CVE-2026-26980, CVE-2026-43029, CVE-2026-43414, CVE-2026-5426
Get tomorrow's brief in your inbox
Today: Supply chain attacks hit developer ecosystems with 34 malicious packages stealing credentials across npm, PyPI, and Crates.io, while 5,500 GitHub repositories were infected with workflow backdoors. Ghost CMS sites face active exploitation of CVE-2026-26980 (CVSS critical, EPSS 98th percentile), and threat actors are using AI assistants as attack vectors by planting poisoned instructions in code repositories.
Ghost CMS SQL Injection (CVE-2026-26980)
Ghost CMS versions 3.24.0 through 6.19.0 are under active exploitation in a large-scale ClickFix campaign. Over 700 domains have been compromised, including Harvard, Oxford, Auburn, and DuckDuckGo. The SQL injection flaw (EPSS 98th percentile) allows unauthenticated attackers to steal admin API keys and inject malicious JavaScript. Attackers fingerprint visitors, then serve fake Cloudflare prompts instructing victims to paste commands into Windows command prompts, dropping DLL loaders and Electron-based malware. The fix was released February 19 in version 6.19.1, but many sites remain unpatched.
KnowledgeDeliver LMS ViewState Deserialization (CVE-2026-5426)
A critical zero-day in KnowledgeDeliver (Japanese LMS platform) allowed unauthenticated remote code execution via ViewState deserialization. The vulnerability stems from identical pre-shared ASP.NET machine keys deployed across multiple customer installations before February 24, 2026. Threat actors who obtained keys from one deployment could compromise any internet-facing instance. Post-exploitation included BLUEBEAM web shell deployment (Godzilla in-memory variant), JavaScript tampering to deliver fake security prompts, and Cobalt Strike BEACON backdoor infections targeting workstations. This follows similar patterns seen in Sitecore exploits and publicly disclosed ASP.NET machine key attacks.
TrapDoor Supply Chain Attack (npm, PyPI, Crates.io)
A coordinated cross-ecosystem attack campaign deployed 34 malicious packages across 384 versions targeting crypto, DeFi, Solana, and AI developer communities. The campaign launched May 22, targeting developer secrets, crypto wallets, SSH keys, cloud credentials, browser data, and environment variables. npm packages deploy trap-core.js to scan credentials, validate AWS and GitHub tokens, and plant persistence through .cursorrules, CLAUDE.md, Git hooks, shell hooks, systemd, cron, and SSH. An unusual tactic involves GitHub pull requests to popular AI projects (browser-use, langchain, langflow) containing .cursorrules and CLAUDE.md files with hidden instructions designed to trick AI assistants into running malicious code during code review sessions. Rust crates search for keystores, XOR-encrypt data with hardcoded keys, and exfiltrate to GitHub Gists. PyPI packages auto-execute on import, downloading JavaScript from attacker-controlled GitHub Pages domains.
Megalodon GitHub Actions Attack (5,500+ Repositories)
Over 5,500 GitHub repositories were infected with malware through 5,718 malicious commits pushed within a six-hour window on May 18. Attackers injected GitHub Actions workflows containing payloads that steal credentials, keys, tokens, and secrets. Two attack patterns were deployed: workflows triggered on every push/pull, and dormant backdoors using workflow_dispatch triggers (exempted from GitHub's anti-recursion rules). The malware exfiltrates CI environment variables, AWS/GCP/Azure credentials, SSH keys, Docker and Kubernetes configs, API keys, database strings, and GitHub Actions tokens. The attack originated from compromised maintainer repositories, with malicious code published to npm without the maintainer realizing the source was poisoned. Tiledesk packages published May 19-21 were confirmed infected.
DocketWise Data Breach (143,000 Affected)
Immigration and legal case management platform DocketWise disclosed a breach affecting 143,480 individuals. Threat actors used valid credentials to clone third-party partner repositories containing data migration pipelines for the DocketWise application. Compromised data includes names, addresses, SSNs, driver's licenses, passport numbers, financial account credentials, payment cards, tax IDs, health insurance policies, and medical information. The company launched investigation in October 2025 and began notifications in April. Unauthorized access has been closed, with no evidence of data publication. Two years of credit monitoring provided to impacted individuals.
Chinese-Language Phishing-as-a-Service Ecosystem
Google Threat Intelligence detailed a mature phishing-as-a-service ecosystem in the Chinese underground, distinct from Russian operations. These services target the general public opportunistically rather than large organizations, operate openly on Telegram with less OPSEC, and offer extensive ancillary services including PII sales, domain registration, VPS hosting, money laundering, IMSI catchers, and spam assistance. Key tactics include RCS and iMessage delivery to bypass SMS carrier filters, real-time admin panels to capture OTPs and bypass MFA instantly, and a shift from static password harvesting to live interception and digital wallet provisioning (tokenization). The goal is unauthorized control over financial accounts, not just login access. Google took legal action against one PhaaS provider and is working on legislation and technical safeguards.
Anthropic Mythos Finds 23,000 Vulnerabilities
Anthropic's Project Glasswing deployed the Mythos cybersecurity AI model to scan open-source projects, finding 23,019 vulnerabilities across 1,000+ projects. Over 6,200 are suspected high or critical severity, with 1,500 confirmed legitimate and almost 100 patched. Anthropic expects the confirmed count to reach 3,900. Governments, intelligence agencies, and private sector entities are requesting access to scan their networks. The flood of AI-generated bug reports is overwhelming maintainers, forcing bug bounty programs to shut down or ban AI-written reports altogether. Triage times are increasing, delaying patches. The industry is seeing major disruption to established vulnerability disclosure and bounty processes.
Linus Torvalds Cracks Down on AI-Generated Pull Requests
Linux kernel maintainer Linus Torvalds announced he will "start being more hardnosed" about "pointless pull requests," some of which are AI-generated. Torvalds warned that large release candidates are not conducive to long-term stability. The statement reflects growing frustration with low-quality AI-assisted contributions flooding open-source projects.
Wireshark 4.6.6
Wireshark 4.6.6 addresses 1 vulnerability and 11 bugs. Windows builds include Npcap 1.88. Details on the vulnerability have not been disclosed publicly.
CVE-2026-43029 (mptcp soft lockup)
Microsoft published CVE-2026-43029 addressing a soft lockup in mptcp_recvmsg(). EPSS score is 0.000 (14th percentile), indicating low active exploitation likelihood. No severity rating disclosed.
CVE-2026-43414 (qla2xxx fcport double free)
Microsoft published CVE-2026-43414 addressing a fcport double free in the qla2xxx SCSI driver. EPSS score is 0.001 (18th percentile), indicating low exploitation risk. No severity rating disclosed.
Supply chain attacks are targeting the AI-assisted development workflow itself. TrapDoor's use of .cursorrules and CLAUDE.md files to trick AI coding assistants into executing malicious code represents a new attack surface. The sheer volume of repositories affected in Megalodon (5,500+) and the speed of deployment (six hours) shows supply chain attacks are moving to industrial scale. Meanwhile, the release of Anthropic's Mythos AI model is overwhelming open-source maintainers with vulnerability reports faster than they can triage, creating a new bottleneck in the patching process. These trends are converging to create a security crisis in the developer toolchain.