Rosetta Daily · Jun 4, 2026
Auto-generated · 29 sources configured (WebSearch mode — feed allowlist still in effect) · 15 items selected
Window: past 24 hours (2026-06-03 → 2026-06-04)
In-the-Wild / Actively Exploited
-
🔴🔥⚠️ Windows Netlogon CVE-2026-41089 (CVSS 9.8) — unauthenticated RCE on domain controllers, now exploited in the wild
The Centre for Cybersecurity Belgium (CCB) warned that CVE-2026-41089, a stack-based buffer overflow in Windows Netlogon, is now under active exploitation. An attacker sends a specially-crafted network request to a server acting as a domain controller — no authentication, local access, or user interaction required — and gains SYSTEM-level code execution on the DC itself, i.e. full control of the Active Directory domain, privileged-account creation, and lateral movement across everything that authenticates against the controller. Microsoft (MSRC, disclosed 5/12, credited to its WARP team) rates it CVSS 9.8 and marks customer action required. Hunt indicators: Netlogon service crashing/restarting, anomalous Netlogon traffic from non-DC sources, auth/domain-trust errors after suspicious DC-bound traffic. Patch domain controllers immediately.
Help Net Security · Bleeping Computer · SecurityWeek · NVD -
🔴🔥⚠️ Citrix NetScaler CVE-2026-3055 (CVSS 9.8) — large-scale exploitation of SAML IDP memory-overread confirmed by Fortinet
Fortinet's threat-intelligence team confirmed large-scale active exploitation of CVE-2026-3055, an out-of-bounds read from insufficient input validation in NetScaler ADC / Gateway when configured as a SAML Identity Provider. A remote, unauthenticated attacker sends crafted SAML requests to trigger a memory overread that can be leveraged for RCE; FortiGuard reports thousands of attempts blocked daily against exposed SAML endpoints worldwide, and CISA has added it to KEV. Fixed in NetScaler ADC 13.1-62.23+ and 14.1-60.58+ (and corresponding Gateway builds). Inventory internet-facing NetScaler SAML IDPs and patch now.
Threat-Modeling.com · Horizon3.ai · Security Affairs (KEV) · Citrix bulletin -
🔥 Kirki WordPress plugin CVE-2026-8206 (CVSS 9.8) — now actively exploited for admin account takeover (500k+ installs)
Yesterday's "expect mass-scanning" call materialized. The Kirki customizer-framework flaw is being actively exploited: a single unauthenticated HTTP request with a known username and an attacker-controlled email triggers a password reset to the attacker, yielding full account takeover including administrators. Wordfence (Defiant) blocked 222+ attempts in 24 hours. Affects 6.0.0–6.0.6 (~150k sites estimated vulnerable); patched in 6.0.7 (released 5/18). Update or disable the plugin and audit for rogue admin accounts.
Bleeping Computer · Threat-Modeling.com · SecurityWeek -
🔥 CISA KEV additions (June 2) — Linux Kernel CVE-2022-0492 + Android Framework CVE-2025-48595
CISA added two flaws to KEV on 2026-06-02: CVE-2022-0492, a Linux kernel cgroups-v1 improper-authentication privilege-escalation bug (container-escape vector), and CVE-2025-48595, the Android Framework integer-overflow EoP that anchored yesterday's Android June bulletin. FCEB remediation deadlines apply. Sweep container hosts for the cgroups path and confirm the June Android patch level is rolling across fleet devices.
CISA alert (6/2) · CISA KEV catalog
Critical Vulnerabilities & Advisories
- Microsoft Word/Outlook CVE-2026-40361 (CVSS 8.4) — zero-click RCE via the Outlook Preview Pane
A use-after-free in a DLL shared by Word and Outlook can execute code as soon as a malicious email renders in the Outlook Preview Pane— no clicks, no macros, no Protected-View dismissal, no admin rights. Discovered by Haifei Li; Microsoft rates it "Exploitation More Likely." Patched in the May 2026 cumulative updatesfor Microsoft 365 Apps, Office 2024/2021/2019 and standalone Word. Interim mitigation: set Outlook to render email as plain text. Prioritize for any org still behind on May Office updates.
SecurityWeek· gblock analysis· Field Effect
Vendor Advisories
-
CISA orders WebLogic patched by today (June 4) — CVE-2024-21182, ~1,600 servers still exposed
Following the 6/1 KEV addition, CISA set the FCEB remediation deadline at June 4 for the Oracle WebLogic Server flaw (unauthenticated access via T3/IIOP). Oracle patched it in July 2024, yet Shodan still shows ~1,592 exposed vulnerable servers (961 on 12.2.1.4.0, 631 on 14.1.1.0.0). CISA urges private-sector defenders to patch alongside agencies. Inventory internet-reachable WebLogic and restrict T3/IIOP.
