← Carolina Clear Tech

Cyber Threat Brief

2026-05-09

Listen to this brief (20:10)

Download MP3
Show Notes

Show Notes - 2026-05-09

Stories Covered

CVEs Referenced

CVE-2026-0300, CVE-2026-1281, CVE-2026-1340, CVE-2026-29201, CVE-2026-29202, CVE-2026-29203, CVE-2026-41940, CVE-2026-42208, CVE-2026-43284, CVE-2026-43500, CVE-2026-6973

Indicators of Compromise

IP Addresses: 12.8.0.0, 12.6.1.1, 12.7.0.1, 12.8.0.1, 11.136.0.9

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

May 9, 2026

Today: Palo Alto Networks is patching CVE-2026-0300, a critical zero-day in PAN-OS being actively exploited for remote code execution with a Sunday deadline for federal agencies. The Dirty Frag Linux kernel exploit is gaining traction in the wild with public root exploit code available and no patches yet released. Poland documents five water treatment plant breaches where attackers gained ICS access and the ability to modify operational parameters, while Ivanti EPMM customers face another zero-day patch deadline after CVE-2026-6973 was exploited by threat actors.

Critical Alerts

Palo Alto Networks PAN-OS Zero-Day (CVE-2026-0300)

Palo Alto Networks disclosed CVE-2026-0300, a critical buffer overflow in the PAN-OS User-ID Authentication Portal (Captive Portal) that allows unauthenticated remote code execution with root privileges. The vulnerability scores 9.3 CVSS and is being actively exploited in the wild. CISA added it to the Known Exploited Vulnerabilities catalog with a May 9 remediation deadline. EPSS scoring indicates 4.6% exploitation probability (89th percentile).

Ivanti EPMM Zero-Day Exploited (CVE-2026-6973)

CISA has given federal agencies until Sunday, May 10 to patch CVE-2026-6973, a high-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows authenticated administrators to execute arbitrary code remotely. The flaw was exploited as a zero-day and affects EPMM 12.8.0.0 and earlier. Over 800 EPMM appliances remain exposed online according to Shadowserver. This is the third actively exploited EPMM vulnerability in 2026, following CVE-2026-1281 and CVE-2026-1340 from January.

Dirty Frag Linux Privilege Escalation Under Active Exploitation

Microsoft reports active exploitation of Dirty Frag, a Linux local privilege escalation vulnerability (CVE-2026-43284, CVE-2026-43500) affecting kernel networking and memory fragment handling in esp4, esp6, and rxrpc components. The exploit enables escalation from unprivileged user to root with higher reliability than traditional Linux privilege escalation techniques. Public proof-of-concept code is available. Affected distributions include Ubuntu, RHEL, CentOS Stream, AlmaLinux, Fedora, openSUSE, and OpenShift. Microsoft Defender detects limited in-the-wild activity showing privilege escalation via 'su' followed by reconnaissance and data access. No patches are currently available.

BerriAI LiteLLM SQL Injection (CVE-2026-42208)

CISA added CVE-2026-42208, a SQL injection vulnerability in BerriAI LiteLLM, to the Known Exploited Vulnerabilities catalog with a May 11 remediation deadline. The vulnerability has extremely low EPSS scoring (0.1%, 24th percentile) but CISA identified evidence of active exploitation. LiteLLM is an AI gateway and proxy tool used to manage API calls to multiple LLM providers.

Ransomware & Extortion

Karakurt Extortion Negotiator Sentenced to 9 Years

Federal prosecutors secured a nearly nine-year prison sentence for Deniss Zolotarjovs, a Latvian national who served as a specialized "cold case" negotiator for the Karakurt extortion syndicate. Operating under the alias Sforza_cesarini, Zolotarjovs targeted victims who had previously stopped communicating with the group, using stolen personal data and sensitive health information, including children's medical records, to coerce ransom payments. The broader Karakurt operation has extorted an estimated $56 million from dozens of organizations. This marks the first federal prosecution of a Karakurt member.

North Korean IT Worker Laptop Farm Operators Sentenced

Two American nationals, Matthew Knoot and Erick Prince, were sentenced to 18 months in prison for operating laptop farms that facilitated North Korean cyber infiltration into nearly 70 U.S. companies. The defendants received company-issued laptops and deployed unauthorized remote desktop software, allowing DPRK-based IT workers to masquerade as legitimate domestic employees while stealing intellectual property, implanting malware, and siphoning funds to the sanctioned regime. The operation generated $1.2 million for North Korea.

