CVE-2025-8110, CVE-2026-0257, CVE-2026-39987, CVE-2026-9872, CVE-2026-9873, CVE-2026-9874, CVE-2026-9875, CVE-2026-9876
Domains:
openew[.]app
Get tomorrow's brief in your inbox
Today: Palo Alto GlobalProtect bypass is now actively exploited with CISA adding CVE-2026-0257 to KEV (patch by June 1). Critical zero-day in Gogs Git service has a Metasploit module but no patch after two months. Supply chain attacks hit npm and NuGet with credential-stealing packages targeting AWS, Vault, and Brazilian banking credentials.
Gogs Zero-Day Exposes Servers to Remote Code Execution (CVE-2025-8110)
Gogs, the open source Git service, has a critical (CVSS 9.4) zero-day enabling remote code execution through pull requests with malicious branch names. The vulnerability affects Windows, Linux, and macOS servers running default configurations. During 'Rebase before merging' operations, the merge function passes the pull request's base branch name to git rebase without preventing argument injection, allowing attackers to inject the --exec flag to execute shell commands. Since Gogs ships with open registration enabled by default, unauthenticated attackers can create accounts and exploit the flaw without interaction from other users. Rapid7 reports the vulnerability has CISA-KEV status (due February 2) and EPSS score of 0.223 (96th percentile). Gogs maintainers received the vulnerability report in mid-March but have not released a patch as of this writing.
PAN-OS GlobalProtect Authentication Bypass Under Active Exploitation (CVE-2026-0257)
Palo Alto Networks PAN-OS and Prisma Access GlobalProtect portal and gateway have come under active exploitation for CVE-2026-0257 (CVSS 7.8), an authentication bypass allowing attackers to establish unauthorized VPN connections. The vulnerability affects firewalls with GlobalProtect portal or gateway configured when authentication override cookies are enabled and a specific certificate configuration exists. Rapid7 identified successful exploitation across numerous customers, with the earliest attempts dating back to May 17, followed by a second wave on May 21. In two cases, attackers obtained VPN IP assignments after cookie authentication, granting access to the internal network. CISA added CVE-2026-0257 to KEV with a June 1, 2026 remediation deadline. EPSS score is currently 0.001 (20th percentile).
Marimo Post-Exploitation via LLM Agent (CVE-2026-39987)
Attackers exploited CVE-2026-39987, a critical pre-auth RCE in Marimo (all versions prior to 0.23.0), to compromise an internet-reachable Marimo notebook and conduct post-exploitation using an LLM agent. Sysdig observed the attack on May 10, 2026: the attacker extracted cloud credentials from the compromised host, replayed them through a fanned-out egress pool to retrieve an SSH private key from AWS Secrets Manager, and used the key to drive eight parallel SSH sessions against a downstream SSH bastion server. The attacker exfiltrated the schema and full contents of an internal PostgreSQL database in under two minutes. Sysdig identified four indicators of LLM-driven activity, including improvised database dumps, Chinese-language planning comments leaking in the command stream, machine-readable command formats with delimiters and bounded output, and value handoffs extracted from prior tool output. CVE-2026-39987 has CISA-KEV status (due May 7) and EPSS score of 0.822 (99th percentile).
Silent Ransom Group Escalates to Physical Intrusions
FBI issued a flash report warning that Silent Ransom Group (SRG, aka UNC3753, Luna Moth, Chatty Spider) is executing social engineering operations against U.S. legal and financial institutions with in-person data theft. The attack chain begins with attackers posing as internal IT support personnel via typosquatted helpdesk domains, using phishing emails or phone calls to urge employees to contact them. Attackers attempt to establish remote desktop sessions to exfiltrate data, but when remote access fails, SRG sends an operative directly to the victim's physical location. Unidentified individuals attempt to gain building access to manually insert USB flash drives or external hard drives into targeted computers. After obtaining information, the gang sends ransom demands threatening to publish stolen data on leak sites while simultaneously harassing employees and external clients by phone to force financial negotiations. SRG split from the Conti syndicate in early 2022 and has historically relied on targeted callback phishing.
