Issue #203 - June 15, 2026
- Jun 15
- 2 min read
INC Ransomware Thrives by Mastering the Basics
Source: Dark Reading
INC ransomware has grown by focusing on practical, repeatable intrusion methods rather than novel tooling. Researchers said the group targets high-pressure sectors, uses familiar techniques such as stolen credentials, phishing, and unpatched remote services, and benefits from affiliate scalability as other ransomware groups decline or reorganize.
Fileless Phantom Stealer Targets Browser Credentials
Source: Dark Reading
Researchers warned that Phantom Stealer is being delivered through a targeted phishing campaign against banks and other high-value organizations. The malware runs largely in memory, uses layered obfuscation, and steals browser credentials, session cookies, financial data, screenshots, and wallet information while exfiltrating through multiple channels.
145 Mastra npm Packages Compromised via Hijacked Contributor Account
Source: The Hacker News
A compromised Mastra contributor account was used to publish malicious versions of 145 npm packages. The attack added an easy-day-js dependency that delivered a cryptocurrency-stealing remote access trojan through a postinstall loader. Researchers urged affected teams to roll back packages, rotate credentials, and inspect build systems.
CISA orders feds to patch max severity Joomla plugin flaw by Friday
Source: BleepingComputer
CISA added a maximum-severity Joomla Content Editor plugin vulnerability to its exploited vulnerabilities catalog and ordered federal agencies to patch quickly. The flaw allows unauthenticated attackers to upload and execute PHP code by creating new editor profiles, creating serious risk for exposed Joomla deployments using the affected plugin.
Critical Command Execution Vulnerability Patched in Cisco ISE
Source: SecurityWeek
Cisco patched a critical command execution flaw in Identity Services Engine and ISE Passive Identity Connector. The vulnerability allows authenticated remote attackers with administrative credentials to run commands on the underlying operating system and potentially elevate privileges. Cisco said fixed versions and a hotfix are available.



