~/greenteam/nerd

Monday, June 1, 2026

Daily digest

A critical Windows Netlogon RCE vulnerability is now being actively exploited in the wild — patch immediately if KB5089549 or its predecessors haven't been applied across your Windows estate.

cybersec BleepingComputer

Critical Windows Netlogon RCE Flaw Now Exploited in Attacks

Threat actors are actively exploiting a recently patched critical remote code execution vulnerability in Windows Netlogon, according to an alert from Belgium's national cybersecurity authority. The flaw could allow attackers to execute arbitrary code on domain controllers and other Windows systems participating in Active Directory environments. Immediate patching is essential for any Windows-based AD infrastructure, including systems in CMMC Level 2 environments where domain controllers are central to access control.

cybersec The Register

Palo Alto VPN Bug Graduates from Advisory to Active Exploitation

Rapid7 confirmed that an authentication bypass vulnerability in Palo Alto Networks' PAN-OS GlobalProtect VPN is now being exploited in the wild. Attackers can bypass authentication to gain unauthorized access to affected VPN gateways, potentially pivoting into protected network segments. Organizations using Palo Alto VPN as a perimeter control — including those securing CUI in CMMC environments — should treat this as an emergency patching priority.

cybersec The Hacker News

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

A malicious npm package named codexui-android, masquerading as a remote web UI for OpenAI Codex, was harvesting authentication tokens from developers and had accumulated over 29,000 weekly downloads before discovery. The package was distributed via both GitHub and npm and remains available for download. This is a direct supply chain threat to any developer environment using npm or AI coding assistants — a growing concern for DevSecOps pipelines in government contractor environments.

cybersec The Hacker News

Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

Dutch police and the NCSC announced the takedown of a large botnet comprising at least 17 million infected devices — including PCs, tablets, smartphones, and IoT devices — backed by over 200 command-and-control servers in the Netherlands. The scale of the operation highlights the continued risk posed by unmanaged and under-patched endpoints, including IoT assets that are often overlooked in asset inventories. For CMMC Level 2 environments, this reinforces the importance of comprehensive asset management and endpoint visibility required under NIST 800-171.

infrastructure BleepingComputer

Microsoft Confirms Outage Affecting MFA and My Sign-Ins Platform

Microsoft acknowledged an active service incident that prevented users from configuring multi-factor authentication or accessing the My Sign-Ins self-service portal. The outage directly impacts identity and access management workflows, including those in Microsoft 365 GCC High tenants where MFA enforcement is a CMMC and NIST 800-171 requirement. Admins should monitor Microsoft's service health dashboard and prepare workarounds for users locked out of MFA enrollment during the incident window.

infrastructure BleepingComputer

Microsoft Fixes KB5089549 Windows Security Update Install Issues

Microsoft resolved a known issue that caused the May 2026 Windows 11 security update (KB5089549) to fail with 0x800f0922 errors during installation on some systems. Given that this update likely addresses the actively exploited Netlogon RCE and potentially other critical vulnerabilities, confirming successful deployment across the managed Windows fleet is urgent. Admins using Intune or WSUS should validate compliance reports to ensure the fix is actually landing.

cybersec The Register

Password Manager Dashlane Suspends Customer Accounts Amid Brute-Force Attacks

Dashlane's automated account protection systems triggered widespread account suspensions after detecting brute-force attack activity targeting customer accounts over the weekend. While the protective lockouts were intentional, the incident disrupted access for legitimate users and surfaced concerns about credential-stuffing resilience in password manager platforms. Organizations relying on Dashlane for enterprise credential management should verify service restoration and review whether any accounts showed anomalous access attempts.

cmmc NextGov

Hackers Are Already Laying Groundwork to Disrupt the 2026 Midterms, Research Says

Check Point Research reports that foreign threat actors are actively conducting reconnaissance and influence operations targeting the 2026 U.S. midterm elections, even as intelligence officials face scrutiny over how election threats are being handled under the current administration. The findings are relevant to defense contractors and government IT teams, as election-adjacent infrastructure and federal agencies are historically targeted in parallel campaigns. CMMC-scoped organizations should review threat intelligence feeds and reinforce monitoring for spearphishing and intrusion attempts tied to politically motivated actors.

infrastructure The Register

Intel Launches 288-Core Clearwater Forest Xeon 6 on 18A Process

Intel officially launched its Clearwater Forest Xeon 6 lineup, featuring up to 288 cores built on Intel's 18A (roughly 2nm-class) process node, targeting AI inference and high-density workloads. The platform is positioned as a competitor to AMD's EPYC for cloud and enterprise server deployments, including hypervisor hosts. Organizations planning future Nutanix AHV cluster refreshes or AWS GovCloud-adjacent on-prem capacity should track availability and compatibility timelines.