Russia-Linked GREYVIBE Targets Ukraine with AI-Powered Campaigns
WithSecure attributed ongoing attacks against Ukraine and Ukraine-related entities since August 2025 to GREYVIBE, a Russian-speaking threat actor operating in the Russian time zone. The group leverages spear-phishing emails, fake captcha pages, and fraudulent Ukrainian adult club websites to deliver malware. Attack chains include PhantomMail (JavaScript-based loaders delivering PhantomRelay PowerShell RAT), PhantomClick (ClickFix-style fake CAPTCHA pages on Zoom and LAPAS domains), PrincessClub (fake adult sites delivering FallSpy on Android and PhantomRelayV1 or LegionRelay on Windows), DroneLink (fake charitable foundations supporting Armed Forces of Ukraine), and Nebo (FallSpy sample mimicking Russian-language login screen). Victimology spans military, government, civilian, and business-related organizations. Evidence indicates GREYVIBE relies on generative AI (Ideogram AI, OpenAI ChatGPT, Google Gemini) to assist with image generation, malware development, obfuscation, loader scripts, backend infrastructure, and post-compromise commands. WithSecure assesses the group as low-to-moderately sophisticated, suffering from OPSEC blunders while employing AI-assisted tooling.
The Com Criminal Collective Funds Violence via Cybercrime
Flashpoint analysis of The Com confirms the disturbing cybercriminal group (comprising ShinyHunters, Lapsus$, and Scattered Spider) uses its hacker wing to support child pornography generation, trafficking, murder, and other violent crimes. The Com operates in three subsets: IRL Com (physical attacks like muggings and arson), Extortion Com (grooming and sextorting children into creating pornography or acting violently), and Hacker Com (breaching corporations, SIM swaps, DDoS, ransomware). The overlap between subsets is significant. The Com targets cloud and SaaS platforms (Okta, Salesforce, Microsoft 365) and skews young, recruiting from gaming communities and social media. Unit 221B CEO Allison Nixon notes that any given hacker in The Com has a much higher than average probability of possessing or forcing the creation of CSAM, and sextorters have a much higher than average probability of engaging in fraud for income.
Malicious npm Packages Abuse Dependency Confusion to Profile Environments
Microsoft Threat Intelligence uncovered 33 malicious npm packages registered under organizational scopes mirroring real internal corporate namespaces, employing dependency confusion to deploy an obfuscated reconnaissance payload. On May 28-29, 2026, threat actors operating under three maintainer aliases (mr.4nd3r50n, ce-rwb, t-in-one) published packages impersonating internal corporate packages across nine organizational scopes (@cloudplatform-single-spa, @wb-track, @data-science, @ce-rwb, @payments-widget, @travel-autotests, @t-in-one, @capibar.chat, @sber-ecom-core). Packages set homepage, repository, bugs, and author fields to fabricated but realistic-looking internal infrastructure URLs (GitHub Enterprise, Jira, documentation portals). Once installed, packages download and execute an obfuscated reconnaissance payload from an attacker-controlled C2 server. The payload runs silently during npm install in reconnaissance-only mode, collecting system information, hostnames, environment variables, and developer context. Architecture includes a RECON_ONLY flag that can be toggled server-side for full exploitation in follow-on attacks. npm team took down repos and users after Microsoft's investigation.
Malicious Sicoob NuGet Package Steals Brazilian Banking Credentials
Socket discovered a malicious NuGet package masquerading as a C# SDK for Sicoob, one of Brazil's largest cooperative financial systems, to siphon client IDs and PFX certificates. Versions 2.0.0 through 2.0.4 of "Sicoob.Sdk" contain functionality to exfiltrate PFX certificates used to authenticate businesses with the Sicoob banking network for automating banking operations (instant payments, dynamic Pix QR codes). When a developer instantiates SicoobClient with a client ID, PFX file path, and PFX password, the package reads the PFX file, Base64-encodes its contents, and sends the client ID, PFX password, and encoded PFX data to a hardcoded Sentry endpoint. The package also captures raw Boleto API responses via a separate Sentry path, exposing transaction details, payment status, amounts, due dates, identifiers, and payer/payee data. The package was surfaced by Google Search AI Mode as a legitimate C# library. The linked GitHub repository is clean, but the malicious data-stealing functionality is introduced only in the package uploaded to NuGet. NuGet blocked the package after responsible disclosure. The profile "sicoob" has listed 11 other NuGet packages with collectively 6,000 downloads.
