Skip to main content
Back to articles
Security Solutions Team

CISO Daily Digest: Miasma Supply Chain Attack Compromises Red Hat npm (20260602)

Key cybersecurity events and threats as of June 02, 2026

CISO Daily Digest Cybersecurity Threat Intelligence

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

A sophisticated supply chain attack dubbed โ€˜Miasmaโ€™ has compromised official Red Hat npm packages, deploying a self-propagating worm designed to steal credentials and cloud tokens. The attack, attributed to the Shai-Hulud threat group, injected malicious code into legitimate packages distributed through Red Hatโ€™s infrastructure. The worm autonomously spreads across systems, harvesting GitHub tokens, cloud provider credentials, and environment variables. This incident underscores the growing risk of software supply chain attacks targeting open-source ecosystems.

๐Ÿ”— ๅƒ่€ƒ่ณ‡ๆ–™๏ผš ็ถœๅˆๅ ฑๅฐŽ๏ผˆThe Hacker Newsใ€Xakep๏ผ‰

ๆœฌ้€ฑๆดป่บๅจ่„…

๐Ÿ“Œ Windows Netlogon RCE Vulnerability Actively Exploited

A remote code execution vulnerability in Windows Netlogon service is being actively exploited in the wild. The flaw allows attackers to execute arbitrary code on Domain Controllers, potentially compromising entire network domains.

๐Ÿ”— Reference: iThome | Xakep

๐Ÿ“Œ Hackers Used Metaโ€™s AI Support Bot to Seize Instagram Accounts

Threat actors exploited Metaโ€™s AI-powered support chatbot to social-engineer customer service representatives into handing over control of high-value Instagram accounts, including those of celebrities and businesses.

๐Ÿ”— Reference: Krebs on Security | Xakep

๐Ÿ“Œ Operation Dragon Weave: China-Linked Hackers Target Czech Republic and Taiwan

A cyber espionage campaign dubbed โ€˜Operation Dragon Weaveโ€™ attributed to Chinese state-sponsored hackers has been targeting government entities in the Czech Republic and Taiwan, conducting intelligence-gathering operations ahead of diplomatic visits.

๐Ÿ”— Reference: iThome

๐Ÿ“Œ Python Marimo Data Tool Vulnerability Actively Targeted by AI Agents

A critical vulnerability in the Python data analysis tool Marimo continues to be actively targeted, with hackers using AI agents to penetrate internal databases through the flaw.

๐Ÿ”— Reference: iThome

๐Ÿ“Œ Carnival Cruise Data Breach: 6 Million Customersโ€™ Data Stolen

Hackers have stolen the personal data of approximately 6 million Carnival Cruise customers, in one of the largest hospitality sector data breaches in recent memory.

๐Ÿ”— Reference: Xakep

๐Ÿ“Œ VoidStealer Malware Bypasses Chrome Security to Steal Credentials

A new malware strain called VoidStealer can bypass Chromeโ€™s built-in security mechanisms to steal cookies, saved passwords, and account information from the browser.

๐Ÿ”— Reference: iThome

๐Ÿ“Œ Samba Patches Critical Vulnerabilities in Printing and Authentication

Samba has released patches for critical vulnerabilities in its printing and authentication functionality that could allow attackers to execute arbitrary code on unpatched systems.

๐Ÿ”— Reference: iThome

๐Ÿ“Œ Pakistan-Linked SideCopy Targets Afghanistan Ministry with Xeno RAT

The Pakistan-linked threat group SideCopy has been targeting the Afghanistan Ministry of Finance using Xeno RAT, a remote access trojan designed for espionage and data theft.

๐Ÿ”— Reference: The Hacker News