# Threat Intel Brief — June 23, 2026

TL;DR

  • Critical database vulnerabilities: pgAdmin 4 and ProxySQL contain RCE and ACL bypass flaws enabling credential theft and infrastructure compromise; immediate patching required.
  • Supply chain attacks escalate: ShapedPlugin WordPress Pro plugins backdoored through compromised vendor update channels; AryStinger botnet infects 4,300+ legacy routers for reconnaissance operations.
  • Cloud infrastructure at risk: Universal bucket hijacking technique disclosed affecting AWS, Azure, and GCP; 29-year-old Squid proxy flaw leaks cleartext credentials.
  • AI platform vulnerabilities: Microsoft patches AutoJack flaw in AutoGen Studio; DifyTap flaws expose cross-tenant AI conversations; FFmpeg PixelSmash enables RCE on Jellyfin servers.
  • Active campaigns: FortiBleed targets FortiGate devices with credential sniffers; Russian-speaking actors deploy OXLOADER via malicious Google Ads; WhatsApp malware campaign distributes VBScript RATs globally.

Critical Threats

pgAdmin 4 Remote Code Execution and Credential Theft

What happened: CERT.BE disclosed critical vulnerabilities in pgAdmin 4 combining remote code execution with cross-site scripting capabilities. Attackers can execute arbitrary commands on pgAdmin servers and exfiltrate PostgreSQL database credentials. The vulnerabilities affect the widely deployed open-source database administration tool used across government, finance, and enterprise sectors. No CVE has been publicly assigned yet.

Impact: Organizations running pgAdmin 4 face immediate risk of database compromise. Successful exploitation grants attackers full access to managed PostgreSQL instances, enabling data exfiltration, ransomware deployment, and lateral movement within networks. The tool's prevalence in critical infrastructure and cloud environments amplifies the blast radius. Database administrators represent high-value targets for credential harvesting operations.

Recommendations: Update pgAdmin 4 to the latest patched version immediately. Restrict pgAdmin network access to trusted IP ranges or VPN-only connections; remove all internet-facing deployments. Audit PostgreSQL access logs for unauthorized queries or account modifications. Review database user permissions and rotate credentials for accounts accessible via pgAdmin. If patching is delayed, disable pgAdmin and use command-line tools for critical operations.

---

ProxySQL ACL Bypass and Heap Corruption

What happened: CERT.BE warned of critical vulnerabilities in ProxySQL enabling ACL bypass and heap memory corruption. The flaws allow attackers to circumvent authentication controls and potentially achieve remote code execution on database proxy infrastructure. ProxySQL is widely deployed for MySQL/MariaDB load balancing in high-availability environments. Specific CVE identifiers have not been assigned.

Impact: Unauthorized database access bypassing authentication mechanisms threatens data confidentiality and integrity across multi-tenant and enterprise database deployments. Heap corruption vulnerabilities create pathways for complete proxy server compromise, potentially exposing all backend database traffic. Organizations using ProxySQL in critical infrastructure, financial services, or cloud platforms face elevated risk of data breach and service disruption.

Recommendations: Apply vendor patches immediately or upgrade to the latest stable ProxySQL version. Implement network segmentation to restrict ProxySQL access to authorized database clients only. Monitor ProxySQL logs for anomalous connection attempts or query patterns. Review backend database access controls and rotate credentials as a precautionary measure. Deploy process monitoring to detect crashes or unexpected memory usage indicating exploitation attempts.

---

ShapedPlugin WordPress Supply Chain Compromise

What happened: Multiple Pro-tier WordPress plugins from ShapedPlugin were backdoored in a supply chain attack. Threat actors compromised the vendor's build and distribution pipeline, injecting malicious code into official plugin releases distributed through licensed update channels. Customers received backdoored updates through trusted mechanisms, bypassing typical security controls.

Impact: Organizations running affected ShapedPlugin Pro plugins received malicious code through legitimate update processes, establishing persistent backdoor access to WordPress installations. The compromise enables data exfiltration, site defacement, malware distribution, and lateral movement within networks. Trust relationships with the vendor are fundamentally compromised, requiring forensic analysis of all installations that received updates during the compromise window.

