# The Threat Box > Canada's Daily Cybersecurity Intelligence ## Posts - [WordPress wp2shell RCE Flaw: Patch Now, Public Exploits Active](https://thethreatbox.com/wordpress-wp2shell-rce-flaw-patch-now-public-exploits-active/): WordPress Core “wp2shell” RCE Flaw: Public Exploits Now Circulating; Patch Immediately A critical pre-authentication remote code execution vulnerability in WordPress Core, dubbed wp2shell, is now under active exploitation after proof-of-concept code surfaced publicly. The flaw, tracked as CVE-2026-63030, allows an unauthenticated attacker to take complete control of a WordPress site with no login credentials, no special configuration, and no plugins required. WordPress issued emergency security releases on July 17, 2026, and has forced automatic updates for affected installations. If you run WordPress, verify your version now. How the WP2Shell Attack Chain Works The vulnerability chains two weaknesses in WordPress’s REST API ... Read more - [Miasma Supply Chain Worm Hits npm, PyPI, and Microsoft Azure](https://thethreatbox.com/miasma-supply-chain-worm-hits-npm-pypi-and-microsoft-azure/): Miasma Supply Chain Worm Infects npm, PyPI, and Microsoft Azure Repositories A fast-moving supply chain campaign dubbed Miasma is spreading across open-source software registries this week, weaponizing a novel install-time technique to steal developer credentials, poison build pipelines, and self-propagate across enterprise cloud environments. Security researchers have confirmed three distinct waves since June 1, 2026, with the latest variant hitting both Microsoft’s GitHub organizations and the Python Package Index in a single 48-hour period. The Phantom Gyp Technique: How Miasma Evades Detection The most alarming innovation in this campaign is a technique researchers call Phantom Gyp. On June 3, 2026, attackers ... Read more - [Chrome Extension YouTube Ad Blocker with 10M Installs Hides Remote Code Injection](https://thethreatbox.com/chrome-extension-youtube-ad-blocker-with-10m-installs-hides-remote-code-injection/): YouTube Ad Blocker with 10 Million Installs Can Inject Code on Any Website A popular Google Chrome ad-blocking extension with more than 10 million installations and an official Featured badge from the Chrome Web Store contains dormant infrastructure that enables its operator to execute arbitrary JavaScript on any website a user visits all through a single server-side configuration change, without requiring an extension update, store review, or any visible indication to the user. The discovery, published June 25, 2026, by researchers at Island, reveals how extensions that appear benign and function exactly as advertised can still pose severe security risks. What ... Read more - [Klue Supply Chain Attack Exposes CRM Data Across Major Firms](https://thethreatbox.com/klue-supply-chain-attack-exposes-crm-data-across-major-firms/): A sweeping supply chain attack against Klue, the Vancouver-based competitive intelligence platform, has triggered cascading data breaches at more than a dozen major technology and cybersecurity firms, including Huntress, Recorded Future, Jamf, and Tanium. The Icarus extortion group compromised a legacy integration credential at Klue on June 11, 2026, planted malicious code to harvest customer OAuth tokens, and used those tokens to pillage connected Salesforce environments for sensitive business data. The incident has once again exposed the fragility of SaaS-to-SaaS trust relationships and forced Salesforce to disable Klue’s Battlecards app entirely. Icarus Extortion Group Breaches Klue to Steal Salesforce Data From ... Read more - [GentleKiller Ransomware Disables 400+ EDR Security Processes](https://thethreatbox.com/gentlekiller-ransomware-disables-400-edr-security-processes/): A newly uncovered EDR-killing framework known as GentleKiller has emerged as one of the most aggressive tools in the ransomware landscape this year, systematically terminating over 400 endpoint protection processes across 48 distinct security products. The framework, developed and maintained by the Gentlemen ransomware-as-a-service operation, exploits the Bring Your Own Vulnerable Driver (BYOVD) technique to blind security defenses before encrypting victim systems. ESET disclosed its findings on June 17, 2026, revealing a centralized infrastructure that supplies affiliates with production-ready evasion tools, a level of operational sophistication rarely seen even among top-tier ransomware crews. GentleKiller Ransomware Exploits Vulnerable Drivers to Blind Endpoint ... Read more - [Anthropic AI Export Ban Pulls Fable 5, Mythos 5 