CVE-2022-40139, CVE-2023-41179, CVE-2023-6606, CVE-2024-9643, CVE-2025-14575, CVE-2025-39901, CVE-2025-39905, CVE-2025-39927, CVE-2025-39932, CVE-2025-39940, CVE-2025-39990, CVE-2025-40003, CVE-2025-40064, CVE-2025-40065, CVE-2025-40074, CVE-2025-51480, CVE-2025-54948, CVE-2026-3039, CVE-2026-34926, CVE-2026-3592, CVE-2026-3593, CVE-2026-41054, CVE-2026-41091, CVE-2026-41940, CVE-2026-42009, CVE-2026-45401, CVE-2026-48172, CVE-2026-5946, CVE-2026-5947, CVE-2026-5950, CVE-2026-8711, CVE-2026-8723, CVE-2026-9082
IP Addresses:
5.3.1.0, 2.223.66.103, 5.181.234.59, 92.38.148.58
Get tomorrow's brief in your inbox
Today: Drupal Core SQL injection (CVE-2026-9082) and Trend Micro Apex One directory traversal (CVE-2026-34926) are both under active exploitation with federal patch deadlines this week. LiteSpeed cPanel plugin CVE-2026-48172 is seeing exploitation for arbitrary script execution as root. First VPN, used by 25 ransomware groups, was taken down in a coordinated global operation.
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV (CVE-2026-9082)
CVE-2026-9082 is an SQL injection vulnerability affecting all supported versions of Drupal Core with a CVSS score of 6.5. The flaw allows privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API. CISA added it to the KEV catalog based on active exploitation less than two days after patches were released. Imperva has observed over 15,000 attack attempts targeting almost 6,000 individual sites across 65 countries, primarily against gaming and financial services. Most activity appears to be reconnaissance and probing to identify PostgreSQL-backed configurations. CVE-2026-9082 is on CISA KEV with EPSS 0.000 (5th percentile), but active exploitation overrides the low score.
Trend Micro Apex One Zero-Day Exploited in the Wild (CVE-2026-34926)
Trend Micro addressed an Apex One zero-day directory traversal vulnerability exploited in attacks targeting Windows systems. CVE-2026-34926 allows local attackers with admin privileges to inject malicious code by modifying a key table on the server to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One, and a potential attacker must have access to the Apex One Server and already obtained administrative credentials via some other method. Despite restrictive requirements, TrendAI observed at least one exploitation attempt in the wild. CISA added CVE-2026-34926 to its KEV catalog and ordered federal agencies to patch by June 4, 2026. CISA currently tracks 12 Trend Micro Apex vulnerabilities that have either been or are still being abused in attacks. CVE-2026-34926 has CVSS not specified, CISA-KEV due June 4, EPSS 0.003 (49th percentile).
LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root
A maximum-severity security vulnerability (CVE-2026-48172, CVSS 10.0) in LiteSpeed User-End cPanel Plugin is under active exploitation. The flaw is an incorrect privilege assignment that allows any cPanel user, including an attacker or compromised account, to exploit the lsws.redisAble function to execute arbitrary scripts as root. All versions of the plugin between 2.3 and 2.4.4 are affected. LiteSpeed's WHM plugin is not impacted. The issue has been addressed in version 2.4.5. LiteSpeed confirmed active exploitation but did not share additional details. CVE-2026-48172 has EPSS 0.000 (13th percentile).
