CVE-2008-4250, CVE-2009-1537, CVE-2009-3459, CVE-2010-0249, CVE-2010-0806, CVE-2018-0802, CVE-2022-35737, CVE-2022-4304, CVE-2023-7104, CVE-2024-26944, CVE-2024-55591, CVE-2025-10504, CVE-2025-12142, CVE-2025-12143, CVE-2025-3277, CVE-2025-34291, CVE-2025-6965, CVE-2026-0968, CVE-2026-33825, CVE-2026-34926, CVE-2026-41091, CVE-2026-43303, CVE-2026-43331, CVE-2026-43465, CVE-2026-43494, CVE-2026-43495, CVE-2026-43496, CVE-2026-43497, CVE-2026-43499, CVE-2026-43501, CVE-2026-43502, CVE-2026-45498, CVE-2026-45584, CVE-2026-9082
Hashes:
049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9
Get tomorrow's brief in your inbox
2026-05-22
Today: Microsoft patched two actively exploited Defender zero-days with CISA deadline June 3. Trend Micro disclosed another Apex One zero-day under exploitation. Drupal fixed a highly critical SQL injection flaw affecting PostgreSQL sites, with exploit creation expected within days.
Microsoft Defender Actively Exploited Zero-Days (CVE-2026-41091, CVE-2026-45498)
Microsoft disclosed active exploitation of two Defender vulnerabilities. CVE-2026-41091 (CVSS 7.8) is a privilege escalation flaw allowing attackers to gain SYSTEM privileges through improper link resolution. CVE-2026-45498 (CVSS 4.0) is a denial-of-service vulnerability. Both vulnerabilities have been added to CISA's KEV catalog with a June 3, 2026 remediation deadline. CVE-2026-41091 has an EPSS score of 0.121 (94th percentile) and CVE-2026-45498 has an EPSS score of 0.023 (85th percentile). The vulnerabilities overlap with RedSun and UnDefend zero-days disclosed by Chaotic Eclipse last month, and Huntress has observed exploitation of both alongside BlueHammer (CVE-2026-33825). Microsoft also addressed CVE-2026-45584 (CVSS 8.1), a heap-based buffer overflow enabling remote code execution, though no active exploitation has been observed for this vulnerability.
Trend Micro Apex One Zero-Day Exploitation (CVE-2026-34926)
Trend Micro patched CVE-2026-34926 (CVSS 6.7), a directory traversal vulnerability in on-premise Apex One installations under active exploitation. An authenticated local attacker with admin credentials can modify a key table on the server to inject malicious code for deployment to agents. The vulnerability was discovered by Trend Micro's internal incident response team. CISA added CVE-2026-34926 to the KEV catalog with a June 4, 2026 deadline. Given the access requirements, this exploitation pattern aligns with advanced persistent threat activity, similar to past Apex vulnerabilities exploited by Chinese state-sponsored hackers.
Drupal Highly Critical SQL Injection (CVE-2026-9082)
Drupal patched CVE-2026-9082 (NIST CMSS 20/25), a highly critical SQL injection vulnerability in the database query sanitization API. The flaw allows unauthenticated attackers to send specially crafted requests resulting in arbitrary SQL injection on sites using PostgreSQL databases. Successful exploitation can lead to information disclosure, privilege escalation, and remote code execution. Drupal developers warn that exploits may be created within hours or days of disclosure. Less than 5% of Drupal sites use PostgreSQL and are affected. Patches are available for Drupal 11.3, 11.2, 10.6, and 10.5.x. This is the first highly critical Drupal vulnerability in years, and there have been no reports of wild exploitation since Drupalgeddon2 in 2019.
Langflow Code Execution Vulnerability Exploited by MuddyWater (CVE-2025-34291)
CVE-2025-34291 (CVSS 9.4) is an origin validation error in Langflow that allows remote code execution and full system compromise. The vulnerability exploits three weaknesses: overly permissive CORS, lack of CSRF protection, and an endpoint allowing code execution by design. Successful exploitation compromises the Langflow instance and exposes all access tokens and API keys, triggering cascading compromise across integrated cloud and SaaS services. Iranian state-sponsored group MuddyWater has exploited this vulnerability for initial access to target networks. CISA added CVE-2025-34291 to the KEV catalog with a June 4, 2026 deadline. EPSS score is 0.095 (93rd percentile).
