Press "Enter" to skip to content

OSINT / CyberSec report 23.06.2026 00:07

1. The Canadian Security Intelligence Service utilized a first of its kind threat reduction warrant to neutralize two foreign run botnets by accessing infected servers and routers on Canadian soil (The Hacker News).

2. A new malware family identified as AryStinger has compromised at least 4300 legacy routers to establish a distributed reconnaissance and proxy network (The Hacker News).

3. Researchers report that AryStinger is specifically targeting outdated D Link routers to facilitate malicious traffic redirection (Bleeping Computer).

4. INTERPOL issued a warning regarding a significant increase in phishing, ransomware, and AI enabled scams across the Asia Pacific region (The Hacker News).

5. Threat actors are actively exploiting a security flaw in the Gravity SMTP WordPress plugin tracked as CVE 2026 4020 (The Hacker News).

6. The exploit of CVE 2026 4020 allows unauthenticated attackers to extract sensitive information including API keys, secrets, and OAuth tokens from approximately 100000 WordPress sites (The Hacker News).

7. A new ransomware operation known as Prinz Eugen has been observed prioritizing recently modified files for encryption during attacks (Bleeping Computer).

8. The Prinz Eugen ransomware is notable for its tactical decision to leave no ransom note on the compromised systems (Bleeping Computer).

9. Microsoft has formally attributed the Mastra AI supply chain attack to the North Korean hacking group known as Sapphire Sleet or BlueNoroff (Bleeping Computer).

10. The Mastra AI supply chain campaign involved the compromise of more than 140 npm packages (Bleeping Computer).

11. Security researchers identified a method for exploiting default configurations in Auth0 to facilitate cross site scripting attacks (Reddit).

12. Technical analysis has been published regarding the use of infinite VPN tunnels to scan malicious websites for security research purposes (Reddit).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *