CVE-2020-13573, CVE-2023-52271, CVE-2025-1055, CVE-2025-14272, CVE-2025-61155, CVE-2026-0646, CVE-2026-0647, CVE-2026-11317, CVE-2026-25089, CVE-2026-39808, CVE-2026-39813, CVE-2026-48907, CVE-2026-50656, CVE-2026-54420
IP Addresses:
2.9.99.4, 2.9.99.5, 39.107.60.51
Get tomorrow's brief in your inbox
Today: CISA gives federal agencies until tomorrow to patch an actively exploited cPanel plugin vulnerability (CVE-2026-54420). Microsoft confirms it's working on a patch for the RoguePlanet zero-day (CVE-2026-50656) disclosed last week. Three Fortinet FortiSandbox flaws are now under active exploitation, including one patched just last week.
CISA Orders LiteSpeed cPanel Patch by June 18 (CVE-2026-54420)
CISA added CVE-2026-54420 to its Known Exploited Vulnerabilities catalog on Monday, giving federal agencies three days to secure their servers against this actively exploited high-severity flaw in the LiteSpeed cPanel user-end plugin. The vulnerability allows attackers with FTP or web shell access to escalate privileges to root on shared hosting servers running CloudLinux/CageFS. It affects all user-end plugin versions before 2.4.8 and stems from a UNIX symlink following weakness. LiteSpeed flagged the flaw as actively exploited in early June. EPSS score is 0.006 (45th percentile), suggesting low predicted exploitation probability despite confirmed active exploitation.
grep -rE 'cpanel_jsonapi_func=(generateEcCert|packageUserSize)|cert_action_entry .*geneccert' /usr/local/cpanel/logs/ /var/cpanel/logs/ 2>/dev/null to check for exploitation. Examine system logs for detected IPs. CISA's deadline is June 18 under BOD 26-04.Microsoft Working on RoguePlanet Defender Zero-Day Patch (CVE-2026-50656)
Microsoft confirmed it is working on a security patch for the RoguePlanet zero-day vulnerability affecting fully patched Windows 10 and Windows 11 devices. Disclosed by researcher Nightmare Eclipse on June 10, the flaw allows attackers to spawn command prompts with SYSTEM privileges via a Microsoft Defender race condition. The exploit works regardless of whether real-time protection is enabled, though success rates vary by machine. Microsoft assigned CVE-2026-50656 on Tuesday but did not provide a timeline for the patch. This is the latest in a series of zero-day disclosures from Nightmare Eclipse, who has publicly leaked Windows exploits including BlueHammer, RedSun, GreenPlasma, MiniPlasma, YellowKey, and UnDefend.
Joomla JCE Plugin Flaw Under Active Exploitation (CVE-2026-48907)
CISA added CVE-2026-48907, a maximum-severity (CVSS 10.0) flaw in Widget Factory Joomla Content Editor (JCE), to the KEV catalog on Tuesday. The vulnerability allows unauthenticated attackers to create new editor profiles, upload PHP code, and execute it. It affects JCE versions 1.0.0 through 2.9.99.4. Widget Factory patched the issue in version 2.9.99.5 on June 3, citing insufficient access controls. Federal agencies must apply the fix by June 19. EPSS score is 0.008 (53rd percentile).
Three Fortinet FortiSandbox Flaws Under Active Exploitation
Threat intelligence firm Defused reports active exploitation of three Fortinet FortiSandbox vulnerabilities: CVE-2026-39813, CVE-2026-39808 (both patched in April), and CVE-2026-25089 (patched last week). CVE-2026-39813 (CVSS 9.1, EPSS 0.236/98th percentile) allows unauthenticated attackers to bypass authentication via path traversal in the JRPC API. CVE-2026-39808 (CVSS 9.1, EPSS 0.662/99th percentile) is an OS command injection flaw allowing arbitrary code execution. CVE-2026-25089 (CVSS 9.1, EPSS 0.027/84th percentile) is another OS command injection issue in the FortiSandbox Web UI. Defused noted that the exploit for CVE-2026-25089 appears AI-generated and is faulty, though a working exploit may emerge.
