CyberSecBrief


Weekly Cybersecurity Briefing (29 June – 5 July 2026)

Published: Loading…

This briefing covers 231 reports published from 29 June to 5 July 2026.

At a Glance

  • Attackers exploited a critical SimpleHelp RMM authentication bypass to deploy Djinn Stealer and TaskWeaver malware, prompting a CISA advisory.
  • The FortiBleed campaign harvested over 110 million credentials from more than 430,000 FortiGate firewalls, linked to INC Ransom and Lynx ransomware.
  • Google and the FBI disrupted the NetNut residential proxy network, which controlled roughly two million compromised devices.
  • Citizen Lab confirmed Pegasus spyware infected a former European Parliament member investigating spyware abuse.
  • A US government entity paid roughly $1 million to the Kairos extortion group after a data-theft-only attack with no encryption.
  • The US Commerce Department lifted export controls on Anthropic's Fable 5 and Mythos 5 models after a three-week suspension.

Summary

  • Attackers actively exploited a SimpleHelp RMM authentication bypass, CVE-2026-48558, to deploy custom malware, with roughly 1,000 exposed servers directly vulnerable.
  • The FortiBleed campaign compromised over 430,000 FortiGate firewalls, harvesting more than 110 million credentials tied to INC Ransom and Lynx ransomware.
  • Google, Lumen and the FBI dismantled the NetNut/Popa residential proxy network, which controlled around two million compromised consumer devices.
  • Citizen Lab documented repeated Pegasus spyware infections of a former MEP who served on the European Parliament's spyware investigation committee.
  • A US local government entity paid roughly $1 million to the Kairos extortion group after a data-theft-only intrusion with no ransomware deployed.
  • Anthropic's Fable 5 and Mythos 5 models regained access after the US Commerce Department lifted export controls imposed following a jailbreak incident.

Highlights of the Week

SimpleHelp Authentication Flaw Exploited for Malware Delivery

Arctic Wolf reported active exploitation of CVE-2026-48558, a critical authentication bypass in SimpleHelp RMM caused by improper OpenID Connect token validation. Attackers forged identity tokens to bypass multi-factor authentication and gain technician-level access. CISA added the flaw to its Known Exploited Vulnerabilities catalogue after roughly 14,000 exposed servers were identified.

Sources: Arctic Wolf

FortiBleed Campaign Harvests 110 Million Credentials

Researchers uncovered the FortiBleed campaign, in which attackers deployed the FortigateSniffer tool on around 12,000 FortiGate devices and harvested over 110 million RADIUS, NTLM and Kerberos credentials. The campaign has been linked to the INC Ransom and Lynx ransomware groups, and the underlying flaw was added to CISA's Known Exploited Vulnerabilities catalogue.

FBI and Google Disrupt NetNut Residential Proxy Network

The FBI, supported by Google and Lumen, seized domains linked to the NetNut proxy network, also known as Popa, which researchers estimate controlled at least two million compromised devices. Google disabled associated command-and-control accounts, and 316 distinct threat clusters were found using NetNut exit nodes in a single week.

Pegasus Spyware Infected EU Committee Member Investigating Spyware

Citizen Lab found that former European Parliament member Stelios Kouloglou was infected with Pegasus spyware twice while serving on the committee investigating such tools. Forensic evidence pointed to the PWNYOURHOME zero-click exploit chain, with infrastructure overlap linked to a prior campaign against Russian and Belarusian journalists.

Sources: Citizen Lab

Kairos Extortion Group Paid Without Deploying Ransomware

A US government entity, believed to be Union County, Ohio, paid approximately $1 million to the Kairos extortion group after attackers claimed to steal more than 2TB of data without encrypting systems. Blockchain analysis traced the payment through wallets linked to Bybit, OKX and the Russian service BELQI.

Sources: The Hacker News

Threats

Mustang Panda Deploys New Malware Against Indian Targets

Acronis identified two Mustang Panda espionage campaigns targeting India's hydropower sector and government organisations, deploying the previously undocumented MINIRECON and ZOHOMURK implants. ZOHOMURK abused Zoho WorkDrive for command-and-control using hardcoded OAuth credentials, and CERT-In coordinated victim notification.

Oracle PeopleSoft Zero-Day Fuels Multiple Breach Disclosures

NAIC, Nissan, Aflac Japan and others disclosed breaches tied to a zero-day in Oracle PeopleSoft, attributed to the ShinyHunters extortion group. NAIC said only public and outdated data was exposed, while Nissan warned that payroll records and Social Security numbers may have been stolen.

Medtronic Discloses Patient Data Exposure

Medtronic notified patients that attackers accessed corporate systems between April 13 and 19, exposing names, Social Security numbers and health information. The incident has been linked to a broader extortion campaign involving the ShinyHunters group.

Sources: The Register

Armored Likho Deploys BusySnake Stealer via Phishing

Kaspersky reported that the Armored Likho APT group used spear-phishing archives to deploy BusySnake Stealer, a Python-based infostealer, against government and energy sector targets in Russia, Brazil and Kazakhstan. The malware harvests clipboard data, browser credentials and cryptocurrency wallet artefacts.

Infrastructure & Exploits

Public PoC Released for Critical libssh2 Flaw

A public proof-of-concept for CVE-2026-55200, a critical pre-authentication flaw in libssh2, allows remote code execution via crafted SSH packets. The bug stems from an integer overflow in packet-length validation during the SSH handshake, with no in-the-wild exploitation reported yet.

Sources: The Hacker News

Ransomware Gangs Exploit Windows BlueHammer Defender Flaw

CISA confirmed ransomware groups are exploiting CVE-2026-33825, a Microsoft Defender privilege escalation flaw allowing local attackers to steal password hashes and reach SYSTEM privileges. Microsoft patched the bug in April 2026 after earlier zero-day exploitation.

