- Out-of-bounds read/write in ANGLE graphics engine, CVSS 9.6, sandbox escape and code execution possible
- Out-of-bounds write in ANGLE graphics engine, critical severity
- Use-after-free in Network component, critical severity
ThreatNoir Afternoon Brief — June 5
Afternoon Review in IT Security — June 5, 2026
The cybersecurity landscape continues to face mounting pressure from both vulnerability disclosures and coordinated threat campaigns. Today's briefing covers critical patches affecting millions of users, state-sponsored recruitment tactics targeting cleared personnel, active exploitation of WordPress infrastructure, and unpatched zero-days in enterprise networking equipment.
Chrome 149 Patches 429 Vulnerabilities
Google has released Chrome 149 with patches addressing 429 vulnerabilities, marking a significant security update for the world's most widely used web browser. Over 100 of these bugs are classified as critical or high-severity, with the majority falling into two categories: use-after-free flaws and insufficient validation of untrusted input issues. The identified vulnerabilities include CVE-2026-10881, CVE-2026-10882, and CVE-2026-10883. Source: Chrome 149 Patches 429 Vulnerabilities
Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities
Intelligence agencies from the Five Eyes alliance have issued a joint warning regarding Chinese intelligence operations targeting government and military personnel through fraudulent recruitment schemes. Threat actors posing as recruiters on online job platforms are actively engaging individuals with access to classified or privileged information, attempting to establish relationships that could lead to espionage or data theft. This campaign represents a sophisticated social engineering approach designed to exploit the trust inherent in professional networking environments. Source: Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities
Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
Threat actors are actively exploiting a critical vulnerability in the Everest Forms Pro WordPress plugin, a component installed on approximately 4,000 active websites. The flaw, tracked as CVE-2026-3300 with a CVSS score of 9.8, allows attackers to execute arbitrary code and achieve complete site compromise. The vulnerability affects all versions of the plugin up to and including version 1.9.12, and exploitation has already begun in the wild. Associated indicators of compromise include the email address diksimarina@gmail.com and multiple IP addresses: 15.235.166.18, 185.78.165.153, 202.56.2.126, and 209.146.60.26. Source: Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
Cisco Warns of Unpatched SD-WAN Zero-Day Exploited in Attacks
Cisco has issued an urgent warning regarding a high-severity, unpatched zero-day vulnerability in the Cisco Catalyst SD-WAN Manager, identified as CVE-2026-20245, which is currently being exploited in active attacks. The flaw enables attackers to achieve root privilege escalation on affected systems, posing a critical risk to enterprise network infrastructure. Additional related CVEs have been identified, including CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20133, and CVE-2026-20182. The active exploitation of this unpatched vulnerability underscores the urgent need for organizations to implement mitigation measures until an official patch becomes available. Source: Cisco warns of unpatched SD-WAN zero-day exploited in attacks
The convergence of these threats—from mass vulnerability disclosures to targeted state-sponsored campaigns and active zero-day exploitation—demonstrates the multifaceted nature of today's security challenges. Organizations must prioritize patch management, personnel security awareness, and infrastructure monitoring to effectively defend against these evolving threats.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Critical RCE vulnerability in Everest Forms Pro WordPress plugin, CVSS 9.8
202.56.2.126Source IP for exploit attempts targeting Everest Forms Pro vulnerability209.146.60.26Source IP for exploit attempts targeting Everest Forms Pro vulnerability15.235.166.18Source IP for exploit attempts targeting Everest Forms Pro vulnerability185.78.165.153Source IP for exploit attempts targeting Everest Forms Pro vulnerability
diksimarina[@]gmail.comCommon payload email used in account creation attempts during exploitation
- Information disclosure flaw in Catalyst SD-WAN Manager actively exploited in late April
- Catalyst SD-WAN Manager vulnerability abused in the wild
- Catalyst SD-WAN Manager vulnerability abused in the wild
- Critical authentication-bypass vulnerability exploited in zero-day attacks since at least 2023
- High-severity unpatched zero-day in Cisco Catalyst SD-WAN Manager enabling root privilege escalation via file upload and command injection
- Maximum severity Catalyst SD-WAN Controller authentication bypass actively exploited as zero-day