← Carolina Clear Tech

Cyber Threat Brief

2026-06-09

Listen to this brief (30:00)

Download MP3
Show Notes

Show Notes - 2026-06-09

Stories Covered

CVEs Referenced

CVE-2024-39930, CVE-2024-39932, CVE-2024-39933, CVE-2025-48595, CVE-2025-8110, CVE-2026-10879, CVE-2026-11463, CVE-2026-11645, CVE-2026-23111, CVE-2026-2441, CVE-2026-26194, CVE-2026-35429, CVE-2026-3909, CVE-2026-3910, CVE-2026-40930, CVE-2026-42208, CVE-2026-42271, CVE-2026-45321, CVE-2026-46250, CVE-2026-46272, CVE-2026-48027, CVE-2026-48710, CVE-2026-49975, CVE-2026-50031, CVE-2026-50256, CVE-2026-50260, CVE-2026-50262, CVE-2026-50292, CVE-2026-50751, CVE-2026-50752, CVE-2026-5281

Indicators of Compromise

Domains: ep6pheij[.]com, business-data-leaks[.]com., business-data-leaks[.]com, grupoconstat[.]bitrix24, com[.]br, ikhwancast[.]com, ghazacast[.]com, fr24cast[.]com., fr24cast[.]com

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

June 9, 2026

Today: Check Point VPN users have three days to patch CVE-2026-50751, a critical zero-day exploited by Qilin ransomware affiliates since early May. Google patched its fifth Chrome zero-day of the year. The TeamPCP supply chain worm continues spreading through npm and PyPI with new Hades-themed variants, while a critical Gogs RCE affects default-configured instances worldwide. LiteLLM deployments face unauthenticated remote code execution when chained with a Starlette vulnerability, and Linux admins need to patch a one-character kernel flaw that grants local root access with public exploits available.

Critical Alerts

Check Point VPN Zero-Day Exploited by Qilin Ransomware (CVE-2026-50751)

Check Point disclosed CVE-2026-50751, a critical authentication bypass (CVSS 9.3) affecting Remote Access VPN and Mobile Access deployments configured with the deprecated IKEv1 key exchange protocol. Unauthenticated remote attackers can bypass authentication and establish VPN connections without valid passwords by exploiting a logic flaw in certificate validation. Attacks began May 7, surged in early June, and have hit a few dozen organizations globally. Check Point confirmed at least one breach linked to a Qilin ransomware affiliate, with evidence suggesting the threat actor is also exploiting VPN vulnerabilities in Palo Alto, Fortinet, and F5 products. CISA added the flaw to its KEV catalog on June 8, ordering federal agencies to patch by June 11. The vulnerability affects Security Gateways R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS), R80.40 (EOS), and Spark Firewalls R80.20.X (EOS), R81.10.X, R82.00.X. While investigating CVE-2026-50751, Check Point found CVE-2026-50752 (CVSS 7.4), a second IKEv1 certificate validation flaw enabling man-in-the-middle attacks on site-to-site VPN connections, with no evidence of exploitation yet.

Gogs RCE Zero-Day Affects Default Configurations

Gogs patched a critical argument injection vulnerability enabling remote code execution on all releases up to 0.14.2 and 0.15.0+dev. Authenticated attackers without admin privileges can compromise servers, read any repository including private repos, steal credentials, move laterally, and alter source code. The vulnerability affects all Gogs servers with default configurations because Gogs ships with open registration enabled (DISABLE_REGISTRATION = false) and no repository creation limit (MAX_CREATION_LIMIT = -1), allowing unauthenticated attackers to simply create an account and repository. Once a user owns a repo, enabling rebase merging is a single toggle, and the entire exploit chain operates without interaction from other users. Rapid7 disclosed the flaw June 8 after multiple status updates went unanswered, and Gogs maintainers released version 0.14.3 on June 7. Shadowserver tracks over 2,300 Internet-exposed Gogs servers, most in Asia (1,839) and Europe (312). This flaw is similar to CVE-2024-39933, CVE-2024-39932, CVE-2026-26194, and CVE-2024-39930, but affects a different code path (Merge()) that was never addressed. In December 2026, Gogs patched CVE-2025-8110, an RCE exploited in zero-day attacks to compromise hundreds of servers, which CISA added to its KEV catalog in January with a February 2 remediation deadline.

