Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (3 June 2026)
Published: Loading…
At a Glance
- GorgonAgora operates over 4,800 fake storefronts using Medusa.js and payment-vanilla.iife.js to intercept checkout card data via fake Stripe iframes and WebSocket exfiltration.
- Deleted PyPI packages retain recoverable artifacts through files.pythonhosted.org, exposing a GitHub PAT with Apache organisation admin access from archived releases.
- Dashlane confirmed fewer than 20 personal plan users had encrypted vaults downloaded following brute-force attacks targeting two-factor authentication protections.
- Gamaredon targeted Ukrainian government networks using GammaPhish lures and WinRAR exploitation to deploy GammaWorm and GammaSteel espionage malware.
- HazyBeacon abused AWS Lambda Function URLs configured without authentication to route command-and-control traffic through trusted AWS infrastructure.
- Google patched an Android Framework zero-day CVE-2025-48595 actively exploited for privilege escalation across billions of device installations.
Summary
GorgonAgora operated a large-scale web skimming network using Medusa.js storefronts impersonating major retail brands across thousands of domains. The campaign used a shared payment skimmer SDK to capture checkout data through fake Stripe interfaces embedded in storefronts. Exfiltration occurred via encrypted WebSocket channels routed to central command infrastructure.
Deleted software packages in the PyPI ecosystem retained recoverable artifacts through object storage systems, enabling extraction of long-dormant credentials. A GitHub personal access token granting administrative access to the Apache organisation was identified within archived package releases. Additional AWS credentials and secrets were observed across multiple historical package versions.
Credential-based attacks affected end-user services, including brute-force attempts against Dashlane accounts leading to encrypted vault downloads for a small number of users. Attackers targeted authentication mechanisms including two-factor protection and device registration controls. Account security responses included automatic locking and incident containment measures.
State-aligned activity included espionage operations by Gamaredon against Ukrainian government systems using WinRAR exploitation and multi-stage malware delivery chains. The activity deployed GammaPhish and GammaWorm components for persistence, lateral movement, and data exfiltration. Command-and-control infrastructure leveraged Telegram and cloud-based dead-drop mechanisms.
Cloud infrastructure abuse involved malware operations using AWS Lambda Function URLs configured without authentication to proxy command-and-control traffic. Stolen IAM credentials enabled deployment of serverless functions acting as relays between infected systems and external operators. Communication blended into legitimate AWS traffic to evade network detection.
Mobile and enterprise systems were impacted by exploitation of an Android Framework zero-day (CVE-2025-48595) enabling privilege escalation on widely deployed devices. The vulnerability was actively exploited before patch release across multiple Android versions. Patch cycles addressed a broader set of Framework, kernel, and vendor-level security flaws.
Highlights of the Day
Android June 2026 Bulletin Details Critical Framework Flaw
June 2026 Android Security Bulletin a critical Framework vulnerability enabling remote elevation of privilege without user interaction across releases 14–16-qpr2, including CVE-2025-65018, CVE-2025-64720 and CVE-2026-0009. System component includes critical elevation-of-privilege vulnerabilities such as CVE-2026-0043, CVE-2026-0097 and CVE-2026-21352, alongside denial-of-service issues and high-severity remote code execution flaw CVE-2026-0059 affecting Android 14–16-qpr2. Kernel CVE-2025-40214 in upstream Net enables local elevation of privilege, while vendor sections report PowerVR GPU, MediaTek, Unisoc and Qualcomm component vulnerabilities across Android devices.
Kirki WordPress Plugin Flaw Enables Admin Account Takeover
CVE-2026-8206 affects the Kirki Freeform Page Builder WordPress plugin, a CVSS 9.8 flaw enabling unauthenticated administrator account takeover via password reset mechanism. Flaw originates in handle_forgot_password() within CompLibFormHandler, where a REST API endpoint accepts attacker-supplied email instead of the account’s registered email. Active exploitation has been reported against versions 6.0.0–6.0.6, deployed on over 500,000 WordPress sites with approximately 150,000 vulnerable installations and 59 blocked attacks 24 hours.
