Summary & highlights
OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs. Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 Address Obfuscation (RFC 4291) to Evade URL Extraction. Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933).
Highlights
- TL-2026-0864 — OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs
- TL-2026-0865 — Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 Address Obfuscation (RFC 4291) to Evade URL Extraction
- TL-2026-0866 — Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933)
- TL-2026-0867 — Pony (Fareit/Siplog) Credential-Stealing Trojan and Downloader
- TL-2026-0869 — Xctdoor Backdoor Delivered via Resume-Themed LNK Files, PowerShell/VBScript Loaders, and ProximityUxHost.exe DLL Side-Loading (Andariel)
Theme of the day
Supply chain attacks and zero-day vulnerabilities are being actively exploited by unknown actors. Multiple high-severity threats enable malware delivery, code execution, and data theft.
- poc-public
- windows
- rce
- remote-code-execution
- espionage
Threats published
20 threat lines in the 2026-06-19 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension Message-Validation Flaws Enable Zero-Interaction Browser Session Compromise Across 11M+ InstallsCRITICAL
- CVE-2026-8713: Avada (Fusion) Builder WordPress Plugin Unauthenticated Path Traversal Arbitrary File DeletionCRITICAL
- Splunk AI Toolkit OS Command Injection in btool Configuration Helper (CVE-2026-20266)CRITICAL
- AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + CWE-306 + CWE-78) in Microsoft AutoGen Studio MCP WebSocket Enables Browsing-Agent Hijack and Host RCECRITICAL
- FortiBleed Campaign: Mass FortiGate SSL VPN / Admin Credential Exposure Affecting ~73,932 Fortinet Firewalls Across 194 Countries (update)CRITICAL
- OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPsHIGH
- Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 Address Obfuscation (RFC 4291) to Evade URL ExtractionHIGH
- Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933)HIGH
- Pony (Fareit/Siplog) Credential-Stealing Trojan and DownloaderHIGH
- Xctdoor Backdoor Delivered via Resume-Themed LNK Files, PowerShell/VBScript Loaders, and ProximityUxHost.exe DLL Side-Loading (Andariel)HIGH
- usbliter8 — checkm8-style unpatchable BootROM/SecureROM exploit for Apple A12/A13 (and S4/S5) devicesHIGH
- CVE-2026-54420 — LiteSpeed cPanel Plugin Symlink-Following (CWE-61) Privilege Escalation to Root on CloudLinux/CageFS Shared Hosting; Added to CISA KEV After In-the-Wild ExploitationHIGH
- AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns an AI Browsing Agent into a Host RCE VectorHIGH
- CVE-2026-4020: Gravity SMTP WordPress Plugin Unauthenticated System-Report Credential Disclosure (Actively Exploited)HIGH
- usbliter8 — Unpatchable SecureROM Boot-Chain Code Execution on Apple A12/A13 (and S4/S5) SoCs via DWC2 USB DMA UnderflowHIGH
- Zscaler ThreatLabz 2026 Report: Encrypted Phishing & AiTM/BiTM Initial-Access Campaigns Targeting the Public SectorHIGH
- Operation Poisson: French-speaking junior operator "Poisson" abuses Tailscale, OpenSSH and RustDesk for C2-independent persistence in 33-day Havoc intrusionHIGH
- Google Cloud Vertex AI Python SDK Bucket-Squatting ("Pickle in the Middle") Enables Cross-Tenant Model Hijacking and RCEHIGH
- FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN Firewalls Across 194 CountriesHIGH
- CVE-2026-55706: 27-Year-Old OpenBSD sppp(4) PAP Authentication Bypass in sppp_pap_input() (update)MEDIUM
Techniques observed
147 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1003.008
- T1005
- T1008
- T1012
- T1014
- T1016
- T1018
- T1021
- T1021.001
- T1021.002
- T1027
- T1033
- T1036
- T1036.005
- T1039
- T1040
- T1041
- T1046
- T1053
- T1055
- T1056
- T1056.003
- T1057
- T1059
- T1059.004
- T1059.007
- T1068
- T1069
- T1070
- T1070.003
- T1070.006
- T1071
- T1071.001
- T1078
- T1078.002
- T1078.004
- T1080
- T1082
- T1083
- T1087
- T1087.002
- T1090
- T1091
- T1095
- T1098
- T1102
- T1102.002
- T1105
- T1106
- T1110
- T1110.001
- T1110.002
- T1110.003
- T1110.004
- T1113
- T1114.002
- T1115
- T1119
- T1132
- T1133
- T1134
- T1135
- T1136
- T1140
- T1176
- T1185
- T1189
- T1190
- T1195
- T1199
- T1200
- T1203
- T1204
- T1211
- T1212
- T1213
- T1217
- T1218
- T1219
- T1222
- T1222.002
- T1482
- T1485
- T1489
- T1490
- T1495
- T1497
- T1499
- T1499.003
- T1499.004
- T1505
- T1505.003
- T1518
- T1526
- T1528
- T1530
- T1531
- T1537
- T1539
- T1542
- T1543
- T1547
- T1548
- T1550
- T1552
- T1552.001
- T1553
- T1555
- T1556
- T1556.006
- T1557
- T1559
- T1562
- T1565
- T1565.001
- T1566
- T1566.002
- T1567
- T1568
- T1571
- T1572
- T1573
- T1574
- T1580
- T1583
- T1585
- T1586
- T1587
- T1588
- T1588.002
- T1589
- T1589.001
- T1592
- T1595
- T1595.002
- T1596
- T1598
- T1602
- T1608
- T1608.005
- T1620
- T1622
- T1648
- T1656
- T1657
- T1659
Threat actors
5 named threat actors across the reports.
- OceanLotus (APT32)
- Andariel
- Paradigm Shift (security research group)
- Poisson
- FortiBleed operators (Russian-speaking cybercriminal collective)
Nation-state attribution
- Vietnam
- North Korea
Threat categories
- APT
- PHISHING
- VULNERABILITY
- MALWARE
- THREAT_INTEL
- DATA_BREACH
Severity breakdown
- critical5
- high14
- medium1
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 156
- file 76
- network 73
- infrastructure 30
- tool 25
- package 15
- entity 12
- malware 8
- technique 7
- domain 3