Summary & highlights
New Wave of SVG-Attachment Phishing — application/ecmascript MIME Evasion + XOR-Decoded Browser Redirect (chinougoo.cfd). Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access. StrongDM Desktop CVE-2026-4387 — Plaintext Session State (JWT + Asymmetric Keypair) Enables Credential-less Cross-Host Session Hijack.
Highlights
- TL-2026-0653 — Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access
- TL-2026-0654 — StrongDM Desktop CVE-2026-4387 — Plaintext Session State (JWT + Asymmetric Keypair) Enables Credential-less Cross-Host Session Hijack
- TL-2026-0655 — Android Framework Integer-Overflow Elevation-of-Privilege 0-Day (CVE-2025-48595) Under Limited Targeted Exploitation — June 2026 Android Security Bulletin
- TL-2026-0656 — Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix Recruitment Portal — TOTPGuard.dll AppDomainManager Hijacking Sideloading Chain Delivering main.dll Implant
- TL-2026-0658 — Mustang Panda PlugX RAT — Multi-Stage Fake Browser Update Chain via G DATA AntiVirus DLL Sideloading (BlueCyber)
Theme of the day
Critical vulnerabilities and supply chain attacks dominate the threat landscape. Unknown actors are actively exploiting multiple high-severity flaws, including Windows Netlogon and others.
- windows
- defense-evasion
- espionage
- social-engineering
- apt
Threats published
14 threat lines in the 2026-06-02 debrief, most severe first. Each links to its full profile.
- KMW CCTV Cameras CVE-2026-5386 — Unauthenticated Remote Administrator Password Reset Enables Full Camera Takeover (CWE-620, CVSS 9.1)CRITICAL
- Linux Kernel cgroups v1 release_agent Container Escape & Privilege Escalation (CVE-2022-0492) — Added to CISA KEV (Active Exploitation)CRITICAL
- WordPress Kirki Plugin CVE-2026-8206 — Unauthenticated Account Takeover via Password-Reset Email Hijack (Active Exploitation, ~500K Sites)CRITICAL
- VSCode Webview 1-Click GitHub OAuth Token Theft — postMessage Keydown-Forwarding Boundary Bypass on github.dev (Full Disclosure, Public PoC)CRITICAL
- Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial AccessHIGH
- StrongDM Desktop CVE-2026-4387 — Plaintext Session State (JWT + Asymmetric Keypair) Enables Credential-less Cross-Host Session HijackHIGH
- Android Framework Integer-Overflow Elevation-of-Privilege 0-Day (CVE-2025-48595) Under Limited Targeted Exploitation — June 2026 Android Security BulletinHIGH
- Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix Recruitment Portal — TOTPGuard.dll AppDomainManager Hijacking Sideloading Chain Delivering main.dll ImplantHIGH
- Mustang Panda PlugX RAT — Multi-Stage Fake Browser Update Chain via G DATA AntiVirus DLL Sideloading (BlueCyber)HIGH
- SolyxImmortal Python Infostealer — Chromium/Firefox Credential & Cookie Theft, Keylogging, Discord Webhook Exfiltration (Turkish-Speaking Actor)HIGH
- Claude Code GitHub Actions — checkWritePermissions [bot] Trust Bypass Enables Unauthenticated Repo Compromise via Prompt Injection + OIDC Token Theft (RyotaK / GMO Flatt Security)HIGH
- WordPress Malware Abuses Steam Community Profiles for C2 — Unicode Steganography, AES-256-CTR Payloads, Cookie-Auth PHP Backdoor + JS Injection (~1,980 Sites, GoDaddy)HIGH
- WeedHack MaaS Infostealer — Trojanized Minecraft Mods/Clients via YouTube + SEO Poisoning, 36-Browser & Crypto-Wallet Credential Theft with Paid RAT Tier (CVE-N/A)HIGH
- New Wave of SVG-Attachment Phishing — application/ecmascript MIME Evasion + XOR-Decoded Browser Redirect (chinougoo.cfd)MEDIUM
Techniques observed
125 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001.002
- T1005
- T1008
- T1021
- T1025
- T1027
- T1027.002
- T1027.010
- T1027.013
- T1036
- T1036.005
- T1041
- T1047
- T1053
- T1053.005
- T1056.001
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1071
- T1071.001
- T1078
- T1080
- T1082
- T1083
- T1087
- T1091
- T1098
- T1102
- T1102.001
- T1102.003
- T1105
- T1106
- T1112
- T1113
- T1120
- T1123
- T1125
- T1133
- T1136
- T1140
- T1176
- T1189
- T1190
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1211
- T1212
- T1213
- T1217
- T1218
- T1222
- T1489
- T1491
- T1505
- T1505.003
- T1518
- T1526
- T1528
- T1531
- T1539
- T1543
- T1547
- T1547.001
- T1548
- T1548.002
- T1550
- T1550.001
- T1552
- T1552.001
- T1553
- T1555.003
- T1556
- T1560.001
- T1562
- T1562.001
- T1564
- T1564.001
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1567
- T1567.004
- T1569
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.001
- T1574.014
- T1583
- T1583.001
- T1583.006
- T1585
- T1587
- T1587.001
- T1588
- T1588.004
- T1589
- T1592
- T1595
- T1598
- T1598.002
- T1606
- T1608
- T1608.006
- T1609
- T1611
- T1613
- T1620
- T1622
- T1659
Threat actors
4 named threat actors across the reports.
- Gamaredon
- Nimbus Manticore
- Mustang Panda (Chinese state-sponsored)
- WeedHack Operators (Unknown)
Nation-state attribution
- Russia
- Iran
- China
Threat categories
- PHISHING
- MALWARE
- VULNERABILITY
Severity breakdown
- critical4
- high9
- medium1
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 101
- network 68
- file 65
- infrastructure 10
- tool 8
- technique 7
- malware 5
- package 3
- entity 2