Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (15 June 2026)
Published: Loading…
At a Glance
- FBI disrupted Chinese phishing-as-a-service operation Outsider Enterprise using millions of URLs to steal credentials and credit card data globally.
- Attackers hijacked over 400 Arch User Repository packages in Atomic Arch campaign, injecting npm dependencies that delivered credential-stealing malware.
- US government ordered suspension of Anthropic Fable 5 and Mythos 5 access for foreign nationals under export control concerns.
- Splunk Enterprise PostgreSQL sidecar endpoint flaw enables unauthenticated file creation and truncation, rated CVSS 9.8 affecting versions below 10.2.4.
- Operation Highland attributed to Velvet Ant shows decade-long intrusion using PAM and OpenSSH compromise for authentication bypass and keylogging.
- WordPress OptinMonster TrustPulse and PushEngage supply chain attack compromised 1.2 million sites via CDN backdoors creating admin accounts.
Summary
Anthropic suspended Fable 5 and Mythos 5 globally after receiving US government export control directive citing national security and jailbreak exploitation concerns. FBI disrupted Chinese phishing-as-a-service operation Outsider Enterprise using a network of millions of URLs to harvest credentials and payment data globally across victims. Outsider Enterprise infrastructure enabled large-scale credential theft and payment data exfiltration through distributed phishing websites operated across multiple domains.
WordPress OptinMonster TrustPulse and PushEngage supply chain compromise affected 1.2 million sites through CDN-delivered scripts creating administrative backdoors and credential exfiltration channels. Attackers hijacked over 400 Arch User Repository packages in Atomic Arch campaign by inserting malicious npm dependencies into trusted build scripts. Splunk Enterprise PostgreSQL sidecar endpoint vulnerability allows unauthenticated file creation and truncation affecting versions below 10.2.4 with CVSS 9.8 severity.
Velvet Ant Operation Highland maintained decade-long access inside isolated networks using compromised PAM modules and modified OpenSSH authentication components. NPM 12 will change default script execution behavior to prevent automatic execution of dependency installation scripts during package installs. Former Iowa school district IT employee received 21-month sentence for hacking former employer systems causing operational disruption and account deletion. Splunk vulnerability CVE-2026-20253 in PostgreSQL sidecar service enables unauthenticated file operations including creation and truncation across affected enterprise deployments.
Highlights of the Day
Supply Chain Attack Hits WordPress Plugin CDN Infrastructure
Sansec identified a supply-chain compromise of OptinMonster TrustPulse and PushEngage WordPress plugins affecting over 1.2m sites via CDN-delivered JavaScript injection. Injected JavaScript executes only in WordPress admin contexts, creating rogue administrator accounts, installing self-hiding plugins, and exfiltrating credentials to tidio.cc infrastructure. Sophisticated payloads persist via Awesome Motive CDN endpoints, establishing hidden admin accounts and backdoors, with activity confirmed continuing as of 13 June 2026.
Operation Highland Reveals Decade-Long Velvet Ant Intrusion
Operation Highland attributed to China-nexus Velvet Ant maintained access from 2016 to 2026 inside a segmented network reached via multi-stage pivoting from internet-facing systems. PAM and OpenSSH were replaced with backdoored components including pam_unix.so variants and modified ssh and sshd binaries enabling credential harvesting, authentication bypass and keylogging. Initial access used GS-Netcat and SOCKS5 tunnelling on internet-facing hosts, with Nginx and FastCGI chaining enabling remote execution into isolated infrastructure alongside SSH authorised_keys persistence.
Splunk PostgreSQL Sidecar Bug Enables Unauthenticated File Manipulation
Splunk Enterprise versions below 10.2.4 and 10.0.7 contain an unauthenticated PostgreSQL sidecar service endpoint allowing remote file creation and truncation via network access. The flaw stems from missing authentication controls on the endpoint, enabling unauthenticated users to invoke file operations without credentials, rated CVSSv3.1 9.8 under VULN-67169. Splunk Enterprise fixes are available in versions 10.4.0, 10.2.4 and 10.0.7, with earlier releases affected across splunkd components.
US Orders Suspension of Fable 5 and Mythos 5 Access
US government issued an export control directive suspending access to Fable 5 and Mythos 5 for foreign nationals, citing concerns linked to a potential jailbreak. Anthropic reviewed a demonstration of the technique and identified previously known minor vulnerabilities, noting similar issues were observable in other publicly available models. Anthropic complied with the directive and disabled Fable 5 and Mythos 5 globally, while stating that all other Anthropic models remain unaffected.
Daily Coverage