CVE-2026-27771, CVE-2026-45321, CVE-2026-48027, CVE-2026-48172, CVE-2026-8398
Get tomorrow's brief in your inbox
May 28, 2026
Today: CISA added a critical LiteSpeed cPanel plugin flaw to the KEV catalog with a Friday midnight deadline. Ransomware actors from Silent Ransom Group are showing up in person at law firms to steal data directly from workstations. CrowdStrike disrupted the Glassworm botnet that poisoned hundreds of open-source packages targeting developer supply chains.
CISA Adds LiteSpeed cPanel Plugin Flaw to KEV Catalog (CVE-2026-48172)
A critical privilege escalation vulnerability in the LiteSpeed cPanel user-end plugin is under active exploitation. CVE-2026-48172 stems from incorrect privilege assignment in the lsws.redisAble function, allowing unauthenticated remote attackers to execute arbitrary scripts with root privileges. CISA added it to the KEV catalog on May 27 with a May 29 midnight deadline for federal agencies. The flaw affects all versions between v2.3 and v2.4.4. EPSS score is 0.080 (92nd percentile).
grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null. If output appears, examine the IPs, determine if valid, and block if not. Review system logs for actions taken by detected IPs.CISA Adds Three Additional KEV Entries (CVE-2026-8398, CVE-2026-45321, CVE-2026-48027)
Three vulnerabilities added to the Known Exploited Vulnerabilities catalog based on active exploitation evidence. CVE-2026-8398 is an embedded malicious code vulnerability in Daemon Tools Lite, CVE-2026-45321 is an unspecified TanStack vulnerability, and CVE-2026-48027 is embedded malicious code in Nx Console. EPSS scores for the two rated entries are minimal (8th and 12th percentile), suggesting targeted exploitation rather than broad scanning.
Silent Ransom Group Targets Law Firms with In-Person Data Theft
The FBI warned that Silent Ransom Group (also known as Luna Moth, Chatty Spider, UNC3753) is targeting law firms through social engineering, including in-person appearances. Active since 2022 and focused on law firms since spring 2023, the group poses as IT personnel via phone calls and phishing emails to establish remote access using legitimate tools. In evolved tactics, SRG actors now physically appear at victim locations to insert storage devices into workstations. The group conducts data theft extortion attacks without encryption, stealing sensitive client data and threatening to leak or sell it. Legal was the fourth most targeted industry by ransomware in early 2026. SRG uses WinSCP or hidden/renamed Rclone to exfiltrate data to Google Drive, OneDrive, or external drives. The group faces no arrests or infrastructure disruptions to date and likely operates from Russia.
Reconstructing Akira Ransomware Kill Chain from Logs
SANS published a detailed forensic walkthrough of an Akira ransomware intrusion at a mid-sized organization using only SSLVPN syslog and Windows EVTX exports. Initial access came through a brute-force attack against a single local SSLVPN account that had been disabled in Active Directory but remained provisioned on the firewall. The account had no MFA and survived a six-hour credential stuffing attack from a single hosting-provider IP. Post-VPN, the attacker pivoted to a jump host and ran textbook discovery commands (nltest, net group, whoami, AdFind). About 24 hours later, EID 4769 events showed RC4-encrypted Kerberoasting attempts against three service accounts within a 90-second window. The reconstruction demonstrates the value of joining perimeter and endpoint logs to identify attack sequencing days before encryption.
CrowdStrike Disrupts Glassworm Botnet Targeting Developer Supply Chain
CrowdStrike, in partnership with Google and Shadowserver, disrupted all four command-and-control channels associated with Glassworm, a persistent supply chain campaign targeting software developers since early 2025. Glassworm operators systematically targeted developers through trojanized VS Code extensions on Microsoft VS Code Marketplace and Open VSX, malicious npm and Python packages, and compromised GitHub repositories (over 300 poisoned using stolen developer credentials). The malware delivered data theft capabilities (credentials, crypto wallets, system profiling) and a WebSocket-based JavaScript RAT called GlassWormRAT that harvested browser data, screenshots, keystrokes, and clipboard content. Infected hosts were converted into covert infrastructure: SOCKS proxies, hidden VNC servers, and remote execution nodes. The operation used four resilient C2 channels simultaneously: Solana blockchain dead drop resolver, BitTorrent DHT queries, Google Calendar event titles as dead drops, and direct connections to commercial VPS infrastructure. All four channels were neutralized simultaneously. The operators are likely Russia-based based on CIS country execution checks and Russian-language comments in code.
