Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (27 June 2026)
Published: Loading…
At a Glance
- Operation Endgame disrupted 66 domains and 296 StealC and Amadey servers, seizing 25.6 million stolen credentials from over 385,000 compromised systems.
- The Miasma Mini Shai-Hulud supply chain worm compromised ImmobiliareLabs Backstage npm packages, targeting developer credentials and CI/CD secrets via install-time execution.
- CISA added CVE-2026-12569 in PTC Windchill and CVE-2026-20230 in Cisco Unified Communications Manager to its Known Exploited Vulnerabilities catalog.
- CVE-2026-12957 in Amazon Q Developer allowed malicious Git repositories to execute code and steal AWS credentials without user consent.
- Russian APT Turla deployed a new .NET backdoor called STOCKSTAY against government and military targets in Ukraine.
- FBI and CISA warned that Russian intelligence actors targeting Signal users now steal Backup Recovery Keys to access historical messages.
Summary
Operation Endgame, coordinated by Europol with support from Proofpoint and IBM X-Force, dismantled 66 domains and 296 servers tied to the StealC and Amadey malware-as-a-service ecosystems. More than 25.6 million unique credentials stolen from over 385,000 compromised systems were seized during the operation. StealC infrastructure had also delivered secondary payloads including AsyncRAT, RedLine Stealer, SmokeLoader, and LockBit Black ransomware.
The Miasma Mini Shai-Hulud supply chain campaign expanded to compromise legitimate npm packages under the @immobiliarelabs scope, including Backstage GitLab and LDAP authentication plugins. Malicious versions used install-time execution via a Phantom Gyp hook, decrypted staged JavaScript payloads, and exfiltrated developer and CI/CD secrets through attacker-controlled GitHub repositories. Earlier waves of the same campaign had poisoned LeoPlatform and RStreams packages and abused GitHub Actions workflows in a fully automated operation completed in under three seconds.
CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-12569, an improper input validation flaw in PTC Windchill PDMLink and FlexPLM, and CVE-2026-20230, a server-side request forgery flaw in Cisco Unified Communications Manager. Federal agencies are required to prioritise remediation under Binding Operational Directive 26-04. Separately, Synology patched three critical vulnerabilities in MailPlus Server, including flaws enabling arbitrary file read and write and access to internal services.
CVE-2026-12957 in the Amazon Q Developer Visual Studio Code extension allowed malicious repositories to automatically load MCP server configurations and execute arbitrary code, exposing AWS credentials and other secrets stored in the developer environment. Amazon patched the flaw in version 1.65.0 by requiring explicit user consent for workspace MCP servers. A related phishing campaign targeting hotel and hospitality organizations in Europe and Asia used photo-themed ZIP files to drop a Node.js implant on front-desk machines.
Russian cyber-espionage group Turla deployed a new .NET backdoor named STOCKSTAY against government and military organizations in Ukraine and entities with interests in Italian foreign policy. In a separate Russian operation, the FBI and CISA warned that actors targeting Signal users now steal Backup Recovery Keys, enabling full account takeover and access to historical message archives. Russian authorities were also found to have used Cellebrite UFED forensic tools on a detained opposition activist's iPhone three months after Cellebrite announced it had stopped selling to Russia.
The SharkLoader dropper, deployed in a campaign tracked as StrikeShark, was used against government organizations and software development companies across multiple countries, delivering Cobalt Strike Beacon on compromised hosts. The Mirage2FA phishing kit combined HTML smuggling with obfuscated JavaScript loaders to present fake Microsoft 365 sign-in and MFA prompt pages, targeting credentials via business-themed lures. A Polish-led international operation, coordinated with the FBI and HSI, arrested four suspected members of a SIM-swapping gang responsible for cryptocurrency theft and money laundering.
