CVE-2008-4250, CVE-2009-1537, CVE-2009-3459, CVE-2010-0249, CVE-2010-0806, CVE-2024-12802, CVE-2026-29518, CVE-2026-32792, CVE-2026-33278, CVE-2026-40622, CVE-2026-41091, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42944, CVE-2026-42959, CVE-2026-42960, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-43970, CVE-2026-44390, CVE-2026-44608, CVE-2026-45232, CVE-2026-45498, CVE-2026-45736, CVE-2026-45803, CVE-2026-46333, CVE-2026-47784, CVE-2026-9082
Get tomorrow's brief in your inbox
2026-05-21
Today: Microsoft patched two actively exploited Defender zero-days that CISA added to KEV with a June 3 deadline. A fresh Mini Shai-Hulud supply chain attack compromised 320+ npm packages targeting CI/CD credentials, propagating through echarts-for-react with 1.1 million weekly downloads. SonicWall Gen6 VPN devices remain vulnerable to MFA bypass via CVE-2024-12802 even after firmware updates because manual LDAP reconfiguration was not completed, enabling ransomware group initial access.
Microsoft Defender Zero-Days (CVE-2026-41091, CVE-2026-45498)
Microsoft patched two Defender vulnerabilities exploited in the wild as zero-days. CVE-2026-41091 (CVSS 7.8) is a privilege escalation flaw in the Malware Protection Engine stemming from improper link resolution, allowing attackers to gain SYSTEM privileges. CVE-2026-45498 (CVSS 4.0) is a denial-of-service vulnerability in the Defender Antimalware Platform. Both flaws are variants of the publicly dropped BlueHammer exploit (RedSun and UnDefend). CISA added both CVEs to the KEV catalog on May 20 with a June 3 remediation deadline. Microsoft also added five legacy CVEs to KEV: CVE-2008-4250 (Windows RPC RCE, EPSS 93.5%), CVE-2009-1537 (DirectX NULL byte overwrite, EPSS 68.1%), CVE-2009-3459 (Adobe Acrobat heap overflow, EPSS 87.0%), CVE-2010-0249 and CVE-2010-0806 (IE use-after-free, EPSS 90.1% and 89.5%).
RaaS Ecosystem Tradecraft Analysis
RaaS operators provide ransomware infrastructure, leak sites, and negotiation support, but affiliates dictate intrusion tradecraft, initial access, and hands-on-keyboard activity. This means the same ransomware family like Akira, Qilin, or LockBit can appear across very different attack chains. Qilin's affiliate base includes Scattered Spider, Moonstone Sleet, and Devman, illustrating how one ransomware brand spans diverse intrusion styles and skill levels. Initial access vectors include RDP (weak credentials, enabled via SMB or MSSQL), vulnerable edge appliances (SonicWall VPNs before Akira deployment), and rogue RMMs (ScreenConnect, TeamViewer, Bomgar). In April 2026, attackers used compromised Bomgar to hit multiple organizations through a dental software company. Persistence methods include creating hidden user accounts (removed from RDP Welcome Screen), installing post-compromise RMMs like Chrome Remote Desktop, and establishing lateral movement via shared local admin passwords. Data exfiltration commonly uses Rclone, Mega, or direct C2 channels. Defense evasion includes disabling EDR via BYOVD techniques.
Microsoft Disrupts Fox Tempest Malware-Signing Service
Microsoft disrupted Fox Tempest, a malware-signing-as-a-service operation that weaponized Artifact Signing (formerly Azure Trusted Signing) to deliver ransomware and malware disguised as legitimate software. Fox Tempest generated short-lived (72-hour) fraudulent code-signing certificates using stolen identities from the US and Canada to pass identity validation. The service charged $5,000 to $9,000 and enabled deployment of Rhysida ransomware, Oyster loader, Lumma Stealer, and Vidar. Affiliates include Vanilla Tempest, INC, Qilin, BlackByte, and Akira. Starting February 2026, Fox Tempest shifted to providing pre-configured VMs hosted on Cloudzy for direct signing. Vanilla Tempest distributed signed binaries via malicious ads for Microsoft Teams, leading to Oyster and Rhysida deployment. Microsoft seized signspace.cloud, took offline hundreds of VMs, and blocked code hosting sites. Attacks targeted healthcare, education, government, and financial services in the US, France, India, and China.
