Weekly review

ThreatNoir Morning Brief — June 4

2026-06-04Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — June 4, 2026

Today's threat landscape reveals critical vulnerabilities spanning nation-state operations, AI security gaps, infrastructure attacks, and mobile platform weaknesses. Organizations face immediate risks from multiple vectors requiring urgent attention and remediation efforts.

Chinese Hackers Deploy New Atlas RAT Malware in European Cyberattacks

A Chinese-speaking cybercrime group has significantly expanded its operational scope to target European organizations with previously undocumented malware capabilities. The threat actors are deploying the Atlas backdoor alongside multiple loader variants including RomulusLoader, SilentRunLoader, and Winos4.0, indicating a sophisticated and evolving toolkit designed for persistent access and lateral movement. This campaign demonstrates the group's intent to establish footholds in European infrastructure through coordinated supply-chain and targeted phishing operations.

Source: Chinese hackers use new Atlas RAT malware in European cyberattacks

WhatsApp and Slack Notifications Could Hijack Google Gemini on Android

A critical vulnerability in Google Gemini's voice assistant implementation on Android devices allows attackers to hijack the AI system through poisoned notifications originating from mainstream communication platforms including WhatsApp, Slack, SMS, Signal, Instagram, and Messenger. A single malicious notification could enable attackers to open victim windows, fabricate messages from authority figures, initiate unwanted video calls, or compromise the assistant's long-term memory without requiring any malicious application installation on the target device. This attack vector exploits the assistant's notification processing logic, creating a significant security gap in AI-powered mobile interfaces.

Source: WhatsApp, Slack Notifications Could Hijack Google Gemini on Android

HTTP/2 Bomb DoS Attack Crashes Web Servers in Under a Minute

A newly discovered denial-of-service attack designated HTTP/2 Bomb enables attackers to incapacitate web servers within seconds using a single machine, exploiting fundamental flaws in HTTP/2 protocol implementation tracked as CVE-2026-49975. The attack's efficiency and low resource requirements present an immediate threat to web infrastructure globally, allowing threat actors to launch devastating service disruptions without sophisticated distributed attack infrastructure. Organizations running vulnerable HTTP/2 implementations face urgent risk of availability loss.

Source: New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute

Microsoft 365 Android Apps Allow Token Theft via Production Debug Flag

Multiple Microsoft 365 Android applications contain a critical vulnerability stemming from a development debug flag that remains enabled in production builds, disabling the security mechanism that restricts account-token sharing to trusted Microsoft applications. This configuration flaw allows any application installed on the same device to request and obtain signed-in user tokens without authentication prompts or permission dialogs, enabling unauthorized access to email, files, calendar data, and messaging capabilities tracked under CVE-2026-41100, CVE-2026-41101, CVE-2026-41102, and CVE-2026-42832. The vulnerability represents a fundamental identity and access control failure requiring immediate patching across all affected Microsoft 365 mobile deployments.

Source: Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

Security teams must prioritize immediate remediation of these vulnerabilities, particularly the Microsoft 365 token theft and HTTP/2 implementation flaws, while implementing network segmentation and notification filtering to mitigate the Gemini hijacking risk. Continuous monitoring for Atlas RAT indicators of compromise remains essential for European-based organizations.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Chinese hackers use new Atlas RAT malware in European cyberattacks
Malware4
  • Winos4.0
    Previously documented malware (tracked as ValleyRAT) providing remote access features deployed by TA4922
  • Atlas RAT
    Remote access trojan with reconnaissance, file theft, keylogging, and surveillance capabilities deployed by TA4922
  • RomulusLoader
    Custom malware loader using process hollowing and shellcode injection to deploy AnyDesk and SyncFuture
  • SilentRunLoader
    Python-based loader and information stealer targeting Google Chrome credentials and browsing data