Supply Chain Attack Hits 32 Red Hat NPM Packages

A supply chain attack has compromised 32 Red Hat npm packages, with attackers publishing 96 malicious package versions. These versions contained a credential-stealing worm, reportedly similar to Mini Shai-Hulud.

Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT

A spear-phishing campaign, attributed to the Pakistan-aligned SideCopy group, has targeted Afghanistan's Ministry of Finance. The attackers used a ZIP archive containing a malicious LNK file with a Pashto-language filename to deliver the Xeno RAT, an open-source remote access trojan.

New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)

A new wave of phishing emails is using SVG files as attachments to deliver malicious content. Threat actors are leveraging the SVG format to embed harmful code, bypassing traditional email filters by presenting the content as an image without any URLs in the email body.

Red Hat npm packages compromised to steal developer credentials

A supply-chain attack compromised over 30 npm packages within Red Hat's '@redhat-cloud-services' namespace. The attackers distributed a new variant of the Shai-Hulud malware, named "Miasma," designed to steal developer credentials.

Election interlopers register 5K+ domains, hope to catch some voting phish

Malicious actors have registered over 5,000 new domains in an effort to impersonate election-related entities and conduct phishing attacks. These domains are designed to mimic legitimate election websites and organizations, aiming to trick voters into revealing personal information. This tactic highlights the shift from direct election system attacks to social engineering methods.

Dashlane password manager users locked out by brute force attacks

Dashlane password manager is investigating reports of users being locked out of their accounts due to brute-force attacks. These attacks appear to originate from unknown locations and devices, with attackers attempting multiple login attempts. Dashlane is working to address the issue and has stated that no user data has been compromised.

Dutch Police Dismantle Massive 17-Million-Device Botnet

Dutch police have successfully dismantled a massive botnet consisting of 17 million infected devices. This botnet was allegedly used to operate a residential proxy network and facilitate various cybercriminal activities.

WordPress malware campaign hides payloads in Steam profiles

A sophisticated WordPress malware campaign has been discovered that uses Steam Community profile comments to hide its command-and-control (C2) infrastructure. Attackers are exploiting WordPress sites to inject malicious code, which then communicates with C2 servers disguised within user comments on Steam profiles, making detection more challenging.

Critical Windows Netlogon RCE flaw now exploited in attacks

The Centre for Cybersecurity Belgium has issued a warning that threat actors are actively exploiting a critical Windows Netlogon Remote Code Execution (RCE) vulnerability in ongoing attacks. This vulnerability was recently patched, highlighting the ongoing threat posed by unaddressed security flaws.

China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan

Operation Dragon Weave, a new cyber espionage campaign aligned with China, is targeting officials and citizens in the Czech Republic and Taiwan. The campaign uses spear-phishing emails with ZIP attachments to deliver the AdaptixC2 agent to sectors including government, research, academic, technology, and financial services.

Unidentified RAT pushes NetSupport RAT, (Mon, Jun 1st)

An unidentified Remote Access Trojan (RAT) is distributing the NetSupport RAT malware. This is a concerning development as it indicates a potentially coordinated effort to spread malicious remote access tools.

WP Maps Pro bug exploited to create admin accounts on WordPress sites

A critical vulnerability in the WP Maps Pro plugin for WordPress is being actively exploited by hackers. The flaw allows unauthenticated attackers to create new administrator accounts on vulnerable websites. This could lead to full site compromise and malicious activity.

Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

Dutch authorities have successfully dismantled a large botnet comprising at least 17 million infected devices, including computers, tablets, smartphones, and IoT devices. The operation, conducted by the Dutch Politie and the National Cyber Security Center (NCSC), involved taking down over 200 servers used to control the bot network.

Botnet of more than 17 million devices dismantled

A massive botnet, reportedly linked to a Russia-based residential proxy network and comprising over 17 million devices, has been dismantled. The operation involved authorities taking down the infrastructure used to control these compromised devices.

Dutch cops wrest 17M devices from mystery botnet's clutches

Dutch police have dismantled a massive botnet by taking control of 17 million infected devices. This operation involved identifying and seizing approximately 200 servers used to control the botnet, which were traced to the Netherlands. The hosting provider subsequently disconnected these servers, effectively disrupting the botnet's operations.

Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

A malicious NuGet package named 'Sicoob.Sdk' has been found to steal banking credentials, specifically client IDs and PFX certificates, from users in Brazil. This package, disguised as a legitimate software development kit for Sicoob, a major financial cooperative, contains functions to exfiltrate this sensitive information.

The Gentlemen are coming for your files, and then your network

The Gentlemen ransomware is evolving with a self-propagating Go-based encryptor that can spread laterally across networks. This sophisticated malware identifies and deploys itself to additional systems using harvested credentials and legitimate administrative tools, leading to broader business disruptions.

BTMOB Android malware service generates custom phishing payloads

A new Android remote access trojan (RAT) called BTMOB is being offered to cybercriminals. It features a builder interface that allows attackers to create custom phishing payloads, making it easier to target specific users and organizations. This advanced customization aims to increase the effectiveness of phishing campaigns.

FBI warns of fake FIFA websites running World Cup fraud schemes

The FBI has issued a warning about fraudulent websites impersonating FIFA to scam individuals ahead of the 2026 World Cup. These fake sites aim to steal personal and financial information, sell counterfeit tickets and hospitality packages, and perpetrate other World Cup-related fraud.

Canvas attack aftermath: What risks come next

The recent Canvas attack, which targeted unpatched VPNs and exploited unpatched vulnerabilities, highlights the persistent risks associated with legacy systems and the need for robust patch management. Attackers exploited known vulnerabilities to gain initial access, demonstrating that even well-publicized flaws can be leveraged for significant impact.

Hackers exploit FortiClient EMS flaw to push infostealer malware

Hackers are exploiting a critical vulnerability in FortiClient EMS to deploy a new infostealer malware known as EKZ. The vulnerability, an authentication bypass flaw, allows attackers to gain unauthorized access and push the malware to vulnerable systems.

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

Threat actors are actively exploiting a critical, patched vulnerability in FortiClient Endpoint Management Server (EMS) to distribute credential-stealing malware. The campaign leverages trusted endpoint management infrastructure to deliver payloads disguised as legitimate Fortinet software across managed endpoints.

New BTMOB Android Malware Enables Full Device Takeover

A new Android malware named BTMOB has been identified that can perform a full device takeover. It is distributed through phishing lures and is capable of financial theft, data exfiltration, and providing remote access to attackers.

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

Fortinet has released patches for a critical vulnerability in FortiClient EMS, which was actively exploited in the wild as a zero-day. The company urged users to apply the fixes immediately following the discovery of these attacks.

GlassWorm falls, but the repo problem is far from solved

A major malware operation known as GlassWorm, which targeted developers by poisoning software repositories, has been disrupted by a coordinated effort led by CrowdStrike. Despite this takedown, the broader problem of securing the open-source ecosystem and distinguishing real threats from automated noise remains a significant challenge for defenders.

BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model

A new advanced remote access Trojan (RAT) known as BTMOB RAT is spreading across Brazil and Latin America. It is being delivered through a malware-as-a-service (MaaS) model and features a no-code interface for malware development.

GPU mining malware spreads via SEO poisoning, AI chatbots

Threat actors are conducting a cryptojacking campaign that leverages SEO poisoning to spread GPU mining malware. This campaign also manipulates AI chatbot recommendations to trick users into downloading malicious software. The attackers are specifically targeting systems with high-performance GPUs.

Ransomware Actors Show Up In Person to Steal Law Firm Data

The FBI has issued a warning regarding the Silent Ransom Group, an extortion gang that is specifically targeting law firms. This group employs social engineering tactics to gain access to sensitive data stored on law firm servers and databases.

Malicious npm Package Stole Files From Claude AI User Directory via GitHub

A malicious npm package named 'mouse5212-super-formatter' has been discovered that steals files from the Claude AI user directory. The package is designed to upload sensitive files from the '/mnt/user-data' directory, which is used by Anthropic's AI tool for handling uploads and outputs.

Glassworm botnet disrupted after resilient C2 infrastructure takedown

Researchers have disrupted the Glassworm botnet, which was used in software supply-chain attacks targeting developers. The takedown was achieved by dismantling its command-and-control infrastructure, which utilized Solana blockchain transactions and the BitTorrent DHT network for resilience.

FBI warns of in-person data theft attacks from extortion gang

The FBI has issued a warning regarding the Silent Ransom Group (SRG) extortion gang, which is now conducting in-person data theft attacks against law firms in the United States. These attacks involve physical intrusion and data exfiltration, posing a new threat vector for organizations.