CVE-2018-1002208, CVE-2024-43093, CVE-2024-50302, CVE-2025-11043, CVE-2025-38352, CVE-2025-48543, CVE-2026-0073, CVE-2026-0300, CVE-2026-0936, CVE-2026-21661, CVE-2026-23918, CVE-2026-29014, CVE-2026-31431, CVE-2026-43037, CVE-2026-43964
Domains:
daemontools[.]cc, daemontools[.]cc.
Get tomorrow's brief in your inbox
Today: Palo Alto Networks firewalls face active zero-day exploitation targeting exposed authentication portals. DAEMON Tools supply chain attack compromises thousands with signed backdoor installers. Latvian Karakurt negotiator sentenced to 8.5 years for extorting $56M from US organizations.
Palo Alto Networks PAN-OS Zero-Day Exploited (CVE-2026-0300)
Palo Alto Networks is patching a critical buffer overflow in the User-ID Authentication Portal (Captive Portal) affecting PA-Series and VM-Series firewalls. The flaw allows unauthenticated remote code execution with root privileges via specially crafted packets. Limited exploitation has been observed targeting publicly exposed portals. Over 5,800 VM-series firewalls remain exposed online, primarily in Asia and North America. First patches drop May 13 with full remediation by May 28.
Apache HTTP Server Double-Free Leads to DoS and RCE (CVE-2026-23918)
Apache HTTP Server 2.4.66 contains a critical double-free vulnerability in mod_http2 that enables denial-of-service and remote code execution. The flaw triggers when a client sends HTTP/2 HEADERS immediately followed by RST_STREAM with non-zero error code, causing the same h2_stream pointer to be freed twice. DoS is trivial on any multi-threaded MPM deployment. RCE requires APR with mmap allocator, default on Debian-derived systems and official httpd Docker images. Researchers demonstrated working RCE proof-of-concept on x86_64. Attack requires one TCP connection and two frames, no authentication.
Android Critical RCE Patched (CVE-2026-0073)
Google patched a critical Android System vulnerability allowing remote code execution as the shell user without requiring additional execution privileges or user interaction. The flaw affects adbd (Android Debug Bridge daemon), which manages communication between devices and computers. No exploitation has been observed. Several Android vulnerabilities from 2024-2025 remain on CISA KEV: CVE-2024-43093 (EPSS 0.2%, KEV deadline Nov 2024), CVE-2025-48543 (EPSS 0.3%, KEV deadline Sep 2025), CVE-2025-38352 (EPSS 0.1%, KEV deadline Sep 2025), CVE-2024-50302 (EPSS 1.7%, KEV deadline Mar 2025).
3 claims tracked across 3 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| ms13-089 | brittanyresidential.com | Healthcare (Developmental Disabilities) | USA, Ohio |
| bavacai | Elken Sdn Bhd | MLM / Health & Beauty | Malaysia |
| icarus | Cazh.id | Technology (User Database) | Indonesia |
Karakurt Ransomware Negotiator Sentenced to 8.5 Years
Deniss Zolotarjovs, 35, of Latvia, received 102 months in federal prison for his role as a negotiator in the Karakurt ransomware operation led by former Conti leaders. Between June 2021 and March 2023, Zolotarjovs analyzed stolen data and conducted ransom negotiations for attacks against 53+ organizations, causing $56 million in confirmed losses. The group operated under multiple names including Conti, Karakurt, Royal, TommyLeaks, SchoolBoys Ransomware, and Akira. Zolotarjovs received 10% of ransom payments in cryptocurrency, converted to Russian rubles through multiple wallets. He researched victims to identify leverage points, including threatening to publish pediatric healthcare records when a children's hospital refused to pay. One attack forced a government 911 system offline. Arrested in Georgia in December 2023, extradited to US in August 2024, pleaded guilty July 2025.