Bleeping Computer · Security Affairs -
Trend Micro Apex One CVE-2026-34926 — KEV remediation deadline is today (June 4)
Reminder: the exploited directory-traversal flaw in the Apex One (on-prem) 2019 server carries an FCEB deadline of 2026-06-04. Affects server/agent builds < 17079; fixed in SP1 Critical Patch Build 18012 / Build 17079. Cloud/SaaS Apex One unaffected. Verify the patch is applied today.
Bleeping Computer · CISA KEV
Web Security Research
-
⚠️🛡 SafeBreach — a single poisoned notification could hijack Google Gemini on Android ("notification injection")
SafeBreach's Or Yair (following the team's "Invitation Is All You Need" Calendar-invite work) showed that a hostile notification from WhatsApp, Slack, SMS, Signal, Instagram or Messenger could be treated by Gemini as trusted context — letting an attacker open connected apps, fake a message from the victim's boss, push the phone into a Zoom call, control smart-home devices, or poison Gemini's long-term memory for persistence. No malicious app on the device is required. Malicious instructions were hidden in foreign languages or muted hyperlinks. Reported to Google's VRP 8/17/2025; Google confirmed content-classifier mitigations on 11/14/2025 and there's no evidence of in-the-wild use. A clean case study of indirect prompt injection crossing into mainstream consumer assistants.
The Hacker News · SafeBreach research · Dark Reading -
🔴 "Miasma" supply-chain attack — 32 @redhat-cloud-services npm packages backdoored with a Shai-Hulud variant
Wiz Research (6/1) found 32+ package releases under the @redhat-cloud-services npm namespace (≈80k weekly downloads combined) carrying unauthorized modifications. Patient zero was a compromised Red Hat employee GitHub account that pushed malicious orphan commits to two RedHatInsights repos, bypassing review. The payload is a (Mini) Shai-Hulud derivative (TeamPCP-open-sourced code, cosmetically re-themed from Dune to Greek mythology) that performs a broad credential sweep: GitHub Actions secrets (GITHUB_TOKEN, ACTIONS_RUNTIME_TOKEN), AWS/GCP/Azure cloud creds, HashiCorp Vault and Kubernetes tokens, npm/PyPI publish tokens, SSH/GPG keys, Docker creds and.envfiles. Treat as TTP-overlap (copycat possible), not definitive TeamPCP attribution. Audit dependency trees and rotate any exposed CI/cloud secrets.
Wiz Research · The Hacker News · Bleeping Computer ·
AI Security
- Sophos — AI-built ransomware toolkit automates EDR evasion and Active Directory discovery (Cursor + Claude Opus agents)
Sophos (6/2) detailed a threat actor whose ransomware tooling was developed with assistance from Cursor and Claude Opus agentsacross coding, analysis and revision — including agents tasked with scraping security-research posts for bypass techniques. The framework bundles an automated AD-discovery paneland a lab that iteratively tests malware against Sophos, CrowdStrike and Windows Defender EDR, plus Cobalt Strike beacon-disguise profiles, Telegram C2, shellcode injectors, and a Cloudflare Worker fronting backend infra. Notably, the lab's own logs overclaimed evasion success— Sophos attributes the inflated results to LLM hallucination, and stresses the workflow remains human-driven. The offense side of the "AI compresses the attack lifecycle" story, in concrete form.
Bleeping Computer· Help Net Security· SC Media
Threat Intelligence
-
DriveSurge — new initial-access broker hijacking thousands of sites for ClickFix + FakeUpdates (Silent Push)
Silent Push named DriveSurge, a mature IAB operating a pay-per-install model across thousands of compromised websites that had evaded detection for nearly a year. Visitors are funneled through a TDS (zTDS) that profiles them and serves either a FakeUpdates lure (bogus update notices for Chrome, Firefox, Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, UC Browser) or a ClickFix PowerShell social-engineering lure. Targets both Windows and macOS; access is resold for data theft, wire fraud, identity theft and ransomware. Reinforce user-side "never paste a command an update told you to run" guidance and hunt for zTDS redirect patterns.
Bleeping Computer · Silent Push · Dark Reading -
June 3 breach cluster — ransomware-attributed disclosures span healthcare, financial, manufacturing
New 6/3 disclosures, most ransomware-attributed: Singing River Health System (Qilin/healthcare), Family Medical Associates of Raleigh (Genesis/healthcare), Hal Otey Financial (Akira/financial), Öztuğ Otomotiv (INC/Turkish auto manufacturing), Copamex (DragonForce/Mexican paper manufacturing), plus a cluster of Qilin victims (MarketJoy, JNP ENG, Eat Salad). Healthcare and manufacturing again over-represented. See Ransomware Today for watchlist hits.
ransomware.live · CISO Platform breach report (6/3)
Chinese-Language Community Picks
- FreeBuf / Anquanke / Yijing Lab and others: continued coverage of the June Android Security Bulletin (in-the-wild 0-day CVE-2025-48595), Exim CVE-2026-45185 high-severity RCE, the Gogs 0-day, and the commercialisation of Anthropic Claude Mythos / Project Glasswing (which surfaced over 10,000 high-severity vulnerabilities across more than 40 organisations) — all picked up in the Chinese-language community.
