← Carolina Clear Tech

Cyber Threat Brief

2026-06-15

Listen to this brief (10:56)

Download MP3
Show Notes

Show Notes - 2026-06-15

Stories Covered

CVEs Referenced

CVE-2026-0257, CVE-2026-11526

Indicators of Compromise

IP Addresses: 23.128.228.6, 104.207.144.154, 146.19.216.119, 146.19.216.120, 146.19.216.125, 179.43.172.213, 185.195.232.139, 198.12.106.60, 202.144.192.47

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

June 15, 2026

Today: Palo Alto GlobalProtect VPN suffers active exploitation with CISA KEV deadline passed. Arch Linux supply chain attack hijacks 1,900+ community packages with rootkit and credential harvester. FBI dismantles Chinese phishing-as-a-service operation responsible for $1.9 billion in losses and 3.8 million stolen credit cards.

Critical Alerts

Palo Alto PAN-OS GlobalProtect VPN Authentication Bypass (CVE-2026-0257)

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257 (CVSS 7.8), an authentication bypass flaw in PAN-OS GlobalProtect portal and gateway components. The vulnerability allows attackers to bypass security controls and establish unauthorized VPN connections. Initial exploitation was observed on May 17, 2026, with limited but targeted attacks establishing VPN sessions on a small number of probed devices. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog with a June 1, 2026 remediation deadline (now passed). EPSS score is 0.604 (98th percentile), indicating high likelihood of exploitation.

Arch Linux Supply Chain Attack Hijacks 1,900+ AUR Packages

A massive supply chain attack has compromised nearly 1,900 Arch Linux packages on the AUR (Arch User Repository) portal, representing almost 10% of the repository's orphaned packages. Attackers exploited an AUR mechanism that allows users to "adopt" abandoned packages and become maintainers. The attack adds a malicious installation procedure that downloads an npm package (later switched to a Bun script to evade detection), which then installs a rootkit and credential harvester. The infostealer targets browser and Electron app credentials plus developer secrets and access keys. The attack began with 400 packages and expanded to 1,500, with hijacking attempts still ongoing. Microsoft SharePoint is also under active zero-day attack after patches failed to fix on-premise installations.

Business & Infrastructure Threats

FBI Dismantles Chinese Phishing-as-a-Service Platform (Outsider Enterprise)

The FBI, working with Google, Black Lotus Labs, AT&T, T-Mobile, and Verizon, has taken down Outsider Enterprise, a Chinese phishing-as-a-service operation active since 2023. The platform distributed phishing kits that enabled criminals to impersonate trusted brands in SMS campaigns, using AI-assisted techniques to improve effectiveness. The operation is linked to stealing approximately 3.8 million credit card records, causing an estimated $1.9 billion in losses across the US and at least 54 other countries. Google identified 9,000 fake websites and over 1 million fraudulent URLs connected to the platform. In May alone, 2.5 million SMS messages from Outsider Enterprise infrastructure were sent to Android users over a two-week period, with 55,000 flagged as fraudulent by recipients.

WordPress Plugin Supply Chain Attack (Awesome Motive)

More than 1.2 million websites have been backdoored following a security incident at Awesome Motive, a major WordPress plugin developer. Malicious code was added to legitimate JavaScript files of three plugins: OptinMonster, TrustPulse, and PushEngage. The code waits for an admin login, creates its own admin account, and installs a self-hiding backdoor plugin to maintain access. No malicious code has been detected in Awesome Motive's other plugins, some of which are installed on tens of millions of sites.

Maine Attorney General Disables Data Breach Portal Due to Fake Submissions

The Maine Office of the Attorney General has taken down its data breach reporting portal after unknown individuals abused it to file fake breach notices on behalf of VRChat (claiming 2.4 million affected) and Discord (claiming 10 million affected). The submissions used fake letterhead and contact information for people who do not exist. Maine's portal is notable because it requires reporting the total number of individuals affected nationwide, not just state residents, making it a valuable public resource. The database contained nearly 6,000 incidents reported since mid-2020 and will remain offline while the state revises submission procedures.

General Security News

Sniper Dz Phishing-as-a-Service Platform Targets MENA Region

Cybersecurity researchers have disclosed details of the Sniper Dz phishing-as-a-service platform that was taken down in an INTERPOL-led operation last month. The platform targeted users across the Middle East and North Africa using fraudulent Facebook accounts impersonating politicians, public figures, and organizations to promote fake offers (free mobile internet, financial compensation, government subsidies). The campaign used link-aggregation services (Linkbio, Linktree) as intermediaries, then directed victims to pages requesting browser notification permissions. The attack employed back-button hijacking (injecting 10 fake history states) and tab-under techniques to trap users in attacker-controlled content. Monetization included premium-rate calls, premium SMS subscriptions, and investment scams.

Hotel Chain Data Breach (BWH Hotels)

BWH Hotels, parent company of WorldHotels and Best Western Hotels & Resorts, has disclosed a data breach affecting personal information belonging to individuals with reservations at the chain's properties. The breach occurred over a six-month period. Guests are warned to remain alert for convincing fraudulent messages.

Novo Nordisk Clinical Trial Patient Data Breach

Pharmaceutical giant Novo Nordisk has reported a data breach affecting clinical trial patients. The company is advising affected individuals to remain vigilant. Details on the scope and nature of the breach have not been fully disclosed.

ShinyHunters Lists New Victims

The ShinyHunters hacking group has listed new victims on its dark web leak site, including the Council of Europe, fashion retailers Ralph Lauren and JCPenney, and Nexstar (the largest TV broadcaster in the US). The group is actively attempting to extort these organizations.

Patch Priority

Vulnerability Disclosures

CVE-2026-11526 (Perl GD Library Command Injection)

GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. EPSS score is 0.003 (50th percentile), indicating lower exploitation likelihood at this time.

Trends & Context

Today's stories highlight the scale and sophistication of supply chain attacks, from Arch Linux package hijacking to WordPress plugin backdoors affecting millions of sites. Phishing-as-a-service platforms continue to operate at massive scale, with Outsider Enterprise alone causing nearly $2 billion in losses before takedown. The Palo Alto GlobalProtect exploitation demonstrates the critical importance of meeting CISA KEV deadlines, as active exploitation began weeks before the June 1 compliance date.