DragonForce Ransomware Abuses Microsoft Teams TURN Relays for Command-and-Control
DragonForce ransomware used a custom malware named Backdoor.Turn to hide command-and-control traffic inside Microsoft Teams relay infrastructure. The backdoor abuses the Traversal Using Relays around NAT (TURN) protocol, which Microsoft Teams uses to distribute messages when a direct connection to the client is unavailable. Symantec researchers observed an attack in December 2025 against a major U.S. services company that began with exploitation of an unknown SQL/MSSQL server flaw. After gaining a foothold, the attacker deployed multiple Bring Your Own Vulnerable Driver (BYOVD) techniques using Huawei's HWAuidoOs2Ec.sys, Topaz Antifraud wsftprm.sys (CVE-2023-52271), Tower of Fantasy GameDriverx64.sys (CVE-2025-61155), and K7 Security K7RKScan.sys (CVE-2025-1055) to terminate security tools at the kernel level. Backdoor.Turn was injected after ransomware deployment, suggesting it is intended for persistence or future access. The malware obtains an anonymous Teams visitor token, uses a legitimate Microsoft TURN relay during connection setup, and establishes communication with the C2 server, allowing defenders to see only traffic associated with Microsoft Teams infrastructure.
Kodak Confirms Data Breach, ShinyHunters Claims 2.2 Million Records
Kodak confirmed that attackers gained temporary access to a limited amount of company data and the company is investigating with external cybersecurity experts. ShinyHunters extortion group claimed responsibility on their dark web leak site, alleging they stole over 2.2 million records containing customer PII and internal corporate data. The group threatened to leak the data on June 18 if Kodak does not engage. ShinyHunters has previously claimed attacks against hundreds of Salesforce customers, over a dozen Snowflake customers, and, one week ago, over 100 organizations following exploitation of a zero-day in Oracle's PeopleSoft enterprise business software.
Lorem Ipsum Malware Pivots to ClickFix Delivery, Likely Linked to Vice Society
BlueVoyant researchers revised their assessment of the Lorem Ipsum malware campaign, now strongly believing it is linked to Rapid Brigantine (also tracked as Vanilla Tempest, DEV-0832, and Vice Society), a financially motivated cybercriminal group associated with Rhysida, BlackCat, Zeppelin, and Quantum Locker ransomware families. After Microsoft disrupted malware-signing provider Fox Tempest in late May, Lorem Ipsum operators abandoned their delivery method of Trojanized Microsoft Teams installers signed with fraudulent Microsoft certificates and pivoted to ClickFix lures hosted on compromised WordPress sites. The new delivery model eliminates code signing entirely and significantly broadens the potential victim pool from users who encountered fake installers on SEO-poisoned download portals to anyone browsing one of at least five compromised WordPress websites spanning architecture, legal services, and construction technology sectors. Lorem Ipsum uses a multistage shellcode loader and backdoor with DLL sideloading, encrypted payloads, and a C2 mechanism that abuses the Indian blogging platform LetsDiskuss.com as a dead drop to retrieve C2 server addresses.
Novo Nordisk Hit by Two Separate Threat Actors Demanding $50M and $25M
FulcrumSec hacked pharmaceutical giant Novo Nordisk and released a detailed report on their dark web leak site. A second threat actor also messaged DataBreaches.net claiming they too had hacked Novo Nordisk. One threat actor demanded $50 million, the other demanded $25 million. Neither received payment.
144 Mastra npm Packages Compromised via Hijacked Contributor Account
A software supply chain attack codenamed easy-day-js compromised 144 npm packages in the Mastra namespace (@mastra/*), a popular JavaScript and TypeScript framework for building AI applications. A hijacked npm account (ehindero), belonging to a legitimate former Mastra contributor whose scope access was never revoked, mass-published the malicious packages within 88 minutes on June 17. The infected packages do not include malicious code directly; instead, they added a dependency on "easy-day-js," a clone of the "dayjs" date library that downloads and runs a cryptocurrency-stealing remote access trojan. The malware harvests browser history, data from over 160 cryptocurrency wallet browser extensions, installs persistence across Windows, macOS, and Linux, and exfiltrates captured information to a C2 server. The malware also polls the C2 to receive commands, including downloading and executing additional modules. Mastra ships real releases from CI with SLSA provenance attestations, but the attacker pushed malicious versions from a personal token without provenance. Npm has since pulled the malicious versions from the highest-profile packages.
