Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
2026-06-16T01:24:10Z•da7aef1db117b746b19a98219c12606ca2ff3b0e681d131efff1126bb6a63301
AI-securityAUR compromiseAgentjackingCVE-2026-0257","CVE-2026-35273","phishing-as-a-service","smishinCVE-2026-20253GlobalProtectGoogle WorkspaceLangGraphLiteLLMMicrosoft 365 CopilotNorth KoreaOpenClawOracle PeopleSoftPAN-OSREDCapSearchLeakSplunkagent-exploitationcredential-thefteBPF rootkitemail-exfiltrationespionageinfostealernation-statesupply-chain
What happened
A multi-incident digest: a China-linked group used a REDCap backdoor and rewired Google Workspace rules to exfiltrate research and defense emails; North Korean-linked actors abused developer-focused lures to deliver malware; and multiple high-impact vulnerabilities were disclosed or actively exploited — including a critical unauthenticated Splunk RCE (CVE-2026-20253), an actively exploited PAN-OS GlobalProtect authentication bypass (CVE-2026-0257), and an Oracle PeopleSoft zero-day (CVE-2026-35273) abused by extortion actors. Additional incidents include a LiteLLM privilege-escalation chain, a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- da7aef1db117b746b19a98219c12606ca2ff3b0e681d131efff1126bb6a63301
- Enrichment time
- 2026-06-16T01:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.