Summary & highlights
Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled Vivo / Amazon Fire TV Apps. Research: ~90% of Leaked Malware Source Code Contains Exploitable Software Weaknesses (Vouvoutsis, Patsakis & Casino, arXiv:2606.05945). RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage Chain.
Highlights
- TL-2026-0722 — RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage Chain
- TL-2026-0723 — Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations
- TL-2026-0724 — DriveSurge: Initial Access Broker Hijacks Thousands of Trusted Websites for ClickFix and FakeUpdate Malware Delivery via zTDS
- TL-2026-0725 — Google Chrome V8 Out-of-Bounds Read/Write Zero-Day CVE-2026-11645 Exploited in the Wild
- TL-2026-0726 — Lazarus Group npm Brandjacking Campaign — buffer-utilities Multi-Stage Staging Framework (sonatype-2026-003558)
Theme of the day
Active exploitation of critical vulnerabilities in multiple platforms and supply chains threatens various sectors. Unknown actors and Qilin ransomware are exploiting vulnerabilities in UniFi, TeamPCP, and Check Point VPNs.
- windows
- credential-theft
- remote-code-execution
- active-exploitation
- espionage
Threats published
21 threat lines in the 2026-06-09 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- CVE-2026-42271: LiteLLM AI Gateway OS Command Injection via MCP Test Endpoints, Chained to Unauthenticated RCE with CVE-2026-48710 (CISA KEV, Active Exploitation)CRITICAL
- Shai-Hulud 'Hades' Campaign — Trojanized PyPI Packages Auto-Execute Bun Credential Stealer via Python Wheel Startup Hooks (*-setup.pth)CRITICAL
- Google Chrome V8 Zero-Day CVE-2026-11645 Out-of-Bounds Read/Write Exploited in the WildCRITICAL
- Miasma Supply Chain Attack Toolkit Open-Sourced on GitHub (Shai-Hulud / Mini Shai-Hulud Variant)CRITICAL
- CVE-2026-42271: LiteLLM MCP Server Command Injection Under Active Exploitation, Chained with CVE-2026-48710 (Starlette BadHost) for Unauthenticated RCECRITICAL
- EndPoint (Midnight) Ransomware — Babuk-derived double-extortion targeting Windows, ESXi, and NASCRITICAL
- RemotePE: In-Memory Lazarus RAT Delivered via DPAPILoader and RemotePELoader Multi-Stage ChainHIGH
- Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian OrganizationsHIGH
- DriveSurge: Initial Access Broker Hijacks Thousands of Trusted Websites for ClickFix and FakeUpdate Malware Delivery via zTDSHIGH
- Google Chrome V8 Out-of-Bounds Read/Write Zero-Day CVE-2026-11645 Exploited in the WildHIGH
- Lazarus Group npm Brandjacking Campaign — buffer-utilities Multi-Stage Staging Framework (sonatype-2026-003558)HIGH
- APT28 PixyNetLoader — Loader Evolution 2024–2026 (Operation Neusploit, CVE-2026-21509)HIGH
- NSO Group Pegasus Spyware — WhatsApp Spearphishing Campaign Alleged in Meta Contempt Complaint (June 2026)HIGH
- CVE-2026-23111: Linux Kernel nf_tables Use-After-Free Enables Local Privilege Escalation and Container EscapeHIGH
- Microsoft June 2026 Patch Tuesday — 198+ CVEs Including CVE-2026-49160 (HTTP.sys 'HTTP/2 Bomb' DoS), CVE-2026-50507 (BitLocker 'YellowKey' Bypass) and CVE-2026-45586 (Collaborative Translation Framework EoP)HIGH
