CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20133, CVE-2026-20182, CVE-2026-40460, CVE-2026-42897, CVE-2026-43490, CVE-2026-44112, CVE-2026-44113, CVE-2026-44115, CVE-2026-44118, CVE-2026-44431, CVE-2026-44662, CVE-2026-44673, CVE-2026-46333, CVE-2026-4782, CVE-2026-4798, CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6637, CVE-2026-6638
Domains:
enrollms[.]com, passkeyms[.]com, setupsso[.]com, setupsso[.]com., sh[.]azurestaticprovider, bt[.]node, azurestaticprovider[.]net, node[.]js, analytics-reports[.]com, protect-wss[.]com
IP Addresses:
3.15.0.3
Get tomorrow's brief in your inbox
2026-05-16
Today: Cisco drops its seventh SD-WAN zero-day in three months as attackers exploit a CVSS 10 authentication bypass for immediate admin access. Microsoft patches an Exchange Server zero-day (CVE-2026-42897) exploited in the wild via malicious emails targeting Outlook Web Access. Multiple supply chain attacks hit node-ipc npm package and TanStack, with OpenAI confirming credential theft from two employee devices.
Cisco SD-WAN Authentication Bypass Zero-Day (CVE-2026-20182)
Cisco disclosed a max-severity authentication bypass vulnerability in Catalyst SD-WAN Controller and Manager under active exploitation by the persistent threat group UAT-8616. The flaw has a CVSS rating of 10 and allows attackers to present themselves as trusted network routers and gain the highest level of administrative access without credentials. Rapid7 discovered and reported the vulnerability on March 9, and Cisco confirmed limited exploitation earlier this month. UAT-8616 has exploited at least three separate zero-days in Cisco's network edge software for multiple years before discovery. CISA added CVE-2026-20182 to the KEV catalog with a due date of 2026-05-17 (EPSS: 0.016, 82nd percentile).
Microsoft Exchange Server Zero-Day (CVE-2026-42897)
Microsoft disclosed a cross-site scripting and spoofing vulnerability in Exchange Server Subscription Edition, 2016, and 2019 that is being exploited in the wild. Attackers send specially crafted emails to target Outlook Web Access users. If the user opens the email in OWA and certain interaction conditions are met, arbitrary JavaScript executes in the browser context. Microsoft has not shared details about the attacks exploiting this vulnerability, but an anonymous researcher reported it. CISA added CVE-2026-42897 to the KEV catalog with a due date of 2026-05-29 (EPSS: 0.002, 44th percentile).
BlackFile (UNC6671) Targets Microsoft 365 and Okta via Vishing
Google Threat Intelligence Group published detailed analysis of UNC6671, a threat actor operating under the "BlackFile" brand, targeting organizations via sophisticated voice phishing and SSO compromise. The group uses adversary-in-the-middle techniques to bypass MFA, targeting Microsoft 365 and Okta infrastructure. UNC6671 leverages Python and PowerShell scripts to programmatically exfiltrate sensitive corporate data from SaaS environments. Attackers call employees' personal cellular phones posing as IT help desk personnel, directing victims to credential harvesting sites with themes like enrollms[.]com, passkeyms[.]com, and setupsso[.]com (Tucows registered). The group maintains a dedicated "BlackFile" data leak site and has targeted dozens of organizations across North America, Australia, and the UK since early 2026. UNC6671 operations are distinct from ShinyHunters (UNC6240) despite co-opting the brand in at least one instance.
node-ipc npm Package Compromised with Credential Stealer
Hackers injected credential-stealing malware into three newly published versions of node-ipc, a popular inter-process communication package with 690,000 weekly downloads. The compromised versions (9.1.6, 9.2.3, 12.0.1) contain heavily obfuscated malware that fingerprints infected systems, collects environment variables and sensitive files, compresses stolen data, and exfiltrates it through DNS TXT queries. The attacker compromised the account of an inactive maintainer named atiertant. The malware targets cloud credentials (AWS, Azure, GCP, OCI, DigitalOcean), SSH keys, Kubernetes/Docker/Helm/Terraform credentials, npm/GitHub/GitLab tokens, .env files, database credentials, shell histories, CI/CD secrets, macOS Keychain files, Linux keyrings, Firefox profiles, and Microsoft Teams local storage. Exfiltration uses a fake Azure-themed domain (sh[.]azurestaticprovider[.]net:443) with DNS TXT requests to bt[.]node[.]js. A 500 KB compressed archive generates approximately 29,400 DNS TXT requests.
