## Executive Summary The threat landscape on June 4, 2026, is dominated by **active exploitation of critical vulnerabilities in enterprise perimeter and development tools**. Urgent patching is required for **Palo Alto GlobalProtect VPN** and **Microsoft SharePoint**, with confirmed in-the-wild attacks. A severe **supply chain attack** targeting Red Hat npm packages is actively stealing developer credentials. Additionally, a critical **zero-day in VSCode** threatens developer OAuth tokens, and a widespread **malware campaign** is leveraging gaming communities for initial access. CISA continues to mandate action on older, exploited vulnerabilities in Oracle WebLogic and Drupal.
## ⚠️ Immediate Action Required
* **Palo Alto PAN-OS GlobalProtect Auth Bypass** A critical authentication bypass flaw in Palo Alto Networks PAN-OS allows unauthenticated attackers to establish unauthorized VPN connections via forged cookies. **Active exploitation is confirmed.** * **CVE:** CVE-2026-0257 (CVSS: 9.1) * **Status:** Active exploitation detected * **Vulnerable:** PAN-OS versions prior to 10.2.7 * **Fixed:** PAN-OS 10.2.7 and later * **Workaround:** None mentioned in source * **Reference:** [CSO Online](https://www.csoonline.com/article/4179847/attackers-exploit-palo-alto-globalprotect-flaw-days-after-disclosure.html)
* **Microsoft SharePoint Remote Code Execution** Multiple critical vulnerabilities in Microsoft SharePoint Server are being actively exploited, allowing remote code execution and spoofing attacks. * **CVE:** CVE-2026-20963 (CVSS: 8.8), CVE-2026-32201 (CVSS: 6.5), CVE-2026-45659 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** SharePoint Server 2016, 2019, and versions prior to specific April 2026 updates * **Fixed:** Patches released April 2026 * **Workaround:** None mentioned in source * **Reference:** [Microsoft Security Response Center](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659)
* **Oracle WebLogic Server Vulnerability (CISA KEV)** CISA has added a high-severity Oracle WebLogic Server vulnerability to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation, mandating patching for federal agencies. * **CVE:** CVE-2024-21182 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Oracle WebLogic Server versions 12.2.1.4.0 and 14.1.1.0.0 * **Fixed:** Patched by Oracle in July 2024 * **Workaround:** None mentioned in source * **Reference:** [The Hacker News](https://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html)
* **Drupal SQL Injection Vulnerability (CISA KEV)** A critical SQL injection vulnerability in Drupal's PostgreSQL database abstraction API is under active exploitation, potentially leading to remote code execution. * **CVE:** CVE-2026-9082 (CVSS: 6.5-9.8) * **Status:** Active exploitation detected * **Vulnerable:** Drupal 10.x and 11.x prior to specific patches * **Fixed:** Patches available for affected releases * **Workaround:** None mentioned in source * **Reference:** [SC Media](https://www.scworld.com/news/drupal-bug-added-to-cisa-list-of-known-exploited-vulnerabilities)
## 🔍 Threat Activity
* **Red Hat npm Supply Chain Attack (Miasma):** Attackers compromised a GitHub account to push malicious updates to 32 official `@redhat-cloud-services` npm packages. The injected preinstall scripts steal developer credentials and secrets, exfiltrating them to a C2 server. This campaign, linked to Mini Shai-Hulud malware, has seen over 80,000 weekly downloads. * **VSCode GitHub Token Stealing Zero-Day:** A critical, unpatched vulnerability in VSCode's webview sandbox allows attackers to steal full GitHub OAuth tokens via a single click on a malicious link in the browser-based editor (GitHub.dev). This grants attackers full repository access. * **WeedHack Malware-as-a-Service:** Over 116,000 Minecraft systems have been infected via malicious mods distributed through YouTube and SEO poisoning. The "WeedHack" infostealer service steals credentials, session IDs, and cryptocurrency data, and offers remote access capabilities. * **Gamaredon Exploits WinRAR Vulnerability:** The Russian state-sponsored group Gamaredon is exploiting CVE-2025-8088 in WinRAR to deliver GammaWorm and GammaSteel malware via weaponized archives, targeting Ukrainian entities. The flaw involves path traversal and NTFS alternate data streams for stealth. * **Fortinet FortiClientEMS Exploited:** Critical SQL injection (CVE-2026-21643) and access control (CVE-2026-35616) vulnerabilities in Fortinet FortiClientEMS are being actively exploited to deploy infostealer malware, enabling unauthenticated remote code execution and security policy bypass.