CISA Adds Legacy Microsoft Vulnerabilities to KEV
CISA added four legacy Microsoft vulnerabilities from 2008-2010 to the KEV catalog, all with June 3, 2026 deadlines. CVE-2010-0806 (EPSS 0.882, 100th percentile) and CVE-2010-0249 (EPSS 0.886, 100th percentile) are use-after-free vulnerabilities in Internet Explorer enabling remote code execution. CVE-2009-1537 (EPSS 0.741, 99th percentile) is a NULL byte overwrite vulnerability in DirectX QuickTime Movie Parser Filter allowing remote code execution via crafted QuickTime files. CVE-2008-4250 (EPSS 0.936, 100th percentile) is a buffer overflow in Windows Server Service allowing remote code execution via crafted RPC requests. CVE-2009-3459 is a heap-based buffer overflow in Adobe Acrobat and Reader. The addition of these legacy CVEs to the KEV catalog suggests active exploitation campaigns targeting unpatched systems.
2 claims tracked across 2 groups in the last 48 hours.
| Group | Victim | Sector | Country |
|---|---|---|---|
| Triple X | Bank of Indonesia (bni.co.id) | Banking | Indonesia |
| Spy Corporate | Hahn Loeser | Legal | Unknown |
These are unverified claims from ransomware leak sites, not confirmed breaches.
The Gentlemen Ransomware Defense Evasion TTPs
Huntress analyzed two incidents involving The Gentlemen ransomware, a RaaS operation active since mid-2025 with over 400 claimed victims across 70 countries. The Gentlemen operators rely on custom defense evasion tools to disable security solutions and abuse Windows logging. In both incidents, attackers cleared Security, System, and Application Event Logs while leaving other Windows logs untouched. Attackers used Scheduled Tasks and PowerShell for execution and attempted to evade antivirus after initial encryptor deployment was blocked. An insider leak of The Gentlemen's internal database in early May revealed the operation's administrator builds ransomware lockers and panels while also engaging in attacks alongside affiliates. The leak exposed tracking of CVEs including Fortinet authentication bypass CVE-2024-55591 (CISA KEV, EPSS 0.941, 100th percentile). Previous reports show The Gentlemen actors use legitimate driver abuse, Group Policy Objects for domain-wide attacks, and AnyDesk for persistence.
First VPN Cybercrime Service Dismantled
International law enforcement dismantled First VPN, a cybercrime anonymization service used by at least 25 ransomware groups and involved in nearly every major cybercrime investigation Europol supported. The operation seized 33 servers across 27 countries, disrupted infrastructure supporting 1vpns.com, 1vpns.net, 1vpns.org, and onion domains, and arrested the alleged Ukrainian administrator. Authorities identified all First VPN users and issued direct notifications. Information on 506 users was shared internationally, and 83 intelligence packages were distributed for ongoing investigations. First VPN advertised as a privacy-focused no-log VPN that ignores law enforcement requests. Investigators infiltrated the VPN infrastructure before takedown and collected the user database identifying VPN connections used in attacks. First VPN has been active since 2014 and provided 32 exit nodes at the time of disruption.
Cloud Atlas APT Returns with New Tools and SSH Tunnels
Kaspersky observed Cloud Atlas APT (active since 2014) conducting pervasive SSH tunnel activity targeting government organizations and commercial companies in Russia and Belarus throughout 2025 and into 2026. The group uses phishing emails with ZIP archives containing malicious LNK shortcuts that launch PowerShell scripts. Cloud Atlas also exploits CVE-2018-0802 (EPSS 0.941, 100th percentile, CISA KEV) in Microsoft Office Equation Editor to download and execute malicious code. The group deploys VBCloud (file stealer targeting DOC, PDF, XLS files) and PowerShower (network reconnaissance and lateral movement backdoor) as primary payloads. PowerShower performs Kerberoasting attacks, collects information on processes, administrator groups, and domain controllers, and downloads additional scripts from C2 servers. Cloud Atlas uses UAC bypass via fodhelper.exe to execute credential grabbing scripts that create Volume Shadow Copies and steal SAM and SECURITY files disguised as PDFs. The group patches termsrv.dll to enable multi-user RDP for lateral movement and uses third-party tools including Tor, SSH, and RevSocks for persistence and backup control channels.