Offline](https://thethreatbox.com/anthropic-ai-export-ban-pulls-fable-5-mythos-5-offline/): Anthropic AI Export Ban: US Forces Fable 5 and Mythos 5 Offline Worldwide Anthropic has pulled its two most capable AI models offline for all users worldwide after the US government issued an unprecedented export control directive ordering the company to cut off access to them for all foreign nationals. The Anthropic AI export ban targets Fable 5 and Mythos 5, the newest models in Anthropic’s Claude lineup. It applies to foreign nationals both inside and outside the US, including Anthropic’s own non-American employees. Because the company had no practical way to separate domestic from foreign accounts on these two models, ... Read more - [Microsoft June 2026 Patch Tuesday: 6 Zero-Days, 200 Flaws](https://thethreatbox.com/microsoft-june-2026-patch-tuesday-6-zero-days-200-flaws/): Microsoft June 2026 Patch Tuesday: 6 Zero-Days and 200 Vulnerabilities Demand Immediate Action Microsoft has released its June 2026 Patch Tuesday security updates, closing 200 vulnerabilities across its product ecosystem, including six zero-day flaws, one of which is confirmed to be actively exploited in live attacks. This is one of the heaviest Patch Tuesday releases of 2026, and the scale of exposure demands urgent attention from Canadian IT administrators, system owners, and security operations teams. Of the 200 flaws addressed, 33 are rated Critical. That critical tier breaks down as 28 remote code execution (RCE) vulnerabilities, four elevation of privilege flaws, ... Read more - [Cisco SD-WAN CVE-2026-20245 Actively Exploited, No Patch Yet](https://thethreatbox.com/cisco-sd-wan-cve-2026-20245-actively-exploited-no-patch-yet/): Cisco Catalyst SD-WAN Manager CVE-2026-20245 Actively Exploited With No Patch Available A high-severity privilege escalation vulnerability in Cisco Catalyst SD-WAN Manager is being actively exploited in the wild, and no patch currently exists to fix it. CVE-2026-20245, rated 7.8 on the CVSS scale, enables an attacker who holds local system access to execute arbitrary commands as root by uploading a specially crafted file to the affected platform. Cisco disclosed the active exploitation on June 6, 2026, crediting researchers at Google Mandiant with the discovery. With no remediation path available, every organization running a vulnerable deployment faces a straightforward and urgent problem: ... Read more - [SolarWinds Serv-U DoS Flaw Actively Exploited: Patch Now](https://thethreatbox.com/solarwinds-serv-u-dos-flaw-actively-exploited-patch-now/): SolarWinds Serv-U Denial-of-Service Flaw CVE-2026-28318 Actively Exploited, CISA Warns Attackers are actively exploiting CVE-2026-28318, a high-severity denial-of-service vulnerability in SolarWinds Serv-U file transfer software, the U.S. Cybersecurity and Infrastructure Security Agency confirmed on June 5, 2026. The flaw requires no credentials, no elevated privileges, and no user interaction to trigger, making it one of the lowest-barrier exploits currently in active use. With over 12,000 Serv-U servers reachable from the public internet and a patch only days old, the exploitation window is wide open for organizations that have not yet acted. What CVE-2026-28318 Is and How Attackers Exploit It SolarWinds Serv-U is ... Read more - [Claude Code GitHub Action Flaw Enabled Repository Hijacking](https://thethreatbox.com/claude-code-github-action-flaw-enabled-repository-hijacking/): Claude Code GitHub Action Flaw Enabled Full Repository Takeover via a Single Bot Issue A critical vulnerability in Anthropic’s Claude Code GitHub Action gave attackers the ability to fully compromise any public repository running the tool, using nothing more than a single GitHub issue submitted by a bot account. Discovered by security researcher RyotaK of GMO Flatt Security, the flaw chained a logic error in permission handling with an indirect prompt injection attack to steal CI/CD secrets and acquire write access to source code, workflow files, and more. Because Anthropic’s own action repository ran the same vulnerable workflow, a successful exploit ... Read more - [Meta AI Support Flaw Let Hackers Hijack Instagram Accounts](https://thethreatbox.com/meta-ai-support-flaw-let-hackers-hijack-instagram-accounts/): Meta’s AI Support Chatbot Was Weaponized to Hijack Instagram Accounts, No Malware Required A critical flaw in Meta’s AI Support Assistant on Instagram allowed attackers to seize control of accounts belonging to high-profile individuals and organizations using nothing more than a target’s username and a VPN. No malware, no phishing