Mini Shai-Hulud npm Supply Chain Attack
Fresh Mini Shai-Hulud campaign compromised 320+ npm packages across the @antv namespace and timeago.js (1.5M weekly downloads), propagating to echarts-for-react (1.1M weekly downloads). Roughly 639 malicious versions published targeting data visualization, graphing, mapping, and charting ecosystems. The payload (499KB obfuscated JavaScript) triggers via preinstall hook during npm install and targets GitHub Actions CI/CD environments. Capabilities include credential theft from GitHub (tokens, PATs, installation tokens), AWS (IMDS, ECS metadata, .aws files, SecretsManager), HashiCorp Vault (12+ token paths), npm, Kubernetes, and 1Password. The payload scrapes GitHub Actions runner process memory for masked secrets, enumerates repo and org secrets, and exfiltrates via GitHub API and fallback C2. Environment gating exits unless running on GitHub Actions on Linux. The payload now downloads and executes Python code from attacker infrastructure, providing ongoing remote execution. Persistent backdoors were dropped into Claude Code. Microsoft's Durabletask Python SDK was compromised (3 malicious versions within 35 minutes). GitHub Action actions-cool/issues-helper was also compromised. Over 2,200 GitHub repos contained exfiltrated data.
SonicWall VPN MFA Bypass via CVE-2024-12802
Threat actors brute-forced VPN credentials and bypassed MFA on SonicWall Gen6 SSL-VPN appliances via CVE-2024-12802, enabling ransomware deployment. The vulnerability stems from missing MFA enforcement for UPN login format. Installing firmware updates alone does not mitigate the flaw; manual LDAP reconfiguration is required. ReliaQuest responded to multiple intrusions in February and March where Gen6 devices appeared patched but remained vulnerable because remediation steps were incomplete. Attackers logged in within 30-60 minutes, performed network recon, tested credential reuse, reached domain-joined file servers via RDP using shared local admin passwords, and attempted to deploy Cobalt Strike and vulnerable drivers (BYOVD). EDR blocked the beacon and driver loading. Attackers logged out and returned days later using different accounts, suggesting initial access broker activity. Gen6 appliances reached end-of-life on April 16, 2026 and no longer receive security updates. Key log indicators: sess="CLI" (scripted VPN auth), event IDs 238 and 1080, VPN logins from VPS/VPN infrastructure.
TamperedChef Trojanized Productivity Software
TamperedChef-style malware delivers trojanized productivity software (PDF editors, calendars, ZIP extractors) via malicious ads. Over 4,000 samples across 100 unique variants tracked since 2023, with three distinct clusters (CL-CRI-1089, CL-UNK-1090, CL-UNK-1110). Malware shares characteristics with PUPs and adware but remains dormant for weeks to months before activating. Continuous C2 enables delivery of infostealers, proxy tooling, and RATs. Campaigns include AppSuite PDF, Calendaromatic, JustAskJacky, and CrystalPDF. Attackers use code-signing certificates, legitimate functionality, and EULAs to cover malicious behavior. Revenue streams include infostealers, residential proxies, and access broker activity. Telemetry shows over 100 unique variants masquerading as productivity tools, often miscategorized as PUPs despite arbitrary code execution capabilities.
Typosquatting Embedded in Third-Party Scripts
Typosquatting has evolved from user mistyping to adversaries embedding lookalike domains inside legitimate third-party scripts. LLMs generate thousands of convincing domain variants in minutes, and full campaign deployment takes under ten minutes. Malicious package uploads to open-source repositories jumped 156% year-over-year. Trust Wallet Chrome extension attack (December 2025) resulted from Shai-Hulud npm worm harvesting developer credentials and pushing trojanized extension through official Chrome Web Store. Malicious extension captured seed phrases and transmitted to lookalike analytics domain. 2,500 wallets drained, $8.5M lost in 48 hours. No server breach, no alert fired. Firewalls, WAFs, EDR, and CSP have no visibility into what approved scripts do once executed in browser. Typical e-commerce checkout page runs 40-60 third-party scripts, each a trusted connection vector.