GitHub Breached via Compromised VS Code Extension
GitHub disclosed that attackers stole over 3,800 internal code repositories after an employee installed a malicious VS Code extension. The malicious extension was Nx Console, which was compromised in the TanStack supply chain attack. GitHub is rotating critical secret tokens to prevent further access. Grafana also attributed its recent breach to the same TanStack incident. The TanStack supply chain attack deployed self-propagating information-stealing malware on victim computers through compromised NPM and PyPI packages. Microsoft's GitHub was compromised when a Microsoft developer using Microsoft VS Code installed a rogue extension from Microsoft's VS Code extension library, which is moderated and hosted by Microsoft.
Cross-Platform NPM Stealer Targets Windows, macOS, Linux
SANS ISC analyzed a heavily obfuscated Node.js stealer (SHA256: 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9) targeting Windows (including WSL), macOS, and Linux. The stealer contains three payloads: browser credential stealer supporting 15 browsers (Chrome, Brave, Edge, Opera, Opera GX, Vivaldi, Kiwi, Yandex, Iridium, Comodo Dragon, SRWare Iron, Chromium, AVG Browser), cryptocurrency wallet extension stealer targeting 40+ Chrome wallet extensions, and system information collector. The malicious code uses obfuscation.io techniques with long arrays of Base64-encoded strings and arithmetic decoder functions. Malicious payloads are embedded in plain text despite the obfuscated wrapper.
ABB Industrial Control Systems Vulnerabilities
CISA published three ICS advisories for ABB products. ABB B&R Automation Studio versions before 6.5 contain 25 SQLite vulnerabilities (CVE-2025-6965, CVE-2025-3277, CVE-2023-7104, CVE-2022-35737, and others) allowing memory corruption, heap-based buffer overflows, and integer overflows. ABB B&R PCs (APC4100, APC910, C80, MPC3100, PPC series) contain 9 EDK2 network stack vulnerabilities enabling remote code execution, DoS, DNS cache poisoning, and information disclosure. ABB Terra AC Wallbox (Japan) versions 1.8.33 and earlier contain three heap and stack-based buffer overflow vulnerabilities (CVE-2025-10504, CVE-2025-12142, CVE-2025-12143) that could allow remote control and firmware alteration. ABB recommends updating to the latest versions and disabling unused features like PXE boot.
Hitachi Energy GMS600 OpenSSL Timing Attack (CVE-2022-4304)
Hitachi Energy disclosed CVE-2022-4304 affecting GMS600 versions 1.3.0 and 1.3.1. This timing-based side channel vulnerability in OpenSSL RSA decryption could allow Bleichenbacher-style attacks to recover plaintext across a network. An attacker must send a large number of trial decryption messages and record processing times to recover pre-master secrets and decrypt TLS connections. The vulnerability affects all RSA padding modes (PKCS#1 v1.5, RSA-OEAP, RSASVE). Hitachi Energy recommends upgrading to GMS600 version 1.3.2 and implementing firewall configurations with ingress IP allowlisting and traffic rate limiting.
Microsoft Linux Kernel CVEs in MSRC Update Guide
Microsoft published advisories for 10 Linux kernel CVEs in the MSRC Security Update Guide, affecting Azure and WSL environments. Notable CVEs include CVE-2024-26944 (btrfs use-after-free), CVE-2026-0968 (libssh DoS), CVE-2026-43331 (x86/kexec KCOV instrumentation), CVE-2026-43303 (mm/page_alloc memory management), CVE-2026-43465 (net/mlx5e XDP multi-buf), CVE-2026-43499 (rtmutex), CVE-2026-43497 (fbdev udlfb use-after-free), CVE-2026-43502 (net/rds zerocopy), CVE-2026-43501 (ipv6 rpl), CVE-2026-43496 (net/sched), CVE-2026-43495 (net wwan t7xx), and CVE-2026-43494 (net/rds zerocopy). Most have low EPSS scores (1st-5th percentiles), indicating low exploitation probability. CVE-2024-26944 and CVE-2026-0968 have EPSS scores in the 1st percentile.
