CVE-2026-13778, CVE-2026-13795, CVE-2026-13809, CVE-2026-13842, CVE-2026-14096, CVE-2026-14396, CVE-2026-14399, CVE-2026-14404, CVE-2026-14423, CVE-2026-14428, CVE-2026-15308, CVE-2026-58281, CVE-2026-59871, CVE-2026-59873, CVE-2026-59874
Domains:
183[.]8, 183[.]8.
Get tomorrow's brief in your inbox
Today: Compromised npm package jscrambler 8.14.0 drops Rust infostealer targeting dev environments and CI pipelines. Microsoft patches on-prem SharePoint zero-day under active attack. GitHub ghost accounts running mass reconnaissance across organizations.
Microsoft SharePoint Zero-Day Under Active Attack
Microsoft patches failed to fix on-prem SharePoint, which is now being exploited in the wild. The vulnerability affects on-premises SharePoint Server deployments and is under active exploitation.
Compromised jscrambler 8.14.0 npm Package Drops Infostealer
npm package jscrambler version 8.14.0 was compromised and published with a preinstall hook that deploys a Rust-based infostealer. Published July 11, the malicious release executes native binaries for Windows, macOS, and Linux during installation. Socket detected the compromise six minutes after publication. The payload targets developer environments and CI systems, harvesting AWS, Azure, and Google Cloud credentials, cryptocurrency wallets (MetaMask, Phantom, Exodus), Bitwarden vaults, browser passwords, Discord/Slack/Telegram sessions, and AI coding tool configs (Claude Desktop, Cursor, Windsurf, VS Code, Zed). The Linux binary includes eBPF capability for kernel-level persistence. Windows and macOS builds include anti-debugging and persistence mechanisms (scheduled tasks and LaunchAgents). The malicious version bypassed jscrambler's normal release process and was pushed directly to npm under a compromised maintainer account. Version 8.13.0 is clean.
Armenian National Pleads Guilty to Ryuk Ransomware Extortion
Karen Serobovich Varyan, 34, extradited from Ukraine, pleaded guilty to conspiracy and computer fraud for his role in Ryuk ransomware attacks targeting US companies, including a technology firm in Oregon. Varyan was part of a coordinated extortion operation that deployed Ryuk to encrypt victim systems and demand ransom payments.
Ransomware Negotiator Sentenced for Colluding with BlackCat
A former ransomware negotiator working for DigitalMint was sentenced to 70 months in prison for colluding with BlackCat threat actors. The negotiator provided inside information on victim defense strategies to the attackers, effectively working both sides of the extortion. This is the third co-conspirator sentenced in connection with BlackCat operations.
Ghost Accounts Abuse GitHub API in Mass Reconnaissance
Threat actors are using dormant GitHub accounts (registered 2-5 years ago) to systematically enumerate organizations, repositories, and user accounts via the GitHub API. The campaign has been running since at least October 2025, using over 50 ghost accounts in bursts of 1-3 weeks. Attackers are leveraging publicly accessible API endpoints that return HTTP 200 responses without authentication, mapping organizations, members, and projects. Some campaigns also used inadvertently exposed tokens from legitimate users to access private repository commit paths. In rare cases, attackers successfully exfiltrated data from targeted organizations. The reconnaissance leverages GraphQL and REST routes with user agents mimicking data exfiltration, analytics, or dashboard tools.
Pakistani Law Enforcement Targeted in Multi-Group Espionage Campaign
China-aligned and India-aligned threat actors compromised Pakistani law enforcement infrastructure between February 2024 and April 2026. Targets included Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad Police, and Punjab Safe Cities Authority. Compromised assets included network appliances, web servers hosting police and citizen data (biometric records, criminal case files, personnel records), and a Fortinet FortiMail appliance. A China-nexus actor deployed a custom implant masquerading as an update to the Complaint Management System, a portal used by police staff and citizens. Four distinct malware families were deployed: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. PlugX and ShadowPad are traditionally associated with Chinese nation-state groups. Remcos RAT activity is linked to Mysterious Elephant (APT-C-08, APT-K-47, TAG-179), which shares infrastructure and tactics with India-nexus actors SideWinder, Confucius, and Bitter. Cobalt Strike C2 infrastructure (142.171.183[.]8) also targeted government, academic, telecommunications, and NGO entities across South, East, and Southeast Asia, the Middle East, and South America.
Signal Phishing Campaign by Russian Actors
Russian threat actors are posing as Signal support staff to launch phishing attacks against Signal users. The campaign targets users of the encrypted messaging platform by impersonating legitimate support channels to harvest credentials or deliver malware.
TikTok Class Action Alleges 2.4 Billion User Data Breach
A class action lawsuit filed June 11, 2026, in the Central District of California alleges TikTok exposed personal data of more than 2.4 billion users worldwide. The complaint claims TikTok stored unencrypted data and failed to implement basic security measures.
Dutch Police Trace Odido Telco Cyberattack to Local Accomplice
Dutch police uncovered evidence suggesting Dutch criminals were involved in the cyberattack on telecom provider Odido that exposed personal data of over 6 million customers. A Dutch-speaking man posing as an Odido IT employee called the company's customer service department before the attack, indicating insider knowledge or social engineering to facilitate access.
CVE-2026-58281: Microsoft Edge Remote Code Execution
Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. EPSS data not yet available.
Multiple Chromium CVEs in Microsoft Edge
Microsoft Edge (Chromium-based) ingests multiple Chromium fixes, including CVE-2026-14428 (insufficient validation in Dawn, EPSS 0.003/17th percentile), CVE-2026-13778 (use after free in WebUSB, EPSS 0.001/4th percentile), CVE-2026-14396 (out of bounds read in ANGLE, EPSS 0.002/16th percentile), CVE-2026-14399 (uninitialized use in Dawn, EPSS 0.002/13th percentile), CVE-2026-14404 (inappropriate implementation in PDFium, EPSS 0.002/10th percentile), CVE-2026-14423 (type confusion in Tint, EPSS 0.002/13th percentile), CVE-2026-13795 (insufficient policy enforcement in Chrome for iOS, EPSS 0.003/17th percentile), CVE-2026-13809 (side-channel information leakage in Safe Browsing, EPSS 0.003/20th percentile), CVE-2026-13842 (incorrect security UI in Chrome for iOS, EPSS 0.002/13th percentile), and CVE-2026-14096 (object lifecycle issue in Input, EPSS 0.002/14th percentile).
node-tar CVEs (CVE-2026-59874, CVE-2026-59871, CVE-2026-59873)
Three CVEs affecting the node-tar npm package: CVE-2026-59874 (negative tar entry size causes infinite loop in archive replace, EPSS 0.004/28th percentile), CVE-2026-59871 (process crash via PAX numeric path type confusion, EPSS 0.004/28th percentile), and CVE-2026-59873 (decompression/parse DoS via unlimited input, EPSS 0.004/28th percentile).
CVE-2026-15308: Python HTMLParser DoS
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations. EPSS 0.006/42nd percentile.
The jscrambler compromise is the latest in a series of supply chain attacks targeting developer environments and CI pipelines through npm. Attackers are specifically harvesting cloud credentials, AI tool API keys, and cryptocurrency wallets from build systems. The GitHub ghost account reconnaissance campaign highlights how adversaries are using dormant accounts and public API endpoints for systematic intelligence gathering before launching targeted attacks.