- Critical unauthenticated remote code execution in Oracle Identity Manager and Web Services Manager
- High-severity Oracle WebLogic Server remote code execution vulnerability actively exploited
- Unauthenticated SSRF vulnerability in Oracle E-Business Suite, actively exploited
ThreatNoir Afternoon Brief — June 2
Afternoon Review in IT Security — June 2, 2026
The security landscape on June 2, 2026 reflects persistent threats across multiple attack vectors, from legacy enterprise systems to mobile platforms and open-source supply chains. Critical vulnerabilities continue to be actively exploited while attackers expand their reach through compromised development ecosystems, underscoring the urgency of comprehensive patch management and supply chain vigilance.
CISA Orders Federal Agencies to Patch Actively Exploited Oracle WebLogic Flaw
The Cybersecurity and Infrastructure Security Agency has mandated that all federal government agencies immediately secure their systems against a high-severity vulnerability in Oracle WebLogic Server. The vulnerability, which was patched two years ago, is now being actively exploited in targeted attacks against government infrastructure. Source: CISA flags two-year-old Oracle flaw as actively exploited in attacks
The incident highlights a critical gap in patch deployment timelines, as organizations continue running unpatched systems despite available security updates. The active exploitation of a two-year-old patch underscores the persistent challenge of legacy system management in enterprise environments. The directive carries significant weight given its application to federal agencies, indicating the severity of the threat and the potential for widespread compromise if remediation efforts are not prioritized.
Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches
A stack-based buffer overflow vulnerability has been identified in HP VoIP phones that can be exploited to achieve remote code execution on vulnerable devices. Source: Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches
This vulnerability represents a significant risk to enterprise networks, as VoIP infrastructure often serves as a critical communication backbone with access to sensitive internal systems. The ability to execute arbitrary code on these devices could provide attackers with a foothold for lateral movement within corporate networks. Organizations deploying HP VoIP systems should prioritize assessment and remediation to prevent potential compromise of their communication infrastructure.
Google Releases June 2026 Android Security Patches Addressing 124 Vulnerabilities
Google has released its June 2026 Android security update addressing a total of 124 vulnerabilities, including one zero-day flaw that is actively being exploited in targeted attacks. Source: Google fixes one actively exploited Android zero-day, 124 flaws
The active exploitation of a zero-day vulnerability in the wild demonstrates the ongoing threat to Android users and the critical importance of timely security updates. The inclusion of 124 total fixes in a single monthly release reflects the continuous discovery and remediation of security issues across the Android ecosystem. Users and device manufacturers should prioritize deployment of these patches to mitigate both the known zero-day threat and the broader vulnerability landscape.
Supply Chain Attack Compromises 32 Red Hat NPM Packages
A significant supply chain attack has targeted the Node Package Manager ecosystem, with attackers publishing 96 malicious package versions across 32 Red Hat NPM packages. The malicious code includes a credential-stealing worm similar to the Mini Shai-Hulud malware family. Source: Supply Chain Attack Hits 32 Red Hat NPM Packages
This attack demonstrates the vulnerability of open-source software supply chains and the potential for widespread impact when popular packages are compromised. Developers and organizations relying on affected NPM packages face the risk of credential theft and potential further compromise of their systems and applications. The incident underscores the necessity for enhanced dependency management practices, including regular audits of supply chain components and implementation of software composition analysis tools to detect compromised packages before they are integrated into production environments.
The convergence of these threats across enterprise systems, mobile platforms, and development infrastructure reinforces the critical importance of comprehensive security strategies that address patching, supply chain integrity, and continuous vulnerability monitoring.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Critical stack-overflow vulnerability in HP Poly VoIP phones enabling RCE with root privileges
- High-severity Qualcomm display component zero-day patched in March, under limited targeted exploitation
- High-severity Android Framework vulnerability actively exploited in targeted attacks, enables code execution and privilege escalation
- High-severity zero-day patched in December, under limited targeted exploitation
- High-severity zero-day patched in December, under limited targeted exploitation
- Mini Shai-HuludCredential-stealing worm used in supply chain attacks
- Miasma: The Spreading BlightVariant of Mini Shai-Hulud deployed in Red Hat NPM attack