Weekly review

ThreatNoir Afternoon Brief — June 5

2026-06-05Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — June 5, 2026

The cybersecurity landscape continues to face mounting pressure from both vulnerability disclosures and coordinated threat campaigns. Today's briefing covers critical patches affecting millions of users, state-sponsored recruitment tactics targeting cleared personnel, active exploitation of WordPress infrastructure, and unpatched zero-days in enterprise networking equipment.

Chrome 149 Patches 429 Vulnerabilities

Google has released Chrome 149 with patches addressing 429 vulnerabilities, marking a significant security update for the world's most widely used web browser. Over 100 of these bugs are classified as critical or high-severity, with the majority falling into two categories: use-after-free flaws and insufficient validation of untrusted input issues. The identified vulnerabilities include CVE-2026-10881, CVE-2026-10882, and CVE-2026-10883. Source: Chrome 149 Patches 429 Vulnerabilities

Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities

Intelligence agencies from the Five Eyes alliance have issued a joint warning regarding Chinese intelligence operations targeting government and military personnel through fraudulent recruitment schemes. Threat actors posing as recruiters on online job platforms are actively engaging individuals with access to classified or privileged information, attempting to establish relationships that could lead to espionage or data theft. This campaign represents a sophisticated social engineering approach designed to exploit the trust inherent in professional networking environments. Source: Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities

Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites

Threat actors are actively exploiting a critical vulnerability in the Everest Forms Pro WordPress plugin, a component installed on approximately 4,000 active websites. The flaw, tracked as CVE-2026-3300 with a CVSS score of 9.8, allows attackers to execute arbitrary code and achieve complete site compromise. The vulnerability affects all versions of the plugin up to and including version 1.9.12, and exploitation has already begun in the wild. Associated indicators of compromise include the email address diksimarina@gmail.com and multiple IP addresses: 15.235.166.18, 185.78.165.153, 202.56.2.126, and 209.146.60.26. Source: Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites

Cisco Warns of Unpatched SD-WAN Zero-Day Exploited in Attacks

Cisco has issued an urgent warning regarding a high-severity, unpatched zero-day vulnerability in the Cisco Catalyst SD-WAN Manager, identified as CVE-2026-20245, which is currently being exploited in active attacks. The flaw enables attackers to achieve root privilege escalation on affected systems, posing a critical risk to enterprise network infrastructure. Additional related CVEs have been identified, including CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20133, and CVE-2026-20182. The active exploitation of this unpatched vulnerability underscores the urgent need for organizations to implement mitigation measures until an official patch becomes available. Source: Cisco warns of unpatched SD-WAN zero-day exploited in attacks

The convergence of these threats—from mass vulnerability disclosures to targeted state-sponsored campaigns and active zero-day exploitation—demonstrates the multifaceted nature of today's security challenges. Organizations must prioritize patch management, personnel security awareness, and infrastructure monitoring to effectively defend against these evolving threats.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
CVE1
  • Critical RCE vulnerability in Everest Forms Pro WordPress plugin, CVSS 9.8
IP Address4
  • 202.56.2.126
    Source IP for exploit attempts targeting Everest Forms Pro vulnerability
  • 209.146.60.26
    Source IP for exploit attempts targeting Everest Forms Pro vulnerability
  • 15.235.166.18
    Source IP for exploit attempts targeting Everest Forms Pro vulnerability
  • 185.78.165.153
    Source IP for exploit attempts targeting Everest Forms Pro vulnerability
Email1
  • diksimarina[@]gmail.com
    Common payload email used in account creation attempts during exploitation
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
CVE6
  • Information disclosure flaw in Catalyst SD-WAN Manager actively exploited in late April
  • Catalyst SD-WAN Manager vulnerability abused in the wild
  • Catalyst SD-WAN Manager vulnerability abused in the wild
  • Critical authentication-bypass vulnerability exploited in zero-day attacks since at least 2023
  • High-severity unpatched zero-day in Cisco Catalyst SD-WAN Manager enabling root privilege escalation via file upload and command injection
  • Maximum severity Catalyst SD-WAN Controller authentication bypass actively exploited as zero-day