EPISODE · May 26, 2026 · 33 MIN
2026-05-26: Critical Alerts
from Cyber Threat Brief
Show Notes - 2026-05-26 Stories Covered: - May 26, 2026 - Drupal SQL Injection (CVE-2026-9082) (https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-drupal-vulnerability/) - Microsoft Defender Zero-Days (CVE-2026-41091, CVE-2026-45498) (https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html) - Trend Micro Apex One Directory Traversal (CVE-2026-34926) (https://research.checkpoint.com/2026/25th-may-threat-intelligence-report/) - Linux Kernel Privilege Escalation (CVE-2026-46333) (https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html) - GitHub Breach via Poisoned VS Code Extension (https://isc.sans.edu/diary/rss/33016) - Microsoft Azure Durable Functions SDK Trojanized (durabletask) (https://isc.sans.edu/diary/rss/33016) - Laravel-Lang Supply Chain Attack (https://www.securityweek.com/laravel-lang-packages-poisoned-for-malware-delivery/) - 7-Eleven Data Breach (ShinyHunters) (https://www.bleepingcomputer.com/news/security/7-eleven-data-breach-exposes-personal-information-of-185-000-people/) - Ghost CMS Mass Exploitation (CVE-2026-26980) (https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html) - Kali365 Phishing-as-a-Service (Microsoft 365 OAuth Abuse) (https://www.bleepingcomputer.com/news/security/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts/) - KnowledgeDeliver LMS Zero-Day (CVE-2026-5426) (https://thehackernews.com/2026/05/knowledgedeliver-lms-flaw-exploited-to.html) - Netherlands Seizes 800 Servers, Arrests Bulletproof Hosting Operators (https://krebsonsecurity.com/2026/05/netherlands-seizes-800-servers-arrests-2-for-aiding-cyberattacks/) - ACR Stealer via Fake Claude Download Pages (https://isc.sans.edu/diary/rss/33018) - Microsoft Fox Tempest Takedown (Rhysida Ransomware Enabler) (https://thehackernews.com/2026/05/weekly-recap-linux-flaws-defender-0.html) - Windows Server 2016 Domain Controller Lookup Failures (KB5087537) (https://www.bleepingcomputer.com/news/microsoft/microsoft-domain-controller-lookup-may-fail-on-windows-server-2016/) - ACR Stealer (Fake Claude Campaign) (https://isc.sans.edu/diary/rss/33018) - Ghost CMS Campaign (CVE-2026-26980) (https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html) - Lazarus RemotePE (https://thehackernews.com/2026/05/lazarus-deploys-remotepe-memory-only.html) - Nimbus Manticore (Iranian APT) (https://thehackernews.com/2026/05/iranian-hackers-deploy-minifast-and.html) - Laravel-Lang Supply Chain Attack (https://www.securityweek.com/laravel-lang-packages-poisoned-for-malware-delivery/) - CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws (https://thehackernews.com/2026/05/cert-in-mandates-12-hour-patching-for.html) - Anthropic Mythos Detected 23,000 Vulnerabilities Across 1,000 OSS Projects (https://www.securityweek.com/anthropic-mythos-detected-23000-potential-vulnerabilities-across-1000-oss-projects/) - Check Point: AI-Driven Attacks Have Entered Routine Criminal Use (https://research.checkpoint.com/2026/25th-may-threat-intelligence-report/) - TeamPCP Supply Chain Campaign (CVE-2026-45321) (https://isc.sans.edu/diary/rss/33016) - CVE-2026-26980 (Ghost CMS SQL Injection) (https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html) - CVE-2026-5426 (KnowledgeDeliver LMS Hard-Coded Machine Keys) (https://thehackernews.com/2026/05/knowledgedeliver-lms-flaw-exploited-to.html) - Healthcare Data Breaches (https://www.securityweek.com/oncology-institute-discloses-third-party-data-breach/) CVEs Referenced: CVE-2026-26980, CVE-2026-34926, CVE-2026-41091, CVE-2026-45321, CVE-2026-45498, CVE-2026-46333, CVE-2026-5426, CVE-2026-9082 Indicators of Compromise: Domains: flipboxstudio[.]info, clo4shara[.]xyz, google[.]com, fairpoint29[.]com, enhanceblabber[.]cc, primemetricsa[.]com, creativecommunityinfo[.]art, ibb[.]co, en ...
Embed this episode
What this episode covers
Show Notes - 2026-05-26 Stories Covered: - May 26, 2026 - Drupal SQL Injection (CVE-2026-9082) (https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-drupal-vulnerability/) - Microsoft Defender Zero-Days (CVE-2026-41091, CVE-2026-45498) (https://thehackernews.c
NOW PLAYING
2026-05-26: Critical Alerts
No transcript for this episode yet
Similar Episodes
No similar episodes found.