← Carolina Clear Tech

Cyber Threat Brief

2026-06-06

Listen to this brief (33:21)

Download MP3
Show Notes

Show Notes - 2026-06-06

Stories Covered

CVEs Referenced

CVE-2021-35211, CVE-2022-20775, CVE-2024-28995, CVE-2026-0257, CVE-2026-10881, CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20133, CVE-2026-20182, CVE-2026-20245, CVE-2026-28318, CVE-2026-39210, CVE-2026-39218

Indicators of Compromise

Domains: lhlsjcb[.]com., polyfill[.]io

IP Addresses: 23.128.228.6, 104.207.144.154, 146.19.216.119, 146.19.216.120, 146.19.216.125, 179.43.172.213, 185.195.232.139, 198.12.106.60, 202.144.192.47

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - June 6, 2026

Today: SolarWinds Serv-U and Cisco SD-WAN vulnerabilities are being exploited in the wild with no patch available for the Cisco flaw. CISA added Serv-U CVE-2026-28318 to the KEV catalog with a June 19 deadline for federal agencies. A Chinese APT deployed new custom backdoors including Plenet and AgentPSD to maintain persistent access after initial detection and remediation. The npm supply chain faces coordinated attacks from IronWorm malware and the Miasma worm, which compromised 73 Microsoft GitHub repositories.

Critical Alerts

SolarWinds Serv-U CVE-2026-28318 Denial-of-Service Vulnerability (CISA KEV)

CISA warned that hackers are actively exploiting a high-severity denial-of-service flaw in SolarWinds Serv-U file transfer software to crash servers. The vulnerability (CVE-2026-28318, CVSS 7.5, EPSS 0.001) stems from uncontrolled resource consumption when specially crafted POST requests use Content-Encoding: deflate. Remote attackers can exploit the flaw without authentication or user interaction. SolarWinds released version 15.5.4 Hotfix 1 on Thursday to address the issue. Over 12,000 Serv-U servers are exposed online according to Shodan, with Shadowserver tracking just over 3,100. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by June 19. Serv-U has been targeted by multiple threat groups in recent years, including the Clop ransomware gang exploiting CVE-2021-35211 (EPSS 0.943, CISA KEV) and Chinese hackers using CVE-2024-28995 (EPSS 0.944, CISA KEV).

Cisco Catalyst SD-WAN Manager CVE-2026-20245 Actively Exploited (No Patch Available)

Cisco confirmed active exploitation of CVE-2026-20245 (CVSS 7.8, EPSS 0.001), a command injection vulnerability in Catalyst SD-WAN Manager CLI that allows authenticated local attackers with netadmin privileges to execute arbitrary commands as root. The flaw affects on-premises deployments, SD-WAN Cloud-Pro, Cisco Managed Cloud, and FedRAMP government installations. Exploitation requires valid credentials or chaining with CVE-2026-20182 (CVSS 10.0, EPSS 0.831, CISA KEV) or CVE-2026-20127 (EPSS 0.548, CISA KEV), both authentication bypass vulnerabilities exploited as zero-days. Cisco observed limited cases where attackers used CVE-2026-20245 to push configuration changes to edge devices. Google Mandiant researchers discovered and reported the vulnerability. No patches or mitigations are currently available. This is the seventh SD-WAN vulnerability exploited in the wild this year, following CVE-2026-20182, CVE-2026-20127, CVE-2026-20122 (EPSS 0.013, CISA KEV), CVE-2026-20128 (EPSS 0.001, CISA KEV), CVE-2026-20133 (EPSS 0.019, CISA KEV), and CVE-2022-20775 (EPSS 0.004, CISA KEV).

Palo Alto PAN-OS CVE-2026-0257 GlobalProtect Authentication Bypass

Unit 42 observed active exploitation of CVE-2026-0257 (EPSS 0.478, CISA KEV due June 1), an authentication bypass in PAN-OS GlobalProtect portal and gateway components. The vulnerability allows unauthenticated attackers to circumvent security controls and establish VPN connections. CISA added the flaw to the KEV catalog on May 29. Exploitation attempts probed devices using suspicious host IDs (aa:bb:cc:dd:ee:ff, 00:11:22:33:44:55) and device names (WINDOWS-LAPTOP-001, DESKTOP-GP01, GP-CLIENT). A small portion of probed devices established successful gateway-connected sessions. Post-PoC exploitation uses hard-coded client configuration values including endpoint OS version "Microsoft Windows 10 Pro 64-bit" and empty source_user_info.domain field. No post-access lateral movement has been identified.

