Daily Briefing

CyberGeoDigest

Geopolitical cyber intelligence in 5 minutes
Wednesday, June 3, 2026 · 20 stories
Share this digest:

Russia's FSB Claims Foreign Spies Compromised Senior Officials' Smartphones (1 minute read)

Russia's FSB alleges a large-scale foreign intelligence operation installed malware on mobile devices belonging to senior Russian officials. The claim, offered without technical evidence, may serve as counter-narrative cover for Russia's own aggressive mobile surveillance operations abroad.

The Record · 16h ago · Read full article →

๐Ÿ‡ท๐Ÿ‡บ FSB ยท Russia

China-Linked Actors Hit Czech Organizations with Azureveil Dual-Layer Spear-Phishing (1 minute read)

Chinese threat actors are targeting high-value Czech organizations using a two-stage spear-phishing campaign deploying Azureveil malware for data exfiltration. The operation signals continued Chinese intelligence focus on Central European government and industrial targets.

Dark Reading · 12h ago · Read full article →

FSB Says Foreign Spies Turned Russian Officials' Phones into Surveillance Devices (1 minute read)

Russia's FSB claims foreign intelligence services conducted a large-scale operation compromising smartphones of senior officials but provided zero technical corroboration. The unsubstantiated allegation follows a pattern of Russian counter-accusation used to deflect scrutiny of its own offensive cyber activity.

The Register Security · 17h ago · Read full article →

๐Ÿ‡ท๐Ÿ‡บ FSB ยท Russia

Commercial Location Data Tracks US Troops; Signal Phishing Campaign Targets Message Backups (4 minute read)

Risky Business #840 covers adversaries using commercially available location data to monitor US troop movements and a new Signal phishing campaign harvesting message backups.

Risky Business · 4h ago · Read full article →

Supply Chain Worm Hits 90+ Red Hat npm Packages, Steals Cloud Credentials (2 minute read)

Microsoft Threat Intelligence identified a campaign dubbed Miasma compromising over 90 versions of @redhat-cloud-services npm packages, deploying credential-stealing worms that harvest GitHub, cloud platform, and local machine secrets from CI/CD environments.

Microsoft Threat Intelligence · 3h ago · Read full article →

Attackers Inject Credential-Stealing Worm Into 32 Red Hat npm Packages (1 minute read)

Unknown attackers published 96 malicious versions across 32 Red Hat npm packages, embedding a credential-stealing worm modeled on Mini Shai-Hulud to propagate through developer environments.

SecurityWeek · 22h ago · Read full article →

Russia's Gamaredon Exploits CVE-2025-8088 in WinRAR to Deploy GammaWorm Against Ukraine (1 minute read)

Gamaredon is weaponizing CVE-2025-8088, a WinRAR path traversal flaw, to deliver GammaPhish, GammaWorm, and GammaSteel malware targeting Ukrainian entities for data theft and lateral propagation. The campaign confirms Gamaredon's role as Russia's primary persistent-access operator against Ukrainian infrastructure.

The Hacker News · 14h ago · Read full article →

Iran Halts US Nuclear Talks, Threatens to End Ceasefire After Israeli Strikes (2 minute read)

Iranian state media reported Tehran is suspending peace negotiations with Washington and may terminate the ceasefire, citing continued Israeli military operations in Lebanon. The move raises immediate escalation risk across the Levant and puts US diplomatic efforts in the region under acute pressure.

Just Security · 21h ago · Read full article →

CISA, FBI, NSA Urge Critical Infrastructure Operators to Harden Automatic Tank Gauge Systems (3 minute read)

CISA and seven U.S. federal agencies issued a joint advisory warning of active malicious activity targeting Automatic Tank Gauge systems used in fuel storage across energy, agriculture, and transport sectors.

CISA Alerts · 20h ago · Read full article →

Zambia Cancels RightsCon Under Chinese Pressure and Democratic Backsliding (1 minute read)

Zambia scrapped hosting of the RightsCon human rights summit, reflecting both Chinese diplomatic pressure and the ruling government's own erosion of civil liberties. The cancellation signals China's expanding ability to export censorship norms through compliant partner governments.

