Summary & highlights
Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026). Fake ChatGPT Download Site openew[.]app — Dual-Platform Delivery: Windows Electron/Inno Setup PowerShell-stdin Loader & macOS Atomic Stealer (AMOS) With Ledger/Trezor Wallet Replacement. Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other Vulnerabilities.
Highlights
- TL-2026-0612 — Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026)
- TL-2026-0614 — Fake ChatGPT Download Site openew[.]app — Dual-Platform Delivery: Windows Electron/Inno Setup PowerShell-stdin Loader & macOS Atomic Stealer (AMOS) With Ledger/Trezor Wallet Replacement
- TL-2026-0616 — Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other Vulnerabilities
- TL-2026-0617 — GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412) Bulletproof Hosting Power Obfuscated JavaScript Backdoor Spam Campaign Targeting Energy, Automotive, FMCG, and Government Finance Across Ukraine, Russia, Poland, Germany, and Transnistria
- TL-2026-0618 — CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic Flaw Enables Unprivileged Local Root via cifs.upcall Namespace Hijack (Public PoC, CVE Pending)
Theme of the day
Critical vulnerabilities and phishing campaigns targeted Windows and Linux systems, with a focus on credential theft and code injection attacks. Exploits and malware attacks were actively used to compromise developer tooling.
- windows
- credential-theft
- cwe-94
- linux
- developer-tooling
Threats published
11 threat lines in the 2026-05-28 debrief, most severe first. Each links to its full profile.
- Notepad++ v8.9.6 — Critical Arbitrary Code Execution via config.xml commandLineInterpreter and shortcuts.xml (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)CRITICAL
- Gogs Authenticated RCE via Argument Injection in git rebase --exec (Unpatched, CVSSv4 9.4, GHSA-qf6p-p7ww-cwr9)CRITICAL
- Silent Ransom Group (Luna Moth / Chatty Spider / UNC3753) — IT Support Impersonation Campaign Targeting US Law Firms (FBI FLASH Advisory, May 2026)HIGH
- Fake ChatGPT Download Site openew[.]app — Dual-Platform Delivery: Windows Electron/Inno Setup PowerShell-stdin Loader & macOS Atomic Stealer (AMOS) With Ledger/Trezor Wallet ReplacementHIGH
- Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other VulnerabilitiesHIGH
- GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412) Bulletproof Hosting Power Obfuscated JavaScript Backdoor Spam Campaign Targeting Energy, Automotive, FMCG, and Government Finance Across Ukraine, Russia, Poland, Germany, and TransnistriaHIGH
- CIFSwitch — Linux Kernel CIFS/SPNEGO Key Validation Logic Flaw Enables Unprivileged Local Root via cifs.upcall Namespace Hijack (Public PoC, CVE Pending)HIGH
- First AI-Agent-Driven Cloud Intrusion — Marimo CVE-2026-39987 RCE → AWS Secrets Manager → SSH Bastion → Internal PostgreSQL Exfiltration (Sysdig TRT, 2026-05-10)HIGH
- VaultJacking — Google Password Manager Vault Theft via Single Captured 6-Digit PIN (PhishU Framework)HIGH
- mouse5212-super-formatter — AI-Generated Malicious npm Package Exfiltrating Anthropic Claude AI /mnt/user-data Sandbox to Attacker GitHub Repository (Malware-Slop Campaign)HIGH
- GreyVibe — Russian-Aligned AI-Assisted Espionage vs Ukraine: LegionRelay/PhantomRelay PowerShell RATs & FallSpy Android Spyware (WithSecure)HIGH
Techniques observed
140 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1005
- T1016
- T1021
- T1021.002
- T1021.004
- T1027
- T1027.002
- T1033
- T1036
- T1036.003
- T1036.005
- T1039
- T1041
- T1048
- T1048.002
- T1052.001
- T1053
- T1056
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.006
- T1059.007
- T1068
- T1070
- T1070.004
- T1070.008
- T1071
- T1071.001
- T1074.002
- T1078
- T1080
- T1082
- T1083
- T1087.004
- T1090.002
- T1090.003
- T1091
- T1098
- T1098.001
- T1098.005
- T1102
- T1102.002
- T1105
- T1106
- T1110
- T1111
- T1112
- T1113
- T1114
- T1114.002
- T1119
- T1123
- T1125
- T1132.001
- T1135
- T1136
- T1140
- T1189
- T1190
- T1195
- T1200
- T1203
- T1204
- T1204.001
- T1204.002
- T1213
- T1217
- T1219
- T1430
- T1485
- T1496
- T1505
- T1518
- T1526
- T1533
- T1539
- T1543.003
- T1546
- T1547
- T1548
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1552.003
- T1552.004
- T1552.005
- T1554
- T1555
- T1555.003
- T1555.005
- T1555.006
- T1556
- T1557
- T1560
- T1562
- T1562.001
- T1564
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1567.002
- T1571
- T1573
- T1574
- T1574.006
- T1580
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.005
- T1585
- T1585.002
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1589
- T1589.003
- T1592
- T1593
- T1595
- T1595.002
- T1606.001
- T1608
- T1608.001
- T1611
- T1613
- T1636
- T1656
- T1657
Threat actors
3 named threat actors across the reports.
- Silent Ransom Group (SRG)
- PhishU Framework operators (technique disclosed by Curtis Brazzell, PhishU, LLC)
- GreyVibe
Nation-state attribution
- Russia
Threat categories
- RANSOMWARE
- MALWARE
- VULNERABILITY
- CLOUD
- PHISHING
Severity breakdown
- critical2
- high9
- medium0
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 75
- network 53
- file 42
- tool 23
- infrastructure 17
- technique 14
- package 10
- entity 8
- malware 6