🛡️ InfoSec Blue Team Briefing

Saturday, June 27, 2026

🎧 Audio Briefing

Download MP3

Cyber security developments for Saturday the 27th of June 2026 covering articles added to the BlueTeamSec community on infosec.pub. Today we have 29 articles to cover. All attribution is by the article authors. All article analysis is automated.

CISA has published strategic guidance on implementing Secure Access Service Edge within the Trusted Internet Connections 3.0 framework. It's aimed at federal agencies transitioning from traditional perimeter defences to Zero Trust architectures — one for anyone working through that shift in government environments.

Russian intelligence services and affiliated hacking groups are running systematic campaigns to compromise messenger apps used by officials in Ukraine, Europe, and the United States, according to a joint disclosure from the SBU and FBI. The tradecraft includes impersonation of support teams, timing attacks during early morning hours, and malicious QR codes — social engineering rather than technical exploitation.

ESET has written up Gamaredon's 2025 activity — at least 35 spearphishing campaigns targeting Ukrainian government and military, six new PowerShell tools, and use of tunnel services like Cloudflare and devtunnels for command and control. The group also exploited the WinRAR vulnerability we've seen elsewhere and appears to be coordinating with Turla and another actor designated UAC-0099.

Google's report on Turla covers the STOCKSTAY campaign, which has been running since December 2022 against government and military organisations, particularly in Ukraine and European foreign policy circles. The malware is a modular .NET backdoor using environmental keying and obfuscation techniques shared with the KAZUAR toolkit, delivered via phishing with malicious RDP configurations and exploitation of that same WinRAR flaw.

A researcher has published analysis of UAC-0226's evolving GIFTEDCROOK infostealer, now exploiting the WinRAR path traversal vulnerability to achieve persistence via Alternate Data Streams. The campaign targets Ukrainian military personnel and uses reflective PE loading with custom API calls to harvest browser credentials, VPN configs, and password databases.

The U.S. State Department's Rewards For Justice programme has posted a notice on UNC5792, a group linked to Russia's FSB Border Guards. They're running phishing campaigns targeting Signal and WhatsApp accounts of U.S. officials, NATO personnel, journalists, and NGO workers involved with Russia-Ukraine matters — exploiting legitimate device-linking features rather than platform vulnerabilities.

Russian authorities used Cellebrite's forensic tools to extract data from political activist Andrey Pivovarov's iPhone in June 2021, according to official Russian documentation analysed by The Citizen Lab. The extracted data was then used to build cases against other opposition figures — a reminder that lawful intercept tools are only as lawful as the jurisdiction using them.

Palo Alto Networks has tracked CL-STA-1062, a Chinese-speaking threat actor, running operations between October and December 2025 against Southeast Asian government and energy sector organisations. The campaign deploys TinyRCT, a C#-based backdoor that uses AppDomainManager injection and scheduled task persistence — at least ten organisations compromised, with one critical infrastructure entity under active attack for several months.

Kaspersky has written up StrikeShark, an ongoing espionage campaign attributed to likely Chinese-speaking actors deploying a custom SharkLoader malware and Cobalt Strike against government, diplomatic, and software development targets across Indonesia, Taiwan, Lebanon, and Syria. Initial access comes via exploitation of known vulnerabilities in Exchange, SharePoint, Openfire, and GeoServer, followed by DLL sideloading and post-exploitation tools of Chinese origin.

An Intelligence-Group report analyses recent APT-C-36 activities targeting Colombia, though the article itself wasn't accessible for full detail. Worth flagging if you're tracking threats to Colombian entities.

Cognyte has published analysis of a Lazarus Group campaign targeting financial and cryptocurrency sectors with a three-component memory-only malware toolset. The tooling uses Windows DPAPI for environmental keying to bind execution to specific victim machines and operates entirely in memory as a fully-featured remote access tool — each deployment gets a unique encrypted payload, defeating hash-based detection.

North Korean threat actors are behind a sophisticated npm supply chain attack on the Mastra package, according to Microsoft. The group, designated Sapphire Sleet, compromised the maintainer account and pushed malicious code — another supply chain incident attributed to DPRK actors following the pattern we've seen repeatedly from this group.

And another supply chain compromise in npm — Sonatype reports that the Shai-Hulud Miasma campaign has compromised the legitimate maintainer account for Leo Platform packages. The attackers injected malicious code into trusted packages using binding.gyp files to execute during installation via node-gyp, bypassing standard lifecycle script detection. The malware targets cloud secrets, GitHub tokens, npm registry tokens, and SSH keys across developer workstations, CI pipelines, and production infrastructure.

Microsoft has flagged an ongoing phishing campaign targeting hospitality industry staff in Europe and Asia since April. The attackers deliver ZIP archives containing fake photo shortcuts that drop a Node.js-based implant with dual registry persistence and sophisticated evasion — authentication laundering through trusted platforms, obfuscated PowerShell, and Cloudflare-fronted command and control. One for anyone in the hospitality sector or supporting it.

ASIO's 2026 Annual Threat Assessment discloses that nation-state actors have compromised Australian critical infrastructure networks in energy, communications, and military support sectors to establish persistent access for future sabotage operations. The assessment also notes Iranian-directed attacks against Jewish communities using proxy networks and active espionage targeting AUKUS-related intelligence and security clearance holders.