OpenClaw Vulnerabilities Allow Data Theft and Privilege Escalation
Cyera disclosed four security flaws in OpenClaw (tracked as Claw Chain) that can be chained to achieve data theft, privilege escalation, and persistence. CVE-2026-44112 (CVSS 9.6/6.3) is a TOCTOU race condition in OpenShell that allows bypassing sandbox restrictions and redirecting writes outside the intended mount root. CVE-2026-44113 (CVSS 7.7/6.3) is a similar TOCTOU race condition allowing file reads outside the mount root. CVE-2026-44115 (CVSS 8.8) is an incomplete list of disallowed inputs allowing attackers to bypass allowlist validation using shell expansion tokens in heredoc bodies. CVE-2026-44118 (CVSS 7.8) is an improper access control vulnerability allowing non-owner loopback clients to impersonate an owner and gain control over gateway configuration, cron scheduling, and execution environment management. The root cause stems from OpenClaw trusting a client-controlled ownership flag (senderIsOwner) without validating it against the authenticated session.
TanStack Supply Chain Attack Hits OpenAI
OpenAI disclosed that two employee devices were impacted by the Mini Shai-Hulud supply chain attack on TanStack, resulting in credential exfiltration from internal source code repositories. The TeamPCP hacking group exploited security weaknesses in the package publishing process on May 11 to release 84 malicious artifacts across 42 packages. Over 170 packages across NPM and PyPI namespaces were compromised in a coordinated campaign. OpenAI confirmed limited credential material was successfully exfiltrated from code repositories to which the two impacted employees had access, but no user data, production systems, or intellectual property were compromised. The compromised repositories contained code-signing certificates for iOS, macOS, Windows, and Android products. OpenAI is revoking the certificates and re-signing all applications. macOS users must update their applications by June 12, 2026.
Pwn2Own Berlin 2026: Microsoft Exchange, Windows 11 Hacked
On day two of Pwn2Own Berlin 2026, competitors collected $385,750 after exploiting 15 unique zero-day vulnerabilities in Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux. Orange Tsai of DEVCORE earned $200,000 by chaining three bugs for remote code execution with SYSTEM privileges on Microsoft Exchange. Siyeon Wi exploited an integer overflow to hack Windows 11 ($7,500), Ben Koo escalated privileges to root on Red Hat Enterprise Linux ($10,000), and multiple teams hacked AI coding agents including Cursor and OpenAI Codex. On day one, Orange Tsai earned $175,000 for a Microsoft Edge sandbox escape using four logic bugs, and three separate teams demonstrated Windows 11 privilege-escalation zero-days (each earning $30,000). Vendors have 90 days to patch disclosed vulnerabilities.
REMUS Infostealer Malware-as-a-Service Operation
Flare researchers analyzed 128 posts from the REMUS underground operation between February 12 and May 8, 2026, revealing a rapid evolution of an infostealer malware marketed as MaaS. The operation focuses on commercialization, operational scalability, session theft, and password-manager targeting. February 2026 marked the initial commercial push with claims of ~90% callback rates with proper crypting. March 2026 represented the most active development period, introducing restore-token functionality, worker tracking, statistics pages, and duplicate-log filtering. April 2026 showed a move toward session continuity and browser-side authentication artifacts, including IndexedDB collection for 1Password and LastPass extensions, Bitwarden-related searches, and SOCKS5 proxy support. By May 2026, the operation focused on refinement and operational stability.
AI Agents Used to Discover and Exploit Zero-Days
Google Threat Intelligence Group revealed a coordinated campaign exploiting an AI-generated zero-day vulnerability targeting an unnamed open-source web administration tool to bypass 2FA. Researchers identified an active threat actor using large language models to discover and weaponize software vulnerabilities in the wild. The targeted flaw involves a high-level semantic logic bug stemming from a hard-coded trust assumption, matching bug classes LLMs excel at identifying. The Python exploit script was assessed with high confidence to be AI-generated based on educational docstrings, textbook structure, and telltale hallucinations including a fabricated CVSS score. State-sponsored actors from China and North Korea show increasing interest in using LLMs for continuous vulnerability discovery and exploit development. Russia-linked adversaries use AI to generate decoy code that obfuscates malware like CANFAIL and LONGSTREAM and deploy advanced voice cloning for social engineering. The Android backdoor PromptSpy integrates with Gemini APIs to bypass LLM safety features and autonomously replay device authentication patterns.
