CVE-2024-39930, CVE-2024-39932, CVE-2024-39933, CVE-2025-8110, CVE-2026-33825, CVE-2026-35616, CVE-2026-40425, CVE-2026-41091, CVE-2026-42250, CVE-2026-42496, CVE-2026-42929, CVE-2026-42941, CVE-2026-42951, CVE-2026-44611, CVE-2026-45498, CVE-2026-45585, CVE-2026-46107, CVE-2026-46155, CVE-2026-46186, CVE-2026-46195, CVE-2026-46232, CVE-2026-48027, CVE-2026-5386, CVE-2026-8398, CVE-2026-9538
Get tomorrow's brief in your inbox
Today: Gogs zero-day enables remote code execution on 2,400+ Internet-exposed servers. DAEMON Tools supply chain attack added to CISA KEV with May 30 deadline. Microsoft patches multiple zero-days under active exploitation after public disclosure dispute. GitHub and Nx Console supply chain intrusions target developer CI/CD pipelines.
Gogs Zero-Day Allows Remote Code Execution
An unpatched critical severity argument injection flaw in the Gogs self-hosted Git service (versions 0.14.2 and 0.15.0+dev) allows authenticated attackers to gain remote code execution via malicious branch names during rebase merge operations. The vulnerability affects all default-configured Gogs servers because registration is enabled by default with no repository creation limits. Attackers can create an account, enable rebase merging in repository settings, and exploit a --exec flag injection in the Merge() code path to execute arbitrary code as the Gogs server process user. This grants access to all repositories including private repos, credentials (password hashes, API tokens, SSH keys, 2FA secrets), and enables lateral movement. Shadowserver tracks over 2,400 Gogs servers exposed online, primarily in Asia and Europe. The maintainers acknowledged the report on March 28 but have not released a patch or provided a status update despite the researcher reporting the flaw on March 17.
DAEMON Tools Supply Chain Attack (CVE-2026-8398)
CISA added the DAEMON Tools supply chain compromise to its Known Exploited Vulnerabilities catalog with a May 30, 2026 remediation deadline for federal agencies. Attackers gained unauthorized access to AVB Disc Soft's build or distribution infrastructure and trojanized three binaries: DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe. The malicious files were digitally signed with the legitimate AVB Disc Soft code-signing certificate, allowing silent distribution through trusted update channels. The vulnerability has CVSS v4 score of 9.3 and EPSS of 0.330 (97th percentile), indicating high likelihood of exploitation.
Multiple Windows Zero-Days Under Active Exploitation (CVE-2026-33825, CVE-2026-41091, CVE-2026-45498)
Microsoft confirmed active exploitation of three zero-day vulnerabilities (BlueHammer/CVE-2026-33825, RedSun/CVE-2026-41091, and UnDefend/CVE-2026-45498) disclosed publicly by researcher Chaotic Eclipse without prior coordination. BlueHammer has CISA KEV deadline of May 6, while RedSun and UnDefend have June 3 deadlines. The researcher disclosed six zero-days total (including YellowKey/CVE-2026-45585, GreenPlasma, and MiniPlasma) after alleging Microsoft deleted their bug reporting account, failed to communicate during the disclosure process, and humiliated them publicly. The researcher threatened to release additional exploits on July 14, 2026 that "will make sure your bones are shattered." Microsoft's security teams worked around the clock to develop updates and urged researchers to follow Coordinated Vulnerability Disclosure rather than releasing proof-of-concept code that threat actors can weaponize. GitHub took down the researcher's account, leading them to repost exploit code on GitLab before that account was also blocked.
