June 26, 2026
- ESET detailed Gamaredon's 2025 evolution: six new PowerShell downloaders (PteroDee, PteroDum, PteroPaste, PteroOdd, PteroEffigy, PteroCache) plus the revived PteroSetup weaponizer, 35 spear-phishing campaigns against Ukrainian government/military, and heavy infrastructure laundering via Cloudflare Workers, Microsoft dev tunnels, Loophole, and dead drops on Telegram, Telegraph, Rentry, Dropbox, Supabase and Clever Cloud. WeLiveSecurity, whitepaper + IOCs
· Threat Intelligence
in Malware Weaponizes Prompt Injection to Sabotage AI Analysis as Gamaredon Retools Against Ukraine
June 21, 2026
- Gamaredon is exploiting the WinRAR path-traversal flaw CVE-2025-8088 against Ukrainian targets: military/conscription-themed
.rar lures use a malicious NTFS alternate data stream to silently plant a .lnk into the Startup folder on extraction, executing a hidden PowerShell stager on next logon. Active since February 2026 and ongoing (Nextron).
· Vulnerabilities & Exploits
in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog
June 20, 2026
- Gamaredon is weaponizing CVE-2025-8088 (WinRAR path traversal) against Ukrainian military/conscription targets since February 2026: a malicious NTFS alternate data stream plants a
.lnk into the Startup folder on extraction, firing a hidden PowerShell stager with anti-analysis checks on next logon. Nextron
· Threat Intelligence & Espionage
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token
June 19, 2026
- Gamaredon is weaponizing WinRAR path-traversal CVE-2025-8088 against Ukraine: a malicious NTFS alternate data stream plants a
.lnk directly into the Startup folder on archive extraction, then runs a hidden anti-analysis PowerShell stager. Campaign active since February 2026 with military/conscription lures (Nextron).
· Nation-State & APT
in FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk