Summary & highlights
Instagram Meta AI Account-Recovery Logic Flaw — Chatbot Forwards Password-Reset Codes Bypassing Identity Verification (Account Takeover, Patched). Signal 'Secure Backups' Recovery-Key Phishing — Coordinated Campaign Impersonating Signal Support to Steal Backup Recovery Keys from Journalists, Dissidents & Activists (2026). Famous Chollima (DPRK) Compromises Packagist Package roberts/leads dev Branch — tailwind.js Node.js Loader Uses TRON/Aptos/BNB Blockchain Dead-Drop C2 (EtherHiding-style).
Highlights
- TL-2026-0636 — Instagram Meta AI Account-Recovery Logic Flaw — Chatbot Forwards Password-Reset Codes Bypassing Identity Verification (Account Takeover, Patched)
- TL-2026-0637 — Signal 'Secure Backups' Recovery-Key Phishing — Coordinated Campaign Impersonating Signal Support to Steal Backup Recovery Keys from Journalists, Dissidents & Activists (2026)
- TL-2026-0638 — Famous Chollima (DPRK) Compromises Packagist Package roberts/leads dev Branch — tailwind.js Node.js Loader Uses TRON/Aptos/BNB Blockchain Dead-Drop C2 (EtherHiding-style)
- TL-2026-0639 — DriveSurge — Initial Access Broker Drives Mass ClickFix & Fake Browser Update Campaign via zTDS (Silent Push)
- TL-2026-0641 — codexui-android npm Supply Chain Attack — OpenAI Codex Auth Token Theft via sentry.anyclaw[.]store (friuns2 / BrutalStrike)
Theme of the day
Critical vulnerabilities and supply chain attacks prevail, targeting account security. Malicious actors exploit flaws to hijack and take over accounts.
- financial-motivation
- social-engineering
- credential-theft
- active-exploitation
- 2026
Threats published
14 threat lines in the 2026-06-01 debrief, most severe first. Each links to its full profile.
- Windows Netlogon 0-Click RCE CVE-2026-41089 — Active Exploitation in the Wild (Domain Controller Takeover)CRITICAL
- Miasma — @redhat-cloud-services npm Supply Chain Compromise (Mini Shai-Hulud Variant, GitHub Actions OIDC/SLSA Abuse with GCP/Azure Cloud-Identity Theft)CRITICAL
- Plesk Obsidian CVE-2026-44962 — Authenticated XPath Injection to OS Command Execution in APS Application Catalog (CVSS 9.9)CRITICAL
- Oracle WebLogic Server CVE-2024-21182 — Unauthenticated T3/IIOP Unspecified Vulnerability Added to CISA KEV on Active-Exploitation EvidenceCRITICAL
- IBM WebSphere Application Server & Liberty Web Server Plug-ins Unauthenticated RCE and HTTP Request Smuggling (CVE-2026-8633, CVE-2026-8620)CRITICAL
- Mirasvit Cache Warmer for Magento — Unauthenticated PHP Object Injection RCE (CVE-2026-45247, CVSS 9.8)CRITICAL
- Instagram Meta AI Account-Recovery Logic Flaw — Chatbot Forwards Password-Reset Codes Bypassing Identity Verification (Account Takeover, Patched)HIGH
- Signal 'Secure Backups' Recovery-Key Phishing — Coordinated Campaign Impersonating Signal Support to Steal Backup Recovery Keys from Journalists, Dissidents & Activists (2026)HIGH
- Famous Chollima (DPRK) Compromises Packagist Package roberts/leads dev Branch — tailwind.js Node.js Loader Uses TRON/Aptos/BNB Blockchain Dead-Drop C2 (EtherHiding-style)HIGH
- DriveSurge — Initial Access Broker Drives Mass ClickFix & Fake Browser Update Campaign via zTDS (Silent Push)HIGH
- codexui-android npm Supply Chain Attack — OpenAI Codex Auth Token Theft via sentry.anyclaw[.]store (friuns2 / BrutalStrike)HIGH
- SmartApeSG ClickFix Campaign Delivers NetSupport Manager RAT via Two-Stage Loader (Unidentified Initial RAT, Encoded TCP/443 C2)HIGH
- Fake BlueWallet macOS Stealer — AppleScript Dropper Delivers Infostealer with Clipboard Crypto-Address Hijack and Telegram C2HIGH
- EndPoint (formerly Midnight) Babuk-Derived Ransomware — Windows/ESXi/NAS Double Extortion with ChaCha20+RSA Encryption and North Korea-Linked Ransom-Note Lineage (CVE-less, ASEC)HIGH
Techniques observed
103 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1005
- T1007
- T1027
- T1036
- T1041
- T1053
- T1055
- T1059
- T1059.002
- T1059.004
- T1068
- T1070
- T1071
- T1071.001
- T1078
- T1082
- T1083
- T1087
- T1098
- T1102
- T1102.002
- T1105
- T1106
- T1110
- T1111
- T1115
- T1132
- T1135
- T1136
- T1140
- T1189
- T1190
- T1195
- T1199
- T1203
- T1204
- T1204.002
- T1207
- T1210
- T1211
- T1218
- T1219
- T1480
- T1482
- T1485
- T1486
- T1489
- T1490
- T1496
- T1497
- T1499
- T1505
- T1505.003
- T1526
- T1528
- T1529
- T1530
- T1531
- T1539
- T1543.001
- T1546
- T1547
- T1548
- T1550
- T1552
- T1552.001
- T1553.001
- T1554
- T1555
- T1555.003
- T1556
- T1558
- T1560
- T1562
- T1564
- T1564.001
- T1565
- T1565.002
- T1566
- T1567
- T1571
- T1573
- T1573.001
- T1574
- T1580
- T1583
- T1584
- T1585
- T1586
- T1586.001
- T1587
- T1588
- T1589
- T1590
- T1592
- T1595
- T1598
- T1606
- T1608
- T1620
- T1656
- T1657
Threat actors
5 named threat actors across the reports.
- Famous Chollima
- DriveSurge
- friuns2 / BrutalStrike (Igor Levochkin)
- SmartApeSG
- TeamPCP (suspected) / Miasma operator
Nation-state attribution
- North Korea
- North Korea (suspected)
Threat categories
- VULNERABILITY
- PHISHING
- SUPPLY_CHAIN
- MALWARE
Severity breakdown
- critical6
- high8
- medium0
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 79
- file 63
- network 52
- malware 16
- infrastructure 11
- tool 11
- package 10
- entity 9
- technique 8
- blockchain 3