← Carolina Clear Tech

Cyber Threat Brief

2026-05-19

Listen to this brief (24:30)

Download MP3
Show Notes

Show Notes - 2026-05-19

Stories Covered

CVEs Referenced

CVE-2026-20127, CVE-2026-20182, CVE-2026-26083, CVE-2026-34260, CVE-2026-34263, CVE-2026-41702, CVE-2026-42231, CVE-2026-42232, CVE-2026-42822, CVE-2026-42897, CVE-2026-44277, CVE-2026-44791, CVE-2026-45321, CVE-2026-8043

Indicators of Compromise

Domains: m-kosche[.]com, mlcrosoft[.]co

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - 2026-05-19

Today: Microsoft Exchange zero-day CVE-2026-42897 is under active attack with no patch available. The TeamPCP supply chain campaign hit peak intensity with Mini Shai-Hulud worming through 170+ npm and PyPI packages including TanStack's 12 million weekly download ecosystem, compromising Checkmarx Jenkins plugins and GitHub Actions workflows. A CISA contractor leaked AWS GovCloud credentials and internal system passwords in a public GitHub repository.

Critical Alerts

Microsoft Exchange Zero-Day Under Attack (CVE-2026-42897)

Microsoft disclosed CVE-2026-42897, an actively exploited cross-site scripting (XSS) vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. CISA added it to the KEV catalog on May 16 with a May 29 remediation deadline. EPSS score is 0.123 (94th percentile). Microsoft assigned CVSS 8.1, NIST assigned 6.1. An attacker can send a crafted email that executes arbitrary JavaScript in Outlook Web Access, leading to mailbox compromise, session token theft, and unauthorized mailbox configuration changes. The risk is not server compromise but mailbox-level access that can enable BEC or ransomware initial access. Four days after disclosure, no patch is available.

Cisco SD-WAN Controller Under Exploitation (CVE-2026-20182)

UAT-8616, the same threat actor behind CVE-2026-20127 exploitation earlier this year, is now exploiting CVE-2026-20182, a critical authentication bypass in Cisco Catalyst SD-WAN Controller. CISA added CVE-2026-20182 to the KEV catalog on May 17 with EPSS 0.259 (96th percentile). Post-compromise activity includes SSH key additions, NETCONF configuration modifications, and privilege escalation to root. SD-WAN controllers are high-value targets for nation-state pre-positioning because they sit in the middle of trust relationships and provide persistent access that blends into normal administrative activity.

Ivanti Xtraction RCE (CVE-2026-8043)

Ivanti Xtraction versions before 2026.2 contain a critical external file name control vulnerability (CVSS 9.6) allowing remote authenticated attackers to read sensitive files and write arbitrary HTML to web directories, leading to information disclosure and client-side attacks.

Ransomware & Extortion

TeamPCP Supply Chain Campaign Reaches Peak Intensity

The TeamPCP campaign produced its loudest week since the March Trivy disclosure. Checkmarx officially confirmed its Jenkins AST plugin was trojanized (version 2026.5.09) with a 31-hour exposure window from May 9 01:25 UTC to May 10 08:47 UTC. This is Checkmarx's third compromise in three months. The malicious plugin was installed by several hundred Jenkins controllers. Remediated builds are 2.0.13-848.v76e89de8a_053 and 2.0.13-847.v08c0072b_2fd5. Last known-good build is 2.0.13-829.vc72453fa_1c16 from December 2025.

The Mini Shai-Hulud worm published 639 malicious versions across 323 unique packages starting May 11 at 19:20 UTC. The worm poisoned 84 npm artifacts across 42 @tanstack packages in six minutes, including @tanstack/react-router with 12 million weekly downloads. It then propagated to Mistral AI, UiPath, OpenSearch, Guardrails AI, and roughly 170 packages across npm and PyPI with combined cumulative downloads above 500 million. The worm harvests 20+ credential types (AWS, GCP, Azure, GitHub, npm, SSH, Kubernetes, Vault, Stripe, database connection strings) and attempts Docker container escape via host socket. Exfiltration goes to t.m-kosche[.]com:443. A reported operator error limits the harvest from @uipath and @mistralai variants because the payload is reassembled incorrectly there.

This is the first documented npm supply chain attack shipping with valid SLSA Build Level 3 provenance, demonstrating that supply chain security attestations can be weaponized. CVE-2026-45321 (CVSS 9.6) was assigned. The worm includes a 1-in-6 disk-wipe payload on Israeli and Iranian locale hosts. NHS England issued the campaign's first government alert. CISA has not issued guidance.

