CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (16 June 2026)

Published: Loading…

At a Glance

  • GlassWASM malware in Open VSX extensions uses TinyGo WebAssembly, Solana blockchain C2, and dodod[.]lat infrastructure deployment chain.
  • UNC6508 targeted North American medical and military research by exploiting REDCap servers, deploying INFINITERED malware and Google Workspace rules.
  • ShinyHunters claims Council of Europe breach involving Oracle PeopleSoft zero-day exploitation, exfiltrating 297GB across 429,000 files records stolen.
  • NVIDIA CVE-2026-24190 kernel driver flaw enables local privilege escalation in enterprise AI GPU systems via IOCTL validation issues.
  • Cisco Catalyst SD-WAN Manager CVE-2026-20262 is actively exploited for authentication bypass enabling unauthorized portal and gateway access exploitation.

Summary

GlassWASM supply-chain activity affected Open VSX extensions delivering GlassWASM malware through TinyGo WebAssembly loaders and blockchain-based command resolution mechanisms. WordPress plugins OptinMonster, TrustPulse, and PushEngage were tampered with, introducing backdoors and unauthorized admin account creation across compromised websites deployments.

SimpleHelp remote management software vulnerability allowed unauthenticated attackers to create privileged technician accounts via OpenID Connect authentication configuration weaknesses protocol. UNC6508 espionage operations targeted North American medical and military research institutions through compromised REDCap servers and persistent malware deployment campaigns. Attackers maintained long-term access and exfiltrated sensitive research communications by abusing Google Workspace rules to silently forward emails externally systematically.

ShinyHunters claimed responsibility for Council of Europe breach involving Oracle PeopleSoft zero-day exploitation and large-scale data theft operations campaign activity. Stolen data reportedly included payroll records, CVs, contracts, financial documents, and medical information across more than 400,000 compromised files datasets.

NVIDIA CVE-2026-24190 kernel driver flaw affects enterprise AI GPU systems, enabling local privilege escalation through IOCTL validation weaknesses infrastructure environments. Cisco Catalyst SD-WAN Manager CVE-2026-20262 is actively exploited for authentication bypass enabling unauthorized access to network portals and gateways exploitation.

Anthropic disabled Fable 5 and Mythos 5 models after US government export control directive citing national security concerns and jailbreak risks. Arch Linux AUR experienced malicious commits affecting hundreds of packages, forcing temporary shutdown of new account registrations during cleanup operations. FBI and Google dismantled Outsider Enterprise phishing service responsible for millions of stolen credit cards and significant financial losses.

Highlights of the Day

ShinyHunters Claims Council of Europe Data Breach

ShinyHunters claims breach of the Council of Europe, posting on a Tor leak site and reporting theft of 297GB across 429,000 files in multiple departments. The group alleges payroll data for over 10,000 employees from 2011 to 2026, along with 14,000 CVs, contracts, purchase orders and financial and medical records. ShinyHunters set a June 16 deadline for negotiations, Council of Europe is investigating, and Google linked group to an Oracle PeopleSoft zero-day affecting 100 organisations.

US export controls restrict Anthropic Fable 5 over alleged jailbreak

US government export control directive suspended access to Anthropic Fable 5 and Mythos 5 over alleged guardrail bypass concerns, leading Anthropic to disable both models. Researchers used vulnerable code with prompts 'fix this code' to generate patches and test scripts, which Moussouris describes as defensive security workflow rather than jailbreak. Critics argue export restrictions on advanced models may weaken defensive capabilities, with an open letter urging reversal citing Wassenaar precedents and limited impact on adversaries.

China-Nexus UNC6508 Targets Medical Research With REDCap Malware

Google Threat Intelligence Group attributes UNC6508, a PRC-nexus actor, to a campaign targeting North American medical, academic and military research organisations via REDCap exploitation. Attackers exploited REDCap servers, deployed INFINITERED malware to harvest credentials, and maintained access for over a year before escalating to domain administrator privileges. UNC6508 later used a malicious content compliance rule to silently BCC-forward targeted emails to a Gmail account, enabling covert data exfiltration of sensitive research communications.

NVIDIA Kernel Driver Flaw Exposes AI GPU Systems to Escalation

Kernel flaw CVE-2026-24190 in NVIDIA Windows kernel display driver nvlddmkm.sys affecting enterprise AI GPU stacks, IOCTL validation issue enabling local privilege escalation. Patch diff analysis shows fixes across multiple routines introducing pointer slot isolation, object lifecycle validation, and error path cleanup including ExReleaseResourceLite to prevent lock leaks. Exploitation risk in multi-tenant GPU passthrough environments enabling kernel compromise, DoS, and BYOVD relevance via vulnerable driver loading.

WebAssembly Malware Hidden in Open VSX Extensions

Socket Threat Research found GlassWASM malware in trojanised Open VSX extensions using TinyGo WebAssembly payload in exargd/vsblack@0.0.1 and noellee-doc/flint-debug@0.0.1, published via account zaitoona43. The WebAssembly module compiled via TinyGo uses ChaCha20 encrypted strings and executes through Node syscall/js bridge, activating on extension startup via go.run() loader. Malware polls Solana blockchain JSON-RPC getSignaturesForAddress and getTransaction to extract SPL Memo commands, then builds OS-specific child_process download-and-execute payloads targeting dodod[.]lat infrastructure.

Source: Socket

Daily Coverage

Developments
Glasswasm MalwareUnc6508 EspionageCouncil Europe BreachNvidia Kernel Flaw
Vulnerabilities
CVE-2026-20262Cisco Catalyst Sd-Wan Manager 20.1.12 (Medium)CVE-2026-39813Fortisandbox 5.0.0 (Critical)CVE-2026-39808Fortisandbox 4.4.0 (Critical)CVE-2026-25089Fortisandbox 5.0.0 (Critical)CVE-2026-54420Cpanel Plugin 2.3 (High)CVE-2026-48558Simplehelp 5.5.0 (Critical)CVE-2026-24190Geforce All Driver Versions Prior To 595.71.05 (High)
Threat Groups
SILICONSea Turtle is a Türkiyelinked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNSbased intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.Velvet AntVelvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use of zero day exploits.Contagious InterviewContagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and user credentials. Contagious Interview targets Windows, Linux, and macOS systems, with a particular focus on individuals engaged in software development and cryptocurrencyrelated activities.