AI Coding Agents and Credential Leakage
AI coding agents concentrate multiple enterprise secrets into insecure locations, becoming high-value targets for prompt injection attacks. Credentials typically live in .env files, scripts, or hardcoded in repositories where they can be exfiltrated. 1Password partnered with OpenAI to provide Environments MCP Server for Codex, issuing just-in-time credentials scoped to tasks while keeping secrets outside model context. Credentials never leave 1Password and exist in memory only for authorized processes. Microsoft released RAMPART (agent test framework for adversarial scenarios in CI) and Clarity (structured sounding board for design decisions before code). RAMPART leverages PyRIT for black-box red teaming, enabling engineers to encode adversarial and benign scenarios as repeatable tests that run in CI pipelines. Clarity helps teams pressure-test assumptions early when changing course is cheap.
CISA Exposed GitHub Repo with Secrets
CISA left a GitHub repository publicly accessible containing passwords, keys, and tokens with obvious filenames. The exposure underscores the risk of secret sprawl in development workflows, even for top cybersecurity agencies. No details on remediation timeline or impact were provided in the source.
9-Year-Old Linux Kernel Privilege Escalation (CVE-2026-46333)
CVE-2026-46333 (CVSS 5.5) is a Linux kernel privilege escalation flaw in the __ptrace_may_access() function, introduced in November 2016 and undetected for nine years. The vulnerability allows unprivileged local users to disclose /etc/shadow and host private keys (/etc/ssh/*_key), and execute arbitrary commands as root on default installations of Debian, Fedora, and Ubuntu. Four exploits target chage, ssh-keysign, pkexec, and accounts-daemon. A PoC exploit was released publicly last week. Temporary mitigation: Set kernel.yama.ptrace_scope to 2. On hosts that allowed untrusted local users during exposure window, treat SSH host keys and locally cached credentials as potentially disclosed.
PinTheft Linux Privilege Escalation (Arch Linux)
PinTheft is a local privilege escalation exploit for an RDS zerocopy double-free in the Linux kernel, turned into a page-cache overwrite through io_uring fixed buffers. The bug in the RDS zerocopy send path allows stealing FOLL_PIN references until io_uring holds a stolen page pointer, enabling root shell. Requires RDS module loaded (default only on Arch Linux among common distros), io_uring enabled, readable SUID-root binary, and x86_64 support. PoC exploit released. Mitigation: rmmod rds_tcp rds and add 'install rds /bin/false' and 'install rds_tcp /bin/false' to /etc/modprobe.d/pintheft.conf.
Identity and Device Security Integration
Identity-centric Zero Trust implementations have focused on strengthening authentication, enforcing MFA, and introducing risk-based sign-in policies, but device verification is inconsistently applied. MFA can be bypassed via phishing kits that proxy authentication in real-time and steal session tokens. A session token in an attacker's browser looks identical to the same token in the user's browser, and traditional authentication logs cannot distinguish them. NIST SP 800-207 warns against relying on implied trustworthiness after authentication and specifies access decisions should account for device security posture. Device posture answers questions identity cannot: Is the device encrypted? Is endpoint protection active? Is the OS patched? Has configuration drifted? Conditions at login are not conditions at hour three of a session. Continuous device verification reduces the value of stolen credentials and intercepted tokens because access is bound to a trusted, healthy device, not just an identity.
Supply Chain Vulnerability Crisis
48,000 CVEs published in 2025, mean time to exploit is now -7 days (exploitation occurs before patches release). Black Kite analyzed 1,024 high-priority CVEs based on EPSS scores, KEV inclusion, and third-party relevance, finding only 58 CVEs easily discoverable to attackers via OSINT and representing the most critical threats. AI is a causal factor: frontier models will find more vulnerabilities in 2026, vibe-coded applications introduce more weaknesses, AI-influenced software updates are more likely to include malicious npm-created weaknesses, and agentic growth leads to exposures because agents are granted authorization and access while remaining undisclosed in IT and security departments.
