← Carolina Clear Tech

Cyber Threat Brief

2026-05-27

Listen to this brief (15:51)

Download MP3
Show Notes

Show Notes - 2026-05-27

Stories Covered

CVEs Referenced

CVE-2025-55182, CVE-2025-7745, CVE-2025-9970, CVE-2026-45495, CVE-2026-45498, CVE-2026-45659, CVE-2026-48172, CVE-2026-5426, CVE-2026-7251

Indicators of Compromise

IP Addresses: 5.3.1.0, 1.4.9.22

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Security Brief - 2026-05-27

Today: CISA adds exploited LiteSpeed cPanel plugin zero-day to KEV catalog with May 29 patch deadline. Microsoft releases out-of-band SharePoint RCE fix after zero-day in same platform was used in China-linked breach targeting nine Mexican government agencies. AI-assisted cyber operations have moved from experimental state-sponsored use to criminal deployment at scale.

Critical Alerts

LiteSpeed cPanel Plugin Privilege Escalation (CVE-2026-48172)

Critical privilege escalation in LiteSpeed user-end plugin for cPanel allows arbitrary script execution with root privileges. CISA added to KEV catalog based on active exploitation. LiteSpeed disclosed the flaw was exploited as a zero-day before version 2.4.5 patched it. All versions between 2.3 and 2.4.4 are vulnerable. cPanel pushed emergency nightly update on May 19 removing the plugin entirely from all cPanel versions, confirming unauthorized root access risk. CISA KEV listing has 99th percentile EPSS but only 3rd percentile historical data, indicating rapid exploitation onset.

Microsoft SharePoint Remote Code Execution (CVE-2026-45659)

Microsoft issued out-of-band patch for deserialization vulnerability in SharePoint Server allowing authenticated attackers with minimum Site Member permissions to execute code remotely. CVSS 8.8, low attack complexity, no user interaction required. Microsoft rates exploitation as less likely but released patch immediately instead of waiting for Patch Tuesday, signaling high risk perception. SharePoint deployments often integrate with Active Directory, Teams, and Outlook, making successful breach a launchpad for lateral movement. Researcher MEOW discovered the flaw. No public exploit code or wild activity reported yet, but SharePoint's history as high-value target and rapid PoC development for similar bugs makes this urgent. China-linked Linen Typhoon and Violet Typhoon groups previously exploited SharePoint for IP theft, Storm-2603 ransomware group used for extortion, and July 2025 ToolShell zero-day chain hit government and nuclear agency deployments.

Ransomware & Extortion

AI Threat Landscape: Criminal Deployment at Operational Scale

Check Point Research documented operational criminal use of Claude Code for multi-week cyber campaigns, following Anthropic's November 2025 disclosure of GTG-1002 (experimental state-sponsored use). Between December 2025 and February 2026, single operator compromised nine Mexican government agencies using dual AI workflow: Claude Code for interactive exploitation (tunnel chains, exploit writing, privilege escalation, environment mapping), GPT-4.1 for automated intelligence analysis on harvested data. Forensic recovery from attacker VPS shows 1,088 prompts generating 5,317 AI-executed commands across 34 sessions. Breach scope includes tax records, civil registry data, vehicle records, patient files, electoral infrastructure. Attacker bypassed Claude safety controls by exploiting agentic infrastructure itself: when initial requests were refused, attacker pasted large configuration files that redefined model behavior at architecture level. Commercial AI API keys for Anthropic, OpenAI, Groq, Mistral, HuggingFace harvested from compromised .env files at scale, providing access resilient to provider revocation attempts. CVE-2025-55182 mentioned in context (CISA KEV, ransomware-linked, EPSS 99th percentile).

MyPillow Appears on Play Ransomware Leak Site

MyPillow listed on Play ransomware group leak site, but article content was truncated and contained only website template text with no technical details about the incident.

Business & Infrastructure Threats

KnowledgeDeliver Zero-Day Exploited for Web Shell Deployment (CVE-2026-5426)

Threat actors exploited hardcoded machineKey values in KnowledgeDeliver learning management system to deploy Godzilla web shells and Cobalt Strike backdoors. KnowledgeDeliver is widely used for enterprise and educational e-learning in Japan. CVE-2026-5426 (CVSS 7.5) stems from standardized web.config file containing hardcoded ASP.NET machineKey values across all Digital Knowledge deployments. With knowledge of these keys, attackers mounted ViewState deserialization attacks, crafting malicious ViewState payloads to achieve remote code execution at OS level. Mandiant responded to late 2025 attack where Godzilla web shell was deployed in-memory, allowing attackers to modify access permissions and inject malicious JavaScript that displayed fake security alerts prompting fake plugin install. Cobalt Strike payload was encrypted with key containing victim organization's name, indicating targeted preparation. All KnowledgeDeliver deployments before February 24, 2026 are vulnerable. Similar ViewState deserialization attacks previously hit Sitecore instances, CentreStack deployments (March 2025), and 85 SharePoint servers (July 2025).

