# Daily Intelligence Briefing — Monday, June 1, 2026

> On 2026-06-01, Threadlinqs published 14 new threat reports, 6 rated critical and 8 high, spanning 103 MITRE ATT&CK techniques and 5 named threat actors. Coverage that day added 126 new detection rules and 262 extracted indicators.

- **Edition:** 2026-06-01 (Monday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-06-01
- **Last updated:** 2026-06-07
- **New threats:** 14
- **Critical / high:** 6 critical, 8 high, 0 medium, 0 low
- **ATT&CK techniques:** 103
- **Threat actors:** 5
- **Indicators (count only):** 262
- **New detection rules (count only):** 126

## Summary & highlights

Instagram Meta AI Account-Recovery Logic Flaw — Chatbot Forwards Password-Reset Codes Bypassing Identity Verification (Account Takeover, Patched). Signal 'Secure Backups' Recovery-Key Phishing — Coordinated Campaign Impersonating Signal Support to Steal Backup Recovery Keys from Journalists, Dissidents & Activists (2026). Famous Chollima (DPRK) Compromises Packagist Package roberts/leads dev Branch — tailwind.js Node.js Loader Uses TRON/Aptos/BNB Blockchain Dead-Drop C2 (EtherHiding-style).

- [TL-2026-0636](https://intel.threadlinqs.com/threat/TL-2026-0636) — Instagram Meta AI Account-Recovery Logic Flaw — Chatbot Forwards Password-Reset Codes Bypassing Identity Verification (Account Takeover, Patched)
- [TL-2026-0637](https://intel.threadlinqs.com/threat/TL-2026-0637) — Signal 'Secure Backups' Recovery-Key Phishing — Coordinated Campaign Impersonating Signal Support to Steal Backup Recovery Keys from Journalists, Dissidents & Activists (2026)
- [TL-2026-0638](https://intel.threadlinqs.com/threat/TL-2026-0638) — Famous Chollima (DPRK) Compromises Packagist Package roberts/leads dev Branch — tailwind.js Node.js Loader Uses TRON/Aptos/BNB Blockchain Dead-Drop C2 (EtherHiding-style)
- [TL-2026-0639](https://intel.threadlinqs.com/threat/TL-2026-0639) — DriveSurge — Initial Access Broker Drives Mass ClickFix & Fake Browser Update Campaign via zTDS (Silent Push)
- [TL-2026-0641](https://intel.threadlinqs.com/threat/TL-2026-0641) — codexui-android npm Supply Chain Attack — OpenAI Codex Auth Token Theft via sentry.anyclaw\[.\]store (friuns2 / BrutalStrike)

## Theme of the day

Critical vulnerabilities and supply chain attacks prevail, targeting account security. Malicious actors exploit flaws to hijack and take over accounts.

financial-motivation, social-engineering, credential-theft, active-exploitation, 2026

