Summary & highlights
SHADOWBYT3$ Claims Breach of Nintendo via Third-Party TINYpulse HR-Engagement SaaS Exposure (~859 MB, $2M Extortion). CVE-2026-20262: Cisco Catalyst SD-WAN Manager (vManage) Arbitrary File Upload Flaw Exploited as Zero-Day for Root Privilege Escalation. HAMLOCK: Split Hardware/Software Neural-Network Backdoor Evading ML Trojan Defenses (arXiv:2510.19145, USENIX Security 2026).
Highlights
- TL-2026-0798 — HAMLOCK: Split Hardware/Software Neural-Network Backdoor Evading ML Trojan Defenses (arXiv:2510.19145, USENIX Security 2026)
- TL-2026-0799 — Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares[.]com / wetransfer[.]ICU SEO-Poisoning Operation)
- TL-2026-0802 — NarwhalRAT: APT37 Python-based RAT delivered via LNK/PowerShell/Python loader chain in Microsoft-themed Korean spear-phishing campaign
- TL-2026-0803 — Dark Web Data-Leak Roundup (June 2026): Iran Hajj Organization (168M records), AdressFakta/SUPEReROI Sweden (5.4M+), Chrysler/Salesforce (1TB+, Everest Ransomware), and Crypto-Platform Lead Lists
- TL-2026-0804 — Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted
Theme of the day
Unknown actors are actively exploiting critical vulnerabilities in Microsoft Exchange, Splunk Enterprise, and phpBB. These exploits enable authentication bypass, cross-site scripting, and remote code execution.
- defense-evasion
- masquerading
- persistence
- obfuscation
- extortion
Threats published
17 threat lines in the 2026-06-15 debrief, most severe first. Each links to its full profile.
- Wazuh Manager 5.0 inventory_sync NDJSON Injection in OpenSearch _bulk API (GHSA-ff9g-85jq-r3g3, CVSS 10.0)CRITICAL
- Awesome Motive WordPress Plugin Supply-Chain Attack (OptinMonster, TrustPulse, PushEngage) Delivering Self-Hiding Backdoor via Poisoned CDN JavaScriptCRITICAL
- SearchLeak: Microsoft 365 Copilot Enterprise One-Click Data Exfiltration (CVE-2026-42824)CRITICAL
- Velvet Ant (Operation Highland): Backdoored Linux PAM and OpenSSH for ~Decade-Long Espionage PersistenceCRITICAL
- HAMLOCK: Split Hardware/Software Neural-Network Backdoor Evading ML Trojan Defenses (arXiv:2510.19145, USENIX Security 2026)HIGH
- Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares[.]com / wetransfer[.]ICU SEO-Poisoning Operation)HIGH
- NarwhalRAT: APT37 Python-based RAT delivered via LNK/PowerShell/Python loader chain in Microsoft-themed Korean spear-phishing campaignHIGH
- Dark Web Data-Leak Roundup (June 2026): Iran Hajj Organization (168M records), AdressFakta/SUPEReROI Sweden (5.4M+), Chrysler/Salesforce (1TB+, Everest Ransomware), and Crypto-Platform Lead ListsHIGH
- Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and ExtortedHIGH
- The Quarry PhaaS/MaaS Operation Impersonating IRS and SSA to Deliver ConnectWise ScreenConnect RMM AccessHIGH
- Velvet Ant (China-Nexus) 'Operation Highland' — Backdoored pam_unix.so PAM Module and Trojanized OpenSSH for Decade-Long Credential Theft in an Isolated NetworkHIGH
- Azure Blob Storage Ransomware: Four Storage-Encryption Abuse Methods (BlackCat/ALPHV, STORM-0501)HIGH
- SearchJack: 23 Malicious Chrome Extensions Hijack Search Queries via chrome_settings_overrides (Yahoo Affiliate Monetization)HIGH
- North Korean Threat Actors Weaponize Developer Tools (VS Code, npm, GitHub) for Cross-Platform Malware Delivery — Contagious Interview / UNK_DeadDropHIGH
- EtherRAT: Node.js Remote Access Trojan with Ethereum Blockchain C2 Resolution and Per-Execution Self-ReobfuscationHIGH
- SHADOWBYT3$ Claims Breach of Nintendo via Third-Party TINYpulse HR-Engagement SaaS Exposure (~859 MB, $2M Extortion)MEDIUM
- CVE-2026-20262: Cisco Catalyst SD-WAN Manager (vManage) Arbitrary File Upload Flaw Exploited as Zero-Day for Root Privilege EscalationMEDIUM
Techniques observed
148 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0010
- AML.T0015
- AML.T0018
- AML.T0031
- AML.T0048
- T1003
- T1005
- T1010
- T1014
- T1020
- T1021.004
- T1025
- T1027
- T1033
- T1036
- T1036.004
- T1036.005
- T1037.004
- T1040
- T1041
- T1046
- T1048
- T1053
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.007
- T1068
- T1070
- T1070.002
- T1070.006
- T1071
- T1071.001
- T1074
- T1078
- T1078.001
- T1082
- T1083
- T1087
- T1090
- T1090.001
- T1098
- T1098.004
- T1102
- T1104
- T1105
- T1110.001
- T1111
- T1112
- T1113
- T1114
- T1115
- T1119
- T1123
- T1129
- T1132
- T1133
- T1136
- T1140
- T1176
- T1185
- T1189
- T1190
- T1195
- T1199
- T1204
- T1204.002
- T1213
- T1217
- T1218
- T1218.007
- T1219
- T1222
- T1484
- T1485
- T1486
- T1490
- T1491.001
- T1497
- T1505
- T1518
- T1526
- T1528
- T1530
- T1537
- T1538
- T1539
- T1542
- T1543
- T1543.002
- T1546
- T1547.001
- T1548
- T1550
- T1550.004
- T1552
- T1552.001
- T1553
- T1554
- T1555
- T1556
- T1556.003
- T1559
- T1562
- T1562.001
- T1562.006
- T1564
- T1564.001
- T1565
- T1565.001
- T1565.002
- T1566
- T1567
- T1568
- T1569.002
- T1571
- T1572
- T1573
- T1574
- T1574.006
- T1578
- T1580
- T1583
- T1583.001
- T1583.006
- T1584
- T1585
- T1586
- T1587
- T1588
- T1589
- T1591
- T1593
- T1595
- T1598
- T1608
- T1608.001
- T1608.004
- T1608.005
- T1608.006
- T1621
- T1650
- T1656
- T1657
Threat actors
9 named threat actors across the reports.
- SHADOWBYT3$
- APT37
- Everest ransomware group; multiple unnamed data brokers; APT43/Kimsuky (claimed, unverified)
- ShinyHunters (UNC6040 / UNC6240)
- RockyBelling
- Velvet Ant
- STORM-0501 / BlackCat (ALPHV)
- SearchJack operators (search-affiliate broker network)
- Contagious Interview (Famous Chollima)
Nation-state attribution
- North Korea
- North Korea (APT43/Kimsuky claim, unverified); Unknown (data brokers)
- China
Threat categories
- DATA_BREACH
- VULNERABILITY
- RESEARCH
- MALWARE
- APT
- PHISHING
- RANSOMWARE
- SUPPLY_CHAIN
Severity breakdown
- critical4
- high11
- medium2
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 131
- behavioral 113
- file 101
- tool 23
- entity 21
- infrastructure 20
- malware 15
- package 10
- technique 5