Microsoft Edge to Stop Loading Passwords into Memory on Startup
Microsoft announced that future versions of Edge will no longer load saved passwords into process memory in cleartext on startup, reversing its initial position that the behavior was "by design." Security researcher Tom Jøran Sønstebyseter Rønning disclosed on May 4 that all credentials stored in Edge's built-in password manager were decrypted on launch and kept in memory even when not in use. Rønning released a proof-of-concept tool allowing attackers with Administrator privileges to dump passwords from other users' Edge processes. Edge was the only Chromium-based browser with this behavior. The fix is already live in Edge Canary and will be included in the next update for all supported Edge releases (build 148 and newer).
WordPress Avada Builder Plugin Flaws
Two vulnerabilities in Avada Builder plugin for WordPress (1 million active installations) allow hackers to read arbitrary files and extract sensitive database information. CVE-2026-4782 affects all versions through 3.15.2 and allows authenticated users with subscriber-level access to read any file on the server via the custom_svg parameter. CVE-2026-4798 affects versions through 3.15.1 and is a time-based blind SQL injection exploitable by unauthenticated attackers if WooCommerce was enabled and then deactivated. Both flaws can lead to extraction of wp-config.php database credentials and cryptographic keys. Partial fix version 3.15.2 released April 13, fully patched version 3.15.3 released May 12.
WordPress Funnel Builder Plugin Exploited for Credit Card Theft
A critical vulnerability in Funnel Builder plugin for WordPress (40,000+ active installations) is being actively exploited to inject malicious JavaScript into WooCommerce checkout pages. The flaw affects all versions before 3.15.0.3 and allows unauthenticated attackers to modify global settings via an unprotected, publicly exposed checkout endpoint. Attackers inject arbitrary JavaScript into the "External Scripts" setting, causing malicious code to execute on every checkout page. The attacker-controlled server delivers a customized payment card skimmer stealing credit card numbers, CVVs, billing addresses, and other customer information. The payload (analytics-reports[.]com/wss/jquery-lib.js) is disguised as fake Google Tag Manager/Google Analytics script and opens a WebSocket connection to wss://protect-wss[.]com/ws. FunnelKit addressed the vulnerability in version 3.15.0.3 released May 15.
PostgreSQL Multiple Vulnerabilities
Microsoft published multiple PostgreSQL CVEs including CVE-2026-6478 (MD5-hashed passwords via covert timing channel, EPSS 11th percentile), CVE-2026-6475 (pg_basebackup and pg_rewind can overwrite unrelated files, EPSS 14th percentile), CVE-2026-6473 (server undersizes allocations via integer wraparound, EPSS 20th percentile), CVE-2026-6638 (REFRESH PUBLICATION allows SQL injection via table name, EPSS 7th percentile), CVE-2026-6637 (refint allows stack buffer overflow and SQL injection, EPSS 12th percentile), CVE-2026-6477 (libpq lo_* functions let server superuser overwrite client stack memory, EPSS 12th percentile), CVE-2026-6474 (timeofday() can disclose portions of server memory, EPSS 8th percentile), CVE-2026-6472 (CREATE TYPE does not check multirange schema CREATE privilege, EPSS 7th percentile), and CVE-2026-6479 (SSL/GSS init causes DoS via uncontrolled recursion, EPSS 12th percentile).
Additional CVEs
CVE-2026-43490 (ksmbd: validate inherited ACE SID length, EPSS 5th percentile), CVE-2026-44673 (libyang: lyb_read_string() integer overflow to heap buffer overflow, EPSS 16th percentile), CVE-2026-40460 (NGINX ngx_quic_module vulnerability, EPSS 6th percentile), CVE-2026-44662 (rust-openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding, EPSS 3rd percentile), CVE-2026-44431 (urllib3: sensitive headers forwarded across origins in proxied low-level redirects, EPSS 9th percentile), CVE-2026-46333 (ptrace: slightly saner get_dumpable() logic).
Supply chain attacks continue to escalate with increasing sophistication. The node-ipc and TanStack compromises demonstrate that attackers are targeting package publishing infrastructure and maintainer accounts rather than exploiting vulnerabilities in the packages themselves. The use of DNS TXT queries for exfiltration in node-ipc shows operational security evolution to blend into normal DNS traffic. Cisco's seventh SD-WAN zero-day in three months highlights persistent targeting of network edge infrastructure by state-sponsored or advanced persistent threat groups. The exploitation window for CVE-2026-20127 was at least three years before discovery, and CVE-2026-20182 was discovered during research of the previous zero-day, indicating deeper systemic issues in SD-WAN security. AI-driven vulnerability discovery and exploit generation is transitioning from research to active exploitation, compressing patch windows from weeks to hours. Organizations must shift from reactive patching to preemptive attack surface reduction and assume obscurity no longer provides protection.