🚨 ACTIVE EXPLOITS & INCIDENTS
- Lawmakers Demand Answers as CISA Tries to Contain Data Leak — Krebs on Security A CISA contractor accidentally leaked AWS GovCloud keys and sensitive agency secrets on a public GitHub repo, prompting congressional inquiries. CISA is actively invalidating credentials and containing the breach, but exposure of GovCloud keys poses significant risk to federal cloud infrastructure. Immediate review of cloud credential management and GitHub repo access controls recommended.
- Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware — The Hacker News Belarus-aligned APT Ghostwriter (UAC-0057/UNC1151) is conducting targeted phishing campaigns leveraging Ukrainian Prometheus platform lures. CERT-UA reports ongoing spear-phishing aimed at government orgs, delivering Prometheus-themed malware. Heightened email filtering and user awareness advised for entities with Ukraine ties.
🔓 VULNERABILITIES & CVEs
- CVE-2026-9082: Critical SQL Injection in Drupal Core — Tenable Cyber Exposure / SecurityWeek A highly critical unauthenticated SQLi in Drupal core’s database abstraction layer affects sites using PostgreSQL (CVSS 9.8). Exploit PoC and patch diff were published same day as advisory (SA-CORE-2026-004). Thousands of sites are already targeted in active attacks. Immediate patching across all supported Drupal branches is critical.
- CVE-2026-20182: Critical Cisco Catalyst SD-WAN Auth Bypass Under Active Exploitation — Tenable Cyber Exposure Multiple critical auth bypass flaws in Cisco Catalyst SD-WAN Controller/Manager, including CVE-2026-20182 (CVSS 10.0), are actively exploited by sophisticated threat actor UAT-8616 and others. POCs and exploitation observed since 2023. Patching is mandated by CISA; immediate remediation required for affected SD-WAN deployments.
- CVE-2026-31431 “Copy Fail”: Linux Kernel Local Privilege Escalation with Public Exploit — Tenable Cyber Exposure A local root escalation vulnerability in Linux kernel present since 2017 affects virtually all major distros. Public exploit code is reliable and circulating. Patch availability varies by distro; urgent kernel updates and mitigations needed to prevent local privilege escalation.
- Dirty Frag (CVE-2026-43284 & CVE-2026-43500): New Linux Kernel Privilege Escalation Chain — Tenable Cyber Exposure Following Copy Fail, Dirty Frag is a chained local privilege escalation in Linux kernel with public exploit code released pre-patch. Expected patches imminent. Linux hosts should be prioritized for updates and monitored for exploitation attempts.
- Microsoft May 2026 Patch Tuesday: 118 CVEs, 16 Critical — Tenable Cyber Exposure No zero-days exploited in the wild this month. Critical fixes include CVE-2026-41103 and patches across .NET, Azure, M365, and Windows components. Organizations should prioritize deployment to reduce attack surface amid rising vulnerability exploitation trends.
- CVE-2026-34207: TypeBot SSRF Protection Bypass via DNS-Resolved Hostnames — CVE ThreatInt TypeBot’s webhook/HTTP request SSRF protections are bypassed by DNS-resolved hostnames, enabling server-side request forgery. Versions prior to 3.15.2 affected. Patch or mitigate to prevent internal network scanning or data exfiltration.
- CVE-2026-32253: Sunshine Game Stream Host Auth Bypass — CVE ThreatInt Improper client certificate validation in Sunshine (pre-2026.516.143833) allows bypass of authentication. Critical for self-hosted game streaming environments; update to latest version to close this gap.
🕵️ THREAT RESEARCH & DEEP DIVES
- Mini Shai-Hulud: Self-Propagating Worm Compromising npm and PyPI Packages — Tenable Cyber Exposure TeamPCP’s worm campaign has compromised 170+ npm and PyPI packages, including those with valid SLSA Build Level 3 provenance attestations, breaching OpenAI and Mistral AI supply chains. Any system installing affected packages must be treated as fully compromised. Supply chain defenders should audit dependencies and enforce stricter provenance checks.
- Verizon DBIR 2026: Vulnerability Exploitation Surges as Patch Delays Grow — Tenable Cyber Exposure Vulnerability exploitation is now the top initial access vector (31% of breaches), while median patch times increased by 11 days. AI-driven vulnerability discovery and exploitation accelerate risk. Continuous exposure management and automated remediation orchestration are essential to keep pace.
📋 VENDOR BULLETINS & LAW ENFORCEMENT
- Former US Execs Plead Guilty to Aiding Tech Support Scammers — BleepingComputer Two ex-executives of a call-tracking/analytics firm admitted to concealing a global tech support fraud scheme. Highlights ongoing law enforcement focus on tech support scams and the importance of monitoring third-party vendor risks.
- Oracle April 2026 CPU: 241 CVEs, 34 Critical — Tenable Cyber Exposure Oracle’s second 2026 CPU fixes 241 CVEs across 28 product families, with 34 critical. Oracle Communications received the highest patch volume. Organizations using Oracle products should prioritize patching to mitigate broad exposure.