
A checkmark for trust, a payload for theft.
Miasma malware meddles with Microsoft. SAP fixes critical flaws, Google patches an exploited Chrome zero-day, CanisterWorm spreads through npm, Mac users face a new malvertising threat, France investigates a breach of its secure messaging platform, insurers rethink AI risk, the FBI launches a Most Wanted Fraudsters list, and a U.S. citizen admits to spying for China. Our guest is Steve Winterfeld, Advisory CISO from Akamai, discussing how AI-powered bots are driving financial services attacks. Unpacking a million dollar hotel fee.
Today is Tuesday June 9th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
Miasma malware meddles with Microsoft.
Late last week, attackers compromised dozens of cryptographically verified open source packages linked to Microsoft, inserting sophisticated credential-stealing malware that activated when developers opened the packages in AI coding tools such as Claude Code, Gemini CLI, Cursor, and VS Code. Researchers identified 73 malicious packages before GitHub removed them, initially citing only a terms-of-service violation rather than explicitly warning users of compromise.
The incident marks the second major software supply-chain breach involving a Microsoft repository account in two months. The malware, known as Miasma and linked to the threat actor TeamPCP, steals credentials from cloud platforms including AWS, Azure, and Google Cloud, along with Kubernetes environments, password managers, and numerous developer tools. It can also spread laterally across cloud infrastructure and developer systems.
Researchers say the attackers abused legitimate Microsoft publishing credentials and OpenID Connect (OIDC) tokens to create packages with valid cryptographic provenance, allowing them to appear trustworthy and evade traditional security checks. Miasma further complicates detection by generating unique encrypted payloads for each infection. Security experts warn that anyone who interacted with the affected packages should assume credential compromise and immediately investigate their systems and cloud environments.
SAP patches 15 security issues.
SAP’s June 2026 Patch Day addresses 15 security issues, including four critical vulnerabilities affecting NetWeaver, ABAP Platform, Commerce Cloud, and Data Hub. The most severe, CVE-2026-44748 (CVSS 9.9), is an XML Signature Wrapping flaw that could allow authenticated attackers to tamper with identity information and gain unauthorized access to sensitive data. Other critical fixes address memory corruption, HTTP header handling weaknesses tied to Spring Security, and a directory traversal flaw enabling unauthenticated access to sensitive files or denial-of-service conditions. SAP also patched multiple high-severity vulnerabilities, including Apache Tomcat flaws and authorization issues.
Google patches a Chrome zero-day.
Google has released emergency updates to fix CVE-2026-11645, a zero-day vulnerability in Chrome’s V8 JavaScript engine that is already being exploited in the wild. The flaw involves an out-of-bounds memory access issue, which can potentially lead to application crashes, privilege escalation, or remote code execution. Google confirmed active exploitation but has not disclosed technical details about the attacks. CVE-2026-11645 is the fifth Chrome zero-day known to have been exploited in the wild and patched by Google so far in 2026.
CanisterWorm targets npm packages.
Researchers at Picus analyze CanisterWorm, a self-propagating malware campaign linked to TeamPCP that emerged in March 2026 after attackers compromised Aqua Security’s Trivy vulnerability scanner and stole npm publishing credentials. Using those credentials, the attackers infected more than 60 npm packages within a day, targeting developers who installed packages from several affected namespaces.
The malware operates in three stages: a Node.js post-install dropper, a stealthy Python backdoor, and a worm component that harvests npm tokens and republishes compromised packages. It steals cloud, SSH, Kubernetes, GitHub, and CI/CD credentials, establishes persistence, and can hijack GitHub Actions secrets. Researchers warn that developers using affected packages or compromised Trivy releases should assume credential exposure, rotate secrets, and audit systems and package repositories for unauthorized changes.
Operation FlutterBridge targets Mac users.
Researchers at Palo Alto Networks’ Unit 42 have uncovered Operation FlutterBridge, a large-scale malvertising campaign targeting Mac users since late 2025. The operation, linked to the cybercrime group CL-CRI-1089, uses fake Google search ads purchased through shell companies to distribute trojanized applications disguised as podcast players and PDF tools.
