← Carolina Clear Tech

Cyber Threat Brief

2026-06-08

Listen to this brief (13:44)

Download MP3
Show Notes

Show Notes - 2026-06-08

Stories Covered

CVEs Referenced

CVE-2021-27137, CVE-2026-28318

Indicators of Compromise

Domains: privnote[.]com, -itdesk[.]com, -it[.]com, -helpdesk[.]com.

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

Date: 2026-06-08

Today: SolarWinds Serv-U exploit is live in the wild with CISA adding CVE-2026-28318 to the KEV catalog, giving federal agencies until June 19 to patch. Silent Ransom Group escalated vishing attacks to physical office intrusions, targeting law firms and professional services with data theft within hours. Meta disclosed 20,000 Instagram accounts compromised via AI support tool abuse, with attackers resetting passwords by exploiting email verification failures.

Critical Alerts

SolarWinds Serv-U Vulnerability Exploited in the Wild (CVE-2026-28318)

SolarWinds patched CVE-2026-28318 in Serv-U on Thursday, a denial-of-service flaw that can be exploited without authentication via specially crafted POST requests containing the 'Content-Encoding: deflate' header. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on Friday after detecting active exploitation. The bug has a CVSS score of 7.5 and affects Serv-U versions 15.4.2, 15.5, and 15.5.1, all of which have reached end-of-life. EPSS score is 0.067 (91st percentile).

UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign

Threat actor UNC3753 (also known as Chatty Spider, Luna Moth, and Silent Ransom Group) targeted dozens of organizations in professional, legal, and financial services between January and May 2026 using vishing and physical intrusions. Attackers pose as IT support staff via phone calls following benign invoice-themed emails, convince targets to join screen-sharing sessions on Zoom, Microsoft Teams, or Quick Assist, then install RMM tools like AnyDesk, Bomgar, SuperOps RMM, or Zoho Assist. The FBI warned that the group has escalated to in-person attacks, with threat actors posing as IT technicians to enter corporate offices and exfiltrate data to USB drives. Extortion demands arrive within 30 minutes of attackers leaving the environment, with three-day deadlines and threats to contact clients directly. The group has tactical overlaps with UNC2686 from the defunct Conti ransomware gang.

Business & Infrastructure Threats

Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse

Meta disclosed that 20,225 Instagram accounts were compromised after attackers exploited a bug in the High Touch Support (HTS) AI-powered account recovery tool. The flaw allowed attackers to reset passwords by requesting a password reset link be sent to an email address not associated with the target account. The system failed to verify email ownership and sent reset links to attacker-controlled addresses. Accounts without two-factor authentication enabled were fully hijacked. Meta discovered the exploitation on May 31, 2026, but the first attacks occurred on April 17. Attackers sold high-profile accounts including the Obama White House, Sephora, and US Space Force Chief Master Sergeant John Bentivegna on the dark web. Meta has disabled the HTS tool, invalidated all password reset links, enrolled affected accounts in mandatory security checkpoints, and reset all passwords.

UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency

Proofpoint tracked a likely North Korean threat actor dubbed UNK_DeadDrop that targeted developers in close to 100 organizations across finance, cryptocurrency, education, and technology sectors between April and May 2026. The campaign used developer recruitment or code review lures linking to actor-controlled GitHub repositories hosting malicious scripts. The infection chain abused Visual Studio Code workflows and deployed malicious Visual Studio Extensions (VSIX) masquerading as legitimate Google services. When users opened the repository in VS Code or Cursor, pre-configured tasks executed silently, triggering platform-specific loaders for Linux, macOS, and Windows. Payloads included the open-source Go framework Overlord. The malware exfiltrated browser wallet extensions, decrypted credentials, and desktop wallets, then deleted malicious payloads to clean up forensic artifacts while maintaining persistence via the VSIX extension. Spoofed companies included Ondo Finance (DeFi), Empower Pharmacy, NXLog, and OnePlan.

C0XMO Botnet Spreads via DD-WRT Router Flaw, Kills Rival Malware

A new Gafgyt botnet variant called C0XMO is targeting DD-WRT router firmware via CVE-2021-27137, a buffer overflow vulnerability that can be exploited without authentication. The botnet supports ARM, MIPS, PowerPC, SuperH, x86, x86_64, and other architectures, with exploits for DVRs, routers, video management platforms, and Android devices. C0XMO downloads a Python script that installs packages for SSH, Telnet, and network scanning, then uses worker threads to brute-force weak credentials on ports 22, 23, 80, 443, 7547, 8080, 8443, and 8888. Once access is gained, it copies itself to hidden locations like /tmp/.sys, /var/tmp/.sys, and /dev/shm/.sys, creates cron jobs for relaunch every 15 minutes, and kills competitor botnet clients and red-team tools. The malware supports 19 DDoS methods including UDP/TCP/SYN/ICMP floods, ping of death, NTP/Memcached amplification, Discord voice UDP floods, and Valve-specific floods.

General Security News

RubyGems Adds Dependency Cooldowns to Counter Supply Chain Attacks

RubyGems added support for dependency cooldowns to its Bundler installer, copying similar efforts in the JavaScript and Python ecosystems. Dependency cooldowns tell the package manager to install dependencies only if they are a certain age in days. A cooldown of 7 will only install packages at least a week old, giving security tools, repository admins, and maintainers time to detect compromises and pull down malicious versions. The feature ships disabled by default and requires developers to configure a cooldown for each project. RubyGems joins npm (February 2026), pip (April 2026), uv (December 2025), Deno, Yarn, and Bun in supporting cooldowns. The downside is that security updates are also delayed, so urgent RCE patches may require manually skipping cooldowns for known-safe updates.

VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

Microsoft announced that Visual Studio Code 1.123 will apply a two-hour delay before extensions are automatically updated to newer versions, adding protection against problematic or compromised releases. Users can still update extensions immediately using the Update button. The delay does not apply to extensions from trusted publishers like Microsoft, GitHub, and OpenAI, which will continue to update immediately. The feature is part of a broader industry trend, with RubyGems, npm, pnpm, Yarn, and Bun all adding similar installation controls over the past year.

OpenAI Rolling Out ChatGPT Account Security Controls

OpenAI is expanding availability of two ChatGPT security controls. Lockdown Mode reduces the risk of data exfiltration from prompt injection attacks by limiting outbound network requests, disabling or limiting live web browsing, image support, deep research, agent mode, canvas networking, and file downloads. The feature is intended only for users and organizations handling highly sensitive data. Active Sessions allows users to review where their account is signed in, see sessions and devices, and log out of unrecognized sessions. The feature is available for all ChatGPT accounts except those linked to SSO. This follows the earlier release of Advanced Account Security, which disables password-based login and requires physical security keys or passkeys.

Patch Priority

Trends & Context

Silent Ransom Group's escalation to physical office intrusions marks a significant shift in extortion tactics, combining traditional vishing with in-person data theft. The targeting of legal and professional services firms reflects the group's understanding that these sectors hold concentrated repositories of sensitive client data and face heavy reputational and regulatory exposure. Meanwhile, supply chain defenses are maturing across the development ecosystem, with dependency cooldowns and package update delays now supported in RubyGems, npm, pip, and VS Code, offering a time-based buffer against the self-spreading worms that have compromised hundreds of packages weekly over the past nine months. North Korean threat actors continue to refine developer-targeted campaigns, with UNK_DeadDrop abusing Visual Studio Code workflows and malicious VSIX extensions to steal cryptocurrency wallets and credentials from close to 100 organizations globally.