CloudZ RAT Abuses Windows Phone Link to Steal OTPs
New CloudZ remote access trojan uses custom Pheno plugin to hijack Microsoft Phone Link application, intercepting SMS and one-time passwords without deploying malware on the mobile device itself. The attack monitors for active Phone Link processes and accesses the SQLite database storing synchronized phone data. Active since January 2026, the campaign leverages fake ConnectWise ScreenConnect executables as initial droppers. CloudZ supports commands for credential exfiltration, browser data theft, Phone Link data extraction, screen recording, and plugin deployment to C:\ProgramData\Microsoft\whealth.
DAEMON Tools Supply Chain Attack Delivers Signed Backdoor
Hackers compromised DAEMON Tools installers distributed from the legitimate website since April 8, 2026. Versions 12.5.0.2421 through 12.5.0.2434 contain trojanized binaries (DTHelper.exe, DiscSoftBusServiceLite.exe, DTShellHlp.exe) signed with valid DAEMON Tools developer certificates. The backdoor contacts env-check.daemontools[.]cc (registered March 27) to receive shell commands, downloading information collector (envchk.exe) and minimalist backdoor (cdg.exe). Kaspersky observed several thousand infections across 100+ countries, but only a dozen systems received the second-stage QUIC RAT, indicating targeted deployment. Victims include government, scientific, manufacturing, and retail organizations in Russia, Belarus, and Thailand. Evidence suggests Chinese-speaking threat actor. Attack remained undetected for nearly one month.
Microsoft Warns of Sophisticated AiTM Phishing Campaign
Microsoft observed 35,000+ phishing attempts between April 14-16 using "code of conduct review" lures to deliver adversary-in-the-middle (AiTM) attacks. 92% of 13,000 targeted organizations were in the US, primarily healthcare, financial services, professional services, and technology sectors. Emails use display names like 'Team Conduct Report' and 'Workforce Communications' with subjects such as 'Reminder: employer opened a non-compliance case log'. PDF attachments direct victims to Cloudflare CAPTCHA pages (anti-analysis gating), then to fake document review pages requesting email address and Microsoft account credentials. AiTM attacks proxy authentication sessions in real time, intercepting tokens to bypass non-phishing-resistant MFA.
Microsoft Edge Stores All Passwords in Cleartext Memory
Microsoft Edge decrypts and stores all saved passwords in cleartext in process memory, even for sites not visited during the current session. An attacker with administrative access on terminal servers, Citrix, or VDI environments can dump process memory to extract all stored credentials without triggering Edge's password view authentication. Research demonstrated extraction using Task Manager memory dump and strings utility searching for "comhttps" pattern. Microsoft classified this behavior as "by design". Risk is significant in shared corporate environments where admins can access memory of all logged-on user processes.
OAuth Grants Create Persistent Backdoor in Enterprise Environments
OAuth tokens granted to third-party apps connected to Google or Microsoft environments persist with no expiration, don't expire when employees leave, and don't reset with password changes. 80% of security leaders consider unmanaged OAuth grants a critical risk, but 45% do nothing to monitor them at scale, and 33% rely on manual spreadsheet tracking. The Drift/Salesloft incident demonstrated real-world impact: threat actor UNC6395 obtained valid OAuth refresh tokens (likely via phishing) and used them to access Salesforce environments at 700+ organizations, bypassing MFA entirely. The tokens were legitimate from a trusted integration, making the activity invisible to perimeter controls. Attackers systematically exported data to harvest AWS keys, Snowflake tokens, and passwords.
MetInfo CMS Remote Code Execution Exploited (CVE-2026-29014)
Attackers actively exploit a critical code injection flaw in MetInfo CMS versions 7.9, 8.0, and 8.1 allowing unauthenticated remote code execution. The vulnerability stems from inadequate input sanitization in the WeChat API request handler (/app/system/weixin/include/class/weixinreply.class.php). Exploitation on non-Windows servers requires /cache/weixin/ directory to exist, created when installing the WeChat plugin. VulnCheck observed initial sparse exploitation starting April 25, with surge on May 1 targeting China and Hong Kong IP addresses. Approximately 2,000 MetInfo CMS instances are accessible online, primarily in China. Patches released April 7, 2026. EPSS 14.3% (94th percentile).