Google Patches Fifth Chrome Zero-Day of 2026 (CVE-2026-11645)

Google patched CVE-2026-11645, a high-severity out-of-bounds read and write weakness in the Chrome V8 JavaScript engine exploited in the wild. This is the fifth Chrome zero-day fixed since the start of the year. Remote attackers can exploit the flaw via crafted HTML pages to execute arbitrary code inside the browser sandbox, access data beyond memory buffers via heap corruption, or bypass ASLR protections. Google released patched versions for Windows (149.0.7827.102), Mac (149.0.7827.103), and Linux (149.0.7827.102) two weeks after an anonymous researcher reported the flaw. Google has not shared details about the exploitation incidents. The four other Chrome zero-days patched in 2026 were CVE-2026-2441 (CSSFontFeatureValuesMap iterator invalidation), CVE-2026-3909 (Skia out-of-bounds write), CVE-2026-3910 (V8 inappropriate implementation), and CVE-2026-5281 (Dawn use-after-free). Last year Google fixed eight zero-days exploited in the wild, many reported by Google's Threat Analysis Group tracking spyware attacks.

LiteLLM RCE Exploited in the Wild (CVE-2026-42271)

CISA added CVE-2026-42271 to its KEV catalog on June 8, a high-severity command injection vulnerability (CVSS 8.7) in BerriAI LiteLLM that allows authenticated users to run arbitrary commands on the host. The flaw affects LiteLLM versions 1.74.2 through 1.83.6. Two endpoints used to preview an MCP server before saving it (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) accepted full server configurations including command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints spawned the supplied command as a subprocess with proxy process privileges. The endpoints were secured only by a valid proxy API key, so any authenticated user including privileged internal-user keys could execute arbitrary commands. Horizon3.ai chained CVE-2026-42271 with CVE-2026-48710 (CVSS 6.5), a "BadHost" host header validation bypass in Starlette ASGI framework affecting versions 1.0.0 and earlier, to bypass authentication entirely and achieve unauthenticated remote code execution. The chained vulnerability has a combined CVSS score of 10.0. Successful exploitation allows attackers to run arbitrary commands on the LiteLLM host, access model provider credentials, siphon API keys and secrets, move laterally into connected AI infrastructure, and compromise downstream systems. CISA ordered federal agencies to remediate by June 22. In April, a critical SQL injection flaw in LiteLLM (CVE-2026-42208, CVSS 9.3) was exploited within 36 hours of becoming public.

TeamPCP Supply Chain Campaign Continues with Hades PyPI Variant

SANS Internet Storm Center reported that the TeamPCP supply chain campaign reached two new developments. First, CISA added CVE-2026-45321 (TanStack/Mini Shai-Hulud) and CVE-2026-48027 (Nx Console v18.95.0 malicious code) to its KEV catalog on May 27 with a June 10 remediation deadline, resolving the multi-week federal silence on the campaign. CISA issued its first standalone advisory on May 28 documenting the poisoned Nx Console VS Code extension, the exfiltration of approximately 3,800 GitHub-internal repositories, and a separate "Megalodon" campaign injecting malicious GitHub Actions workflows to harvest CI/CD secrets and cloud credentials. Second, the leaked Mini Shai-Hulud framework produced its first major wave targeting @redhat-cloud-services npm packages. Beginning June 1, the Miasma worm compromised at least 32 packages across roughly 90 or more versions with cumulative weekly downloads of about 80,000. The attacker used a compromised Red Hat employee GitHub account. A "Hades" campaign hit PyPI with Mini Shai-Hulud, compromising 37 malicious PyPI wheels across 19 packages. Socket identified the tradecraft as unmistakably Shai-Hulud/Miasma based on the cross-runtime design: the attack chain installs Bun (a JavaScript runtime) as a heavily obfuscated JavaScript stealer before executing the payload, even on npm where Node.js would be the expected runtime. The PyPI wave abuses Python .pth startup behavior to launch the Bun-powered credential stealer targeting developer, cloud, package-publishing, and CI/CD secrets. New features include Hades-themed GitHub exfiltration markers (repository description "Hades - The End for the Damned") and component names (stygian, tartarean, cerberus, charon, styx, lethe, thanatos, persephone). The campaign demonstrates adaptability across ecosystems, using .pth startup files as a distinct execution mechanism compared to the npm lifecycle script abuse seen previously.