Just Security · 19h ago · Read full article →

Russia Courts Taliban in Security Deal Driven by Labor Shortage, Not Ideology (1 minute read)

Moscow's new security agreements with the Taliban prioritize filling Russia's acute wartime labor shortage over strategic alliance-building. The arrangement exposes how severely the Ukraine war has degraded Russia's domestic workforce and military manpower pool.

The Diplomat · 19h ago · Read full article →

Ukraine War Revives Spanish Civil War Analogies, but the Parallels Mislead (3 minute read)

Western analysts are mapping the Ukraine conflict onto the 1936โ€“39 Spanish Civil War interwar framework, but the analogy risks distorting current escalation calculus and alliance dynamics. Strategic misreads drawn from flawed historical analogies shape NATO policy and deterrence posture in dangerous ways.

War on the Rocks · 1h ago · Read full article →

Ransomware Operator Self-Destructs by Encrypting Russia-Based Victims (1 minute read)

A ransomware actor broke the cardinal CIS-exemption rule, encrypting targets in Russia and Commonwealth of Independent States countries, exposing their operation to Russian law enforcement scrutiny.

The Register Security · 10h ago · Read full article →

FBI-Flagged Phishing Kit Kali365 Expands from Microsoft 365 to AWS and Okta (1 minute read)

The Kali365 phishing-as-a-service platform, previously flagged by the FBI for targeting Microsoft 365, now harvests credentials from AWS, Okta, and Russian platforms using device code phishing techniques.

Dark Reading · 11h ago · Read full article →

VS Code Zero-Day Lets Attackers Steal GitHub Tokens in One Click (1 minute read)

A published exploit for an unpatched VS Code vulnerability allows attackers to steal GitHub authentication tokens by luring users to click a single link. Millions of developers using VS Code for CI/CD pipelines face token theft and downstream supply chain compromise.

BleepingComputer · 1h ago · Read full article →

CISA Orders Agencies to Patch Two-Year-Old Oracle WebLogic Flaw (1 minute read)

CISA added CVE-2024-21182, a high-severity Oracle WebLogic Server flaw patched in 2024, to its KEV catalog after confirming active exploitation. Federal agencies face BOD 22-01 remediation deadlines for a bug that should have been closed years ago.

BleepingComputer · 20h ago · Read full article →

CVE-2024-21182 Hits CISA KEV: Unauthenticated WebLogic Takeover Active (1 minute read)

CISA confirmed active exploitation of CVE-2024-21182 (CVSS 7.5), which lets unauthenticated network attackers fully compromise Oracle WebLogic servers. Unpatched enterprise middleware remains a persistent entry point for ransomware and state-linked actors targeting critical infrastructure.

The Hacker News · 14h ago · Read full article →

CISA Adds CVE-2022-0492 and CVE-2025-48595 to Exploited Vulnerabilities Catalog (3 minute read)

CISA flagged CVE-2022-0492, a Linux kernel improper authentication flaw, and CVE-2025-48595, an Android Framework integer overflow, as actively exploited. The Linux flaw's age underscores persistent patch-lag risk across federal and enterprise Linux deployments.

CISA Alerts · 20h ago · Read full article →

Google Patches CVE-2025-48595 Android Zero-Day Exploited in Targeted Attacks (1 minute read)

Google's July Android update patches CVE-2025-48595, an integer overflow in the Android Framework confirmed exploited in limited, targeted attacks, alongside 123 other vulnerabilities. Targeted exploitation before public disclosure indicates probable threat-actor access to private exploit inventory.

SecurityWeek · 18h ago · Read full article →

CVE-2024-21182 Oracle WebLogic Flaw Actively Exploited Without Authentication (1 minute read)

CVE-2024-21182 is being exploited in the wild, giving unauthenticated attackers with network access full control of vulnerable Oracle WebLogic servers. WebLogic's recurring position in KEV catalogs marks it as a sustained high-value target for initial access brokers and ransomware operators.

SecurityWeek · 21h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now