CVE-2026-26980, CVE-2026-34926, CVE-2026-41091, CVE-2026-45321, CVE-2026-45498, CVE-2026-46333, CVE-2026-5426, CVE-2026-9082
Domains:
flipboxstudio[.]info, clo4shara[.]xyz, google[.]com, fairpoint29[.]com, enhanceblabber[.]cc, primemetricsa[.]com, creativecommunityinfo[.]art, ibb[.]co, enhanceblabber[.]cc., aes-secure[.]net, getsqldeveloper[.]com
Hashes:
70b5ecc110e074dbca92932c0e840ea3492ea0a43c3f215b71392c12b02213b2, a14c3ecf5eb3d2543358482e43dc765dbf9ee7a4bec7571f5ecb8829ca719692, 47fa746422f1bf6b7712dc6803378e6a995488007193a7441d790f70d204728f
Get tomorrow's brief in your inbox
May 26, 2026
Today: Drupal SQL injection under active exploitation with CISA's deadline Wednesday, Microsoft Defender zero-days confirmed exploited in the wild (CVE-2026-41091, CVE-2026-45498), and Ghost CMS attackers poisoned 700+ sites including Harvard and DuckDuckGo with ClickFix malware. The TanStack supply chain breach that hit GitHub now has a public blueprint after TeamPCP released their Shai-Hulud framework source code.
Drupal SQL Injection (CVE-2026-9082)
CISA added CVE-2026-9082 to the KEV catalog Friday and gave federal agencies until Wednesday, May 27 to patch. The SQL injection flaw affects Drupal sites running PostgreSQL and allows unauthenticated attackers to execute database commands, steal data, or achieve code execution. The 9-year-old vulnerability remained undetected since November 2016 and active exploitation was confirmed shortly after public disclosure. Shadowserver tracks nearly 670 unpatched Drupal installations exposed online, concentrated in North America (272) and Europe (273). EPSS score is 12.6% (94th percentile).
Microsoft Defender Zero-Days (CVE-2026-41091, CVE-2026-45498)
Microsoft disclosed active exploitation of two Defender vulnerabilities. CVE-2026-41091 is a privilege escalation flaw allowing attackers to gain SYSTEM privileges through the Malware Protection Engine. CVE-2026-45498 is a denial-of-service vulnerability in the Defender Antimalware Platform. Both flaws are on CISA's KEV catalog with remediation deadlines of June 3. EPSS scores are 4.5% (89th percentile) for CVE-2026-41091 and 3.2% (87th percentile) for CVE-2026-45498. Patches are distributed automatically through normal Defender updates.
Trend Micro Apex One Directory Traversal (CVE-2026-34926)
Attackers with administrator access can exploit CVE-2026-34926 to push malicious code to Windows endpoints via directory traversal in Apex One on-premises servers. Trend Micro confirmed active exploitation attempts against Windows systems. The vulnerability affects enterprise endpoint security platforms in corporate deployments and has been added to CISA's KEV catalog with a remediation deadline of June 4. EPSS score is 0.2% (41st percentile).
Linux Kernel Privilege Escalation (CVE-2026-46333)
A 9-year-old vulnerability in the Linux kernel remained undetected since November 2016. CVE-2026-46333 (CVSS 5.5) is an improper privilege management flaw that permits unprivileged local users to disclose sensitive files and execute arbitrary commands as root on default installations of Debian, Fedora, and Ubuntu. The vulnerability affects major distributions but requires local access to exploit. EPSS score is negligible at 0.0% (1st percentile).
GitHub Breach via Poisoned VS Code Extension
GitHub confirmed that the breach of approximately 3,800 internal repositories originated from a compromised employee device running a poisoned version of the Nx Console VS Code extension (v18.95.0, publisher nrwl.angular-console). The malicious extension was live on the Visual Studio Marketplace for 18 minutes before removal and carried a verified-publisher badge. The attack is attributed to TeamPCP, the cybercriminal group behind the TanStack supply chain compromise (CVE-2026-45321). GitHub has rotated critical secrets and confirmed no customer-facing systems were impacted. OpenAI, Grafana Labs, and Mistral AI were named as downstream victims. Grafana Labs confirmed a breach via a compromised GitHub token, refused to pay ransom, and claims no customer data exposure.
