outsider.netCore admin server domain seized as part of Operation Ghost Hook.
ThreatNoir Weekend Brief — June 13
Morning Review in IT Security — June 13, 2026
The threat landscape on June 13, 2026, reflects a particularly active period across multiple attack vectors, from nation-state infrastructure takedowns and zero-day exploits targeting critical systems to supply-chain compromises affecting open-source communities and browser extensions. Organizations face intensifying pressure to patch vulnerabilities, secure authentication mechanisms, and validate the integrity of third-party software.
FBI Dismantles China-Based Cybercrime Network Behind $1.9 Billion in Losses
Law enforcement has successfully taken down a massive cybercrime operation originating from China that caused approximately $1.9 billion in financial losses globally. The network, known as Outsider, provided phishing kits and supporting infrastructure that enabled cybercriminals to conduct large-scale scams targeting victims with deceptive messages claiming missed package deliveries, unpaid tolls, and parking violations. The operation demonstrates the scale at which organized cybercrime can operate when infrastructure providers actively support fraudulent activities at scale. Source: FBI takes down massive China-based cybercrime network that caused $1.9B in losses
ShinyHunters Exploits Oracle Zero-Day to Target Higher Education Institutions
A critical vulnerability in Oracle's Enterprise Resource Planning software has become the focal point of a coordinated attack campaign against American universities. The threat actor group ShinyHunters has capitalized on the zero-day flaw to breach multiple higher education institutions and exfiltrate substantial volumes of sensitive data. The disproportionate impact on the academic sector underscores how zero-day exploits in widely-deployed enterprise software can create cascading risks across entire industry verticals. Source: ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
Critical Windows Kernel Vulnerability Enables Browser Sandbox Escape
Security researchers have disclosed CVE-2026-40369, a severe Windows kernel vulnerability that permits attackers to escape browser sandboxes and achieve SYSTEM-level privileges on affected systems. The flaw, reachable through the NtQuerySystemInformation API, requires only twelve bytes of kernel write capability to achieve complete system compromise from within a browser's restricted execution environment. This vulnerability represents a fundamental threat to the isolation guarantees that browsers depend upon to protect users from malicious web content. Source: CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox - VoidSec
Over 400 Arch Linux AUR Packages Compromised with Credential Stealer and eBPF Rootkit
Attackers have successfully compromised more than 400 packages within the Arch User Repository, rewriting build scripts to deploy a sophisticated credential-stealing Rust binary on systems that compile the affected software. When executed with root privileges, the malware can additionally load an eBPF rootkit designed to hide its presence from detection mechanisms. The AUR's community-driven model, while enabling rapid package distribution, has created an attack surface where compromised developer accounts can poison the supply chain at scale. Source: Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit
phpBB Forum Software Patched for Decade-Old Authentication Bypass
The phpBB forum software has been patched to address a ten-year-old authentication bypass vulnerability that permitted attackers to log in as arbitrary users, including administrative accounts. The extended timeline between vulnerability introduction and discovery highlights critical gaps in security review practices for widely-deployed open-source projects and underscores the risks posed by legacy code paths that persist without adequate scrutiny. Source: phpBB forum fixes auth bypass bug lurking for a decade
China-Linked Group Maintained Decade-Long Persistence Through Backdoored Linux Authentication Components
A China-nexus threat actor group, tracked as Velvet Ant by Sygnia, has been discovered maintaining persistent access to targeted networks for nearly a decade by backdooring the PAM and OpenSSH authentication components. Rather than establishing presence on monitored endpoints, the group embedded itself within the Linux login system itself, positioning access where routine cleanup and forensic analysis would not detect it. The extended dwell time demonstrates the effectiveness of targeting foundational authentication infrastructure as a persistence mechanism. Source: China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
May 2026 CVE Landscape Shows 11 Percent Increase in High-Impact Vulnerabilities
Insikt Group identified 41 high-impact vulnerabilities in May 2026 that warrant immediate remediation priority, all carrying a Very Critical Recorded Future Risk Score. This represents an 11 percent increase from the previous month, indicating an accelerating pace of critical vulnerability disclosure. The volume and severity of disclosed flaws continue to outpace organizational patching capacity, creating an expanding window of exposure across enterprise environments. Source: May 2026 CVE Landscape
Malicious Chrome Extensions Bypass Store Security to Deploy Ad Fraud and Telemetry
A network of 152 Chrome Web Store extensions masquerading as "live wallpaper" applications has been discovered deploying undisclosed telemetry collection, deceptive traffic attribution fraud, and anti-forensic capabilities across approximately 105,000 installations. The extensions fabricate Google organic search attribution through forged utm parameters and cloaked google.com/url redirects, laundering extension-driven traffic to appear as legitimate user searches. The operation spans 38 separate publisher accounts across three brand domains, deliberately fragmenting the network to resist takedown efforts. The Chrome Web Store privacy disclosures falsely claim no data collection while the linked privacy policies admit logging IP addresses, ISP information, and click data shared with Google AdSense, DoubleClick, and third-party ad partners. Source: 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic
The convergence of infrastructure takedowns, zero-day exploits, supply-chain compromises, and browser-based fraud demonstrates that threat actors continue to operate across the full spectrum of attack surfaces. Organizations must prioritize vulnerability management, implement software supply-chain verification, and enforce strict extension policies to mitigate exposure to these evolving threats.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Windows kernel arbitrary write vulnerability
- eBPF rootkitStealth and persistence mechanism
- deps.linux.elfName of the infostealer payload
- Cisco NX-OS flaw exploited by Velvet Ant for persistence.