## Threats published

- [TL-2026-0642](https://intel.threadlinqs.com/threat/TL-2026-0642) — CRITICAL — Windows Netlogon 0-Click RCE CVE-2026-41089 — Active Exploitation in the Wild (Domain Controller Takeover)
- [TL-2026-0643](https://intel.threadlinqs.com/threat/TL-2026-0643) — CRITICAL — Miasma — @redhat-cloud-services npm Supply Chain Compromise (Mini Shai-Hulud Variant, GitHub Actions OIDC/SLSA Abuse with GCP/Azure Cloud-Identity Theft)
- [TL-2026-0645](https://intel.threadlinqs.com/threat/TL-2026-0645) — CRITICAL — Plesk Obsidian CVE-2026-44962 — Authenticated XPath Injection to OS Command Execution in APS Application Catalog (CVSS 9.9)
- [TL-2026-0649](https://intel.threadlinqs.com/threat/TL-2026-0649) — CRITICAL — Oracle WebLogic Server CVE-2024-21182 — Unauthenticated T3/IIOP Unspecified Vulnerability Added to CISA KEV on Active-Exploitation Evidence
- [TL-2026-0650](https://intel.threadlinqs.com/threat/TL-2026-0650) — CRITICAL — IBM WebSphere Application Server & Liberty Web Server Plug-ins Unauthenticated RCE and HTTP Request Smuggling (CVE-2026-8633, CVE-2026-8620)
- [TL-2026-0651](https://intel.threadlinqs.com/threat/TL-2026-0651) — CRITICAL — Mirasvit Cache Warmer for Magento — Unauthenticated PHP Object Injection RCE (CVE-2026-45247, CVSS 9.8)
- [TL-2026-0636](https://intel.threadlinqs.com/threat/TL-2026-0636) — HIGH — Instagram Meta AI Account-Recovery Logic Flaw — Chatbot Forwards Password-Reset Codes Bypassing Identity Verification (Account Takeover, Patched)
- [TL-2026-0637](https://intel.threadlinqs.com/threat/TL-2026-0637) — HIGH — Signal 'Secure Backups' Recovery-Key Phishing — Coordinated Campaign Impersonating Signal Support to Steal Backup Recovery Keys from Journalists, Dissidents & Activists (2026)
- [TL-2026-0638](https://intel.threadlinqs.com/threat/TL-2026-0638) — HIGH — Famous Chollima (DPRK) Compromises Packagist Package roberts/leads dev Branch — tailwind.js Node.js Loader Uses TRON/Aptos/BNB Blockchain Dead-Drop C2 (EtherHiding-style)
- [TL-2026-0639](https://intel.threadlinqs.com/threat/TL-2026-0639) — HIGH — DriveSurge — Initial Access Broker Drives Mass ClickFix & Fake Browser Update Campaign via zTDS (Silent Push)
- [TL-2026-0641](https://intel.threadlinqs.com/threat/TL-2026-0641) — HIGH — codexui-android npm Supply Chain Attack — OpenAI Codex Auth Token Theft via sentry.anyclaw\[.\]store (friuns2 / BrutalStrike)
- [TL-2026-0647](https://intel.threadlinqs.com/threat/TL-2026-0647) — HIGH — SmartApeSG ClickFix Campaign Delivers NetSupport Manager RAT via Two-Stage Loader (Unidentified Initial RAT, Encoded TCP/443 C2)
- [TL-2026-0648](https://intel.threadlinqs.com/threat/TL-2026-0648) — HIGH — Fake BlueWallet macOS Stealer — AppleScript Dropper Delivers Infostealer with Clipboard Crypto-Address Hijack and Telegram C2
- [TL-2026-0652](https://intel.threadlinqs.com/threat/TL-2026-0652) — HIGH — EndPoint (formerly Midnight) Babuk-Derived Ransomware — Windows/ESXi/NAS Double Extortion with ChaCha20+RSA Encryption and North Korea-Linked Ransom-Note Lineage (CVE-less, ASEC)

## Techniques observed

[T1003](https://intel.threadlinqs.com/technique/T1003), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1007](https://intel.threadlinqs.com/technique/T1007), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.002](https://intel.threadlinqs.com/technique/T1059.002), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1111](https://intel.threadlinqs.com/technique/T1111), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), T1207, [T1210](https://intel.threadlinqs.com/technique/T1210), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1480](https://intel.threadlinqs.com/technique/T1480), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1486](https://intel.threadlinqs.com/technique/T1486), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1496](https://intel.threadlinqs.com/technique/T1496), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1529](https://intel.threadlinqs.com/technique/T1529), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543.001](https://intel.threadlinqs.com/technique/T1543.001), [T1546](https://intel.threadlinqs.com/technique/T1546), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1553.001](https://intel.threadlinqs.com/technique/T1553.001), [T1554](https://intel.threadlinqs.com/technique/T1554), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1558](https://intel.threadlinqs.com/technique/T1558), [T1560](https://intel.threadlinqs.com/technique/T1560), T1562, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.002](https://intel.threadlinqs.com/technique/T1565.002), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1584](https://intel.threadlinqs.com/technique/T1584), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1586](https://intel.threadlinqs.com/technique/T1586), T1586.001, [T1587](https://intel.threadlinqs.com/technique/T1587), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1590](https://intel.threadlinqs.com/technique/T1590), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1620](https://intel.threadlinqs.com/technique/T1620), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657)

## Threat actors

[Famous Chollima](https://intel.threadlinqs.com/actor/Famous%20Chollima), [DriveSurge](https://intel.threadlinqs.com/actor/DriveSurge), friuns2 / BrutalStrike (Igor Levochkin), [SmartApeSG](https://intel.threadlinqs.com/actor/SmartApeSG), TeamPCP (suspected) / Miasma operator

Nation-state attribution: North Korea, North Korea (suspected)

Threat categories: VULNERABILITY, PHISHING, SUPPLY_CHAIN, MALWARE

## Severity breakdown

- critical: 6
- high: 8
- medium: 0
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 262 (behavioral 79, file 63, network 52, malware 16, infrastructure 11, tool 11, package 10, entity 9, technique 8, blockchain 3)
- New detection rules: 126 (100% of the day’s threats covered)

## More editions

- Previous: [2026-05-28](https://intel.threadlinqs.com/debrief/2026-05-28)
- Next: [2026-06-02](https://intel.threadlinqs.com/debrief/2026-06-02)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-06-01
