Back to Weekly Roundups
2026-W24 Classification: PUBLIC

WEEKLY INTELLIGENCE BRIEFING

2026-06-08 to 2026-06-14 80 articles

Articles scanned
80
Top IOCs
15
The week persistence met supply chain chaos

Tagline

The week persistence met supply chain chaos

Executive Summary

The week in one line

Chinese espionage persisted for a decade while supply chains cracked under coordinated attacks.

What happened

The cybersecurity landscape saw sustained nation-state campaigns and supply chain compromises dominating threat activity. Law enforcement operations disrupted major criminal infrastructure while new AI governance concerns emerged.

  • Chinese Velvet Ant group ran undetected espionage for nearly 10 years using backdoored Linux authentication
  • ShinyHunters exploited Oracle PeopleSoft zero-day CVE-2026-35273 to breach 100+ universities globally
  • Attackers compromised 400+ Arch Linux packages via npm typosquat, deploying rootkit and credential stealer
  • US government ordered Anthropic to disable advanced AI models over national security jailbreak concerns
  • FBI dismantled Chinese phishing network causing $1.9 billion in losses across 55 countries

Why it matters for defenders and leaders

This week highlighted the persistence of advanced threats and the vulnerability of trusted software ecosystems. The combination of decade-long espionage campaigns and rapid supply chain compromises shows attackers operating across multiple timescales simultaneously.

  • Legacy authentication systems remain deeply compromised by nation-state actors with years of persistence
  • Package repositories and software supply chains are under active, sophisticated attack
  • AI model governance is becoming a national security issue requiring immediate policy responses
  • Educational institutions face concentrated targeting due to valuable research data and weaker security postures

What to do this week

  • Patch Oracle PeopleSoft CVE-2026-35273 and Ivanti Sentry CVE-2026-10520 immediately
  • Audit Linux PAM modules and OpenSSH configurations for unauthorized modifications
  • Review package dependencies in AUR, npm, and PyPI for suspicious recent updates
  • Enable stricter controls on automated script execution from package managers
  • Assess AI model access policies and export control compliance requirements
TLDR
  • 🎯 Chinese hackers ran decade-long espionage using backdoored Linux authentication
  • 🏫 Oracle zero-day CVE-2026-35273 exploited by ShinyHunters to ransack universities worldwide
  • 🐧 400+ Arch Linux packages hijacked to deliver rootkit and credential stealer via npm typosquat
  • 🤖 US government forces Anthropic to disable advanced AI models over national security concerns
  • 📱 FBI dismantles massive Chinese phishing network causing $1.9B in losses
  • ⚖️ Ukrainian Conti ransomware member pleads guilty, faces 20 years for $150M extortion campaign

Intelligence Breakdown

6 modules
Vulnerabilities & Exploits
VULNERABILITIES-AND-EXPLOITS
2026-W24

ShinyHunters exploits Oracle PeopleSoft zero-day to target 100+ universities. CVE-2026-35273 allows remote code execution and has been actively exploited since late May to exfiltrate sensitive academic data.

Critical Ivanti Sentry flaw added to CISA KEV catalog. CVE-2026-10520 enables OS command injection and is being exploited to backdoor exposed gateways.

Chrome 149 patches 28 vulnerabilities including 5 critical flaws. Majority are use-after-free memory bugs that could enable remote code execution.

Browser sandbox escape vulnerability disclosed. CVE-2026-40369 allows attackers to escape browser sandboxes with just 12 bytes and achieve SYSTEM privileges on Windows.

Key Takeaway

Patch Oracle PeopleSoft, Ivanti Sentry, and Chrome immediately - these are seeing active exploitation.

Supply Chain & Package Repositories
SUPPLY-CHAIN-AND-PACKAGE-REPOSITORIES
2026-W24

Over 400 Arch Linux AUR packages compromised. Attackers took over abandoned packages, injecting malicious npm dependency 'atomic-lockfile' to deploy Rust-based credential stealer and eBPF rootkit.

152 Chrome wallpaper extensions tracked users despite privacy claims. Extensions built from single codebase logged user data, shared with ad partners, and faked Google search traffic across 38 publisher accounts.

NPM 12 will block dependency scripts by default. July release prevents automatic script execution from dependencies to stop supply chain attacks like the recent Shai-Hulud worm.

PyPI typosquat 'pylogxo' delivered Sirkeira Stealer. Malicious package impersonated 'pylogx' to harvest browser credentials, Discord tokens, and Roblox accounts.

Key Takeaway

Audit your package dependencies and enable stricter controls on automated script execution.

APT & Nation-State Activity
APT-AND-NATION-STATE-ACTIVITY
2026-W24

Chinese Velvet Ant group ran decade-long espionage campaign. Attackers compromised isolated infrastructure by backdooring PAM modules and OpenSSH components starting in 2016.

Iranian Handala group claims California Water Service hack. Group exfiltrated 5GB of customer data and gained access to RTKBase platform and billing systems.

Iran and Russia create fake maritime registries to evade sanctions. Shadow fleets use 36+ inauthentic websites impersonating maritime organizations to generate fraudulent compliance documents.

Key Takeaway

Harden authentication systems and monitor for unusual access patterns in critical infrastructure.

Ransomware & Breaches
RANSOMWARE-AND-BREACHES
2026-W24

Ukrainian Conti ransomware member pleads guilty. Oleksii Lytvynenko admitted to wire fraud conspiracy in operation that extorted $150M from 1,000+ victims.

Novo Nordisk discloses clinical trial data breach. Attackers copied pseudonymized patient data and healthcare professional PII from internal systems.

ShinyHunters adds major infrastructure companies to leak site. Group lists Zayo Group, Allstream, and American Tower on dark web portal following Oracle exploitation campaign.

Key Takeaway

Segment sensitive data systems and prepare incident response plans for healthcare and infrastructure sectors.

Law Enforcement Operations
LAW-ENFORCEMENT-OPERATIONS
2026-W24

FBI dismantles massive Chinese phishing network causing $1.9B losses. Operation Ghost Hook disrupted Outsider PhaaS platform operating across 55 countries with AI-generated lures.

International operation shuts down AudiA6 crypto laundering service. US Secret Service and IRS-CI arrested two suspects for laundering $389M in ransomware and dark web proceeds.

INTERPOL takedown of Sniper Dz phishing platform results in 201 arrests. Decade-old PhaaS platform collected 45,000+ victim records across MENA region.

Key Takeaway

Coordinated international enforcement is disrupting major cybercrime infrastructure - update threat intelligence accordingly.

Regulatory Updates

Regulatory & AI Governance
Action items and policy signal

US government forces Anthropic to disable advanced AI models. Commerce Department ordered suspension of Fable 5 and Mythos 5 models for foreign nationals citing national security concerns over jailbreak capabilities.

Spanish DPA fines delivery company €205,000 for GDPR violations. SEUR GEOPOST failed to establish proper data processing agreement with parcel locker provider.

Lithuanian doctor fined €1,153 for unlawful patient data access. Used patient information to invite 1,200+ patients to new medical institution without legal basis.

Key Takeaway

Review AI model access controls and ensure third-party data processing agreements comply with GDPR requirements.