Recommendations: Immediately identify all WordPress installations using ShapedPlugin Pro plugins via asset inventory. Isolate or disable affected plugins until the vendor publishes verified clean versions and incident timeline. Review WordPress access logs for suspicious administrative actions, new user accounts, or file modifications following recent updates. Monitor outbound network connections from WordPress servers for unexpected C2 activity. Consider replacing ShapedPlugin products with alternatives from vendors demonstrating stronger supply chain security controls.

---

FFmpeg PixelSmash Vulnerability

What happened: FFmpeg fixed a vulnerability dubbed PixelSmash affecting its video decoder. The flaw enables remote code execution on Jellyfin media servers and denial-of-service attacks in applications including Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. FFmpeg's widespread use in media processing pipelines amplifies the attack surface. No CVE has been assigned yet.

Impact: Jellyfin deployments face critical RCE exposure allowing full server compromise when processing untrusted media files. Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio installations are vulnerable to denial-of-service attacks disrupting media services and workflows. Organizations processing user-uploaded media or operating internet-facing media servers face immediate exploitation risk.

Recommendations: Update FFmpeg to the latest patched version immediately once specific version details are published. Prioritize patching Jellyfin servers exposed to untrusted media sources or internet-facing deployments. Monitor vendor security advisories from Jellyfin, Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio for patch releases addressing PixelSmash. Restrict media file uploads and processing to trusted sources until patches are applied. Implement network segmentation to isolate media processing infrastructure.

Threat Actor Activity

FortiBleed Campaign Targets FortiGate Devices

The FortiBleed campaign deployed custom credential-sniffing malware on compromised Fortinet FortiGate firewalls to harvest authentication credentials at scale. The operation demonstrates sophisticated understanding of FortiOS internals and strategic positioning on network perimeters to intercept VPN and administrative credentials. The large-scale nature suggests systematic exploitation of internet-facing FortiGate management interfaces, likely leveraging known vulnerabilities or weak credentials. Organizations using FortiGate devices as VPN gateways or perimeter firewalls face elevated risk.

Defensive actions: Audit all FortiGate devices for unauthorized processes, custom binaries, or modified system files using Fortinet integrity verification tools. Monitor for anomalous outbound connections or data exfiltration patterns. Apply all available Fortinet security patches, particularly for authentication bypass vulnerabilities. Restrict administrative access to trusted IP ranges and implement jump host architecture. Deploy network-based detection for exploitation attempts against FortiGate management interfaces.

---

Russian-Speaking Actors Deploy OXLOADER and CastleStealer

A financially motivated, Russian-speaking threat actor is distributing OXLOADER—a previously unreported custom loader—via malicious Google Ads to deploy CastleStealer information-stealing malware. The campaign leverages malvertising for initial access, targeting users searching for popular software. OXLOADER serves as a first-stage loader with defense evasion capabilities, delivering CastleStealer for credential harvesting and data exfiltration.

Defensive actions: Monitor and block malicious Google Ads campaigns through threat intelligence feeds and DNS filtering. Deploy behavioral detection for loader activity focusing on process injection and unusual parent-child process relationships. Implement credential theft detection by monitoring access to browser credential stores and password vaults using EDR telemetry. Enforce application control policies to prevent execution of unsigned binaries from advertising networks. Conduct user awareness training on malvertising risks and verification of download sources.

---

AryStinger Botnet Builds Reconnaissance Network

AryStinger, a newly discovered malware family, has infected over 4,300 legacy routers to build a distributed reconnaissance and proxy network. Unlike traditional DDoS botnets, AryStinger is purpose-built for pre-attack reconnaissance operations. The malware targets end-of-life D-Link routers and other legacy devices in telecommunications and ISP infrastructure, providing strategic network positioning for intelligence gathering and anonymized traffic routing.

Defensive actions: Inventory and isolate legacy router devices from internet exposure; implement network segmentation to restrict management interface access. Deploy network-based detection for anomalous outbound connections and proxy traffic patterns from router infrastructure. Enforce strong authentication on all router management interfaces and disable default credentials. Establish firmware update policies with regular patching cycles; prioritize replacement of end-of-life routers. Monitor NetFlow data to identify compromised routers participating in proxy or scanning activity.

Geopolitical Context

The disclosure of critical vulnerabilities in pgAdmin 4 and ProxySQL by CERT.BE reflects Belgium's role as a European cybersecurity coordination hub, hosting EU institutions and NATO infrastructure. These database management tools underpin critical systems across government, finance, and telecommunications globally, making them attractive targets for espionage-focused advanced persistent threat actors. The vulnerabilities pose heightened risk across the European Union, where PostgreSQL is extensively deployed in public sector digitalization initiatives.