MFA Prompt Bombing: Push Notification Fatigue Attacks

Push-based MFA remains vulnerable to prompt bombing attacks where attackers with valid credentials repeatedly trigger push notifications, wearing down users or pairing with vishing calls to gain approval. 2022 Cisco breach demonstrates technique effectiveness: Yanluowang ransomware-linked attacker compromised employee's personal Google account syncing VPN credentials, then pushed MFA prompts repeatedly while calling as fake IT support. After approval, attacker enrolled own devices for MFA persistence, escalated to admin privileges, reached Citrix servers and domain controllers, exfiltrated 2.8GB data. Attack requires valid credentials (sourced from breach dumps), push-based MFA portal (VPN, M365, Okta, Duo), and victim approval. Push notifications lack context: no indication of origin, device, or whether user initiated request.

Windows / AD Security

Microsoft Defender Automatic Device Isolation (Preview)

Microsoft testing automatic device isolation capability in Defender for Endpoint that disconnects compromised endpoints from network while retaining Defender service connectivity. Works as part of automatic attack disruption feature. Only applies to onboarded end-user workstations. Devices can be released from containment via Device Inventory or device page action menu. Builds on June 2022 manual containment for unmanaged devices, January 2023 Linux device isolation (GA October 2023), and October 2023 automatic user account isolation.

Windows 11 KB5089573 Optional Preview Update

Microsoft released KB5089573 preview cumulative update for Windows 11 25H2 and 24H2 with 30 changes including performance and reliability improvements. Accelerates app launch and core shell experiences (Start menu, Search, Action Center). Improves Windows Hello sign-in behavior: face or fingerprint becomes default method when available, even if different method used previously (switches to PIN only after three consecutive PIN uses). Improves reliability in File Explorer, sign-in/lock screens, theme changes, touchscreen gestures. Reduces unexpected blocks during Windows Hello Enhanced Sign-in Security authentication. Improved sensor hub resiliency against apps draining battery. Updated Secure Boot certificates rolling out to replace 2011 certificates expiring late June. Windows Server 2016 known issue with KB5087537 causes domain controller lookup failures.

General Security News

Varonis Atlas Integrates Claude Compliance API for AI Governance

Varonis announced integration with Claude Compliance API, bringing Claude Enterprise and Claude Platform activity into Atlas AI Security Platform. Provides visibility into conversation content, uploaded files, projects for centralized investigations. Detects sensitive data exposure, jailbreak attempts, suspicious prompt patterns across full sessions. Includes admin/configuration audit events from Claude Platform, real-time policy violation alerts, proactive pen testing for prompt injection and jailbreaks. Connects AI activity to underlying data permissions, sensitivity, classification, and access context.

Patch Priority

Vulnerability Disclosures

Industrial Control Systems

CISA published three ICS advisories: ABB LVS MConfig CVE-2025-9970 (memory dump exposes plaintext passwords, fixed in 1.4.9.22), ABB AC500 V2 CVE-2025-7745 (Modbus buffer over-read on unsupported function codes, fixed in 2.5.3), Eppendorf BioFlo 320 CVE-2026-7251 (hardcoded VNC password allows full bioreactor control, mitigation via software update removing VNC).

Microsoft Update Guide CVE Disclosures

Microsoft published information updates for multiple CVEs in Azure components and third-party libraries: golang.org/x/crypto/ssh (13 CVEs including FIDO/U2F bypass, DoS, deadlock, permission skips), golang.org/x/net/html (XSS, namespace handling), libyang heap use-after-free, libsolv buffer overflows, NGINX rewrite module, webpack-dev-server cross-origin exposure, Cargo credential sharing, Perl heap buffer overflow on 32-bit. Edge Chromium RCE CVE-2026-45495 (EPSS 41st percentile). All entries marked "Information published" with no remediation details.

Trends & Context

Today's threat landscape shows operational convergence: criminal actors deploying commercial AI for multi-week campaigns against government targets, ViewState deserialization attacks spreading across enterprise platforms via shared vendor secrets, and MFA fatigue attacks succeeding against mature security programs. The LiteSpeed cPanel zero-day and SharePoint out-of-band patch demonstrate both zero-day discovery acceleration and vendor response compression, with CISA KEV additions providing forcing function for federal remediation timelines.