Afternoon Review in IT Security — June 15, 2026
The threat landscape continues to evolve rapidly as security researchers and law enforcement agencies uncover sophisticated attacks targeting critical infrastructure, browser extensions, and content management systems. Today's review highlights active exploitation of enterprise VPN vulnerabilities, widespread malicious browser extensions, supply chain compromises affecting WordPress sites, and the dismantling of a major phishing service.
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
Palo Alto Networks has disclosed that it is observing active exploitation of CVE-2026-0257, a critical authentication bypass vulnerability affecting PAN-OS GlobalProtect VPN portals and gateways. The vulnerability carries a CVSS score of 7.8 and has been weaponized by an unknown threat actor to gain unauthorized access to affected systems. Organizations running vulnerable PAN-OS deployments face immediate risk of compromise and should prioritize patching efforts.
The company has identified multiple threat actor IP addresses associated with exploitation attempts, providing defenders with indicators to monitor and block. Source: Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw
152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic
Cybersecurity researchers have uncovered a coordinated campaign involving 152 malicious Google Chrome extensions distributed across 38 separate publisher accounts. These extensions, disguised as live wallpaper utilities, have been collectively installed more than 105,000 times and are designed to distribute a potentially unwanted program family. The campaign leverages three infrastructure backends: tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com.
The scale and sophistication of this operation underscore the vulnerability of browser extension ecosystems to supply chain abuse. Users should audit installed extensions and remove any wallpaper utilities from untrusted sources. Source: 152 Chrome Wallpaper Extensions with 105K Installs Linked to Adware and Fake Traffic
Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
Attackers have successfully compromised trusted JavaScript files used by widely deployed WordPress plugins including PushEngage, OptinMonster, and TrustPulse. The tampered scripts execute malicious code when site administrators are logged in, automatically creating hidden admin accounts and installing persistent backdoor plugins under attacker control. This supply chain attack bypasses traditional detection mechanisms by targeting legitimate plugin infrastructure.
The compromise demonstrates how attackers can leverage trusted third-party code to establish long-term persistence on WordPress installations. Site administrators should immediately audit their active accounts and installed plugins for unauthorized additions. Source: Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites
FBI, Google Dismantle 'Outsider Enterprise' Phishing Service
The FBI and Google have successfully dismantled a major phishing-as-a-service platform known as Outsider Enterprise, which operated more than 9,000 phishing sites and stole nearly 4 million credit cards. The operation resulted in approximately $1.9 billion in financial losses across its victim base. The takedown represents a significant law enforcement victory against infrastructure enabling mass credential theft and fraud.
The scale of this operation highlights the persistent threat posed by phishing-as-a-service platforms and underscores the importance of user awareness, multi-factor authentication, and advanced threat detection capabilities. Source: FBI, Google Dismantle 'Outsider Enterprise' Phishing Service
Today's threat landscape demonstrates that attacks continue to target organizations across multiple vectors—from enterprise network infrastructure to user-facing browser extensions and content management systems. Security teams should prioritize vulnerability management, supply chain monitoring, and user education as core defensive strategies.