14 Malicious npm Packages Target AWS and CI/CD Secrets
Microsoft Defender Security Research Team discovered 14 malicious npm packages typosquatting OpenSearch, ElasticSearch, DevOps, and environment-configuration libraries to harvest AWS credentials, HashiCorp Vault tokens, npm tokens, and CI/CD pipeline secrets. Packages were published by a single threat actor named "vpmdhaj" ([email protected]) on May 28, 2026. The packages launch a purpose-built credential harvester through a preinstall hook. All packages have been removed from npm.
TrapDoor Supply Chain Campaign Hits 176 npm Packages
Security researchers uncovered TrapDoor, a coordinated software supply chain campaign distributing credential-stealing malware across npm, PyPI, and Crates.io. Starting on May 2, the campaign targeted multiple ecosystems simultaneously.
ChatGPT Share Links Abused for Malware Distribution
Threat actors abuse ChatGPT's content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT desktop application. The "LLMShare" campaign, discovered by Push Security, uses Google ads to direct users searching for ChatGPT to a malicious shared ChatGPT page hosted on chatgpt.com. Users see a rendered outage notice claiming the web version is unavailable and should download the desktop application instead. The fake outage notice is rendered through ChatGPT itself via a custom HTML page published through a shared chatgpt.com/s/ link. Clicking the download button brings visitors to openew[.]app, which impersonates OpenAI's desktop application download portal. The site uses cloaking to display content only to targeted victims. Both macOS and Windows downloads install malware. Push Security also observed attacks abusing Claude Artifacts to host ClickFix-style lures.
Shadow AI: 2,000+ Vibe-Coded Apps Exposed Corporate Data
Red Access identified more than 380,000 publicly accessible web assets across leading vibe-coding platforms, with roughly 5,000 looking corporate. More than 2,000 held sensitive corporate, operational, or personal data sitting on the open web, deployed without basic access controls, often granting admin access by default to anyone who reached the URL. The Shadow Builders report documented exposures across six continents and every industry. Vibe coding platforms allow anyone to build a working application by describing what they want, compressing months of engineering work into hours. A marketing manager builds a campaign tracker and connects it to the BI tool. An operations manager builds a vendor-intake form and connects it to the ticketing system. Applications get connected to sanctioned production systems (CRMs, ERPs, ticketing tools, BI platforms) and published to the open internet with whatever access controls the builder configured (often none). Traditional security stacks miss this category: EDR sees the browser process, not the build inside it. DLP watches enumerated channels and can't see vibe-coded applications connecting programmatically to BI tools via API, moving data cloud-to-cloud. CASB was built for SaaS vendors, not custom-built applications.
Zapier Nearly Compromised via Multi-Step Exploit Chain
Token Security researchers discovered they could compromise low-code automation service Zapier by exploiting the platform's sandboxed environment. Using code blocks (Code by Zapier), researchers queried the sandbox OS and discovered it was running on AWS Lambda with an overly permissive role incorrectly named "allow_nothing_role." The researchers created a Python script to extract secrets from memory (AWS Lambda does not proactively delete tokens until the container is recycled), discovered they could list and request 1,111 files from Zapier's private repository, and found one file that exposed an NPM token for publishing that could be used for every package. A developer comment in the code read: "# note - this isn't a security thing since we pass a allow_nothing role - just avoids responding to dozens of annoying false positive security reports." Token Security researchers could have pushed malicious code to Zapier's repositories and to any users authenticated to the system. The finding highlights the complexity of cloud integrations and the risks of over-permissioned roles, secrets discovery, and non-human identities.
Dutch Authorities Disrupt 17 Million Device Botnet
Dutch authorities took offline a massive botnet of 17 million devices and seized more than 200 servers at a local provider that supported the operation. The Police collaborated with the National Cyber Security Centre (NCSC) on the investigation. The seized servers controlled computers, tablets, and smartphones to carry out cyberattacks. Local media reported the botnet was linked to Asocks, which advertises itself as a "universal proxy service" with 7 million IP addresses, 150 locations, and 100,000 clients. The platform offers corporate, residential, and mobile proxies for monthly subscriptions between $5 and $15. NCSC's action indicates that the owners of the devices were not knowing participants in supporting cybercrime operations.
