Security Intel Feed
Cyber Hose
Page 51 of 52
Threat Research & Deep Dives
Claude Mythos AI finds 10,000 high-severity flaws in common software
Read digest- Claude Mythos AI finds 10,000 high-severity flaws in widely used software — Anthropic's Project Glasswing, working with ~50 partners, has identified over 10,000 high- and critical-severity vulnerabilities in systemically important software since launch — expect a surge in disclosures.
Vulnerabilities & CVEs
Underminr DNS flaw lets attackers hide C2 behind trusted domains
Read digest- Underminr DNS flaw lets attackers hide C2 behind trusted domains — A stealthy DNS vulnerability affecting roughly 88 million domains lets attackers bypass DNS filtering and cloak command-and-control traffic behind trusted names.
- Laravel-Lang PHP packages compromised with credential stealer — Multiple popular Laravel localization packages were trojanized via newly published malicious tags, targeting developers and CI pipelines.
Active Exploits & Incidents
LiteSpeed cPanel plugin flaw exploited to run scripts as root
Read digest- LiteSpeed cPanel plugin flaw exploited to run scripts as root — The CVSS 10.0 CVE-2026-48172 lets any cPanel user execute arbitrary scripts as root via incorrect privilege assignment, and is being actively exploited on hosting environments.
- Drupal core SQL injection added to CISA KEV — CVE-2026-9082 is confirmed exploited in the wild across all supported Drupal Core versions, enabling arbitrary SQL execution and potential site takeover.
Threat Research & Deep Dives
Stack strings in high-level languages: tradecraft for defenders
Read digest- Stack strings in high-level languages — A SANS ISC diary from SEC670 explores Windows implant, shellcode and C2 development, giving detection engineers insight into attacker tool evasion techniques.
Active Exploits & Incidents
Cisco SD-WAN auth bypass exploited by 10+ threat clusters
Read digest- Cisco SD-WAN auth bypass exploited by 10+ threat clusters — The CVSS 10.0 authentication bypass CVE-2026-20182 is exploited by UAT-8616 alongside 10 other clusters leveraging public PoCs; CISA mandates remediation.
- Highly critical SQL injection in Drupal core — The unauthenticated CVSS 9.8 SQLi on PostgreSQL-backed sites has a public PoC and patch diff; urgent patching is advised including select EOL versions.
- Mini Shai-Hulud worm bypasses build integrity controls — TeamPCP compromised 170+ npm and PyPI packages, the first campaign to defeat SLSA Build Level 3 provenance attestations at scale.
- Oracle April CPU: 241 CVEs fixed, 34 critical — Oracle's second quarterly update of 2026 delivers 481 patches across 28 product families, with Oracle Communications hardest hit at 139 patches.
- Fragnesia: Linux kernel privilege escalation with public PoC — CVE-2026-46300 targets the XFRM ESP-in-TCP subsystem with a working exploit on Ubuntu; existing Dirty Frag mitigations are only partially effective.
Vulnerabilities & CVEs
Dirty Frag Linux kernel LPE chain circulating with public exploit
Read digest- Dirty Frag: Linux kernel privilege escalation chain with public exploit — The chained CVE-2026-43284/CVE-2026-43500 extends the Copy Fail bug class with exploit code circulating before patches land; prioritize kernel updates.
- Cisco Catalyst SD-WAN auth bypass under active exploitation — The CVSS 10.0 CVE-2026-20182 has been exploited by UAT-8616 since 2023 and 10+ clusters post-PoC; CISA mandates immediate remediation.
- Verizon DBIR 2026: exploitation overtakes phishing — Vulnerability exploitation now accounts for 31% of breaches while median patch time increased 11 days year-over-year.
- Microsoft May Patch Tuesday: 118 CVEs, 16 critical — Patches cover .NET, Azure services and M365 agents, with no zero-days exploited in the wild this month.
- Mini Shai-Hulud supply-chain worm hits npm and PyPI — The worm compromised 170+ packages including ones with valid SLSA Level 3 provenance; systems that installed them must be treated as fully compromised.
Vulnerabilities & CVEs
Copy Fail: Linux kernel root escalation hits nearly all major distros
Read digest- Copy Fail: Linux kernel privilege escalation with reliable public exploit — CVE-2026-31431 lets local users escalate to root on nearly all major Linux distros shipped since 2017, and many distros lag on kernel patch deployment.
