CISA flags two-year-old Oracle flaw as actively exploited in attacks
2026-06-02T13:23:32Z•c1ea5e5cb0ee201c0860781d6ede29b852f3ff076cbcc2d2dc07a1df8f965293
Android zero-dayC2CISAClickFixDashlaneDriveSurgeFakeUpdateGoogle June 2026 patchMiasmaMicrosoft Teams outageNetlogon RCEOffice for the webOracle WebLogicRed HatShai-HuludSpainSteam CommunityWindows vulnerability','WP Maps Pro','WordPress plugin','PaloAlWordPressactively exploitedbrute-forcedoxingnpm compromisepassword managersupply chain
What happened
Multiple high-impact active threats and incidents reported: CISA ordered U.S. federal agencies to patch a two-year-old, high-severity Oracle WebLogic Server vulnerability now being actively exploited; Google shipped June 2026 Android security patches addressing 124 flaws including one actively exploited zero-day; DriveSurge campaigns are distributing malware via ClickFix and FakeUpdate techniques on compromised websites; more than 30 Red Hat npm packages were trojanized to deliver a new Shai-Hulud credential stealer variant called “Miasma”; a Spanish doxer was arrested for leaking sensitiveGov
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- c1ea5e5cb0ee201c0860781d6ede29b852f3ff076cbcc2d2dc07a1df8f965293
- Enrichment time
- 2026-06-02T13:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.