π¨ ACTIVE EXPLOITS & INCIDENTS
- First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups β The Hacker News European and North American authorities dismantled a criminal VPN service heavily used by ransomware gangs for anonymizing attacks including data theft and DDoS. The operation, led by France and the Netherlands, disrupts a key enabler of ransomware TTPs, potentially reducing attacker operational security.
- Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure β SecurityWeek Active exploitation attempts targeting CVE-2026-9082, a highly critical SQL injection in Drupal core affecting PostgreSQL-backed sites, have been observed within days of disclosure. Thousands of websites are under attack; immediate patching is critical to prevent full database compromise.
π VULNERABILITIES & CVEs
- CVE-2026-9082: Highly Critical SQL Injection in Drupal Core β Tenable Unauthenticated attackers can exploit this SQLi in Drupalβs database abstraction API on PostgreSQL sites. CVSS 9.8. Patches available for all supported branches plus two EOL releases. Detection PoC and patch diff publicly released simultaneously with advisory on May 20.
- CVE-2026-20182: Critical Cisco Catalyst SD-WAN Authentication Bypass Under Active Exploitation β Tenable A CVSS 10.0 zero-day auth bypass in Cisco Catalyst SD-WAN Controller/Manager is actively exploited by a sophisticated threat actor (UAT-8616) since at least 2023. Multiple other threat clusters have joined post-PoC release. Patches available; CISA mandates immediate remediation.
- Copy Fail (CVE-2026-31431): Linux Kernel Privilege Escalation with Public Exploit β Tenable Local root escalation affecting virtually all major Linux distros since 2017. Public exploit code is reliable and widely circulated. Patch availability varies; some distros lag behind. Critical for Linux hosts in sensitive environments to patch immediately.
- Dirty Frag (CVE-2026-43284, CVE-2026-43500): New Linux Kernel LPE Chain with Public Exploit β Tenable Follow-up to Copy Fail, this chained local privilege escalation has public exploit code and affects multiple Linux kernels. Patches are expected imminently. Combined with Copy Fail, this increases risk of local compromise on Linux systems.
- Fragnesia (CVE-2026-46300): New Linux Kernel Privilege Escalation with Public PoC β Tenable Targets Linux kernel XFRM ESP-in-TCP subsystem, requires separate patch from Dirty Frag. Confirmed working on Ubuntu; no in-the-wild exploitation reported yet. Patch released May 13; mitigations partially overlap with Dirty Frag.
π΅οΈ THREAT RESEARCH & DEEP DIVES
- Mini Shai-Hulud: Self-Propagating Worm Compromising npm and PyPI Supply Chains β Tenable TeamPCP group compromised 170+ npm and PyPI packages, bypassing SLSA Build Level 3 provenance attestations, stealing developer and cloud credentials, including from OpenAI and Mistral AI ecosystems. Any system installing affected packages must be treated as fully compromised.
- Verizon DBIR 2026: Vulnerability Exploitation Surges as Leading Initial Access Vector β Tenable Vulnerability exploitation now accounts for 31% of breaches, overtaking phishing. Median patch time increased by 11 days year-over-year. AI-driven vulnerability discovery and exploitation accelerate risk, underscoring urgent need for continuous exposure management and automated remediation.
π VENDOR BULLETINS & LAW ENFORCEMENT
- Netherlands Seizes 800 Servers of Hosting Firm Enabling Cyberattacks β BleepingComputer Dutch FIOD arrested two men and seized 800 servers from a hosting provider facilitating cyberattacks, interference ops, and disinformation campaigns. This disrupts infrastructure supporting multiple threat actors and may impact ongoing campaigns.
- Microsoft May 2026 Patch Tuesday: 118 CVEs, 16 Critical, No Zero-Days Exploited in the Wild β Tenable Includes fixes for .NET, Azure, M365, and Edge components. No zero-days exploited in the wild this month, a positive shift since June 2024. Prioritize patching critical updates to reduce attack surface.
- Oracle April 2026 CPU: 241 CVEs, 34 Critical Across 28 Product Families β Tenable Second quarterly update of 2026 addresses 241 CVEs with 481 patches; Oracle Communications hardest hit. Critical patches affect core infrastructure components; immediate review and patching recommended.
π° LESSER-KNOWN / UNDER-REPORTED
- No significant under-reported items this cycle.