/usr/local/lsws/admin/misc/lscmctl cpanelplugin --uninstall. Check for compromise with grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null. If this command produces output, examine the IP addresses and block any that are not legitimate. This development comes weeks after a critical cPanel vulnerability (CVE-2026-41940, CVSS 9.8, CISA-KEV) was exploited to deploy Mirai botnet variants and a ransomware strain called Sorry. CVE-2026-41940 has EPSS 0.844 (99th percentile).FBI Warns About Fast-Growing Phishing Kit Targeting Microsoft 365 Users (Kali365)
The FBI issued a public service announcement Thursday warning organizations and defenders about Kali365, a growing phishing-as-a-service platform that retrieves Microsoft 365 access tokens. The toolkit bypasses multi-factor authentication and abuses OAuth device code authorizations via phishing lures impersonating common enterprise services. This technique grants cybercriminal-controlled applications access to Microsoft 365 accounts, opening victims up to data theft, fraud, extortion, and ransomware attacks. Device-code phishing platforms connect a malicious app to a legitimate account with a single code. The process requires fewer steps and less interaction with the user, but victims do have to copy-and-paste a code generated by the Kali365 platform to grant access. Proofpoint observed an explosion in device-code phishing activity starting in February. By April, Kali365 was up and running and primarily distributed on Telegram. Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities. The platform charges affiliates $250 for 30 days of service or $2,000 for a full year. Kali365 stores the OAuth access and refresh tokens it captures, and makes those available to affiliates on its platform. Those tokens can also be shared and reused by other cybercriminals who didn't participate in the initial phishing lure. These Microsoft 365 tokens provide persistent access, allowing attackers to wade through multiple Microsoft services without a password or additional MFA requests.
First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
Authorities in Europe and North America dismantled First VPN Service, a criminal virtual private network used by ransomware groups, cybercriminals, and threat actors to obscure the origins of attacks. The operation (codenamed Operation Saffron) was led by France and the Netherlands, with support from 16 other nations. First VPN has been active since about 2014, offering services designed specifically for criminal use with anonymous payments and hidden infrastructure. It was promoted on Russian-speaking cybercrime forums such as Exploit.in and XSS.is as a tool to evade law enforcement. The service provided 32 exit node servers in 27 countries. Between May 19 and 20, authorities interviewed the service's administrator, conducted a house search in Ukraine, took down 33 servers, and seized infrastructure. No less than 25 ransomware groups, such as Avaddon Ransomware, used First VPN infrastructure to perform network reconnaissance and intrusions. Subscription duration ranged from one day to one year, costing between $2 for a single day and $483 for a whole year. It accepted payments through Bitcoin, Perfect Money, Webmoney, EgoPay, and InterKass. First VPN offered several connection protocols including OpenConnect, WireGuard, Outline, and VLess TCP Reality. The FBI shared three U.S. exit node IPs: 2.223.66.103, 5.181.234.59, 92.38.148.58. Europol said First VPN's users have been notified of the shutdown and warned that their identities are now known to authorities, with information linked to 506 users shared with law enforcement.
Four-Faith Industrial Router Vulnerability Exploited by Botnets (CVE-2024-9643)
Attackers are aggressively exploiting CVE-2024-9643, an authentication bypass flaw in Four-Faith F3x36 industrial cellular routers that stems from hardcoded administrative credentials. CrowdSec has tracked a surge in exploitation since late April 2026. This vulnerability affects industrial environments and critical infrastructure deployments. CVE-2024-9643 has EPSS 0.191 (95th percentile).
Multi-Stage Linux Intrusion via F5 and Confluence Edge Appliance Compromise
Microsoft documented a growing trend of internet-facing edge appliances such as firewalls and VPN gateways being compromised as initial access points. In this incident, the threat actor compromised an internet-facing F5 BIG-IP load balancer and used trusted relationships to pivot to an internal Linux host. The source was identified as an Azure-hosted appliance running version 15.1.201000, a BIG-IP Virtual Edition (VE) image version that reached end-of-life on December 31, 2024. From there, the threat actor compromised a vulnerable SaaS application and leveraged its credentials to conduct relay-style authentication attacks against Active Directory. The threat actor authenticated to a Linux server over SSH using a privileged account with sudo rights, maintaining sustained hands-on keyboard access throughout the attack without establishing explicit persistence mechanisms. The threat actor performed extensive reconnaissance using Nmap for network scanning and service discovery, and used gowitness to perform detailed reconnaissance of HTTP/HTTPS services. Edge appliances often store credentials, certificates, session material, authentication tokens, and identity integrations with directories, cloud services, and identity providers. Once compromised, these trust relationships enable lateral movement that bypasses traditional security controls.