The worm uses stolen npm tokens to validate, enumerate packages, download tarballs, inject payload, add preinstall hooks, increase versions, and republish using the compromised maintainer's identity. 630 of 637 malicious versions also inject optionalDependencies entries pointing to imposter commits that deliver a second payload copy via the legitimate antvis/G2 GitHub repository. The attack also compromised GitHub Actions workflows actions-cool/issues-helper and actions-cool/maintain-one-comment. All tags in both repositories now point to imposter commits containing malicious code that exfiltrates credentials to t.m-kosche[.]com (the same domain as @antv compromise). Only workflows pinned to known-good full commit SHAs are unaffected.

The @antv compromise affected packages tied to npm maintainer account "atool", including echarts-for-react (1.1 million weekly downloads), @antv/g2, @antv/g6, @antv/x6, @antv/l7, @antv/s2, @antv/f2, @antv/g, @antv/g2plot, @antv/graphin, @antv/data-set, timeago.js, size-sensor, and canvas-nest.js. The attacker published 558 versions across 279 unique @antv packages. The stealer harvests 20+ credential types and exfiltrates to t.m-kosche[.]com:443. The malware creates GitHub repositories with the description "niagA oG eW ereH :duluH-iahS" (reverses to "Shai-Hulud: Here We Go Again"). Over 2,500 such repositories exist in GitHub, providing a lower bound on the number of unique compromised CI/CD environments.

Business & Infrastructure Threats

CISA Contractor Leaked AWS GovCloud Keys on GitHub

A CISA contractor maintained a public GitHub repository named "Private-CISA" that exposed credentials to multiple highly privileged AWS GovCloud accounts and internal CISA systems. The repository contained a file "importantAWStokens" with administrative credentials to three AWS GovCloud servers, and "AWS-Workspace-Firefox-Passwords.csv" with plaintext usernames and passwords for dozens of internal CISA systems including LZ-DSO (Landing Zone DevSecOps), the agency's secure code development environment. The repository also contained plaintext credentials to CISA's internal artifactory, a prime target for backdooring software packages that would deploy across CISA infrastructure with every new build. The commit logs show the CISA administrator disabled GitHub's default secret detection feature. GitGuardian detected the exposure and contacted the contractor, who did not respond. The repository was public until May 15. Security experts described this as one of the most egregious government data leaks in recent history.

Threat Actors Disabling Antivirus and EDR

Huntress reports threat actors are moving beyond evasion to actively disabling endpoint security tools. Common methods include blocking EDR communications via Windows Firewall rules or Windows Filtering Platform (WFP) to create hidden firewall rules that silence EDR agents while leaving them running locally. Attackers also escalate privileges to uninstall agents directly, or use Bring Your Own Vulnerable Driver (BYOVD) techniques to load legitimate signed drivers with known vulnerabilities into the kernel, then exploit the driver to gain kernel-mode access and terminate protected EDR processes. Huntress observes attackers abusing Microsoft Defender Antivirus exclusions to exclude entire C: and C:\Windows drives, and using rogue RMM tools to uninstall EDR from the command line. BYOVD is described as the new "gold standard" for EDR impairment.

Developer Workstations Are Part of the Software Supply Chain

Recent supply chain attacks (TeamPCP, Shai-Hulud) target developer workstations to steal credentials, API keys, cloud credentials, SSH keys, npm tokens, and environment variables. Developer workstations concentrate context: local repositories, .env files, shell history, SSH keys, package manager credentials, build scripts, debugging logs, and browser sessions. A single access token found next to a Git remote, deployment script, README, cloud profile, and CI configuration tells an attacker where the token fits and what it might unlock. In the Shai-Hulud 2.0 campaign, GitHub credentials dominated the exposed and exfiltrated credentials, each with potential admin access to repositories and CI workflows. Developer machines concentrate software delivery authority, making local compromise a map for source control, cloud accounts, package publishing workflows, CI/CD systems, internal APIs, and production-adjacent infrastructure.

Windows / AD Security

Storm-2949 Turned Compromised Identity into Cloud-Wide Breach

Microsoft Threat Intelligence documented Storm-2949, a threat actor that launched a methodical attack to exfiltrate data from Microsoft 365 applications, file-hosting services, and Azure-hosted production environments. The attack began with targeted social engineering leveraging Microsoft's Self-Service Password Reset (SSPR) process. The threat actor initiated SSPR on behalf of a targeted user and used social engineering (impersonating IT support) to persuade the user to approve MFA prompts. Once the user approved, the threat actor reset the password, removed existing authentication methods (phone numbers, email addresses, Microsoft Authenticator registrations), and enrolled Microsoft Authenticator on their own device for persistent access. Storm-2949 did not rely on traditional malware. They leveraged legitimate cloud and Azure management features to gain control-plane and data-plane access, execute code remotely on VMs, and access Key Vaults and storage accounts. The attack exfiltrated data from Microsoft 365 applications, file-hosting services, and Azure-hosted production environments.

BitLocker Zero-Day Exploit (YellowKey)

Researcher Nightmare-Eclipse published YellowKey, a zero-day exploit that reliably bypasses default Windows 11 BitLocker deployments. The exploit targets the decryption key stored in the Trusted Platform Module (TPM). The exploit requires physical access to the computer.