Ransomware & Extortion

Silent Ransom Group Uses DNS Fast Flux in Attacks

The Silent Ransom Group (SRG), also tracked as Chatty Spider, Luna Moth, and UNC3753, is using a fast flux network of infected devices to hide its infrastructure, according to Resecurity. SRG uses voice phishing (vishing) and social engineering to gain remote access to victims' environments. The group typically sends phishing emails themed around data migration or invoices, encouraging recipients to engage in phone conversations with operatives posing as IT specialists who convince victims to host screen-sharing sessions and install remote access software. SRG is known for targeting law firms in the US and for sending operatives in person to insert USB drives into victims' computers for data exfiltration or malware deployment, according to a recent FBI alert. The group also targets finance, healthcare, insurance, and hospitality firms. After gaining access, SRG focuses on lateral movement and data exfiltration without deploying file-encrypting malware. Shortly after data exfiltration, often within 30 minutes, the threat actor sends extortion emails threatening to publish stolen data on its clear web data leak site. If unresponsive, the group contacts employees and partners to increase pressure. SRG's fast flux network uses infected routers, modems, gateways, and other IoT/CPE devices. The technique rapidly changes DNS records of a legitimate domain, rotating numerous IP addresses and DNS name servers to hide server locations. Resecurity identified SRG fast flux nodes in 18 countries across Latin America, Eastern Europe, Central Asia, the Middle East, Africa, East Asia, and the Caribbean, spread across 22 ISPs. The botnet rotates DNS records for ep6pheij[.]com and business-data-leaks[.]com. Law firms accounted for almost a quarter of all ransomware-related incidents tracked in Q1 2026, making it the fourth-most targeted industry. Google reported SRG has been active since at least 2022, with activities overlapping UNC2686, known for BazarCall campaigns and the use of TrickBot, Ursnif, and BazarLoader malware.

Ransomware Closes Illinois High Schools

A ransomware attack forced Evanston Township High School to close, canceling summer school, sports camps, and on-campus activities. The incident is part of a growing trend of ransomware targeting educational institutions, particularly during the summer when IT staffing is often reduced and schools are planning for the fall semester.

Qilin NHS Breach Tally Grows

Two years after the Qilin ransomware attack on Synnovis pathology services, Essex trust confirmed stolen patient records, adding to the growing tally of NHS organizations impacted by the breach. The incident demonstrates the long tail of ransomware impacts, with victim organizations still working to identify and warn affected patients years after the initial compromise.

Business & Infrastructure Threats

Microsoft Teams Phishing Campaigns Bypass Email Defenses

Unit 42 reported a 42% increase in phishing alerts from collaboration tools in the first four months of 2026, up from 30% in the preceding four months. Threat actors are moving away from traditional email phishing toward trusted collaboration tools like Microsoft Teams. Cloaked Ursa (APT29, Cozy Bear, Midnight Blizzard) successfully operationalized this approach in late 2024, leveraging compromised accounts to send Teams messages containing malicious links redirecting to credential harvesting pages mimicking legitimate Microsoft login portals. In December 2025, UNC6692 used Teams to impersonate IT helpdesk staff, convincing employees to accept Teams chat invitations from accounts outside their organization. Threat actors initiate chats with employees using typosquatted domains that closely resemble trusted vendors or internal naming conventions, sometimes operating from Microsoft 365 tenants deliberately named to mimic IT support functions, security teams, or managed service providers. Teams federation is enabled by default in many organizations, allowing users to communicate with external tenants unless restricted by policy. In advanced scenarios, threat actors bypass deception by compromising legitimate service provider or partner accounts and leveraging existing trust relationships to initiate chats from recognized and allowed domains. While Teams provides visual indicators that a sender is external and has an impersonation protection feature, users may overlook warnings when the sender appears to represent a known vendor, partner, or internal support function.

