Hackers Hit Global Stock Exchange, Finance Ministry, Dashlane, Red Hat, and Meta in a Week of Escalating Attacks
A global stock exchange executive was spied on for months; Afghanistan's finance ministry was targeted with Xeno RAT; Dashlane had user vaults downloaded; Red Hat npm packages were wormed; and Meta's AI bot was tricked into seizing Instagram accounts.
A global stock exchange executive had their inbox pillaged for at least five months. Afghanistan's Ministry of Finance was targeted in a spear-phishing campaign. Password manager Dashlane disclosed that fewer than 20 users had their encrypted vaults stolen. Red Hat's npm packages were compromised by a credential-stealing worm. And Meta's AI support bot was tricked into handing over Instagram accounts. Those five separate incidents were all disclosed or analyzed in the first week of June 2026.
Symantec and Carbon Black published details on June 3 of an email spying campaign against a senior member of an unnamed major financial exchange. The attacker used legitimate Windows tools and a custom infostealer built on Aspose's .NET library to convert and exfiltrate emails via Dropbox. The spying ran from at least August 2025 to February 2026. The researchers noted that information about listings, enforcement actions, and market-moving events could have been of significant value to businesses, investors, or a foreign government.
On the same day, The Hacker News reported that the Pakistan-aligned SideCopy group targeted Afghanistan's Ministry of Finance with a spear-phishing campaign. The delivery method was a ZIP archive containing a malicious LNK file with a Pashto-language filename. The payload was Xeno RAT, an open-source remote access trojan.
Dashlane disclosed on May 31 that an external threat actor launched a brute-force attack against certain user accounts on the personal subscription plan. The attacker aimed to break two-factor authentication. Fewer than 20 users had their encrypted vaults downloaded. The company did not specify when the attack occurred or how the attacker gained enough information to target specific accounts.
A new supply chain attack campaign codenamed Miasma compromised Red Hat npm packages, according to a June 2 report. The attack used install-time execution to steal credentials and secrets from developer machines and delivered a self-propagating worm. The researchers said the campaign reused core tactics from the earlier Mini Shai-Hulud campaign, including CI/CD targeting and encrypted exfiltration.
Krebs on Security reported on June 1 that hackers exploited Meta's AI support bot to reset passwords for high-profile Instagram accounts. The attackers followed instructions circulating on Telegram that detailed how to trick the bot into authorizing password changes. Among the accounts defaced were the Obama White House Instagram account and the Chief Master Sergeant of the U.S. Space Force. Both were briefly defaced with pro-Iranian images and messages. Meta has since updated the bot's response protocols.
Security teams across finance, government, and major platforms now face a common pattern: attackers are finding and exploiting the path of least resistance. For the stock exchange and the finance ministry, that path was email and spear-phishing. For Dashlane, it was brute-forcing accounts. For Red Hat, it was the npm supply chain. For Meta, it was a large language model.
Fact check
-
Symantec and Carbon Black reported that a threat actor spied on a senior member of a global stock exchange for at least five months using legitimate Windows tools and Dropbox for exfiltration.
verified · source
-
The Pakistan-aligned SideCopy group targeted Afghanistan's Ministry of Finance with a spear-phishing campaign delivering Xeno RAT.
reported · source
-
Dashlane disclosed that fewer than 20 personal subscription users had their encrypted vaults downloaded after a brute-force attack on May 31, 2026.
verified · source
-
The Miasma supply chain attack compromised Red Hat npm packages with a credential-stealing worm that self-propagated.
reported · source
-
Hackers used Meta's AI support bot to reset passwords for the Obama White House and U.S. Space Force Instagram accounts, which were defaced with pro-Iranian content.
verified · source
Source reporting (5)
- Dark Reading · Global Stock Exchange Hit by Monthslong Email Campaign
- The Hacker News · Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT
- The Hacker News · Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded
- The Hacker News · Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
- Krebs on Security · Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Related Articles
Snowflake hacker pleads guilty to stealing data from 165 organizations, faces 32 years in prison
Aug 5, 2026
AI Agents From OpenAI and Anthropic Breach Real Websites During Security Tests
Aug 5, 2026
AI Agent Security Startups Zenity and Horizon3.ai Raise $375M Combined as SentinelOne Expands Autonomous SOC
Aug 3, 2026
0 Comments
No comments yet
Be the first to share your thoughts on this article.