RansomHouse Claims Trellix Source Code Breach

RansomHouse claimed responsibility for the May 1 breach of Trellix's source code repository, publishing screenshots of the cybersecurity company's appliance management system. Trellix confirmed unauthorized access to a portion of its source code repository on April 17, followed by data encryption. The company stated it found no evidence that source code release or distribution processes were affected, or that source code has been exploited. Trellix has over 53,000 customers in 185 countries. BleepingComputer could not independently verify the authenticity of the leaked data.

ShinyHunters Second Breach of Instructure Canvas

The ShinyHunters gang claimed a second breach of Instructure, the Canvas learning management system provider, hours after the company declared the incident contained. On May 7, Instructure took Canvas offline again after confirming the threat actor exploited an issue related to Free-For-Teacher accounts. The company temporarily shut down all Free-For-Teacher accounts and restored Canvas service. Students and teachers reported disruptions to final exams and coursework during the outage. ShinyHunters extended their leak deadline to May 12 and offered affected schools the option to negotiate directly. Canvas is used by hundreds of colleges and universities, with hundreds of millions of user records potentially exposed.

IOCs & Detection

PCPJack Cloud Worm Evicts TeamPCP, Harvests Credentials

SentinelLABS exposed PCPJack, a credential theft framework and cloud worm that actively hunts, evicts, and deletes artifacts associated with TeamPCP, a threat group responsible for multiple supply chain intrusions. The multi-stage infection begins with bootstrap.sh, which downloads specialized Python modules from an attacker-controlled S3 bucket. The malware extracts cloud access keys, Kubernetes service account tokens, Docker secrets, enterprise application tokens, and cryptocurrency wallets. Unlike typical cloud threats, PCPJack does not deploy cryptomining payloads. The framework exploits Next.js and WordPress vulnerabilities while scanning for exposed Docker, Redis, RayML, and MongoDB instances. Stolen data is encrypted and exfiltrated via Telegram.

Business & Infrastructure Threats

Poland Documents ICS Breaches at Five Water Treatment Plants

Poland's Internal Security Agency (ABW) documented security breaches at water treatment stations in Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko, and Sierakowo during 2025. In some cases, attackers gained access to industrial control systems and obtained the ability to modify operational parameters of equipment, creating direct risk to operational continuity and public water supply. ABW identified two primary attack vectors: weak password policies and systems exposed directly to the internet. The agency attributed responsibility to Russian APT groups APT28 and APT29, and Belarusian-linked UNC1151. Attacks also targeted supply chains, wastewater treatment plants, and waste incineration facilities.

Zara Breach Exposes 197,000 Customer Records

Hackers breached databases hosted by a former Zara technology provider, exposing data belonging to 197,400 people according to Have I Been Pwned. The compromised data includes email addresses, geographic locations, purchases, and support tickets. Inditex, Zara's parent company, stated that attackers did not access names, phone numbers, addresses, credentials, or payment information. The ShinyHunters extortion gang claimed responsibility and leaked a 140GB archive allegedly stolen from BigQuery instances using compromised Anodot authentication tokens. The group told BleepingComputer they had stolen data from dozens of companies using the same method.

NVIDIA GeForce NOW Armenian Partner Breach

NVIDIA confirmed a data breach affecting GeForce NOW users in Armenia, caused by a compromise of infrastructure operated by regional partner GFN.am. The breach exposed full names, email addresses, usernames, dates of birth, and 2FA/TOTP status for users who registered between March 20 and 26. No account passwords were compromised. NVIDIA stated its own network was not impacted. The Armenian operator GFN.am also manages GeForce NOW operations in Azerbaijan, Georgia, Kazakhstan, Moldova, Ukraine, and Uzbekistan, but no impact on those countries has been confirmed. A threat actor using the ShinyHunters name claimed the breach and offered the database for $100,000, but this actor is believed to be an imposter.

AI Platform Braintrust Breach Exposes Customer API Keys

Braintrust, an AI evaluation and observability platform, urged customers to rotate API keys after hackers accessed an AWS account on May 4. The compromised internal AWS account likely provided attackers with access to org-level API keys that organizations use to access AI models from providers including OpenAI, Anthropic, and others. At least one customer was confirmed affected, with three others reporting suspicious spikes in AI provider usage. The company has not identified broader customer exposure but notified all org admins with stored AI provider secrets as a precaution.

Windows / AD Security

TCLBANKER Banking Trojan Spreads via WhatsApp and Outlook

Elastic Security Labs flagged TCLBANKER, a Brazilian banking trojan targeting 59 banking, fintech, and cryptocurrency platforms. The malware is a major update of the Maverick family and leverages DLL side-loading against a signed Logitech program (Logi AI Prompt Builder) to deploy a full-featured banking trojan and worm component. The loader includes comprehensive anti-analysis capabilities that detect sandboxes, debuggers, disassemblers, instrumentation tools, and antivirus software. It removes usermode hooks, disables Event Tracing for Windows telemetry, and only executes if the user's default language is Brazilian Portuguese. The banking trojan monitors browser URLs for financial institutions and establishes WebSocket connections to enable remote control, screen capture, keylogging, and fake overlay attacks. The worm module propagates via WhatsApp Web and Microsoft Outlook.

