Загрузка...

June 15, 2026 Emerging Threats Weekly

This week’s briefing covers:

00:00 – Intro

00:50 [VULNERABILITY] Check Point VPN Zero-day Linked to Qilin Ransomware Activity
CVE-2026-50751 is a critical authentication bypass vulnerability affecting Check Point Remote Access VPN, Mobile Access and Spark Firewall products when configured to use the deprecated IKEv1 key exchange protocol.

03:28 [CAMPAIGN] TA4922 Expanding to European and South African Targets
Proofpoint has highlighted a newer threat actor, they designate as TA4922. The group are a Chinese-speaking cybercriminal actor that has rapidly expanded beyond its historical East Asia focus. The group is assessed as financially motivated, but its tooling could also support surveillance or be monetized through access resale.

06:10 [SOCIAL ENGINEERING] Luna Moth Targets U.S. Law Firms with IT Impersonation and Data-Theft Extortion
From January through May 2026, Google Mandiant identified a financially motivated data-theft extortion campaign by UNC3753, also known as Luna Moth, Chatty Spider and Silent Ransom Group. The campaign targeted dozens of U.S. organizations, with emphasis on legal, professional and financial services.

08:22 [THREAT ACTOR] VerdantBamboo Used BRICKSTORM, Plenet, and AgentPSD to Regain Access After Remediation
Reports this week claim China-aligned intrusion cluster UNC5221, also known as VerdantBamboo, maintained access to a victim environment for at least 18 months and successfully reestablished access following remediation.

11:09 [MALWARE] Operation FlutterBridge Spreads New FlutterShell Backdoor Through macOS Malvertising
Operation FlutterBridge is a macOS-focused malvertising campaign distributing a new backdoor called FlutterShell. The campaign appears to be an evolution of earlier activity known as JSCoreRunner, run by a financially motivated cluster that Unit 42 tracks as CL-CRI-1089.

Dive deeper:

Kroll’s Monthly Threat Intelligence Spotlight Report: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/cti-spotlight-trends-report

Kroll’s Q4 2024 Cyber Threat Landscape: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/q4-2024-threat-landscape-report-phishing

Kroll’s 2025 Cyber Threat Landscape Report: Cybercrime in the Crypto Era: https://www.kroll.com/Reports/Cyber/Threat-Intelligence-Reports/Threat-Landscape-Report-Lens-on-Crypto

Playlist of Kroll's Weekly Cyber Threat Intelligence Briefings: https://www.youtube.com/playlist?list=PLLef3lAMozGAqLwFx5mAPCod0ciNzZVOw

Kroll Cyber Blog: https://www.kroll.com/en/insights/cyber

Kroll Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services

Kroll Threat Intelligence Reports: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports

Kroll Responder MDR: https://www.kroll.com/en/services/cyber/kroll-responder

#krollcyber #threatintelligence #cyberthreats

Видео June 15, 2026 Emerging Threats Weekly канала Kroll
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять