Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (9 June 2026)
Published: Loading…
At a Glance
- Check Point CVE-2026-50751 VPN authentication bypass exploited by Qilin ransomware affiliate targeting Remote Access and Mobile Access deployments.
- Hades PyPI supply chain campaign compromises packages using startup hooks and credential-stealing malware targeting AWS, GitHub, Kubernetes, and cloud environments.
- Meta AI-assisted support vulnerability allowed password reset abuse leading to hijacking of over 20,000 Instagram accounts globally incident.
- WhatsApp pursued contempt action against NSO Group after spear-phishing campaigns continued despite injunction blocking targeting of users order.
- Russia-aligned campaigns exploited WinRAR CVE-2025-8088 against Ukrainian organisations using decoy documents and credential-stealing malware persistence chains activity reported.
Summary
The Hades PyPI supply chain campaign compromised numerous bioinformatics and developer packages, executing startup hook malware to harvest cloud credentials. GitHub repositories were disabled after suspected Miasma worm infection triggered CI/CD failures and malicious commits affecting Microsoft projects systems globally. Attackers abused Visual Studio Code workflows and malicious VSIX extensions to execute cross-platform malware through developer repository interactions automation chains.
Exploitation of Check Point Remote Access VPN CVE-2026-50751 enabled authentication bypass attacks against organisations using IKEv1-based deployments across multiple sectors globally. CISA confirmed active exploitation of SolarWinds Serv-U CVE-2026-28318 allowing remote attackers to crash file transfer services via unauthenticated requests globally. Qilin ransomware affiliates leveraged VPN access obtained through authentication bypass flaws to progress post-compromise activity in targeted environments campaign operations.
Meta disclosed an AI-assisted support flaw that allowed attackers to reset passwords and hijack over 20,000 Instagram accounts. WhatsApp reported continued NSO Group spear-phishing attempts despite court injunctions leading to legal contempt proceedings in US federal court action. FBI reporting showed nearly 900 million dollars in losses from AI-powered scams involving deepfakes voice cloning and impersonation fraud schemes.
Russia-aligned actors exploited WinRAR CVE-2025-8088 against Ukrainian organisations using path traversal and malicious archive-based payload delivery techniques across campaigns activity. UNK_DeadDrop campaigns targeted developers via GitHub recruitment lures and VS Code extensions delivering credential-stealing malware globally operations tactics.
Highlights of the Day
Check Point VPN Flaw Bypasses Authentication
Check Point disclosed CVE-2026-50751, a critical authentication bypass vulnerability with a CVSS score of 9.3 affecting Remote Access VPN and Mobile Access deployments using the deprecated IKEv1 protocol. The flaw stems from a certificate validation logic weakness that allows attackers to establish VPN sessions without a valid user password, and active exploitation has targeted a few dozen organisations globally since at least May 2026. During its investigation, Check Point also identified CVE-2026-50752, a certificate validation issue with a CVSS score of 7.4 that could enable man-in-the-middle attacks against site-to-site VPN connections, although no exploitation has been observed.
Hades PyPI Campaign Compromises Developer and Cloud Credentials
Multiple security researchers reported the Hades supply-chain campaign affecting at least 30–37 PyPI packages, including ensmallen, embiggen and gpsea, where malicious releases execute on Python import using .pth startup hooks and trojanised native extensions to launch a Bun-based JavaScript payload. The malware extracts cloud and developer credentials such as AWS, Azure, GCP, Kubernetes, GitHub, PyPI, npm and SSH keys from Linux, macOS and Windows environments, using cross-platform memory scraping and encrypted exfiltration to attacker-controlled GitHub repositories. Analyses from Orca Security, Socket and StepSecurity further describe evolving variants with sys.path-based payload loading, worm-like propagation into CI/CD and package ecosystems, and persistence mechanisms tied to stolen GitHub tokens.
WhatsApp Seeks Contempt Order Against NSO Group
WhatsApp said it disrupted NSO Group-linked social-engineering activity that attempted to lure users to malicious external websites through phishing-style links and removed associated test accounts and groups created on the platform. The company is asking a US court to hold NSO in contempt of a permanent injunction issued after a 2025 ruling found the spyware vendor had violated federal and state anti-hacking laws. WhatsApp also released threat indicators linked to the activity, including the domains ikhwancast.com, ghazacast.com and fr24cast.com.
Fake Amazon Alert Delivers HarborWatch Remote Access Trojan
Cofense identified a phishing campaign using Amazon-themed security alerts and the ClickFix technique, directing victims to a fake verification page that copies a malicious PowerShell command to the clipboard and executes additional payloads. The infection chain downloads a file named mysql.exe from a remote server and launches it with a required command-line argument, ultimately deploying a custom remote access trojan tracked as HarborWatch Agent. Analysis showed the malware communicating with command-and-control infrastructure at 185[.]193[.]127[.]44, collecting system information including host details, resource usage, running processes and network status through API endpoints used for tasking and telemetry.
North Korean UNK_DeadDrop Targets Developers via GitHub Phishing
North Korean-aligned UNK_DeadDrop phishing campaign targeted developers across finance crypto education tech using fake recruitment GitHub repositories delivering malware via VS Code workflows. Attackers used actor-controlled GitHub links, malicious VSIX extensions, and VS Code tasks.json folderOpen automation to execute cross-platform Overlord Go malware. Payload delivered cross-platform credential theft and cryptocurrency wallet exfiltration on Windows, macOS and Linux, using Go binaries, Electron Node pipelines and C2 WebSocket infrastructure.
WinRAR Flaw Exploited in Ukraine Cyber Campaigns
Russia-aligned SHADOW-EARTH-066 and Earth Dahu exploited WinRAR CVE-2025-8088 path traversal vulnerability in RAR archives targeting Ukrainian organisations through decoy documents and hidden ADS payloads. SHADOW-EARTH-066 deployed evolved GIFTEDCROOK variant result.dll stealing browser credentials and files via PowerShell loaders, Startup folder persistence, and in-memory DLL execution chains. Earth Dahu used HTA-to-VBScript chains and Cloudflare Workers infrastructure, while exploitation persisted through at least April 2026 despite WinRAR 7.13 patch released July 2025.
Daily Coverage