link, no access to the victim’s email account was required at any point. The Meta AI Instagram account hijack exploit was publicly exposed on June 1, 2026, by security researchers ZachXBT and Dark Web Informer and patched by Meta the same evening, but not before attackers had already monetized the vulnerability ... Read more - [AI-Built Ransomware Toolkit Automates EDR Evasion in 2026](https://thethreatbox.com/ai-built-ransomware-toolkit-automates-edr-evasion-in-2026/): AI-Built Ransomware Toolkit Automates EDR Evasion, Leverages Claude Agents for Attack Development Researchers at Sophos have uncovered an active threat actor operating a fully functional, AI-built ransomware toolkit that automates Active Directory (AD) reconnaissance, systematically tests endpoint detection bypass techniques, and uses multiple AI agents, including one powered by Claude Opus 4.5, to build and refine malware at a pace no traditional development workflow could match. The discovery, published June 2, 2026, by the Sophos Counter Threat Unit (CTU), is a concrete demonstration of what AI-accelerated offensive operations look like in practice, and the implications reach directly into Canadian enterprise environments. ... Read more - [CVE-2026-41089: Critical Windows Netlogon RCE Exploited](https://thethreatbox.com/cve-2026-41089-critical-windows-netlogon-rce-exploited/): CVE-2026-41089: Critical Windows Netlogon RCE Flaw Now Actively Exploited A critical Windows Netlogon remote code execution flaw is now being actively weaponized in the wild, three weeks after Microsoft shipped the patch. CVE-2026-41089, carrying a near-perfect CVSS score of 9.8, allows unauthenticated attackers to seize full SYSTEM-level control of any unpatched Windows domain controller by sending a single malicious network request. Belgium’s national cybersecurity authority confirmed the active exploitation on Friday and issued an emergency warning to administrators worldwide. For Canadian organizations running Active Directory environments, which includes the majority of enterprise, government, and mid-market IT infrastructure in the country, this ... Read more - [Microsoft 365 Outage Blocks Teams and Office Web File Access](https://thethreatbox.com/microsoft-365-outage-blocks-teams-and-office-web-file-access/): Microsoft 365 Outage Blocks Teams and Office Web Access A Microsoft 365 outage struck organizations worldwide on June 1, 2026, blocking users from opening files in Microsoft Teams and Office for the web. Microsoft confirmed the incident through its official Microsoft 365 Status channel on X, directing administrators to incident notice MO1329446 in the Microsoft 365 admin center. For Canadian businesses that depend on cloud-based productivity tools, the timing, on a Monday morning at the start of the workweek, amplified the disruption significantly. What Broke: File Access Across Core Microsoft 365 Apps The outage disrupted file-opening capabilities across multiple web-based Office ... Read more - [Microsoft enforces registered-only authentication for Entra ID](https://thethreatbox.com/microsoft-enforces-registered-only-authentication-for-entra-id/): Microsoft Entra ID SSPR Will Only Accept Registered Authentication Methods Starting September 2026 Microsoft has formally notified customers that a significant shift is coming to how Microsoft Entra ID handles identity verification during Self-Service Password Reset (SSPR). Under Message Center update MC1325414, the company is moving to a model where only explicitly registered authentication methods will be accepted for SSPR, eliminating a long-standing gap between directory contact attributes and properly validated recovery factors. The change is classified as a “Major Change” in Microsoft’s Message Center and takes effect on September 7, 2026. What Is Changing in Entra ID’s Password Reset Portal ... Read more - [PAN-OS GlobalProtect Auth Bypass CVE-2026-0257 Exploited](https://thethreatbox.com/pan-os-globalprotect-auth-bypass-cve-2026-0257-exploited/): PAN-OS GlobalProtect Authentication Bypass CVE-2026-0257 Is Being Actively Exploited Right Now A confirmed, in-progress attack campaign is targeting enterprise VPN infrastructure globally, and Canadian organizations are directly in the line of fire. Palo Alto Networks has confirmed that CVE-2026-0257, a PAN-OS GlobalProtect authentication bypass flaw carrying a CVSS score of 7.8, is under active exploitation. Though formally classified as medium severity by the scoring framework, security researchers are urging all affected organizations to treat it with critical-level urgency. If your