EPISODE · May 9, 2026 · 20 MIN
2026-05-09: Palo Alto Networks is patching CVE-2026-0300, a critical zero-day in PAN-OS being actively
from Cyber Threat Brief
Show Notes - 2026-05-09 Stories Covered: - May 9, 2026 - Today: - Palo Alto Networks PAN-OS Zero-Day (CVE-2026-0300) (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-19-7/) - Ivanti EPMM Zero-Day Exploited (CVE-2026-6973) (https://www.bleepingcomputer.com/news/security/cisa-gives-feds-four-days-to-patch-ivanti-flaw-exploited-as-zero-day/) - Dirty Frag Linux Privilege Escalation Under Active Exploitation (https://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/) - BerriAI LiteLLM SQL Injection (CVE-2026-42208) (https://www.cisa.gov/news-events/alerts/2026/05/08/cisa-adds-one-known-exploited-vulnerability-catalog) - Karakurt Extortion Negotiator Sentenced to 9 Years (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-19-7/) - North Korean IT Worker Laptop Farm Operators Sentenced (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-19-7/) - RansomHouse Claims Trellix Source Code Breach (https://www.bleepingcomputer.com/news/security/trellix-source-code-breach-claimed-by-ransomhouse-hackers/) - ShinyHunters Second Breach of Instructure Canvas (https://www.darkreading.com/cyberattacks-data-breaches/shinyhunters-second-attack-instructure) - PCPJack Cloud Worm Evicts TeamPCP, Harvests Credentials (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-19-7/) - Poland Documents ICS Breaches at Five Water Treatment Plants (https://www.securityweek.com/polish-security-agency-reports-ics-breaches-at-five-water-treatment-plants/) - Zara Breach Exposes 197,000 Customer Records (https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/) - NVIDIA GeForce NOW Armenian Partner Breach (https://www.bleepingcomputer.com/news/security/nvidia-confirms-geforce-now-data-breach-affecting-armenian-users/) - AI Platform Braintrust Breach Exposes Customer API Keys (https://www.securityweek.com/ai-firm-braintrust-prompts-api-key-rotation-after-data-breach/) - TCLBANKER Banking Trojan Spreads via WhatsApp and Outlook (https://thehackernews.com/2026/05/tclbanker-banking-trojan-targets.html) - Quasar Linux RAT Targets Developer Credentials for Supply Chain Attacks (https://thehackernews.com/2026/05/quasar-linux-rat-steals-developer.html) - PamDOORa Linux Backdoor Advertised for $900 (https://thehackernews.com/2026/05/new-linux-pamdoora-backdoor-uses-pam.html) - SOC Alert Backlogs Hiding Real Threats (https://thehackernews.com/2026/05/one-missed-threat-per-week-what-25m.html) - Fake Android Call History Apps Steal $7.3M in Subscriptions (https://thehackernews.com/2026/05/fake-call-history-apps-stole-payments.html) - cPanel and WHM Patch Three Vulnerabilities (https://thehackernews.com/2026/05/cpanel-whm-patch-3-new-vulnerabilities.html) CVEs Referenced: CVE-2026-0300, CVE-2026-1281, CVE-2026-1340, CVE-2026-29201, CVE-2026-29202, CVE-2026-29203, CVE-2026-41940, CVE-2026-42208, CVE-2026-43284, CVE-2026-43500, CVE-2026-6973 Indicators of Compromise: IPs: 12.8.0.0, 12.6.1.1, 12.7.0.1, 12.8.0.1, 11.136.0.9 Full brief: https://carolinacleartech.com/brief/2026-05-09/
Embed this episode
What this episode covers
Show Notes - 2026-05-09 Stories Covered: - May 9, 2026 - Today: - Palo Alto Networks PAN-OS Zero-Day (CVE-2026-0300) (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-19-7/) - Ivanti EPMM Zero-Day Exploited (CVE-2026-6973) (https://www.bleepingcomputer.com/news/s
NOW PLAYING
2026-05-09: Palo Alto Networks is patching CVE-2026-0300, a critical zero-day in PAN-OS being actively
No transcript for this episode yet
Similar Episodes
No similar episodes found.