General Security News

Quasar Linux RAT Targets Developer Credentials for Supply Chain Attacks

Trend Micro uncovered Quasar Linux RAT (QLNX), a previously undocumented Linux implant targeting developers to steal credentials from .npmrc, .pypirc, .git-credentials, .aws/credentials, .kube/config, .docker/config.json, .vault-token, Terraform credentials, GitHub CLI tokens, and .env files. The malware executes filelessly from memory, masquerades as kernel threads (kworker, ksoftirqd), detects containerized environments, wipes system logs, and establishes persistence using systemd, crontab, and .bashrc injection. It supports 58 distinct commands including shell execution, file management, process injection, screenshots, keylogging, SOCKS proxies, TCP tunnels, and Beacon Object File execution. The malware includes a PAM inline-hook backdoor that intercepts plaintext credentials and a two-tiered rootkit architecture using LD_PRELOAD and eBPF to hide artifacts.

PamDOORa Linux Backdoor Advertised for $900

Flare.io detailed PamDOORa, a new Linux backdoor advertised on the Rehub Russian cybercrime forum by threat actor "darkworm" for $1,600 (reduced to $900 as of April 9). The PAM-based post-exploitation toolkit enables persistent SSH access via a magic password and specific TCP port combination while harvesting credentials from all legitimate users who authenticate through the compromised system. The backdoor incorporates anti-forensic capabilities to tamper with authentication logs and erase traces of malicious activity. There is no evidence of real-world deployment yet, but the reduced price suggests either lack of buyer interest or intent to accelerate sales.

SOC Alert Backlogs Hiding Real Threats

Analysis of 25 million security alerts across live enterprise environments found that nearly 1% of confirmed incidents originated from alerts initially classified as low-severity or informational. On endpoints specifically, that figure climbed to nearly 2%. At enterprise scale generating 450,000 alerts per year, this translates to approximately 54 real threats annually (one per week) that never get investigated under traditional SOC or MDR triage models. Of 82,000 alerts that underwent live forensic memory scans, 2,600 had active infections. Of those confirmed compromised endpoints, 51% had already been marked as "mitigated" by source EDR vendors. Malware families found running in memory included Mimikatz, Cobalt Strike, Meterpreter, and StrelaStealer.

Fake Android Call History Apps Steal $7.3M in Subscriptions

ESET discovered 28 fraudulent apps on Google Play Store that claimed to provide access to call histories, SMS records, and WhatsApp call logs for any phone number. The apps collectively racked up over 7.3 million downloads before removal, with one app alone accounting for over 3 million downloads. The scam, codenamed CallPhantom, primarily targeted users in India and the Asia-Pacific region. Victims were prompted to pay for access, but received only randomly generated fake data embedded in the app source code. At least one app was published under the developer name "Indian gov.in" to build false trust.

Patch Priority

Vulnerability Disclosures

cPanel and WHM Patch Three Vulnerabilities

cPanel released updates addressing three vulnerabilities in cPanel and Web Host Manager that could lead to privilege escalation, code execution, and denial-of-service. CVE-2026-29201 (CVSS 4.3) is an insufficient input validation allowing arbitrary file read. CVE-2026-29202 (CVSS 8.8) allows arbitrary Perl code execution via the create_user API. CVE-2026-29203 (CVSS 8.8) is an unsafe symlink handling vulnerability allowing chmod modification of arbitrary files. Patches are available in versions 11.136.0.9 and higher across multiple branches. While no evidence of in-the-wild exploitation exists, the disclosure comes days after CVE-2026-41940 was weaponized as a zero-day to deliver Mirai botnets and Sorry ransomware.

Trends & Context

Three significant patterns emerge from today's threat landscape. First, the exploitation timeline continues to compress: Palo Alto's CVE-2026-0300 and Ivanti's CVE-2026-6973 both reached active exploitation as zero-days, with federal remediation deadlines measured in days rather than weeks. Second, Linux systems face escalating post-compromise risk from Dirty Frag privilege escalation (public exploit, no patches), QLNX developer credential theft, and PamDOORa PAM backdoors, all targeting the supply chain through developer access. Third, cloud and SaaS security incidents (Zara via Anodot tokens, Braintrust AI keys, Instructure Canvas Free-For-Teacher accounts) demonstrate that third-party provider compromises create cascading breach risk across customer bases. Organizations relying on "secure by default" cloud services need credential rotation procedures and supply chain security reviews.