⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More ⚡
A weekly security roundup covers active Android exploitation, a GitHub supply-chain worm, a U.S. fraud crackdown, and long-running mailbox spying.
Intelligence analysis by GPT-5.4 Mini

The recap pulls together several separate security stories: a worm that hit Microsoft GitHub repos, an Android framework flaw now under exploitation, and multiple campaigns ranging from cyber fraud disruption to stealthy email theft. The theme is familiar but unpleasant: attackers still win with old tricks and patient access.
This roundup is like a report card on burglars. Some smash the front door, like the Android bug and GitHub worm, while others sneak in quietly and read mail for months without being noticed.
Analysis
What stands out
The biggest headline is the Miasma worm, which affected 73 Microsoft GitHub repositories across Azure, Azure-Samples, Microsoft, and MicrosoftDocs. GitHub disabled access to the repos after the activity was identified, and the campaign is described as a variant of the Mini Shai-Hulud worm released in mid-May 2026.
Active exploitation on Android
Google’s June 2026 Android update fixes 124 vulnerabilities, including CVE-2025-48595, a high-severity Framework flaw that Google says may be under “limited, targeted exploitation.” The bug affects Android 14 through 16 QPR2 and allows privilege escalation without user interaction, which makes it especially important for mobile defenders and device fleet operators.
Broader criminal and espionage activity
The U.S. Department of Justice also announced a disruption effort against cyber-enabled and cryptocurrency fraud tied to transnational groups in Southeast Asia. Private-sector partners froze more than $3.8 million in cryptocurrency, and authorities said millions of social media, email, and internet access accounts were taken down.
The roundup also describes TA4922, a financially motivated Chinese-speaking group expanding from East Asia into Europe and Africa, and OP-512, a previously unreported cluster targeting Microsoft IIS servers with a custom web shell framework. In a separate espionage case, attackers reportedly watched a senior executive’s Outlook mailbox for at least five months and exfiltrated mail in small batches through Dropbox and Microsoft OneDrive Personal.
Taken together, the stories show a mix of loud attacks and quiet persistence: worms, zero-days, fraud takedowns, and mailbox intrusions all operating at once.
Key points
- A supply-chain worm called Miasma hit 73 Microsoft GitHub repositories across multiple organizations.
- Google patched 124 Android vulnerabilities, including a Framework flaw under limited targeted exploitation.
- U.S. authorities and private companies disrupted cyber-enabled fraud networks and froze more than $3.8 million in crypto.
- TA4922 is expanding from East Asia into Europe and Africa with localized phishing and malware delivery.
- Attackers reportedly spent months inside a stock exchange executive's Outlook mailbox and exfiltrated mail slowly.
The roundup shows defenders are finding and disrupting attacks faster in some cases, such as GitHub disabling affected repositories and the DOJ working with companies to freeze stolen crypto. Google also pushed patches for the Android flaw, which gives device owners a chance to block exploitation.
The same roundup shows how much damage attackers can do before they are noticed, especially in mailbox theft cases that lasted for months. It also suggests that supply-chain worms, mobile zero-days, and fraud operations are all active at once, leaving defenders with several fronts to protect.



