Cyber security developments for Friday the 5th of June 2026 covering articles added to the BlueTeamSec community on infosec.pub. Today we have 14 articles to cover. All attribution is by the article authors. All article analysis is automated.
CISA have added a critical PHP object injection vulnerability in the Mirasvit Cache Warmer extension for Magento 2 to their Known Exploited Vulnerabilities catalogue. This one's actively being exploited in the wild β attackers can send malicious serialised data through crafted cookies to achieve remote code execution on internet-facing e-commerce platforms without authentication.
Check Point Research have exposed a sophisticated malware distribution operation that uses SEO poisoning to impersonate legitimate software, then employs click-hijacking and a traffic distribution system with fingerprinting to filter targets. The interesting bit is how they're using BNB Smart Chain smart contracts for command-and-control infrastructure resolution, effectively bypassing traditional DNS-based blocking.
Huntress have analysed the DeskCvb RAT, a multi-stage malware campaign that arrives via malspam with HTML attachments redirecting through legitimate Google DoubleClick URLs. The infection chain uses process hollowing into trusted Microsoft binaries and actively patches AMSI and ETW to evade detection β fairly heavy obfuscation throughout the five-stage delivery.
Researchers have detailed a shellcode injection technique called BYORWXDLL that exploits pre-existing readable-writable-executable memory regions in legitimate signed Windows DLLs. It evades EDR detection by avoiding the usual monitored API calls and instead uses WriteProcessMemory and CreateRemoteThread to inject code directly β one for offensive security practitioners.
A security researcher has identified an arbitrary code execution mechanism in Visual Studio during NuGet package restoration and project evaluation. Microsoft have classified this as by design rather than a vulnerability, which is either reassuring or concerning depending on whether you regularly open projects from untrusted sources without proper Trust Settings configured.
0xsp have released Aether, a Windows memory-forensics and threat-hunting tool now in public beta. It scans live process memory for malicious patterns, detects injection techniques, implant signatures, and reflectively loaded .NET assemblies using a multi-layer structural memory indicator system β supports JSON output for SIEM integration if that's your workflow.
Check Point Research have covered a significant law enforcement action β the seizure of WorkTitans hosting infrastructure has disrupted multiple Iranian-nexus cyber espionage operations. The action impacted MuddyWater, Agrius, and Nimbus Manticore threat groups that were using the provider for command-and-control infrastructure supporting various backdoors and campaigns targeting Israeli organisations and aerospace sectors.
Natto Team have reported that China-linked threat actors breached Italy's Interior Ministry network in February, exfiltrating personnel data of approximately five thousand DIGOS officers β that's the unit that monitors extremist threats and protects foreign communities. The operation demonstrates how state-sponsored cyber activity targets foreign law enforcement agencies to facilitate transnational repression of dissidents, including Uyghurs, Tibetans, Falun Gong practitioners, and pro-democracy activists.
Broadcom have written up an espionage campaign that ran for five months from October 2025 through to early this year, targeting a senior executive at a major global stock exchange. The attackers maintained persistent access and systematically exfiltrated the executive's Outlook mailbox in small incremental batches to evade detection β patient tradecraft.
Proofpoint have been tracking TA4922, a financially motivated Chinese-speaking threat actor that's expanded from regional East Asian operations to global campaigns targeting Europe and South Africa. They're using highly localised social engineering lures and rapidly iterating malware including Atlas RAT and RomulusLoader β likely using large language models to accelerate development, which is either efficient or slightly depressing depending on your view of AI in the threat landscape.
Qualys have detailed the HazyBeacon campaign, which demonstrates threat actors using compromised AWS IAM credentials to deploy malicious Lambda functions as command-and-control relays, targeting Southeast Asian government networks for espionage. The attackers configure Lambda functions with public HTTPS endpoints and no authentication to mask malicious traffic as legitimate cloud activity β complicates attribution and detection considerably.
Palo Alto Networks have uncovered Operation FlutterBridge, a malvertising campaign targeting macOS users that delivers FlutterShell, a new backdoor designed specifically to compromise macOS systems through malicious advertising networks. One for organisations with Mac deployments to review.
And finally, there's an analysis of the Lazarus Group utilising a vulnerability designated CVE-2025-55182 in conjunction with a component called Copperhedge. The article itself is currently inaccessible due to technical issues with the source platform, so details are limited at present.
That concludes today's briefing.