← Carolina Clear Tech

Cyber Threat Brief

2026-06-05

Listen to this brief (27:52)

Download MP3
Show Notes

Show Notes - 2026-06-05

Stories Covered

CVEs Referenced

CVE-2024-8176, CVE-2025-11482, CVE-2025-20309, CVE-2025-59375, CVE-2026-0257, CVE-2026-10881, CVE-2026-10882, CVE-2026-10883, CVE-2026-20045, CVE-2026-20127, CVE-2026-20182, CVE-2026-20230, CVE-2026-20245, CVE-2026-25253, CVE-2026-3300, CVE-2026-45497, CVE-2026-7310

Indicators of Compromise

IP Addresses: 202.56.2.126, 209.146.60.26, 15.235.166.18, 185.78.165.153

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

June 5, 2026

Today: Cisco discloses seventh SD-WAN zero-day this year, now actively exploited for root escalation with public IOCs. Unified CM gets critical SSRF patch as public exploit code drops. Chrome 149 ships record 429 vulnerability fixes driven by AI-discovered flaws.

Critical Alerts

Cisco SD-WAN Zero-Day Actively Exploited (CVE-2026-20245)

Cisco warned Thursday of an unpatched high-severity zero-day in Catalyst SD-WAN Manager enabling root privilege escalation. CVE-2026-20245 stems from insufficient input validation and allows local attackers with low privileges to upload crafted files and execute arbitrary commands as root. The flaw impacts all deployment types: On-Prem, Cloud-Pro, Cloud Managed, and Government. Cisco observed limited exploitation resulting in configuration changes pushed to edge devices. To exploit, attackers need netadmin privileges, obtainable by chaining with CVE-2026-20182 (maximum severity auth bypass, CISA-KEV due 2026-05-17, EPSS 0.831/99th percentile) or CVE-2026-20127 (critical auth bypass exploited since 2023, CISA-KEV due 2026-02-27, EPSS 0.548/98th percentile).

Mandiant reported the flaw in June but provided no public details. Cisco shared IOCs: check /var/log/scripts.log for attempts to upload tenant configuration data to vSmart controllers via legitimate commands, example log line "Apr 15 09:44:57 vmanage vScript: Tenant list upload per vsmart serial number: /usr/bin/vconfd_script_upload_tenant_list.sh -cli path /home/admin/malicious.csv vpn 0". This marks Cisco's seventh SD-WAN vulnerability added to CISA KEV, and 90 total Cisco vulnerabilities flagged as exploited in the wild (six by ransomware operations).

Cisco Unified CM Critical SSRF with Public PoC (CVE-2026-20230)

Cisco patched a critical SSRF vulnerability in Unified Communications Manager (CVSS 8.6) allowing unauthenticated remote attackers to write arbitrary files to the OS and escalate to root. The flaw stems from improper input validation for specific HTTP requests. Public proof-of-concept exploit code is available, shortening the attack window. Cisco rated the advisory Critical (overriding the 8.6 score) because the file-write leads to root escalation. The vulnerability only affects systems with WebDialer service enabled (disabled by default). Fixed in versions 14SU6 and 15SU5 (full 15SU5 not due until September 2026, interim COP patch available now).

Unified CM has been a steady source of unauthenticated root-level trouble. Last July, Cisco removed a hardcoded root SSH account left from development (CVE-2025-20309, CVSS 10). In January, it patched an unauthenticated RCE (CVE-2026-20045) exploited in the wild, now CISA-KEV listed with due date 2026-02-11 and EPSS 0.039 (89th percentile). An independent researcher working with SSD Secure Disclosure reported CVE-2026-20230.

Windows 11 Zero-Day (CVE-2026-0257)

CISA added Windows 11 vulnerability CVE-2026-0257 to Known Exploited Vulnerabilities catalog with due date June 1, 2026. EPSS score 0.465 (98th percentile) indicates high exploitation likelihood. No additional technical details available in SentinelOne's weekly roundup.

Business & Infrastructure Threats

AI Agents as Insider Threat

DTEX research demonstrates how Claude Cowork (now Claude Code) enables rapid data exfiltration through legitimate integrations. Researchers used single-turn prompts to exfiltrate Salesforce data via Outlook drafts and archive files in 10-30 minutes. The Dispatch tool relays commands from phone to desktop agent. Tests confirmed agent access to SharePoint corporate data, OneDrive production docs, Outlook email, Salesforce (and all downstream data), and endpoint files. Each application has dedicated plugins or APIs for external sharing. This is not a CVE but an IT governance problem: organizations integrate AI without security controls, access policies, or prompt logging. The threat is amplified by North Korean IT workers infiltrating western companies who now possess AI tools to accelerate data theft. DTEX reports adversary kill chains have compressed from hours to 10-30 minutes.