AI Brands Used as Social Engineering Lures

Microsoft Threat Intelligence observed a growing number of campaigns impersonating the branding of popular AI platforms (ChatGPT, Microsoft Copilot, DeepSeek, Anthropic's Claude) as lures in phishing, malvertising, and SEO-driven attacks leading to credential theft, financial fraud, or malware infection. While traditional lures like invoices, payment notifications, or delivery alerts remain effective, AI-themed lures reflect a shift in social engineering likely to persist as a long-term tactic from cybercriminal groups to nation states. Storm-3075 employed AI-themed malvertising to deliver payloads, including malware signed by the malware-signing-as-a-service (MSaaS) offering attributed to Fox Tempest, on behalf of multiple downstream actors. On May 5, Microsoft detected a ChatGPT-themed phishing attack delivering malicious URLs leading to phishing pages collecting credit card and personal information. The campaign sent 4,500 emails to targets in South Africa (97%), and delivered as much as 100,000 emails on a single day to targets in Switzerland, Austria, and South Africa affecting higher education and professional services. The emails used sender display name "ChatGPT" with subject "To ensure your ChatGPT Plus continues to work - please update your payment method," posing as urgent requests to update subscription payment methods with warnings of account downgrades within seven days. Targets were redirected through legitimate and abused redirector hops including grupoconstat[.]bitrix24[.]com[.]br (a legitimate CRM service) to exploit trusted domain reputations, bypass email filters, evade detection, and track victim engagement.

NSO Group Spyware Campaigns Defy Court Injunction

Meta detected and disrupted spear-phishing campaigns allegedly conducted by NSO Group after investigating user reports of social engineering attacks, despite a 2025 permanent injunction barring NSO from targeting WhatsApp users. NSO Group is an Israeli commercial spyware vendor known for its Pegasus tool deployed against politicians, activists, journalists, and academics. NSO has been on the U.S. sanctioned entities list since November 2021. Meta secured a permanent injunction against NSO in 2025, a declaration of liability for 1,400 infections, and an associated $167 million fine. The attacker attempted to lure targets into clicking malicious links redirecting to external websites, resembling previously documented one-click phishing campaigns associated with NSO. Meta caught NSO creating test accounts and groups on WhatsApp, which were taken down. IOCs include ikhwancast[.]com, ghazacast[.]com, and fr24cast[.]com. Meta filed a contempt-of-court complaint and argues the activity violates the 2025 court order. Meta noted that end-to-end encryption effectively protects users' messages and calls from Pegasus and other spyware, but urged users to update apps and operating systems for optimal protection. Android users can activate "Advanced Protection" and iOS users can enable "Lockdown Mode" to reduce attack surface and data exposure to spyware.

Patch Priority

Vulnerability Disclosures

Linux Kernel One-Character Flaw Enables Local Root (CVE-2026-23111)

Security researchers published detailed working exploits for CVE-2026-23111, a Linux kernel use-after-free that lets unprivileged local users escalate to root and break out of containers. The flaw sits in the kernel's nf_tables packet-filtering code and was patched upstream February 5. Exodus Intelligence released its full technical walkthrough June 8, and FuzzingLabs published an independent reproduction in April. The flaw came down to a single stray character, an inverted check in nf_tables, and the upstream fix removed it in one line. Ubuntu rates the flaw CVSS 7.8 (high). The reachable setup is common: nf_tables plus unprivileged user namespaces, both shipping by default on most desktops and many server builds. There is no remote vector. This is a bug attackers reach for after getting a foothold, turning a low-privileged shell, compromised container, or service account into root on the host. Exodus researcher Oliver Sieber chained it into full local root, demonstrating on Debian Bookworm, Debian Trixie, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. FuzzingLabs reproduced the bug on RHEL 10 ahead of Pwn2Own Berlin 2026, building its own root exploit by a different route. CVE-2026-23111 lands in the middle of a heavy run of Linux local-root disclosures including Copy Fail, the Dirty Frag chain, its Fragnesia variant, DirtyDecrypt, and a nine-year-old ptrace flaw that reads /etc/shadow and runs commands as root. Synacktiv links the LPE surge pace to AI-assisted research and patch-diffing that put working exploits out before fixes spread, and makes the case that ordinary hardening still buys defenders time by cutting off what unprivileged users can reach. There are no public reports of exploitation in the wild.

