Sunday, June 21, 2026
Daily digest
Microsoft Links Mastra AI Supply Chain Attack to North Korean Hackers
Microsoft has attributed a supply chain attack targeting the Mastra AI framework to North Korean threat actor Sapphire Sleet (BlueNoroff). The attack compromised more than 140 npm packages, potentially affecting any developer or pipeline that pulled those dependencies.
Why it matters: If your self-hosted AI stack or any Ansible/automation pipelines consume npm packages โ including indirectly via tooling โ audit your dependency trees now for the affected Mastra-related packages. North Korean supply chain ops frequently target credentials and tokens embedded in CI/CD environments, which is a direct CMMC L2 (AC/IA) concern.
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
Active exploitation has been confirmed for CVE-2026-4020 (CVSS 5.3), an unauthenticated information disclosure flaw in the Gravity SMTP WordPress plugin installed on roughly 100,000 sites. Attackers can extract configuration data, API keys, OAuth tokens, and secrets without authentication. A patch is available.
New Prinz Eugen Ransomware Prioritizes Recent Files for Encryption
A newly identified ransomware strain called Prinz Eugen targets recently modified files first during encryption, maximizing damage to active working data before defenders can respond. Unusually, it drops no ransom note on compromised systems, complicating initial incident identification.
Why it matters: The no-ransom-note behavior means initial detection will likely fall entirely on EDR/behavioral telemetry rather than user reports โ verify your Intune-managed endpoints have behavioral ransomware protection enabled and that AHV VM snapshot schedules cover recent files.