# Daily Intelligence Briefing — Tuesday, June 2, 2026

> On 2026-06-02, Threadlinqs published 14 new threat reports, 4 rated critical and 9 high, spanning 125 MITRE ATT&CK techniques and 4 named threat actors. Coverage that day added 126 new detection rules and 269 extracted indicators.

- **Edition:** 2026-06-02 (Tuesday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-06-02
- **Last updated:** 2026-06-08
- **New threats:** 14
- **Critical / high:** 4 critical, 9 high, 1 medium, 0 low
- **ATT&CK techniques:** 125
- **Threat actors:** 4
- **Indicators (count only):** 269
- **New detection rules (count only):** 126

## Summary & highlights

New Wave of SVG-Attachment Phishing — application/ecmascript MIME Evasion + XOR-Decoded Browser Redirect (chinougoo.cfd). Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access. StrongDM Desktop CVE-2026-4387 — Plaintext Session State (JWT + Asymmetric Keypair) Enables Credential-less Cross-Host Session Hijack.

- [TL-2026-0653](https://intel.threadlinqs.com/threat/TL-2026-0653) — Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access
- [TL-2026-0654](https://intel.threadlinqs.com/threat/TL-2026-0654) — StrongDM Desktop CVE-2026-4387 — Plaintext Session State (JWT + Asymmetric Keypair) Enables Credential-less Cross-Host Session Hijack
- [TL-2026-0655](https://intel.threadlinqs.com/threat/TL-2026-0655) — Android Framework Integer-Overflow Elevation-of-Privilege 0-Day (CVE-2025-48595) Under Limited Targeted Exploitation — June 2026 Android Security Bulletin
- [TL-2026-0656](https://intel.threadlinqs.com/threat/TL-2026-0656) — Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix Recruitment Portal — TOTPGuard.dll AppDomainManager Hijacking Sideloading Chain Delivering main.dll Implant
- [TL-2026-0658](https://intel.threadlinqs.com/threat/TL-2026-0658) — Mustang Panda PlugX RAT — Multi-Stage Fake Browser Update Chain via G DATA AntiVirus DLL Sideloading (BlueCyber)

## Theme of the day

Critical vulnerabilities and supply chain attacks dominate the threat landscape. Unknown actors are actively exploiting multiple high-severity flaws, including Windows Netlogon and others.

windows, defense-evasion, espionage, social-engineering, apt

## Threats published

- [TL-2026-0661](https://intel.threadlinqs.com/threat/TL-2026-0661) — CRITICAL — KMW CCTV Cameras CVE-2026-5386 — Unauthenticated Remote Administrator Password Reset Enables Full Camera Takeover (CWE-620, CVSS 9.1)
- [TL-2026-0662](https://intel.threadlinqs.com/threat/TL-2026-0662) — CRITICAL — Linux Kernel cgroups v1 release_agent Container Escape & Privilege Escalation (CVE-2022-0492) — Added to CISA KEV (Active Exploitation)
- [TL-2026-0666](https://intel.threadlinqs.com/threat/TL-2026-0666) — CRITICAL — WordPress Kirki Plugin CVE-2026-8206 — Unauthenticated Account Takeover via Password-Reset Email Hijack (Active Exploitation, ~500K Sites)
- [TL-2026-0667](https://intel.threadlinqs.com/threat/TL-2026-0667) — CRITICAL — VSCode Webview 1-Click GitHub OAuth Token Theft — postMessage Keydown-Forwarding Boundary Bypass on github.dev (Full Disclosure, Public PoC)
- [TL-2026-0653](https://intel.threadlinqs.com/threat/TL-2026-0653) — HIGH — Gamaredon (Russia/FSB) "GammaWorm" — VBScript Worm Hidden in NTFS ADS with Cloud-Service Dead Drop Resolver C2 (Gamma Toolset) vs Ukraine, WinRAR CVE-2025-8088 Initial Access
- [TL-2026-0654](https://intel.threadlinqs.com/threat/TL-2026-0654) — HIGH — StrongDM Desktop CVE-2026-4387 — Plaintext Session State (JWT + Asymmetric Keypair) Enables Credential-less Cross-Host Session Hijack
- [TL-2026-0655](https://intel.threadlinqs.com/threat/TL-2026-0655) — HIGH — Android Framework Integer-Overflow Elevation-of-Privilege 0-Day (CVE-2025-48595) Under Limited Targeted Exploitation — June 2026 Android Security Bulletin
- [TL-2026-0656](https://intel.threadlinqs.com/threat/TL-2026-0656) — HIGH — Nimbus Manticore (UNC1549 / Smoke Sandstorm) Fake Ebix Recruitment Portal — TOTPGuard.dll AppDomainManager Hijacking Sideloading Chain Delivering main.dll Implant
- [TL-2026-0658](https://intel.threadlinqs.com/threat/TL-2026-0658) — HIGH — Mustang Panda PlugX RAT — Multi-Stage Fake Browser Update Chain via G DATA AntiVirus DLL Sideloading (BlueCyber)
- [TL-2026-0659](https://intel.threadlinqs.com/threat/TL-2026-0659) — HIGH — SolyxImmortal Python Infostealer — Chromium/Firefox Credential & Cookie Theft, Keylogging, Discord Webhook Exfiltration (Turkish-Speaking Actor)
- [TL-2026-0660](https://intel.threadlinqs.com/threat/TL-2026-0660) — HIGH — Claude Code GitHub Actions — checkWritePermissions \[bot\] Trust Bypass Enables Unauthenticated Repo Compromise via Prompt Injection + OIDC Token Theft (RyotaK / GMO Flatt Security)
- [TL-2026-0663](https://intel.threadlinqs.com/threat/TL-2026-0663) — HIGH — WordPress Malware Abuses Steam Community Profiles for C2 — Unicode Steganography, AES-256-CTR Payloads, Cookie-Auth PHP Backdoor + JS Injection (~1,980 Sites, GoDaddy)
- [TL-2026-0665](https://intel.threadlinqs.com/threat/TL-2026-0665) — HIGH — WeedHack MaaS Infostealer — Trojanized Minecraft Mods/Clients via YouTube + SEO Poisoning, 36-Browser & Crypto-Wallet Credential Theft with Paid RAT Tier (CVE-N/A)
- [TL-2026-0657](https://intel.threadlinqs.com/threat/TL-2026-0657) — MEDIUM — New Wave of SVG-Attachment Phishing — application/ecmascript MIME Evasion + XOR-Decoded Browser Redirect (chinougoo.cfd)

