~/greenteam/nerd

Sunday, June 21, 2026

Daily digest

cybersec BleepingComputer

Microsoft Links Mastra AI Supply Chain Attack to North Korean Hackers

Microsoft has attributed a supply chain attack targeting the Mastra AI framework to North Korean threat actor Sapphire Sleet (BlueNoroff). The attack compromised more than 140 npm packages, potentially affecting any developer or pipeline that pulled those dependencies.

Why it matters: If your self-hosted AI stack or any Ansible/automation pipelines consume npm packages โ€” including indirectly via tooling โ€” audit your dependency trees now for the affected Mastra-related packages. North Korean supply chain ops frequently target credentials and tokens embedded in CI/CD environments, which is a direct CMMC L2 (AC/IA) concern.

cybersec The Hacker News

Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

Active exploitation has been confirmed for CVE-2026-4020 (CVSS 5.3), an unauthenticated information disclosure flaw in the Gravity SMTP WordPress plugin installed on roughly 100,000 sites. Attackers can extract configuration data, API keys, OAuth tokens, and secrets without authentication. A patch is available.

cybersec BleepingComputer

New Prinz Eugen Ransomware Prioritizes Recent Files for Encryption

A newly identified ransomware strain called Prinz Eugen targets recently modified files first during encryption, maximizing damage to active working data before defenders can respond. Unusually, it drops no ransom note on compromised systems, complicating initial incident identification.

Why it matters: The no-ransom-note behavior means initial detection will likely fall entirely on EDR/behavioral telemetry rather than user reports โ€” verify your Intune-managed endpoints have behavioral ransomware protection enabled and that AHV VM snapshot schedules cover recent files.