, financial fraud, and irreparable harm. The case involves one of India's largest asset management companies.

General Security News

Russia Expands SORM Surveillance Requirements

Russian government expanded data collection requirements for mobile operators and ISPs under the SORM (System for Operative Investigative Activities) surveillance system. New rules require telcos to collect extremely sensitive PII from every customer including home addresses, passport data, tax IDs, bank account details, and geo-location coordinates, linked to technical identifiers like IP addresses, phone numbers, MAC addresses, IMEI and IMSI codes. Technical data collection expanded to include domains accessed by users and even user logins visible to telcos. Over 200 servers were seized or taken offline. A minimum SORM deployment package previously cost around 5 million rubles ($70,000) and costs are now significantly higher. The government has been aggressively enforcing SORM compliance, fining 85 telcos last week for failing to provide IP address assignment data, and passed legislation to revoke licenses for up to 10 years for non-compliant ISPs. Many small ISPs (estimated 10,000 companies) lack financial resources to comply, leading to market consolidation.

2026 Election Threats Target Campaign Infrastructure, Not Voting Systems

Check Point research found that cybersecurity threats to the 2026 midterm elections are targeting campaign accounts, email systems, websites, and fundraising platforms rather than voting machines or ballot-counting systems. 82% of malicious attacks arrive through email. ActBlue had approximately 9,500 stolen passwords, while WinRed had about 6,500. In January 2026, about 1,300 new websites included the word "election" and 4,010 included "vote," with the majority expected to be used for phishing scams. AI is lowering the barrier to entry for attackers and increasing the quality of attacks, making everything more realistic and effective. AI-generated manipulated content is becoming increasingly visible in the 2026 cycle.

YARA-X 1.17.0 Released

YARA-X version 1.17.0 released with 5 improvements including several performance enhancements and 1 bugfix. YARA-X is a rewrite of YARA in Rust for improved performance and safety in malware detection rule engines.

Patch Priority

Vulnerability Disclosures

CVE-2026-8732 - WP Maps Pro Privilege Escalation

Critical privilege escalation vulnerability (CVSS 9.8, EPSS 0.001/22%ile) in WP Maps Pro WordPress plugin versions 6.1.0 and earlier. Unauthenticated attackers can create administrator accounts via flawed temporary access feature. The AJAX endpoint wpgmp_temp_access_ajax is registered with wp_ajax_nopriv_ and protected only by a nonce check embedded in frontend JavaScript as the nonce field of the wpgmp_local JavaScript object, making the check ineffective as an access control mechanism. Attackers can invoke wpgmp_temp_access_support with check_temp=false to unconditionally create a WordPress user with hardcoded administrator role via wp_insert_user() and receive a magic login URL that calls wp_set_auth_cookie() for full authentication, resulting in complete site takeover. Fixed in version 6.1.1 by restricting endpoint access to authenticated administrators only. Active exploitation confirmed with over 3,600 attempts blocked.

CVE-2019-5736 - Container Runtime Escape

Container runtime escape vulnerability with EPSS score 0.592 (98th percentile), indicating high likelihood of exploitation. Remains one of the most prominent and illustrative vulnerabilities associated with containerization. Successful exploitation can lead to container escape, Kubernetes node or cluster compromise, lateral movement, secrets theft, and service disruption.

CVE-2022-0492 - Container Escape Vulnerability

Container escape vulnerability with EPSS score 0.052 (90th percentile). Allows attackers to break out of container isolation when exploited under specific configuration settings or privileges.

Trends & Context

Container security continues to be a critical concern as attacks evolve beyond simple misconfigurations to multi-stage campaigns involving supply chain compromises and APT groups poisoning public repositories. The WordPress ecosystem remains a high-value target with premium plugins representing attractive attack surfaces due to wide deployment and privileged functionality. Botnet operations at scale, exemplified by the 17 million device Asocks takedown, demonstrate the ongoing challenge of IoT and residential device security where default credentials and unpatched systems enable mass compromise.