Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (19 June 2026)
Published: Loading…
At a Glance
- Operation Endgame dismantled SocGholish infrastructure, taking down 106 servers and cleaning nearly 15,000 Evil Corp-linked WordPress sites.
- FortiBleed exposed verified administrator credentials and configuration data for over 73,000 internet-facing Fortinet FortiGate firewalls and VPN gateways.
- The Gentlemen RaaS group maintains GentleKiller, an in-house EDR-killing framework targeting 400-plus security processes across 48 products.
- Nearly 4,000 FIFA World Cup 2026-themed domains and a personalised Voidrift malware campaign are actively harvesting credentials and payments from fans.
- A pre-authentication RCE chain in Oracle PeopleSoft PeopleTools CVE-2026-35273 was exploited against 100-plus organisations in higher education before patching.
- The Mastra npm supply-chain attack compromised 140-plus packages via a dormant maintainer account to deliver a cross-platform wallet-stealing RAT.
Summary
Operation Endgame dealt a significant blow to the SocGholish malware operation linked to the Russian cybercrime group Evil Corp. Law enforcement from the Netherlands, Canada, the United States, and Germany took down 106 servers and domains. Nearly 15,000 compromised WordPress websites used to deliver malware and facilitate ransomware deployments were also cleaned as part of the action.
Over 73,000 internet-facing Fortinet FortiGate firewalls and VPN gateways have had credentials exposed in the FortiBleed data leak. A Russian-speaking cybercriminal group stole the credentials from configuration files before accidentally exposing the dataset on an open server. The UK NCSC separately issued guidance urging organisations to investigate FortiGate devices for indicators of compromise, including unauthorised account creation.
The Gentlemen ransomware-as-a-service group continues to develop and maintain an in-house defensive evasion toolkit called GentleKiller, targeting more than 400 security processes across 48 products. Internal data leaked in May 2026 confirmed Gentlemen centrally manages at least eight EDR-killing variants that abuse vulnerable or malicious drivers. The framework incorporates third-party tools including HexKiller, ThrottleBlood, and HavocKiller alongside the Rust-based OxideHarvest credential stealer.
A pre-authentication remote code execution vulnerability in Oracle PeopleSoft PeopleTools (CVE-2026-35273, CVSS 9.8) was exploited against over 100 higher education organisations before an out-of-band patch was issued on 10 June 2026. The attack chain abuses the PSIGW Integration Broker gateway to trigger XMLDecoder execution inside the WebLogic JVM. Oracle's broader June Critical Patch Update also addressed 245 vulnerabilities across its product families, with Oracle Fusion Middleware receiving the largest share of fixes.
FIFA World Cup 2026 has generated two concurrent threat operations targeting fans and organisations. Cyble identified nearly 4,000 fraudulent domains impersonating ticketing platforms and streaming services since May 2026. A separate Voidrift malware campaign distributed highly personalised phishing emails featuring recipients' names and company branding, successfully bypassing Cisco IronPort, Microsoft ATP, and Abnormal Security gateways.
The Mastra npm ecosystem suffered a supply-chain compromise affecting 140-plus packages after a dormant maintainer account takeover injected a malicious dependency delivering a cross-platform wallet-stealing RAT. Microsoft disclosed an unpatched RoguePlanet elevation of privilege flaw (CVE-2026-50656) in the Microsoft Malware Protection Engine that allows escalation to NT AUTHORITY\SYSTEM from a standard user account. F5 also released out-of-band patches for two critical NGINX vulnerabilities enabling remote unauthenticated code execution, tracked as CVE-2026-42530 with a CVSS v4 score of 9.2.
Highlights of the Day
Operation Endgame Disrupts SocGholish Malware Infrastructure
International law enforcement agencies disrupted the SocGholish malware infection chain during Operation Endgame by taking down 106 servers and domains, remediating 14,971 infected WordPress websites and dismantling the botnet’s infrastructure. Authorities from the Netherlands, Canada, the United States and Germany linked SocGholish, also known as FakeUpdates, to the Russian cybercrime group Evil Corp, which has used compromised WordPress sites since 2017 to deliver malware, gain initial access and deploy ransomware.
FIFA World Cup Scams Drive Phishing and Malware Campaigns
Cyble identified nearly 4,000 FIFA World Cup 2026-themed domains registered since May 2026 that impersonate ticketing platforms, streaming services and official brands, using phishing, VIP scams, counterfeit hospitality portals, Telegram and WhatsApp channels, and alleged football-sector identity leak claims to harvest credentials and payments. Cofense reported a concurrent phishing campaign distributing Voidrift malware through personalised emails featuring recipients' names, company branding and fake FIFA merchandise offers, with messages bypassing Cisco IronPort, Microsoft ATP and Abnormal Security while hosting the malware on a legitimate domain.
Gentlemen Builds In-House Framework to Disable Security Software
ESET analysed the ransomware-as-a-service group Gentlemen and found it develops and maintains an affiliate-ready EDR-killing framework called GentleKiller with at least eight variants that abuse vulnerable or malicious drivers, alongside integrated third-party tools including HexKiller, ThrottleBlood and HavocKiller. Internal data leaked in May 2026 confirmed the group centrally manages these defence-evasion tools, rapidly incorporates newly disclosed Bring Your Own Vulnerable Driver proofs of concept, impersonates security vendors using fake version information and copied certificates, and also deploys the Rust-based OxideHarvest credential stealer through an affiliate.
NCSC Warns of Global Attacks Targeting Fortinet VPN Devices
The UK National Cyber Security Centre warned that threat actors have targeted internet-facing Fortinet firewalls and SSL VPN gateways worldwide using brute-force, dictionary and credential stuffing attacks, followed by the leak of a database containing compromised credentials. The agency said organisations should investigate affected FortiGate devices for indicators of compromise, including unauthorised account creation and suspicious log activity, after reports of potential impact in the United Kingdom.
FlutterShell macOS Malware Uses Flutter Framework for C2 Control
Security researchers analysed FlutterShell macOS malware linked to Operation FlutterBridge CL-CRI-1089, using Flutter framework binaries and ten Mach-O samples across generations. The analysis found C2-conditional execution via WKWebView, Dart AOT obfuscation, and generation-based symbol rotation, with no malicious behaviour in sandbox environments without live C2 response. Gen 1 to Gen 3 variants included Chrome Secure Preferences modification for search hijacking, Sparkle update mechanism abuse, and ioreg-based hardware UUID fingerprinting techniques.
PeopleSoft PSIGW SSRF Chain Enables Pre-Auth JVM RCE
A pre-authentication RCE in Oracle PeopleSoft PeopleTools (CVE-2026-35273) uses PSIGW SSRF to reach PSEMHUB and triggers XMLDecoder execution in the WebLogic JVM on versions 8.61 and 8.62. Oracle issued CVE-2026-35273 (CVSS 9.8) with an out-of-band patch on 10 June 2026 following exploitation linked to SHADOW-AETHER-015 (ShinyHunters) from 27 May to 9 June 2026 affecting over 100 organisations in higher education. The final execution occurs in-process during a web-tier restart with no child processes or outbound beacons.
Popa Botnet Linked to Residential Proxy Firm NetNut
The Popa Android botnet has infected millions of TV boxes, routing traffic for advertising fraud, scraping and account takeover operations via residential proxy networks. Researchers linked Popa infrastructure to NetNut, operated by Alarum Technologies, citing domains used to control devices across large-scale distributed proxy operations. The botnet is associated with Vo1d malware on Android streaming devices, reportedly handling over one million daily IP addresses through proxy relays.
Daily Coverage