Critical vulnerability in Qualcomm closed-source components affecting Android devices. Part of vendor-specific fixes in Android June 2026 security bulletin. Additional Qualcomm chipset firmware vulnerability enabling system compromise.
Apply Android June 2026 security updates containing Qualcomm patches. Implement mobile threat defense solution to detect exploitation attempts. Review mobile device security posture and enforce minimum security patch levels.
Source: GTIG • Published: 2026-06-22
Critical vulnerability in Qualcomm closed-source components affecting Android devices. Part of vendor-specific fixes in Android June 2026 security bulletin. Third critical Qualcomm vulnerability requiring immediate patching.
Apply Android June 2026 security updates containing Qualcomm patches. Audit enterprise mobile device inventory for vulnerable Qualcomm-based devices. Establish accelerated patch deployment procedures for critical mobile vulnerabilities.
Source: GTIG • Published: 2026-06-22
17-year-old remote code execution vulnerability in FreeBSD affecting NFS. Autonomously discovered and exploited by Anthropic Mythos Preview AI model with no human involvement after initial request. Allows anyone to gain root on a machine running NFS. Demonstrates AI capability surpassing skilled humans at finding and exploiting software vulnerabilities.
Apply FreeBSD security patches immediately for CVE-2026-4747. Disable NFS if not required. Restrict NFS access to trusted networks only. Implement network segmentation to isolate NFS servers. Monitor for unusual NFS access patterns. This finding underscores need for accelerated vulnerability management as AI-driven discovery capabilities proliferate.
Source: GTIG • Published: 2026-06-22
Qilin ransomware affiliate exploited Check Point VPN zero-day CVE-2026-50751 affecting IKEv1 deployments. Attacks began May 7, surged in early June. Post-exploitation activity includes malicious ELF file downloads and Qilin Linux ransomware execution. Check Point assesses threat actor exploiting multiple VPN vulnerabilities from Palo Alto, Fortinet, and F5.
Apply Check Point patches immediately. Disable IKEv1 protocol. Hunt for indicators of Qilin ransomware including malicious ELF files and encryption activity. Implement network segmentation to contain potential breaches. Review and test backup and recovery procedures. Monitor for lateral movement and data exfiltration attempts.
Source: CISA • Published: 2026-06-22
TeamPCP orchestrated sophisticated multi-ecosystem supply chain campaign cascading through developer tooling. Compromised TanStack (84 malicious npm versions), LiteLLM (PyPI backdoor), and Nx Console (VS Code extension). Campaign exposed how AI proxy services concentrating API keys and cloud credentials become high-value targets. Resulted in GitHub and Grafana Labs breaches.
Implement multi-layered supply chain security: enable npm provenance verification, use dependency lock files with integrity hashes, implement SLSA framework, deploy SIEM monitoring for anomalous package installations, require code review for dependency updates, use private package registries with scanning, rotate credentials on 30-day cycle, implement least-privilege for CI/CD pipelines.
Source: Cycode • Published: 2026-06-22
GitHub CISO confirmed TeamPCP used malicious Nx Console VS Code extension to steal secrets and developer credentials, exfiltrating approximately 3,800 GitHub private code repositories. Attack chain originated from TanStack npm supply chain compromise via Mini Shai-Hulud campaign detected on May 11. Attackers demanded payment not to release stolen codebase.
GitHub users who installed Nx Console v18.95.0 must immediately rotate all GitHub personal access tokens, SSH keys, and OAuth tokens. Review repository access logs for unauthorized clones or downloads. Enable GitHub Advanced Security features including secret scanning and push protection. Implement commit signing. Audit organization member access and remove unnecessary permissions.
Source: GitHub • Published: 2026-06-22
Grafana Labs confirmed incident originated from TanStack npm supply chain attack via Mini Shai-Hulud campaign. Missed token led to attackers gaining access to GitHub repositories. Attackers contacted Grafana demanding payment not to release or sell stolen codebase. Grafana decided not to pay ransom.
Organizations using Grafana should verify they are running official builds from trusted sources. Review GitHub repository access patterns for anomalies. Implement token expiration policies with maximum 90-day lifetime. Use GitHub secret scanning alerts. Deploy code signing and verification for internal builds. Establish crisis communication procedures for extortion scenarios.
Source: GTIG • Published: 2026-06-22
Q1 2026 ransomware activity remained steady confirming surge seen in late 2025 has reset baseline expectations. The Gentlemen expanded from 35 to 182 victims. Established groups Qilin and Akira declined 25% and 22%. EDR killers became standard component of attack playbooks. Groups adopting DDoS-as-a-Service, insider recruitment, encryptionless extortion, and post-quantum cryptography.
Implement defense-in-depth: deploy EDR with tamper protection and behavioral analytics, enable kernel-mode protection, implement application allowlisting, maintain offline encrypted backups with 3-2-1 rule, conduct tabletop exercises quarterly, establish insider threat program, implement zero-trust architecture, deploy network segmentation, monitor for living-off-the-land techniques.
Source: GTIG • Published: 2026-06-22
U.S. Commerce Department used national security export controls to bar Anthropic from distributing Fable 5 and Mythos 5 AI models to any foreign national after learning of technique to bypass safeguards. Mythos Preview autonomously identified and exploited 17-year-old FreeBSD RCE vulnerability CVE-2026-4747. Model found thousands of high-severity vulnerabilities in major OS and browsers.
Organizations using Anthropic models must prepare for potential service disruptions due to export controls. Implement AI model usage monitoring and approval workflows. Establish governance framework for frontier AI model deployment. Review and restrict AI model access to authorized personnel only. Participate in Project Glasswing for responsible AI vulnerability disclosure.
Source: GTIG • Published: 2026-06-22
45% of AI-generated code contains real security vulnerabilities according to Veracode. Java hitting 70%+ failure rates including SQL injections, bad authentication patterns, and XSS. New CVEs include CamoLeak in Copilot, case-sensitivity bypass in Cursor, RCE via config files in Claude Code. 87% of survey respondents identified AI-related vulnerabilities as fastest-growing cyber risk.
Implement mandatory security review for all AI-generated code before production deployment. Deploy static application security testing (SAST) in CI/CD pipelines. Train developers on secure coding practices specific to AI-generated code patterns. Establish AI code generation policies requiring human verification. Use tools like Semgrep or CodeQL to detect common AI-generated vulnerabilities.
Source: Veracode • Published: 2026-06-22
QILIN-CHECKPOINT-VPN-2026: Qilin ransomware affiliate exploited Check Point VPN zero-day CVE-2026-50751 affecting IKEv1 deployments. Attacks began May 7, surged in early June. Post-exploitation activity includes malicious ELF file downloads and Qilin Linux ransomware execution. Check Point assesses threat actor exploiting multiple VPN vulnerabilities from Palo Alto, Fortinet, and F5.