Monthly Cybersecurity Briefing (June 2026)
Published: Loading…
This briefing covers 1.121 reports published during June 2026.
At a Glance
- A sprawling npm/PyPI supply chain worm family (Miasma, Shai-Hulud, Hades) compromised hundreds of packages and dozens of organisations throughout June.
- The FortiBleed campaign harvested credentials from hundreds of thousands of internet-facing Fortinet FortiGate devices across 194 countries.
- ShinyHunters exploited an Oracle PeopleSoft zero-day to breach over 100 organisations, including universities, insurers, and the Council of Europe.
- Coordinated law enforcement actions, including Operation Endgame, dismantled major infostealer and malware-delivery infrastructure, seizing tens of millions of credentials.
- AI systems became both attack surface and attack vector, from Meta chatbot abuse enabling account takeovers to Anthropic's export-controlled model suspension.
Summary
Software supply chains absorbed sustained punishment throughout June as a single malware lineage mutated across ecosystems. Beginning with Red Hat's npm packages and Miasma worm variants early in the month, the campaign evolved through Hades on PyPI, IronWorm's eBPF-rootkit infostealer, hundreds of hijacked Arch Linux AUR packages, and finally a North Korean-attributed compromise of Mastra npm packages that pivoted toward cryptocurrency wallet theft. Each wave reused the same install-time execution tricks — malicious binding.gyp files, poisoned postinstall hooks, and dormant maintainer account takeovers — to harvest cloud, CI/CD, and AI-tooling credentials at scale, repeatedly hitting Microsoft-owned repositories and developer registries.
Credential-harvesting operations against network infrastructure reached unprecedented scale with the FortiBleed campaign, in which a Russian-speaking initial access broker deployed custom sniffing tools against hundreds of thousands of Fortinet FortiGate firewalls, ultimately exposing well over 100 million authentication secrets and confirming at least one NATO-aligned defence contractor compromise. The operation exploited legacy password-hashing artefacts surviving firmware upgrades, prompting emergency guidance from CISA and the UK's NCSC and underscoring how long-tail technical debt in widely deployed edge devices can be weaponised industrially.
Enterprise application exploitation was dominated by a single actor's persistence: ShinyHunters chained a critical Oracle PeopleSoft zero-day to breach more than 100 organisations, disproportionately in higher education, before expanding to insurers, government bodies including the Council of Europe, and automakers such as Nissan. Parallel exploitation of Cisco SD-WAN Manager, Windows Netlogon, and Splunk's PostgreSQL sidecar service demonstrated that unauthenticated remote code execution in core enterprise platforms remained a reliable entry point for both criminal extortion crews and state-linked operators throughout the month.
Law enforcement mounted a notably aggressive response, with a Europol- and Microsoft-led Operation Endgame dismantling SocGholish's WordPress-based delivery network and later seizing over 25 million credentials from StealC and Amadey infostealer infrastructure. These actions ran alongside the AudiA6 cryptocurrency-laundering takedown and Scattered Spider members pleading guilty over the 2024 Transport for London attack, while artificial intelligence emerged as a persistent double-edged theme — attackers abused Meta's AI support assistant to hijack Instagram accounts, and the US government's export-control suspension of Anthropic's Fable 5 and Mythos 5 models sparked debate over the security tradeoffs of restricting advanced AI access.
Major Highlights
Miasma/Shai-Hulud Supply Chain Worm Dominates the npm and PyPI Ecosystems
A single malware lineage — variously branded Miasma, Shai-Hulud, and Hades — compromised Red Hat, Microsoft Azure, LeoPlatform, and ImmobiliareLabs Backstage npm packages, plus dozens of PyPI bioinformatics tools, throughout June. The worm used install-time execution via binding.gyp and .pth startup hooks to steal cloud, GitHub, and AI-tooling credentials, with GitHub disabling 73 Microsoft repositories in one incident to contain propagation.
Sapphire Sleet Hijacks Mastra npm Packages for Crypto Theft
North Korean state actor Sapphire Sleet compromised a Mastra npm maintainer account, injecting a malicious easy-day-js dependency across more than 140 packages. The postinstall payload disabled TLS verification and targeted cryptocurrency wallet extensions, exposing developers running affected packages in CI/CD pipelines to credential theft and build compromise.
