{"id":1161,"date":"2026-06-11T16:23:08","date_gmt":"2026-06-11T16:23:08","guid":{"rendered":"https:\/\/cybercolombia.co\/index.php\/2026\/06\/11\/worm-code-leaked-ai-agent-phished-claude-action-patch-28-new-stories-cyberdefensa-mx\/"},"modified":"2026-06-11T16:23:08","modified_gmt":"2026-06-11T16:23:08","slug":"worm-code-leaked-ai-agent-phished-claude-action-patch-28-new-stories-cyberdefensa-mx","status":"publish","type":"post","link":"https:\/\/cybercolombia.co\/index.php\/2026\/06\/11\/worm-code-leaked-ai-agent-phished-claude-action-patch-28-new-stories-cyberdefensa-mx\/","title":{"rendered":"Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories \u2013 CYBERDEFENSA.MX"},"content":{"rendered":"<div id=\"articlebody\">\n<p>It\u2019s been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there\u2019s a supply chain attack kit in a public repo, a $5,000-a-month RAT that clones browsers, and research showing AI agents can be tricked into leaking real credentials.<\/p>\n<p>The bigger problem is how polished this all looks now. Mule networks run like SaaS. Deepfake KYC bypass is sold as a feature. Endpoint tools can be quietly weakened using built-in OS settings, with no exploit needed.<\/p>\n<p>Here\u2019s the full list of threats, tools, flaws, and updates worth knowing.<\/p>\n<div class=\"td-wrap\">\n<section aria-labelledby=\"threatsday-title\" class=\"td-section\">\n<ol class=\"td-timeline\" role=\"list\">\n<a name=\"more\"\/><\/p>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">3.3B identity records exposed<\/span><\/p>\n<p class=\"td-desc\">\n      A new analysis from Flashpoint has <a href=\"https:\/\/flashpoint.io\/blog\/proactive-defender-guide-infostealers\/\">revealed<\/a> that \u00abmore than 11.1 million devices were infected with infostealers last year, fueling a supply of over 3.3 billion stolen credentials, session cookies, cloud tokens, and other forms of identity data now circulating across illicit markets.\u00bb There are over 30 unique infostealer strains actively listed for sale across illicit marketplaces, forums, and underground communities, indicating the \u00abscale and accessibility of the modern malware-as-a-service ecosystem.\u00bb Lumma, Acreed, Rhadamanthys, Vidar, and StealC were the most prolific stealers in 2025. India, Brazil, Indonesia, Vietnam, the Philippines, and the U.S. were the top six countries affected by stealer malware during the same period.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">MaaS RAT targets credentials<\/span><\/p>\n<p class=\"td-desc\">\n      A threat actor named \u00abo1oo1\u00bb has advertised an advanced remote access trojan (RAT) named SilabRAT that\u2019s sold under a malware-as-a-service (MaaS) model for $5,000 a month on darknet forums since September 2025. \u00abSilabRAT is heavily focused on financial gain through credential theft,\u00bb Group-IB <a href=\"https:\/\/www.group-ib.com\/blog\/silabrat-hijackloader-trojan-malware\/\">said<\/a>. \u00abIt offers stability and is capable of bypassing existing security measures.\u00bb Delivered via ClickFix campaigns using Hijack Loader, the malware uses Hidden Virtual Network Computing (HVNC) to facilitate remote control capabilities, employs techniques like Browser Profile Cloning to replicate a user\u2019s browser profile (user agent, extensions, storage, and other fingerprinting attributes) to the attacker\u2019s system, and can identify wallet addresses or extract cryptocurrency-related artifacts. The Russian-speaking malware developer and vendor, \u00abo1oo1,\u00bb has been active since late 2020, previously launching a service called AsmCrypt.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">47% of tech intrusions<\/span><\/p>\n<p class=\"td-desc\">\n      CrowdStrike has revealed that a North Korean threat actor known as Famous Chollima, which is behind the long-running IT worker and Contagious Interview campaign, accounted for 47% of all state-sponsored hands-on-keyboard operations against the tech sector between April 2025 and March 2026. Hands-on intrusions refer to cyber attacks in which a human operator controls and interacts with a system rather than relying solely on malware. \u00abIn their IT worker infiltration campaigns, they sought fraudulent employment at tech companies across North America, Europe, and Asia,\u00bb the cybersecurity company <a href=\"https:\/\/www.crowdstrike.com\/en-us\/blog\/crowdstrike-2026-technology-threat-landscape-report\/\">said<\/a>.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">13 domains seized<\/span><\/p>\n<p class=\"td-desc\">\n      The U.S. Department of Justice has announced the seizure of 13 internet domains masquerading as consulting companies used to target U.S. persons, including current and former security clearance holders with access to classified and sensitive U.S. government information. \u00abThese domain seizures offer a glimpse at how foreign actors can use promises of easy money to lure Americans into revealing sensitive or classified information that they are duty-bound to protect,\u00bb <a href=\"https:\/\/www.justice.gov\/opa\/pr\/justice-department-fbi-disable-13-websites-backed-suspected-chinese-agents-sought-sensitive\">said<\/a> Assistant Attorney General for National Security John A. Eisenberg. \u00abAnyone approached online with offers of easy income for vague \u2018consulting\u2019 work should treat those overtures with extreme caution and remain vigilant for warning signs of malicious targeting.