npm audit signatures. Consider enforcing provenance requirements in package policies.15 Malicious JetBrains Plugins Steal AI API Keys from 70,000 Developers
Aikido Security discovered at least 15 malicious plugins on the JetBrains Marketplace designed to steal AI API keys from developers. The plugins, published under seven vendor accounts and installed close to 70,000 times, act as AI coding assistants, code-review tools, and Git utilities powered by OpenAI, DeepSeek, and SiliconFlow. The plugins function as advertised but secretly transmit AI API keys entered into plugin settings to a hardcoded server at 39.107.60.51 over HTTP. The plugins were first published in October 2025, with new ones continuing to appear as recently as June 10, 2026. Aikido also discovered functionality that allows the remote server to provide AI API keys to paid users, theorizing that the plugin operators may be harvesting credentials from free users and then providing them to paid users. BleepingComputer independently confirmed that the latest version of the DeepSeek AI Assist plugin still contains the credential theft code. At the time of writing, the plugins remained available for download through the JetBrains Marketplace.
Steam Workshop Abused to Spread Malware via Wallpaper Engine
Threat actors are abusing Steam Workshop, Valve's community hub for downloading game-related content, to push malware hidden in wallpaper packages for the Wallpaper Engine desktop customization application. Kaspersky researchers found dozens of malicious application wallpapers on Steam Workshop, each downloaded thousands or tens of thousands of times since at least late 2025. The malware is bundled either directly in the package or inside password-protected archives that the user is tricked into opening. Payloads execute automatically when the user installs the wallpaper. One wallpaper posing as a game called NTRaholic launched as expected but installed a DarkKomet backdoor file in the background, along with a custom version of AggregatorHost.dll to search for and steal Steam account credentials. Kaspersky found multiple malware families, including Lumma and Vidar infostealers, cryptocurrency miners, botnet loaders, RanEngine, and ransomware strains, showing that multiple threat actors are abusing Wallpaper Engine. While Steam has removed the malicious wallpaper applications Kaspersky identified, threat actors are likely to submit new ones.
30,000 Compromised Fortinet Firewalls Expose Corporate Networks (FortiBleed Campaign)
SOCRadar detected more than 30,000 compromised Fortinet firewalls that expose corporate networks to hacking. The campaign, dubbed FortiBleed, involves a threat actor systematically hacking Fortinet firewalls and VPN gateways and compiling a database of verified credentials. The compromised systems belong to companies and government organizations across more than 190 countries, with many devices located in India and the United States. Attackers scan the internet for Fortinet devices, try a curated list of known passwords against each one, and record every successful login. Once a device is compromised, they use it as a listening post to monitor traffic and collect additional credentials, which are then fed back into the scanner to compromise even more devices. The threat actor left its server exposed, enabling researchers to collect data on its infrastructure and targets, including credentials for what appears to be a defense industry VPN endpoint. SOCRadar believes the hackers are likely Russian speakers.
ClickFix Campaigns Expand with BabaDeda, Lorem Ipsum, and Potemkin Loaders
Cybersecurity researchers flagged multiple ClickFix campaigns delivering three malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. BabaDeda Loader, observed in April 2026 targeting education and financial organizations, uses ClickFix social engineering to deliver PowerShell commands, then drops information stealers and remote access trojans via hidden PowerShell, in-memory shellcode, DLL side-loading, and external payload storage. The loader is designed to profile the host, avoid running on Russian or Belarusian systems, and perform security product checks before retrieving the main payload and injecting it into svchost.exe. One .NET backdoor and information stealer delivered via BabaDeda harvests sensitive data, extracts browser artifacts (cookies, history, saved credentials, preferences, encryption keys), reads and exfiltrates file contents, captures screenshots, executes shell commands, and transfers data to the C2 server. A second attack chain drops a ZIP archive that employs DLL side-loading to launch DanaBot and SectopRAT (aka ArechClient).
GhostTree Attack Abuses Recursive Windows Junctions to Hide Malware from EDR
Security researchers disclosed GhostTree, a technique that uses recursive NTFS junctions to create effectively infinite file paths, causing security tools that recursively scan directories to follow the loop and never finish. By pointing a junction back at its own parent directory, an attacker can create unlimited valid paths to the same file (e.g., C:\Parent\Child\Child\Child\Child\Program.exe). Malicious files sitting in the same folder go unexamined. The technique requires only write permissions and a single mklink command, with no admin privileges needed. The maximum path length of 260 characters on classic Windows systems determines how deep the recursive loops can go and how many unique paths GhostTree can produce, though the limit can be extended to 32,767 characters via a registry key.