FortiBleed Campaign Exposes Over 100 Million Fortinet Credentials
A Russian-speaking initial access broker ran the FortiBleed operation against more than 430,000 internet-facing FortiGate firewalls since February, using a custom FortigateSniffer tool to abuse a diagnostic command and capture authentication traffic across 24 protocols. The campaign identified over 110 million credentials and confirmed compromise of a NATO-aligned defence contractor, prompting joint CISA-NCSC hardening guidance.
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Across 100+ Organisations
UNC6240 (ShinyHunters) exploited CVE-2026-35273, a pre-authentication PeopleSoft Integration Broker flaw, to breach over 100 organisations between late May and mid-June, two-thirds of them US higher education institutions. Confirmed victims expanded through the month to include the University of Nottingham, the Council of Europe, NAIC, and Nissan, exposing payroll, academic, and financial records.
Operation Endgame Dismantles SocGholish and StealC/Amadey Infrastructure
International law enforcement disrupted the SocGholish "FakeUpdates" malware chain tied to Evil Corp, taking down 106 servers and remediating nearly 15,000 compromised WordPress sites. A follow-on Endgame action against StealC and Amadey seized 66 additional domains and 296 servers, recovering over 25.6 million stolen credentials from more than 385,000 systems.
Meta AI Support Assistant Abused for Mass Instagram Account Takeovers
Attackers manipulated Meta's AI-assisted support chatbot into approving fraudulent password resets, hijacking over 20,000 Instagram accounts including high-profile government and public figures. Victims reported the same AI chatbot loops that enabled the takeovers subsequently blocked recovery attempts, delaying remediation for affected users.
US Export Control Directive Suspends Anthropic's Fable 5 and Mythos 5
The US government ordered Anthropic to suspend global access to its Fable 5 and Mythos 5 models over jailbreak-related national security concerns, a directive Anthropic complied with despite disputing the severity of the underlying vulnerability. The decision drew criticism from security researchers who argued restricting advanced models could weaken defensive cybersecurity capabilities more than it hinders adversaries.
Repeated Cisco SD-WAN Manager Zero-Days Draw Sustained Exploitation
Cisco disclosed its seventh actively exploited SD-WAN Manager vulnerability of 2026 in CVE-2026-20245, later followed by CVE-2026-20262 enabling file-write privilege escalation to root. Mandiant observed attackers using rogue peering connections and anti-forensic cleanup to escalate from compromised administrative access to full root control.
The Gentlemen Ransomware Group Scales Operations with In-House EDR Killer
The Gentlemen RaaS group surpassed 800 victims for 2026, driven by rapid VPN and firewall exploitation followed by network-wide encryption within hours. ESET documented the group's centrally managed GentleKiller framework, which targets over 400 security processes across 48 products using abused vulnerable drivers.
Klue OAuth Breach Cascades Across Salesforce-Connected Customers
Attackers using the alias Icarus stole OAuth tokens via a compromised legacy Klue integration credential, gaining access to connected Salesforce environments at named cybersecurity firms including Huntress, Recorded Future, HackerOne, and Snyk. Klue revoked affected credentials and disabled integrations while engaging CrowdStrike for incident response.
Gamaredon Sustains Multi-Stage Espionage Against Ukraine
FSB-linked Gamaredon deployed layered GammaLoad, GammaWorm, and GammaSteel malware components against Ukrainian government and military networks throughout June, using Telegram-based dead-drop resolvers and NTFS Alternate Data Streams for stealth persistence. The group exploited a WinRAR path-traversal flaw patched a year earlier, illustrating continued reliance on unpatched legacy vulnerabilities.
KDDI Breach Exposes 14.2 Million Accounts Across Japanese ISPs
KDDI disclosed unauthorised access to a shared managed email platform serving six Japanese internet service providers, exploiting a third-party software vulnerability to potentially expose up to 14.2 million email addresses and passwords. The breach affected STNet, JCOM, Chubu Telecommunications, NIFTY, and BIGLOBE customers, with credentials stored in hashed or encrypted form.
Monthly Coverage
Developments
Miasma/Shai-Hulud Npm Worm Fortibleed Campaign Oracle Peoplesoft Zero-Day Operation Endgame
Vulnerabilities
CVE-2026-35273Peoplesoft Enterprise Peopletools 8.61 (Critical)CVE-2026-20245Cisco Catalyst Sd-Wan Controller 20.6.4 (High)CVE-2026-20262Cisco Catalyst Sd-Wan Manager 20.1.12 (Medium)
Threat Groups
Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.MuddyWaterMuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.Salt TyphoonSalt Typhoon is a People's Republic of China (PRC) statebacked actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U. S. telecommunication and internet service providers (ISP).Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.