Android Framework Privilege Escalation Under Exploitation (CVE-2025-48595)

Google patched 124 security vulnerabilities in Android for June 2026, including CVE-2025-48595 (CVSS 8.4), a high-severity privilege escalation flaw in the Framework component under active exploitation. The vulnerability affects Android versions 14, 15, 16, and 16 QPR2, and requires no user interaction. Google acknowledged indications that CVE-2025-48595 may be under "limited, targeted exploitation" but did not reveal specifics about who may have been behind the activity, the targets affected, or the scale of efforts.

Multiple MSRC CVE Publications

Microsoft Security Response Center published information for multiple CVEs affecting various components: - CVE-2026-11463: USCiLab Cereal shared pointer type confusion (EPSS 0.000, 15th percentile) - CVE-2026-49975: Apache HTTP Server mod_http2 denial of service - CVE-2026-40930: LIBPNG chunk smuggling in push-mode APNG parser (EPSS 0.000, 9th percentile) - CVE-2026-10879: DBI versions before 1.648 for Perl heap overflow with more than 9 binders (EPSS 0.000, 5th percentile) - CVE-2026-50256: Xorg-x11-server stack buffer overflow in font alias resolution (EPSS 0.000, 2nd percentile) - CVE-2026-50260: Xorg-x11-server use-after-free in freecounter() (EPSS 0.000, 2nd percentile) - CVE-2026-50031: FreeIPMI before 1.6.18 exploitable buffer overflows on response messages in ipmi-oem Dell and Fujitsu subcommands (EPSS 0.000, 12th percentile) - CVE-2026-46272: coresight tmc-etr race condition between sysfs and perf mode (EPSS 0.000, 4th percentile) - CVE-2026-50292: libinput before 1.30.4 and 1.31.x before 1.31.3 unescaped phys output can inject udev properties leading to arbitrary root code execution (EPSS 0.001, 17th percentile) - CVE-2026-35429: Microsoft Edge (Chromium-based) for Android spoofing vulnerability, updated acknowledgement (EPSS 0.001, 20th percentile) - CVE-2026-46250: MIPS LLVM bug when gp is used as global register variable (EPSS 0.000, 2nd percentile) - CVE-2026-50262: Xorg-x11-server out-of-bounds read/write in glx changedrawableattributes (EPSS 0.000, 2nd percentile)

Instagram Recovery Tool Bug Exposed 20,225 Accounts

Meta disclosed a security incident involving an Instagram account recovery tool after attackers used a flaw to send password reset links to email addresses not connected to targeted accounts. The issue affected 20,225 people according to a data breach notice filed with the Maine Attorney General's Office.

General Security News

Apple Announces AI-Powered Automatic Password Fixer

At WWDC 2026, Apple announced an Apple Intelligence-powered feature that can automatically fix weak and compromised passwords. Currently, Safari and the Apple Passwords app can flag weak, duplicate, or compromised passwords, but do not automatically fix them. The new AI-powered feature will launch with iOS 27 for the Passwords app and Safari, enabling automatic updates of eligible accounts to strong passwords. The feature uses next-generation Apple Foundation Models custom-built in collaboration with Google, using Gemini models to fine-tune Apple's own model. The models run on-device and on servers using Private Cloud Compute. When Private Cloud Compute handles users' requests, personal data is not stored nor made accessible to Apple or anyone else. The feature is available in beta for Developer Program members.

Trends & Context

The Check Point VPN zero-day, Gogs RCE, and LiteLLM command injection demonstrate a continued pattern of authentication bypass and command injection vulnerabilities affecting enterprise infrastructure. The TeamPCP supply chain campaign's transition from a single operator to an open-sourced framework marks a significant shift in supply chain threat models, with tradecraft now available to copycat attackers. The surge in Linux local privilege escalation vulnerabilities, with AI-assisted research producing working exploits before patches spread widely, highlights the narrowing window between disclosure and exploitation. Microsoft Teams phishing and AI brand impersonation campaigns show threat actors adapting to improved email security controls by targeting collaboration tools and exploiting user curiosity around emerging technologies.