June 21, 2026
- ESET uncovered two undocumented Windows variants of the SprySOCKS backdoor (WIN_DRV and WIN_PLUS), attributed with high confidence to China-nexus FishMonger and used against governments in Honduras, Taiwan, Thailand, and Pakistan. WIN_DRV weaponizes a kernel driver to redirect traffic to a hidden TCP port triggered by crafted packet data, with possible UEFI bootkit involvement (WeLiveSecurity, The Hacker News).
· Threat Intelligence
in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog
June 20, 2026
- ESET attributed two undocumented Windows variants of the previously Linux-only SprySOCKS backdoor (WIN_DRV, WIN_PLUS) to China-nexus FishMonger; WIN_DRV weaponizes a kernel driver for a passive, hidden-port TCP backdoor triggered by crafted packets, used against governments in Honduras, Taiwan, Thailand, and Pakistan. The Hacker News, WeLiveSecurity
· Threat Intelligence & Espionage
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token
June 19, 2026
- ESET attributed two undocumented Windows variants of the SprySOCKS backdoor (WIN_DRV, WIN_PLUS) to China-nexus FishMonger, with a kernel driver redirecting traffic to a hidden passive TCP backdoor for stealth against government targets (WeLiveSecurity, Dark Reading).
· Nation-State & APT
in FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk
June 18, 2026
- SprySOCKS — ESET attributes two undocumented Windows variants (WIN_PLUS, WIN_DRV) of the previously Linux-only backdoor to China-nexus FishMonger (Earth Lusca). WIN_DRV weaponizes a kernel driver to redirect traffic to a hidden passive TCP backdoor, with possible UEFI bootkit involvement. IOCs published (WeLiveSecurity, The Hacker News).
· Threat Activity & Ransomware
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel
June 17, 2026
- SprySOCKS (China-linked FishMonger) expanded from Linux to Windows with two new variants — WIN_DRV and WIN_PLUS — featuring kernel-driver rootkit capabilities and possible UEFI bootkit involvement, hitting government targets in Honduras, Taiwan, Thailand, and Pakistan. ESET attributes with high confidence. ESET/WeLiveSecurity, The Hacker News.
· Threat Activity
in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists