CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers

2026-06-05T19:23:30Zfda05e1c6cb7784ad4b493e9fb16d9a2bd4adbb2d36a35c5d9d8822a6537c08d
active-exploitationaptcritical-infrastructurecryptominercve-2026-20245data-breachinfostealermagecartnpmsd-wanserv-usolarwindssupply-chainunc5221zero-day

What happened

Collection of June 5–4, 2026 security reports highlighting multiple active threats and exposures: attackers actively exploit a recently patched/high-severity SolarWinds Serv‑U flaw to crash servers; Cisco warns of an actively exploited, unpatched SD‑WAN zero‑day (CVE‑2026‑20245) enabling root escalation; Chinese APT UNC5221 is maintaining access to Microsoft 365 environments with Brickstorm and new malware families (Plenet, AgentPSD); over 900 US gas station automatic tank gauge (ATG) systems are exposed and vulnerable; several supply‑chain compromises detected (Hola Browser delivering a crypt

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
fda05e1c6cb7784ad4b493e9fb16d9a2bd4adbb2d36a35c5d9d8822a6537c08d
Enrichment time
2026-06-05T19:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers · Baitaphish