Italy targeted by multiple adversaries, developments in the APT landscape, vulnerabilities exploited ITW

Weekly Threats hor Telsy

Italy: several malicious activities observed

A phishing campaign has been detected in Italy that abuses the identity of the Postal Police’s Online Public Security Office (Commissariato di P.S. Online) to induce users to voluntarily provide personal and payment information, which is then exfiltrated in real time through WebSocket Secure (WSS). In addition, a new phishing operation delivered via Certified Email (PEC) has been tracked, using ZIP-compressed attachments containing an HTML page named to appear consistent with alleged tax or administrative documentation. Furthermore, a smishing campaign has been observed leveraging visual and textual references associated with SEND – Digital Notification Service and pagoPA, aimed at persuading potential victims to initiate a verification procedure and perform a fraudulent online payment. Security researchers have also identified a spear-phishing operation, active since at least February 2026, aimed at distributing UpCrypter and NeptuneRAT against Italian users and organizations. The emails employ credible themes related to alleged invoices. Turning to the ransomware landscape, The Gentlemen claimed on its leak site the compromise of Buratti S.n.c.; DragonForce Team claimed Tecfi S.p.A.; INC RANSOM Team claimed Framesi S.p.A.; and SAFEPAY claimed B.R.S. Cappuccio S.r.l. and SEI NORDOVEST S.r.l. The railway company managing regional public rail transport services in Emilia-Romagna, Trenitalia Tper S.c.a.r.l., published an official statement reporting that an information security incident had been confirmed, carried out by unidentified external actors, resulting in unauthorized access to certain personal data associated with the purchase of travel tickets. The company specified that no payment data, account access information, or personal credentials were affected. Finally, a large-scale credential harvesting and compromise campaign known as FortiBleed, currently ongoing, has impacted internet-exposed Fortinet FortiGate firewall and VPN gateway devices worldwide. The dataset includes 73,932 unique firewall URLs distributed across 194 countries and associated with 21,632 unique domains. According to the analysis, it corresponds to approximately 75,000 Fortinet devices, representing about half of all Fortinet firewalls currently reachable from the internet. The exposed records include usernames, email addresses, plaintext or cracked passwords, firewall URLs, and organizational details such as industry sector, revenue, and employee count. Evidence of involvement of Italian Public Administration entities has been identified, and the affected administrations were promptly notified through institutional channels.

 

APT: vietnamese, north korean, chinese, and belarusian operations tracked

Security researchers observed two espionage campaigns orchestrated by the Vietnamese threat actor APT32, aimed at deploying the SPECTRALVIPER backdoor. In the first campaign, the network of a Vietnamese company operating in the infrastructure and transportation sector was persistently compromised, while the second campaign took the form of a supply-chain attack targeting Vietnamese stock investors through the FireAnt Metakit platform. An espionage operation orchestrated by the North Korean actor ScarCruft targeting South Korean users was also identified, aimed at distributing a previously undocumented RAT known as NarwhalRAT. Its capabilities include keylogging, continuous or on-demand screen capture, collection of data from USB devices, execution of remote commands, and additional information-gathering routines. Also in Asia, a campaign orchestrated by a threat actor linked to the People’s Republic of China (PRC), tracked as UNC6508, was identified. The actor compromised internet-exposed REDCap servers belonging to numerous North American medical research, academic, and military institutions for more than a year. The objective was the collection of sensitive information related to national security, Indo-Pacific Command operations, and advanced research within the aforementioned sectors. Remaining on the Chinese threat landscape, AQUATIC PANDA was observed distributing SprySOCKS variants for Windows systems against government organizations in Honduras, Taiwan, Thailand, and Pakistan. The new implementations, named WIN_DRV and WIN_PLUS, retain the encryption keys and core command structure of the previous Linux version while adapting them to native Windows mechanisms. Finally, CERT Polska observed that the Belarusian state-sponsored group Ghostwriter intensified phishing campaigns against Gmail accounts belonging to Polish citizens beginning in March 2026. The activities targeted two-factor authentication (2FA) credentials and primarily affected individuals active in political and public life, prominent figures, researchers, journalists, public administration employees, law enforcement personnel, and individuals connected to these groups through family or social ties.

 

Vulnerabilities: multiple vendor flawseExploited ITW and CVE assigned to RoguePlanet

On June 16, 2026, Microsoft released an advisory assigning a CVE identifier to the Microsoft Defender zero-day vulnerability known as RoguePlanet, recently disclosed by the researcher known as Nightmare Eclipse. Tracked as CVE-2026-50656 (CVSS 7.8), the vulnerability is a Link Following issue in the Microsoft Malware Protection Engine component of Microsoft Defender and is classified as an Elevation of Privilege flaw. Microsoft has reported the issue as publicly disclosed but not actively exploited. Following evidence of active exploitation, CISA added to its Known Exploited Vulnerabilities (KEV) catalog CVE-2026-20253 affecting Splunk Enterprise, CVE-2026-48907 affecting Widget Factory Joomla Content Editor (JCE), CVE-2026-35273 affecting Oracle PeopleSoft Enterprise PeopleTools, CVE-2026-20262 affecting Cisco Catalyst SD-WAN Manager, and CVE-2026-54420 affecting the LiteSpeed cPanel Plugin. Regarding CVE-2026-35273, security researchers provided additional details on the exploitation campaign claimed by the ShinyHunters group. Through this activity, PeopleSoft servers belonging to more than 100 organizations across the United States and the United Kingdom were compromised, totaling more than 300 affected instances. The vulnerability was exploited as a zero-day in active attacks before Oracle released its advisory, and the activity was observed starting on May 27, 2026, when staging infrastructure was deployed on attacker-controlled servers. Scanning and exploitation operations continued until June 9, 2026, when the stolen data was publicly released. Lastly, on Monday, June 15, 2026, security researchers reported observing threat actors exploiting three critical vulnerabilities affecting Fortinet FortiSandbox, identified as CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. All three vulnerabilities can be exploited remotely by unauthenticated attackers with low attack complexity and without requiring user interaction. Specifically, they allow unauthenticated adversaries to escalate privileges and execute unauthorized code remotely through command injection attacks.

 


Weekly Threats Report is Telsy’s weekly update featuring the main developments on cyber attacks and threat actors worldwide, produced by our Threat Intelligence & Response team.

The team is composed of analysts and security researchers with technical and investigative skills and internationally recognized experience.

Through continuous monitoring of cyber threats and geopolitical events, it produces and provides organizations with useful information to anticipate attacks and understand their scope, with the support of a trusted partner in the event of a cyber incident.

Learn more about our Cyber Threat Intelligence solution.