GitHub and Nx Console Supply Chain Intrusions (CVE-2026-48027)
CISA is responding to multiple developer ecosystem supply chain intrusions including a malicious Nx Console Visual Studio Code extension (version 18.95.0) that compromised a GitHub employee's device and led to unauthorized access and exfiltration of internal GitHub repositories. The malicious extension was distributed through VS Code's automatic update mechanism, meaning systems with Nx Console previously installed received the malicious build without manual action. CVE-2026-48027 has been added to CISA KEV (ransomware-linked) with June 10 remediation deadline and EPSS of 0.268 (96th percentile). A separate "Megalodon" campaign injected malicious GitHub Action workflows to harvest CI/CD secrets, cloud credentials, and tokens from public repositories.
FortiClient EMS Vulnerability Exploited for Infostealer Deployment (CVE-2026-35616)
A critical FortiClient Endpoint Management Server vulnerability (CVE-2026-35616, CVSS 9.1, CISA KEV due April 9) patched in April continues to be exploited in fresh attacks deploying EKZ Infostealer malware. The flaw allows unauthenticated remote code execution via crafted requests. Threat actors used FortiClient's own VPN scripting workflows to push malicious PowerShell commands to managed endpoints disguised as a fake Fortinet endpoint patch. Because FortiClient EMS functions as central management for all FortiClient devices, access to the appliance enabled code execution on every managed endpoint. The infostealer targets Chrome, Edge, Firefox, and other Chromium/Gecko browsers for credential, cookie, and autofill data exfiltration over HTTP. EPSS score of 0.432 (98th percentile) indicates very high exploitation likelihood.
The Gentlemen Ransomware: Self-Propagating Go Encryptor
Microsoft Threat Intelligence published detailed analysis of The Gentlemen ransomware-as-a-service (RaaS), a financially motivated threat tracked as Storm-2697. The ransomware emerged mid-2025 as a closed group, began offering RaaS to affiliates in September 2025, and recently established an official partnership with BreachForums to recruit penetration testers and initial access brokers. Written in Go and obfuscated with Garble, The Gentlemen uses per-file ephemeral Curve25519 keys with XChaCha20 stream cipher and combines strong encryption with aggressive self-propagation using simultaneous lateral movement methods. The malware accepts command-line arguments for encryption scope, speed, lateral movement, and post-encryption behaviors, with --full mode spawning two child processes (--system for local volumes under SYSTEM privileges, --shares for network shares). Speed flags (--fast, --superfast, --ultrafast) control how much of large files is encrypted (default 9% per-chunk for files over 1 MB). The operators use double extortion tactics, encrypting data while exfiltrating sensitive information. Microsoft observed impacts across education, transportation, healthcare, and financial industries in North America, South America, Europe, Africa, and Asia.
1,350 C2 Servers Across Middle East Infrastructure
Hunt.io identified over 1,350 command-and-control servers across 98 Middle East infrastructure providers between February 1 and May 1, 2026. C2 infrastructure represents 96.8% of malicious activity, far exceeding phishing infrastructure (0.5%) and publicly reported IOCs (0.5%), while malicious open directories account for 2.2%. Saudi Arabia's STC (Saudi Telecom Company) hosts 981 C2 servers, representing 72.4% of all detected C2 infrastructure in the region. IoT-focused botnets (Hajime, Mozi, Mirai) combined with offensive frameworks (Tactical RMM, Cobalt Strike, Sliver) represent the dominant malware families.
Azure Backup for AKS Privilege Escalation Flaw
Microsoft silently fixed a privilege escalation flaw in Azure Backup for AKS that allowed a user with only "Backup Contributor" Azure role (zero Kubernetes permissions) to gain cluster-admin on any AKS cluster. The vulnerability carries CVSS score of 9.9 but does not have a CVE ID. Microsoft initially rejected the vulnerability report as "AI-generated content" but appears to have patched the issue since March 2026, enforcing additional validation checks that did not exist previously. The flaw allowed non-Kubernetes users to escalate to full cluster control through Azure Backup management pathways.
