- Linux kernel improper authentication vulnerability in cgroups v1 enabling container escape and privilege escalation; actively exploited in the wild
- High-severity Android Framework vulnerability exploited as zero-day; patched by Google
ThreatNoir Afternoon Brief — June 3
Afternoon Review in IT Security — June 3, 2026
The security landscape continues to face mounting pressure from critical vulnerabilities across multiple infrastructure layers. Today's briefing covers urgent threats affecting Linux systems, network hardware, web servers, and development tools that demand immediate attention from IT teams worldwide.
Organizations Warned of Exploited Linux Kernel Vulnerability
A serious improper authentication bug in the Linux kernel is being actively exploited by attackers to escalate privileges and escape containers. The vulnerability, identified through CVE-2022-0492 and CVE-2025-48595, poses a significant risk to containerized environments and systems relying on kernel-level isolation. Organizations running affected Linux systems should prioritize patching efforts immediately to prevent unauthorized privilege escalation and container breakout attacks. Source: Organizations Warned of Exploited Linux Kernel Vulnerability
Acer Working to Patch Maximum Severity Zero-Days in Wave 7 Routers
Acer has disclosed two maximum-severity zero-day vulnerabilities affecting its Wave 7 mesh routers, identified as CVE-2026-49200 and CVE-2026-49201. The company is actively developing patches to address these critical flaws that could expose home and business networks to complete compromise. Users of Wave 7 routers should monitor Acer's security advisories closely and apply patches immediately upon release to prevent potential network intrusions. Source: Acer working to patch max severity zero-days in Wave 7 routers
HTTP/2 Bomb Exploit Knocks Web Servers Offline in Seconds
A newly discovered attack chain combining a compression bomb with a Slowloris-style hold technique can incapacitate major web servers in seconds. The HTTP/2 Bomb exploit leverages default configurations in popular web servers, exploiting vulnerabilities tracked as CVE-2016-1546, CVE-2016-6581, CVE-2016-8740, CVE-2025-53020, and CVE-2026-49975. Web administrators should review their HTTP/2 settings and implement rate limiting and connection controls to mitigate the risk of denial-of-service attacks through this vector. Source: 'HTTP/2 Bomb' Exploit Knocks Web Servers Offline in Seconds
VS Code Zero-Day Lets Hackers Steal GitHub Tokens in One Click
A Visual Studio Code zero-day vulnerability has been exploited in the wild, allowing attackers to steal GitHub authentication tokens through malicious VS Code extensions. Security researchers have released working exploit code demonstrating how attackers can trick users into clicking a link that compromises their GitHub credentials. Developers should exercise caution when installing extensions and consider implementing additional authentication safeguards such as hardware security keys for GitHub accounts to prevent token theft. Source: VS Code zero-day lets hackers steal GitHub tokens in one click
The convergence of these critical vulnerabilities across infrastructure, networking, web services, and development tools underscores the importance of maintaining vigilant patch management practices and implementing defense-in-depth strategies across all technology layers.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Broken access control vulnerability in Acer Wave 7 routers allowing unauthenticated remote access to plaintext credentials in acer_cgi.log
- Hardcoded cryptographic key vulnerability in upload.cgi binary enabling persistent backdoor access via decryption and modification of system backups
- Apache vulnerability resolved in late May patches related to HTTP/2 Bomb
- HPACK Bomb compression-layer attack on HTTP/2 header compression
- Apache HTTP Server vulnerability related to HPACK Bomb, resolved in version 2.4.64
- Apache HTTPD HTTP/2 Slowloris-type DoS via Continuation frames
- Apache HTTPD Slow Read vulnerability leading to DoS via modified flow-control windows
- Malicious VS Code extensionExtension that steals GitHub OAuth tokens from github.dev