← Carolina Clear Tech

Cyber Threat Brief

2026-06-02

Listen to this brief (22:59)

Download MP3
Show Notes

Show Notes - 2026-06-02

Stories Covered

CVEs Referenced

CVE-2026-0257, CVE-2026-21182, CVE-2026-26980, CVE-2026-33825, CVE-2026-41089, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-48131, CVE-2026-48132, CVE-2026-8732

Indicators of Compromise

IP Addresses: 164.92.88.210

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Today: Windows domain controllers face active exploitation of a critical Netlogon RCE flaw patched in May. Red Hat's npm repositories were compromised in a supply chain attack distributing credential-stealing malware to 117,000 weekly downloads. Palo Alto Networks confirms VPN authentication bypass CVE-2026-0257 under active exploitation since May 17, with CISA setting a June 1 deadline.

Critical Alerts

CVE-2026-21182: Oracle WebLogic Server Added to CISA KEV

CISA added Oracle WebLogic Server CVE-2026-21182 to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The vulnerability has an EPSS score of 0.877, placing it in the 99th percentile for exploitation probability. Federal agencies have until June 4 to remediate.

CVE-2026-41089: Windows Netlogon RCE Under Active Exploitation

Belgium's Centre for Cybersecurity warns that attackers are actively exploiting CVE-2026-41089, a critical stack-based buffer overflow in Windows Netlogon allowing remote code execution on domain controllers. The flaw (CVSS 9.8) was patched in Microsoft's May 2026 Patch Tuesday but attackers can send crafted network requests without authentication to gain SYSTEM-level access. All Windows Server versions including Server 2025 are affected. Microsoft states they found no evidence of exploitation, contradicting CCB's warning.

CVE-2026-0257: Palo Alto Networks GlobalProtect Authentication Bypass Exploited

Palo Alto Networks and CISA confirm active exploitation of CVE-2026-0257 (CVSS 7.8, EPSS 0.415 at 97th percentile) affecting PAN-OS GlobalProtect portal and gateway. Rapid7 detected the first exploitation attempts on May 17, just four days after public disclosure. Attackers use forged authentication override cookies to establish unauthorized VPN sessions, granting access to internal networks. The threat actor operated from Vultr and Dromatics Systems hosting providers. CISA added the flaw to its KEV catalog with a June 1 remediation deadline.

Gogs Remote Code Execution Zero-Day (No CVE Yet)

Gogs, an open-source self-hosted Git service, has a critical unauthenticated RCE vulnerability (CVSS 9.4) with no patch available. Rapid7 disclosed the flaw affecting servers running default configurations on Windows, Linux, and macOS. Attackers can abuse rebase merging via pull requests with malicious branch names to execute arbitrary commands. Since Gogs ships with open registration enabled by default, unauthenticated attackers can create accounts and exploit the flaw to access all repositories, steal credentials, and pivot to other systems. The vulnerability has been unpatched for over two months.

Business & Infrastructure Threats

Red Hat npm Packages Compromised in Supply Chain Attack

More than 30 npm packages under Red Hat's @redhat-cloud-services namespace were compromised in a supply chain attack distributing Miasma, a new variant of the Shai-Hulud credential-stealing worm. The packages receive approximately 117,000 weekly downloads. Attackers compromised a Red Hat employee's GitHub account and pushed malicious commits adding GitHub Actions workflows that abused npm's OIDC publishing mechanism. The malicious code executed via preinstall scripts, stealing GitHub Actions secrets, AWS/GCP/Azure credentials, Kubernetes tokens, SSH keys, Docker credentials, GPG keys, and .env files. The malware exfiltrates data to attacker-controlled servers and creates persistence hooks in Claude Code and VS Code. Red Hat removed affected packages and states the compromise was limited to internal development tooling with no customer impact.

DriveSurge Campaign Hijacks Thousands of Sites for Malware Distribution

A threat actor tracked as DriveSurge operates as an initial access broker using ClickFix and FakeUpdates social engineering across thousands of compromised WordPress sites. SilentPush researchers identified attacks leveraging zTDS (an open-source Traffic Distribution System active since 2015) to profile visitors and serve targeted malware. Victims see fake browser update prompts for Chrome, Firefox, Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, and UC Browser. ClickFix attacks deliver PowerShell commands. The campaign extends to macOS via obfuscated JavaScript targeting desktop systems with clipboard hijacking.

codexui-android npm Package Steals OpenAI Codex Tokens

A malicious npm package named codexui-android advertised as a remote web UI for OpenAI Codex has attracted over 29,000 weekly downloads while stealing authentication tokens. The package is functional but contains code extracting ~/.codex/auth.json and exfiltrating access tokens, refresh tokens, and account IDs to sentry.anyclaw.store. The stolen refresh tokens do not expire, granting persistent silent access. Associated Android apps (OpenClaw Codex Claude AI Agent with 50,000+ downloads and Codex with 10,000+ downloads) run the npm package in a PRoot sandbox to steal credentials from in-app sign-ins.

