Tuesday, June 2, 2026
Daily digest
Two stories dominate today: a critical Windows Netlogon RCE flaw now actively exploited in the wild, and a Palo Alto PAN-OS GlobalProtect authentication bypass also under active attack — both demand immediate patching priority.
Critical Windows Netlogon RCE Flaw Now Exploited in Attacks
Belgium's national cybersecurity authority confirmed threat actors are actively exploiting a recently patched critical remote code execution vulnerability in Windows Netlogon. This is a high-severity flaw targeting domain infrastructure — environments running Windows Server domain controllers should treat this as an emergency patch. Any AD-integrated environment, including those backing M365 GCC High tenants, is at risk if unpatched.
Patch Now: Palo Alto PAN-OS GlobalProtect Auth Bypass Under Active Exploitation
A PAN-OS GlobalProtect VPN authentication bypass vulnerability has moved from advisory status to confirmed active exploitation, with Rapid7 documenting two distinct attack waves beginning in mid-May. Attackers can bypass authentication under certain conditions, making this a critical patch priority for any organization using Palo Alto firewalls for remote access. Organizations using GlobalProtect for CUI-handling network perimeters should patch immediately.
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
Over 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply chain attack distributing the Miasma variant of Shai-Hulud malware, which steals credentials and secrets at install time and self-propagates as a worm. The malware specifically targets CI/CD pipelines, harvests credentials, and exfiltrates data over encrypted channels — a serious risk for Ansible automation pipelines that pull from npm or integrate with Red Hat tooling. Developers and admins should audit their dependency trees and CI/CD runners for exposure immediately.
CISA Adds Oracle WebLogic Server Unspecified Vulnerability to KEV Catalog
CISA added CVE-2024-21182, an unspecified Oracle WebLogic Server vulnerability, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. Federal agencies under BOD 22-01 are required to remediate KEV entries on mandated timelines, and this adds to the patching backlog. Organizations running WebLogic in GovCloud or on-prem environments should prioritize this alongside the Netlogon and PAN-OS issues.
Hackers Used Meta's AI Support Bot to Seize Instagram Accounts
Attackers exploited Meta's AI support assistant chatbot to reset account passwords, briefly defacing the Instagram accounts of the Obama White House and the Chief Master Sergeant of the U.S. Space Force with pro-Iranian imagery. Instructions for the technique circulated on Telegram, indicating broad awareness and likely continued exploitation. This highlights a new AI-specific attack surface: social engineering AI-powered helpdesk bots to bypass account recovery controls.
OpenAI Codex Authentication Tokens Stolen in npm Supply Chain Attack
A malicious npm package named 'codexui-android,' advertised as a remote web UI for OpenAI Codex on GitHub and npm with 29,000 weekly downloads, was found stealing OpenAI Codex authentication tokens from developer machines. The package remains available for download, amplifying ongoing exposure risk. Dev teams using AI coding tools in pipelines — particularly in environments handling controlled data — should audit installed npm packages and rotate any exposed API tokens.
Microsoft Threatening Security Researcher Over Published Zero-Days, Including BitLocker Bypass
Microsoft has threatened legal action against an anonymous researcher dubbed 'Nightmare Eclipse' who published multiple Windows zero-day exploits, including one that bypasses BitLocker encryption. The threat has drawn significant backlash from the security community, raising concerns about chilling effects on independent vulnerability research. For CMMC Level 2 environments relying on BitLocker for CUI data-at-rest protection, the existence of a public BitLocker bypass warrants immediate attention and review of compensating controls.
Hackers Hijack Thousands of Sites for ClickFix and FakeUpdate Attacks
A threat actor tracked as DriveSurge is operating large-scale malware distribution campaigns across thousands of compromised websites using ClickFix and FakeUpdates techniques, tricking users into running malicious scripts disguised as browser or software updates. These campaigns are broadly opportunistic and effective against end users who lack application whitelisting or strong endpoint controls. Organizations should ensure endpoint protection and user awareness training cover these social engineering vectors, particularly for users accessing the web from managed devices.
Google Fixes One Actively Exploited Android Zero-Day Among 124 Flaws in June 2026 Patches
Google's June 2026 Android security update addresses 124 vulnerabilities, including one zero-day confirmed to be exploited in targeted attacks. Organizations managing Android devices via Intune MDM — including any mobile endpoints with access to CUI or GCC High environments — should prioritize pushing this update. The targeted nature of the zero-day exploitation suggests nation-state or sophisticated threat actor involvement.
NSA Taps Three Officials for Top Cybersecurity Positions
The NSA has named David Imbordino and Holly Baroody to leadership roles in its Cybersecurity Directorate, with Bruce Jones heading the Cybersecurity Collaboration Center. These appointments signal continued institutional investment in NSA's cybersecurity mission at a time of heightened threat activity. Defense contractors operating under CMMC should monitor any updated guidance or advisories that may flow from the new leadership.
AWS Spring 2026 SOC 1, 2, and 3 Reports Now Available — 188 Services in Scope
AWS has released its Spring 2026 SOC 1, 2, and 3 audit reports covering 188 services over a 12-month period from April 2025 through March 2026. For organizations using AWS GovCloud and needing to demonstrate third-party assurance for CMMC or FedRAMP assessments, these reports are directly usable as evidence of cloud provider controls. Admins should download the relevant reports now and update their system security plans accordingly.
AI-Driven Exploitation Is Destroying Vulnerability Management — Exploitation Windows Now Measured in Hours
AI is enabling threat actors to discover, reproduce, and weaponize vulnerabilities faster than ever, collapsing the window between public disclosure and active exploitation from days to hours. This fundamentally breaks traditional patch-cycle-based vulnerability management programs that assume days or weeks of lead time before exploitation begins. CMMC Level 2 organizations should reassess their patch SLAs and consider continuous vulnerability scanning and automated remediation workflows to stay ahead of this compressed timeline.