Pwn2Own Berlin 2026: 47 Zero-Days Exploited
Pwn2Own Berlin 2026 concluded with researchers earning $1,298,250 after exploiting 47 zero-day vulnerabilities in Windows, Linux, VMware, and NVIDIA products. DEVCORE won with 50.5 Master of Pwn points and $505,000 by hacking Microsoft SharePoint, Exchange, Edge, and Windows 11. STARLabs SG earned $242,500 (25 points) and Out Of Bounds earned $95,750 (12.75 points). All discovered vulnerabilities will be disclosed to vendors for patching. This high zero-day count demonstrates continued security weaknesses in enterprise platforms and hypervisors.
Microsoft Ends SMS MFA for Personal Accounts
Microsoft is phasing out SMS as a multi-factor authentication and account recovery option for personal Microsoft accounts. All users will be prompted to add a passkey the next time they log in. Microsoft cited SMS as a leading source of fraud and the most targeted vector for account takeover. Passkeys provide phishing resistance and faster login flows compared to SMS MFA, which can be phished using AitM (adversary-in-the-middle) phishing kits like Modlishka, Muraena, and Evilginx. Microsoft becomes the first major platform to abandon SMS MFA entirely, though Google, Facebook, and Twitter still allow SMS as a fallback option.
UK NCSC Issues Agentic AI Security Guidance
The UK National Cyber Security Centre released guidance for securing agentic AI deployments in enterprise environments. NCSC warns that over-privileged or poorly designed AI agents can escalate a single failure into a serious incident. The guidance emphasizes thinking before deploying AI agents and implementing adequate security controls. Omdia research shows 45% of organizations use standalone AI budgets separate from digital transformation or innovation funds, and 36% of identity leaders tap separate AI budgets to fund identity security for AI agents. Organizations are reallocating funds from other technology budgets (28%), using digital transformation initiatives (21%), or reducing existing identity budgets (15%) to fund AI agent security.
Poland Urges Officials to Switch from Signal to mSzyfr
The Polish government is urging public officials and National Cybersecurity System entities to stop using Signal and instead use mSzyfr, an encrypted messenger developed by a Polish research organization. The directive cites social engineering attacks by advanced persistent threat groups, including efforts impersonating Signal support to take control of accounts. Multiple governments have warned of rising social engineering attacks targeting messaging platforms. The switch from Signal to a domestic encrypted messenger raises questions about cryptographic implementation and independent security audits.
Dutch Police Unmasked 74 Fraud Suspects via Game Over?! Campaign
Dutch police identified 74 of 100 suspected fraudsters through the Game Over?! initiative, which displayed blurred photos of suspects on billboards, television, and online advertisements, giving criminals two weeks to surrender before images were unblurred. 34 suspects voluntarily reported to authorities, while the remaining 40 were identified through public tips. Suspects range in age from 14 to 42 years old. The initiative, launched in March 2026, demonstrates innovative public engagement in cybercrime investigations.
Trump Postpones AI Security Executive Order
President Trump postponed an executive order that would establish a 90-day voluntary testing regime for frontier AI models, citing concerns about harming US AI industry competition with China. The draft order would have empowered NSA to conduct classified evaluations of frontier AI models, and Treasury would have established information sharing between AI companies and critical infrastructure cybersecurity defenders. ONCD, CISA, and NIST would have defined which models are covered. The order would have formalized existing cooperative relationships between AI companies and government agencies. The administration's early rhetoric of "no institution of guardrails" has created tension with implementing AI security testing.
US-China Cyber Espionage Acknowledgment
President Trump acknowledged mutual cyber espionage activities between the US and China during bilateral meetings with President Xi Jinping. Trump stated "we spy like hell on them too" and discussed cyber attacks conducted by both nations. The acknowledgment comes as China has been accused of sweeping intrusions into US networks. Trump did not elaborate on specific attacks carried out against China.
Today's brief highlights the convergence of actively exploited zero-days in widely deployed security products (Microsoft Defender, Trend Micro Apex One) with aggressive CISA KEV deadlines, supply chain compromises affecting developer toolchains (VS Code extensions, NPM packages), and legacy infrastructure exploitation (First VPN takedown revealing widespread ransomware group usage). The addition of decade-old Microsoft vulnerabilities to the KEV catalog signals persistent exploitation of unpatched legacy systems. The Drupal highly critical SQL injection flaw with expected rapid exploit development demonstrates the ongoing challenge of securing open source infrastructure. These converging threats require coordinated patching, supply chain security hardening, and elimination of legacy unpatched systems.