\u00bb These sham companies advertised generic consulting or analyst jobs on platforms like Upwork, Expertia AI, Hubstaff Talent, Wellfound, and Post Job Free that sought to recruit current or former U.S. government and U.S. military employees to lend their expertise to unspecified clients. The recruiters then pressured candidates to part with confidential information and reports from \u00abinsider\u00bb sources in exchange for cryptocurrency payments. The announcement comes after the Five Eyes intelligence alliance countries warned of China aggressively using job platforms to target people for information. In a statement shared with Reuters, the Chinese Embassy in Washington <a href=\"https:\/\/www.reuters.com\/legal\/litigation\/us-seizes-13-website-domains-tied-alleged-chinese-intelligence-collection-2026-06-10\/\">condemned<\/a> the allegations and called them fabricated.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Supply-chain toolkit exposed<\/span><\/p>\n<p class=\"td-desc\">\n      The Miasma credential-stealing attack framework was briefly made available for free on GitHub, after multiple repositories with the name \u00abMiasma-Open-Source-Release\u00bb began appearing since June 8, 2026. According to SafeDep, the source code has been published through compromised developer accounts. \u00abThe <a href=\"https:\/\/www.ox.security\/blog\/600000-monthly-downloads-affected-miasma-supply-chain-attack-is-back-on-npm\/\">Miasma<\/a> codebase appears to be larger than a supply chain worm,\u00bb SafeDep <a href=\"https:\/\/safedep.io\/inside-the-miasma-supply-chain-attack-toolkit\/\">said<\/a>. \u00abIt is a full supply chain attack toolkit that allows the operator to execute various attacks via stolen credentials against arbitrary or targeted packages on public registries (PyPI, npm, RubyGems), JFrog Artifactory, GitHub repositories and GitHub Actions, AI coding tools config poisoning, SSH-based lateral movement, and other attack vectors.\u00bb As opposed to relying on conventional command-and-control (C2) infrastructure, the malware employs three independent C2 channels using GitHub commit search, each with a different search string and crypto key: \u00abDontRevokeOrItGoesBoom\u00bb to discover attacker-controlled personal access tokens (PATs) for data exfiltration, \u00abTheBeautifulSandsOfTime\u00bb to deliver JavaScript, and \u00abfiredalazer\u00bb to deliver Python script URLs that act as a remote code execution backdoor. Miasma is assessed to be a variant of the Shai-Hulud worm. The campaign has since morphed into a Python variant called <a href=\"https:\/\/www.endorlabs.com\/learn\/shai-hulud-hades-wave-hits-six-pypi-bioinformatics-packages\">Hades<\/a>, which represents the latest evolution of the sustained software supply chain campaign. As of last week, a total of <a href=\"https:\/\/www.sonatype.com\/blog\/new-shai-hulud-miasma-wave-hits-hundreds-of-npm-packages\">304 components<\/a> have been impacted by Miasma.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Search uploads retained<\/span><\/p>\n<p class=\"td-desc\">\n      Google has <a href=\"https:\/\/support.google.com\/websearch\/answer\/17024959\">revealed<\/a> that it intends to save the images, files, audio, and video users upload to Search under a new \u00abSearch Services History\u00bb setting. This can include images, files, and audio\/video recordings, such as Google Lens images, content you upload, and recordings from Search Live, Translate speaking practice, and voice searches, per <a href=\"https:\/\/support.google.com\/websearch\/answer\/17025248\">Google<\/a>. The tech giant said the Search Services History setting will be used to \u00abprovide, develop, and improve its services,\u00bb including its AI models, as well as <a href=\"https:\/\/support.google.com\/websearch\/answer\/17026260\">offer personalized suggestions<\/a> and ads if the new \u00ab<a href=\"https:\/\/www.google.com\/search-personalization\/\">Personalized Recommendations<\/a>\u00bb option is switched on. These two settings are separate from Google\u2019s Web &amp; App Activity.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Cross-platform RAT emerges<\/span><\/p>\n<p class=\"td-desc\">\n      Iru has analyzed a new cross-platform RAT called SStar Agent that\u2019s designed for both Windows and macOS systems. \u00abThe macOS builds are heavily instrumented surveillance tools focused on recon and exfiltration, while the Windows build layers on a keyboard hook, clipboard monitor, and remote mouse\/keyboard control,\u00bb the company <a href=\"https:\/\/www.iru.com\/blog\/sstar-agent\">said<\/a>. \u00abNotably, the malware includes a large POST request via endpoint \/api\/telemetry\/report that constantly monitors and exfiltrates the entire directory tree to monitor files of interest. The gap between the Windows and macOS versions indicates this is still a work in progress.