← Carolina Clear Tech

Cyber Threat Brief

2026-05-12

Listen to this brief (17:29)

Download MP3
Show Notes

Show Notes - 2026-05-12

Stories Covered

CVEs Referenced

CVE-2022-26923, CVE-2026-43284, CVE-2026-43500, CVE-2026-45321

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - May 12, 2026

Today: Linux systems face a second privilege escalation exploit in two weeks with Dirty Frag working reliably across all distributions. TeamPCP compromised Checkmarx's Jenkins plugin days after their last breach. Instructure paid ransomware extortionists to stop the leak of 3.6TB from Canvas, ending a crisis that disrupted K-12 and university access nationwide.

Critical Alerts

Linux Dirty Frag Vulnerability (CVE-2026-43284, CVE-2026-43500)

Two vulnerabilities allow low-privilege users and untrusted containers to gain root access on Linux systems. Exploit code works reliably across all distributions with no crashes and leaves minimal detection footprint. Microsoft reports signs of in-the-wild exploitation. This is the second severe Linux privilege escalation in two weeks, following Copy Fail which remains unpatched for end users. The exploit chains CVE-2026-43284 and CVE-2026-43500 together, and both vulnerabilities have EPSS scores of 0.000 (1-2nd percentile), meaning automated scanners are not yet prioritizing them.

Active Directory Certificate Services Exploitation

Palo Alto Unit 42 analysis reveals AD CS remains a high-impact attack vector despite years of awareness. Adversaries misuse certificate templates and shadow credentials for privilege escalation and persistence without relying on zero-days or malware. Ransomware groups and state-sponsored actors actively exploit insecure default configurations. CVE-2022-26923 is on CISA KEV (due date September 8, 2022) with EPSS 0.914 (100th percentile), indicating extremely high exploitation likelihood.

Ransomware Claims (Last 48h)

1 claim tracked across 1 group in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Group Victim Sector Country
Money Message Forestdale Unknown Unknown

Ransomware & Extortion

Instructure Pays Ransom to ShinyHunters

Instructure reached an "agreement" with ShinyHunters to prevent the leak of 3.6TB of data stolen from Canvas LMS, used by 30 million educators and students across 8,000 schools. ShinyHunters exploited XSS vulnerabilities in the Free-for-Teacher environment to obtain admin sessions and exfiltrate usernames, email addresses, course names, enrollment information, and messages. After initial intrusion, attackers returned on May 7 using the same vulnerability to deface login portals and inject extortion messages targeting 330 institutions. Instructure says the threat actor confirmed no customers will be extorted and provided shred logs confirming data destruction. This is ShinyHunters' second Instructure breach in nine months.

The Gentlemen Ransomware Group Suffers Data Breach

The Gentlemen, a ransomware-as-a-service group active since mid-2025, is experiencing internal correspondence leaked online through a breach of their own operations. Details are limited but the incident highlights ongoing drama and instability within the cybercrime ecosystem.

State of Ransomware in 2026

Kaspersky reports ransomware attacks declined in 2025 across all regions, but the threat remains adaptive and persistent. Key trends: new families adopting post-quantum cryptography (PE32 ransomware using ML-KEM/Kyber1024), increasing use of EDR killers and BYOVD techniques to neutralize endpoint defenses before encryption, and a shift toward encryptionless extortion as ransom payment rates drop to 28%. Manufacturing sector alone lost over $18 billion in the first three quarters. Initial access brokers focus on RDWeb as preferred remote access method.

Business & Infrastructure Threats

Checkmarx Jenkins Plugin Compromised by TeamPCP

TeamPCP published a malicious version (2026.5.09) of the Checkmarx Jenkins AST plugin to the Jenkins Marketplace using credentials stolen from the March Trivy supply chain attack. The rogue plugin contains credential-stealing malware targeting CI/CD environments. Checkmarx confirms users should verify they are running version 2.0.13-829.vc72453fa_1c16 from December 17, 2025, or the new clean release 2.0.13-848.v76e89de8a_053. This is TeamPCP's third attack against Checkmarx in two months. The group defaced the GitHub repository with the message "Checkmarx fails to rotate secrets again."

Mini Shai-Hulud Worm Spreads Across npm and PyPI

TeamPCP launched a fresh Mini Shai-Hulud campaign compromising TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI packages. The npm worm exploits GitHub Actions via pull_request_target trigger, cache poisoning, and OIDC token extraction to publish malicious packages with valid SLSA Build Level 3 provenance attestations. Affected packages include [email protected], [email protected], @opensearch-project/[email protected], and 42 TanStack packages across 84 versions. The malware targets cloud providers, crypto wallets, AI tools, messaging apps, and CI systems. TanStack traced the compromise to a chained GitHub Actions attack (CVE-2026-45321, CVSS 9.6). The worm spreads by locating npm tokens with bypass_2fa enabled and publishing to all packages by the same maintainer.

GhostLock Tool Abuses Windows API for File Access Denial

Security researcher Kim Dvash released GhostLock, a proof-of-concept tool demonstrating how the Windows CreateFileW API can be abused to block access to files on local and SMB shares. The technique opens files with exclusive access (dwShareMode = 0), preventing other users and applications from accessing them until handles are closed. Standard domain users can launch the attack without elevated privileges. Multiple simultaneous attackers can compound the effect. The attack generates legitimate file open requests, evading EDR and behavioral detection systems that focus on mass file writes or encryption. Detection requires per-session open-file count monitoring with ShareAccess = 0 at the file server layer, a metric not captured in Windows event logs or standard EDR telemetry.

