EPISODE · May 25, 2026 · 12 MIN
2026-05-25: Supply chain attacks hit developer ecosystems with 34 malicious packages stealing credentials
from Cyber Threat Brief
Show Notes - 2026-05-25 Stories Covered: - Today: - Ghost CMS SQL Injection (CVE-2026-26980) (https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/) - KnowledgeDeliver LMS ViewState Deserialization (CVE-2026-5426) (https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/) - TrapDoor Supply Chain Attack (npm, PyPI, Crates.io) (https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html) - Megalodon GitHub Actions Attack (5,500+ Repositories) (https://www.securityweek.com/over-5500-github-repositories-infected-in-megalodon-supply-chain-attack/) - DocketWise Data Breach (143,000 Affected) (https://www.securityweek.com/docketwise-data-breach-impacts-143000/) - Chinese-Language Phishing-as-a-Service Ecosystem (https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services/) - Anthropic Mythos Finds 23,000 Vulnerabilities (https://news.risky.biz/risky-bulletin-mythos-found-thousands-of-critical-bugs/) - Linus Torvalds Cracks Down on AI-Generated Pull Requests (https://www.theregister.com/oses/2026/05/25/linus-torvalds-to-start-being-more-hardnosed-about-pointless-pull-requests-some-of-which-come-from-ais/5245549) - Wireshark 4.6.6 (https://isc.sans.edu/diary/rss/33010) - CVE-2026-43029 (mptcp soft lockup) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43029) - CVE-2026-43414 (qla2xxx fcport double free) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43414) CVEs Referenced: CVE-2026-26980, CVE-2026-43029, CVE-2026-43414, CVE-2026-5426 Full brief: https://carolinacleartech.com/brief/2026-05-25/
Embed this episode
What this episode covers
Show Notes - 2026-05-25 Stories Covered: - Today: - Ghost CMS SQL Injection (CVE-2026-26980) (https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/) - KnowledgeDeliver LMS ViewState Deserialization (CVE-2026-5426) (https://cloud.goog
NOW PLAYING
2026-05-25: Supply chain attacks hit developer ecosystems with 34 malicious packages stealing credentials
No transcript for this episode yet
Similar Episodes
No similar episodes found.