\u00bb The malware is delivered by means of a poisoned npm package named \u00abtw-style-utils.\u00bb The lure is a bogus Web3 engineering take-home assessment, a GitHub repository (\u00abstar45674\/smart-contract-engineer-role\u00bb) that\u2019s likely distributed to targets. While the repository itself is clean, the payload resides in the npm dependency. Although it\u2019s not clear who is behind the malware, the activity overlaps with previously observed social engineering attacks mounted by North Korean hacking groups.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fake npm popularity<\/span><\/p>\n<p class=\"td-desc\">\n      Tenable has detailed a technique dubbed download pumping, where attackers artificially inflate npm package download counts in order to make malicious packages appear legitimate and trustworthy to developers. This approach has been observed in a package named \u00ab<a href=\"https:\/\/www.tenable.com\/blog\/cybersecurity-research-faq-new-malicious-npm-package-ambar-src\">ambar-src<\/a>,\u00bb which reached more than 50,000 downloads in three days after attackers published hundreds of benign versions of the package before introducing the actual malicious payload. \u00abEvery time a new version was published, automated systems like repository mirrors and analysis bots automatically downloaded it,\u00bb Tenable <a href=\"https:\/\/www.tenable.com\/blog\/how-cyberattackers-inflate-malicious-package-npm-download-counts\">said<\/a>. \u00abBecause the attackers systematically uploaded hundreds of versions, they artificially generated a massive wave of automated traffic, inflating the package\u2019s download count to more than 50,000 downloads in just three days.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Exchange spoofing risk<\/span><\/p>\n<p class=\"td-desc\">\n      A weakness in certain configurations of Microsoft Exchange could be abused by attackers to send emails masquerading as any user to a vulnerable organization. The technique has been codenamed Ghost-Sender. \u00abUsing Exchange Online (or on-premises Exchange in hybrid mode) in combination with an external MX record, such as a third-party email server or spam protection solution, can allow the spoofing of emails from any sender to any recipient in the target tenant,\u00bb InfoGuard Labs <a href=\"https:\/\/labs.infoguard.ch\/posts\/ghost-sender\/\">said<\/a>. \u00abThis is regardless of the configured SPF, DKIM, and DMARC policies of the spoofed sender\u2019s domain, and the emails are delivered without any further warning. It is possible to send emails from anyone, including external and internal email addresses. For internal senders, Outlook even resolves the sender\u2019s profile picture.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Russia-focused phishing waves<\/span><\/p>\n<p class=\"td-desc\">\n      A previously unknown group known as <a href=\"https:\/\/www.f6.ru\/blog\/siribclone\/\">SiribClone<\/a> has targeted Russian military personnel using bait applications for \u00absafe photo exchange\u00bb to distribute malicious files for desktop and mobile devices. In some cases, members of the group have posed as women seeking romantic relationships to infect smartphones, computers, and Telegram accounts. The group has been active since early 2025. Attacks targeting Android devices lead to the deployment of a spyware called SafeLoveStealer that can steal photographs, videos, documents, and location data. Windows systems, on the other hand, are infected by a stealer known as SiribGrabber. The malware is distributed via phishing emails containing ZIP archives disguised as military-themed documents. In addition, the group operates phishing sites mimicking Telegram login pages to trick targets into entering their phone numbers, verification codes, and two-factor authentication passwords, allowing them to seize control of the accounts. Also linked to the threat actor is a tool called Kontur that stores stolen Telegram sessions and allows operators to review captured messages. Russian maritime universities, energy facilities, diplomatic missions, and government agencies have also been targeted through phishing campaigns by an <a href=\"https:\/\/securelist.ru\/unknown-group-targets-maritime-universities\/115765\/\">unidentified group<\/a> since at least July 2024. Recent attack waves have employed a C2 framework called <a href=\"https:\/\/github.com\/FL1GHT5\/Ravage\">Ravage<\/a>, although two distinct phishing campaigns observed in 2024 have used Cobalt Strike. The third hacking group to single out Russia (along with Belarus) is Cloud Atlas, which has resorted to sending phishing emails with ZIP archives containing malicious shortcuts that launch PowerShell scripts, paving the way for malware like VBShower and PowerShower, the latter of which is used to drop a credential grabber. Lateral movement via RDP, SSH, and RevSocks is achieved via PAExec or PsExec as part of a framework known as PowerAdmin. Furthermore, the attacks involve two new tools: PowerCloud, which collects user data with administrator privileges and writes it to Google Sheets, and Browser checker, a PowerShell script that checks whether browser processes (Chrome, Edge, Firefox, and others) are running.