General Security News

macOS Stealer SHub Reaper Spoofs Apple, Google, and Microsoft

SentinelOne documented a new SHub Stealer variant named "Reaper" targeting macOS. The malware uses fake WeChat and Miro installers as lures. The infection chain shifts its disguise at each stage: payload hosted on typo-squatted Microsoft domain (mlcrosoft[.]co[.]com), executed under the guise of an Apple security update, and persists from a fake Google Software Update directory. Reaper leverages the applescript:// URL scheme to launch macOS Script Editor pre-populated with malicious payload, bypassing Terminal entirely and sidestepping Apple's Tahoe 26.4 mitigation for ClickFix attacks. The malware checks victim locale settings for Russian input sources and exits if detected (CIS region exclusion). Reaper profiles visitors with JavaScript that collects IP address, location, WebGL fingerprinting, VM/VPN indicators, and installed browser extensions (password managers like 1Password, Bitwarden, LastPass, and cryptocurrency wallets like MetaMask, Phantom). The malware exfiltrates credentials, steals documents with chunked uploads, and sends telemetry to operators via Telegram bot. The pages interfere with analysis by overriding console functions, intercepting F12 keystrokes, and running a continuous debugger loop.

Microsoft Security Focus on Small Business

Microsoft published guidance for small business cybersecurity during National Small Business Month. Microsoft now processes 100+ trillion security signals daily and blocks 4.5 million new malware files daily. AI-automated phishing is 4.5 times more effective than traditional attacks. Most modern attacks target identities (user accounts and access). Microsoft recommends Microsoft 365 Business Premium as integrated productivity and security solution for small businesses with centralized visibility and automation. Microsoft emphasizes security as foundation of trust and business resilience.

Patch Priority

Vulnerability Disclosures

Fortinet Critical RCE Vulnerabilities

Fortinet released fixes for two critical flaws: CVE-2026-44277 (CVSS 9.1) in FortiAuthenticator allowing unauthenticated code execution via crafted requests (fixed in 6.5.7, 6.6.9, 8.0.3), and CVE-2026-26083 (CVSS 9.1) in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS allowing unauthenticated code execution via HTTP requests (fixed in FortiSandbox 4.4.9 and 5.0.2, FortiSandbox Cloud 5.0.6, FortiSandbox PaaS 4.4.9 and 5.0.2).

SAP Critical SQL Injection and Authentication Bypass

SAP shipped fixes for CVE-2026-34260 (CVSS 9.6), an SQL injection vulnerability in SAP S/4HANA allowing low-privileged authenticated attackers to inject malicious SQL code and expose sensitive database information. The vulnerability only allows read access, so integrity is not compromised. SAP also fixed CVE-2026-34263 (CVSS 9.6), a missing authentication check in SAP Commerce cloud configuration caused by overly permissive security configuration with improper rule ordering. An unauthenticated attacker can perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution.

VMware Fusion Privilege Escalation (CVE-2026-41702)

Broadcom patched CVE-2026-41702 (CVSS 7.8), a TOCTOU (Time-of-check Time-of-use) vulnerability in VMware Fusion that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges can exploit this to escalate privileges to root on the system where Fusion is installed. Fixed in VMware Fusion version 26H1.

n8n Critical Prototype Pollution and RCE

n8n released fixes for five critical vulnerabilities: CVE-2026-42231 and CVE-2026-42232 (both CVSS 9.4) allowing authenticated users with workflow permissions to achieve remote code execution via prototype pollution in the xml2js library and XML Node respectively. CVE-2026-44791 (CVSS 9.4) is a bypass for CVE-2026-42232 that also results in RCE. Fixed in n8n versions 1.123.32, 2.17.4, and 2.18.1.

Azure Local Disconnected Operations Privilege Escalation (CVE-2026-42822)

Microsoft disclosed CVE-2026-42822, an improper authentication vulnerability in Azure Local Disconnected Operations (ALDO) that allows an unauthorized attacker to elevate privileges over a network.

Trends & Context

Supply chain attacks have matured from isolated incidents to automated, self-propagating worm campaigns with valid security attestations. The Mini Shai-Hulud campaign demonstrates that SLSA Build Level 3 provenance can be weaponized, undermining trust in supply chain security frameworks. The TeamPCP campaign's rapid escalation (Checkmarx Jenkins plugins, TanStack npm packages, GitHub Actions workflows, and 170+ packages in 48 hours) shows attackers are targeting the trust relationships in software delivery pipelines rather than individual vulnerabilities. Developer workstations have become high-value targets because they concentrate credentials and context that map to production infrastructure. Identity compromise is now the primary vector for cloud breaches, with legitimate administrative features replacing traditional malware for lateral movement and data exfiltration.