The Russian-speaking OXLOADER campaign operates within a permissive environment where cybercriminal infrastructure faces limited domestic enforcement. While financially motivated rather than state-directed, such actors often benefit from de facto safe harbor when targeting entities outside the Commonwealth of Independent States. The campaign underscores persistent exposure to threats leveraging advertising platforms that cross jurisdictional boundaries.

The AryStinger botnet's targeting of telecommunications and ISP infrastructure echoes tactics observed in state-sponsored operations seeking strategic network access. The reconnaissance-focused design suggests the botnet serves as preparatory infrastructure for subsequent operations, potentially enabling network mapping of downstream customers or anonymized command-and-control for follow-on intrusions.

Recommended Actions

Immediate (0-24 hours)

  • Patch critical database vulnerabilities: Update pgAdmin 4 and ProxySQL to latest versions; restrict network access to trusted ranges.
  • Audit WordPress installations: Identify and isolate ShapedPlugin Pro plugins; review access logs for compromise indicators.
  • Update FFmpeg and dependent applications: Patch Jellyfin, Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio to versions incorporating FFmpeg fixes.
  • Assess FortiGate exposure: Audit FortiGate devices for unauthorized modifications; apply all available Fortinet security patches.
  • Block VBScript execution: Configure Group Policy or AppLocker to prevent VBScript file execution on Windows endpoints.

Short-term (24-72 hours)

  • Review cloud storage configurations: Audit all cloud bucket references in application code and configurations; implement bucket name reservation policies.
  • Enhance SIEM correlation: Review correlation rules to detect anomalous patterns indicating multiple concurrent intrusions or overlapping threat actor behaviors.
  • Rotate credentials: Rotate credentials and session tokens for services accessed through Squid proxies and database management tools.
  • Deploy EDR rules: Implement detection for OXLOADER loader activity, credential theft attempts, and malicious advertising-based downloads.

This week

  • Replace legacy routers: Prioritize replacement of end-of-life D-Link and other legacy routers lacking security support.
  • Conduct threat hunting: Execute hunting exercises targeting indicators of simultaneous access by distinct actors and bucket hijacking scenarios.
  • Review AI platform deployments: Identify Dify and AutoGen Studio instances; monitor for patches addressing DifyTap and AutoJack vulnerabilities.
  • Implement network segmentation: Isolate database proxy infrastructure, media processing systems, and legacy networking equipment from critical assets.

Watch List

  • Cloud bucket hijacking: Monitor for vendor responses from AWS, Azure, and GCP regarding namespace policy changes to address universal bucket hijacking technique.
  • Squidbleed exploitation: Track for proof-of-concept exploit code publication and active exploitation attempts against unpatched Squid instances.
  • Cryptocurrency MEV bot attacks: JaredFromSubway Ethereum MEV bot compromise demonstrates sophisticated manipulation of automated trading logic; monitor for similar attacks on DeFi infrastructure.
  • Dual ransomware actor scenarios: Microsoft's documentation of parallel threat actors in single environments highlights detection gaps; watch for additional reports of overlapping intrusions.
  • WhatsApp malware campaigns: Monitor for expansion of VBScript-based malware distribution via messaging platforms targeting business users.

Sources

  • BleepingComputer: WhatsApp phishing attack uses fake business docs to hack PCs
  • BleepingComputer: FFmpeg fixes PixelSmash flaw in widely used video decoder
  • BleepingComputer: FortiBleed campaign used custom FortiGate sniffer to steal credentials
  • BleepingComputer: Microsoft fixes AutoGen Studio flaw that enabled code execution
  • BleepingComputer: AryStinger botnet infected thousands of D-Link routers worldwide
  • The Hacker News: ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
  • The Hacker News: Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
  • The Hacker News: 29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests
  • The Hacker News: New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
  • The Hacker News: AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network
  • Unit 42 (Palo Alto Networks): The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration
  • Microsoft Security: One intrusion, two cyberattackers: Uncovering parallel threat activity
  • CERT.BE: WARNING: Remote Code Execution and Cross-Site Scripting in pgAdmin 4
  • CERT.BE: WARNING: ACL Bypass and Heap Memory Corruption in ProxySQL