Meta AI Support Bot Exploited for Instagram Account Takeover

Attackers used Meta's AI support assistant to hijack Instagram accounts including the Obama White House and U.S. Space Force Chief Master Sergeant accounts. A Telegram video demonstrated a simple exploit: using a VPN with an IP near the target's location, requesting password reset, then instructing the AI bot to link a new email address to the account. The bot sent a one-time code to the attacker's email enabling password reset. The exploit failed against accounts with any form of MFA enabled. Meta pushed an emergency patch over the weekend.

WordPress Malware Hides C2 Data in Steam Profile Comments

Nearly 2,000 WordPress sites were infected with malware using Steam Community profile comments to hide command-and-control data. GoDaddy researchers discovered attackers embedding payloads in invisible Unicode characters (zero-width non-joiner, zero-width joiner, function application, invisible times, invisible separator, invisible plus) within benign-looking Steam profile text. The malware decodes payloads building URLs to hello-mywordl.info serving obfuscated JavaScript disguised as legitimate libraries. A backdoor responds to POST requests with a tEcaKKXEsb authentication cookie.

Windows / AD Security

CVE-2026-45498, CVE-2026-33825, CVE-2026-41091: Additional Windows Zero-Days Under Exploitation

Security researcher Nightmare Eclipse disclosed multiple Windows zero-days now under active exploitation. CVE-2026-45498 (UnDefend, EPSS 0.041 at 89th percentile, CISA KEV due June 3) allows standard users to block Microsoft Defender definition updates. CVE-2026-33825 (BlueHammer, EPSS 0.071 at 92nd percentile, CISA KEV due May 6) and CVE-2026-41091 (RedSun, EPSS 0.080 at 92nd percentile, CISA KEV due June 3) are privilege escalation flaws providing SYSTEM privileges. CVE-2026-45585 (YellowKey) is a BitLocker zero-day granting access to protected drives. Microsoft initially responded with legal threats but has since provided mitigation guidance.

Microsoft Outages Affecting MFA Setup and Office Apps

Microsoft resolved two separate outages on June 1. The first prevented users from setting up MFA or accessing mysignins.microsoft.com, with customers seeing 504 Gateway Timeout errors. Microsoft blamed a cache configuration change causing high CPU and memory utilization during EU traffic peaks. A second incident prevented users from opening files in Office for the web and Teams, affecting Excel and PowerPoint with "Office Online services aren't available" errors. The issue recovered without specific engineering actions.

KB5089549 Windows 11 Security Update Installation Issues Resolved

Microsoft resolved a known issue causing May 2026 Windows 11 security update (KB5089549) installation failures with 0x800f0922 errors. The issue affected devices with limited free space on the EFI System Partition (ESP), especially those with 10MB or less available. Installations failed at 35-36% completion during reboot. The fix is included in KB5089573 preview update released May 26 and will be in June Patch Tuesday updates.

General Security News

CVE-2026-26980: Ghost CMS SQL Injection Under Active Exploitation

Attackers are actively exploiting CVE-2026-26980 (EPSS 0.567 at 98th percentile), a SQL injection vulnerability in Ghost CMS, to steal Admin API keys and modify website pages. At least two groups have targeted over 700 sites using fake Cloudflare checks to deliver data-stealing malware. Check Point IPS provides protection against this threat.

CVE-2026-8732: WP Maps Pro WordPress Plugin Exploited for Site Takeover

Threat actors are exploiting CVE-2026-8732 (CVSS 9.8) in WP Maps Pro WordPress plugin to create administrative accounts and take over sites. The vulnerability exists in a callback AJAX function handling temporary access generation protected only by a nonce embedded in every frontend page and exposed to unauthenticated users. Attackers can invoke the AJAX action with check_temp=false to create admin users with hardcoded email addresses and receive magic login URLs. Defiant blocked over 1,700 attacks in 24 hours.

