Weekly review

ThreatNoir Morning Brief — June 17

2026-06-17Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — June 17, 2026

The threat landscape continues to evolve on multiple fronts as adversaries target cloud infrastructure, open-source ecosystems, and developer tools with increasing sophistication. Today's briefing covers critical vulnerabilities in machine learning platforms, novel evasion techniques against AI-powered security scanners, and coordinated attacks on developer infrastructure.

Google Vertex AI SDK Flaw Enables Model Hijacking via Bucket Squatting

A vulnerability discovered in the Google Cloud Vertex AI SDK for Python allows attackers without any access to a victim's project to intercept and hijack machine learning model uploads while executing arbitrary code within Google's serving infrastructure. Researchers at Palo Alto Networks Unit 42 identified the flaw through Google's bug bounty program and designated the attack technique "Pickle in the Middle." The vulnerability exploits predictable bucket naming conventions in the SDK, enabling an attacker to claim intermediate storage buckets and inject malicious code during the model upload process. Unit 42 reported no evidence of active exploitation in the wild at the time of disclosure. Source: The Hacker News

npm Package Weaponizes Prompt Injection and Context Flooding Against AI Scanners

Socket Threat Research identified shai_hulululud@1.0.48596, a newly published npm package that appears deliberately engineered to test and disrupt AI-based malware scanners. The package combines multiple adversarial techniques including policy-triggering prompt content designed to activate AI safety guardrails, fake system override instructions embedded in JavaScript comments, tens of thousands of repetitive comment lines for context flooding, and heavily obfuscated JavaScript payloads. The approximately 9.28 MB index.js file exceeds 3.5 million tokens, far beyond the context window of current frontier models, forcing scanners to either truncate analysis or exhaust computational resources before reaching executable code. While classified as protestware rather than a sophisticated stealer, the package demonstrates a significant tactical shift in which attackers now target the AI systems used to analyze their code rather than merely evading static rules or human review. Source: Socket Threat Research

Malicious JetBrains Marketplace Plugins Target Developer AI API Keys

At least 15 malicious plugins discovered on the official JetBrains Marketplace were designed to steal AI API keys directly from developers. The compromised plugins exploited the trusted nature of the JetBrains ecosystem to gain access to developer credential stores and API authentication tokens used for AI services. This supply-chain attack vector demonstrates how threat actors continue to infiltrate trusted development tool marketplaces to harvest sensitive credentials from high-value targets. Source: Bleeping Computer

SprySOCKS Windows Variant Abuses Kernel Drivers for Detection Evasion

FishMonger, a China-nexus threat group, has deployed a previously undocumented Windows variant of the SprySOCKS backdoor against government targets across Honduras, Taiwan, Thailand, and Pakistan. The malware leverages kernel driver abuse techniques to evade Windows security tools and maintain persistent access on compromised systems. This represents a significant escalation in the group's operational capabilities and geographic targeting. Source: Dark Reading

Today's threat intelligence reflects a coordinated evolution across multiple attack surfaces. Cloud infrastructure, open-source supply chains, and developer tools remain primary targets, while adversaries demonstrate increasing sophistication in evasion techniques and AI-aware attack design. Organizations should prioritize patching cloud SDKs, implementing deterministic preprocessing in AI-assisted security tools, vetting marketplace plugins, and monitoring for kernel-level persistence mechanisms.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).