The attack chain began with OIDC credentials harvested in the May 11 TanStack compromise, used to publish the trojanized extension on May 18. TeamPCP has since released the Shai-Hulud framework source code publicly, providing a blueprint for similar worms targeting open-source repositories and developer environments. This marks the first confirmed multi-stage operation in the campaign, with credentials stolen in one attack used to poison a developer tool that then breached GitHub's internal infrastructure.
Microsoft Azure Durable Functions SDK Trojanized (durabletask)
An officially Microsoft-published Python SDK on PyPI (durabletask, the Azure Durable Functions client with roughly 417,000 monthly downloads) was trojanized across three versions (1.4.1 through 1.4.3) during a 35-minute window. Independent reporting characterizes the second-stage payload as carrying a Linux disk wiper. The attack is attributed to TeamPCP as part of their broader Mini Shai-Hulud campaign. The poisoned versions were removed but any systems that installed them during the compromise window should be treated as potentially wiped or backdoored.
Laravel-Lang Supply Chain Attack
Four popular Composer packages maintained by Laravel-Lang were poisoned with malware after attackers rewrote all their Git tags. The affected packages (laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/attributes, laravel-lang/actions) are third-party localization libraries used by Laravel applications. The attack started May 22 and by May 23 all four packages had been poisoned across over 700 historical version tags. The malicious code was never committed to official repositories. Instead, GitHub's feature allowing version tags to point to commits in a fork was exploited to create tags pointed at malicious fork-hosted commits. The malware fingerprints the machine, connects to flipboxstudio[.]info C2, and harvests cloud keys (AWS, GCP, Azure), Docker/Kubernetes configs, HashiCorp Vault tokens, SSH keys, developer credentials, browser passwords, password managers, cryptocurrency wallets, and VPN configurations across Windows, Linux, and macOS.
7-Eleven Data Breach (ShinyHunters)
ShinyHunters stole the personal information of 185,300 people after breaching 7-Eleven's Salesforce environment in April 2026. The company confirmed unauthorized access to systems used to store franchisee documents on April 8. ShinyHunters claimed responsibility April 17 and leaked a 9.4GB archive after 7-Eleven refused to pay ransom. Exposed data includes names, dates of birth, unique email addresses, phone numbers, and physical addresses. ShinyHunters has been targeting Salesforce customers for the past year and breached hundreds of companies, claiming theft of billions of records in the Salesforce Aura data theft attacks and the Salesloft Drift campaign.
Ghost CMS Mass Exploitation (CVE-2026-26980)
Threat actors exploited CVE-2026-26980 to compromise over 700 Ghost CMS websites, including sites belonging to DuckDuckGo, Harvard University, and Oxford University. The vulnerability is a critical SQL injection (CVSS 9.4) in Ghost's Content API that allows unauthenticated attackers to extract the Admin API Key, then use that key to bulk-modify articles and inject malicious JavaScript loaders for ClickFix attacks. The flaw was patched in February 2026 (version 6.19.1) after being discovered by Anthropic using Claude. EPSS score is 63.5% (98th percentile). The campaign began May 7 with at least two different threat clusters competing to poison sites. Nearly half of the hacked sites are personal blogs and independent sites, but dozens belong to software development, tech blogs, AI, cryptocurrency, and university sectors. The injected JavaScript uses a two-stage loader architecture, retrieves the payload at runtime from clo4shara[.]xyz, and employs the commercial Adspect cloaking service to ensure only real victims are served the ClickFix payload.
