# Daily Intelligence Briefing — Friday, June 19, 2026

> On 2026-06-19, Threadlinqs published 18 new threat reports and updated 2, 5 rated critical and 14 high, spanning 147 MITRE ATT&CK techniques and 5 named threat actors. Coverage that day added 180 new detection rules and 405 extracted indicators.

- **Edition:** 2026-06-19 (Friday)
- **Canonical:** https://intel.threadlinqs.com/debrief/2026-06-19
- **Last updated:** 2026-06-25
- **New threats:** 18 (2 updated)
- **Critical / high:** 5 critical, 14 high, 1 medium, 0 low
- **ATT&CK techniques:** 147
- **Threat actors:** 5
- **Indicators (count only):** 405
- **New detection rules (count only):** 180

## Summary & highlights

OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs. Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 Address Obfuscation (RFC 4291) to Evade URL Extraction. Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933).

- [TL-2026-0864](https://intel.threadlinqs.com/threat/TL-2026-0864) — OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs
- [TL-2026-0865](https://intel.threadlinqs.com/threat/TL-2026-0865) — Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 Address Obfuscation (RFC 4291) to Evade URL Extraction
- [TL-2026-0866](https://intel.threadlinqs.com/threat/TL-2026-0866) — Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933)
- [TL-2026-0867](https://intel.threadlinqs.com/threat/TL-2026-0867) — Pony (Fareit/Siplog) Credential-Stealing Trojan and Downloader
- [TL-2026-0869](https://intel.threadlinqs.com/threat/TL-2026-0869) — Xctdoor Backdoor Delivered via Resume-Themed LNK Files, PowerShell/VBScript Loaders, and ProximityUxHost.exe DLL Side-Loading (Andariel)

## Theme of the day

Supply chain attacks and zero-day vulnerabilities are being actively exploited by unknown actors. Multiple high-severity threats enable malware delivery, code execution, and data theft.

poc-public, windows, rce, remote-code-execution, espionage

## Threats published

- [TL-2026-0870](https://intel.threadlinqs.com/threat/TL-2026-0870) — CRITICAL — Spyder (SiderAI) & MaXSS (MaxAI) Chrome/Edge Extension Message-Validation Flaws Enable Zero-Interaction Browser Session Compromise Across 11M+ Installs
- [TL-2026-0874](https://intel.threadlinqs.com/threat/TL-2026-0874) — CRITICAL — CVE-2026-8713: Avada (Fusion) Builder WordPress Plugin Unauthenticated Path Traversal Arbitrary File Deletion
- [TL-2026-0877](https://intel.threadlinqs.com/threat/TL-2026-0877) — CRITICAL — Splunk AI Toolkit OS Command Injection in btool Configuration Helper (CVE-2026-20266)
- [TL-2026-0883](https://intel.threadlinqs.com/threat/TL-2026-0883) — CRITICAL — AutoJack: Three-Vulnerability Exploit Chain (CWE-1385 + CWE-306 + CWE-78) in Microsoft AutoGen Studio MCP WebSocket Enables Browsing-Agent Hijack and Host RCE
- [TL-2026-0868](https://intel.threadlinqs.com/threat/TL-2026-0868) — CRITICAL — FortiBleed Campaign: Mass FortiGate SSL VPN / Admin Credential Exposure Affecting ~73,932 Fortinet Firewalls Across 194 Countries (update)
- [TL-2026-0864](https://intel.threadlinqs.com/threat/TL-2026-0864) — HIGH — OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs
- [TL-2026-0865](https://intel.threadlinqs.com/threat/TL-2026-0865) — HIGH — Belfius eBanking Phishing Campaign Using IPv4-Mapped IPv6 Address Obfuscation (RFC 4291) to Evade URL Extraction
- [TL-2026-0866](https://intel.threadlinqs.com/threat/TL-2026-0866) — HIGH — Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933)
- [TL-2026-0867](https://intel.threadlinqs.com/threat/TL-2026-0867) — HIGH — Pony (Fareit/Siplog) Credential-Stealing Trojan and Downloader
- [TL-2026-0869](https://intel.threadlinqs.com/threat/TL-2026-0869) — HIGH — Xctdoor Backdoor Delivered via Resume-Themed LNK Files, PowerShell/VBScript Loaders, and ProximityUxHost.exe DLL Side-Loading (Andariel)
- [TL-2026-0871](https://intel.threadlinqs.com/threat/TL-2026-0871) — HIGH — usbliter8 — checkm8-style unpatchable BootROM/SecureROM exploit for Apple A12/A13 (and S4/S5) devices
- [TL-2026-0872](https://intel.threadlinqs.com/threat/TL-2026-0872) — HIGH — CVE-2026-54420 — LiteSpeed cPanel Plugin Symlink-Following (CWE-61) Privilege Escalation to Root on CloudLinux/CageFS Shared Hosting; Added to CISA KEV After In-the-Wild Exploitation
- [TL-2026-0873](https://intel.threadlinqs.com/threat/TL-2026-0873) — HIGH — AutoJack: AutoGen Studio MCP WebSocket Exploit Chain Turns an AI Browsing Agent into a Host RCE Vector
- [TL-2026-0875](https://intel.threadlinqs.com/threat/TL-2026-0875) — HIGH — CVE-2026-4020: Gravity SMTP WordPress Plugin Unauthenticated System-Report Credential Disclosure (Actively Exploited)
- [TL-2026-0876](https://intel.threadlinqs.com/threat/TL-2026-0876) — HIGH — usbliter8 — Unpatchable SecureROM Boot-Chain Code Execution on Apple A12/A13 (and S4/S5) SoCs via DWC2 USB DMA Underflow
- [TL-2026-0878](https://intel.threadlinqs.com/threat/TL-2026-0878) — HIGH — Zscaler ThreatLabz 2026 Report: Encrypted Phishing & AiTM/BiTM Initial-Access Campaigns Targeting the Public Sector
- [TL-2026-0879](https://intel.threadlinqs.com/threat/TL-2026-0879) — HIGH — Operation Poisson: French-speaking junior operator "Poisson" abuses Tailscale, OpenSSH and RustDesk for C2-independent persistence in 33-day Havoc intrusion
- [TL-2026-0880](https://intel.threadlinqs.com/threat/TL-2026-0880) — HIGH — Google Cloud Vertex AI Python SDK Bucket-Squatting ("Pickle in the Middle") Enables Cross-Tenant Model Hijacking and RCE
- [TL-2026-0882](https://intel.threadlinqs.com/threat/TL-2026-0882) — HIGH — FortiBleed: Large-Scale Credential-Stuffing and Brute-Force Compromise of 73,932 Fortinet FortiGate SSL VPN Firewalls Across 194 Countries
- [TL-2026-0881](https://intel.threadlinqs.com/threat/TL-2026-0881) — MEDIUM — CVE-2026-55706: 27-Year-Old OpenBSD sppp(4) PAP Authentication Bypass in sppp_pap_input() (update)

