New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

2026-06-26T19:24:05Z9af61271720311298c7117f3375e3640d8560a99f48cdefb3aa6266851588c27
APTCI/CDChrome extensionCobalt StrikeCordycepsDirtyCloneFortiBleed','FortiGate'GaslightGitHub ActionsLinux kernelMisticNode.js implantSTOCKSTAYSharkLoaderStrikeSharkTinyRCTadblockcredential harvestingloadermalwarenpmpedit COWphishingprivilege escalationsupply chain

What happened

A cluster of active and emerging threats across multiple platforms: a new SharkLoader loader delivering Cobalt Strike (StrikeShark) and other bespoke malware (TinyRCT, STOCKSTAY, Mistic, Gaslight); multiple Linux kernel local privilege-escalation flaws with public exploits (pedit COW, DirtyClone); high-severity product vulnerabilities and active exploitation (Amazon Q MCP flaw, Cisco Catalyst SD‑WAN zero-day, Cisco Unified CM RCE, Lantronix EDS5000 code injection, and a PTC Windchill RCE added to CISA KEV). Supply‑chain and credential-harvesting campaigns continue (Miasma targeting npm/GitHub,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
9af61271720311298c7117f3375e3640d8560a99f48cdefb3aa6266851588c27
Enrichment time
2026-06-26T19:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks · Baitaphish