SymJack Attack Hijacks AI Coding Agents for Supply Chain Attacks
Adversa AI disclosed SymJack, a novel attack that turns AI coding agents into supply chain attack delivery systems by hijacking symlinks in the development process. The attack requires attacker control of a coding agent repo, a malicious MCP server, and a developer using an AI coding tool. A malicious symlink is renamed to appear innocuous but redirects to the malicious MCP server. A cp command automatically inserts the attacker's payload into the agent's configuration, registering the malicious MCP server. On next restart, the planted server spawns and the attacker's code runs unsandboxed, able to steal SSH keys, cloud tokens, and browser sessions or destroy production assets. If the attack targets CI pipelines, the blast radius expands with no further user interaction since CI runners contain deployment secrets. Adversa tested the attack against five major coding agents (Claude Code, Gemini CLI, Antigravity CLI, Cursor Agent CLI, Grok Build CLI, GitHub Copilot CLI) and found it worked in all cases. Google, Cursor, and Anthropic initially rejected the report, but Anthropic quietly hardened Claude Code weeks later to resolve symlinks before approval and show the real destination path.
Active Directory Password Policy Best Practices
Analysis of AD password policy trade-offs between security and user frustration. Traditional complexity rules lead to predictable patterns like "Password!2026". The modern approach prioritizes length over complexity with passphrases. NIST recommends allowing passwords up to 64 characters; raising the minimum to 15+ characters strengthens security. Solutions like Specops Password Policy block weak passwords at creation using custom banned word lists and checking against 5.4+ billion known breached credentials. Length-based aging ties expiration periods to password length, encouraging longer passwords with extended or removed expiry unless compromise is detected. Mandatory password expiration without evidence of compromise leads to minimal tweaks and incremental changes. Password managers remove the burden of remembering dozens of credentials and prevent reuse across systems.
Gitea Private Container Image Exposure (CVE-2026-27771)
A vulnerability in Gitea allows unauthenticated remote attackers to pull private container images from Gitea deployments without credentials. CVE-2026-27771 (CVSS 8.2) affects all versions prior to 1.26.2. The private designation on container repositories did not deliver expected protection. The flaw went undetected for close to four years and likely impacts more than 30,000 deployments across over 30 countries, with the majority in China, the U.S., Germany, France, and the U.K. Affected organizations span healthcare providers, aerospace manufacturers, retail infrastructure, and ISPs. Any fork of Gitea should be treated as potentially impacted. Forgejo has been confirmed impacted.
[service].REQUIRE_SIGNIN_VIEW=true in Gitea configuration as a temporary workaround (note: this isn't ideal if some containers are meant to be public). Review container pull logs for unauthorized access. Rotate secrets in any container images that may have been exposed.Microsoft Security Update Guide Linux CVE Publications
Microsoft published 24 Linux kernel CVEs to its Security Update Guide, covering various subsystems including md/raid10 deadlocks, media drivers, HID drivers, netfilter, XFS, thermal core, RDMA, rxrpc crypto, KVM, ALSA, iommu, openvswitch, selinux, UDF, net/smc, and BPF. These entries have minimal metadata ("Information published") and no CVSS scores or exploitability assessment. Most have EPSS scores in the 5th-12th percentile where reported, indicating low probability of exploitation. These appear to be Linux kernel fixes that Microsoft is tracking for WSL or Azure Linux compatibility.
Lastwall Raises $11.5M for Quantum-Resilient Identity Platform
Lastwall announced $11.5 million in Series A extension funding for its identity security and quantum resilience platform. The company provides secure identity management for defense and government organizations, focusing on credential attacks, phishing, and post-quantum threats. Its IDCommand Suite combines zero-trust architecture with PKI and passwordless authentication in three configurations: Enterprise (cloud-native), Tactical (field-deployable on-premises for DDIL environments), and BOLT (biometric add-on for AAL-3 assurance). The solution evaluates 200 contextual signals (keystroke cadence, mouse movement, hardware profiling) to assign risk scores and trigger additional authentication when needed. Quantum Shield is a quantum-safe TLS terminator and load balancer using NIST-approved post-quantum cryptography algorithms with backward compatibility. The company earned FedRAMP Moderate Authorization and has secured U.S. government systems.
Developer supply chains remain under sustained pressure with two major stories today. CrowdStrike's disruption of Glassworm shows the operational maturity of Russia-linked actors poisoning open-source ecosystems at scale, while the SymJack research demonstrates how AI coding agents introduce new trust boundaries that attackers are already exploiting. The pattern across both is automation: Glassworm automated package poisoning and infrastructure conversion, while SymJack automates payload injection through developer approval workflows. Ransomware tactics continue to diversify, with Silent Ransom Group's shift to in-person data theft representing a rare and concerning escalation beyond purely technical attack chains. CISA's addition of four actively exploited vulnerabilities in one day, including a critical cPanel flaw with a Friday deadline, underscores the velocity required for vulnerability response in 2026.