The malware, called FlutterShell, functions as a backdoor capable of executing commands, accessing files, and stealing system information. It can hijack Chrome browser settings, redirect users through attacker-controlled websites, and silently exfiltrate uploaded documents through fake AI-powered features. Researchers observed multiple evolving versions of the malware, suggesting active development.
The campaign evaded detection by using legitimate developer signatures and fake business entities to obtain verified advertising accounts. Although Google has suspended the identified advertiser accounts, researchers warn that the threat actors rapidly launch new variants, indicating the operation remains active and ongoing.
Attackers compromise the French government’s encrypted messaging platform.
France’s digital affairs directorate, DINUM, has disclosed a breach of Tchap, the French government’s encrypted messaging platform, after attackers gained access through a compromised user account. The incident was detected by ANSSI, France’s cybersecurity agency, which said the malicious account was quickly blocked while investigators assess what data may have been accessed or exfiltrated.
Tchap, built on the Matrix protocol and used by more than 300,000 monthly users across the French public sector, may have exposed information shared in public chat rooms, which are not end-to-end encrypted. A threat actor claimed the breach resulted from a social engineering attack and alleged access to hundreds of thousands of messages, account details, and shared files. DINUM has notified France’s data protection authority and warned users against sharing sensitive information in public channels while the investigation continues.
Insurers increasingly add exclusions to limit AI coverage.
As AI adoption accelerates, insurers are increasingly adding exclusions to liability policies to limit coverage for AI-related lawsuits and regulatory actions. The shift comes as businesses face growing legal exposure from claims involving copyright infringement, privacy violations, antitrust concerns, algorithmic bias, and alleged misrepresentations about AI capabilities.
Some insurers have introduced broad exclusions that seek to deny coverage for claims arising from AI development, deployment, disclosures, or compliance obligations. However, legal experts note that courts often interpret exclusions narrowly and may still require insurers to defend claims containing both AI-related and non-AI allegations. Policyholders may also challenge overly broad exclusions if they effectively eliminate coverage for core business operations, creating “illusory” insurance.
Experts advise organizations to carefully review policy language, negotiate narrower exclusions where possible, and evaluate older policies issued before AI-specific exclusions became common, as they may provide broader coverage for current AI-related claims.
Fraudsters get their own FBI most wanted list.
The FBI has launched a new “Most Wanted Fraudsters” list to publicly identify and help capture individuals accused of major fraud schemes who have evaded arrest. The initiative is part of a broader federal anti-fraud effort established by a March 2026 executive order creating the Task Force to Eliminate Fraud, chaired by Vice President J.D. Vance. The FBI says the listed suspects are charged with causing significant financial harm to victims and communities. The Bureau is encouraging the public to submit tips anonymously through its website, hotline, or local field offices to assist in locating and apprehending the fugitives.
A U.S. citizen pleads guilty to spying for China.
Thomas Weir Pauken II, a 50-year-old U.S. citizen, has pleaded guilty to acting as an agent for China and helping collect sensitive U.S. information. According to court documents, Pauken worked with individuals he believed were Chinese intelligence operatives, receiving more than $100,000 and travel expenses in exchange for gathering information and producing reports on U.S. technology and government matters. The FBI said he also attempted to infiltrate U.S. political circles on behalf of China’s Ministry of State Security. Pauken faces up to 10 years in prison, with sentencing scheduled for September 1, 2026.
Unpacking a million dollar hotel fee.
Middle school teacher Matthew Spencer can finally sleep a little easier after a mysterious $1,002,852.82 hotel charge vanished from his bank account. For five days, Spencer watched his finances with understandable concern after a one-night stay at an America’s Best Value Inn in Blytheville, Tennessee somehow resulted in a seven-figure charge.
Hotel management says the culprit appears to be a cyberattack affecting card processing systems, not an unusually ambitious room rate. General Manager Miad Ramon demonstrated that the hotel’s payment terminal cannot even accept a million-dollar transaction, then provided transaction records showing no such charge was processed through the property.
With the charge now dropped, Spencer says he feels significantly better. The hotel, meanwhile, is eager to reassure travelers that it would much rather collect room fees than accidental millionaire-sized payments, and continues investigating how the bogus charge appeared in the first place.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