Broadcom has written up Mistic, a fileless backdoor first observed in April this year and used by the initial access broker Woodgnat to establish persistent access for ransomware affiliates including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. It uses DLL side-loading and operates entirely in memory with capabilities for remote payload execution — targeting has been opportunistic across insurance, education, IT services, and professional services.

Infoblox has uncovered a massive scam-as-a-service infrastructure abusing the legitimate DCloud uni-app framework to deploy over 236,000 fraudulent domains since 2022. The operation mass-produces cryptocurrency and investment scam sites across eight languages using rapid deployment techniques and pre-fabricated UI components, hosted on mainstream cloud providers and bulletproof services to evade takedowns.

Mandiant has disclosed a targeted campaign exploiting a zero-day in Cisco Catalyst SD-WAN Manager that enabled root-level privilege escalation through malicious CSV file uploads. The attackers compromised a service provider's SD-WAN infrastructure, created a root-privileged user, and employed anti-forensic techniques to evade detection — initial access likely via stolen certificates or a second undisclosed vulnerability. The CVE is 2026-20245.

A researcher has analysed a type confusion vulnerability pattern in Windows RPC servers caused by inconsistent validation of context handles. The flaw arises when BIND_CONTEXT handles lack runtime validation, allowing attackers to force RPC interfaces to operate on incorrect object types — demonstrated through the ssdpsrv service enabling arbitrary handle closure.

On June 24th, attackers compromised the codfish/semantic-release-action GitHub repository by force-pushing malicious code, repointing mutable version tags, and then using GitHub Repository Rulesets to lock maintainers out. The payload is worm-like — it harvests GitHub OIDC tokens and PATs, hijacks AI coding assistant configurations, and propagates by injecting backdoors into other repositories and publishing malicious packages to npm, PyPI, and RubyGems. Any workflows that referenced the compromised mutable tags after 15:39 UTC on the 24th are affected.

Buguard has analysed the WeedHack malware-as-a-service campaign, which has compromised over 116,000 endpoints in the Minecraft community since January. LoaderClient malware stores command-and-control URLs in Ethereum smart contracts to make takedown resistant and targets Microsoft OAuth tokens to hijack accounts — two-stage execution with native-code payloads in memory and C2 URL validation via hardcoded RSA keys.

Threatray has tracked six months of evolution in KuinaExtractor, a Rust-based infostealer that underwent a major rewrite in January and rebranded as 'k0to' in June. It targets about 40 browsers including a Chrome App-Bound-Encryption bypass, gaming platforms like Roblox and Steam, and cryptocurrency wallets on Windows — development shows consistent sophistication improvements with enhanced stealth and anti-analysis measures.

SpecterOps has introduced Oracle, a framework that automates the complete lifecycle of creating, deploying, and verifying custom Mythic command-and-control agents using large language models. It represents a shift from manually-crafted tooling to disposable, AI-generated offensive agents that can be rapidly created and deployed — worth a look if you're tracking how automation is changing red team operations.

XM Cyber has disclosed a privilege escalation technique on macOS that exploits XPC service trust boundaries to allow unprivileged users to disable EDR and MDM solutions. The attack manipulates Code Directory Hash caching and injects malicious NIB payloads into legitimately signed applications, causing privileged daemons to trust compromised processes — affects enterprise security tools across the macOS ecosystem that rely on CDHash-based authentication.

A researcher has developed LACUNA Chain, a technique that defeats EDR call-stack inspection by exploiting executable code gaps in Windows system DLLs. The method creates synthetic call stacks that appear to originate from legitimate Microsoft binaries, bypassing kernel-level monitoring used by enterprise EDR solutions including Elastic, Bitdefender, and Kaspersky.

White Knight Labs has published part three of a series on advanced Malleable C2 profile configurations for Cobalt Strike. This instalment covers Drip Loading, Return Address Spoofing via BeaconGate, and checkin delay configurations that break behavioural detection heuristics by fragmenting memory allocation patterns — techniques that reduce the behavioural footprint and evade process injection and reflective loading detections.

Version 1.5 of Obfusk8 has been released — a maintenance update fixing critical bugs in AES string decryption, PE obfuscation routines, and API wrappers. The update corrects PEB export directory offsets for x64 binaries, prevents stack-walking crashes, and hardens cryptography and networking API calls, improving reliability of obfuscated payloads in diverse environments.

Apple Security Research has introduced Target Flags, a standardised mechanism enabling researchers to objectively demonstrate exploit primitives and vulnerability exploitability across Apple operating systems. The system includes Commpage Target Flags for proving register control, arbitrary read/write, and code execution, plus flags for demonstrating unauthorised permission database modifications — designed to reduce ambiguity in bounty reports and enable accelerated awards.

Alex Teixeira conducted a comparative test between human-expert KQL queries and AI-generated queries from ChatGPT and Claude for detecting Windows Defender exclusion attempts. The AI-generated queries were syntactically correct but lacked genuine detection capability — a cautionary note for SOC teams and detection engineers relying on LLM-generated hunting logic.

That concludes today's briefing.

📰 Articles Covered