Ransomware & Extortion

UNC3753 (Luna Moth, Chatty Spider) Vishing Campaign Targets US Law Firms

Google Mandiant identified a financially motivated data theft extortion campaign by UNC3753 targeting dozens of organizations across professional, legal, and financial services in the United States from January through May 2026. The threat group uses voice phishing and social engineering to achieve remote access, posing as IT support and convincing targets to host screen-sharing sessions and download remote monitoring and management utilities. Attackers initiate campaigns with benign invoice-themed emails from consumer accounts containing no malicious links or attachments, establishing a pretext for follow-up vishing calls. Once inside, threat actors search for and exfiltrate proprietary legal agreements, personally identifiable information, and financial records for subsequent extortion. The entire attack sequence from initial contact to data theft and extortion often occurs within a single business day, with recent incidents showing data searches, staging, and theft initiated in under one hour. In physical incidents possibly linked to UNC3753, individuals posing as IT technicians entered corporate offices to directly exfiltrate data from endpoints using USB storage media.

Business & Infrastructure Threats

Over 900 US Automatic Tank Gauge Systems Exposed to Attacks

CISA, FBI, NSA, and Department of Energy issued a joint advisory warning that over 900 automatic tank gauge (ATG) systems used to monitor fuel and chemical storage tanks across US critical infrastructure are exposed online and vulnerable to ongoing attacks. Threat actors exploit hardcoded credentials, authentication bypasses, SQL injection, OS command execution flaws, and privilege escalation weaknesses to alter system settings through command execution. Following successful compromises, attackers disable system alerts, increasing the risk of leaks or equipment failures and potentially causing permanent damage to tank systems. Shadowserver reported 1,061 ATG systems exposed globally on port 10001/tcp as of June 5, with 909 in the United States. CNN reported in May that Iranian hackers breached ATG systems at multiple US gas stations, manipulating display readings without altering actual fuel levels. These incidents, while not causing physical damage, raise concerns about hindering automated fuel leak detection and safety-related functions. In April, Iranian state-backed hackers were linked to attacks on Rockwell Automation/Allen-Bradley PLC devices since March 2026, with Censys reporting 74.6% (3,891 hosts) of exposed industrial control systems globally located in the United States.

IronWorm and Miasma Worm Hit npm Supply Chain

Multiple software supply chain attacks targeted the npm ecosystem, distributing a Rust-based information stealer (IronWorm) and a self-spreading worm (Miasma). IronWorm scrapes secrets from developer machines, hides behind an eBPF kernel rootkit, and communicates over Tor. The malware targets 86 environment variables and files containing credentials for OpenAI Codex, Anthropic Claude, Google Gemini, Cursor, AWS, Docker, Kubernetes, npm, vault configurations, and Exodus cryptocurrency wallets. The attack originated from compromised npm account "asteroiddao," publishing trojanized package versions containing a Rust ELF binary executed via preinstall hooks. IronWorm uses stolen credentials as a propagation mechanism, publishing itself to npm and committing malicious code to GitHub repositories under the author name "claude" ([email protected]) mimicking Anthropic's AI chatbot. In CI environments, the malware abuses npm's Trusted Publishing flow to obtain short-lived tokens for pushing poisoned packages. The eBPF payload functions as a kernel-level rootkit to hide processes, though it fails on systems with kernel lockdown enabled. Separately, Miasma worm compromised 57 npm packages across 286 malicious versions and 73 Microsoft GitHub repositories across Azure, Azure-Samples, Microsoft, and MicrosoftDocs organizations. GitHub disabled access to affected repositories. The Miasma attack included re-compromise of the durabletask PyPI package previously infected by TeamPCP last month, suggesting credential persistence. The worm skipped npm registry entirely for some attacks, pushing malicious code directly to repositories including icflorescu/mantine-datatable and related projects, with payloads detonating when developers clone affected repos and open them in AI coding agents (Claude Code, Gemini CLI, Cursor, VS Code).