## Techniques observed

[T1003](https://intel.threadlinqs.com/technique/T1003), [T1003.008](https://intel.threadlinqs.com/technique/T1003.008), [T1005](https://intel.threadlinqs.com/technique/T1005), [T1008](https://intel.threadlinqs.com/technique/T1008), [T1012](https://intel.threadlinqs.com/technique/T1012), [T1014](https://intel.threadlinqs.com/technique/T1014), [T1016](https://intel.threadlinqs.com/technique/T1016), [T1018](https://intel.threadlinqs.com/technique/T1018), [T1021](https://intel.threadlinqs.com/technique/T1021), [T1021.001](https://intel.threadlinqs.com/technique/T1021.001), [T1021.002](https://intel.threadlinqs.com/technique/T1021.002), [T1027](https://intel.threadlinqs.com/technique/T1027), [T1033](https://intel.threadlinqs.com/technique/T1033), [T1036](https://intel.threadlinqs.com/technique/T1036), [T1036.005](https://intel.threadlinqs.com/technique/T1036.005), [T1039](https://intel.threadlinqs.com/technique/T1039), [T1040](https://intel.threadlinqs.com/technique/T1040), [T1041](https://intel.threadlinqs.com/technique/T1041), [T1046](https://intel.threadlinqs.com/technique/T1046), [T1053](https://intel.threadlinqs.com/technique/T1053), [T1055](https://intel.threadlinqs.com/technique/T1055), [T1056](https://intel.threadlinqs.com/technique/T1056), [T1056.003](https://intel.threadlinqs.com/technique/T1056.003), [T1057](https://intel.threadlinqs.com/technique/T1057), [T1059](https://intel.threadlinqs.com/technique/T1059), [T1059.004](https://intel.threadlinqs.com/technique/T1059.004), [T1059.007](https://intel.threadlinqs.com/technique/T1059.007), [T1068](https://intel.threadlinqs.com/technique/T1068), [T1069](https://intel.threadlinqs.com/technique/T1069), [T1070](https://intel.threadlinqs.com/technique/T1070), [T1070.003](https://intel.threadlinqs.com/technique/T1070.003), [T1070.006](https://intel.threadlinqs.com/technique/T1070.006), [T1071](https://intel.threadlinqs.com/technique/T1071), [T1071.001](https://intel.threadlinqs.com/technique/T1071.001), [T1078](https://intel.threadlinqs.com/technique/T1078), [T1078.002](https://intel.threadlinqs.com/technique/T1078.002), [T1078.004](https://intel.threadlinqs.com/technique/T1078.004), [T1080](https://intel.threadlinqs.com/technique/T1080), [T1082](https://intel.threadlinqs.com/technique/T1082), [T1083](https://intel.threadlinqs.com/technique/T1083), [T1087](https://intel.threadlinqs.com/technique/T1087), [T1087.002](https://intel.threadlinqs.com/technique/T1087.002), [T1090](https://intel.threadlinqs.com/technique/T1090), [T1091](https://intel.threadlinqs.com/technique/T1091), [T1095](https://intel.threadlinqs.com/technique/T1095), [T1098](https://intel.threadlinqs.com/technique/T1098), [T1102](https://intel.threadlinqs.com/technique/T1102), [T1102.002](https://intel.threadlinqs.com/technique/T1102.002), [T1105](https://intel.threadlinqs.com/technique/T1105), [T1106](https://intel.threadlinqs.com/technique/T1106), [T1110](https://intel.threadlinqs.com/technique/T1110), [T1110.001](https://intel.threadlinqs.com/technique/T1110.001), [T1110.002](https://intel.threadlinqs.com/technique/T1110.002), [T1110.003](https://intel.threadlinqs.com/technique/T1110.003), [T1110.004](https://intel.threadlinqs.com/technique/T1110.004), [T1113](https://intel.threadlinqs.com/technique/T1113), [T1114.002](https://intel.threadlinqs.com/technique/T1114.002), [T1115](https://intel.threadlinqs.com/technique/T1115), [T1119](https://intel.threadlinqs.com/technique/T1119), [T1132](https://intel.threadlinqs.com/technique/T1132), [T1133](https://intel.threadlinqs.com/technique/T1133), [T1134](https://intel.threadlinqs.com/technique/T1134), [T1135](https://intel.threadlinqs.com/technique/T1135), [T1136](https://intel.threadlinqs.com/technique/T1136), [T1140](https://intel.threadlinqs.com/technique/T1140), [T1176](https://intel.threadlinqs.com/technique/T1176), [T1185](https://intel.threadlinqs.com/technique/T1185), [T1189](https://intel.threadlinqs.com/technique/T1189), [T1190](https://intel.threadlinqs.com/technique/T1190), [T1195](https://intel.threadlinqs.com/technique/T1195), [T1199](https://intel.threadlinqs.com/technique/T1199), [T1200](https://intel.threadlinqs.com/technique/T1200), [T1203](https://intel.threadlinqs.com/technique/T1203), [T1204](https://intel.threadlinqs.com/technique/T1204), [T1211](https://intel.threadlinqs.com/technique/T1211), [T1212](https://intel.threadlinqs.com/technique/T1212), [T1213](https://intel.threadlinqs.com/technique/T1213), [T1217](https://intel.threadlinqs.com/technique/T1217), [T1218](https://intel.threadlinqs.com/technique/T1218), [T1219](https://intel.threadlinqs.com/technique/T1219), [T1222](https://intel.threadlinqs.com/technique/T1222), [T1222.002](https://intel.threadlinqs.com/technique/T1222.002), [T1482](https://intel.threadlinqs.com/technique/T1482), [T1485](https://intel.threadlinqs.com/technique/T1485), [T1489](https://intel.threadlinqs.com/technique/T1489), [T1490](https://intel.threadlinqs.com/technique/T1490), [T1495](https://intel.threadlinqs.com/technique/T1495), [T1497](https://intel.threadlinqs.com/technique/T1497), [T1499](https://intel.threadlinqs.com/technique/T1499), [T1499.003](https://intel.threadlinqs.com/technique/T1499.003), [T1499.004](https://intel.threadlinqs.com/technique/T1499.004), [T1505](https://intel.threadlinqs.com/technique/T1505), [T1505.003](https://intel.threadlinqs.com/technique/T1505.003), [T1518](https://intel.threadlinqs.com/technique/T1518), [T1526](https://intel.threadlinqs.com/technique/T1526), [T1528](https://intel.threadlinqs.com/technique/T1528), [T1530](https://intel.threadlinqs.com/technique/T1530), [T1531](https://intel.threadlinqs.com/technique/T1531), [T1537](https://intel.threadlinqs.com/technique/T1537), [T1539](https://intel.threadlinqs.com/technique/T1539), [T1542](https://intel.threadlinqs.com/technique/T1542), [T1543](https://intel.threadlinqs.com/technique/T1543), [T1547](https://intel.threadlinqs.com/technique/T1547), [T1548](https://intel.threadlinqs.com/technique/T1548), [T1550](https://intel.threadlinqs.com/technique/T1550), [T1552](https://intel.threadlinqs.com/technique/T1552), [T1552.001](https://intel.threadlinqs.com/technique/T1552.001), [T1553](https://intel.threadlinqs.com/technique/T1553), [T1555](https://intel.threadlinqs.com/technique/T1555), [T1556](https://intel.threadlinqs.com/technique/T1556), [T1556.006](https://intel.threadlinqs.com/technique/T1556.006), [T1557](https://intel.threadlinqs.com/technique/T1557), [T1559](https://intel.threadlinqs.com/technique/T1559), T1562, [T1565](https://intel.threadlinqs.com/technique/T1565), [T1565.001](https://intel.threadlinqs.com/technique/T1565.001), [T1566](https://intel.threadlinqs.com/technique/T1566), [T1566.002](https://intel.threadlinqs.com/technique/T1566.002), [T1567](https://intel.threadlinqs.com/technique/T1567), [T1568](https://intel.threadlinqs.com/technique/T1568), [T1571](https://intel.threadlinqs.com/technique/T1571), [T1572](https://intel.threadlinqs.com/technique/T1572), [T1573](https://intel.threadlinqs.com/technique/T1573), [T1574](https://intel.threadlinqs.com/technique/T1574), [T1580](https://intel.threadlinqs.com/technique/T1580), [T1583](https://intel.threadlinqs.com/technique/T1583), [T1585](https://intel.threadlinqs.com/technique/T1585), [T1586](https://intel.threadlinqs.com/technique/T1586), [T1587](https://intel.threadlinqs.com/technique/T1587), [T1588](https://intel.threadlinqs.com/technique/T1588), [T1588.002](https://intel.threadlinqs.com/technique/T1588.002), [T1589](https://intel.threadlinqs.com/technique/T1589), [T1589.001](https://intel.threadlinqs.com/technique/T1589.001), [T1592](https://intel.threadlinqs.com/technique/T1592), [T1595](https://intel.threadlinqs.com/technique/T1595), [T1595.002](https://intel.threadlinqs.com/technique/T1595.002), [T1596](https://intel.threadlinqs.com/technique/T1596), [T1598](https://intel.threadlinqs.com/technique/T1598), [T1602](https://intel.threadlinqs.com/technique/T1602), [T1608](https://intel.threadlinqs.com/technique/T1608), [T1608.005](https://intel.threadlinqs.com/technique/T1608.005), [T1620](https://intel.threadlinqs.com/technique/T1620), [T1622](https://intel.threadlinqs.com/technique/T1622), [T1648](https://intel.threadlinqs.com/technique/T1648), T1656, [T1657](https://intel.threadlinqs.com/technique/T1657), T1659