organization is running Palo Alto Networks firewalls with GlobalProtect enabled, stop reading after this paragraph and go check your configuration. What ... Read more - [Gentlemen RaaS Uses SYSTEM Scheduled Task to Encrypt Drives](https://thethreatbox.com/gentlemen-raas-uses-system-scheduled-task-to-encrypt-drives/): The Gentlemen Ransomware Abuses Windows SYSTEM Tasks to Encrypt Entire Networks The Gentlemen ransomware is a growing and technically sophisticated threat that Canadian organizations in healthcare, finance, education, and transportation cannot afford to overlook. Published in a new analysis by Microsoft Threat Intelligence, this ransomware-as-a-service (RaaS) platform combines self-propagation, SYSTEM-level privilege abuse, and double extortion into one tightly engineered attack chain. The group behind it, tracked by Microsoft as Storm-2697, recently cemented a formal recruitment partnership with BreachForums, a prominent criminal marketplace, significantly broadening its potential affiliate base. Storm-2697 and the Evolution of The Gentlemen RaaS The Gentlemen first surfaced around ... Read more - [Anthropic Confirms Claude Mythos AI Models Coming to Public](https://thethreatbox.com/anthropic-confirms-claude-mythos-ai-models-coming-to-public/): Anthropic Confirms Claude Mythos AI Models Are Coming to the General Public Anthropic has confirmed that it will bring Claude Mythos-class models to general public availability, ending one of the most tightly controlled AI model restrictions in the industry. The company withheld the model from public release since April 2026, citing the risk that a tool capable of autonomously discovering and exploiting zero-day vulnerabilities could cause catastrophic harm if deployed without the necessary safeguards. With those safeguards now in development, a broader rollout is coming, and Canadian organizations need to understand exactly what that means. From Restricted Preview to General Release: The Mythos ... Read more - [GreyVibe Hackers Weaponize ChatGPT and Gemini in Attacks](https://thethreatbox.com/greyvibe-hackers-weaponize-chatgpt-and-gemini-in-attacks/): GreyVibe Hackers Weaponize ChatGPT and Gemini in Attacks A threat group tracked as GreyVibe is actively using commercial AI platforms, including ChatGPT and Google Gemini, to build convincing attack lures and develop a custom suite of malware tools targeting military, government, civilian, and business organizations. Cybersecurity firm WithSecure identified and reported the campaign in January 2026, with activity traced back to at least August 2025. Although the group’s current focus is on Ukrainian and Ukraine-related entities, the tactics, techniques, and tooling on display are fully portable, and organizations in Canada operating in defense, government, or critical infrastructure have clear reason to ... Read more - [Microsoft Zero-Day Feud: Six Windows Flaws Disclosed](https://thethreatbox.com/microsoft-zero-day-feud-six-windows-flaws-disclosed/): Six Windows Zero-Days Dropped Without Warning; Three Are Now Actively Exploited Three Windows zero-day vulnerabilities disclosed publicly without prior notice to Microsoft are now being actively exploited in the wild. The situation has triggered a sharp public response from Microsoft and a growing controversy over vulnerability disclosure ethics, GitHub account takedowns, and a researcher threatening further releases. For Canadian organizations running Windows environments, the exposure window is open right now. The Vulnerabilities: Six Flaws, Three Under Active Attack A researcher operating under the handle Chaotic Eclipse (also known as Nightmare-Eclipse) released details on six Windows vulnerabilities over the past month, none ... Read more - [AI-Driven LLM Agent Exploits Marimo RCE to Dump Databases](https://thethreatbox.com/ai-driven-llm-agent-exploits-marimo-rce-to-dump-databases/): AI-Powered LLM Agent Exploits Marimo RCE and Dumps Internal Database in Under Two Minutes Researchers have documented the first confirmed intrusion in which a large language model (LLM) agent autonomously executed a complete post-exploitation chain, moving from a single exposed notebook server to a fully exfiltrated internal database in fewer than 120 seconds. The attack, captured on May 10, 2026, by Sysdig’s Threat Research Team (TRT), is not just a technical milestone. It is a direct signal to Canadian IT defenders that AI is no longer only a tool of defense. The Vulnerability at the Core: CVE-2026-39987 The entry point was ... Read more - [Toronto Sextortionist Gets 33 Years for Targeting 145 