2026-05-23: Drupal Core SQL injection (CVE-2026-9082) and Trend Micro Apex One directory traversal episode artwork

EPISODE · May 23, 2026 · 27 MIN

2026-05-23: Drupal Core SQL injection (CVE-2026-9082) and Trend Micro Apex One directory traversal

from Cyber Threat Brief

Show Notes - 2026-05-23 Stories Covered: - Today: - Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV (CVE-2026-9082) (https://thehackernews.com/2026/05/drupal-core-sql-injection-bug-actively.html) - Trend Micro Apex One Zero-Day Exploited in the Wild (CVE-2026-34926) (https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-apex-one-zero-day-exploited-in-attacks/) - LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root (https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html) - FBI Warns About Fast-Growing Phishing Kit Targeting Microsoft 365 Users (Kali365) (https://cyberscoop.com/fbi-phishing-kali365-microsoft365-access-tokens/) - First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups (https://thehackernews.com/2026/05/first-vpn-dismantled-in-global-takedown.html) - Four-Faith Industrial Router Vulnerability Exploited by Botnets (CVE-2024-9643) (https://www.securityweek.com/in-other-news-industrial-router-exploitation-cisa-kev-nomination-form-gas-station-hacking/) - Multi-Stage Linux Intrusion via F5 and Confluence Edge Appliance Compromise (https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluence/) - Iranian Hackers Suspected in US Gas Station Tank Monitor Breaches (https://www.securityweek.com/in-other-news-industrial-router-exploitation-cisa-kev-nomination-form-gas-station-hacking/) - CISA Contractor Exposes Credentials on Public GitHub Repository (https://www.securityweek.com/in-other-news-industrial-router-exploitation-cisa-kev-nomination-form-gas-station-hacking/) - Hugging Face Hiding Second-Stage Malware for npm Supply Chain Attack (https://databreaches.net/2026/05/22/hugging-face-hiding-second-stage-malware-for-npm-supply-chain-attack/?pk_campaign=feed&pk_kwd=hugging-face-hiding-second-stage-malware-for-npm-supply-chain-attack) - New macOS Stealer Variant Masquerades as Apple, Google & Microsoft (Reaper) (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-21-7/) - Interpol Operation Ramz Rounds Up 200+ Cybercrime Suspects Across Middle East and North Africa (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-21-7/) - Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks (https://www.darkreading.com/cyber-risk/verizon-dbir-healthcare-fends-off-increased-social-engineering-attacks) - CVE-2026-41091 (CISA-KEV, EPSS 0.066, 91st percentile) - CVE-2026-45401 (EPSS 0.000, 12th percentile) - CVE-2025-14575 (Qt Network OpenSSL TLS backend, EPSS 0.000, 1st percentile) - CVE-2026-3593 (BIND 9 DNS-over-HTTPS, EPSS 0.000, 5th percentile) - CVE-2026-42009 (GnuTLS DTLS, EPSS 0.001, 31st percentile) - CVE-2026-3039 (BIND 9, EPSS 0.001, 16th percentile) - CVE-2026-3592 (BIND 9, EPSS 0.000, 4th percentile) - CVE-2026-5946 (BIND 9, EPSS 0.000, 11th percentile) - CVE-2026-5950 (BIND 9, EPSS 0.001, 21st percentile) - CVE-2026-41054 (haveged, EPSS 0.000, 0th percentile) - CVE-2026-8723 (qs.stringify, EPSS 0.000, 14th percentile) - CVE-2026-5947 (BIND 9, EPSS 0.000, 6th percentile) - CVE-2026-8711 (NGINX JavaScript, EPSS 0.002, 47th percentile) - CVE-2025-51480 (ONNX 1.17.0, EPSS 0.004, 59th percentile) - CVE-2023-6606 (Linux kernel SMB, EPSS 0.000, 1st percentile) - CVE-2025-39932 (Linux SMB client, EPSS 0.000, 2nd percentile) - Multiple Linux kernel CVEs CVEs Referenced: CVE-2022-40139, CVE-2023-41179, CVE-2023-6606, CVE-2024-9643, CVE-2025-14575, CVE-2025-39901, CVE-2025-39905, CVE-2025-39927, CVE-2025-39932, CVE-2025-39940, CVE-2025-39990, CVE-2025-40003, CVE-2025-40064, CVE-2025-40065, CVE-2025-40074, CVE-2025-51480, CVE-2025-54948, CVE-2026-3039, CVE-2026-34926, CVE-2026-3592, CVE-2026-3593, CVE-2026-41054, CVE-2026-41091, CVE-2026-41940, CVE-2026-42009, CVE-2026-45401 ...

Episode metadata supplied by the publisher feed · Published May 23, 2026

Embed this episode

Show Notes - 2026-05-23 Stories Covered: - Today: - Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV (CVE-2026-9082) (https://thehackernews.com/2026/05/drupal-core-sql-injection-bug-actively.html) - Trend Micro Apex One Zero-Day Exploited in the Wild (CVE-2026-34926) (https://www

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

2026-05-23: Drupal Core SQL injection (CVE-2026-9082) and Trend Micro Apex One directory traversal

0:00 27:32

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Cyber Threat Brief?

This episode is 27 minutes long.

When was this Cyber Threat Brief episode published?

This episode was published on May 23, 2026.

Can I download this Cyber Threat Brief episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!