## 📋 Patches & Updates
* **Google Android Zero-Day:** Google's June 2026 Android security patches address 124 flaws, including the actively exploited privilege escalation zero-day **CVE-2025-48595** in the Framework component, affecting Android 14.0 and earlier. * **Linux Kernel 'Dirty Frag' & 'Fragnesia':** Critical local privilege escalation vulnerabilities in the Linux kernel (`Dirty Frag` and related `Fragnesia` - CVE-2026-46300) are being actively exploited. Patches are available but not yet for all affected components/kernel versions. * **Apache ActiveMQ RCE:** The critical RCE vulnerability **CVE-2026-34197** in Apache ActiveMQ Classic (affecting versions prior to 5.19.4 and 6.0.0–6.2.2) is under active attack, with over 6,400 servers still unpatched. * **Multiple Exim Vulnerabilities:** Critical vulnerabilities in Exim mail servers (versions 4.97 through 4.99.2) allow remote code execution, denial of service, and data leaks. Patches are available in Exim 4.99.3 and later.
## 📰 Industry & Policy
* **AI-Powered Election Threats:** Threat actors are increasingly using AI to enhance phishing and social engineering campaigns targeting 2026 election communications, with a primary focus on email and fundraising platforms of campaign organizations. * **CISA KEV Catalog Expansions:** CISA continues to aggressively add actively exploited vulnerabilities to its KEV catalog, recently including flaws in Langflow, Trend Micro Apex One, Daemon Tools, TanStack, and Nx Console, mandating timely patching for federal networks. * **OpenClaw AI Agent Security Crisis:** Over 135,000 internet-exposed OpenClaw AI agent instances are at risk due to multiple critical vulnerabilities (e.g., `ClawJacked`, `Claw Chain`) that enable hijacking, data exfiltration, and privilege escalation.
## Today's Priorities 1. **Patch VPN & Collaboration Servers:** Immediately apply patches for **Palo Alto PAN-OS** (CVE-2026-0257) and **Microsoft SharePoint** (CVE-2026-20963, CVE-2026-32201). Verify patch levels for Oracle WebLogic and Drupal systems per CISA directives. 2. **Audit Development Environments:** Scan for and remove compromised `@redhat-cloud-services` npm packages. Mandate credential reviews for developers who may have used these packages and enforce MFA on all source control and CI/CD accounts. 3. **Communicate VSCode Risk:** Issue an advisory to development teams warning against clicking links within the VSCode webview/GitHub.dev interface until a patch is available. Consider temporary policy restrictions. 4. **Review External-Facing Services:** Prioritize patching for **Apache ActiveMQ**, **Exim**, and **Linux kernel** systems, especially those accessible from the internet, given active exploitation.
## 🔗 References
- [CSO Online: Attackers exploit Palo Alto GlobalProtect flaw days after disclosure](https://www.csoonline.com/article/4179847/attackers-exploit-palo-alto-globalprotect-flaw-days-after-disclosure.html)
- [Ars Technica Security: Dozens of Red Hat packages backdoored through its official NPM channel](https://arstechnica.com/security/2026/06/dozens-of-red-hat-packages-backdoored-through-its-offical-npm-channel/)
- [The Hacker News: One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens](https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html)
- [SC Media: Over 6,400 Apache ActiveMQ servers at risk of ongoing attacks](https://www.scworld.com/brief/over-6400-apache-activemq-servers-at-risk-of-ongoing-attacks)
- [CISA All Advisories: CISA Adds Three Known Exploited Vulnerabilities to Catalog](https://www.cisa.gov/news-events/alerts/2026/05/27/cisa-adds-three-known-exploited-vulnerabilities-catalog)