CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (30 May 2026)

Published: Loading…

At a Glance

  • Google Chrome 148 addresses 151 vulnerabilities including multiple critical GPU, WebGL, and V8 flaws across desktop components and installations.
  • A single npm maintainer published 14 malicious OpenSearch and Elasticsearch impersonation packages stealing AWS and CI/CD credentials via install hooks.
  • Unpatched Gogs argument injection vulnerability enables authenticated users to achieve remote code execution through malicious branch name manipulation.
  • LLM-driven attacker exploited marimo CVE-2026-39987 to pivot through AWS credentials and Cloudflare Workers into internal database exfiltration within one hour.
  • Kimsuky campaigns used spoofed Webex pages and HTTPSpy malware with JSONPing technique targeting South Korean military and corporate networks.

Summary

Google Chrome 148 resolves 151 vulnerabilities across desktop builds, including critical GPU, WebGL, and V8 memory corruption issues affecting multiple components. OpenSearch and Elasticsearch ecosystems face supply-chain compromise through malicious npm packages delivering credential-stealing install-time hooks.

Unpatched Gogs vulnerability enables authenticated users to execute remote code through argument injection in repository branch handling workflows across self-hosted Git deployments. Attackers exploited FortiClient EMS CVE-2026-35616 to deploy infostealers into enterprise systems via endpoint management and VPN scripting workflows across managed devices.

An LLM-driven intrusion exploited marimo CVE-2026-39987, pivoting through AWS credentials and Cloudflare Workers to exfiltrate internal PostgreSQL databases rapidly from internal systems. Kimsuky campaigns used spoofed Webex pages and HTTPSpy malware with JSONPing to target South Korean military and corporate network operations.

Dutch authorities dismantled a 17 million device botnet, seizing over 200 servers linked to proxy and distributed attack infrastructure operations. California filed lawsuit against 23andMe over 2023 breach exposing genetic data of nearly 7 million customers and accounts records.

Highlights of the Day

Kimsuky Deploys JSONPing and New HttpSpy Malware Chain

ENKI WhiteHat researchers identified Kimsuky campaigns targeting South Korean military and corporate organisations through fake security software pages and spoofed Webex meeting sites that delivered a redesigned HttpSpy remote access trojan. The campaigns introduced a "JSONPing" technique that uses JSONP requests to localhost services created by the malware to verify infection status in real time and prompt installation when execution has not occurred. Analysis linked the activity to Kimsuky through shared RC4 keys, infrastructure overlaps and code patterns, while the latest HttpSpy variant operates through a three-stage installer, loader and payload architecture supporting command execution, file transfer, screenshot capture and DLL injection.

Chrome 148 Fixes 151 Security Flaws

Google released Chrome 148 to address 151 vulnerabilities, including 22 critical flaws such as CVE-2026-9872, an out-of-bounds write in GPU, and CVE-2026-9873, a use-after-free issue in Network. Additional critical vulnerabilities include CVE-2026-9874 in Dawn, CVE-2026-9875 in WebGL and CVE-2026-9876 in WebGL, with use-after-free defects accounting for most critical findings. The update also fixes 123 high-severity and six medium-severity vulnerabilities across components including ANGLE, Skia, V8, WebRTC and PDFium, with more than $130,000 awarded for externally reported bugs.

California Sues 23andMe Over 2023 Data Breach

California Attorney General Rob Bonta sued 23andMe, now operating as Chrome Holding Co., alleging the company failed to protect sensitive genetic and personal data exposed in a 2023 credential-stuffing attack. The breach compromised roughly 14,000 accounts and enabled access to data belonging to nearly 7 million customers, including genetic information, health reports, DNA matching details and relatives' location data. The lawsuit alleges attackers remained undetected for more than five months, while warning signs including unusual login activity and reports of stolen data surfaced before the company disclosed the incident.

Unpatched Gogs Flaw Enables Authenticated Server Takeover

Rapid7 disclosed a critical CVSS 9.4 argument injection vulnerability in Gogs that allows any authenticated user to achieve remote code execution through the “Rebase before merging” feature. The flaw abuses malicious branch names to inject the Git --exec flag during git rebase, enabling command execution as the Gogs service account without administrator privileges or user interaction. Rapid7 confirmed the issue in Gogs 0.14.2 and 0.15.0+dev, affecting Linux, macOS and Windows deployments, and reported that no vendor patch was available at disclosure.

Source: Rapid7

Microsoft Condemns Uncoordinated Windows Zero-Day Releases

Microsoft criticised a campaign by researcher Nightmare Eclipse that publicly released six Windows zero-day vulnerabilities with proof-of-concept code on GitHub and Blogger without coordinated disclosure. Three flaws disclosed in April, BlueHammer, UnDefend and RedSun, have been exploited in attacks and are listed in CISA’s Known Exploited Vulnerabilities catalogue, while YellowKey, GreenPlasma and MiniPlasma remain unpatched. Microsoft stated that disclosures providing exploit code for unpatched vulnerabilities are “never justifiable” and said its Digital Crimes Unit pursues threat actors and those enabling criminal activity.

Dutch Authorities Dismantle Malware Botnet Infecting 17 Million Devices

Dutch authorities have taken offline a malware botnet involving 17 million infected devices and seized over 200 servers in the Netherlands. Police and the National Cyber Security Centre said the infrastructure controlled computers, tablets and smartphones used in cyberattacks and was linked to proxy service Asocks. Authorities seized over 200 servers hosted in the Netherlands supporting distributed denial of service, traffic proxying and other illicit activity across the botnet network.

AI Agent Uses LLM to Drive Rapid Cloud Intrusion via CVE

Sysdig reported an intrusion where an LLM agent exploited CVE-2026-39987 in a marimo notebook to gain initial remote code execution access. The attacker pivoted using harvested AWS credentials, retrieved secrets from Secrets Manager, and used Cloudflare Workers and SSH bastion to exfiltrate an internal PostgreSQL database. Sysdig stated the end-to-end compromise from initial access to database dump occurred in under one hour, with the bastion exfiltration completing in under two minutes.

Source: Sysdig

Malicious npm Packages Impersonate OpenSearch Libraries and Steal Credentials

A single npm maintainer published 14 malicious packages in four hours impersonating OpenSearch and Elasticsearch libraries using typosquatting and lookalike names, Microsoft reported. Packages used install-time hooks preinstall and postinstall to run stagers collecting host and CI/CD environment data, exfiltrating it to command-and-control servers and delivering second-stage payloads. All 14 packages were removed after discovery, with payloads persisting across module re-imports and optionally using the Bun runtime for additional credential theft.

Daily Coverage

Developments
Chrome 148 PatchNpm Supply ChainGogs RceAi Agent Intrusion
Vulnerabilities
CVE-2026-0257Pan-Os 12.1.0 (Critical)CVE-2026-9873CVE-2026-9876CVE-2026-39987Marimo < 0.23.0 (Critical)CVE-2026-9872CVE-2026-9875CVE-2026-9874CVE-2026-35616Forticlientems 7.4.5 (Critical)
Threat Groups
Kimsuky[Also known as: Velvet Chollima] Kimsuky is a North Koreabased cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subjectmatter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Its operations have overlapped with other DPRK actors, likely due to ad hoc collaboration or limited resource sharing. Because of overlapping operations, some researchers group a wide range of North Korean statesponsored cyber activity under the broader Lazarus Group umbrella rather than tracking separate subgroup or cluster distinctions. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models to assist with vulnerability research, scripting, social engineering and reconnaissance.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.