Kali365 Phishing-as-a-Service (Microsoft 365 OAuth Abuse)
The FBI warned about Kali365, a phishing-as-a-service platform distributed via Telegram that uses device code phishing to hijack Microsoft 365 accounts and bypass MFA. Kali365 first emerged in April 2026 and abuses Microsoft's legitimate OAuth 2.0 Device Authorization grant flow designed for limited-input devices like smart TVs and IoT devices. Threat actors initiate device authorization to generate a code, then trick targets into entering it at microsoft.com/devicelogin via phishing. Once the victim completes MFA, Microsoft issues an OAuth access token granting full account access without requiring additional MFA challenges. Attackers gain access to Microsoft 365, Salesforce, and other SSO-linked SaaS platforms. Kali365 provides AI-generated phishing lures, automated campaign templates, real-time victim-tracking dashboards, and token-capture functionality. Arctic Wolf reported widespread campaigns targeting organizations worldwide, with attackers creating malicious inbox rules to hide activity and registering new devices in victim Microsoft environments. Kali365 operates as a business with admins managing product development, resellers promoting the service, and affiliates conducting attacks. The platform offers device code phishing and an adversary-in-the-middle mode called "Cookie Link" that proxies victims to capture session cookies and tokens.
KnowledgeDeliver LMS Zero-Day (CVE-2026-5426)
A high-severity security flaw (CVSS 7.5) in Digital Knowledge KnowledgeDeliver, a Learning Management System popular in Japan, was exploited as a zero-day to deploy Godzilla web shell and Cobalt Strike Beacon. CVE-2026-5426 stems from hard-coded ASP.NET machine keys in a standardized web.config file provided by the vendor, leading to unauthenticated remote code execution via ViewState deserialization. Threat actors obtained keys from one deployment and used them to compromise other internet-facing KnowledgeDeliver instances. The attack sequence granted attackers full control over the web server's file system by granting "Everyone" permissions, then tampering with JavaScript files to display fake security alerts urging users to install a "security authentication plugin." The malicious script hosted on attacker-controlled domains delivered Cobalt Strike Beacon payloads encrypted with keys using the compromised organization's name, indicating targeted preparation. The vulnerability affected deployments prior to February 24, 2026 and has been patched. EPSS score is 0.1% (24th percentile).
Netherlands Seizes 800 Servers, Arrests Bulletproof Hosting Operators
Dutch authorities arrested the co-owners of MIRhosting and WorkTitans for operating infrastructure used by Russia to carry out cyberattacks, influence operations, and disinformation campaigns inside the EU. The investigation focuses on Stark Industries Solutions, a hosting provider sanctioned by the EU in May 2025 as a staging ground for Russia's intelligence agencies. Andrey Nesterenko (39, The Hague) and Youssef Zinad (57, Amsterdam) were arrested May 18 and charged with violating sanctions law by making economic resources available to EU-sanctioned entities. FIOD seized laptops, phones, and over 800 servers from three businesses in Enschede and Almere and two data centers in Dronten and Schiphol-Rijk. Data reviewed by de Volkskrant shows WorkTitans and MIRhosting were the most-used networks in pro-Russian DDoS attacks on Danish government bodies during the week of Denmark's November 2025 municipal elections. After PQHosting and the Neculiti brothers were sanctioned in May 2025, Stark network assets were transferred to WorkTitans under control of Nesterenko and Zinad, getting connectivity solely through MIRhosting.
ACR Stealer via Fake Claude Download Pages
SANS ISC identified Windows malware distributed via fake Claude download pages impersonating Anthropic's Claude AI assistant. Malicious ads in Google searches lead to concealed URLs at sites.google[.]com, which redirect to pages like fairpoint29[.]com offering a "Download for Windows" button. The download delivers ACR Stealer, a credential theft malware that connects to yw.enhanceblabber[.]cc for C2 traffic. The infection chain involves a corrupted ZIP archive (hxxps://primemetricsa[.]com/1518925), a PowerShell script from creativecommunityinfo[.]art, and a JPEG file from ibb[.]co (possibly steganography or a decoy). The fake Claude pages serve macOS malware when viewed from macOS systems and Windows malware when viewed from Windows systems. This is a persistent campaign with reliable discovery through Google search ads.