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">ClickFix backdoor expands<\/span><\/p>\n<p class=\"td-desc\">\n      A ransomware-related threat actor has put to use a new malware family called MLTBackdoor that\u2019s delivered via ClickFix. \u00abMTLBackdoor supports a set of commands like downloading and uploading files from the victim\u2019s system,\u00bb Zscaler ThreatLabz <a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/technical-analysis-mltbackdoor\">said<\/a>. \u00abHowever, one of the most powerful features is the ability to load Beacon Object Files (BOFs) to expand its capabilities.\u00bb The malware was discovered in May 2026. In recent months, ransomware and data extortion attacks involving DragonForce and World Leaks have employed backdoors like <a href=\"https:\/\/labs.infoguard.ch\/posts\/slithering_through_the_noise\/\">VIPERTUNNEL<\/a>, a Python malware previously linked to RansomHub, and <a href=\"https:\/\/www.linkedin.com\/posts\/t-ryan-whelan-1156ab5_rusty-rocket-overview-ugcPost-7427362470236864512-CLdf\/\">RustyRocket<\/a>, a custom-built Rust tool to facilitate covert data exfiltration and persistent access. \u00abOnce an attacker runs it, RustyRocket can securely connect back to an attacker-controlled server using heavily encrypted and layered traffic that blends in with normal internet activity, making it very hard for defenders to detect,\u00bb Accenture\u2019s T. Ryan Whelan said. \u00abThis malware is an integrated communications architecture built for persistence and obfuscation.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">WooCommerce card theft<\/span><\/p>\n<p class=\"td-desc\">\n      A new skimmer campaign is targeting WooCommerce sites to steal card details from checkout pages. \u00abThe skimmer impersonates the real Stripe payment element, validates cards in real time so the victim never suspects anything,\u00bb CloudSEK <a href=\"https:\/\/www.cloudsek.com\/blog\/woocommerce-payment-skimmer-card-data-theft-checkout-backdoor\">said<\/a>. \u00abThe most \u2018professional\u2019 aspect of this sample is how hard it works to feel legitimate. It re-implements the same client-side checks a real checkout performs.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">33,000 users targeted<\/span><\/p>\n<p class=\"td-desc\">\n      A new Go-based loader named GoFlateLoader is being used to deliver multiple infostealers, including Amatera, Remus, Lumma, Vidar, StealC, and SvitStealer. \u00abGoFlateLoader appears both in x86 (32-bit) and x86-64 (64-bit) variants, matching the bitness of the payload it is supposed to execute,\u00bb Gen Digital\u2019s Avast <a href=\"https:\/\/www.gendigital.com\/blog\/insights\/research\/goflateloader-delivers-multiple-infostealers\">said<\/a>. \u00abThe loader is designed for in-memory payload execution and is deliberately inflated with a massive PE overlay to hinder detection.\u00bb The malware is delivered via cracked software and a malicious Traffic Distribution System (TDS) that has been used to deliver Remus Stealer, AnimateClipper, and the SessionGate framework. Since the beginning of April 2026, more than 33,000 unique users have been targeted, with the most affected countries including Brazil, India, Argentina, Mexico, Turkey, and Spain.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">$862K damage case<\/span><\/p>\n<p class=\"td-desc\">\n      Maxwell Schultz, 36, of Columbus, Ohio, has been <a href=\"https:\/\/www.justice.gov\/usao-sdtx\/pr\/former-contractor-sent-federal-prison-hacking-employers-network-retaliation\">sentenced<\/a> to 24 months in federal prison for hacking into his employer\u2019s network after his contract was terminated in May 2021. Impersonating another contractor, Schultz obtained login credentials, accessed the former employer\u2019s systems, and executed a malicious PowerShell script that reset roughly 2,500 passwords, locking out employees and contractors and causing more than $862,000 in losses. Schultz pleaded guilty to the crime in November 2025.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fake banking updates<\/span><\/p>\n<p class=\"td-desc\">\n      A new phishing campaign impersonating <a href=\"https:\/\/www.d3lab.net\/nfcshare-evolves-from-a-banking-phishing-apk-to-a-github-hosted-android-nfc-fraud-campaign\/\">Italian and European banking brands<\/a> is being used to distribute an Android malware called <a href=\"https:\/\/www.d3lab.net\/nfcshare-android-trojan-nfc-card-data-theft-via-malicious-apk\/\">NFCShare<\/a>. The attacks use phishing sites that aim to trick users into entering their credentials, after which they are prompted to update the banking application by downloading an APK file hosted on GitHub (\u00abantoniocastaldo1998\/app-scuola\u00bb). The end goal is to guide the user through a fake card verification flow: bring the card near the phone, keep it close while \u00abauthenticating,\u00bb and enter the card PIN. Under the hood, the app reads NFC card data (ISO-DEP) and exfiltrates it to a remote WebSocket endpoint. The activity shares tactical overlaps with other NFC relay malware, such as SuperCardX and RelayNFC. The presence of Chinese text suggests a China-linked operator or tooling lineage.