Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (22 June 2026)
Published: Loading…
At a Glance
- AryStinger botnet compromised over 4,300 D-Link and Linksys routers via CVE-2013-3307 and CVE-2016-5681 for proxy-based attacks.
- North Korean Sapphire Sleet compromised a Mastra npm maintainer account, introducing malicious postinstall hooks across 140 packages.
- Gravity SMTP WordPress plugin CVE-2026-4020 exposed API keys and OAuth tokens, with attackers issuing over 17 million exploitation requests.
- Prinz Eugen ransomware, written in Go, gains access via stolen RDP credentials and encrypts recent files without leaving ransom notes.
- Cryptographic boot keys securing Windows and Linux systems are set to expire on June 24, affecting secure boot sequences.
Summary
Sapphire Sleet, a North Korean state-linked threat actor also known as BlueNoroff, compromised a Mastra npm maintainer account to inject malicious code into over 140 packages. The attack introduced an easy-day-js dependency with a postinstall hook that disabled TLS verification and contacted command-and-control infrastructure. Systems running affected packages in CI/CD pipelines were exposed to credential theft and build compromise.
The Gravity SMTP WordPress plugin was actively exploited via CVE-2026-4020, an unauthenticated information disclosure flaw affecting versions up to 2.1.4. Attackers targeted a REST endpoint returning system configuration data, API keys, OAuth tokens, and email service credentials. Over 17 million exploitation requests were blocked across the peak attack window of June 7–11, 2026.
Prinz Eugen ransomware gained initial access through stolen RDP credentials before deploying a Go-based encryptor using ChaCha20-Poly1305. The malware prioritises recently modified files and leaves no ransom note, with operators conducting out-of-band extortion directly. RemotePC remote management software was used to maintain persistence during hands-on-keyboard intrusion activity.
The AryStinger botnet has compromised more than 4,300 legacy D-Link and Linksys routers by exploiting CVE-2013-3307 and CVE-2016-5681. Infected devices receive commands over HTTP/HTTPS using Protobuf encoding and XOR encryption, supporting tunnelling, scanning, and remote execution. The botnet deploys dropbear backdoors and uses compromised routers as proxies for distributed reconnaissance and lateral movement.
Cryptographic boot keys securing the startup sequences of Windows and Linux systems are scheduled to expire on June 24. The expiry affects the secure boot chain across a broad range of consumer and enterprise devices.
Highlights of the Day
Gravity SMTP Flaw Exposes WordPress API Credentials at Scale
WordPress Gravity SMTP plugin contained a sensitive information exposure flaw allowing unauthenticated access to REST endpoint leaking system configuration and API credentials across email integrations. Wordfence reported exploitation of the Gravity SMTP vulnerability affecting versions up to 2.1.4, with attackers issuing over 17 million requests blocked by firewall rules. Attack activity peaked between June 7 and 11 2026 targeting /wp-json/gravitysmtp/v1/tests/mock-data endpoint returning system reports including PHP, WordPress, plugins and email service credentials.
npm Supply Chain Attack Hits Mastra Packages via Compromised Account
Microsoft observed a large npm supply chain attack affecting 140 Mastra and @mastra scoped packages after compromise of maintainer account ehindero introducing easy-day-js dependency. easy-day-js used postinstall hook executing obfuscated dropper disabling TLS verification, contacting command-and-control infrastructure, downloading second-stage payload executed as detached Node.js process. Install or update in CI/CD environments exposed systems to credential theft and build compromise, attributed to Sapphire Sleet North Korean state actor targeting financial sector.
Prinz Eugen Ransomware Prioritises Recent Files, Drops No Notes
ThreatDown reported Prinz Eugen ransomware gaining access via stolen RDP credentials, deploying servertool.exe with RemotePC RMM and manually executed payloads in intrusions. The Go-based encryptor prioritises recently modified files for encryption, uses ChaCha20-Poly1305, and leaves no ransom note while recursively processing directories. Investigators also observed hands-on-keyboard activity using RemotePC for persistence and out-of-band extortion without local ransom notes across affected environments.
AryStinger Botnet Compromises 4,300 Legacy Routers for Proxy Attacks
QiAnXin XLab reported AryStinger botnet compromising legacy RTL819X routers via CVE-2013-3307 and CVE-2016-5681, affecting over 4,300 D-Link and Linksys devices. Malware communicates over HTTP/HTTPS using Protobuf encoding and XOR encryption, supporting authentication, heartbeat, scanning tasks, tunnelling, and remote command execution via executor model. Infected devices deploy dropbear backdoors and execute distributed reconnaissance tasks including port scanning, DNS enumeration, and service identification, enabling lateral movement and proxy-based attacks.
Daily Coverage