Microsoft Fox Tempest Takedown (Rhysida Ransomware Enabler)
Microsoft dismantled Fox Tempest, a cyber threat actor operating upstream in the malware and ransomware supply chain as an enabler for Rhysida ransomware, Oyster, Lumma Stealer, and Vidar. Fox Tempest provided a fraudulent code-signing service that let cybercriminals deploy malware "through the front door" without detection. While bad actors have resold code-signing certificates for at least a decade, Fox Tempest's operation stood out for providing a scalable service supporting extortion, phishing, SEO poisoning, and malware-laced advertising.
Windows Server 2016 Domain Controller Lookup Failures (KB5087537)
Microsoft confirmed a known issue affecting Windows Server 2016 systems running the May 2026 KB5087537 security update. Domain controller discovery fails on servers with hostnames exactly 15 characters long. DCLocator calls (e.g., nltest /dsgetdc:<domain> /pdc) return ERROR_INVALID_PARAMETER, preventing applications and administrative tools from locating a domain controller. This impacts administrative operations requiring DC lookup, such as DFS Namespace management. Windows Server 2016 reached end of mainstream support in January 2022 but extended support was pushed back 5 years. Microsoft is investigating but has not provided a timeline for resolution.
ACR Stealer (Fake Claude Campaign)
Ghost CMS Campaign (CVE-2026-26980)
Lazarus RemotePE
Nimbus Manticore (Iranian APT)
Laravel-Lang Supply Chain Attack
CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws
The Indian Computer Emergency Response Team (CERT-In) issued new guidelines requiring organizations to patch critical vulnerabilities in internet-exposed systems within 12 hours where "feasible." The directive responds to AI-assisted attacks that significantly compress exploitation timelines. CERT-In warns that AI tools and LLMs now automate vulnerability discovery and exploitation, enhancing scale and velocity of attacks. The 38-page blueprint outlines defensive principles including Zero Trust, defense-in-depth, continuous vulnerability monitoring, secure-by-design, SBOM validation, red teaming, and formal AI governance. Organizations should assume breach, prioritize controls based on operational criticality, and maintain visibility into AI systems and operational behavior.
Anthropic Mythos Detected 23,000 Vulnerabilities Across 1,000 OSS Projects
Anthropic's Claude Mythos model discovered over 23,000 potential vulnerabilities across 1,000+ open source software projects. Of these, 1,900 have been reviewed by external security firms and 1,726 confirmed, including over 1,000 rated high or critical severity. Anthropic estimates nearly 3,900 critical/high vulnerabilities will be confirmed based on current findings, potentially reaching 6,200 as scans continue. Over 1,100 unverified findings have been reported to vendors and 75 critical/high issues have been patched. Vendors have published 65 security advisories. Mozilla reported finding 271 Firefox vulnerabilities. Palo Alto Networks found dozens of flaws. Curl found only one low-severity vulnerability, with experts debating whether that reflects AI model failure or Curl's maturity. Anthropic has not developed strong enough safeguards to prevent Mythos misuse but is working to add more organizations to Project Glasswing. References to claude-mythos-1-preview briefly appeared in Claude Code and Claude Security, indicating public rollout preparation.
Check Point: AI-Driven Attacks Have Entered Routine Criminal Use
Check Point Research released the March-April 2026 AI Threat Landscape digest showing AI-driven attacks have entered routine criminal use. A single operator used commercial AI to compromise nine Mexican government agencies and execute over 5,000 automated commands. Malicious configuration files override safety controls, commercialized toolkits are widely available, and stolen API keys enable abuse. Researchers identified phishing campaigns using indirect prompt injections to evade AI-powered email filters by embedding invisible text (zero-size fonts, background-matched colors) that recipients cannot see but AI scanning tools process as attacker instructions during automated security review. A Russian-speaking actor operated a MAGA-themed Telegram channel with 17,000 subscribers, bypassing Gemini safeguards to automate propaganda and credential theft using stolen API keys, cracked WordPress accounts, and drained crypto wallets.