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI agent phishing risk<\/span><\/p>\n<p class=\"td-desc\">\n      Four phishing simulations on an OpenClaw email agent codenamed Pinchy have revealed it to be susceptible to tactics commonly used to deceive human users. \u00abIn some cases, Pinchy not only failed at spotting the phishing attacks, it also performed risky actions that could potentially compromise a real-world organization,\u00bb Varonis <a href=\"https:\/\/www.varonis.com\/blog\/openclaw-phishing\">said<\/a>. \u00abIn one notable case, a casual email from \u2018Dan\u2019 asking the agent to share staging credentials was enough to forward AWS IAM keys, database passwords, and SSH access to an external Gmail.\u00bb This agent phishing is different from indirect prompt injection. While the latter embeds malicious instructions inside data the model consumes to trigger unintended actions or responses, agent phishing operates above the application surface. \u00abA believable request arrives through a normal communication channel, reads like a legitimate business message, and succeeds when the agent acts on it before verifying who asked,\u00bb Varonis added.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI fixes weak passwords<\/span><\/p>\n<p class=\"td-desc\">\n      Apple has revealed that its upcoming version of Apple Intelligence, the company\u2019s generative artificial intelligence (AI) system, will support capabilities to update its weak and compromised passwords with a single tap via the Passwords app. \u00abBuilding on its ability to alert users about weak and compromised passwords, Passwords can now automatically fix these for users with just a tap,\u00bb Apple <a href=\"https:\/\/www.apple.com\/newsroom\/2026\/06\/apple-intelligence-brings-powerful-ai-capabilities-into-everyday-experiences\/\">said<\/a>. \u00abUsing Apple Intelligence and Safari to agentically take action on a user\u2019s behalf, Passwords securely navigates through websites to sign in and upgrade their accounts to strong passwords.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">EDR telemetry throttled<\/span><\/p>\n<p class=\"td-desc\">\n      A new technique called EDRChoker that interferes with the client-server connection of Endpoint Detection and Response (EDR) software to sidestep defenses. \u00abEDRChoker uses policy-based Quality of Service (QoS) to throttle EDR agents to the lowest bandwidth; when agents attempt to connect, they will consistently time out due to the extremely low bandwidth,\u00bb a security researcher who goes by the name Zero Salarium <a href=\"https:\/\/www.zerosalarium.com\/2026\/06\/edrchoker-choking-telemetry-stream-block-edr.html\">said<\/a>. \u00abIt takes a list of common EDR process names and creates QoS policies that limit those processes to 8 bits per second. At that bandwidth, an EDR agent becomes effectively isolated from its server.\u00bb Earlier this January, the researcher also demonstrated EDRStartupHinder, which prevents an EDR program from starting. \u00abEDRStartupHinder aims to exploit Windows Bindlink to redirect a DLL from System32 to another location, alongside taking advantage of the function that only loads DLLs signed by a program protected with Protected Process Light (PPL) to prevent AV\/EDR services from starting,\u00bb the researcher <a href=\"https:\/\/www.zerosalarium.com\/2026\/01\/edrstartuphinder-edr-startup-process-blocker.html\">said<\/a>. Another technique <a href=\"https:\/\/binarydefense.com\/resources\/blog\/windows-defender-acl-blocking-a-silent-technique-with-serious-impact\">devised<\/a> by Binary Defense involves disabling critical security services, such as Windows Defender and Sysmon, without triggering traditional malware alerts. It modifies Windows Access Control Lists (ACLs) to add \u00abDeny\u00bb Access Control Entries (ACEs) against core system libraries like \u00abkernel32.dll.\u00bb Because these services rely on the DLL to function, the dependency chain is broken. Upon a system reboot, the protected services fail to start, leaving the endpoint without any defenses.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">STX RAT supply chain grows<\/span><\/p>\n<p class=\"td-desc\">\n      The supply chain attack targeting CPUID to deliver STX RAT is broader in scope than previously thought, with a new analysis from Cyderes uncovering seven additional trojanized packages tied to the same campaign. \u00abAll packages follow the same delivery mechanism,\u00bb the cybersecurity company <a href=\"https:\/\/www.cyderes.com\/howler-cell\/cpuid-hwmonitor-xvpn-dll-sideloading-stx-rat\">said<\/a>. \u00abThe actor, operating under the alias Leda Elacoate (pufferfish11@firemail[.]cc), built and maintained a Bitbucket repository of trojanized installers over approximately one month, targeting a wide range of user demographics.