Summary & highlights
OpenAI Releases GPT-5.5-Cyber: Defender-Restricted AI for Automated Vulnerability Detection, Exploitability Validation, and Patching (Daybreak / Patch the Planet). Remcos RAT Delivered via Steganographic Multi-Stage Loader in 'GST Debit Note' India-Targeted Phishing Campaign. Agent Tesla .NET Remote Access Trojan — Credential and Data Theft via Keylogging and MaaS Operations.
Highlights
- TL-2026-0911 — Remcos RAT Delivered via Steganographic Multi-Stage Loader in 'GST Debit Note' India-Targeted Phishing Campaign
- TL-2026-0912 — Agent Tesla .NET Remote Access Trojan — Credential and Data Theft via Keylogging and MaaS Operations
- TL-2026-0913 — CodeStorm AiTM Phishing Kit Abuses Compromised Microsoft 365 Accounts for Real-Time MFA-Bypass Account Takeover (Storm-1167 Overlap)
- TL-2026-0914 — AI-Accelerated Exploitation Collapses Vulnerability-Management Patch Windows (Picus: ~24h time-to-exploit vs 43-day median fix)
- TL-2026-0917 — Edgecution: Payouts King Initial Access Broker Deploys Malicious Microsoft Edge Extension with Embedded Python Backdoor
Theme of the day
Active exploitation of vulnerabilities in software and firewalls dominates the threat landscape, with Russian-speaking and DPRK actors prominent. Supply-chain compromises and arbitrary code execution are key concerns.
- credential-theft
- infostealer
- browser-credential-theft
- windows
- mfa-bypass
Threats published
17 threat lines in the 2026-06-23 debrief, most severe first. Each links to its full profile.
- Typosquatted npm Package postcss-minify-selector-parser Delivers Nuitka-Compiled Windows RAT with RC4-Encrypted HTTP C2CRITICAL
- CVE-2026-2031 "StubZero": Remote Code Execution in Google Cloud Application Integration via Exposed Proto Descriptors, GenericStubbyTypedTaskV2 and ACL BypassCRITICAL
- FortiBleed — Credential Exposure Campaign Targeting Fortinet FortiGate Firewalls and SSL-VPN GatewaysCRITICAL
- Cordyceps: Systemic Cross-Workflow Privilege-Escalation Supply-Chain Flaw in GitHub Actions CI/CD Pipelines (Microsoft Azure Sentinel, Google ADK, Apache Doris, Cloudflare Workers SDK, PSF Black)CRITICAL
- Remcos RAT Delivered via Steganographic Multi-Stage Loader in 'GST Debit Note' India-Targeted Phishing CampaignHIGH
- Agent Tesla .NET Remote Access Trojan — Credential and Data Theft via Keylogging and MaaS OperationsHIGH
- CodeStorm AiTM Phishing Kit Abuses Compromised Microsoft 365 Accounts for Real-Time MFA-Bypass Account Takeover (Storm-1167 Overlap)HIGH
- AI-Accelerated Exploitation Collapses Vulnerability-Management Patch Windows (Picus: ~24h time-to-exploit vs 43-day median fix)HIGH
- Edgecution: Payouts King Initial Access Broker Deploys Malicious Microsoft Edge Extension with Embedded Python BackdoorHIGH
- FortiBleed: Russian Initial-Access-Broker Credential-Harvesting Campaign Weaponizing FortiGate Firewalls with the FortigateSniffer ToolHIGH
- Dark Web Identity-Theft Ecosystem: $0.95 Fullz, STORM Infostealer-as-a-Service, and Scam-as-a-Service MarketplacesHIGH
- macOS.Gaslight — DPRK-aligned Rust Backdoor & Infostealer with Analyst-Targeting Prompt-Injection Anti-Analysis (Telegram Bot API C2)HIGH
- OpenClaw / ClawHub AI Skill Marketplace Supply-Chain Compromise — Malicious Skills cluw, AMOS, omnicogg, money-radar, letssenditHIGH
- Xsolis, Inc. Healthcare Technology Data Breach via Targeted Phishing (CVE-less; 1,396,519 individuals)HIGH
- macOS ClickFix Campaign Silently Mounts Malicious DMGs (hdiutil attach -nobrowse) to Deploy Atomic macOS Stealer (AMOS)HIGH
- CalPhishing: Phishing Campaign Abusing Microsoft 365 Groups and Outlook Calendar Invites for Persistent Lures and EvilTokens Device-Code Session TheftHIGH
- OpenAI Releases GPT-5.5-Cyber: Defender-Restricted AI for Automated Vulnerability Detection, Exploitability Validation, and Patching (Daybreak / Patch the Planet)
Techniques observed
164 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003
- T1005
- T1010
- T1016
- T1018
- T1020
- T1021
- T1027
- T1027.001
- T1030
- T1033
- T1036
- T1036.005
- T1039
- T1040
- T1041
- T1046
- T1047
- T1048
- T1053
- T1053.003
- T1053.005
- T1055
- T1056
- T1056.002
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.006
- T1068
- T1070
- T1070.004
- T1071
- T1071.001
- T1074
- T1078
- T1078.004
- T1082
- T1083
- T1087
- T1090.002
- T1095
- T1098
- T1098.001
- T1098.003
- T1102
- T1102.002
- T1105
- T1106
- T1110
- T1112
- T1113
- T1114
- T1115
- T1119
- T1123
- T1124
- T1125
- T1127
- T1132
- T1133
- T1136
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1210
- T1213
- T1213.003
- T1217
- T1218
- T1222.002
- T1486
- T1497
- T1505
- T1518
- T1526
- T1528
- T1530
- T1534
- T1539
- T1543
- T1543.001
- T1543.004
- T1547
- T1548
- T1548.003
- T1550
- T1550.001
- T1552
- T1552.001
- T1553
- T1553.001
- T1555
- T1555.001
- T1555.003
- T1556
- T1557
- T1558
- T1559.001
- T1560
- T1560.001
- T1562
- T1562.001
- T1564
- T1564.001
- T1564.003
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1567
- T1571
- T1573
- T1580
- T1583
- T1583.001
- T1583.003
- T1583.006
- T1585.003
- T1586
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.002
- T1588.005
- T1588.006
- T1589
- T1590
- T1592
- T1592.002
- T1593
- T1595
- T1595.002
- T1596
- T1596.005
- T1598
- T1598.003
- T1608
- T1608.001
- T1608.005
- T1620
- T1621
- T1650
- T1656
- T1657
Threat actors
5 named threat actors across the reports.
- CodeStorm operators
- AI-augmented adversaries
- Payouts King initial access broker
- FortiBleed operator
- DPRK-aligned activity cluster
Nation-state attribution
- Russia
- North Korea
Threat categories
- THREAT_INTEL
- MALWARE
- PHISHING
- DATA_BREACH
- SUPPLY_CHAIN
- VULNERABILITY
Severity breakdown
- critical4
- high12
- medium0
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 129
- file 95
- network 73
- entity 27
- infrastructure 23
- malware 21
- tool 19
- technique 8
- package 7