Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (4 June 2026)
Published: Loading…
At a Glance
- US federal audit found NIST lacked strategic plan for National Vulnerability Database, leaving backlog exceeding 27,000 unprocessed vulnerabilities.
- Malicious ai-sdk-ollama npm package versions used binding.gyp node-gyp execution to run install-time payload stealing cloud credentials and CI secrets.
- HTTP/2 memory exhaustion attack affects nginx, Apache, IIS, Envoy and Cloudflare Pingora, enabling single clients to consume large server memory.
- Attackers maintained five-month access to stock exchange executive Outlook mailbox, exfiltrating emails through Dropbox and OneDrive using incremental extraction tools.
- C0XMO Gafgyt botnet exploits DD-WRT CVE-2021-27137, spreading across Linux IoT systems using brute-force modules and multi-stage command-and-control infrastructure.
Summary
US federal audit of NIST National Vulnerability Database found absence of strategic planning and persistent backlog exceeding 27,000 unprocessed vulnerabilities across reporting cycles. HTTP/2 memory exhaustion attacks affected nginx, Apache HTTPD, Microsoft IIS, Envoy and Cloudflare Pingora, enabling single clients to retain large server memory allocations rapidly.
Malicious ai-sdk-ollama npm package versions executed install-time hooks via binding.gyp and node-gyp, launching obfuscated payloads that exfiltrated cloud credentials and CI/CD secrets. Separate open-source campaigns injected malicious GitHub Actions workflows and poisoned package ecosystems, targeting GitHub, npm, PyPI and Crates.io to steal developer credentials and tokens.
FSB-linked Gamaredon operations used GammaLoad multi-stage loaders with Telegram-based delivery, scheduled tasks and registry persistence to deploy GammaSteel against Ukrainian government networks. Espionage activity included stock exchange executive mailbox compromise using Dropbox and OneDrive exfiltration, alongside expansion of Chinese-speaking group TA4922 deploying Atlas RAT and ValleyRAT.
WeedHack malware-as-a-service targeted Minecraft users via YouTube and SEO poisoning, delivering trojanised clients that enabled remote access, credential theft and webcam monitoring across infected systems. C0XMO Gafgyt botnet exploited DD-WRT vulnerability CVE-2021-27137, spreading across Linux IoT devices using brute-force propagation, cron persistence and multi-stage command-and-control infrastructure.
Redis CVE-2026-23479 use-after-free vulnerability allowed authenticated users to trigger remote code execution affecting Redis 7.2.x through 8.6.x across multiple deployments. Impersonation campaigns and Traffic Distribution Systems hijacked software downloads and open-source portals, while WordPress plugin flaws enabled privilege escalation and website takeover attacks.
Highlights of the Day
Federal Audit Faults NIST Over NVD Backlog
A U.S. Department of Commerce Office of Inspector General audit found NIST lacked a strategic plan for the National Vulnerability Database and set a September 2024 backlog-clearing target beyond its processing capacity. The report said unprocessed vulnerabilities grew from about 13,000 in June 2024 to more than 27,000 by the end of 2025, and 34% of reviewed CISA Known Exploited Vulnerabilities entries were not enriched within a one-day benchmark. Auditors also identified at least 21,000 duplicated enrichment activities between NIST and CISA from May 2024 through December 2025, estimating roughly $200,000 in wasted spending while vulnerability processing delays persisted.
Attackers Hide Malicious Content in Legitimate Emails
Cofense documented a tactic in which threat actors abuse arbitrary text fields in legitimate services, including Zoom usernames, meeting descriptions and event details, to embed phishing links and scam messages in automated emails. Because the messages are generated and sent by legitimate platforms, they retain valid DMARC, DKIM and SPF authentication while preserving official branding and sender addresses. Observed examples included Zoom notifications containing a PayPal-themed phone scam and meeting invitations spoofing the U.S. Social Security Administration that linked to a site delivering the ConnectWise remote access tool.
Gamaredon Uses Layered Loaders to Deploy Malware
Sekoia analysed GammaLoad, a multi-stage loader framework used by the FSB-linked Gamaredon group in cyberespionage campaigns targeting Ukrainian government, military and critical infrastructure networks. The infection chain uses VBScript and PowerShell loaders that store command-and-control configuration in the Windows registry, retrieve payloads through Telegram, Telegraph, Check-Host and Cloudflare infrastructure, and execute code largely in memory. Researchers observed GammaLoad creating a scheduled task named \Windows\ApplicationData\DsSvcCleanup, using Alternate Data Streams for payload storage, and ultimately delivering the GammaSteel information-stealing malware.
HTTP/2 Flaw Enables Severe Memory Exhaustion Attacks
Researchers disclosed an HTTP/2 denial-of-service technique that combines HPACK header-compression amplification with flow-control stalling, allowing attackers to consume and retain large amounts of server memory using minimal bandwidth. The attack affects default HTTP/2 configurations in nginx, Apache httpd, Microsoft IIS, Envoy and Cloudflare Pingora, with testing showing a single client could hold roughly 32GB of memory on Apache httpd and Envoy within about 20 seconds. Apache addressed the issue in mod_http2 v2.0.41 under CVE-2026-49975, nginx added a default header-count limit in version 1.29.8, and Envoy has released patches while fixes for IIS and Pingora were not available at publication.
