CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (13 June 2026)

Published: Loading…

At a Glance

  • Attackers compromised over 400 Arch Linux AUR packages by altering build scripts to execute malicious npm dependencies delivering Rust-based infostealer payloads.
  • Splunk Enterprise CVE-2026-20253 enables pre-authentication exploitation of PostgreSQL Sidecar endpoints for file write and remote code execution via backup and restore workflows.
  • Check Point Remote Access VPN CVE-2026-50751 allows authentication bypass through IKEv1 certificate validation flaws affecting multiple Gaia product versions.
  • Law enforcement dismantled AudiA6 cryptocurrency laundering service, seizing infrastructure linked to more than €336 million in ransomware-related transactions.
  • Attackers registered approximately 1.5 million malicious domains in early 2026, showing industrial-scale deployment of rapidly weaponised infrastructure.

Summary

A large-scale supply-chain intrusion affected the Arch Linux AUR ecosystem, where attackers modified build scripts across hundreds of community packages. The activity introduced a Rust-based infostealer that executed during package compilation and targeted developer credentials. Additional npm-based payloads expanded the distribution chain through dependency injection during builds.

Enterprise vulnerability exploitation featured prominently with Splunk Enterprise CVE-2026-20253, where PostgreSQL Sidecar Service endpoints exposed unauthenticated backup and restore operations. Attackers leveraged these workflows to manipulate database parameters, extract credentials, and achieve file write conditions leading to remote code execution. The exploitation chain relied on abuse of internal database tooling exposed through web-accessible interfaces.

Authentication and perimeter security issues also emerged in Check Point Remote Access VPN CVE-2026-50751, where IKEv1 certificate validation logic allowed authentication bypass. The flaw affected multiple Gaia versions and enabled unauthorised access under specific protocol conditions. Exploitation activity has been observed against limited targets including enterprise environments.

Financially motivated infrastructure disruption included the dismantling of AudiA6 cryptocurrency laundering service, which processed ransomware proceeds across thousands of transactions. Law enforcement actions resulted in seizure of servers, domains, and associated digital assets linked to laundering operations. The service supported multiple ransomware groups through multi-stage obfuscation of cryptocurrency flows.

Mass-scale malicious infrastructure creation was recorded through the registration of approximately 1.5 million malicious domains within the first half of 2026. The domains were rapidly weaponised and concentrated across a small number of registrars and hosting providers. Activity patterns indicate automated deployment pipelines supporting phishing, malware delivery, and SEO poisoning campaigns.

Highlights of the Day

152 Chrome Extensions Faked Google Search Traffic

Socket Threat Research identified a family of 152 Chrome new-tab live wallpaper extensions, distributed across 38 publisher accounts with about 105,000 reported installs, that generated fabricated Google organic search attribution, logged install and uninstall events, and linked to privacy policies admitting collection of IP addresses, ISP details, click counts and referrers despite Chrome Web Store disclosures stating no user data was collected. The researchers found 54 extensions using forged utm_source=google&utm_medium=organic parameters and disguised google.com/url uninstall redirects to make extension-generated visits appear as genuine Google search traffic, while all analysed variants contained an undisclosed IndexedDB deletion routine that was inactive in the current build but present across the shared codebase.

Source: Socket

Crypto Laundering Network Behind Ransomware Dismantled

An international law enforcement operation dismantled the ‘AudiA6’ cryptocurrency laundering service, which allegedly processed more than EUR 336 million between 2022 and 2025 for ransomware groups and other cybercriminals, arresting two suspected administrators in Georgia, seizing more than 30 servers, taking down 25 domains and freezing or seizing cryptocurrency assets. Europol linked the service to more than 15 ransomware and cryptocurrency theft investigations, finding it used thousands of fraudulently created exchange accounts supported by over 6,000 Know Your Customer records and charged commissions of 3 to 10 percent to obscure the origin of stolen cryptocurrency through rapid multi-stage transactions.

Source: Europol

Conti Ransomware Developer Pleads Guilty in US Case

A Ukrainian national, Oleksii Oleksiyovych Lytvynenko, pleaded guilty in the United States to conspiracy to commit wire fraud for his role in the Conti ransomware operation between 2021 and 2022, admitting he possessed data stolen from eight US victims and four overseas victims and helped develop a malware loader used in attacks. According to the US Department of Justice, the Conti group targeted more than 1,000 victims worldwide, collected over $150 million in ransom payments, and Lytvynenko now faces a maximum prison sentence of 20 years following his extradition from Ireland in 2024.

Check Point VPN Flaw Enables Full Authentication Bypass

Check Point disclosed CVE-2026-50751, a critical IKEv1 authentication bypass in Remote Access VPN and Mobile Access/SSL VPN products affecting multiple Gaia versions, where certificate validation logic in the deprecated IKEv1 code allows attackers to influence authentication decisions through vendor-specific payload flags. The flaw stems from a logic error in machine certificate handling and peer verification where attacker-controlled Vendor ID fields can set authentication state flags that disable signature verification, enabling unauthenticated access even with invalid certificates. Exploitation has been observed in the wild since May 2026, with Check Point releasing hotfixes in June 2026 after reports of targeted attacks against a limited number of organisations, including activity linked to a Qilin ransomware affiliate.

Over 400 AUR Packages Hijacked to Deliver Infostealer Rootkit

Attackers compromised more than 400 packages in the Arch User Repository (AUR) by modifying PKGBUILD and install scripts to execute a malicious npm dependency, atomic-lockfile@1.4.2, which triggered a Rust-based infostealer during package builds and enabled credential theft from browsers, Electron apps, SSH keys, and developer tooling. The malware exfiltrated data via HTTP to temp.sh and used Tor-based command-and-control, with optional eBPF rootkit functionality that, when executed with root privileges, hid processes, sockets, and process identifiers using pinned BPF maps and installed persistent systemd services. A second wave of related AUR compromises involved the js-digest npm package, while confirmed affected AUR packages included alvr and premake-git, with overall exposure exceeding 400 community-maintained packages.

Splunk PostgreSQL Sidecar Endpoint Enables Pre-Auth RCE

Splunk Enterprise CVE-2026-20253 is a pre-authentication vulnerability in the PostgreSQL Sidecar Service endpoint that allows unauthenticated users to invoke backup and restore operations through /v1/postgres/recovery/backup and /v1/postgres/recovery/restore, exposing file write and file overwrite primitives via the pg_dump and pg_restore workflow. The flaw enables attackers to manipulate database connection parameters embedded in the database field, bypass localhost restrictions to connect to external PostgreSQL instances, extract credentials via .pgpass, and trigger arbitrary file writes through SQL functions executed during restore operations. Successful exploitation results in arbitrary file creation and overwriting under the Splunk service context, with chained abuse of the restore process leading to pre-authenticated remote code execution across affected Splunk Enterprise deployments.

Daily Coverage

Developments
Aur Package HijackSplunk Rce FlawCheck Point BypassAudia6 Takedown
Vulnerabilities
CVE-2026-20253Splunk Enterprise 10.2 (Critical)CVE-2026-50751Quantum Security Gateway R82.10 With Jumbo Hotfix Take 19 Or Below (Critical)
Threat Groups
Velvet AntVelvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.