Google Vertex AI SDK Flaw Allowed Cross-Tenant Model Hijacking (Pickle in the Middle)
Palo Alto Networks Unit 42 discovered a vulnerability in the Google Cloud Vertex AI SDK for Python that allowed an attacker operating entirely from their own Google Cloud project to hijack a victim's model upload and poison it. The flaw, dubbed Pickle in the Middle, exploited a predictable default bucket name combined with a missing ownership check in the SDK's staging logic. When a Vertex AI user uploaded a model without specifying a custom staging bucket, the SDK constructed a bucket name using a deterministic pattern based on the project ID and region. An attacker who knew the victim's project ID could preemptively create this bucket in their own project (bucket squatting). The SDK then silently uploaded the victim's model artifacts to the attacker-controlled bucket, where the attacker could replace the legitimate model with one carrying a malicious payload. Once the victim deployed the compromised model, the attacker's code executed, leading to data exfiltration, lateral movement, and further compromise. The issue affected google-cloud-aiplatform SDK versions 1.139.0 and 1.140.0. Google completed the fix in version 1.148.0, released April 15, 2026.
China Arrests 67 Suspects Linked to Silver Fox Cybercrime Group
Chinese police arrested 67 suspects linked to Silver Fox, the country's largest and most active cybercrime group targeting Chinese-speaking audiences. Arrests took place across five provinces and targeted everyone from developers to phishing site operators and various affiliates. Ji Moufei, identified as the main developer who wrote and sold the Silver Fox trojan, was arrested in Zhejiang along with four associates. Twenty-eight others were arrested in Jilin, including Chen, who developed a variant of the trojan. Other arrests occurred in Shandong (Yang and 15 suspects for setting up phishing sites), Guangdong (Li and 13 others for using the trojan to steal victims' online assets), and Zhejiang (Zhou and two accomplices for developing fake app download sites). The Silver Fox group began operations in mid-2024 and only targeted Chinese-speaking users, living in both China and abroad, expanding to other countries only in recent months. The group used malspam campaigns and fake download websites to lure victims into installing its trojan, which then deployed other tools such as infostealers and custom RATs named AtlasRAT and ValleyRAT. Silver Fox is also known as Void Arachne, YouSnake, UTG-Q-1000, and TA4922, and its main trojan is also tracked as Winos.
Chrome Extensions Steal AI Conversations (PromptSnatcher Campaign)
Two Google Chrome ad blocker extensions have been caught capturing users' conversations with AI chatbots including OpenAI ChatGPT, Anthropic Claude, Google Gemini, Microsoft Copilot, Perplexity, DeepSeek, xAI Grok, and Meta AI. The extensions, Smart Adblocker (90,000 users, published October 2025) and another unnamed extension, are still available on the Chrome Web Store. The campaign, dubbed PromptSnatcher, represents a new attack vector targeting AI usage data.
China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth
ESET researchers discovered two previously undocumented Windows variants of the SprySOCKS backdoor, which was believed to be Linux-only. The Windows variants, internally marked as WIN_DRV and WIN_PLUS, support more than 30 commands for system information collection, process enumeration, service management, and file system operations. WIN_DRV uses kernel drivers to conceal the malware's network connections, processes, files, and registry keys, and enables TCP traffic diversion that allows operators to send commands through a random TCP port without exposing the backdoor's actual listening port. SprySOCKS is used by a China-nexus state-sponsored threat actor known as Earth Lusca (also tracked as Aquatic Panda, Bronze University, Charcoal Typhoon, RedHotel, FishMonger), assessed to be operated by Chinese contractor i-Soon. The group has previously exploited N-day flaws in Fortinet, GitLab, Microsoft Exchange Server, Progress Telerik UI, and Zimbra instances to obtain a foothold.
New Rokarolla Android Malware Targets 217 Banking and Crypto Apps
Zimperium researchers documented Rokarolla, a new Android banking trojan that targets 217 banking and cryptocurrency applications using 137 commands. The malware is distributed via malicious websites posing as Google Chrome or TikTok. During installation, the malicious app acts as a dropper and impersonates Google Play Protect, offering users the option to install Chrome or TikTok, which include the Rokarolla malware. When launched, Rokarolla requests Accessibility service permissions, access to notifications, SMS, and calls. The malware checks the infected device against a list of 217 targeted applications, downloads the phishing payload corresponding to any matching apps, and displays fake login overlays to steal credentials, credit card information, and other financial data. Additional capabilities include stealing lock-screen credentials, contact lists, and SMS data, keylogging, disabling Google Play Protect, hiding the application icon, silencing audio and vibration, keeping the screen awake indefinitely, blocking incoming calls and bank fraud alerts, and periodically taking screenshots.