Espionage Operation Stole Exchange Executive’s Emails
Researchers uncovered a five-month espionage campaign targeting a senior executive at a major global stock exchange, where attackers maintained SYSTEM-level access using masquerading binaries, scheduled tasks and repeated persistence mechanisms. The operation used an Aspose-based tool to extract Outlook OST mailbox data in incremental date ranges, creating near-continuous copies of emails from August 2025 through February 2026. Stolen data was exfiltrated through Dropbox and OneDrive Personal using API access and hard-coded Microsoft IP addresses, while attackers also employed public tools including Secretsdump, SharpDecryptPwd and BypassUAC.
WeedHack Minecraft Malware-as-a-Service Spreads via YouTube
McAfee Labs reported Weedhack, a Minecraft-focused malware-as-a-service campaign active since January 2026, distributing trojanised JAR clients and mods impersonating Minecraft tools. It leverages SEO poisoning and YouTube videos, with two channels and over 240 distribution URLs identified, hosting more than 3820 malicious JAR files. The malware uses EtherHiding with Ethereum blockchain-based C2 resolution and RSA-signed responses, enabling credential theft, remote access, webcam monitoring and system control.
New C0XMO Gafgyt Variant Exploits DD-WRT Flaw for IoT Botnet
C0XMO Gafgyt botnet variant exploits CVE-2021-27137 in DD-WRT firmware before changeset 45723, abusing UPnP SSDP M-SEARCH parsing to gain execution. C0XMO propagates across Linux architectures using a separate Python-based scanner module, performing Telnet and SSH brute-force attacks and installing cron and shell profile persistence mechanisms. C0XMO establishes a custom multi-stage C2 handshake and supports 19 DDoS techniques while leveraging HTTP exploits and Android Debug Bridge vulnerabilities for propagation.
Impersonation Sites Hijack Downloads via CloudFront TDS Chains
Check Point Research analysed a large campaign impersonating open-source and freeware projects, including Ghidra and dnSpy, to capture search traffic and downloads via malicious-looking portals. The sites load CloudFront-hosted JavaScript that hijacks download clicks into a Traffic Distribution System enforcing anti-bot gating, device filtering, and multi-step redirect chains. Observed branches delivered PUAs and malware including RemusStealer, AnimateClipper and SessionGate, with per-session payload generation, encrypted modules, and server-side key-based decryption mechanisms.
Redis use-after-free in blocked clients enables remote code execution
CVE-2026-23479 describes a use-after-free in Redis unblockClientOnKey within blocked client handling that allows an authenticated user to trigger remote code execution on the host system. The issue arises when processCommandAndResetClient may free the client without return value checks, leaving dangling references accessed in unblockClientOnKey and subsequent execution paths. Redis 7.2.0 onwards across 7.2.x, 7.4.x, 8.2.x, 8.4.x and 8.6.x are affected, with vendor patches released on 5 May 2026 across all maintained branches.
Havoc Stager Abuses Fake Microsoft Defender in Invoice Campaign
LevelBlue SpiderLabs reports a Havoc campaign using Brazilian NF-e invoice ZIP attachments in May 2026, delivering a fake Microsoft Defender DLP installer that drops a stager DLL which retrieves Havoc from remote infrastructure. Nine stager variants spoof Microsoft Defender metadata and use a Microsoft-Delivery-Optimization user-agent to request /stage endpoints for payload delivery. Persistence uses HKCU UserInitMprLogonScript, and Havoc enables remote execution, screen monitoring, and lateral movement after deployment.
Four Open-Source Ecosystem Campaigns Steal Developer Credentials
Megalodon campaign injected GitHub Actions workflows into 5,561 repositories via 5,718 commits to steal CI pipelines and cloud credentials from CI pipelines. Laravel-Lang campaign rewrote Git tags across four Composer packages poisoning 700+ versions to deliver PHP credential stealers targeting cloud and vault tokens. TrapDoor and Miasma combined npm, PyPI, Crates.io, and Red Hat packages using preinstall and build hooks plus OIDC abuse to exfiltrate secrets.
TA4922 Chinese Cybercrime Group Expands Global Malware Campaigns
TA4922, a Chinese-speaking cybercriminal cluster tracked by Proofpoint, has expanded operations globally while deploying Atlas RAT, RomulusLoader, SilentRunLoader and ValleyRAT/Winos4.0 across campaigns. Campaigns use HR, payroll, tax and invoicing themed lures combined with credential phishing, DLL sideloading, and malware delivery via cloud file hosting services. Sophisticated tooling includes RomulusLoader deploying AnyDesk and SyncFuture RMM, SilentRunLoader stealing Chrome credentials, and rapidly developed Python malware likely generated using LLM assistance.
Malicious npm Package Steals Cloud Credentials via Install Hook
Endor Labs found four malicious versions of ai-sdk-ollama published to npm within 17 seconds, using binding.gyp to trigger node-gyp rebuild and execute node index.js during install, despite unchanged library code. Payload used ROT and AES-GCM obfuscation, launched Bun runtime, and stole AWS, GCP, Azure, Kubernetes and CI/CD secrets including GitHub and npm tokens, with potential worm-like republishing behaviour, downloading Bun from GitHub releases and executing a 668KB payload via a 4.5MB obfuscated script.
Daily Coverage