Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts

2026-06-15T07:24:09Z88913bc3e6577fe125388d1cd86f7bf1cdd2c1663abe4f85b3fff89806558710
active-exploitationagentjackingai-securityaur-compromiseauth-bypassbitlocker-bypassbotnetebpf-rootkitinfostealerlangflowlanggraphlaw-enforcement-takedownoracle-peoplesoftpalo-alto-globalprotectphishingphishing-as-a-servicercesplunksupply-chainvulnerability-management

What happened

The feed aggregates multiple high-impact security stories from mid-June 2026: active exploitation of several high/critical vulnerabilities (notably Splunk Enterprise RCE CVE-2026-20253 and a PAN-OS GlobalProtect auth bypass CVE-2026-0257), exploited Oracle PeopleSoft (CVE-2026-35273) used in breaches, and other high-severity bugs added to CISA's KEV list. It also highlights large supply-chain and software-distribution attacks (over 400 Arch AUR packages hijacked to deploy an infostealer and eBPF rootkit; npm install-script hardening by GitHub), multiple AI-related attack classes (Agentjacking,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
88913bc3e6577fe125388d1cd86f7bf1cdd2c1663abe4f85b3fff89806558710
Enrichment time
2026-06-15T07:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts · Baitaphish