EPISODE · May 23, 2026 · 27 MIN
2026-05-23: Drupal Core SQL injection (CVE-2026-9082) and Trend Micro Apex One directory traversal
from Cyber Threat Brief
Show Notes - 2026-05-23 Stories Covered: - Today: - Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV (CVE-2026-9082) (https://thehackernews.com/2026/05/drupal-core-sql-injection-bug-actively.html) - Trend Micro Apex One Zero-Day Exploited in the Wild (CVE-2026-34926) (https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-apex-one-zero-day-exploited-in-attacks/) - LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root (https://thehackernews.com/2026/05/litespeed-cpanel-plugin-cve-2026-48172.html) - FBI Warns About Fast-Growing Phishing Kit Targeting Microsoft 365 Users (Kali365) (https://cyberscoop.com/fbi-phishing-kali365-microsoft365-access-tokens/) - First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups (https://thehackernews.com/2026/05/first-vpn-dismantled-in-global-takedown.html) - Four-Faith Industrial Router Vulnerability Exploited by Botnets (CVE-2024-9643) (https://www.securityweek.com/in-other-news-industrial-router-exploitation-cisa-kev-nomination-form-gas-station-hacking/) - Multi-Stage Linux Intrusion via F5 and Confluence Edge Appliance Compromise (https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluence/) - Iranian Hackers Suspected in US Gas Station Tank Monitor Breaches (https://www.securityweek.com/in-other-news-industrial-router-exploitation-cisa-kev-nomination-form-gas-station-hacking/) - CISA Contractor Exposes Credentials on Public GitHub Repository (https://www.securityweek.com/in-other-news-industrial-router-exploitation-cisa-kev-nomination-form-gas-station-hacking/) - Hugging Face Hiding Second-Stage Malware for npm Supply Chain Attack (https://databreaches.net/2026/05/22/hugging-face-hiding-second-stage-malware-for-npm-supply-chain-attack/?pk_campaign=feed&pk_kwd=hugging-face-hiding-second-stage-malware-for-npm-supply-chain-attack) - New macOS Stealer Variant Masquerades as Apple, Google & Microsoft (Reaper) (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-21-7/) - Interpol Operation Ramz Rounds Up 200+ Cybercrime Suspects Across Middle East and North Africa (https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-21-7/) - Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks (https://www.darkreading.com/cyber-risk/verizon-dbir-healthcare-fends-off-increased-social-engineering-attacks) - CVE-2026-41091 (CISA-KEV, EPSS 0.066, 91st percentile) - CVE-2026-45401 (EPSS 0.000, 12th percentile) - CVE-2025-14575 (Qt Network OpenSSL TLS backend, EPSS 0.000, 1st percentile) - CVE-2026-3593 (BIND 9 DNS-over-HTTPS, EPSS 0.000, 5th percentile) - CVE-2026-42009 (GnuTLS DTLS, EPSS 0.001, 31st percentile) - CVE-2026-3039 (BIND 9, EPSS 0.001, 16th percentile) - CVE-2026-3592 (BIND 9, EPSS 0.000, 4th percentile) - CVE-2026-5946 (BIND 9, EPSS 0.000, 11th percentile) - CVE-2026-5950 (BIND 9, EPSS 0.001, 21st percentile) - CVE-2026-41054 (haveged, EPSS 0.000, 0th percentile) - CVE-2026-8723 (qs.stringify, EPSS 0.000, 14th percentile) - CVE-2026-5947 (BIND 9, EPSS 0.000, 6th percentile) - CVE-2026-8711 (NGINX JavaScript, EPSS 0.002, 47th percentile) - CVE-2025-51480 (ONNX 1.17.0, EPSS 0.004, 59th percentile) - CVE-2023-6606 (Linux kernel SMB, EPSS 0.000, 1st percentile) - CVE-2025-39932 (Linux SMB client, EPSS 0.000, 2nd percentile) - Multiple Linux kernel CVEs CVEs Referenced: CVE-2022-40139, CVE-2023-41179, CVE-2023-6606, CVE-2024-9643, CVE-2025-14575, CVE-2025-39901, CVE-2025-39905, CVE-2025-39927, CVE-2025-39932, CVE-2025-39940, CVE-2025-39990, CVE-2025-40003, CVE-2025-40064, CVE-2025-40065, CVE-2025-40074, CVE-2025-51480, CVE-2025-54948, CVE-2026-3039, CVE-2026-34926, CVE-2026-3592, CVE-2026-3593, CVE-2026-41054, CVE-2026-41091, CVE-2026-41940, CVE-2026-42009, CVE-2026-45401 ...
Embed this episode
What this episode covers
Show Notes - 2026-05-23 Stories Covered: - Today: - Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV (CVE-2026-9082) (https://thehackernews.com/2026/05/drupal-core-sql-injection-bug-actively.html) - Trend Micro Apex One Zero-Day Exploited in the Wild (CVE-2026-34926) (https://www
NOW PLAYING
2026-05-23: Drupal Core SQL injection (CVE-2026-9082) and Trend Micro Apex One directory traversal
No transcript for this episode yet
Similar Episodes
No similar episodes found.