Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine
2026-06-02T19:24:14Z•d8440aeaab4d5846f418a2e0081f252ec569d320d73633e7747ac05fcf956b26
CISA KEVCVE-2024-21182CVE-2025-8088CVE-2026-0257CVE-2026-39987DashlaneEKZ Infostealer (FortiClient EMS campaign)`,`WP Maps Pro`,`WordfGamaredonGammaPhishGammaSteelGammaWormMarimoMiasmaOpenAI Codex token theftOracle WebLogicPAN-OSSicoob.SdkWinRARbrute-force attackcodexui-androidcredential theftmalicious NuGetmalicious npmredhat npmsupply-chain
What happened
The Hacker News roundup describes multiple active and emerging threats: Russian-linked Gamaredon is weaponizing a WinRAR path‑traversal (CVE-2025-8088) to drop HTML App payloads (GammaPhish) that retrieve GammaWorm and GammaSteel; CISA added Oracle WebLogic CVE-2024-21182 to its KEV list after observed exploitation; Palo Alto PAN-OS GlobalProtect auth bypass (CVE-2026-0257) and a Marimo notebook vulnerability (CVE-2026-39987) are being exploited in the wild; and numerous supply‑chain attacks target developers (Miasma: compromised @redhat-cloud-services npm packages, codexui-android stealing Op
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- d8440aeaab4d5846f418a2e0081f252ec569d320d73633e7747ac05fcf956b26
- Enrichment time
- 2026-06-02T19:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.