Sophos X-Ops observed a threat actor using AI tools including Cursor and Claude Opus 4.5 to develop EDR evasion capabilities within a red team-style framework. The activity included Cobalt Strike beacons, Telegram API-based command and control, Cloudflare Worker redirectors, and virtual machines simulating Windows Server 2022 environments for testing. Researchers identified a Python payload generator producing Rust and Go executables with layered encryption and evasion linked to ransomware and data theft operations.
Dashlane Brute-Force Attack Exposes Encrypted Vaults of Users
Dashlane disclosed that an external threat actor conducted a brute-force attack against selected user accounts, targeting 2FA protections and device registration mechanisms. On 31 May 2026, fewer than 20 personal plan users had encrypted vaults downloaded after attackers succeeded in account access despite security controls. Dashlane confirmed accounts were temporarily suspended during the incident response, with affected users notified and no evidence of internal system compromise reported.
Instagram Accounts Hijacked via Meta AI Support Abuse
Multiple Instagram users had accounts hijacked after attackers convinced Meta AI support tools they were legitimate owners, affecting Obama White House and Jane Manchun Wong. Attackers used password reset flow, passing AI selfie verification with AI-generated video from target images, then changed associated email and bypassed 2FA and geolocation checks. Victims reported recovery lockouts where Instagram AI support chatbot loops prevented escalation to human agents, leaving users unable to regain access after account takeover.
HazyBeacon Abuses AWS Lambda Function URLs for Cloud C2
HazyBeacon CL-STA-1020 targets Southeast Asian government networks by abusing AWS Lambda Function URLs configured with AuthType NONE as command-and-control relays, deployed using stolen IAM credentials. Attackers use stolen IAM keys to deploy Lambda functions and Function URLs, routing HTTP POST traffic through AWS infrastructure to attacker-controlled servers via on.aws domains. HazyBeacon operates as a Windows backdoor performing system enumeration, remote command execution and data exfiltration, while blending communications into AWS HTTPS traffic to evade detection.
Gamaredon Uses GammaPhish and GammaWorm in Ukraine Espionage Campaign
Gamaredon, a Russia FSB-linked APT, targeted Ukrainian government networks using GammaPhish xHTML lures, RAR archives exploiting CVE-2025-8088 to deploy HTA via Startup and mshta.exe. GammaWorm VBScript malware establishes persistence through NTFS Alternate Data Streams, scheduled tasks, propagating via USB and network drives while creating malicious LNK shortcuts. Reporting details a modular infection chain including GammaLoad, GammaSteel, GammaPhish and GammaWorm, using Dead Drop Resolvers via Telegram and Cloudflare for C2 communication and exfiltration.
Deleted PyPI Packages Expose Apache Admin GitHub Token
Researchers recovered 678,376 deleted PyPI releases and scanned 600,000 packages, identifying 190 unique secrets including a GitHub PAT granting admin access to Apache and Astronomer. Deleted PyPI packages remain accessible via files.pythonhosted.org object storage, while PyPI BigQuery metadata enables reconstruction of download paths and recovery of package artifacts. Across 161 packages containing secrets, findings included additional AWS access keys and credentials spanning multiple years, with the oldest leak dating to 2018.
GorgonAgora Runs 4,800 Fake Storefronts Stealing Cards
GorgonAgora operates over 4,800 fake storefronts impersonating global brands, scraping Shopify catalogs and running Medusa.js with payment-vanilla.iife.js skimmer SDK to capture checkout data. The skimmer injects a fake Stripe iframe and exfiltrates card data via WebSocket using AES-256-GCM, relaying 3D Secure flows to C2 at 80.97.160.51 in Moldova. Two backend generations include shared-key and per-store Medusa deployments, with unchanged frontend fingerprints across thousands of sites and expansion exceeding 6,000 urlscan matches.
Daily Coverage