Oracle E-Business Suite Flaw Under Active Attack

Defused Cyber reported active exploitation of CVE-2026-46817, a critical Oracle Payments flaw allowing unauthenticated takeover of affected E-Business Suite instances. Attacks began roughly six weeks after Oracle's patch, despite no public exploit code being available.

Sources: The Hacker News

Citrix Patches NetScaler Flaws Including CitrixBleed-Style Bug

Citrix released patches for six NetScaler ADC and Gateway flaws, including a new HTTP/2 Bomb denial-of-service attack and a memory-overread bug, CVE-2026-8451, in SAML request parsing. The overread flaw can leak uninitialised memory and occasionally crash the nsppe process.

Sources: watchTowr Labs

CISA Flags Active Exploitation of SharePoint and Cisco Flaws

CISA added CVE-2026-45659, a SharePoint deserialisation flaw, to its Known Exploited Vulnerabilities catalogue after confirming active exploitation. Cisco separately confirmed in-the-wild exploitation of CVE-2026-20230 in Unified Communications Manager, enabling server-side request forgery.

phpBB Authentication Bypass Allowed Login as Any User

Aikido disclosed CVE-2026-48611, a critical phpBB authentication bypass allowing login as any user via a single unauthenticated request. The flaw abused the login_link feature and default apache authentication provider, and was patched in version 3.3.17.

Sources: Aikido Security

Linux Bad Epoll Flaw Enables Root Privilege Escalation

Researchers disclosed Bad Epoll, CVE-2026-46242, a Linux kernel race condition allowing unprivileged processes to escalate to root, with impact extending to Android devices. Exploitation was demonstrated with high reliability in Google's kernelCTF environment.

Sources: GitHub

Tools & Techniques

Microsoft Removes StegoAd Extensions Hiding Malware in Images

Microsoft removed 119 Edge extensions linked to the StegoAd campaign, which hid malware payloads inside image and font files. The extensions, downloaded by 2.6 million users, stole Google credentials, second-factor codes and WordPress logins.

Sources: The Hacker News

npm Supply Chain Campaigns Target Developer Credentials

A campaign using ten npm maintainer accounts published roughly 30 packages impersonating Polymarket and DeFi tooling, delivering a JavaScript infostealer. A separate dependency-confusion campaign under the @marketfront scope harvested SSH keys and cloud credentials from developers.

Sources: SafeDep SafeDep

JadePuffer Agentic Ransomware Automates Database Extortion

Sysdig documented JadePuffer, in which an AI system exploited a Langflow flaw to autonomously breach, move laterally through, and encrypt a production database. The agent performed reconnaissance and credential harvesting before encrypting configuration items and generating a ransom note with an ephemeral key.

Browser-Only Ransomware Demonstrated Using AI-Generated Code

Check Point Research described a browser-only ransomware concept derived from LLM-generated malware ideas, exploiting Chrome's File System Access API without native payload installation. The proof-of-concept can enumerate, encrypt and overwrite user-selected files while displaying ransom overlays.

Avalon Framework Delivers CrownX Ransomware

Blackpoint Cyber analysed Avalon, a malware framework delivered through phishing that bypassed AMSI and ETW before deploying an integrated ransomware component, CrownX. CrownX used AES-GCM encryption, disabled recovery features and included a direct disk destruction capability.

AI-Hallucinated Domains Fuel Phantom Squatting Attacks

Unit 42 identified "phantom squatting," where attackers register LLM-hallucinated domains and weaponise them for phishing and malware delivery. Analysis of 2.1 million LLM-generated URLs found 13,229 malicious URLs and roughly 250,000 unregistered phantom domains available for preemptive registration.

Policy & Legal

US Offers $10 Million Reward for Russian State-Linked Hackers

The US State Department offered a $10 million reward for information on UNC5792 and UNC4221, Russian state-linked groups targeting Signal and WhatsApp accounts of government and military officials. WhatsApp separately began rolling out optional usernames to reduce phone number exposure.

Sources: The Hacker News

US Lifts Export Controls on Anthropic Cybersecurity Models

US authorities lifted export controls on Anthropic's Fable 5 model, restoring global access after a three-week shutdown tied to a jailbreak technique. Anthropic also reinstated access to Mythos 5 under Project Glasswing for vetted US organisations.

Scattered Spider Suspect Extradited on US Hacking Charges

US authorities extradited a 19-year-old dual US and Estonian citizen from Finland after charging him with conspiracy and computer intrusion tied to the Scattered Spider group. Prosecutors allege the group conducted over 100 intrusions generating more than $100 million in ransom payments.

Weekly Topic Distribution

Weekly Coverage

Developments
Fortibleed Campaign Simplehelp Exploitation Netnut Proxy Takedown Pegasus Spyware
Vulnerabilities
CVE-2026-48558Simplehelp 5.5.0 (Critical)CVE-2026-55200Libssh2 (High)CVE-2026-33825Microsoft Defender Antimalware Platform 4.0.0.0 (High)CVE-2026-46817Oracle Payments 12.2.3 (Critical)CVE-2026-8451Adc 14.1 (High)CVE-2026-45659Microsoft Sharepoint Enterprise Server 2016 16.0.0 (High)CVE-2026-20230Cisco Unified Communications Manager N/ACVE-2026-48611Phpbb 3.3.0 (Critical)CVE-2026-46242Linux 58C9B016E12855286370Dfb704C08498Edbc857A (High)
Threat Groups
Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.MuddyWaterMuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.Salt TyphoonSalt Typhoon is a People's Republic of China (PRC) statebacked actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U. S. telecommunication and internet service providers (ISP).Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.