Claude Code GitHub Action Repository Takeover

Security researcher RyotaK discovered a flaw in Anthropic's Claude Code GitHub Action enabling repository takeover via a single malicious GitHub issue. The vulnerability (CVSS v4.0 7.8, fixed in v1.0.94 within four days, bug bounty paid) bypassed permission checks by allowing any actor whose name ended in [bot]. Attackers could register a GitHub App, install it on a repo they own, and use its token to open issues on any public repository. The action saw "a bot" and let content through. Tag mode had a human check; agent mode did not. From there, indirect prompt injection tricks Claude into reading /proc/self/environ, recovering GitHub OIDC credentials. Claude Code trades that token for a Claude GitHub App installation token with write access. Replay the exchange and you control the target's code, issues, and workflows. A softer route: example workflows shipped with allowed_non_write_users: "*", letting anyone trigger. Claude posted task summaries to public workflow summary panels, a ready exfiltration channel. This same attack hit Cline in February, stealing an npm publish token and pushing unauthorized [email protected].

Microsoft Agentic AI Failure Modes v2.0

Microsoft AI Red Team published an updated taxonomy adding seven new failure mode categories based on 12 months of red team engagements. New categories: Agentic Supply Chain Compromise (malicious plugins/MCP servers inject natural-language instructions), Goal Hijacking (adversarial instructions redirect agent's terminal goal), Inter-Agent Trust Escalation (compromised agents assert false identity to orchestrators), and others. The update was driven by OpenClaw (336,000 GitHub stars in 48 hours, security audit found 512 vulnerabilities including CVE-2026-25253 one-click RCE via WebSocket hijacking, 1,800+ exposed instances leaking API keys in first week, 336 malicious plugins in skills marketplace), MCP ecosystem maturation (99 CVEs published in 2025), and computer-use agents moving from research to production.

UN World Food Programme Gaza Breach (600,000 Households)

The UN World Food Programme disclosed a breach of its self-registration application for Palestine on May 14. Attackers stole names, ID numbers, phone numbers, and neighborhood data for approximately 600,000 Palestinian households in Gaza. The registration platform remains suspended while security improvements are implemented. WFP serves 35 million customers globally, operates in 120+ countries with 20,000 staff, and runs the largest humanitarian logistics network (5,000 trucks, 20 ships, 80 aircraft). In 2024 it delivered $2.82 billion in financial assistance and 2.5 million metric tons of food.

DentaQuest Breach (2.6 Million Accounts)

Dental benefits administrator DentaQuest confirmed a breach exposing 2.6 million accounts. Extortion group ShinyHunters leaked 234 GB after negotiations failed. Compromised data includes emails, names, phone numbers, government IDs, health insurance info, genders, and dates of birth. DentaQuest, a Sun Life subsidiary, serves 35 million customers in 50 states with a 140,000-dentist network. HaveIBeenPwned analysis shows 66% of exposed records were already in its database from previous incidents.

Ransomware & Extortion

China-Linked TA4922 Expands to Europe

China-linked threat actor TA4922 expanded phishing campaigns from East Asia to UK, Germany, Italy, and South Africa. The financially motivated group shares tradecraft with Silver Fox but focuses on data theft, fraud, and access resale. Recent campaigns use HR, tax authority, and invoice-themed lures. TA4922 moves conversations from monitored email to WhatsApp, LINE, and Microsoft Teams to bypass security controls. The group deploys ValleyRAT, Atlas RAT, RomulusLoader, and SilentRunLoader via DLL side-loading. SilentRunLoader (vibe-coded Python) harvests Google Chrome credentials, cookies, and browsing data. Proofpoint notes the malware's surveillance capabilities could be resold to espionage groups.

IronWorm npm Supply Chain Attack (36 Packages)

New supply-chain malware campaign infected 36 npm packages with 32,000 combined monthly downloads. The Rust-based IronWorm malware uses an eBPF kernel rootkit to hide processes, files, and network activity. It harvests 86 environment variables and 20 credential files targeting OpenAI, AWS, Anthropic, npm credentials, vault configs, SSH keys, and Exodus cryptocurrency wallets. IronWorm self-propagates using stolen npm publishing credentials and Trusted Publishing workflow secrets. The malware abuses GitHub Actions to deliver stolen secrets by serializing them into lint-output files uploaded as build artifacts. Researchers found similarities to Shai Hulud campaign (same commit names). The attack originated from compromised account "asteroiddao" with commit author "claude" and backdated timestamps. OX Security detected and mitigated before spread to more popular packages.

