Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine

2026-06-02T19:24:14Zd8440aeaab4d5846f418a2e0081f252ec569d320d73633e7747ac05fcf956b26
CISA KEVCVE-2024-21182CVE-2025-8088CVE-2026-0257CVE-2026-39987DashlaneEKZ Infostealer (FortiClient EMS campaign)`,`WP Maps Pro`,`WordfGamaredonGammaPhishGammaSteelGammaWormMarimoMiasmaOpenAI Codex token theftOracle WebLogicPAN-OSSicoob.SdkWinRARbrute-force attackcodexui-androidcredential theftmalicious NuGetmalicious npmredhat npmsupply-chain

What happened

The Hacker News roundup describes multiple active and emerging threats: Russian-linked Gamaredon is weaponizing a WinRAR path‑traversal (CVE-2025-8088) to drop HTML App payloads (GammaPhish) that retrieve GammaWorm and GammaSteel; CISA added Oracle WebLogic CVE-2024-21182 to its KEV list after observed exploitation; Palo Alto PAN-OS GlobalProtect auth bypass (CVE-2026-0257) and a Marimo notebook vulnerability (CVE-2026-39987) are being exploited in the wild; and numerous supply‑chain attacks target developers (Miasma: compromised @redhat-cloud-services npm packages, codexui-android stealing Op

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
d8440aeaab4d5846f418a2e0081f252ec569d320d73633e7747ac05fcf956b26
Enrichment time
2026-06-02T19:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.