FTC Warns of Record $3.5 Billion Losses to Imposter Scams in 2025
The U.S. Federal Trade Commission warned that Americans lost $3.5 billion to imposter scams in 2025, with reported losses nearly tripling since 2020. Imposter scams were the most reported fraud category last year, accounting for nearly one in three fraud reports. Victims lost nearly $1 billion to business impersonators (with bank impersonators being behind the most lucrative scams) and approximately $920 million to government impersonators. Social media was the most cost-effective attack vector, with more than $2.1 billion in 2025 losses traced to social platforms (an eightfold increase since 2020). Facebook losses alone exceeded those from text and email combined, while WhatsApp and Instagram ranked second and third. Overall reported fraud losses across all categories surged to about $16 billion in 2025, the highest on record and roughly 25% above the prior year.
Rockwell Automation FLEX I/O EtherNet/IP Adapters (CVE-2026-0646, CVE-2026-0647)
Two vulnerabilities affect Rockwell Automation FLEX I/O EtherNet/IP Adapters 1794-AENTR and 1794-AENTRXT version 2.012. CVE-2026-0646 is a denial-of-service issue due to improper memory handling of CIP protocol requests, which can result in the adapter faulting and losing connection to its associated I/O modules, requiring a manual reset to recover. CVE-2026-0647 is an improper authentication issue in the embedded web server that allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, leading to unauthorized access, account takeover, and loss of availability. Rockwell Automation recommends updating to version 2.013.
Rockwell Automation RSLinx Classic (CVE-2020-13573)
A stack-based buffer overflow vulnerability in RSLinx Classic version 4.50.00 and earlier allows an attacker to remotely execute arbitrary code, leading to a denial of service where the application becomes unresponsive and will not recover on its own. EPSS score is 0.035 (87th percentile). Rockwell Automation recommends upgrading to version 4.60.00 or later, or applying patch BF31213 for customers who cannot upgrade.
Rockwell Automation Logix 5370 & 5570 Controllers (CVE-2026-11317)
A denial-of-service vulnerability exists in CompactLogix 5370, Compact GuardLogix 5370, ControlLogix 5570, and GuardLogix 5570 controllers. The issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be affected, resulting in a major nonrecoverable fault (MNRF) that requires a program download to recover. Rockwell Automation recommends updating to CompactLogix 5370 version 34.016 or later, Compact GuardLogix 5370 version 35.015 or later, ControlLogix 5570 version 36.012 or later, and GuardLogix 5570 version 37.011 or later.
Rockwell Automation FactoryTalk Analytics PavilionX (CVE-2025-14272)
An improper authorization vulnerability in FactoryTalk Analytics PavilionX versions below 7.01 allows an unauthorized actor to execute privileged operations, including user/role management and other administrative actions. Rockwell Automation recommends updating to version 7.01 or later.
Chrome and Firefox Memory Safety Updates
Chrome has been updated to versions 149.0.7827.155/.156 for Windows and macOS and 149.0.7827.155 for Linux to resolve 33 security defects, including seven critical-severity use-after-free issues that could lead to remote code execution and sandbox escape. Firefox 152 was released with fixes for 40 vulnerabilities, including 13 high-severity use-after-free, privilege escalation, incorrect boundary condition, sandbox escape, JIT miscompilation, and memory safety bugs. Some of the resolved memory safety flaws could potentially be exploited for arbitrary code execution. Google makes no mention of any Chrome vulnerabilities being exploited in the wild.
Today's threat landscape shows attackers are increasingly leveraging legitimate infrastructure to hide malicious activity, as seen with DragonForce's abuse of Microsoft Teams TURN relays and Lorem Ipsum's use of LetsDiskuss.com for C2 communication. Supply chain attacks continue to mature, with the Mastra npm compromise and JetBrains plugin campaign demonstrating how threat actors target developer environments to harvest credentials for resale. The ClickFix social engineering technique is gaining traction across multiple campaigns, delivering loaders like BabaDeda, Lorem Ipsum, and Potemkin by deceiving users into running attacker-supplied PowerShell commands. Meanwhile, CISA's KEV catalog additions and Fortinet's ongoing exploitation underscore the importance of rapid patch deployment for internet-facing systems.