New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
2026-06-26T19:24:05Z•9af61271720311298c7117f3375e3640d8560a99f48cdefb3aa6266851588c27
APTCI/CDChrome extensionCobalt StrikeCordycepsDirtyCloneFortiBleed','FortiGate'GaslightGitHub ActionsLinux kernelMisticNode.js implantSTOCKSTAYSharkLoaderStrikeSharkTinyRCTadblockcredential harvestingloadermalwarenpmpedit COWphishingprivilege escalationsupply chain
What happened
A cluster of active and emerging threats across multiple platforms: a new SharkLoader loader delivering Cobalt Strike (StrikeShark) and other bespoke malware (TinyRCT, STOCKSTAY, Mistic, Gaslight); multiple Linux kernel local privilege-escalation flaws with public exploits (pedit COW, DirtyClone); high-severity product vulnerabilities and active exploitation (Amazon Q MCP flaw, Cisco Catalyst SD‑WAN zero-day, Cisco Unified CM RCE, Lantronix EDS5000 code injection, and a PTC Windchill RCE added to CISA KEV). Supply‑chain and credential-harvesting campaigns continue (Miasma targeting npm/GitHub,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 9af61271720311298c7117f3375e3640d8560a99f48cdefb3aa6266851588c27
- Enrichment time
- 2026-06-26T19:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.