← Carolina Clear Tech

Cyber Threat Brief

2026-06-07

Listen to this brief (15:40)

Download MP3
Show Notes

Show Notes - 2026-06-07

Stories Covered

CVEs Referenced

CVE-2026-10722, CVE-2026-11332, CVE-2026-27145, CVE-2026-3276, CVE-2026-3300, CVE-2026-37460, CVE-2026-42504, CVE-2026-42507, CVE-2026-43958, CVE-2026-50219, CVE-2026-5419, CVE-2026-7774, CVE-2026-8643, CVE-2026-8829

Indicators of Compromise

IP Addresses: 202.56.2.126, 209.146.60.26

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

2026-06-07

Today: WordPress site takeovers are spreading via a critical Everest Forms Pro exploit that creates rogue admin accounts. Cisco SD-WAN systems face active zero-day attacks with no patch available. US fuel tank gauges are under attack, with 909 Internet-exposed devices concentrated stateside creating infrastructure disruption risks.

Critical Alerts

Cisco SD-WAN Zero-Day Under Active Attack

Cisco SD-WAN systems are being actively exploited through a zero-day vulnerability with no patch currently available. The vulnerability allows attackers to compromise SD-WAN infrastructure, potentially enabling network-wide access and traffic manipulation. Cisco has not released specific CVE details or severity scores yet.

Critical Everest Forms Pro Flaw Exploited to Take Over WordPress Sites (CVE-2026-3300)

Hackers are exploiting CVE-2026-3300, a critical unauthenticated remote code execution vulnerability in Everest Forms Pro plugin versions 1.9.12 and earlier. The flaw exists in the Complex Calculation feature, where user input passed through forms is inserted into PHP code strings and executed via eval(). Attackers are injecting PHP code to create administrator accounts with username "diksimarina". Wordfence blocked over 29,300 exploitation attempts since active exploitation began April 13. EPSS score is 0.003 (55th percentile), indicating low predicted exploitation probability, but active exploitation is confirmed.

Exposed Fuel Tank Gauges Under Attack in the US

Threat actors are targeting Internet-exposed automatic tank gauge (ATG) systems at industrial facilities and gas stations across the United States. ATGs monitor liquid storage tanks for fuel, chemicals, and other materials. By compromising these systems, attackers can alter tank readings, disable safety alerts, or manipulate pump controls. CISA, FBI, NSA, DoE, EPA, TSA, DOT, and USDA issued a joint notice urging organizations to harden ATG systems. Shadowserver Foundation scans identified 909 exposed ATG devices in the US, representing over 90% of global exposure. Previous campaigns linked to Iranian threat actors have targeted gas station ATGs.

Business & Infrastructure Threats

Adaptive AI Worms Loom as Next Enterprise Threat

Researchers at University of Toronto, Vector Institute, ServiceNow, Cambridge, and BeyondTrust have developed proof-of-concept agentic AI worms that autonomously propagate by searching for vulnerabilities, adapting to new environments, and creating exploit code dynamically. These worms use small, free AI models to power recursive reasoning loops that detect and exploit diverse vulnerabilities across systems. Unlike traditional worms that exploit a single bug, AI worms adapt in real-time and cannot be stopped by patching a specific vulnerability. BeyondTrust predicts AI-powered worm attacks targeting developers and engineers within six months to a year. Early examples like Shai-hulud (npm credential stealer) and GlassWorm (VS Code extension attack) have already combined self-propagation with credential theft.

ChatGPT Lockdown Mode Limits Data Exfiltration Tools

OpenAI has rolled out Lockdown Mode for ChatGPT personal accounts (Free, Go, Plus, Pro, and self-serve Business plans) to reduce data exfiltration risks from prompt injection attacks. Lockdown Mode disables live web browsing (restricts to cached content only), image display and retrieval, deep research, agent mode, Canvas networking, and file downloads. The feature does not prevent prompt injections but eliminates pathways for exfiltrating sensitive data to attacker-controlled infrastructure. Lockdown Mode and another unnamed feature cannot be enabled simultaneously. OpenAI also launched session management controls allowing users to review active sessions by device, location, and sign-in time.

