- SolarWinds Serv-U RCE vulnerability previously exploited by Clop and DEV-0322
- SolarWinds Serv-U path-traversal vulnerability actively exploited in June 2024
- SolarWinds Serv-U denial-of-service vulnerability actively exploited in the wild
ThreatNoir Weekend Brief — June 6
Morning Review in IT Security — June 6, 2026
The cybersecurity landscape continues to intensify as multiple critical threats emerge across supply chain ecosystems, cloud infrastructure, and industrial control systems. Today's briefing covers active exploitation campaigns targeting enterprise software, widespread compromises of open-source packages, and emerging vulnerabilities in critical infrastructure that demand immediate attention from security teams worldwide.
CISA Warns of Active SolarWinds Serv-U Exploitation
The Cybersecurity and Infrastructure Security Agency has issued an alert regarding active exploitation of a high-severity vulnerability in SolarWinds Serv-U. Threat actors are leveraging recently patched flaws to conduct denial-of-service attacks against affected servers. The vulnerability represents a significant risk to organizations relying on Serv-U for file transfer and remote access capabilities. Source: CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
Miasma Malware Compromises 32 Red Hat npm Packages
A supply chain attack has resulted in the compromise of 32 Red Hat npm packages through a breached GitHub account. The Miasma malware family, along with the Mini Shai-Hulud variant, has been deployed to expose cloud tokens, CI/CD secrets, and developer credentials across affected systems. This incident underscores the persistent threat to open-source software repositories and the need for enhanced authentication controls on developer accounts. Source: Miasma Malware Hits 32 Red Hat Packages via Compromised GitHub Account
Chinese APT UNC5221 Deploys New Backdoors for Persistent Access
A Chinese espionage group tracked as UNC5221 has been maintaining access to compromised Microsoft 365 environments using multiple malware families including Brickstorm, Plenet, and the previously undocumented AgentPSD. The threat actor has demonstrated sophisticated persistence capabilities, leveraging these tools to maintain long-term access to victim networks while remaining undetected. Source: Chinese APT deploys new malware to keep access to hacked networks
npm Ecosystem Hit by IronWorm and Miasma Worm Variants
The npm package repository has become the target of coordinated supply chain attacks distributing both IronWorm, a Rust-based information stealer, and a self-spreading Miasma worm variant. Threat actors have poisoned over 50 legitimate packages to distribute these malicious payloads. The IronWorm stealer is particularly concerning due to its ability to scrape secrets from developer machines and hide behind an eBPF kernel rootkit, providing attackers with deep system access. Source: IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
PAN-OS Vulnerability CVE-2026-0257 Under Active Exploitation
Palo Alto Networks has disclosed that CVE-2026-0257 in PAN-OS is currently under active exploitation by threat actors. The vulnerability enables authentication bypass attacks against affected firewall systems. Security researchers have identified multiple malicious IP addresses conducting exploitation attempts, and mitigation guidance has been released for organizations running vulnerable versions. Source: Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
Claude Code GitHub Action Vulnerability Exposes Workflow Secrets
Microsoft Threat Intelligence has identified a prompt injection vulnerability in the Claude Code GitHub Action that could allow attackers to access workflow secrets under specific conditions. The research demonstrates how AI-powered CI/CD tools introduce new attack surfaces when integrated into development pipelines. Anthropic has implemented mitigations, and the disclosure highlights the importance of securing AI-powered automation tools in software development environments. Source: Securing CI/CD in an agentic world: Claude Code Github action case
Over 900 US Gas Station Tank Gauge Systems Exposed Online
Security researchers have discovered more than 900 automatic tank gauge systems across the United States exposed to internet-accessible attacks. These systems, which monitor fuel and chemical storage tanks in critical infrastructure sectors including gas stations, are vulnerable to unauthorized access and potential manipulation. The exposure represents a significant risk to fuel supply chain integrity and public safety. Source: Over 900 US gas station tank gauge systems exposed to attacks
Polyfill CDN Compromise Affects Toshiba and Muji Websites
Toshiba and Muji have warned customers of suspicious login prompts appearing on their websites following a compromise of the polyfill.io content delivery network. The attack leverages compromised polyfill domains including polyfill.com, polyfill.io, and polyfill.top to inject credential-harvesting prompts into legitimate websites. This incident demonstrates how third-party CDN compromises can rapidly affect multiple major organizations and expose user credentials to attackers. Source: Suspicious Polyfill login prompts pop up on Toshiba, Muji websites
Today's threat landscape reflects an escalating pattern of supply chain attacks, persistent advanced threats, and infrastructure vulnerabilities that require coordinated response efforts across industry sectors. Organizations should prioritize patching critical vulnerabilities, implementing supply chain security controls, and monitoring for indicators of compromise related to the malware families and threat actors highlighted in this briefing.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- MiasmaSelf-propagating credential-stealing worm variant based on Mini Shai-Hulud; deployed via compromised Red Hat npm packages.
- Mini Shai-HuludOpen-source malware framework published by TeamPCP on BreachForums; basis for Miasma variant.
- PlenetCross-platform .NET-based backdoor also tracked as Grimbolt; offers interactive shell and remote command execution
- AgentPSDPython-based reverse shell utility used as fallback persistence mechanism by UNC5221
- BrickstormAdvanced backdoor malware implant used by UNC5221 for persistent access; written in Golang and Rust variants
- IronWormRust-based information stealer with eBPF kernel rootkit, distributed via poisoned npm packages
- Miasma wormSelf-spreading worm variant infecting npm packages; 57 packages compromised across 286 versions
claude[@]users.noreply.github.comAuthor name used in malicious GitHub commits to impersonate Anthropic's Claude AI
- Authentication bypass in PAN-OS GlobalProtect portal and gateway components
23.128.228.6Attacker IP observed in pre-PoC exploitation activity; search GlobalProtect logs202.144.192.47Attacker IP observed in pre-PoC exploitation activity; search GlobalProtect logs198.12.106.60Attacker IP observed in pre-PoC exploitation activity; search GlobalProtect logs185.195.232.139Attacker IP observed in pre-PoC exploitation activity; search GlobalProtect logs179.43.172.213Attacker IP observed in pre-PoC exploitation activity; search GlobalProtect logs146.19.216.125Attacker IP observed in pre-PoC exploitation activity; search GlobalProtect logs146.19.216.120Attacker IP observed in pre-PoC exploitation activity; search GlobalProtect logs146.19.216.119Attacker IP observed in pre-PoC exploitation activity; search GlobalProtect logs104.207.144.154Attacker IP observed in pre-PoC exploitation activity; search GlobalProtect logs
- Unauthorized read of workflow environment variables containing secrets
- XSS payload injection into repository files via AI-assisted workflow
- AI agent executing commands via natural language instruction
polyfill.topSecondary legitimate domain for Polyfill servicepolyfill.comLegitimate replacement domain launched by Andrew Bettspolyfill.ioMalicious CDN serving fake authentication prompts; reactivated in May 2026