Stark Industries Hosting Network Dismantled
Dutch financial crime investigators (FIOD) arrested two individuals and seized 800 servers across multiple data centers that actively enabled Russian-based cyberattacks, disinformation operations, and widespread interference campaigns. Web hosting firm Stark Industries was founded just before the 2022 invasion of Ukraine and had deep ties to Russian and Belarusian entities all sanctioned by the EU. After being sanctioned in May of last year, Stark Industries shifted operations to a front company named WorkTitans B.V., which provided hosting services under a new brand, THE.Hosting. This entity allegedly supported the pro-Russian hacktivist syndicate NoName057(16) in executing DDoS attacks and indirectly supplied economic resources to restricted organizations.
Google Chrome Rolls Out Device Bound Session Credentials
Google says the Chrome Device Bound Session Credentials (DBSC) security feature is now generally available and rolling out to all users to prevent account takeovers. DBSC cryptographically binds session cookies to a specific device, preventing hackers from using stolen cookies to bypass multi-factor authentication and hijack accounts. DBSC works by cryptographically linking user sessions to hardware security chips (TPM on Windows, Secure Enclave on macOS). Unique public/private keys used to encrypt and decrypt sensitive data are generated by the security chip and cannot be stolen. The feature is enabled by default for all Google Workspace customers upon rollout, and administrators cannot disable it. In the past, threat actors abused the undocumented Google OAuth "MultiLogin" API endpoint to generate new authentication cookies after stolen ones expired. Lumma and Rhadamanthys information-stealing malware claimed they could restore expired Google authentication cookies.
California AG Sues 23andMe Over 2023 Breach
California Attorney General Rob Bonta filed a lawsuit against 23andMe, now Chrome Holding Co., over the company's failure to protect sensitive customer genetic and personal information. Improper security led to a high-profile data breach in 2023 that exposed the sensitive information of nearly 7 million customers, including 855,541 Californians. The incident exposed genetic data, health predisposition information, ancestry and ethnicity information, biological relatives, and DNA matches. AG Bonta claims 23andMe failed to implement reasonable safeguards against credential-stuffing attacks, missed multiple opportunities to detect the intrusion, and failed to catch the coding error in DNA Relatives that led to the widespread breach. The complaint also notes misleading public statements 23andMe made before and after the incident. The AG seeks an injunction to prevent further violations and statutory penalties of $1,000-$7,500 per violation.
DDoS-as-a-Service Market Evolves from Scripts to Polished Products
Flare researchers compared DDoS-related underground activity from the first five months of 2023 and the first five months of 2026, finding that what once appeared more frequently as scripts, tutorials, leaked tools, and scattered forum posts is now more often presented as a repeatable product that is easier to buy and operate. Recent underground activity describes attack panels, API access, monthly plans, reseller options, customer support, botnet-backed capacity, game-server methods, and Cloudflare bypass claims. Cloudflare reported blocking a 7.3 Tbps attack in 2025 and mitigated a 31.4 Tbps attack in Q4 2025. Microsoft said Azure mitigated a 15.72 Tbps attack in October 2025, attributing the activity to the Aisuru botnet.
Chrome 148 Patches 151 Vulnerabilities
Google released Chrome 148 update resolving 151 vulnerabilities, including 22 critical-severity flaws. The most severe are CVE-2026-9872 (out-of-bounds write in GPU) and CVE-2026-9873 (use-after-free in Network), each earning reporting researchers a $43,000 reward. Three other critical defects are CVE-2026-9874 (use-after-free in Dawn), CVE-2026-9875 (out-of-bounds read in WebGL), and CVE-2026-9876 (use-after-free in WebGL). Most critical-severity vulnerabilities are use-after-free bugs that could allow attackers to achieve remote code execution and escape Chrome's sandbox to potentially compromise the entire system. Google paid over $130,000 in bug bounty rewards for 10 security flaws reported by external researchers. Starting in late March, the number of vulnerabilities resolved with each update has increased significantly, with over 350 issues addressed in Chrome 148 alone. The surge in vulnerability discoveries is likely driven by AI use, which determined Google to lower Chrome bug bounties last month.