FleetWave Data Breach Confirmed

Chevin confirmed attackers accessed customer data in the FleetWave SaaS outage disclosed in April. One month after bringing systems back online, the company notified customers that operational data, contact details, and payroll numbers were potentially exfiltrated during the breach.

State-Sponsored Actors: Long-Term Covert Access

Cisco Talos analysis explains why responding to state-sponsored intrusions differs fundamentally from ransomware response. State actors log in with valid credentials, operate inside the trust boundary using trusted tools, and pursue espionage or long-term positioning rather than immediate ransom. Standard incident response playbooks designed for malware containment and ransomware recovery are inadequate. State actors conduct prolonged reconnaissance, exploit trusted vendor relationships, and maintain persistence for months without triggering alarms. Zero trust architecture becomes essential when adversaries operate with authorized access.

Patch Priority

Vulnerability Disclosures

FCC Extends Foreign Router Support Deadline

The FCC softened its March 2026 ban on foreign-made consumer routers by extending the support deadline from March 2027 to January 2029 and expanding permissible updates beyond minor security patches. The original ruling prohibited new sales but raised concerns about leaving deployed devices unpatched. The revision allows vendors to provide major software and firmware updates affecting functionality without additional FCC review. Security professionals note the ban addresses the wrong problem, as router security risks stem from default passwords, poor configurations, and lack of patching rather than manufacturing origin.

OpenAI Launches Daybreak AI Security Platform

OpenAI launched Daybreak, combining GPT-5.5 models with Codex Security to identify and patch vulnerabilities before attackers exploit them. The platform builds editable threat models, identifies and tests vulnerabilities in isolated environments, and proposes fixes. Three models power the effort: GPT-5.5 (general purpose with standard safeguards), GPT-5.5 with Trusted Access for Cyber (for verified defensive work), and GPT-5.5-Cyber (permissive model for red teaming and penetration testing). Major companies including Akamai, Cisco, Cloudflare, CrowdStrike, Fortinet, Oracle, Palo Alto Networks, and Zscaler are integrating these capabilities. The initiative addresses the remediation bottleneck as AI-assisted research accelerates vulnerability discovery faster than patching can keep pace.

CrowdStrike Automated Leads: AI-Powered Threat Detection

CrowdStrike detailed Automated Leads, an AI-driven threat detection system powered by CrowdStrike Signal that surfaces subtle attack signs before they become breaches. The system shifts from individual alerts to entity-based scoring, assigning scores to every indicator and detection event, then correlating them by endpoint. When multiple positive events occur on the same host, scores are summed to identify threats that would be lost in noise. New capability isolates unusual processes and anomalous RMM tool usage. The approach addresses the limitation where "noisy" rules are suppressed due to high volume, allowing malicious activity to slip through.

General Security News

GM Settles California CCPA Violation for $12.75M

California Attorney General settled with General Motors for $12.75 million over allegations the company violated CCPA by collecting and selling driver behavior and location data to Verisk Analytics and LexisNexis between 2020 and 2024. Data was collected through OnStar's Smart Driver system without proper consent and retained longer than necessary. GM made $20 million nationwide from the sales. The settlement is California's largest CCPA penalty and first enforcement focused on data minimization rules. GM must stop selling driving data for five years, delete retained data within 180 days unless consumers consent, request data deletion from Verisk and LexisNexis, and implement a stronger privacy compliance program. California drivers unlikely to face insurance premium impacts due to state law prohibiting use of driving data to set rates.

Apple and Google Launch Cross-Platform E2EE RCS

iOS 26.5 and Google Messages now support end-to-end encrypted RCS messaging between iPhone and Android by default for all conversations. The feature enables high-resolution media, typing indicators, and read receipts between platforms while protecting message content in transit. A lock icon indicates encrypted conversations. The capability is the result of cross-industry collaboration through the GSMA RCS Working Group. iOS 26.5 also patches over 50 vulnerabilities including flaws in AppleJPEG, ImageIO, Kernel, mDNSResponder, and WebKit that could lead to information disclosure, denial-of-service, or unexpected system termination.

DOJ Charges Premium Home Service with Fake Review Scheme

The Department of Justice filed a civil complaint against B.E.S.T. GDR LLC (doing business as Premium Home Service) and CEO Yosef Bernath for creating over 15,000 fake Google Search and Maps business profiles with fabricated local identities, brick-and-mortar addresses belonging to unrelated businesses, and phone numbers routing to overseas call centers. The defendants posted fake consumer reviews using stolen staff photos from unrelated websites. The company collected fees claiming to be a local provider but referred work to third-party contractors who often lacked qualifications, performed substandard work, arrived late, or failed to appear. The complaint alleges violations of the FTC Act, FTC Rule on Consumer Reviews and Testimonials, Illinois Consumer Fraud and Deceptive Business Practices Act, and Gramm-Leach-Bliley Act for obtaining payment card numbers through false statements.

Fake Claude Code Installers Deliver Credential Stealers

Attackers are distributing fake Claude Code installers that deliver cookie-stealing malware targeting developer secrets and session credentials. The campaign represents a growing threat to development environments as AI coding assistants gain popularity.

Trends & Context

Supply chain attacks dominate the threat landscape this week with TeamPCP maintaining persistent access to Checkmarx systems despite remediation efforts and launching a sophisticated npm worm with valid SLSA attestations. The pattern suggests incomplete credential rotation and missed footholds during incident response. Linux privilege escalation vulnerabilities arriving back-to-back highlight a concerning trend of severe kernel flaws with reliable exploits reaching public disclosure before patches reach end users. The education sector faces sustained targeting, with both Canvas and previous FleetWave breaches exposing millions of student and staff records.