- Cisco Catalyst SD-WAN auth bypass under active exploitation — The CVSS 10.0 CVE-2026-20182 is exploited by UAT-8616 and 10+ other clusters leveraging public PoC code; CISA mandates immediate patching.
- Mini Shai-Hulud worm compromises 170+ npm and PyPI packages — TeamPCP's campaign defeated SLSA Build Level 3 provenance attestation, stealing developer and cloud credentials across both ecosystems.
- Microsoft May Patch Tuesday: 118 CVEs, 16 critical — No zero-days were exploited in the wild this month — a first since June 2024 — with patches across .NET, Azure and Edge components.
- Highly critical SQL injection in Drupal core — The unauthenticated SQLi on PostgreSQL-backed Drupal sites has a public PoC and patch diff; urgent patching is advised across all supported branches.
Vulnerabilities & CVEs
Mini Shai-Hulud worm defeats SLSA provenance across npm and PyPI
Read digest- Mini Shai-Hulud worm defeats SLSA provenance across npm and PyPI — TeamPCP's worm compromised 170+ packages — including ones with valid SLSA Build Level 3 attestations — breaching OpenAI and Mistral AI environments and stealing credentials.
- Cisco Catalyst SD-WAN auth bypass under active exploitation — The CVSS 10.0 CVE-2026-20182 has been exploited by UAT-8616 since 2023, with more clusters joining after the public PoC; CISA mandates immediate remediation.
- Verizon DBIR 2026: exploitation overtakes phishing — Vulnerability exploitation now drives 31% of breaches while median patch time grew 11 days year-over-year, accelerated by AI-driven discovery.
- Microsoft May Patch Tuesday: 118 CVEs, 16 critical — Fixes span .NET, Azure, M365 and Edge Copilot Chat, with no zero-days exploited in the wild for the first time since June 2024.
- Highly critical SQL injection in Drupal core — The unauthenticated CVE-2026-9082 affects PostgreSQL-backed Drupal sites; PoC and patch diff are public and patches cover six supported branches.
Active Exploits & Incidents
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
Read digest- Netherlands seizes 800 servers of hosting firm enabling cyberattacks — Dutch FIOD arrested two suspects and seized 800 servers from a hosting provider whose infrastructure supported ransomware, DDoS and disinformation operations.
- Cisco Catalyst SD-WAN vulnerabilities under active exploitation — The CVSS 10.0 authentication bypass CVE-2026-20182 is exploited by multiple threat clusters including UAT-8616; CISA has issued a remediation directive.
- Critical SQL injection in Drupal core (CVE-2026-9082) — The unauthenticated CVSS 9.8 SQLi on PostgreSQL-backed Drupal sites is reportedly being targeted in early exploitation attempts; patch immediately.
- Verizon DBIR 2026: vulnerability exploitation leads breaches — Vulnerability exploitation now accounts for 31% of breaches, surpassing phishing, while median patch times grew by 11 days year-over-year.
- Microsoft May Patch Tuesday: 118 CVEs, 16 critical, no zero-days — Microsoft patched 118 CVEs across .NET, Azure, M365 and Edge, with no zero-days exploited in the wild for the first time since June 2024.
Active Exploits & Incidents
First VPN dismantled in global takedown over use by ransomware gangs
Read digest- First VPN dismantled in global takedown — European and North American authorities dismantled a criminal VPN service used by 25 ransomware groups to anonymize data theft, scanning and DDoS operations.
- Drupal SQL injection in hacker crosshairs shortly after disclosure — An unauthenticated CVSS 9.8 SQL injection in Drupal's database abstraction layer (CVE-2026-9082) is drawing exploitation attempts against PostgreSQL-backed sites.
- Mini Shai-Hulud worm hits npm and PyPI supply chains — The TeamPCP worm compromised 170+ packages, bypassing SLSA Build Level 3 provenance attestations to steal developer and cloud credentials.
- Netherlands seizes 800 servers of hosting firm enabling attacks — Dutch FIOD arrested two men and seized 800 servers from a hosting provider that facilitated cyberattacks, interference operations and disinformation campaigns.
- Fragnesia: new Linux kernel privilege escalation with public PoC — CVE-2026-46300 in the kernel's XFRM ESP-in-TCP subsystem has a public PoC confirmed on Ubuntu and needs a separate patch from Dirty Frag.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check