Highlights of the Day
Miasma Campaign Compromises ImmobiliareLabs Backstage npm Packages
Socket Threat Research reported that the Miasma Mini Shai-Hulud supply chain campaign compromised multiple legitimate @immobiliarelabs Backstage GitLab and LDAP authentication npm packages published on 26 June 2026, with malicious versions republished across several historical release branches. The malicious packages use a Phantom Gyp install-time execution technique, decrypt staged JavaScript payloads, install Bun to run additional malware, steal developer and CI/CD credentials, abuse GitHub Actions for propagation, and exfiltrate secrets through attacker-controlled GitHub repositories. Socket also identified a possible link to the earlier compromise of the codfish/semantic-release-action GitHub Action, although it said this remains an unconfirmed lead pending further investigation.
Amazon Q Flaw Allowed Malicious Repositories to Execute Code
Wiz disclosed CVE-2026-12957, a high-severity vulnerability in the Amazon Q Developer extension for Visual Studio Code that automatically loaded Model Context Protocol (MCP) server configurations from workspace files, allowing arbitrary code execution when a developer opened a malicious repository and activated Amazon Q. Affected language server versions earlier than 1.65.0 inherited the user's full environment, exposing AWS credentials, API keys and other secrets to attacker-controlled processes, and Amazon fixed the issue in version 1.65.0 by introducing a consent prompt for workspace MCP servers.
CISA Adds Windchill and Cisco Flaws to KEV Catalogue
CISA added CVE-2026-12569, an improper input validation vulnerability affecting PTC Windchill and FlexPLM, and CVE-2026-20230, a server-side request forgery vulnerability in Cisco Unified Communications Manager, to its Known Exploited Vulnerabilities Catalogue after confirming active exploitation. The agency said the vulnerabilities are being used by threat actors, requiring Federal Civilian Executive Branch agencies to prioritise remediation under Binding Operational Directive 26-04 for publicly exposed systems that could be fully compromised after exploitation.
Mirage2FA Phishing Kit Abuses HTML Smuggling for Microsoft 365 MFA Theft
Fortra identified Mirage2FA, a multi-stage Microsoft 365 phishing kit delivered via HTML smuggling and obfuscated JavaScript loaders that decode payloads in the browser using Base64, XOR, TextDecoder and eval(), retrieving second-stage scripts from attacker-controlled infrastructure at cheacker[.]store. The kit presents a Microsoft-branded sign-in flow with fake CAPTCHA and credential capture pages, alongside MFA-themed prompts including authenticator app codes, SMS codes and number-matching approval screens intended for account takeover. The infrastructure includes newly registered domains such as user.cheacker[.]store resolving to 185[.]174[.]100[.]224 and loads additional phishing assets from miniapp.bereetro[.]it.com.
GitHub Actions Misconfigurations Expose Supply Chain Risks
Kaspersky GReAT analysed GitHub Actions configurations across around 30,000 repositories and 130,000 pipelines, finding over 250,000 deviations from secure CI/CD guidance. Slightly more detail 0.4% of deviations were high risk, with eight repositories showing conditions potentially enabling supply chain compromise across diverse software projects. Common issues included overly broad permissions, missing version pinning, workflow-level configuration settings, secret exposure, and insecure external data handling in GitHub Actions pipelines.
Operation Endgame Disrupts StealC Infostealer Infrastructure
Proofpoint and IBM X-Force supported Europol’s Operation Endgame against the StealC malware-as-a-service ecosystem, leading to the disruption of 66 domains and 296 servers linked to StealC and Amadey and the seizure of over 25.6 million stolen credentials from more than 385,000 compromised systems. Researchers analysed StealC command-and-control configurations and built emulation tooling to map affiliate operations, payload delivery chains and infrastructure relationships, while also identifying a vulnerability in StealC’s PHP-based C2 panel that enabled law enforcement-assisted server access and takedown actions. The campaign infrastructure delivered a range of secondary payloads including AsyncRAT, RedLine Stealer, SmokeLoader and LockBit Black ransomware, often via multi-stage loader chains initiated by StealC infections.
Daily Coverage