- Miasma / Shai-Hulud Supply-Chain Campaign Pushes Password-Stealing Malware via Compromised Microsoft GitHub Repos (durabletask PyPI 1.4.1-1.4.3)HIGH
- CVE-2026-11645: Actively Exploited V8 Out-of-Bounds Memory Access Zero-Day in Google ChromeHIGH
- NFCShare Android Banking Malware Steals EMV Card Data and PINs via Weaponized European Banking Apps (com.modol.nap)HIGH
- APT Spear-Phishing Campaign Targeting South Korean Entities (April 2026) — LNK/PowerShell Loaders, AutoIt, XenoRAT, Infostealers/Keyloggers/Backdoors (update)HIGH
- Android.MagicAd Trojan Floods Devices with Ads via Xiaomi GetApps, Samsung Galaxy Store, and Preinstalled Vivo / Amazon Fire TV AppsMEDIUM
- Research: ~90% of Leaked Malware Source Code Contains Exploitable Software Weaknesses (Vouvoutsis, Patsakis & Casino, arXiv:2606.05945)
Techniques observed
168 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1003.001
- T1005
- T1006
- T1008
- T1021
- T1025
- T1027
- T1033
- T1036
- T1036.004
- T1041
- T1053
- T1055
- T1056
- T1056.001
- T1057
- T1059
- T1059.004
- T1059.006
- T1059.007
- T1068
- T1070
- T1070.004
- T1071
- T1071.001
- T1078
- T1080
- T1082
- T1083
- T1087
- T1090
- T1095
- T1098
- T1102
- T1105
- T1106
- T1112
- T1113
- T1114
- T1115
- T1119
- T1123
- T1125
- T1129
- T1132
- T1132.001
- T1133
- T1135
- T1137
- T1140
- T1185
- T1187
- T1189
- T1190
- T1195
- T1200
- T1203
- T1204
- T1210
- T1211
- T1212
- T1218
- T1406.001
- T1406.002
- T1407
- T1409
- T1417
- T1418
- T1422
- T1426
- T1429
- T1430
- T1437
- T1437.001
- T1456
- T1474.002
- T1474.003
- T1480
- T1480.001
- T1485
- T1486
- T1489
- T1490
- T1496
- T1497
- T1498
- T1499
- T1516
- T1518
- T1518.001
- T1526
- T1528
- T1530
- T1537
- T1539
- T1541
- T1542
- T1543
- T1543.003
- T1546
- T1547
- T1548
- T1552
- T1552.001
- T1552.005
- T1553
- T1554
- T1555
- T1555.003
- T1556
- T1557
- T1560
- T1560.001
- T1562
- T1562.001
- T1562.006
- T1564
- T1566
- T1566.002
- T1566.003
- T1567
- T1568
- T1570
- T1571
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.001
- T1574.002
- T1575
- T1583
- T1583.001
- T1583.003
- T1584
- T1585
- T1586
- T1587
- T1587.001
- T1588
- T1588.005
- T1589
- T1592
- T1592.004
- T1595
- T1598
- T1603
- T1608
- T1608.004
- T1611
- T1613
- T1614
- T1620
- T1624.001
- T1628
- T1628.001
- T1628.002
- T1630
- T1633.001
- T1636
- T1643
- T1646
- T1655.001
- T1656
- T1657
- T1658
- T1660
Threat actors
10 named threat actors across the reports.
- Lazarus Group (financially-motivated subgroup)
- Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066)
- DriveSurge
- Lazarus Group
- APT28 / Fancy Bear
- NSO Group
- Shai-Hulud worm operators (unattributed)
- TeamPCP
- TeamPCP (suspected; copycat possible)
- North Korea-linked operators (EndPoint/Midnight)
Nation-state attribution
- North Korea
- Russia
- Israel
- North Korea (suspected, low confidence)
Threat categories
- MALWARE
- THREAT_INTEL
- VULNERABILITY
- SUPPLY_CHAIN
- ZERO_DAY
- RANSOMWARE
- APT
Severity breakdown
- critical6
- high13
- medium1
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 158
- file 129
- network 81
- technique 33
- package 27
- entity 24
- infrastructure 24
- malware 20
- tool 20