Iranian Hackers Suspected in US Gas Station Tank Monitor Breaches
US officials believe Iranian hackers breached automatic tank gauge (ATG) systems that monitor fuel levels in underground storage tanks at gas stations across multiple states. The attackers exploited unprotected, internet-connected devices lacking passwords and were able to alter display readings, though they could not change actual fuel volumes. While no physical damage or safety incidents have occurred, the intrusions have sparked concerns that such access could potentially mask gas leaks or create other risks to critical infrastructure. The cybersecurity industry has long warned about the risks posed by exposed, unprotected ATG systems.
CISA Contractor Exposes Credentials on Public GitHub Repository
A contractor working for CISA left a public GitHub repository named Private-CISA openly accessible for months, exposing administrative keys to multiple AWS GovCloud accounts along with plaintext passwords for internal CISA systems. While CISA states there is no evidence of unauthorized access to sensitive data so far, the exposed credentials could have allowed attackers to move laterally into government systems or tamper with internal software packages.
Hugging Face Hiding Second-Stage Malware for npm Supply Chain Attack
Hackers linked to North Korea have embedded second-stage malware inside Hugging Face, the widely used AI and machine learning hub, effectively turning it into a malware delivery channel. This represents a new and alarming way to weaponize one of the most trusted platforms in the AI world.
New macOS Stealer Variant Masquerades as Apple, Google & Microsoft (Reaper)
SentinelOne researchers identified a new macOS infostealer variant using the build tag "Reaper", the latest evolution within the SHub Stealer malware family. The infection chain uses fake WeChat and Miro installers hosted on typosquatted domains to lure victims. The websites employ extensive anti-analysis techniques, blocking developer tools and fingerprinting visitors to avoid virtual environments. To sidestep Apple's recent macOS Tahoe mitigations, the malware abandons traditional "ClickFix" social engineering in Terminal, instead leveraging the applescript:// URL scheme to launch the macOS Script Editor. The malicious HTML from the webpage creates a script deliberately padded with ASCII art to hide the malicious command. On execution, the script displays a message indicating it is downloading an Apple security update. Once executed, the AppleScript prompts the user for their password to access protected Keychain items and decrypt credentials. Reaper extensively harvests browser data, password manager extensions, and iCloud account details. The variant introduces an AMOS-style Filegrabber module that targets business and financial documents, dividing the stolen data into 70MB chunked ZIP archives for exfiltration. The Reaper malware also actively hijacks desktop cryptocurrency applications by terminating the active processes and replacing the legitimate core app.asar file. To bypass macOS Gatekeeper, the script clears quarantine attributes and applies ad hoc code signing to the modified application bundle.
Interpol Operation Ramz Rounds Up 200+ Cybercrime Suspects Across Middle East and North Africa
Over 200 individuals and another 382 suspects have been rounded up in Interpol's Operation Ramz, an initiative targeting cybercrime networks across the Middle East and North Africa. Spanning thirteen countries and working alongside cybersecurity partners, police seized 53 servers used for malware distribution, phishing campaigns, and online fraud responsible for attacks with at least 3,867 confirmed victims. Highlights of the operation include dismantling an investment scam in Jordan and a phishing-as-a-service (PHaaS) platform in Algeria, and confiscating devices, servers, and data linked to various operations in Qatar, Oman, and Morocco. Ukrainian cyberpolice, alongside U.S. law enforcement, identified a suspect in Odesa allegedly responsible for operating an infostealer malware campaign. Between 2024 and 2025, the accused targeted users of a California-based online store, compromising 28,000 customer accounts. He then exploited 5,800 of these stolen session tokens to make $721,000 in unauthorized purchases.
Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks
Verizon Business' 2026 Data Breach Investigations Report (DBIR) highlights how the healthcare sector faces mounting social engineering attacks, many emboldened by artificial intelligence. The industry faces challenges stemming from ransomware, third-party vendor breaches, and social engineering. Social engineering returned as one of the top three patterns attackers used in breaches, alongside system intrusion and miscellaneous errors. The three represented 81% of breaches. Attackers' social engineering tactics have evolved significantly. For the past 12 to 18 months, more healthcare organizations have grappled with advanced attacks that leverage AI-fueled social engineering to create a sense of urgency and catch people off guard. Attackers have taken traditional phishing up a notch by using generative AI to create highly targeted, context-aware communications, and malicious documents at scale. The rise of pretexting (faking identities or scenarios to manipulate a target into performing actions they would otherwise not undertake) jumped to the No. 2 spot among social actions in the report for healthcare breaches, right behind phishing. Pretexting was not mentioned under healthcare in Verizon's 2025 DBIR. With help from AI, threat actors have responded to improved email security by refining pretexts and tailoring lures to healthcare workflows, including vendor billing, human resources, IT access, and even clinical operations. The apparent increase may also be due to better reporting quality, as social engineering attacks that previously lacked sufficient detail to classify are now being accurately reported.