Patch Priority

Vulnerability Disclosures

CVE-2026-3300: Everest Forms Pro Unauthenticated RCE

Critical vulnerability in Everest Forms Pro for WordPress versions 1.9.12 and earlier allows unauthenticated remote code execution via PHP injection in Complex Calculation feature. EPSS 0.003 (55th percentile). Active exploitation since April 13 targeting admin account creation.

CVE-2026-50219: libexpat Use-After-Free Vulnerability

libexpat versions before 2.8.2 contain a use-after-free vulnerability due to missing handler call depth tracking when XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset are called from within handlers during policy violations. EPSS 0.000 (2nd percentile).

CVE-2026-8643: pip Path Traversal in Script Installation

Python package installer pip can extract console_scripts and gui_scripts outside the intended installation directory, allowing path traversal attacks. EPSS 0.000 (6th percentile).

CVE-2026-7774: Python tarfile Path Traversal Bypass

tarfile.data_filter in Python allows path traversal bypass, enabling malicious archives to write files outside the extraction directory. EPSS 0.000 (9th percentile).

CVE-2026-11332: Ansible-core Argument Injection in ansible-galaxy

Ansible-core vulnerable to argument injection in ansible-galaxy role install command, leading to arbitrary code execution. EPSS 0.000 (6th percentile).

CVE-2026-3276: Python DoS via Quadratic Complexity in unicodedata.normalize()

Python unicodedata.normalize() function vulnerable to denial-of-service through quadratic complexity when processing specially crafted Unicode input. EPSS 0.000 (16th percentile).

CVE-2026-43958: RRDtool Stack Buffer Overflow

RRDtool stack buffer overflow allows local code execution or denial-of-service. EPSS 0.000 (2nd percentile).

CVE-2026-10722: cilium eBPF Integer Overflow

cilium eBPF library vulnerable to integer overflow in LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec function. EPSS 0.000 (2nd percentile).

CVE-2026-37460: FRRouting BGP DoS Vulnerability

FRRouting (FRR) stable/10.0 through stable/10.6 vulnerable to denial-of-service via crafted BGP UPDATE messages due to missing input validation in rfapiRibBi2Ri() function. EPSS 0.000 (13th percentile).

CVE-2026-42504: Go mime Package Quadratic Complexity DoS

Go WordDecoder.DecodeHeader in mime package vulnerable to denial-of-service through quadratic complexity when processing malformed MIME headers. EPSS 0.000 (13th percentile).

CVE-2026-42507: Go net/textproto Unescaped Input in Errors

Go net/textproto package includes arbitrary inputs in error messages without escaping, potentially enabling injection attacks when error messages are logged or displayed. EPSS 0.000 (9th percentile).

CVE-2026-27145: Go Inefficient Hostname Parsing in crypto/x509

Go crypto/x509 package vulnerable to resource exhaustion through inefficient candidate hostname parsing when validating certificates. EPSS 0.000 (1st percentile).

CVE-2026-8829: Perl HTML::Entities Use-After-Free

HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities function. EPSS 0.000 (9th percentile).

CVE-2026-5419: GnuTLS Timing Side-Channel in PKCS#7 Padding

GnuTLS vulnerable to information disclosure via timing side-channel in PKCS#7 padding removal. EPSS 0.000 (12th percentile).

General Security News

Opal Security Raises $23 Million for AI-Native Identity Governance

Opal Security raised $23 million in funding led by Greylock and Battery Ventures, bringing total investment to $59 million. The company provides AI-native identity governance with real-time visibility and policy-as-code for employees, service accounts, and AI agents. Opal automates just-in-time access, revokes access based on risk and staleness, and enforces policies at machine speed. The company expanded headcount by 60% in 2026, primarily in engineering, product, and go-to-market roles.

Trends & Context

Today's threat landscape shows active exploitation of critical vulnerabilities in widely-deployed systems (WordPress plugins, Cisco SD-WAN, industrial controls), with attackers moving faster than patching cycles. The emergence of AI-powered adaptive worms represents a fundamental shift from single-exploit propagation to intelligent, multi-vector attacks that will require behavioral detection rather than signature-based defenses. Industrial control systems remain critically exposed, with US infrastructure disproportionately vulnerable due to Internet-facing management interfaces on legacy devices.