## Threat actors

OceanLotus (APT32), [Andariel](https://intel.threadlinqs.com/actor/Andariel), Paradigm Shift (security research group), [Poisson](https://intel.threadlinqs.com/actor/Poisson), FortiBleed operators (Russian-speaking cybercriminal collective)

Nation-state attribution: Vietnam, North Korea

Threat categories: APT, PHISHING, VULNERABILITY, MALWARE, THREAT_INTEL, DATA_BREACH

## Severity breakdown

- critical: 5
- high: 14
- medium: 1
- low: 0

## Indicator & detection coverage

Counts only; indicator values require Red and above, detection rule text requires Blue and above.

- Indicators of compromise: 405 (behavioral 156, file 76, network 73, infrastructure 30, tool 25, package 15, entity 12, malware 8, technique 7, domain 3)
- New detection rules: 180 (100% of the day’s threats covered)

## More editions

- Previous: [2026-06-18](https://intel.threadlinqs.com/debrief/2026-06-18)
- Next: [2026-06-23](https://intel.threadlinqs.com/debrief/2026-06-23)
- [Archive of daily debriefs](https://intel.threadlinqs.com/debrief/archive)
- [Latest debrief](https://intel.threadlinqs.com/debrief)

Canonical: https://intel.threadlinqs.com/debrief/2026-06-19
