77.83.39.211C2 server
ThreatNoir Afternoon Brief — June 1
Afternoon Review in IT Security — June 1, 2026
The threat landscape continues to evolve with critical vulnerabilities being actively exploited and sophisticated supply chain attacks targeting developers. Today's review covers a long-standing Linux kernel flaw now weaponized, fileless malware campaigns leveraging email trust, rapid exploitation of network security vulnerabilities, and malicious packages compromising OpenAI credentials.
19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access
A decades-old vulnerability in the Linux kernel has become an immediate concern following the release of proof-of-concept exploit code. The CIFSwitch flaw allows low-privileged users to escalate their privileges to root on vulnerable Linux systems, creating a significant security risk across organizations relying on affected kernel versions. Source: SecurityWeek
The availability of working exploit code dramatically increases the likelihood of widespread attacks against unpatched systems. Organizations running legacy or outdated Linux kernels should prioritize assessment and patching efforts to mitigate the risk of unauthorized root access and complete system compromise.
Fake Purchase Order Emails Spread Fileless PureLogs Malware via RAR Archives
Threat actors are leveraging trust in business communications to distribute fileless malware through fraudulent purchase order emails. The PureLogs malware employs process hollowing techniques to evade traditional detection methods while targeting sensitive data including browser credentials, cryptocurrency wallets, and Discord account information from Windows users. Source: Hackread
The use of RAR archives as delivery containers and fileless execution techniques represents an evolution in evasion tactics designed to bypass endpoint security controls. Users should exercise heightened caution when receiving unsolicited purchase order communications and verify requests through out-of-band channels before opening attachments.
Recent Palo Alto Networks Vulnerability Exploited for Weeks
An authentication bypass vulnerability in Palo Alto Networks PAN-OS, identified as CVE-2026-0257, began experiencing active exploitation just four days after public disclosure. The rapid weaponization of this flaw demonstrates the compressed timeline between vulnerability announcement and real-world attacks targeting network security infrastructure. Source: SecurityWeek
Organizations operating Palo Alto Networks appliances should have implemented patches immediately upon availability. The speed of exploitation underscores the critical importance of maintaining rapid patch deployment capabilities for internet-facing security infrastructure.
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack
A malicious npm package named codexui-android has been identified stealing OpenAI authentication tokens from developers. The package, advertised as a legitimate remote web UI for OpenAI Codex and attracting over 29,000 weekly downloads, remains available in the repository despite its malicious nature. Source: The Hacker News
This supply chain attack demonstrates the persistent risk posed by compromised open-source packages targeting developer tools and credentials. The high download volume indicates significant exposure, and developers who have installed this package should immediately rotate their OpenAI authentication credentials and audit their development environments for signs of compromise.
Today's threat intelligence highlights the necessity for comprehensive patch management programs, vigilant email security practices, rapid response capabilities for critical vulnerabilities, and careful vetting of open-source dependencies in development workflows.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- codexui-androidMalicious npm package
- OpenClaw Codex Claude AI AgentMalicious Android application
sentry.anyclaw[.]storeAttacker-controlled server masquerading as Sentry for exfiltrating Codex authentication tokens