CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (8 June 2026)

Published: Loading…

At a Glance

  • The Miasma worm compromised 73 Microsoft GitHub repositories and deployed credential-harvesting payloads through AI coding tools and developer workflows.
  • Thirty-seven malicious PyPI packages linked to Shai-Hulud downloaded the Bun runtime and executed JavaScript stealers targeting developer credentials.
  • Attackers are actively exploiting CVE-2026-3300 in Everest Forms Pro to execute PHP code and create rogue WordPress administrator accounts.
  • Cisco warned that CVE-2026-20245 in Catalyst SD-WAN Manager is under active exploitation across multiple deployment environments.
  • CISA added SolarWinds Serv-U vulnerability CVE-2026-28318 to the KEV catalogue after evidence of active denial-of-service exploitation.
  • The Silent Ransom Group is targeting US law firms with fake IT support calls that frequently lead to rapid data theft.

Summary

Supply-chain attacks remained a dominant theme as the Miasma campaign expanded across software development ecosystems. A compromised contributor account enabled malicious commits that triggered credential-harvesting payloads when repositories were opened through AI-assisted coding environments. Related activity also involved malicious PyPI packages that abused Python startup mechanisms to install the Bun runtime and execute JavaScript-based credential stealers.

Developer environments and cloud credentials were repeatedly targeted through attacks designed to compromise trusted workflows. The Miasma-linked payloads sought access to GitHub, AWS, Azure, GCP, Kubernetes, npm, PyPI and Claude-related configurations. Separately, a record Chrome security release addressed hundreds of vulnerabilities while autonomous tooling identified multiple previously unknown FFmpeg flaws.

Actively exploited vulnerabilities affected enterprise infrastructure, content management systems and file transfer software. Cisco warned that CVE-2026-20245 in Catalyst SD-WAN Manager is under active exploitation and currently lacks an available patch. CISA also added CVE-2026-28318 in SolarWinds Serv-U to its Known Exploited Vulnerabilities catalogue following evidence of ongoing attacks.

WordPress environments faced continued exploitation through CVE-2026-3300 in Everest Forms Pro. The remote code execution flaw allows unauthenticated PHP code injection through the Complex Calculation feature and has been used to create rogue administrator accounts. Router infrastructure also remained under pressure as the C0XMO botnet targeted DD-WRT firmware and attempted to eliminate competing malware infections.

Social engineering operations continued to target professional organisations and sensitive data repositories. The Silent Ransom Group used fake IT support calls against US law firms and professional services organisations, with data theft often occurring within hours of contact. Oxford University disclosed another third-party platform breach affecting CareerConnect users, exposing names, email addresses and encrypted passwords.

Highlights of the Day

Attackers Exploit Everest Forms Pro Code Execution Flaw

Wordfence reported active exploitation of a critical CVSS 9.8 remote code execution vulnerability in Everest Forms Pro for WordPress, affecting versions up to 1.9.12. The flaw stems from the Calculation Addon's process_filter() function, which concatenates user-supplied form values into PHP code and executes it through eval(), enabling unauthenticated PHP code injection when forms use the Complex Calculation feature. Attackers have targeted sites since 13 April 2026, with Wordfence blocking more than 29,300 exploit attempts, including payloads designed to create rogue WordPress administrator accounts.

Source: Wordfence

Miasma Worm Targets Microsoft Azure Repositories and AI Coding Tools

A supply chain attack tied to the Miasma worm campaign compromised a contributor account to push malicious commit 5f456b8 into Microsoft's Azure/durabletask GitHub repository on 5 June 2026, planting configuration files that execute a 4.6 MB obfuscated JavaScript credential harvester when developers open the repository in Claude Code, Gemini CLI, Cursor, or VS Code. GitHub's automated enforcement disabled 73 Microsoft repositories across four organisations in a 105-second window, including Azure/functions-action, breaking CI/CD pipelines for developers relying on the official Azure Functions deployment action. In a related development, Socket Research identified 37 malicious PyPI wheel artifacts across 19 packages — attributed to the same Miasma/Shai-Hulud lineage — which abuse Python's .pth startup execution to download the Bun JavaScript runtime and run a credential stealer targeting GitHub, AWS, GCP, Azure, Kubernetes, npm, PyPI, and Claude/MCP configurations.

Research Exposes Residential Proxy SDK in Consumer Devices

Include Security analysed Bright Data’s SDK and reported that partner apps can turn mobile phones and smart TVs into residential proxy nodes, routing customer web-scraping traffic through users’ home internet connections. The researchers reverse-engineered the iOS framework, observed persistent WebSocket connections to Bright Data infrastructure, and documented telemetry collection covering battery status, network state, device activity and bandwidth availability. The report also found the SDK can bind traffic directly to physical network interfaces on iOS, allowing proxy communications to bypass some VPN-based inspection and monitoring controls.

Daily Coverage

Developments
Miasma Supply ChainPypi CompromisesEverest Forms ExploitationCisco Sd-Wan Flaw
Vulnerabilities
CVE-2026-50751Quantum Security Gateway R82.10 With Jumbo Hotfix Take 19 Or Below (Critical)CVE-2026-28318CVE-2025-8088Winrar 7.13 (High)CVE-2026-23111CVE-2026-20245Cisco Catalyst Sd-Wan Controller 20.6.4 (High)CVE-2026-3300CVE-2026-40984CVE-2026-40983CVE-2026-49975CVE-2026-41722