
Daily Cybersecurity News - June 2, 2026
CISA Flags Two Year Old Oracle Flaw
CISA added an old Oracle WebLogic bug to its known exploited list. Federal agencies now must patch or face deadlines.
CVE-2024-21216 scores CVSS 9.8. Attackers reach it over the network with no authentication and can execute code as the server process. The flaw was fixed in October 2024.
It affects WebLogic Server 12.2.1.4 and 14.1.1.0 on multiple platforms. Any exposed admin console or T3 port draws attention from real attackers.
CISA first listed it on the KEV catalog in May 2025.
Google Fixes One Actively Exploited Android Zero Day
Google shipped June patches for Android that close one actively exploited zero-day along with 123 other flaws.
The zero-day sits in the Android Framework component. Attackers used it in targeted attacks against users. The zero-day carries a high severity rating, with the rest spanning multiple subsystems.
Affects devices running Android 14, 15, and 16. Other vendors will roll out builds soon.
Zero-day tracked as CVE-2025-48595 and listed on CISA KEV.
Palo Alto VPN Bug Under Active Exploit
Two attack waves hit starting mid-May. Adversaries are already exploiting the flaw in PAN-OS.
Affects GlobalProtect VPN setups on PAN-OS devices. Anyone running that portal should check exposure.
Exploitation requires certain conditions but adversaries have done so in two attack waves.
WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites
WP Maps Pro plugin flaw lets unauthenticated attackers create admin accounts on WordPress sites.
CVE-2026-8732 stems from missing authorization in a settings endpoint. Attackers send a crafted request to register a new administrator user with no credentials needed. The issue affects version 6.1.0 and earlier, patched in 6.1.1.
Hits any WordPress install running the plugin, popular for adding interactive maps and location features to sites.
Public PoC appeared the same day the vulnerability was disclosed.
Red Hat npm packages compromised to steal developer credentials
Attackers hit more than 30 npm packages under the Red Hat cloud services namespace.
The move reuses a classic supply chain play but lands inside a trusted vendor namespace. That reuse makes the compromise feel lazy rather than inventive.
The packages stayed live for several days before Red Hat yanked them.
US Troops in Active War Zones Tracked with Commercial Location Data
Foreign adversaries are pulling location data from commercial apps to track US troops in active combat zones.
The data comes from fitness trackers, ride-sharing, and weather apps that sell or leak precise coordinates. Adversaries combine it with open-source intelligence to build movement patterns.
This is not new surveillance tech. It is the same consumer data brokers that privacy advocates have warned about for years, now weaponized against military personnel.
Microsoft Threatens Researcher Over Windows Exploits
Microsoft threatened legal action against a researcher publishing Windows exploits, then walked back the threat on June 1, clarifying it would not sue security researchers.
This reads as damage control rather than enforcement. Companies often prefer silence on zero-days over public disclosure fights.
Researcher has already dropped additional Windows issues since the threat surfaced.