Drupal Core SQL Injection (CVE-2026-9082)
Highly critical vulnerability in Drupal Core database abstraction API allows SQL injection on sites using PostgreSQL databases. CVSS 6.5, exploitable by anonymous users, can lead to information disclosure, privilege escalation, or RCE. Patched in Drupal 11.3.10, 11.2.12, 11.1.10, 10.6.9, 10.5.10, 10.4.10. Drupal 7 not affected. Drupal 11.1.x, 11.0.x, 10.4.x and below are EOL and do not receive security coverage. Manual patches released for EOL Drupal 9.5 and 8.9 as best effort. Supported branches include upstream security updates for Symfony and Twig.
Memcached SASL Timing Side Channel (CVE-2026-47784)
CVE-2026-47784 is a timing side channel in memcached before 1.6.42, affecting SASL password database authentication. Password data for SASL authentication is vulnerable because memcmp is used by sasl_server_userdb_checkpass. EPSS 0.1% (17th percentile).
DNS Software Vulnerabilities (Multiple CVEs)
MSRC published multiple DNS-related CVEs: CVE-2026-32792 (packet of death with DNSCrypt), CVE-2026-42959 (crash during DNSSEC validation), CVE-2026-33278 (possible arbitrary code execution during DNSSEC validation, EPSS 0.4%), CVE-2026-41292 (long list of incoming EDNS options degrades performance), CVE-2026-42944 (heap overflow with multiple NSID, COOKIE, PADDING EDNS options), CVE-2026-42960 (cache poisoning via promiscuous records for authority section), CVE-2026-44608 (use-after-free in RPZ code), CVE-2026-42923 (degradation with unbounded NSEC3 hash calculations), CVE-2026-42534 (jostle logic bypass degrades resolution performance), CVE-2026-40622 (ghost domain names attack variant), CVE-2026-44390 (unbounded name compression causes degradation). All have low EPSS scores (0.0-0.4%). No exploitation details provided.
Rsync Vulnerabilities (CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-29518, CVE-2026-45232)
Multiple vulnerabilities disclosed in rsync before 3.4.3: CVE-2026-43617 (authorization bypass via hostname resolution), CVE-2026-43618 (integer overflow information disclosure), CVE-2026-43619 (symlink race condition via path-based syscalls), CVE-2026-43620 (out-of-bounds array read via recv_files()), CVE-2026-29518 (TOCTOU race condition allows symlink-based arbitrary file write), CVE-2026-45232 (off-by-one stack write via HTTP proxy). All have EPSS scores 0.0% (0th-12th percentile).
GitHub CLI Terminal Escape Sequence Injection (CVE-2026-45803)
CVE-2026-45803 is a terminal escape sequence injection vulnerability in gh (GitHub CLI) in GitHub Actions log output via 'gh run view'. EPSS 0.0% (14th percentile).
Cowboy SPDY Decompression Bomb (CVE-2026-43970)
CVE-2026-43970 is a decompression bomb in cow_spdy:inflate/2 that allows memory exhaustion via crafted SPDY frame. EPSS 0.2% (40th percentile).
WebSocket Uninitialized Memory Disclosure (CVE-2026-45736)
CVE-2026-45736 is an uninitialized memory disclosure in ws (WebSocket library). EPSS 0.0% (1st percentile).
This collection highlights the convergence of supply chain attacks, credential theft, and inadequate patch validation. Mini Shai-Hulud demonstrates how a single compromised maintainer account cascades through dependency chains into millions of CI/CD environments, extracting credentials from process memory and repository secrets. SonicWall CVE-2024-12802 shows incomplete patching (firmware update without manual LDAP reconfiguration) leaves MFA bypass open, enabling ransomware initial access. Microsoft's disruption of Fox Tempest reveals how code-signing abuse legitimizes malware distribution at scale. The nine-year-old Linux kernel flaw (CVE-2026-46333) and fresh PinTheft exploit underscore the reality that legacy code vulnerabilities remain exploitable across default installations of major distributions. AI coding agents now concentrate enterprise secrets into insecure locations, requiring just-in-time credential architectures. The shift from identity-only to identity-plus-device security reflects the inadequacy of MFA against session token theft. Organizations must focus on the 58 truly critical CVEs discoverable via OSINT instead of attempting to patch all 48,000 annual CVEs, prioritizing KEV additions and high EPSS scores.