Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (2 June 2026)
Published: Loading…
At a Glance
- CVE-2026-41089 Windows Netlogon stack-based buffer overflow enables unauthenticated remote code execution on domain controllers, now actively exploited in attacks.
- Meta AI support assistant abuse enabled Instagram account takeovers after attackers manipulated password reset flows via Telegram instructions.
- CVE-2026-45618 LiquidJS vulnerability allows unauthenticated remote code execution via crafted templates, impacting Node.js applications using Liquid templating engine.
- Red Hat @redhat-cloud-services npm packages compromised in Miasma supply chain attack deploying Shai-Hulud credential-stealing worm via preinstall scripts.
- Palo Alto Networks GlobalProtect authentication bypass CVE-2026-0257 exploited to establish unauthorised VPN sessions and access internal networks systems.
Summary
Windows Netlogon CVE-2026-41089 is actively exploited through RPC requests enabling unauthenticated code execution on domain controllers across enterprise Windows Server deployments. Palo Alto Networks GlobalProtect CVE-2026-0257 authentication bypass is being used to establish unauthorised VPN sessions and internal network access across affected environments. WP Maps Pro vulnerability CVE-2026-8732 enables unauthenticated administrator account creation in WordPress installations leading to full site takeover in active exploitation.
Red Hat Cloud Services npm packages were compromised with Shai-Hulud derived Miasma worm executing preinstall scripts to steal developer credentials. LiquidJS CVE-2026-45618 enables unauthenticated remote code execution via crafted templates affecting Node.js applications processing untrusted input across multiple deployments systems. codexui-android npm supply chain attack targeting OpenAI Codex users exfiltrated authentication tokens through malicious remote web UI package campaign activity.
Meta AI support assistant exploitation enabled Instagram account takeovers via manipulated password reset workflows initiated through Telegram instructions campaigns reported. Dashlane password manager accounts experienced brute-force attacks triggering temporary account suspensions and authentication lockouts across user base systems impact events. Atlas Menu GTA cheat service breach exposed user emails, IP addresses, and account data after attackers accessed and dumped databases online.
FSB-linked Gamaredon operations concealed fileless malware within Windows NTFS data streams to enable persistent espionage against Ukrainian targets campaigns observed. Operation Dragon Weave targeted Czech Republic and Taiwan entities using spear-phishing emails delivering AdaptixC2 agents across government and research sectors. Dutch authorities dismantled a 17-million-device botnet used as residential proxy infrastructure supporting large-scale cybercrime operations following seizures of command-and-control servers.
Highlights of the Day
Palo Alto GlobalProtect Bypass Exploited in Active Attacks
Palo Alto Networks disclosed CVE-2026-0257, an authentication bypass in PAN-OS GlobalProtect portal and gateway enabling attackers to establish unauthorised VPN connections. The flaw, rated CVSS 7.8, was raised from medium to high severity after limited exploitation attempts against unpatched devices using forged authentication cookies. Rapid7 observed exploitation in two waves starting 18 and 21 May, while CISA added CVE-2026-0257 to its Known Exploited Vulnerabilities catalog.
WP Maps Pro Flaw Enables Unauthorised Admin Account Creation
WP Maps Pro contains a CVSS 9.8 vulnerability enabling unauthenticated attackers to create administrator accounts via an exposed AJAX action in versions up to 6.1.0. Nonce protection in the wpgmp_temp_access_ajax endpoint was ineffective due to public exposure and missing capability checks allowing wp_insert_user to create administrator accounts. Attackers could use generated login URLs to authenticate as newly created administrators and take full control, with the vendor fixing the issue in version 6.1.1.
Malicious npm Packages Infect Red Hat Cloud Services
Multiple @redhat-cloud-services npm packages were found compromised with malicious preinstall scripts executing on npm install, deploying multi-stage credential-stealing malware targeting CI/CD and cloud environments. Analysis identified worm-like behaviour using stolen npm tokens and bypass_2fa to republish backdoored packages, with CI/CD compromise via GitHub Actions OIDC workflows. Across at least 32 affected releases, the malware exfiltrated GitHub, AWS, GCP, Azure, Kubernetes, and developer secrets during installation-time execution across infected systems.
Windows Netlogon RCE Exploited in Domain Controller Attacks
CVE-2026-41089 is a stack-based buffer overflow in the Windows Netlogon RPC service enabling unauthenticated remote code execution on domain controllers across supported Windows Server versions including Windows Server 2025, with CVSS 9.8 and active exploitation reported. The Centre for Cybersecurity Belgium warned of in-the-wild exploitation following May 2026 Patch Tuesday, where crafted network RPC requests can trigger improper handling in Netlogon and allow attackers to execute code without authentication or prior access.
Instagram accounts for Obama White House and Space Force Chief Master Sergeant were defaced with pro-Iranian messages after Telegram instructions exploited Meta’s AI support assistant. Attackers used VPNs near targets’ locations, initiated password reset flows, instructed Meta’s chatbot to link new email addresses and generate one-time codes enabling account takeover. Meta said the issue was resolved and affected accounts were secured, with no backend database breach confirmed in the incident.
LiquidJS RCE Enables Unauthenticated Host Command Execution
CVE-2026-45618 affects LiquidJS, a Node.js implementation of Shopify’s Liquid templating engine, enabling unauthenticated remote code execution via crafted template input and filter evaluation logic flaws including valueOf chaining to the JavaScript Function constructor, with CVSS 10.0 assigned. The issue impacts the liquidjs npm package in all versions prior to 10.26.0 and affects applications processing untrusted Liquid templates, with approximately 7.3 million monthly downloads across web, CMS, and email templating environments. Public proof-of-concept code demonstrates file reads such as /etc/passwd and command execution via child_process.execSync, and a national CERT advisory has highlighted active risk due to exploit availability.
Daily Coverage