ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-06-02
▶The Wire — Daily Briefing

The Wire — Tuesday, June 2, 2026

Credentials Under Siege: Supply Chain Poisoning Meets Brute Force at Scale

30 stories analyzed

Credentials Under Siege: Supply Chain Poisoning Meets Brute Force at Scale

Today's threat landscape reveals a chilling convergence: adversaries are attacking credentials from every conceivable angle simultaneously. From poisoned npm packages to automated brute-force campaigns to weaponizing Meta's own AI support chatbot, the message is clear—your authentication layer is now ground zero for coordinated, multi-vector assault.

The most alarming development is the scope. Red Hat npm packages compromised to steal developer credentials and the Miasma campaign targeting @redhat-cloud-services packages represent a new sophistication in supply chain compromise. These aren't opportunistic attacks on obscure libraries—they're targeting established, trusted packages where defenders have the highest false-negative risk. Developers install these believing they're legitimate updates from trusted vendors, only to have self-propagating credential-stealing worms installed alongside. The same pattern emerged with OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack, where threat actors specifically targeted developers working with AI tooling. These campaigns understand that developer credentials represent keys to countless enterprise systems.

Meanwhile, Dashlane users are locked out of their accounts following brute-force attacks, with the company disclosing that fewer than 20 users had encrypted vaults downloaded in a separate incident. For a password manager—the last line of defense for credential storage—this represents a foundational failure. Even more troubling is the technique: adversaries are using widespread brute-force attacks to probe accounts, relying on the assumption that some users still maintain weak passwords or reused credentials. That Dashlane's security lockout prevented large-scale compromise is reassuring, but the attempt itself signals that attackers are running industrialized credential harvesting at scale.

This credential siege extends beyond traditional hacking. Hackers used Meta's AI Support Bot to seize Instagram accounts, including high-profile targets like the Obama White House and the Chief Master Sergeant of the U.S. Space Force. The attack exploited the chatbot's account recovery workflow—a feature designed to restore access became an authentication bypass. It's a reminder that security is only as strong as the weakest link in the recovery chain, and AI support systems, by design, must be trusting and responsive. Threat actors are weaponizing that trust.

The Critical Vulnerability Situation Is Deteriorating Fast

If credentials are the new battleground, critical vulnerabilities are the weapons being deployed at accelerating velocity. Windows Netlogon vulnerability CVE-2026-41089 is now exploited in active attacks, according to Belgium's national cybersecurity authority. The window between patch availability and active exploitation has collapsed. Another Palo Alto auth bypass bug is under active exploit, and WP Maps Pro vulnerability (CVE-2026-8732) is being actively exploited to create administrative accounts on WordPress sites. WP Maps Pro has sold over 15,000 copies on Envato Market alone—meaning tens of thousands of sites may be vulnerable to instant administrative takeover.

Oracle's monthly patch cycle released 77 vulnerabilities, a shift toward faster, more frequent patching. This is good defensive practice, but it also reflects the sheer volume of flaws entering the market. The underlying problem hasn't changed: patch windows are shrinking, exploit chains are optimizing, and defenders are being forced into a reactive posture.

Large-Scale Attacks Continue to Evolve Beyond the Perimeter

What's particularly noteworthy is how threat actors are distributing malware at unprecedented scale while remaining invisible to conventional detection. The DriveSurge campaign hijacked thousands of sites for ClickFix and FakeUpdate attacks, creating a distributed delivery network for malware. These aren't boutique, targeted attacks—they're industrialized campaigns leveraging compromised infrastructure for mass malware distribution. Similarly, a WordPress malware campaign hides payloads in Steam profiles using invisible Unicode characters in comments, turning a gaming platform into a command-and-control network. When nearly 2,000 WordPress sites can be infected through a supply-chain vector, we're seeing the emergence of new attack vectors that bypass traditional network security.

The Dutch police dismantled a 17-million-device botnet operating as a residential proxy network—a stark reminder that the scale of compromised infrastructure continues to dwarf most defenders' detection capabilities. That law enforcement had to intervene suggests this botnet was actively being weaponized for financial crime and cybercrime facilitation.

Nation-State Activity Reflects Shifting Geopolitical Pressures

China-aligned groups ramped up attacks with Operation Dragon Weave, targeting government, research, academic, and financial institutions. Meanwhile, Spain arrested a doxer leaking sensitive data of government employees, signaling increased law enforcement action against information disclosure. These developments bracket an important dynamic: as traditional cyber espionage operations intensify, law enforcement is beginning to recognize the political dimensions of data leaks and doxing campaigns.

What This Means for Your Organization

We're entering a phase where defenders face a three-layer attack: credential theft through supply chain poisoning, critical vulnerabilities being exploited before patches can be deployed, and large-scale malware distribution through compromised infrastructure. The traditional security model—perimeter defense, patch management, credential protection—is being attacked simultaneously at every layer.

Organizations need to move from a "patch and hope" strategy to one that assumes breach. As we noted in our analysis on why faster vulnerability alerts matter, the competitive advantage now goes to teams that can detect and respond to compromise within hours, not days. For MSPs building security practices, the shift away from traditional vCISO tools toward integrated security platforms reflects this reality—compliance and box-checking are insufficient when threats move this fast.

The encouraging note: Dragos acquiring Phosphorus suggests the security industry is recognizing the need for unified asset visibility and automated remediation. That's the direction defenders need to move—less manual hunting, more automated detection and response.

Looking ahead, watch for two things: whether credential-theft supply chain attacks proliferate beyond developer tools to mainstream packages, and whether the exploitation window for critical flaws continues to shrink. If both trends continue, we're looking at a fundamental shift in the attacker advantage curve.

Key Takeaways

  • Supply chain compromise is now the preferred vector for stealing credentials at scale. Red Hat npm, Miasma, and OpenAI Codex attacks show adversaries targeting trusted packages where defenses are lowest. Implement zero-trust dependency management and continuous monitoring of development supply chains.
  • Critical vulnerabilities are moving from active exploitation to mass compromise within 24-48 hours. Netlogon, Palo Alto, and WP Maps Pro are all being weaponized in real-time. Patch SLAs measured in days are now insufficient—organizations need hours.
  • Attackers are bypassing traditional security by weaponizing legitimate platforms. From Meta's AI support bot to Steam profiles to thousands of compromised websites, threats no longer announce themselves through suspicious channels—they hide in plain sight within trusted infrastructure.

The Wire is HackWire's daily editorial briefing, published every morning.