TeamPCP Supply Chain Campaign (CVE-2026-45321)
The TanStack supply chain breach has evolved into a multi-stage campaign. TeamPCP now operates across three package ecosystems (npm, PyPI, VS Code Marketplace) in parallel. The Nx Console VS Code extension compromise (v18.95.0, 18-minute window, verified-publisher badge) used credentials harvested in the TanStack OIDC abuse chain (CVE-2026-45321) to publish a trojanized extension that breached GitHub's internal repositories. A third Mini Shai-Hulud wave pushed 639 malicious package versions across 323 npm packages, including echarts-for-react (1.1M weekly downloads) and size-sensor (4.2M weekly downloads). Microsoft's durabletask Python SDK on PyPI was trojanized across three versions (1.4.1-1.4.3) during a 35-minute window, with second-stage payload characterized as a Linux disk wiper. TeamPCP released the Shai-Hulud framework source code publicly on GitHub, and copycat forks are already running. EPSS score is 0.0% (8th percentile) but impact is widespread.
CVE-2026-26980 (Ghost CMS SQL Injection)
Ghost CMS patched CVE-2026-26980 in February 2026 (version 6.19.1). The vulnerability is a critical SQL injection (CVSS 9.4) in Ghost's Content API allowing unauthenticated attackers to extract Admin API Keys and modify content. Discovered by Anthropic using Claude. EPSS score is 63.5% (98th percentile), indicating high likelihood of exploitation. Over 700 websites confirmed compromised in mass attacks starting May 7.
CVE-2026-5426 (KnowledgeDeliver LMS Hard-Coded Machine Keys)
Digital Knowledge KnowledgeDeliver LMS suffered a zero-day exploit due to hard-coded ASP.NET machine keys (CVSS 7.5). Threat actors leveraged keys from one deployment to compromise other internet-facing instances via ViewState deserialization, deploying Godzilla web shell and Cobalt Strike Beacon. Patched February 24, 2026. EPSS score is 0.1% (24th percentile). Similar vulnerabilities in Sitecore Experience Manager and Gladinet CentreStack/TrioFox have also been exploited.
Healthcare Data Breaches
The Oncology Institute disclosed a third-party cybersecurity incident affecting patient information. Kroll is handling disclosures for the unnamed vendor, with timeline and multi-provider impact pointing to TriZetto Provider Solutions as a possible candidate. TriZetto reported a breach affecting multiple customers and roughly 3.4 million individuals earlier in 2026. Separately, Radiology Associates of Richmond disclosed a breach impacting 266,183 individuals after hackers accessed internal systems on July 25, 2025. RAR's investigation concluded April 6, 2026 confirming theft of names, Social Security numbers, government-issued IDs, financial information (credit/debit card numbers), and medical/health insurance details. Notification letters sent May 21.
Supply chain attacks have reached a new maturity level with TeamPCP's Shai-Hulud framework now publicly available for copycat attackers. The TanStack compromise that began in May continues to cascade through the developer ecosystem, with credentials harvested in one attack used to poison VS Code extensions and breach GitHub's internal infrastructure. The public release of the worm framework gives attackers a ready-made blueprint for targeting open-source repositories and developer environments. Device code phishing via platforms like Kali365 is rapidly displacing traditional credential theft, with OAuth token capture bypassing MFA entirely. The Ghost CMS campaign demonstrates that even patched vulnerabilities continue to yield mass compromises when defenders fail to update within the exploitation window. AI-assisted vulnerability discovery is adding thousands of confirmed high/critical CVEs to an already-overloaded security ecosystem, forcing organizations to compress patching timelines to match AI-accelerated exploitation.