Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (2 May 2026)
Published: Loading…
At a Glance
- Critical cPanel flaw CVE-2026-41940 allows unauthenticated administrative access and is actively exploited, exposing over one million websites to potential full server takeover.
- Shai-Hulud supply chain attack compromised lightning and intercom-client packages, stealing credentials and spreading through CI/CD pipelines into over 1,800 repositories.
- Malicious Ruby gems and Go modules from BufferZoneCorp harvest credentials, tamper with GitHub Actions workflows, and establish persistent SSH access in CI environments.
- Over 575 malicious OpenClaw skills and Hugging Face repositories distribute trojans and AMOS infostealer using prompt injection and hidden dependency execution techniques.
- Google AppSheet phishing campaign compromised 30,000 Facebook accounts using authenticated emails, Telegram exfiltration, and real-time credential harvesting infrastructure.
- Linux kernel vulnerability CVE-2026-31431 enables local privilege escalation to root across systems built since 2017, affecting a wide range of servers and devices.
Summary
Software supply chain attacks continue to expand across ecosystems, with Shai-Hulud compromising widely used Python and npm packages to steal credentials and propagate through CI/CD pipelines. Parallel campaigns involving malicious Ruby gems and Go modules manipulate GitHub Actions, exfiltrate secrets, and establish persistent SSH access within developer and build environments.
AI development platforms including Hugging Face and OpenClaw are being abused to distribute malware embedded in models, datasets, and agent extensions. Attackers leverage indirect prompt injection, hidden dependencies, and staged payload delivery to execute trojans and infostealers across Windows and macOS systems.
A critical cPanel vulnerability tracked as CVE-2026-41940 allows unauthenticated attackers to gain administrative control over hosting environments and hosted websites. The flaw is actively exploited in the wild and impacts over one million internet-facing systems, including infrastructure supporting financial and healthcare services.
Large-scale phishing operations are targeting consumer platforms, with a Google AppSheet campaign compromising approximately 30,000 Facebook accounts using authenticated email delivery and real-time credential harvesting. Stolen data, including login credentials and identity documents, is exfiltrated via Telegram infrastructure and monetised through underground marketplaces.
A long-standing Linux kernel vulnerability, CVE-2026-31431 or CopyFail, enables local privilege escalation to root across systems built since 2017. The flaw affects a broad range of servers and endpoints, exposing environments to full compromise where unprivileged access is obtained.
Law enforcement actions continue against ransomware operators, with individuals linked to ALPHV BlackCat attacks receiving prison sentences for deploying ransomware against US organisations. The group’s ransomware-as-a-service model facilitated attacks on over 1,000 victims globally, combining data theft with encryption and extortion.
Highlights of the Day
Malicious Ruby and Go Packages Target CI Pipelines
Researchers identified a supply chain campaign using malicious Ruby gems and Go modules from the BufferZoneCorp GitHub account, impersonating legitimate developer tools to infiltrate CI environments and developer systems. The Ruby packages execute during installation via extconf.rb, harvesting environment variables and credentials such as SSH keys, AWS profiles, and GitHub tokens, then exfiltrating the data to a concealed remote endpoint. The Go modules manipulate GitHub Actions by altering GOPROXY and checksum settings, planting fake binaries, intercepting workflows, and in some cases adding SSH keys to authorised_keys to establish persistent access.
Shai-Hulud Malware Infects Lightning and Intercom Packages
Researchers reported a new Shai-Hulud supply chain attack compromising the Python package lightning versions 2.6.2 and 2.6.3 and the npm package intercom-client 7.0.4, both widely used with millions of downloads. The malware harvests environment variables, npm tokens, and GitHub credentials, exfiltrating them to an obfuscated HTTPS endpoint while also abusing valid tokens to enumerate accounts, modify packages, and republish trojanised versions. The campaign has resulted in over 1,800 public GitHub repositories containing stolen credentials, with the malicious code also capable of injecting files into repositories and spreading further across CI workflows.
Google AppSheet Phishing Hijacks 30,000 Facebook Accounts
Researchers uncovered a phishing campaign dubbed “AccountDumpling” that abused Google AppSheet to send fully authenticated emails from noreply AT appsheet DOT com, targeting Facebook users with lures such as policy violations, login alerts, and verification offers. The operation used Netlify and Vercel-hosted phishing pages, Google Drive PDFs, and Telegram bots to collect credentials, government IDs, and two-factor codes, enabling real-time account takeover and data exfiltration. Analysis identified more than 30,000 compromised accounts globally, with stolen data funnelled into Telegram channels and linked to a Vietnamese-led ecosystem monetising hijacked accounts and recovery services.
US Cybersecurity Professionals Sentenced for BlackCat Ransomware Attacks
Two US cybersecurity professionals, Ryan Goldberg and Kevin Martin, were sentenced to four years in prison for deploying ALPHV BlackCat ransomware against multiple US organisations between April and December 2023. The attackers operated as affiliates in a ransomware-as-a-service scheme, paying a 20% share to BlackCat operators, and extorted at least $1.2 million in Bitcoin from a victim while laundering proceeds. The ALPHV BlackCat group targeted more than 1,000 organisations globally, using data theft and system encryption, including incidents involving leaked patient data from a medical provider.
Malicious AI Models on Hugging Face Spread Malware
Acronis researchers identified active campaigns abusing Hugging Face and ClawHub platforms to distribute malware disguised as AI models, datasets, and agent extensions, leveraging trust in widely used AI ecosystems. The investigation uncovered over 575 malicious OpenClaw skills across 13 developer accounts delivering trojans, cryptominers, and AMOS infostealer, often using encoded commands, hidden dependencies, and external payload downloads targeting Windows and macOS systems. Attackers also employed indirect prompt injection to trigger AI-driven execution, while Hugging Face repositories were used to host payloads and stage multi-step infection chains with obfuscation, in-memory execution, and covert command-and-control communication.
Daily Coverage