- Microsoft Windows vulnerability, actively exploited, RCE, PoC available.
- Ghost CMS vulnerability, actively exploited, PoC available.
- Drupal Core vulnerability, actively exploited, RCE, PoC available.
- Daemon Tools Lite vulnerability, actively exploited.
- Ivanti Endpoint Manager Mobile (EPMM) vulnerability, actively exploited, RCE.
- LiteSpeed cPanel Plugin vulnerability, actively exploited, RCE, PoC available.
- Nx Console vulnerability, actively exploited.
- Microsoft Defender vulnerability, actively exploited.
- TanStack (Multiple Packages) vulnerability, actively exploited, RCE, PoC available.
- Microsoft Exchange Server vulnerability, actively exploited, RCE, PoC available.
- BerriAI LiteLLM vulnerability, actively exploited, RCE, PoC available.
- Microsoft Defender vulnerability, actively exploited, RCE, PoC available.
- Trend Micro Apex One (On-Premise) vulnerability, actively exploited.
- Linux Kernel vulnerability, actively exploited, RCE, PoC available.
- Cisco Catalyst SD-WAN and SD-WAN Manager vulnerability, actively exploited, RCE, PoC available.
- Palo Alto Networks PAN-OS, Cloud NGFW, Prisma Access vulnerability, actively exploited, RCE, PoC available.
- Palo Alto Networks PAN-OS, Cloud NGFW, and Prisma Access vulnerability, actively exploited, RCE, PoC available.
- Langflow vulnerability, actively exploited, RCE, PoC available.
- Microsoft Internet Explorer vulnerability, actively exploited, RCE, PoC available.
- Microsoft Internet Explorer vulnerability, actively exploited, RCE, PoC available.
- Adobe Acrobat and Reader vulnerability, actively exploited.
- Microsoft DirectX vulnerability, actively exploited.
- Acquire Infrastructure: Domains
- Application Layer Protocol: Web Protocols
- Indicator Removal
- Masquerading
- Browser Extensions
tabplugins.comBackend domain for 109 extensions, associated with forged Google attribution and cloaked uninstall redirects.owhit.comRedirect target for chromewallpaper.com, associated with operator contact information.chromewallpaper.comBackend domain for 13 extensions, redirects to owhit.com.yowgames.comBackend domain for 19 extensions, shipping core functionality without forged Google attribution.
hxxps://avads[[.]]live/s/av-tabplugins[.]jsAd bundle URL serving for the tabplugins.com cluster.hxxps://www[.]google[.]com/url?sa=t&source=web&rct=j&opi=89978449&url=https://tabplugins[.]com/live-wallpaper/&ved=2ahUKEwigjZv3_sqUAxWaTKQEHVVYOFUQFnoECB4QAQ&usg=AOvVaw3S1cD8TWcvQUivIwcBGtSpExample uninstall URL wrapped in a fake Google search-result click.hxxps://tabplugins[.]com/tanjiro-demon-slayer-live-wallpaper/?utm_source=google&utm_medium=organic&utm_campaign=tanjiro-demon-slayer-live-wallpaperExample install URL with fabricated Google organic search attribution.
support[@]owhit.comOperator contact email.yahyagazi06[@]gmail.comOperator contact email, potentially linked to Turkey.keremsopar[@]gmail.comPublisher account contact email, potentially linked to Turkey.ferhatbadem831[@]gmail.comPublisher account contact email, potentially linked to Turkey.hussnain1122akram[@]gmail.comPublisher account contact email.hirakiranpk[@]gmail.comPublisher account contact email.