Russian Mobile Spyware Operation

Russia's FSB disclosed a "large-scale action" by foreign intelligence services to implant spyware on mobile devices of high-ranking officials. The spyware exfiltrated data, intercepted conversations, and conducted covert audio/video surveillance. FSB stated foreign intelligence leveraged "technical capabilities of major international IT corporations" to exploit mobile communication channels. Russia did not identify responsible parties. Investigation ongoing.

Windows / AD Security

Microsoft M365 Copilot RCE (CVE-2026-45497)

Microsoft disclosed a command injection vulnerability in Microsoft 365 Copilot allowing authorized attackers to execute code over a network. The flaw stems from improper neutralization of special elements used in commands. No CVSS score, EPSS data, or patch details available yet.

Windows Driver Update Issue

Microsoft fixed an issue causing Windows devices to install driver updates without notice despite policies preventing auto-updates. The bug stemmed from Windows Update caching service misconfiguration that dropped device enrollment information, treating devices as non-enrolled. Microsoft resolved the issue June 3 after updating service cache and enrollment status. Admins reported tens of thousands of devices unexpectedly receiving BIOS and driver updates, causing audio/video device failures.

General Security News

Chrome 149 Patches Record 429 Vulnerabilities

Google released Chrome 149 with patches for 429 vulnerabilities, a record for a single Chrome refresh and several times the total Chrome fixes in 2025. The surge is likely driven by AI-assisted vulnerability discovery, which prompted Google to lower Chrome bug bounties in April. Over 100 are critical and high-severity, mostly use-after-free and insufficient input validation flaws. Most severe: CVE-2026-10881 (CVSS 9.6), out-of-bounds read/write in ANGLE graphics engine enabling sandbox escape and OS-level code execution via crafted HTML pages ($97,000 bounty). Two other critical bugs: CVE-2026-10882 (use-after-free in Network, $43,000) and CVE-2026-10883 (out-of-bounds write in ANGLE, $5,000). Google paid ~$208,000 in bug bounties with final amount pending.

Hola Browser Supply Chain Compromise

Windows version of Hola Browser was compromised delivering an undeclared Monero cryptocurrency miner. AppEsteem certification testing discovered undeclared executable "me.exe" under C:\Program Files\Hola\ that was unsigned, obfuscated, and contained mining strings. The miner adds Windows Defender exclusions, copies itself as "HolaMonitorService.exe," creates auto-starting service "hola_monitor_svc," and runs during idle. Hola confirmed the breach and stated 0.1% of users affected with no data theft evidence. The company rebuilt distribution pipeline and implemented code-signing verification.

Everest Forms Pro WordPress RCE Actively Exploited (CVE-2026-3300)

Threat actors exploit critical RCE in Everest Forms Pro WordPress plugin (4,000 active installations). CVE-2026-3300 (CVSS 9.8) affects all versions up to 1.9.12, patched in 1.9.13 (March 18, 2026). The flaw: Calculation Addon's process_filter() concatenates unsanitized user input into PHP eval(). Unauthenticated attackers inject arbitrary PHP code via string-type form fields when "Complex Calculation" is enabled. Exploitation started April 13, 2026. Wordfence blocked 29,300+ attempts (16 in last 24 hours). Common payload creates admin account "diksimarina" ([email protected]). Attack IPs: 202.56.2.126, 209.146.60.26, 15.235.166.18, 2402:1f00:8000:800::40db, 185.78.165.153.

Magecart Campaign Abuses Stripe API

Sansec discovered Magecart campaigns using Stripe API infrastructure to host credit card-stealing payloads and exfiltrate data. Malicious code loads from Google Tag Manager containers targeting Magento/Adobe Commerce checkout pages. The skimmer reads obfuscated JavaScript from Stripe customer metadata (cus_TfFjAAZQNOYENR), captures payment data, stores it in localStorage, then exfiltrates back to attacker's Stripe account as fake customer records. Trusted domains (api.stripe.com, googletagmanager.com) bypass CSP rules and network filters. A variant uses Google Firestore document tracking/captcha in project braintree-payment-app. The Stripe customer record was created December 24, 2025.

