Suspicious Polyfill login prompts pop up on Toshiba, Muji websites
2026-06-06T13:23:31Z•d6672c10e1cfbd5a176ffb26fa582f42a531fb9f442be4d609396d04beba8c59
APT-UNC5221ATG-exposureCISACVE-2026-20245DentaQuest-breach","WFP-breachagentpsdbrickstormcredential-harvestingcritical-infrastructurecryptominerdata-breachhola-browserironwormmagecartnpm-malwarepayment-card-theftphishingplenetpolyfill-loginroot-privilege-escalationsd-wansolarwinds-serv-ustripe-abusesupply-chainzero-day
What happened
Multiple active and emerging threats reported: suspicious polyfill-based login prompts on Toshiba and Muji sites used for credential theft; CISA warns of active exploitation of a recently patched high-severity SolarWinds Serv-U flaw to crash servers; Cisco reports an actively exploited, unpatched SD‑WAN zero-day (CVE-2026-20245) enabling root escalation. A Chinese APT (UNC5221) is deploying Brickstorm plus new Plenet and AgentPSD malware to maintain Microsoft 365 access. Large-scale exposures and supply-chain incidents include 900+ US automatic tank gauge (ATG) systems exposed, 36 npm packages
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d6672c10e1cfbd5a176ffb26fa582f42a531fb9f442be4d609396d04beba8c59
- Enrichment time
- 2026-06-06T13:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.