CISA flags two-year-old Oracle flaw as actively exploited in attacks

2026-06-02T13:23:32Zc1ea5e5cb0ee201c0860781d6ede29b852f3ff076cbcc2d2dc07a1df8f965293
Android zero-dayC2CISAClickFixDashlaneDriveSurgeFakeUpdateGoogle June 2026 patchMiasmaMicrosoft Teams outageNetlogon RCEOffice for the webOracle WebLogicRed HatShai-HuludSpainSteam CommunityWindows vulnerability','WP Maps Pro','WordPress plugin','PaloAlWordPressactively exploitedbrute-forcedoxingnpm compromisepassword managersupply chain

What happened

Multiple high-impact active threats and incidents reported: CISA ordered U.S. federal agencies to patch a two-year-old, high-severity Oracle WebLogic Server vulnerability now being actively exploited; Google shipped June 2026 Android security patches addressing 124 flaws including one actively exploited zero-day; DriveSurge campaigns are distributing malware via ClickFix and FakeUpdate techniques on compromised websites; more than 30 Red Hat npm packages were trojanized to deliver a new Shai-Hulud credential stealer variant called “Miasma”; a Spanish doxer was arrested for leaking sensitiveGov

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c1ea5e5cb0ee201c0860781d6ede29b852f3ff076cbcc2d2dc07a1df8f965293
Enrichment time
2026-06-02T13:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.