CVE-2026-41091 (CISA-KEV, EPSS 0.066, 91st percentile) - Added to CISA KEV with due date June 3, 2026. Specific details not provided in sources, but EPSS score suggests moderate exploitation likelihood.
CVE-2026-45401 (EPSS 0.000, 12th percentile) - Vulnerability disclosed but specific details not available in sources.
CVE-2025-14575 (Qt Network OpenSSL TLS backend, EPSS 0.000, 1st percentile) - Uncontrolled search path element allows rogue CA certificate loading. Low exploitation probability based on EPSS.
CVE-2026-3593 (BIND 9 DNS-over-HTTPS, EPSS 0.000, 5th percentile) - Heap use-after-free vulnerability. Patch available from ISC.
CVE-2026-42009 (GnuTLS DTLS, EPSS 0.001, 31st percentile) - Denial of service via DTLS packet reordering vulnerability.
CVE-2026-3039 (BIND 9, EPSS 0.001, 16th percentile) - Server memory exhaustion during GSS-API TKEY negotiation.
CVE-2026-3592 (BIND 9, EPSS 0.000, 4th percentile) - Amplification vulnerabilities via self-pointed glue records.
CVE-2026-5946 (BIND 9, EPSS 0.000, 11th percentile) - Invalid handling of CLASS != IN.
CVE-2026-5950 (BIND 9, EPSS 0.001, 21st percentile) - Unbounded resend loop in BIND 9 resolver.
CVE-2026-41054 (haveged, EPSS 0.000, 0th percentile) - Missing exit out of permission check could lead to root exploit.
CVE-2026-8723 (qs.stringify, EPSS 0.000, 14th percentile) - Crashes on null/undefined entries in comma-format arrays under encodeValuesOnly.
CVE-2026-5947 (BIND 9, EPSS 0.000, 6th percentile) - SIG(0) validation during query flood may lead to undefined behavior.
CVE-2026-8711 (NGINX JavaScript, EPSS 0.002, 47th percentile) - Vulnerability in NGINX JavaScript module.
CVE-2025-51480 (ONNX 1.17.0, EPSS 0.004, 59th percentile) - Path traversal vulnerability in onnx.external_data_helper.save_external_data allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences.
CVE-2023-6606 (Linux kernel SMB, EPSS 0.000, 1st percentile) - Out-of-bounds read vulnerability in smbcalcsize.
CVE-2025-39932 (Linux SMB client, EPSS 0.000, 2nd percentile) - Lets smbd_destroy() call disable_work_sync for post_send_credits_work.
Multiple Linux kernel CVEs (CVE-2025-40064, CVE-2025-39927, CVE-2025-39901, CVE-2025-39905, CVE-2025-39940, CVE-2025-39990, CVE-2025-40003, CVE-2025-40074, CVE-2025-40065) - Various use-after-free, race condition, and information disclosure vulnerabilities in Linux kernel subsystems. All have EPSS 0.000 (low percentiles), indicating minimal observed exploitation attempts.
This week's intelligence highlights a continued focus on exploiting trusted infrastructure and edge devices as initial access vectors. The compromise of EOL F5 BIG-IP appliances demonstrates how operational constraints delaying patching create durable footholds for threat actors. The coordinated takedown of First VPN, used by 25 ransomware groups, temporarily disrupts criminal infrastructure but raises costs rather than eliminating the capability. Social engineering continues to evolve with AI assistance, particularly in healthcare and enterprise environments where OAuth device code phishing platforms like Kali365 provide turnkey solutions for bypassing MFA. The weaponization of trusted platforms like Hugging Face for supply chain attacks signals a new frontier in targeting AI/ML development workflows.