\u00bb Among the impacted packages is X-VPN, a consumer VPN with over 100 million reported users. Users who installed X-VPN from official channels are not affected. \u00abThe actor began with cryptocurrency exchange and trading software as lures, targeting users with likely access to financial accounts, and progressively expanded that lure portfolio across a social engineering decoy and VPN software,\u00bb Cyderes added.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Agent Tesla via ZIP lures<\/span><\/p>\n<p class=\"td-desc\">\n      Phishing emails masquerading as legitimate payment advice messages are being used to deliver ZIP archives, opening which triggers a multi-stage infection chain that leads to the deployment of Agent Tesla. \u00abIn simple terms, the victim opens what looks like a harmless file, but behind the scenes, a heavily obfuscated Batch script silently launches PowerShell, which then pulls and executes additional malicious code directly in memory,\u00bb Point Wild <a href=\"https:\/\/www.pointwild.com\/threat-intelligence\/from-phishing-email-to-process-injection-inside-a-multi-stage-agent-tesla-infection-chain\/\">said<\/a>. \u00abFrom there, the attack escalates into a staged execution chain involving shellcode decoding, persistence setup, and process injection into legitimate Windows applications like charmap.exe.\u00bb Agent, Tesla is designed to steal browser credentials, log keystrokes, capture screenshots, and extract sensitive data from the system. The collected information is then exfiltrated using SMTP-based communication, allowing malicious traffic to blend with normal-looking email activity.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI video lures spread malware<\/span><\/p>\n<p class=\"td-desc\">\n      Two social engineering campaigns are using AI-generated TikTok videos and Instagram Reels to direct users to sketchy sites that deploy Vidar Stealer and other dubious programs. \u00abOne methodology involves fake tutorials for software installs, with professional-sounding voice-overs and clean graphics,\u00bb ReversingLabs <a href=\"https:\/\/www.reversinglabs.com\/blog\/social-media-attacks-phishing\">said<\/a>. \u00abThe second approach relies on posts demonstrating how to use premium software for free, spanning multiple videos, with a centralized tutorial being introduced after the account gains traction.\u00bb\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Routers turned into C2 nodes<\/span><\/p>\n<p class=\"td-desc\">\n      A suspected China-nexus intrusion set has been identified conducting a large-scale campaign targeting edge network devices across Southeast Asia. \u00abThe adversary deploys a custom Linux ELF implant (router.elf) directly onto compromised border routers, establishing persistent command-and-control (C2) via DNS over HTTPS (DoH) while simultaneously weaponizing the router\u2019s iptables subsystem to hijack downstream DNS traffic at scale,\u00bb a security researcher named Y4er <a href=\"https:\/\/qiita.com\/Y4er\/items\/0b6071745e4b7b240b3e\">said<\/a>. \u00abCorrelated Windows-side tradecraft leverages a cracked Cobalt Strike 4.4 Beacon delivered via DLL sideloading (version.dll), sharing identical C2 infrastructure and malleable C2 profiles with the router implant \u2013 confirming unified operational control.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">RMM abused in Brazil<\/span><\/p>\n<p class=\"td-desc\">\n      An active phishing campaign has been observed targeting Brazilian organizations with fake business-document lures, resulting in the download of a NinjaOne Remote Monitoring and Management (RMM) agent. \u00abThe campaign begins with phishing emails that redirect victims to Portuguese-language landing pages impersonating familiar Brazilian workflows, including SEFAZ-related fiscal documents, Reclame Aqui-style complaint processes, and secure document-delivery portals,\u00bb Cato Networks <a href=\"https:\/\/www.catonetworks.com\/blog\/cato-ctrl-previously-undocumented-ninjaone-rmm-abuse-chain\/\">said<\/a>. \u00abAfter completing a fake verification process, victims are prompted to download what appears to be a protected business document. Instead, the download delivers a legitimate NinjaOne RMM agent configured to provide remote access to attacker-controlled infrastructure, highlighting a previously undocumented abuse of NinjaOne in the Brazilian threat Landscape.\u00bb The development once again highlights how threat actors no longer need to rely on bespoke malware to infiltrate organizations.