Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails

2026-06-16T01:24:10Zda7aef1db117b746b19a98219c12606ca2ff3b0e681d131efff1126bb6a63301
AI-securityAUR compromiseAgentjackingCVE-2026-0257","CVE-2026-35273","phishing-as-a-service","smishinCVE-2026-20253GlobalProtectGoogle WorkspaceLangGraphLiteLLMMicrosoft 365 CopilotNorth KoreaOpenClawOracle PeopleSoftPAN-OSREDCapSearchLeakSplunkagent-exploitationcredential-thefteBPF rootkitemail-exfiltrationespionageinfostealernation-statesupply-chain

What happened

A multi-incident digest: a China-linked group used a REDCap backdoor and rewired Google Workspace rules to exfiltrate research and defense emails; North Korean-linked actors abused developer-focused lures to deliver malware; and multiple high-impact vulnerabilities were disclosed or actively exploited — including a critical unauthenticated Splunk RCE (CVE-2026-20253), an actively exploited PAN-OS GlobalProtect authentication bypass (CVE-2026-0257), and an Oracle PeopleSoft zero-day (CVE-2026-35273) abused by extortion actors. Additional incidents include a LiteLLM privilege-escalation chain, a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
da7aef1db117b746b19a98219c12606ca2ff3b0e681d131efff1126bb6a63301
Enrichment time
2026-06-16T01:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails · Baitaphish