Dashlane Brute-Force Attack Results in Limited Vault Downloads

Dashlane disclosed that fewer than 20 personal plan users had encrypted vaults downloaded following a brute-force attack on May 31. The attack targeted accounts attempting to bypass two-factor authentication and register new devices. High-volume attempts triggered temporary account suspensions as designed. While encrypted vaults were downloaded, the data cannot be accessed without Master Passwords. Dashlane's systems were not compromised.

SVG Files Used in Phishing Campaigns

SANS Internet Storm Center reports a surge in phishing emails delivering SVG (Scalable Vector Graphic) files containing JavaScript that redirects victims to phishing pages. The SVG files contain Base64-encoded and XOR'd payloads with the decryption key embedded. The JavaScript uses the application/ecmascript MIME type to evade security controls looking for "JavaScript." Phishing pages use the .cfd TLD (Clothing, Fashion, and Design), a cheap domain increasingly abused in campaigns.

GlassWorm C2 Infrastructure Taken Down

CrowdStrike, Google, and Shadowserver Foundation dismantled the GlassWorm malware operation on May 26 by simultaneously taking down all four C2 channels. GlassWorm distributed trojanized VS Code extensions via Microsoft VS Code Marketplace and Open VSX, and compromised npm and Python packages. The malware checks system locale and avoids CIS countries, with Russian-language comments in code suggesting Russian operators. Infected endpoints now beacon to benign IP 164.92.88.210 for identification.

Carnival Corporation, Charter Communications, Lithuania Data Breaches

Check Point Research reports multiple significant breaches. Carnival Corporation confirmed a data breach affecting nearly 6 million people after social engineering compromised an employee account, exposing names, contact details, dates of birth, and government IDs. Charter Communications (Spectrum) suffered a breach by ShinyHunters exposing 4.9 million email addresses with names, phone numbers, physical addresses, and employee records. Lithuania's Centre of Registers disclosed a breach affecting over 600,000 records after attackers misused institutional login credentials to access names, dates of birth, national IDs, and property data.

Spain Arrests Doxer Targeting Government Employees

Spanish National Police arrested an individual for leaking sensitive data of employees from the State Attorney General's Office, INCIBE, National Police, Civil Guard, and National Security Council. The operation posed national security risks. No direct system compromise occurred; the threat group Police-ESP-Doxed aggregated data from older breaches, credential dumps, and OSINT tools to create curated collections posted to BreachForum and Doxbin.

Patch Priority

Vulnerability Disclosures

Check Point Security Gateways: CVE-2026-48131, CVE-2026-48132

Check Point announced a Jumbo Security Release based on AI-driven code scanning addressing vulnerabilities in security gateways. CVE-2026-48131 (IKE Unsigned Underflow) and CVE-2026-48132 (IKE Improper Length Validation) were not exploited in the wild. Check Point IPS provides protection against these threats.

China-Aligned Threat Activity Targeting Czech Republic, Taiwan, India

Operation Dragon Weave targeted Czech Republic and Taiwan government, research, academic, technology, and financial services sectors with AdaptixC2 agent delivered via spear-phishing. The campaign uses Rust-based RUSTCLOAK loader and AZUREVEIL implant leveraging Microsoft Azure Blob Storage for dead-drop C2 communication to evade detection. Separately, TencShell (a Go-based implant derived from rshell C2) targeted an Indian manufacturing company. China-aligned groups including newly identified SteppeDriver cluster remain highly active globally.

Pakistan-Linked SideCopy Targets Afghanistan with Xeno RAT

The Pakistan-aligned SideCopy group (operating under Transparent Tribe) targeted Afghanistan's Ministry of Finance, provincial revenue directorates, and Pashto-speaking government officials with Xeno RAT delivered via spear-phishing. The campaign uses LNK files with Pashto-language names fetching HTA files from compromised Afghan education domains. Xeno RAT 1.8.7 provides full remote access including keylogging, screenshots, webcam/microphone monitoring, SOCKS5 proxy, and self-uninstall capabilities.

Trends & Context

Supply chain attacks dominate today's threat landscape with the Red Hat npm compromise and ongoing Shai-Hulud variants demonstrating that credential theft worms now self-propagate through developer toolchains. The GlassWorm takedown shows defender collaboration can disrupt these operations, but the TeamPCP source code release ensures copycat campaigns will continue. Meanwhile, critical infrastructure vulnerabilities in Windows Netlogon and Palo Alto GlobalProtect highlight the persistent gap between patch availability and deployment, with exploitation beginning within days of disclosure. AI-driven security tools are increasingly targeted, as seen in the Meta support bot exploit, creating new attack surfaces that blend social engineering with automated decision-making systems.