## Techniques observed

T1001.002, [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1025](https://intel.threadlinqs.com/technique/T1025), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1027.002](https://intel.threadlinqs.com/technique/T1027.002), [T1027.010](https://intel.threadlinqs.com/technique/T1027.010), [T1027.013](https://intel.threadlinqs.com/technique/T1027.013), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1047](https://intel.threadlinqs.com/technique/T1047), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1053.005](https://intel.threadlinqs.com/technique/T1053.005), [T1056.001](https://intel.threadlinqs.com/technique/T1056.001), [T1056.003](https://intel.threadlinqs.com/technique/T1056.003), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.001](https://intel.threadlinqs.com/technique/T1059.001), [T1059.003](https://intel.threadlinqs.com/technique/T1059.003), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.005](https://intel.threadlinqs.com/technique/T1059.005), [T1059.006](https://intel.threadlinqs.com/technique/T1059.006), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1080](https://intel.threadlinqs.com/technique/T1080), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1091](https://intel.threadlinqs.com/technique/T1091), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.001](https://intel.threadlinqs.com/technique/T1102.001), T1102.003, [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1112](https://intel.threadlinqs.com/technique/T1112), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1120](https://intel.threadlinqs.com/technique/T1120), [T1123](https://intel.threadlinqs.com/technique/T1123), [T1125](https://intel.threadlinqs.com/technique/T1125), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195.002](https://intel.threadlinqs.com/technique/T1195.002), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1204.001](https://intel.threadlinqs.com/technique/T1204.001), [T1204.002](https://intel.threadlinqs.com/technique/T1204.002), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1222](https://intel.threadlinqs.com/technique/T1222), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1491](https://intel.threadlinqs.com/technique/T1491), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1547.001](https://intel.threadlinqs.com/technique/T1547.001), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1548.002](https://intel.threadlinqs.com/technique/T1548.002), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1550.001](https://intel.threadlinqs.com/technique/T1550.001), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1555.003](https://intel.threadlinqs.com/technique/T1555.003), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1560.001](https://intel.threadlinqs.com/technique/T1560.001), T1562, T1562.001, [T1564](https://intel.threadlinqs.com/technique/T1564), [T1564.001](https://intel.threadlinqs.com/technique/T1564.001), [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.001](https://intel.threadlinqs.com/technique/T1566.001), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1567.004](https://intel.threadlinqs.com/technique/T1567.004), [T1569](https://intel.threadlinqs.com/technique/T1569), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1573.001](https://intel.threadlinqs.com/technique/T1573.001), [T1573.002](https://intel.threadlinqs.com/technique/T1573.002), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1574.001](https://intel.threadlinqs.com/technique/T1574.001), T1574.014, [T1583](https://intel.threadlinqs.com/technique/T1583), [T1583.001](https://intel.threadlinqs.com/technique/T1583.001), [T1583.006](https://intel.threadlinqs.com/technique/T1583.006), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1587.001](https://intel.threadlinqs.com/technique/T1587.001), [T1588](https://intel.threadlinqs.com/technique/T1588), T1588.004, [T1589](https://intel.threadlinqs.com/technique/T1589), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1598](https://intel.threadlinqs.com/technique/T1598), T1598.002, [T1606](https://intel.threadlinqs.com/technique/T1606), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.006](https://intel.threadlinqs.com/technique/T1608.006), [T1609](https://intel.threadlinqs.com/technique/T1609), [T1611](https://intel.threadlinqs.com/technique/T1611), [T1613](https://intel.threadlinqs.com/technique/T1613), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1622](https://intel.threadlinqs.com/technique/T1622), T1659

## Threat actors

[Gamaredon](https://intel.threadlinqs.com/actor/Gamaredon), [Nimbus Manticore](https://intel.threadlinqs.com/actor/Nimbus%20Manticore), Mustang Panda (Chinese state-sponsored), WeedHack Operators (Unknown)

Nation-state attribution: Russia, Iran, China

Threat categories: PHISHING, MALWARE, VULNERABILITY

## Severity breakdown

- critical: 4
- high: 9
- medium: 1
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 269 (behavioral 101, network 68, file 65, infrastructure 10, tool 8, technique 7, malware 5, package 3, entity 2)
- New detection rules: 126 (100% of the day’s threats covered)

## More editions

- Previous: [2026-06-01](https://intel.threadlinqs.com/debrief/2026-06-01)
- Next: [2026-06-09](https://intel.threadlinqs.com/debrief/2026-06-09)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-06-02