Google Expands Binary Transparency for Android Apps
Google launched Binary Transparency for Android, creating a public cryptographic ledger recording metadata about official Google app releases to safeguard against supply chain attacks. The initiative builds on Pixel Binary Transparency introduced October 2021. All Google production Android applications released after May 1, 2026 will have cryptographic entries confirming authenticity. Binary Transparency provides verifiable proof that software is the intended production version, not a malicious one-off build. The system addresses the limitation that digital signatures certify origin but not intent. Coverage includes Google Play Services, standalone Google apps, and Mainline modules. Verification tooling is publicly available.
Quasar Linux Malware Targets Software Developers
New Linux implant QLNX combines rootkit, backdoor, and credential-stealing capabilities to target developer systems. The malware demonstrates growing sophistication of Linux-focused threats.
DarkSword iOS Exploit Chain
Google Threat Intelligence Group identified DarkSword, a sophisticated iOS full-chain exploit leveraging multiple zero-days to fully compromise devices. Active since November 2025, GTIG observed multiple commercial surveillance vendors and suspected state-sponsored actors deploying DarkSword. Toolmarks suggest government-designed malware.
Trellix Source Code Breach
Trellix experienced a source code breach. Such breaches can reveal security control locations and detection design, giving attackers insights into bypassing the security product.
Instructure Breach Claims 280M Records
Hacker claims to have stolen 280 million data records for students and staff from 8,809 colleges, school districts, and online education platforms in a breach at education technology provider Instructure.
Copy Fail Linux Kernel Vulnerability (CVE-2026-31431)
Critical Linux kernel local privilege escalation flaw allows stealthy root access. Impacts millions of systems. Palo Alto Unit 42 warns this is one of the most severe Linux threats in years.
ICS Vulnerabilities
Multiple industrial control system vulnerabilities disclosed by CISA:
Hitachi Energy PCM600 (CVE-2018-1002208): SharpZipLib directory traversal (Zip-Slip) affects PCM600 Legacy 2.11 and earlier, plus PCM600 3.0-3.1 SP3. EPSS 0.6% (70th percentile). Migrate to PCM600 3.1 SP4 when available.
ABB B&R Automation Studio (CVE-2025-11043): Improper certificate validation in OPC-UA and ANSL over TLS clients allows network position attacks. Fixed in version 6.5. EPSS 0.0% (7th percentile).
ABB B&R PVI (CVE-2026-0936): Sensitive information in log files for PVI client versions before 6.5.0. Logging disabled by default. EPSS 0.0% (4th percentile).
Johnson Controls CEM AC2000 (CVE-2026-21661): DLL hijacking allows privilege escalation. Affects versions 10.6, 11.0, 12.0. Upgrade to respective latest releases (10.6 R3, 11.0 R9, 12.0 R10).
Sources: CISA ICS Advisories
SSL.com Root Certificate Rotation
SSL.com rotated root certificate May 5, 2026. Organizations with pinned trust anchors, custom trust stores, or certificate validation logic tied to 2016 roots should audit configurations. Cross-certificates available for backward compatibility during transition.
Microsoft CVE Disclosures
Microsoft published information for CVE-2026-43037 (ip6_tunnel kernel issue) and CVE-2026-43964. Minimal details available in MSRC update guide.
Supply chain attacks dominate today's threat landscape with three major incidents: DAEMON Tools (signed backdoor, one month undetected), Google's Binary Transparency response, and Trellix source code breach. These demonstrate the sophistication of modern supply chain compromise and the industry's defensive response. Zero-day exploitation remains high-priority with Palo Alto firewalls (5,800+ exposed), Apache HTTP/2 RCE, and iOS DarkSword chain. Enterprise authentication vectors expand beyond credentials to include OAuth tokens (Drift incident, 700+ orgs) and phone sync features (CloudZ/Pheno). The sentencing of the first Karakurt operator signals increasing international law enforcement coordination against ransomware gangs operating from historically safe havens.