Smart TV Apps Turn Devices Into Web-Scraping Proxies for AI

Researchers reverse-engineered the iOS SDK embedded by Bright Data in consumer apps, documenting how it turns devices including always-on smart TVs into exit nodes relaying web-scraping traffic for AI industry customers. Bright Data operates what it claims is the largest residential proxy network in the world, advertised at over 400 million residential IPs, with 150 million-plus IPs from SDK-embedded apps. The scraping uses the user's home IP address and bandwidth, not the customer's. Connected TVs are ideal targets: usually plugged in, on fast connections, effectively unmetered, and unwatched. The peer channel carrying scraping jobs has no authentication on iOS, and its traffic bypasses configured VPNs. The SDK can relay in the background during screen use or calls, as long as battery is not low. Opt-in screens do not match actual SDK behavior. One Roku app (Petflix) stated it would use the device "occasionally," but SDK settings allow up to 200 GB monthly traffic. In some countries including Uzbekistan and Oman, limits are set far higher with devices cleared to work almost until battery depletion. The SDK can tie together multiple devices (phone, computers) running the same company's apps, treating them as one user. Bright Data's public partner list includes smart-TV app makers PlayWorks Digital, CloudTV, and Longvision. The business model is not new, but AI demand has driven scale. Anti-bot defenses from Cloudflare and DataDome block datacenter IPs, forcing AI scrapers to route through residential connections.

Microsoft Claude Code GitHub Action Exposes CI/CD Secrets

Microsoft Threat Intelligence discovered that Anthropic's Claude Code GitHub Action could expose CI/CD workflow secrets when AI agents process untrusted GitHub content including issue bodies, pull request descriptions, and comments. While Claude Code Action supported environment scrubbing for subprocess execution paths like Bash, the Read tool was not subject to the same sandboxing model and was authorized to access /proc/self/environ, reading the workflow's ANTHROPIC_API_KEY and potentially other credentials available to the runner. Anthropic mitigated the issue in Claude Code version 2.1.128 by blocking access to sensitive /proc files. Microsoft observed prompt injection attempts in public repositories using AI-assisted GitHub workflows across multiple vendors, where attacker-controlled issue or PR content is processed by AI agents and can influence tool use. One example showed an XSS injection via issue triage workflow where a payload disguised as HTML comment instructed an AI bot with operational tools (search_local_git_repo, read_local_git_repo_file_content, create_pull_request_from_changes) to append malicious HTML and immediately create a pull request, effectively steering the AI through a supply-chain compromise step-by-step.

Windows / AD Security

Chinese APT UNC5221 Deploys New Malware (Plenet, AgentPSD) for Persistent Access

Volexity researchers responding to an incident found Chinese espionage group UNC5221 (also tracked as VertiBamboo) accessing Microsoft 365 environments using the Brickstorm backdoor and previously undocumented malware named Plenet and AgentPSD. The threat actor had gained access to the victim network at least 18 months before detection and also compromised the victim organization's managed services provider. UNC5221 has been involved in attacks exploiting zero-day vulnerabilities in edge devices since at least 2023 and used Brickstorm undetected for over a year until March 2025. Initial access involved compromising an Egnyte Storage Sync system accessed periodically through the victim's web SSL VPN. From this foothold, using Brickstorm proxying features and stolen credentials, the threat actor accessed Microsoft 365 to blend in with legitimate network traffic and evade Conditional Access policies. After remediation, the attacker returned using stolen credentials to enable and configure SSL VPN access on the victim's firewall, then deployed custom malware to a Synology NAS device. Investigation at the MSP found a BSD variant of Brickstorm on a pfSense firewall compromised at least 18 months earlier. Plenet (also tracked as Grimbolt) is a cross-platform .NET-based backdoor offering interactive shell access, remote command execution, file manipulation, and C2 server switching, using WebSocket protocol for communications. AgentPSD is a simple Python-based reverse shell utility configured to connect to a different domain than Brickstorm, serving as a fallback persistence mechanism.