Kids](https://thethreatbox.com/toronto-sextortionist-gets-33-years-for-targeting-145-kids/): Toronto Man Sentenced to 33 Years in U.S. for Sextortion Scheme Targeting 145 Children A sextortion scheme originating from Toronto has resulted in one of the most significant child exploitation sentences in recent North American legal history. Ramanan Pathmanathan, 40, was handed a 33-year federal prison term by a U.S. District Court in Washington, D.C. on May 27, 2026, after pleading guilty to targeting at least 145 children across the United States, some as young as six years old, over the course of nearly eight years. The case is a stark reminder that online child exploitation knows no borders and that ... Read more - [Zero-Click WhatsApp Attack Hijacks iOS 16 Accounts Silently](https://thethreatbox.com/zero-click-whatsapp-attack-hijacks-ios-16-accounts-silently/): Silent Threat: Zero-Click WhatsApp Attack Is Hijacking iOS 16 Accounts Without Warning A newly documented zero-click WhatsApp account takeover attack is compromising iPhones running iOS 16 without any interaction from the device owner. Victims have had unauthorized messages sent from their accounts, including fraudulent money transfer requests, while their WhatsApp app showed no sign of intrusion, no linked devices, no login alerts, and no visible activity. The attack was uncovered through forensic investigation by Italian security firm Forenser and represents a significant escalation in mobile messaging threats affecting millions of iPhone users, including an estimated 9 to 10 million active WhatsApp ... Read more - [GHOST STADIUM Phishing Targets FIFA World Cup Fans in Canada](https://thethreatbox.com/ghost-stadium-phishing-targets-fifa-world-cup-fans-in-canada/): GHOST STADIUM: Chinese-Linked Phishing Operation Deploys 300+ Fake FIFA Domains to Defraud World Cup Fans A large-scale, financially motivated phishing campaign has been uncovered targeting fans of the 2026 FIFA World Cup, with researchers identifying over 300 fraudulent domains engineered to steal credentials, payment information, and ticket access. The operation, attributed to a threat actor designated GHOST STADIUM, is one of the most technically sophisticated fraud ecosystems ever tied to a major sporting event and carries serious implications for Canadian fans attending or following matches hosted on Canadian soil. Threat intelligence firm Group-IB published findings on May 27, 2026, confirming the ... Read more - [Kali365 PhaaS (phishing-as-a-service) Bypasses MFA to Hijack Microsoft 365 Accounts](https://thethreatbox.com/kali365-phaas-phishing-as-a-service-bypasses-mfa-to-hijack-microsoft-365-accounts/): Kali365 PhaaS Platform Hijacks Microsoft 365 Accounts Without Stealing a Single Password A criminal subscription service called Kali365 is actively compromising Microsoft 365 accounts across North America and Europe, and it does so without ever needing a victim’s password or triggering a standard multi-factor authentication (MFA) prompt. The FBI issued a formal public service announcement on May 21, 2026 (referenced as PSA260521), warning organizations that Kali365 represents a fast-growing and technically accessible threat that is already hitting Canadian and American organizations across government, healthcare, financial services, manufacturing, and education. Every confirmed victim in documented campaigns was using MFA. That fact alone ... Read more - [7-Eleven Data Breach: ShinyHunters Exposes 185,000 Personal Records](https://thethreatbox.com/7-eleven-data-breach-shinyhunters-exposes-185000-personal-records/): ShinyHunters breached 7-Eleven's Salesforce systems in April 2026, exposing 185,000 people's personal data. Canadian franchisees and applicants may be affected. - [Microsoft Defender Now Auto-Isolates Compromised Endpoints in Real Time](https://thethreatbox.com/microsoft-defender-now-auto-isolates-compromised-endpoints-in-real-time/): Microsoft Defender for Endpoint can now automatically isolate hacked devices in real time. Here is what Canadian IT teams need to know and do right now. - [Claude Mythos Nears Public Release via Claude Code](https://thethreatbox.com/claude-mythos-nears-public-release-via-claude-code/): Anthropic’s Restricted Claude Mythos Model Is Edging Toward Public Release Through Claude Code Anthropic’s most powerful and previously locked-down AI model, Claude Mythos, has surfaced briefly inside Claude Code and Claude Security. A signal that a controlled public rollout may be closer than the company has publicly acknowledged. The fleeting appearance of a toggle labeled “claude-mythos-1-preview” in the live