Security Intel Feed
Cyber Hose
Page 52 of 52
Vulnerabilities & CVEs
Drupal core SQL injection under active attack days after disclosure
Read digest- Drupal core SQL injection under active attack — Thousands of PostgreSQL-backed Drupal sites are being targeted via an unauthenticated CVSS 9.8 SQL injection (CVE-2026-9082) days after the advisory, with PoC and patch diff public.
- Lawmakers demand answers as CISA contains its GovCloud leak — CISA is invalidating credentials after a contractor leaked AWS GovCloud keys and sensitive agency secrets on public GitHub, prompting congressional inquiries.
- Mini Shai-Hulud worm compromises 170+ npm and PyPI packages — TeamPCP's self-propagating worm bypassed SLSA Build Level 3 provenance and stole developer and cloud credentials across the npm and PyPI supply chains.
- Former US execs plead guilty to aiding tech support scammers — Two ex-executives of a call-tracking firm admitted to concealing a global tech support fraud scheme.
- Ghostwriter targets Ukraine government with Prometheus phishing — Belarus-aligned APT Ghostwriter is spear-phishing Ukrainian government organizations with Prometheus-themed malware lures, per CERT-UA.
Vulnerabilities & CVEs
Cisco Catalyst SD-WAN CVSS 10 auth bypass under active exploitation
Read digest- Cisco Catalyst SD-WAN auth bypass under active exploitation — A CVSS 10.0 authentication bypass in Catalyst SD-WAN Controller and Manager (CVE-2026-20182) has been exploited by UAT-8616 since 2023; CISA mandates immediate remediation.
- Lawmakers demand answers on the CISA GovCloud data leak — Congress is pressing CISA for accountability after a contractor published AWS GovCloud keys and sensitive agency secrets on public GitHub.
- Mini Shai-Hulud worm compromises 170+ npm and PyPI packages — The self-propagating worm bypassed SLSA Build Level 3 provenance attestations to steal developer and cloud credentials, reaching OpenAI and Mistral AI environments.
- Microsoft May Patch Tuesday: 118 CVEs, no zero-days — Microsoft patched 118 CVEs (16 critical) across Azure, .NET, M365 and Windows, with no zero-days exploited in the wild this cycle.
- CrowdStrike leads Gartner's first threat-intel Magic Quadrant — CrowdStrike was named a leader in Gartner's first Magic Quadrant for Cyberthreat Intelligence Technologies alongside new AI-powered detection tools.
Active Exploits & Incidents
Trend Micro Apex One zero-day exploited in the wild, no workaround
Read digest- Trend Micro Apex One zero-day exploited in the wild — A directory traversal flaw in on-premise Apex One (CVE-2026-34926) is under active exploitation and now in CISA's KEV catalog; patch immediately — no workaround exists.
- Three max-severity Ubiquiti UniFi OS RCE flaws — Three CVSS 10.0 remotely exploitable, unauthenticated vulnerabilities were patched in UniFi OS — high exposure given UniFi's prevalence in SMB and enterprise networks.
- Megalodon supply-chain attack hits 5,561 GitHub repos — Attackers using forged CI bot identities pushed 5,718 malicious commits injecting payloads into GitHub Actions workflows to exfiltrate CI/CD secrets.
- Kimwolf botnet admin arrested — A 23-year-old Ottawa man was charged in the US and Canada with operating the ~2M-device Kimwolf IoT DDoS botnet and attacking the researchers who tracked him.
- CISA contractor exposed AWS GovCloud credentials on public GitHub — A contractor's public repo contained credentials to highly privileged AWS GovCloud accounts plus internal CISA build and deploy pipeline details.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check