OP-512 Threat Cluster Targets Microsoft IIS Servers with Custom Web Shell Framework

ReliaQuest discovered OP-512, a previously unreported Chinese-aligned threat cluster targeting Microsoft IIS servers with a bespoke web shell framework. The espionage-focused activity was observed against a legacy IIS server running Windows Server 2016 with end-of-life .NET Framework 4.0. The custom framework consists of three web shells granting remote access while evading signature-based detection and complicating forensic timelines using timestomping. The malware scans every file and sub-folder around web shell placement, calculates the median last-modified timestamp, and overwrites creation and modification times to match that value, creating the impression of long-term presence. Each deployment is uniquely generated with cryptographic access controls restricted to the attacker. Compromised servers automatically report back for centralized management at scale. Prior activity on the same host occurred 75 days before the main incident, involving DNS queries to attacker-controlled domain "ashx.lhlsjcb[.]com." The main attack used the web server's worker process (w3wp.exe) to drop web shells to the application's upload directory, triggering self-reporting via DNS query or HTTP fallback to transmit the web shell's location. The framework provides file management, authenticated command execution through two independent access paths, and automated reporting. OP-512 attempted privilege escalation to SYSTEM level using the Potato Suite, followed by running "whoami /priv" to confirm system rights. This is the fourth Chinese-aligned threat group (after CL-STA-0048, DragonRank, and GhostRedirector) targeting IIS servers in the past 12 months.

General Security News

Polyfill Service Reactivation Causes Login Prompts on Major Websites

Japanese companies Toshiba and Muji warned visitors that suspicious sign-in screens popping up on their websites could collect credentials. Both companies advised users who entered login data to change passwords. The login pop-ups were generated by the external service hosted at polyfill[.]io, which in 2024 introduced malicious code after the domain was purchased by a Chinese entity. Polyfill is a JavaScript CDN for legacy browsers, providing a compatibility layer for unsupported technologies. The original domain polyfill[.]io was not owned by the project creator Andrew Betts, so when it expired, it was claimed by another party. Betts recommended removing the service and relaunched at polyfill.com, later settling at polyfill.top. While deactivation of polyfill[.]io stopped redirections in 2024, some sites failed to clean all pages over the past two years, leaving remnants of Polyfill code. Starting in late May 2026, the polyfill[.]io domain became active again and started responding with HTTP 401 authentication requests. User browsers interpret this as a request for username and password, serving a login prompt. Japanese media outlets reported Zojirushi, FiNC Technologies, Ishiyaku Publishers, and Hobonichi were also impacted. Samsung Smart TVs and websites displayed login prompts on June 1. There is no indication that impacted websites were hacked or that credentials entered on rogue login screens were stolen, but users should be cautious.

2026 Verizon DBIR Highlights Browser-Based Attacks and Shadow AI

The 2026 Verizon Data Breach Investigations Report (DBIR) identified browser-based attacks and shadow AI as major enterprise risks. Shadow AI was the third most common non-malicious insider action in DLP datasets, representing a fourfold increase from the previous year. 67% of users access AI services on corporate devices through personal, non-corporate accounts, and 45% of employees are regular AI users. Over half of AI prompt inputs are sent to personal accounts, with 23% of sensitive prompt uploads involving data transiting through personal or unverified accounts outside corporate DLP policy or logging. 39% of breaches involved credential abuse. Keep Aware attack data shows browser-based credential theft as the number one browser-based attack at 41% of observed threat activity. 63% of Microsoft-themed phishing sites were not flagged by any VirusTotal vendor at time of employee exposure. 100% of credential theft attempts observed passed through existing non-browser security controls (network proxies, DNS filters, endpoint agents) unblocked. The average enterprise had more than 15% of users with unauthorized AI extensions installed. 13% of unique browser extensions across customer base were classified as high or critical risk. 93% of poor-risk extensions were not detected by traditional controls.

Vulnerability Disclosure Dispute Between Microsoft and Nightmare Eclipse Researcher

Microsoft threatened criminal legal action against security researcher "Nightmare Eclipse" who publicly disclosed six zero-day vulnerabilities (RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, MiniPlasma) with proof-of-concept exploits. Microsoft claimed it received no details prior to release and that defects were not responsibly disclosed, putting customers at unnecessary risk. Attackers exploited three of the six vulnerabilities before Microsoft patched them. The researcher claimed Microsoft refused to communicate, did not pay or credit them for discovering and reporting vulnerabilities, deleted their Microsoft Security Response Center account, and flagged their GitHub account for removal. The researcher threatened Microsoft with a release in mid-July that "will make sure your bones are shattered that day." The dispute revived friction between vendors and researchers who find and report software flaws. Katie Moussouris, former Microsoft employee who created the company's first bounty program, said Microsoft got emotional and should not have publicly called out a researcher while involving law enforcement. The controversy highlights ongoing challenges in coordinated vulnerability disclosure processes.