- CVE-2026-41089, a Windows Netlogon domain-controller RCE, is expected to spread quickly among domestic site operators and ops teams: unauthenticated RCE on a domain controller at CVSS 9.8 is a top-priority patch for Chinese enterprise AD environments.
- Supply-chain attacks stay hot for a second week: following TanStack / Mini Shai-Hulud, this cycle's Red Hat npm "Miasma" incident keeps Chinese-language discussion of npm and CI supply-chain poisoning climbing.
FreeBuf· FreeBuf vulnerabilities column
Ransomware Today
- ~30–40 new DLS posts in last 24hacross ~90 active leak sites (public-aggregator estimate; RansomLook direct fetch blocked). Confirmed 6/3 victims (8): Qilin → Singing River Health System (US hospital), MarketJoy, JNP ENG, Eat Salad; Akira → Hal Otey Financial (US financial); INC_RANSOM → Öztuğ Otomotiv (TR auto manufacturing); Genesis → Family Medical Associates of Raleigh (US healthcare); DragonForce → Copamex (MX paper manufacturing); Apt73/Bashe → smarty.arpinet.am (AM telecom). Watchlist hits today (6): Qilin × healthcare/multi-sector, Akira × financial, INC × manufacturing, healthcare/manufacturing/financial sector hits, US geo. Structural context unchanged: Qilin holds the multi-quarter #1 spot (>1,700 tracked victims), Akira second (>$150M 2025 proceeds), payment rate near an all-time low (~28%).
- Full per-victim breakdown → intel/ransomware/daily/2026-06-04.html
AI Frontier
OpenAI
- Codex role-specific plugins + Sites + annotations (June 3)— six new no-code plugins (62 apps, 110 skills), incl. a data-analytics plugin (Snowflake, Databricks Genie, Hex, Tableau); preview of Sitesfor sharing interactive workspace apps; in-place annotationsfor docs/sheets/slides. Codex now at 5M weekly users. SD Times roundup· Releasebot
- ChatGPT "Active sessions" security feature— users can review account sessions (device, location, sign-in time, trusted status) and sign out of unrecognized ones. Releasebot
- Model retirements (reminder)— GPT-4.5 leaves ChatGPT June 27; o3 leaves Aug 26. OpenAI model release notes
Anthropic
- Services Track + Partner Hub launched (June 3)— new tiers of the Claude Partner Network for services partners and a central partner hub. Anthropic news
- Project Glasswing expands to ~150 new orgs across 15+ countries (June 2)— total ≈200 partners; adds power, water, healthcare, communications and hardware sectors. Anthropic also shipped Claude Security(Opus 4.8-powered codebase scanning + patch suggestions) and is releasing Glasswing tooling to trusted security teams on request. The "AI finds 10,000+ critical bugs" arc continues. Anthropic — Expanding Glasswing· TechCrunch
- Claude Code ships Opus 4.8— high-effort defaults for harder tasks, dynamic workflows orchestrating tens-to-hundreds of background agents, faster Fast mode. (Note: Sophos' AI-built ransomware lab above used Claude Opus + Cursor agents — capability cuts both ways.) Releasebot
- IPO context (reminder)— Anthropic confidentially filed for IPO 5/28–6/1 following the $65B Series H at a ~$965B valuation. CBS News
Google DeepMind / AI
- Gemini 3.5 Flash GA + Gemini Omni + Deep Think rollout— 3.5 Flash positioned as the strongest agentic/coding model yet (beats 3.1 Pro on key benchmarks); Gemini Omniany-to-any generation; Gemini 3 Deep Thinkto Ultra subscribers; Ultra cut to $200/mo, new $100/mo Developer tier. Google Cloud — I/O 26· llm-stats
- DeepMind hires 20+ Contextual AI researchers— reported $80–90M licensing/talent deal. HeyGoTrade
🛡 = security-related
Failed Sources
- RansomLook API + RSS— blocked by sandbox egress allowlist (host not on network allowlist). Ransomware section uses WebSearch aggregation (ransomware.live, BreachSense, vendor trackers) cross-checked against confirmed 6/3 victim disclosures; full per-victim accuracy not guaranteed.
- Direct RSS/Atom feeds (CISA, The Hacker News, Bleeping Computer, vendor blogs)— direct fetch blocked by egress allowlist; coverage in this brief is reconstructed from WebSearch results against the same sources.
- Chinese sources (FreeBuf, 安全客, 先知社区)— direct feed fetch not available in current sandbox; coverage based on WebSearch summaries.
Sources used: see intel/sources.yaml