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Money laundering goes MaaS<\/span><\/p>\n<p class=\"td-desc\">\n      Cybersecurity company KELA has shed light on money mule networks, which play a crucial role in modern cybercrime and financial fraud ecosystems, enabling threat actors to launder and monetize proceeds through ransomware, scams, and Business Email Compromise (BEC), and other illicit schemes. \u00abIn recent years, traditional mule recruitment has increasingly evolved into professionalized Mule-as-a-Service (MaaS) ecosystems that provide scalable laundering infrastructure to cybercriminals,\u00bb KELA <a href=\"https:\/\/www.kelacyber.com\/blog\/mule-as-a-service-money-laundering\/\">said<\/a>, adding \u00abmule operations increasingly rely on stolen identities, synthetic identities, compromised accounts, and AI-assisted onboarding techniques rather than solely recruiting human participants.\u00bb Threat actors have also been found to rely on forged documentation, deepfake-enabled KYC bypass methods, account takeover techniques, and automated account \u00abwarming\u00bb activity to set up resilient laundering infrastructures across multiple financial platforms.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI chats exposed<\/span><\/p>\n<p class=\"td-desc\">\n      G DATA said it has <a href=\"https:\/\/blog.gdatasoftware.com\/2026\/06\/38428-browser-addons-spy-on-ai-chats\">witnessed<\/a> a growing number of Google Chrome extensions that impersonate legitimate productivity tools while stealthily hijacking users\u2019 conversations with AI chatbots. Some of these include Urban VPN, Smart Sidebar: ChatGPT, Claude &amp; DeepSeek, and Chat AI, the last of which exhibits traits consistent with a campaign dubbed AiFrame. \u00abUser data generated through AI conversations may still be vulnerable to theft by threat actors utilizing plug-ins that pose as legitimate tools,\u00bb G DATA said.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">507 Meta repos exposed<\/span><\/p>\n<p class=\"td-desc\">\n      A public Meta IP address running an open Grafana instance acted as a pathway for read-write access to 507 private Meta repositories, netting the Sectricity Security Team a bug bounty of $157,000. \u00abThe pivot was a wildcard SAN on the TLS certificate: *.llm-playground.aws.metafb.cloud, which exposed a quiet shadow estate behind metafb.cloud,\u00bb the cybersecurity company <a href=\"https:\/\/sectricity.com\/blog\/misconfigured-grafana-507-private-meta-repos\/\">said<\/a>. \u00abBy parsing JavaScript bundles across that estate, we uncovered references to a previously unseen domain: api.haloworld.xyz, which became the next pivot point. Slight (AI built wordlist given JS bundles, context, etc) fuzzing against api.haloworld.xyz then exposed \/_api\/gcp-token, an unauthenticated endpoint that handed out a valid GCP OAuth2 token.\u00bb The GCP token, in turn, granted read access to the project\u2019s Secret Manager that contained a Vercel token. The Vercel token exposed 85 environment variables across Meta\u2019s projects, including multiple GitHub personal access tokens (PATs) and other secrets. One of those GitHub tokens had read\/write access to 507 private repositories.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">7M seniors\u2019 data sold<\/span><\/p>\n<p class=\"td-desc\">\n      Troy Murray, 57, of Hickory, North Carolina, has been sentenced to more than 10 years in prison for selling the personal information of over 7 million elderly Americans to Jamaican lottery fraud scammers. He has also been ordered to pay a forfeiture in the amount of $5,214,688.48. Murray \u00abdevised a scheme where he organized, maintained, and sold lists containing the names, phone numbers, physical addresses, and, in some cases, ages and email addresses, of elderly Americans to individuals in Jamaica involved in lottery fraud schemes,\u00bb the U.S. Justice Department <a href=\"https:\/\/www.justice.gov\/opa\/pr\/fraudster-who-sold-personal-information-over-7-million-elderly-americans-jamaican-scammers\">said<\/a>. \u00abFrom 2016 to 2023, Murray sold these lists to Jamaican scammers, who perpetrated lottery fraud on elderly American consumers, earning Murray hundreds of thousands of dollars each year.\u00bb Each of these lists was sold for $500.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">One-packet crash bug<\/span><\/p>\n<p class=\"td-desc\">\n      Security researcher Marcus Hutchins has released details and a proof-of-concept (PoC) exploit for ComoDoS, an integer underflow vulnerability residing in Comodo Internet Security\u2019s firewall driver, Inspect.sys (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-49494\">CVE-2026-49494<\/a>, CVSS score: 7.5). \u00abAlthough the vulnerability can be used to remotely trigger both an out-of-bounds (OOB) read and out-of-bounds write in the Windows kernel, the limitations on both primitives lead me to believe it\u2019s unlikely this bug could be weaponized into RCE,\u00bb Hutchins <a href=\"https:\/\/malwaretech.com\/2026\/06\/exploiting-a-remote-kernel-vulnerability-in-comodo-internet-security.html\">said<\/a>. \u00abThe bug does, however, enable you to remotely crash the target system with a single TCP\/IP packet, even if the firewall is configured to block all ports.