# SANS Stormcast Tuesday, June 2nd, 2026: Netlogon Exploit; Unidentified RAT; Windows Netlogon Exploited; RedHat npm Affected; Dashlane Bruteforce Attach (#) Page: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-7764184/sans-stormcast-tuesday-june-2nd-2026-netlogon-exploit-unidentified-rat-windows-netlogon-exploited-redhat-npm-affected-dashlane-bruteforce-attach Text version: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-7764184/sans-stormcast-tuesday-june-2nd-2026-netlogon-exploit-unidentified-rat-windows-netlogon-exploited-redhat-npm-affected-dashlane-bruteforce-attach.md Podcast: [SANS Internet Storm Center's Daily Network Security News Podcast](https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-7764184) Published: 2026-06-02T00:26:53+00:00 Episode link: https://mp3.sans.edu/sans-stormcast-tuesday-june-2nd-2026-netlogon-exploit-unidentified-rat-windows-netlogon-exploited-redhat-npm-affected-dashlane-bruteforce-attach Audio file: https://traffic.libsyn.com/secure/securitypodcast/9954.mp3?dest-id=448030 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-7764184/episodes/sans-stormcast-tuesday-june-2nd-2026-netlogon-exploit-unidentified-rat-windows-netlogon-exploited-redhat-npm-affected-dashlane-bruteforce-attach Duration seconds: 329 ## Resource SANS Stormcast Tuesday, June 2nd, 2026: Netlogon Exploit; Unidentified RAT; Windows Netlogon Exploited; RedHat npm Affected; Dashlane Bruteforce Attach Unidentified RAT pushes NetSupport RAT https://isc.sans.edu/diary/Unidentified%20RAT%20pushes%20NetSupport%20RAT/33034 CVE-2026-41089: Windows Netlogon Vulnerability Exploited https://ccb.belgium.be/advisories/warning-microsoft-patch-tuesday-may-2026-patches-118-vulnerabilities-16-critical-102 RedHat npm Packages Affected https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm Dashlane Locking Accounts after Brute Force https://status.dashlane.com/pages/5aabcb89fccc4b04d3774443 My Upcoming Classes https://www.sans.org/profiles/dr-johannes-ullrich keywords: dashlange; redhat; npm; windows; netlogon; netsupport; rat; clickfix ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-7764184/episodes/sans-stormcast-tuesday-june-2nd-2026-netlogon-exploit-unidentified-rat-windows-netlogon-exploited-redhat-npm-affected-dashlane-bruteforce-attach/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-7764184/sans-stormcast-tuesday-june-2nd-2026-netlogon-exploit-unidentified-rat-windows-netlogon-exploited-redhat-npm-affected-dashlane-bruteforce-attach.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.