Romanian Cybercrime Operator Sentenced to 56 Months
A 46-year-old Romanian national, Catalin Dragomir, was sentenced to 56 months in prison for breaking into an Oregon state government office network in 2021 and other U.S. cyber attacks. Dragomir pleaded guilty to aggravated identity theft and obtaining information from a protected computer. He was arrested in Romania in November 2024 and extradited to the U.S. in January 2025. Dragomir sold access to the compromised Oregon government computer after providing prospective buyers with samples of personal identifying information. He also sold access to numerous other victim networks across the United States, causing losses of at least $250,000.
IBM and Red Hat Commit $5 Billion to "Project Lightwell" for Open Source Supply Chain Security
IBM and Red Hat announced Project Lightwell, a joint initiative backed by $5 billion and over 20,000 engineers to systematically secure open source software across enterprise supply chains. The project establishes an "enterprise clearinghouse" leveraging AI to identify, triage, prioritize, and validate vulnerabilities and fixes across open source codebases. Engineers will focus on upstream maintenance with open source community leaders, high-volume AI-assisted vulnerability reviews, and secure patch development. Validated patches and lifecycle management features will be delivered through commercial software subscriptions for platforms including Linux, Java, Kubernetes, Kafka, Ansible, Terraform, Flink, and Cassandra. IBM currently uses over 62,000 open source packages across its enterprise footprint. Initial participants include Bank of America, BNY, Citi, Goldman Sachs, JPMorgan Chase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa, and Wells Fargo.
MacGregor Voyage Data Recorder (VDR) G4e
Five vulnerabilities in MacGregor Voyage Data Recorder (VDR) G4e versions before V5.250 could allow attackers to gain administrator access. CVE-2026-42941: default username and password with no enforced password change. CVE-2026-42951: authenticated users can download device backup including account data and password hashes. CVE-2026-44611: passwords stored with weak hashing susceptible to brute force. CVE-2026-42929: default accounts with hard-coded credentials. CVE-2026-40425: administrator account can directly edit authentication files including root password. Affects maritime transportation systems worldwide.
KMW CCTV Security Cameras (CVE-2026-5386)
KMW CCTV camera models KM-IP521 and KM-IP421 are vulnerable to unauthenticated password reset allowing attackers to remotely reset administrator password to a known value without authentication, granting full access to camera feeds and settings.
Perl Archive::Tar Vulnerabilities
CVE-2026-42496: Archive::Tar versions before 3.08 for Perl extract symlinks with attacker-controlled targets outside extraction directory. CVE-2026-9538: Archive::Tar versions before 3.10 allows memory exhaustion via attacker-controlled entry size field in tar header. Both have low EPSS scores (12th percentile) indicating low current exploitation likelihood.
Multiple Linux Kernel CVEs
Microsoft Security Update Guide published 22 Linux kernel vulnerabilities (CVE-2026-46107 through CVE-2026-46232) covering SMB client bugs, network stack issues, memory safety flaws, and driver problems. All have EPSS scores in the 4th-12th percentile range indicating low current exploitation activity. Specific issues include SMB client out-of-bounds read (CVE-2026-46155), DACL validation (CVE-2026-46195), virtio Bluetooth header validation (CVE-2026-46186), and various use-after-free conditions.
bzip2 Off-by-One Vulnerability (CVE-2026-42250)
Off-by-one error leading to out-of-bounds write in bzip2 compression library. No EPSS score or KEV listing, suggesting limited current exploitation context.
Supply chain attacks dominate the threat landscape with DAEMON Tools, Nx Console, and GitHub intrusions all demonstrating how adversaries compromise trusted software distribution mechanisms. The pattern of trojanizing legitimate code-signing certificates and update channels continues to be effective. Meanwhile, the public dispute between Microsoft and security researcher Chaotic Eclipse highlights the tension between coordinated disclosure and researcher frustration with vendor responsiveness, resulting in three actively exploited zero-days and a threatened July 14 release of additional exploits. The self-propagating capabilities of The Gentlemen ransomware and the massive Middle East C2 infrastructure footprint suggest threat actors are investing in scalable, automated attack platforms that can rapidly compromise entire environments once initial access is achieved.