Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (16 June 2026)
Published: Loading…
At a Glance
- GlassWASM malware in Open VSX extensions uses TinyGo WebAssembly, Solana blockchain C2, and dodod[.]lat infrastructure deployment chain.
- UNC6508 targeted North American medical and military research by exploiting REDCap servers, deploying INFINITERED malware and Google Workspace rules.
- ShinyHunters claims Council of Europe breach involving Oracle PeopleSoft zero-day exploitation, exfiltrating 297GB across 429,000 files records stolen.
- NVIDIA CVE-2026-24190 kernel driver flaw enables local privilege escalation in enterprise AI GPU systems via IOCTL validation issues.
- Cisco Catalyst SD-WAN Manager CVE-2026-20262 is actively exploited for authentication bypass enabling unauthorized portal and gateway access exploitation.
Summary
GlassWASM supply-chain activity affected Open VSX extensions delivering GlassWASM malware through TinyGo WebAssembly loaders and blockchain-based command resolution mechanisms. WordPress plugins OptinMonster, TrustPulse, and PushEngage were tampered with, introducing backdoors and unauthorized admin account creation across compromised websites deployments.
SimpleHelp remote management software vulnerability allowed unauthenticated attackers to create privileged technician accounts via OpenID Connect authentication configuration weaknesses protocol. UNC6508 espionage operations targeted North American medical and military research institutions through compromised REDCap servers and persistent malware deployment campaigns. Attackers maintained long-term access and exfiltrated sensitive research communications by abusing Google Workspace rules to silently forward emails externally systematically.
ShinyHunters claimed responsibility for Council of Europe breach involving Oracle PeopleSoft zero-day exploitation and large-scale data theft operations campaign activity. Stolen data reportedly included payroll records, CVs, contracts, financial documents, and medical information across more than 400,000 compromised files datasets.
NVIDIA CVE-2026-24190 kernel driver flaw affects enterprise AI GPU systems, enabling local privilege escalation through IOCTL validation weaknesses infrastructure environments. Cisco Catalyst SD-WAN Manager CVE-2026-20262 is actively exploited for authentication bypass enabling unauthorized access to network portals and gateways exploitation.
Anthropic disabled Fable 5 and Mythos 5 models after US government export control directive citing national security concerns and jailbreak risks. Arch Linux AUR experienced malicious commits affecting hundreds of packages, forcing temporary shutdown of new account registrations during cleanup operations. FBI and Google dismantled Outsider Enterprise phishing service responsible for millions of stolen credit cards and significant financial losses.
Highlights of the Day
ShinyHunters Claims Council of Europe Data Breach
ShinyHunters claims breach of the Council of Europe, posting on a Tor leak site and reporting theft of 297GB across 429,000 files in multiple departments. The group alleges payroll data for over 10,000 employees from 2011 to 2026, along with 14,000 CVs, contracts, purchase orders and financial and medical records. ShinyHunters set a June 16 deadline for negotiations, Council of Europe is investigating, and Google linked group to an Oracle PeopleSoft zero-day affecting 100 organisations.
US export controls restrict Anthropic Fable 5 over alleged jailbreak
US government export control directive suspended access to Anthropic Fable 5 and Mythos 5 over alleged guardrail bypass concerns, leading Anthropic to disable both models. Researchers used vulnerable code with prompts 'fix this code' to generate patches and test scripts, which Moussouris describes as defensive security workflow rather than jailbreak. Critics argue export restrictions on advanced models may weaken defensive capabilities, with an open letter urging reversal citing Wassenaar precedents and limited impact on adversaries.
China-Nexus UNC6508 Targets Medical Research With REDCap Malware
Google Threat Intelligence Group attributes UNC6508, a PRC-nexus actor, to a campaign targeting North American medical, academic and military research organisations via REDCap exploitation. Attackers exploited REDCap servers, deployed INFINITERED malware to harvest credentials, and maintained access for over a year before escalating to domain administrator privileges. UNC6508 later used a malicious content compliance rule to silently BCC-forward targeted emails to a Gmail account, enabling covert data exfiltration of sensitive research communications.
NVIDIA Kernel Driver Flaw Exposes AI GPU Systems to Escalation
Kernel flaw CVE-2026-24190 in NVIDIA Windows kernel display driver nvlddmkm.sys affecting enterprise AI GPU stacks, IOCTL validation issue enabling local privilege escalation. Patch diff analysis shows fixes across multiple routines introducing pointer slot isolation, object lifecycle validation, and error path cleanup including ExReleaseResourceLite to prevent lock leaks. Exploitation risk in multi-tenant GPU passthrough environments enabling kernel compromise, DoS, and BYOVD relevance via vulnerable driver loading.
WebAssembly Malware Hidden in Open VSX Extensions
Socket Threat Research found GlassWASM malware in trojanised Open VSX extensions using TinyGo WebAssembly payload in exargd/vsblack@0.0.1 and noellee-doc/flint-debug@0.0.1, published via account zaitoona43. The WebAssembly module compiled via TinyGo uses ChaCha20 encrypted strings and executes through Node syscall/js bridge, activating on extension startup via go.run() loader. Malware polls Solana blockchain JSON-RPC getSignaturesForAddress and getTransaction to extract SPL Memo commands, then builds OS-specific child_process download-and-execute payloads targeting dodod[.]lat infrastructure.
Daily Coverage