\u00bb The vulnerability remains unpatched as of writing.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">CI\/CD secrets exposed<\/span><\/p>\n<p class=\"td-desc\">\n      Microsoft said it discovered an issue in the Claude Code GitHub Action that could be exploited to expose CI\/CD workflow secrets when AI agents process untrusted GitHub content, including issue bodies, pull request descriptions, and comments. \u00abWhile Claude Code Action supported environment scrubbing for subprocess execution paths such as Bash, the Read tool was not subject to the same sandboxing model,\u00bb the Windows maker <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/06\/05\/securing-ci-cd-in-agentic-world-claude-code-github-action-case\/\">said<\/a>. \u00abIt was eventually authorized to access \/proc\/self\/environ, reading the workflow\u2019s ANTHROPIC_API_KEY and potentially other credentials available to the runner.\u00bb Following responsible disclosure on April 29, 2026, the issue was fixed on May 5 with the release of Claude Code version 2.1.128. The patch strengthens the Read tool by unconditionally rejecting a number of files in \/proc\/ in order to protect those files from exfiltration.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fake $200K job lure<\/span><\/p>\n<p class=\"td-desc\">\n      The Iranian hacking group known as Nimbus Manticore approached an employee via LinkedIn by impersonating a headhunter, luring them with a salary offer of $200,000 per year. Per Nextron Systems, the interaction is said to have redirected the victim to a fake hiring portal branded as Ebix Recruitment that prompted them to enter temporary credentials received from the recruiter to log in to the website. \u00abAfter authentication, the portal prompted the victim to download a two-factor authentication application for \u2018additional security,&#8217;\u00bb the company <a href=\"https:\/\/www.nextron-systems.com\/2026\/06\/01\/detecting-nimbus-manticore-and-their-sideloading-infection-chains\/\">said<\/a>. \u00abThe advertised 2FA application was delivered as a ZIP archive and contained the malware payload.\u00bb The attack culminates with the deployment of a custom implant with data exfiltration and remote control capabilities.\n    <\/p>\n<\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Backdoor with wiper modules<\/span><\/p>\n<p class=\"td-desc\">\n      Cybersecurity researchers have flagged a new Golang backdoor called BLUERABBIT that routes C2 through RabbitMQ for tasking, Redis for state management, and MinIO for S3-compatible data exfiltration. \u00abIt is a full-spectrum intrusion tool: remote access, system profiling, file encryption with a .candy extension, and two distinct disk-wiping modules capable of rendering systems permanently unrecoverable,\u00bb Binary Defense <a href=\"https:\/\/binarydefense.com\/resources\/blog\/bluerabbit-a-golang-based-backdoor-with-ransomware-and-destructive-capabilities\">said<\/a>. The backdoor is assessed to be the work of an Iran-nexus threat actor. It was first observed in mid-to-late March 2026, and is likely used for targeting entities in Israel. BLUERABBIT is \u00abrelated to the same likely Iran-nexus activity cluster that previously leveraged BLUEWIPE and SEWERGOO in June 2025,\u00bb it added.\n    <\/p>\n<\/div>\n<\/li>\n<\/ol>\n<\/section>\n<\/div>\n<p>The throughline is simple: attackers do not always need exploits. They need patience, stolen credentials, trusted tools, and one policy setting nobody has checked since the last reorg. The perimeter is not the real problem anymore. The problem is everything inside it that still trusts by default.<\/p>\n<p>Same old lesson: audit what your agents can access, treat every identity in the pipeline as a risk, and check what your browser extensions are sending home. See you Thursday.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>It\u2019s been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there\u2019s a supply chain attack kit in a public repo, a $5,000-a-month RAT that clones browsers, and research showing AI agents can be tricked into leaking real credentials. The bigger problem is how polished [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,5],"tags":[3055,1602,16,1046,24,3053,3012,3054,23,1161],"class_list":["post-1161","post","type-post","status-publish","format-standard","hentry","category-noticias","category-trending","tag-action","tag-agent","tag-claude","tag-code","tag-cyberdefensa-mx","tag-leaked","tag-patch","tag-phished","tag-stories","tag-worm"],"_links":{"self":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts\/1161","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/comments?post=1161"}],"version-history":[{"count":0,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts\/1161\/revisions"}],"wp:attachment":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/media?parent=1161"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/categories?post=1161"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/tags?post=1161"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}