Patch Priority

Vulnerability Disclosures

AI Agent Discovers 21 Zero-Days in FFmpeg

Security startup depthfirst reported 21 previously unknown vulnerabilities in FFmpeg, the media library used in most video-touching software, all discovered by an autonomous AI agent. The scan of FFmpeg's approximately 1.5 million lines of C cost around $1,000. Several bugs had been latent for 15 to 20 years, with one stack overflow in the service-description-table code dating to 2003 (23 years). Most are heap or stack overflows in parsers and demuxers, spanning components from the TS demuxer to the VP9 decoder. Nine vulnerabilities carry CVE identifiers (CVE-2026-39210 through CVE-2026-39218), with the rest fixed but not yet numbered. A proof-of-concept was published. FFmpeg is widely bundled in media pipelines, Python wheels, container images, and appliances, so embedded copies need patching in addition to system packages. Google's Big Sleep agent previously reported FFmpeg bugs tagged BIGSLEEP on the project's security page. Anthropic's Mythos model found a 16-year-old H.264 flaw and others for about $10,000, with three shipping in FFmpeg 8.1. Another autonomous tool recently found an authenticated RCE in Redis present since version 7.2.0, unnoticed for over two years.

Chrome 149 Patches Record 429 Vulnerabilities

Google shipped Chrome 149 with patches for 429 security bugs, the most ever in a single release. Over 100 are critical or high severity, mostly use-after-free and insufficient input validation. CVE-2026-10881 (CVSS 9.6, EPSS 0.001) is the worst: an out-of-bounds read and write in the ANGLE graphics engine allowing crafted pages to escape the sandbox and run code on the host. Google paid $97,000 for it. Of roughly 90 high-severity bugs, only 10 came from outside researchers. 19 of 22 critical bugs were Google's own internal finds. The volume increase correlates with Google's April bounty program overhaul prompted by a flood of AI-generated submissions, now asking for concise reproducers over long writeups AI generates. Google has not tied the 429 count to AI, but the bounty changes signal AI-driven volume. The record release comes the same week as the FFmpeg AI-discovered zero-days and follows a February study showing an agent reproducing working PoCs for more than half of 100 real Linux kernel N-day bugs, beating fuzzing.

Sound Blaster Katana V2X Speaker Remote Code Execution via Bluetooth

Researcher Rasmus Moorats discovered remote code execution vulnerabilities in Creative Technologies Sound Blaster Katana V2X speaker ($283). The speaker connects to PCs, Macs, and Linux devices over USB or Bluetooth using Creative Transport Protocol (CTP). Bluetooth devices can connect without authentication or pairing and send CTP commands to the speaker, which is connected to a PC via USB. One CTP command labeled "upload new firmware to device" allows replacing official firmware with custom code without code signing or verification. An attacker within Bluetooth range can reflash the speaker's firmware and potentially pivot to the connected PC. The vulnerability chain requires physical proximity but no physical access to the target device.

Trends & Context

Four distinct threat patterns converge this week. First, enterprise infrastructure faces sustained targeting with no patch availability (Cisco SD-WAN) or active exploitation before vendor response (SolarWinds Serv-U, Palo Alto GlobalProtect). Second, supply chain attacks show exponential propagation through automated credential theft and self-replication (IronWorm, Miasma worm, Microsoft GitHub compromise). Third, AI-driven vulnerability discovery and exploitation is accelerating faster than human-dependent remediation processes (FFmpeg 21 zero-days for $1,000, Chrome 429 bugs in one release, Redis 2-year-old RCE). Fourth, Chinese APT groups demonstrate multi-year persistence through custom tooling and MSP compromise (UNC5221's 18-month dwell time, OP-512's timestomping web shells, four IIS-targeting clusters in 12 months). Organizations face machine-speed threats requiring automated defenses and assume-breach posture for legacy systems.