VS Code Remote SSH Extension Vulnerability
A remote code execution vulnerability in the Visual Studio Code Remote-SSH extension could allow attackers to pivot to remote systems. The issue exists because, upon initiating a Remote SSH connection, the extension writes a bootstrap shell script to the Temp directory. An attacker with access to the system can modify the script before it is transmitted and executed on the remote server, to deploy a reverse shell.
Veeam, Notepad++, Roundcube Patches
Veeam resolved two high-severity vulnerabilities in its Backup & Replication product, warning they could lead to privilege escalation and arbitrary file writes. Notepad++ patched three security issues, including two leading to arbitrary code execution. The latest Roundcube security updates fix eight flaws, including unauthenticated SQL injection and arbitrary file delete bugs.
CISA Expands KEV Catalog with Supply Chain Attack CVEs
The U.S. cybersecurity agency CISA expanded its KEV catalog with three vulnerabilities describing recent software supply chain attacks: Daemon Tools Lite, TanStack, and Nx Console (which led to the 3,800 internal GitHub repositories hack). CISA also issued an alert on the Megalodon and Nx Console attacks, urging organizations to hunt for and remediate potential compromises. NPM invalidated granular access tokens in response to these attacks.
ChatGPhish Vulnerability in ChatGPT Web Summaries
Permiso Security disclosed ChatGPhish, a vulnerability in OpenAI ChatGPT leveraging the AI assistant's implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks. The chatgpt.com response renderer trusts Markdown links and Markdown image URLs that originated from a third-party page the assistant has just summarized, auto-fetching those images and surfacing those links as live, clickable elements inside the trusted assistant UI. In a hypothetical attack scenario, a bad actor can append a small payload to any web page that the victim later prompts ChatGPT to summarize, causing it to leak their IP, User-Agent, and Referer details when attacker-hosted images embedded in the page are automatically fetched. It can result in malicious Markdown links being rendered as live clickable elements inside the assistant's response, serve fake system-style security alerts, and serve a QR code from an attacker's S3 bucket to trick the victim into scanning it via their mobile device, bypassing desktop URL filters and enterprise security controls.
SymJack and TrustFall: AI Coding Agent Attacks
Adversa AI documented two attack techniques targeting AI coding agents and agentic coding CLIs: SymJack (a single attack pattern that lets a malicious repository achieve remote code execution through AI coding assistants by tricking the agent into a benign-looking file copy that secretly overwrites its own config, and the next restart runs attacker code with full user privileges) and TrustFall (a one-click remote code execution attack via a malicious repository that can ship a configuration that auto-approves and spawns an MCP server without a user's explicit approval or requiring a tool call from the agent).
CIFSwitch: Linux Local Root Vulnerability
A non-universal Linux local root vulnerability dubbed CIFSwitch was disclosed. The vulnerability is an architectural failing that goes back to the early days of *nix and other OSes, caused by resource issues. Due to various issues in the base OS, extra security was needed, and the choice was to add extra security as a layer over the base OS rather than completely rework the base OS design. The problem is that adding the extra security layer would create legacy code issues unless the layer could be bypassed by legacy code. The result is that the extra security layer suffered two failings: it was too complex to use, and the default use for everything was bypass.
Supply chain attacks dominated this reporting period, with coordinated campaigns hitting npm, NuGet, and PyPI ecosystems simultaneously. The shift from isolated malicious packages to multi-ecosystem campaigns suggests attackers are optimizing their infrastructure for parallel targeting. Authentication bypass vulnerabilities in edge-facing VPN appliances (PAN-OS GlobalProtect) and self-hosted Git services (Gogs) highlight the continued risk of exposing enterprise services directly to the internet without defense-in-depth controls. The emergence of LLM agents in post-exploitation (Marimo incident) and malware development (GREYVIBE) marks a tactical shift where AI augments both attacker speed and adaptability.