Monday, June 15, 2026
Daily digest
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
Palo Alto Networks confirmed active exploitation of CVE-2026-0257 (CVSS 7.8), an authentication bypass vulnerability in PAN-OS affecting GlobalProtect portal and gateway components. An unknown threat actor is leveraging the flaw to gain unauthorized access to GlobalProtect portals. Patches or mitigations have been disclosed alongside the advisory.
Why it matters: If GlobalProtect is part of your remote access or Zero Trust boundary, this is an actively exploited auth bypass — patch or apply mitigations immediately and review access logs for anomalous portal authentication events.
FBI Disrupts Massive AI-Powered Phishing Service Using a Million URLs
The FBI, Google, and Black Lotus Labs jointly dismantled a Chinese phishing-as-a-service operation dubbed 'Outsider Enterprise,' which operated thousands of phishing sites and used AI to generate roughly one million unique URLs for credential and payment card theft. The operation was coordinated takedown of infrastructure used to target victims at scale.
Why it matters: AI-generated URL diversity is specifically designed to evade URL-reputation filters — worth validating that your M365 GCC High Safe Links policies and DNS filtering are tuned to behavioral or heuristic detection, not purely signature-based blocklists.
Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
Attackers tampered with JavaScript files distributed by three widely used WordPress plugins — PushEngage, OptinMonster, and TrustPulse — injecting code that silently created attacker-controlled admin accounts and installed a persistent backdoor plugin when a logged-in site administrator loaded the compromised script. Ordinary site visitors did not trigger the payload.
Why it matters: If any externally facing or contractor-managed WordPress sites are in scope for your CUI boundary or handle organization data, audit plugin file integrity and review admin account logs immediately.
US Cracks Down on Anthropic AI Models Amid Abuse Concerns
The U.S. government issued an export control directive requiring Anthropic to suspend all foreign national access to its Fable 5 and Mythos 5 AI models, citing abuse concerns. Anthropic abruptly cut off access to the affected models in response. The action signals expanding application of export control frameworks to commercially available AI systems.
Why it matters: If your self-hosted AI stack or any approved tools leverage Anthropic APIs — or if contractors use Anthropic models to process any controlled data — this is a leading indicator that AI model access may face formal export control compliance requirements analogous to EAR/ITAR, worth flagging to your legal/compliance team.
The Onboarding Password Mistake That Creates Unnecessary Risk
Security researchers highlight a persistent risk in IT onboarding: temporary first-day passwords are frequently shared via email or SMS, never changed, and sometimes reused across accounts. These practices leave credentials exposed in communication systems long after initial use and increase risk of unauthorized access.
Why it matters: NIST 800-171 control 3.5.2 requires authenticators to be protected and changed at first use — if your Intune/Entra onboarding workflows don't enforce a mandatory password reset at first login and expire provisioned credentials automatically, this is a documented compliance gap.
152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic
Researchers identified 152 Chrome extensions marketed as live wallpaper new-tab add-ons, collectively installed 105,000 times, that distribute a potentially unwanted program family and generate fake web traffic. The extensions span 38 publisher accounts and three coordinated brand backends.
Why it matters: If Chrome browser extension policies in Intune or Entra are not locked down via allowlist, users on your managed Windows 11 fleet could install these — browser extension control is also a relevant safeguard under CMMC practice CA.2.159 and general least-functionality requirements.
Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts
Group-IB disclosed details of a fraudulent campaign by threat actor 'Sniper Dz' targeting Middle East and North Africa users through fake Facebook accounts impersonating politicians and official organizations, promoting phishing lures such as free mobile data, financial compensation, and government subsidy programs. The campaign uses social engineering via browser alerts and social media at scale.
Fire Burns Google Cloud India's Network, Which Remains Slow a Week Later
A physical fire damaged Google Cloud's network infrastructure in India, causing degraded network performance that persisted for over a week after the incident. The outage highlighted the vulnerability of physical data center infrastructure to non-cyber physical events.
EU Sovereignty Push Gives Tech Buyers a New Alphabet Soup to Swallow
The EU is advancing a cloud sovereignty framework that would impose data residency and operational independence requirements on cloud services used by European public sector buyers, despite pushback from the U.S. The initiative promotes open-source alternatives and is driving new certification schemes for cloud providers operating in Europe.