🚨 Threat Intel Weekly Update (Week of June 6, 2026) 🚨
Here are the critical developments dominating the threat landscape this week:
🕷️ ALTERED SPIDER: Ramping up npm supply chain attacks with an updated TeamPCPCloudStealer. The new variant includes worm capabilities via SSH/RubyGems and rudimentary EDR evasion against major sensors.
🤖 AI DEVS TARGETED: Massive SEO poisoning campaign is disguising credential stealers as the Anthropic Claude Code CLI installer. Deploys a fileless .NET payload and the ArchPipe stealer to access Windows Credential Manager and Chromium data.
💥 HYDRO KITTEN: Iran-nexus actor is deploying the upgraded ZodiacRAT and destructive ScratchWiper against Middle Eastern engineering firms, signaling elevated risk for destructive operations.
💼 LABYRINTH CHOLLIMA: Targeting Fintech and Maritime sectors using recruitment-themed phishing (masquerading as Paxos Labs) to drop the UnderGround RAT via malicious LNK infection chains.
⚠️ VULN ALERT (CVE-2026-0257): Authentication-bypass vulnerability identified in Palo Alto Networks GlobalProtect.
Stay vigilant. Full breakdown and IOCs available for CrowdStrike customers in report CSWR-26023.