Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (18 June 2026)
Published: Loading…
At a Glance
- A supply chain attack compromised 144 @mastra npm packages via a malicious easy-day-js dependency, enabling credential theft and persistence across Windows, macOS and Linux.
- The FortiBleed campaign extracted credentials from 30,000–75,000 FortiGate firewalls across 194 countries, exposing administrator accounts at major multinationals.
- Microsoft confirmed CVE-2026-50656, the RoguePlanet Defender zero-day enabling SYSTEM-level privilege escalation from a standard user account with no user interaction.
- Fifteen malicious JetBrains Marketplace plugins masquerading as AI assistants exfiltrated OpenAI and DeepSeek API keys, amassing nearly 70,000 installations.
- The Rokarolla Android trojan targets 217 banking and cryptocurrency applications and can execute 137 commands, enabling full device takeover and credential theft.
Summary
A coordinated supply chain attack compromised 144 packages in the @mastra npm organisation on 17 June 2026 via a malicious easy-day-js dependency injected across the scope. The postinstall dropper disabled TLS certificate validation, fetched and launched a second-stage payload, then deleted itself to hinder forensic recovery. The attack enables credential theft, cryptocurrency wallet compromise, and persistent access across Windows, macOS, and Linux environments.
The FortiBleed campaign has exposed administrator credentials for between 30,000 and 75,000 FortiGate firewalls across 194 countries. Compromised accounts include those at FoxConn, Samsung, Siemens, and Comcast, with full network access possible in confirmed cases. The leak is linked to legacy SHA-256 password hashes persisting in upgraded FortiOS deployments that have not triggered PBKDF2 migration.
Microsoft has confirmed CVE-2026-50656, a privilege escalation zero-day in Microsoft Defender known as RoguePlanet, and is developing a patch. The flaw exploits NTFS reparse points and opportunistic locks to achieve SYSTEM-level execution from a standard user account without kernel exploitation. A separate GreatXML proof-of-concept targeting BitLocker recovery workflows was also disclosed by the same researcher group.
Fifteen malicious JetBrains Marketplace plugins posed as AI coding assistants and exfiltrated API keys for OpenAI, DeepSeek, and other providers to an attacker-controlled server over plain HTTP. A separate ClickFix malvertising campaign impersonating AI tools later abused claude.ai shared chat as a trusted delivery domain, deploying the MacSync infostealer targeting credentials, SSH keys, and cryptocurrency wallets. A low-skilled attacker also used Claude Code and OpenAI Codex agents to breach 14 companies, demonstrating reduced skill requirements for AI-assisted intrusions.
INC ransomware has surpassed 800 victims since 2023, with Windows and Linux/ESXi variants rewritten in Rust and tooling expanded to include a modified Veeam credential dumper. A 24-billion-record credential database was also briefly exposed online, sourced from Telegram channels, breach compilations, and infostealer logs.
Highlights of the Day
RoguePlanet Abuses Microsoft Defender to Gain SYSTEM Access
LevelBlue SpiderLabs analysed RoguePlanet, a proof-of-concept published after Microsoft's June 2026 Patch Tuesday that abuses Microsoft Defender, NTFS reparse points, opportunistic locks and Windows Error Reporting to achieve SYSTEM-level execution from a standard user account without kernel exploitation or memory corruption. The researchers also examined GreatXML, a separate proof-of-concept targeting the Windows Recovery Environment and BitLocker recovery workflow that allows attackers with existing administrative access to modify recovery partition contents and maintain access to protected data, alongside forensic artefacts and EDR detection opportunities for both techniques.
Mastra npm Attack Trojanises 144 Packages
Attackers compromised the @mastra npm organisation on 17 June 2026, republishing more than 140 packages during an automated campaign after publishing a clean easy-day-js@1.11.21 one day earlier and weaponising version 1.11.22 minutes before the attack, causing npm install to resolve the malicious dependency automatically. The easy-day-js postinstall script disabled TLS certificate validation, downloaded and launched a second-stage payload as a detached process before deleting itself, enabling credential theft, cryptocurrency wallet compromise, host reconnaissance and persistence across Windows, macOS and Linux systems that installed the affected packages.
Malicious JetBrains Plugins Stole AI API Keys
Aikido Security identified at least 15 malicious JetBrains Marketplace plugins published under seven vendor accounts that masqueraded as AI coding assistants and exfiltrated OpenAI, DeepSeek and other AI provider API keys to a hardcoded server at 39[.]107[.]60[.]51 over plain HTTP, with nearly 70,000 reported installations. The plugins, first published in October 2025 and still appearing in June 2026, transmitted API keys immediately when users saved them in the settings panel and also supported a paid mode in which the attacker-controlled server returned replacement API keys for subsequent model requests.
INC Ransomware Evolves with Rust-Based Cross-Platform Tooling
INC ransomware evolved from a 2023 RaaS operation into one of 2026’s most active groups, reporting over 800 victims and expanding after LockBit and BlackCat disruptions. Windows and Linux/ESXi variants were rewritten in Rust, while tooling includes a modified Veeam credential dumper supporting salted DPAPI decryption and credential extraction improvements. Initial access relies on phishing, stolen credentials and exploitation of edge vulnerabilities, with lateral movement via RDP and PsExec and exfiltration using rclone and 7-Zip.
ClickFix Malvertising Campaign Abuses Claude.ai Shared Chat
Trend Micro tracked a ClickFix malvertising campaign using Google Ads, impersonating AI tools and rotating 106 malicious hostnames across six waves over seven weeks. It later pivoted to abusing claude.ai shared chat features, using trusted domains and impacting mainly Asia-Pacific traffic, led by Taiwan concentration. It delivered MacSync infostealer via base64 encoded curl commands leading to a loader script that steals credentials, SSH keys and cryptocurrency wallets.
FortiBleed Campaign Exposes Fortinet Firewalls Across 194 Countries
Researchers identified FortiBleed campaign targeting Fortinet FortiGate firewalls, extracting configuration files from internet-facing devices across 194 countries and cracking stored credential hashes. Analysis indicates between 30,000 and 75,000 devices impacted, with datasets containing validated administrator credentials organised by organisation, sector, and revenue classification from multiple sources. Compromise is linked to legacy SHA-256 password storage in upgraded FortiOS deployments, where older hashes persist until administrators log in and trigger PBKDF2 migration.
Daily Coverage