Acer working to patch max severity zero-days in Wave 7 routers

2026-06-03T13:23:34Zdd37d782f6ed4f23619feb2b5fa8d451fd89a7b239882460b9dbabe58c0ab4d4
AI-driven attacksAcerActive Directory discoveryAndroid patchCISACVE-2026-8206ClickFixDriveSurgeEDR evasionExchange Online outageFakeUpdateGitHub tokensGoogleInstagram account takeoverKirkiMeta AI abuseMinecraftOracle WebLogicVisual Studio CodeWave 7 routersWeedHackWordPressmalwareransomwarezero-day

What happened

BleepingComputer reported multiple high-impact incidents (June 2–3, 2026): Acer is patching two maximum‑severity zero‑days in Wave 7 mesh routers; a Visual Studio Code zero‑day with published exploit can steal GitHub tokens via one click; the Kirki WordPress plugin has a critical, actively exploited privilege‑escalation (CVE-2026-8206) enabling admin takeover; the WeedHack campaign has infected >116,000 Minecraft systems; an AI-built ransomware toolkit automates Active Directory discovery and EDR evasion; CISA flagged an actively exploited Oracle WebLogic vulnerability; Google pushed June 2026

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
dd37d782f6ed4f23619feb2b5fa8d451fd89a7b239882460b9dbabe58c0ab4d4
Enrichment time
2026-06-03T13:23:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Acer working to patch max severity zero-days in Wave 7 routers · Baitaphish