VIP Keylogger via JavaScript Loaders

Threat actors deploy VIP Keylogger via social engineering using JavaScript, batch scripts, and VBS loaders. The 2MB "Remittance Advice.js" file contains junk code masking a ROT13-obfuscated PowerShell payload executed via WMI. PowerShell fetches MSI background JPEG from Cloudflare Workers (icy-lab-0431.guilherme-telecomunicacoes2024.workers.dev) containing Base64-encoded payload (delimited "IN-" and "-in1", "A" replaced by "#"). The payload is a modified .NET DLL (Microsoft.Win32.TaskScheduler). A secondary file (snake.png) from Cloudflare R2 (pub-a06eb79f0ebe4a6999bcc71a2227d8e3.r2.dev) contains steganography-protected payloads. Attackers masquerade as bank payments, procurement orders, and logistics updates.

FlutterShell macOS Malvertising

Operation FlutterBridge spreads FlutterShell backdoor via malicious Google/YouTube ads. FlutterShell (built with Flutter) infects macOS with adware via malicious desktop apps (PodcastsLounge, PDF-Brain, PDF-Ninja). The backdoor has shell command execution and file system manipulation capabilities. Attributed to CL-CRI-1089 (active since 2023), the campaign targets macOS users in US, Canada, Australia, France, Germany. FlutterShell modifies Chrome config files to hijack the browser, forcing traffic through attacker-controlled ad-filled intermediary. All samples were signed with valid Apple Developer IDs and passed notarization. FlutterShell uses WebView-based architecture with JavaScript-to-native bridge, allowing dynamic behavior changes without recompiling.

FIFA World Cup 2026 Scams

Group-IB tracked 4,300+ fraudulent FIFA domains registered since August 2025. GHOST STADIUM (Chinese-speaking) runs one phishing kit across 300+ sites. The fake login mimics FIFA's PingIdentity single sign-on with genuine client ID, loads images from FIFA servers, and asks to reset passwords to lock victims out and resell tickets. Traffic comes from Facebook ads, Telegram, WhatsApp, search results. Payment includes crypto (a tell, as FIFA never accepts crypto). Group-IB estimates $71-474 million losses from premium/hospitality ticket fraud. FortiGuard Labs counted 13,000+ World Cup domains (8.8% malicious). ThreatFabric saw spike in malicious streaming apps (pretending to be RojaDirecta) installing Android banking trojans.

Patch Priority

Vulnerability Disclosures

Hitachi Energy ICS Vulnerabilities

CISA published three advisories for Hitachi Energy industrial control systems. RTU500 (ICSA-26-155-04): 7 CVEs affecting CMU Firmware 12.7.1-12.7.7, 13.5.1-13.5.4, 13.6.1-13.6.3, 13.7.1-13.7.8, 13.8.1, primarily DoS impact with potential confidentiality/integrity impacts. Update to 13.8.2 or 13.7.9. ITT600 Explorer (ICSA-26-155-02): CVE-2024-8176 (stack overflow in libexpat) and CVE-2025-59375 (uncontrolled resource allocation), both DoS vulnerabilities. Update to 2.1 SP6 HF1. MACH HiDraw (ICSA-26-155-05): CVE-2026-7310 heap-based buffer overflow in XML parser. Update to 9.23. Critical infrastructure: Dams, Energy, Water/Wastewater, Transportation.

B&R PPT30 OPC-UA DoS (CVE-2025-11482)

Resource allocation vulnerability in OPC-UA Server in B&R PPT30 Operating System before 1.8.0 allows unauthenticated network-based attackers to permanently DoS the service. OPC-UA server is not activated by default. Fixed in 1.8.0. Critical infrastructure: Commercial Facilities, Critical Manufacturing, Energy, Transportation, Water/Wastewater.

Trends & Context

Three patterns dominate. First, authentication bypasses compound: Cisco's seventh SD-WAN zero-day chains with two prior auth bypasses for root access, Unified CM's third critical auth flaw in 18 months. Second, AI accelerates both attack and defense: Chrome's 429 patches are AI-discovered, Claude Code and Cowork enable 10-30 minute exfiltration, Microsoft documents 512 OpenClaw vulnerabilities days after launch. Third, trusted infrastructure weaponizes: Stripe/Firestore host skimmers, Cloudflare Workers deliver malware, GTM containers execute theft, Apple Developer IDs sign malware that passes notarization. Defenders must assume trusted platforms carry malicious payloads.