interface, followed by its rapid removal, confirms the model is in active product preparation, not merely experimental development. For Canadian IT professionals and security teams watching the AI-driven security landscape, this development carries significant operational weight. What Is Claude Mythos and Why ... Read more - [Critical Ghost CMS SQL Injection Flaw Exploited in Massive ClickFix Malware Campaign](https://thethreatbox.com/critical-ghost-cms-sql-injection-flaw-exploited-in-massive-clickfix-malware-campaign/): Welcome back to The Threat Box. If your organization relies on Ghost CMS for its corporate blog, newsroom, or publishing platform, you need to pay close attention. A highly critical vulnerability is actively being exploited in the wild, turning otherwise reputable websites into delivery mechanisms for a sophisticated malware campaign known as ClickFix. Cybersecurity researchers have uncovered a massive, large-scale operation exploiting a severe SQL injection flaw in Ghost CMS (tracked as CVE-2026-26980). This vulnerability has already compromised over 700 high-profile domains globally. From prestigious educational institutions like Harvard and Oxford universities to tech heavyweights like DuckDuckGo, the victims span multiple ... Read more ## Pages - [Contact Us](https://thethreatbox.com/contact-us/): Get in Touch with The Threat Box We love hearing from our readers! Whether you have a question about a recent cybersecurity news article, want to report a digital threat, or are inquiring about business and advertising opportunities, we are here to help. - [Terms and Conditions](https://thethreatbox.com/terms-and-conditions/): Welcome to The Threat Box! These terms and conditions outline the rules and regulations for the use of The Threat Box’s website, located at https://thethreatbox.com. By accessing this website, we assume you accept these terms and conditions. Do not continue to use The Threat Box if you do not agree to take all of the terms and conditions stated on this page. License & Intellectual Property Unless otherwise stated, The Threat Box and/or its licensors own the intellectual property rights for all material on The Threat Box. All intellectual property rights are reserved. You may access this from The Threat Box ... Read more - [Disclaimer](https://thethreatbox.com/disclaimer/): General Disclaimer The information provided by The Threat Box (“we,” “us,” or “our”) on https://thethreatbox.com is for general informational and educational purposes only. All information on the Site is provided in good faith, however, we make no representation or warranty of any kind, express or implied, regarding the accuracy, adequacy, validity, reliability, availability, or completeness of any information on the Site. Not Professional Cybersecurity Advice The cybersecurity news, tips, and alerts provided on The Threat Box do not constitute professional IT, legal, or cybersecurity advice. While we strive to provide accurate and up-to-date information regarding digital threats and online safety, the ... Read more - [About Us](https://thethreatbox.com/about-us/): Welcome to The Threat BoxIn today’s highly connected digital world, cyber threats are no longer just a problem for massive corporations or tech experts. Data breaches, phishing scams, and malware affect everyday people. That is where we come in. Our Mission Proudly based and entirely operated out of Ontario, Canada, our primary mission is to make cybersecurity accessible, understandable, and actionable. While cyber threats have no borders, our core focus is delivering timely cybersecurity news impacting the Canadian region, followed by major global threat alerts. Whether it is a local data privacy update or a massive international breach, we break down ... Read more - [Privacy Policy](https://thethreatbox.com/privacy-policy/): Privacy Policy for The Threat Box At The Threat Box, accessible from https://thethreatbox.com, one of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that are collected and recorded by The Threat Box and how we use it. Log Files The Threat Box follows a standard procedure of using log files. These files log visitors when they visit websites. The information collected by log files includes Internet Protocol (IP) addresses, browser type, Internet Service Provider (ISP), date and time stamp, referring/exit pages, and possibly the number of clicks. These are not linked to ... Read more - [Home](https://thethreatbox.com/home/) ## Optional - [Agent (MCP protocol)](websites-agents.hostinger.com/thethreatbox.com/mcp) [comment]: # (Generated by Hostinger Tools Plugin)