Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (5 May 2026)
Published: Loading…
At a Glance
- A malicious PyTorch Lightning package on PyPI deployed credential-stealing malware targeting cloud credentials, browser data and environment files.
- Over 40,000 servers were compromised through active exploitation of cPanel vulnerability CVE-2026-41940 enabling administrative access and ransomware deployment.
- CISA added the Linux ‘Copy Fail’ vulnerability to its KEV list as threat actors began exploiting it to gain root access.
- Attackers increasingly abuse Amazon SES and Google AppSheet to send phishing emails that bypass SPF, DKIM and DMARC protections.
- DigiCert revoked certificates after attackers breached its support portal via a malicious screensaver file delivered through a customer chat channel.
- A coordinated international operation arrested 276 suspects and shut nine cryptocurrency scam centres responsible for large-scale investment fraud schemes.
Summary
Supply chain threats remain active with a backdoored PyTorch Lightning package deploying credential-stealing malware targeting cloud environments, browsers, and developer secrets through hidden execution chains. The emergence of Quasar Linux (QLNX) introduces a stealthy RAT with rootkit capabilities, PAM backdoors, and extensive credential harvesting from developer and CI/CD environments. New protections in pnpm 11 address risks from malicious dependencies by enforcing minimum release age and restricting execution of build scripts.
Active exploitation of cPanel CVE-2026-41940 has compromised more than 40,000 servers, enabling administrative access, ransomware deployment, and widespread website defacement across internet-facing systems. The Copy Fail Linux vulnerability has also entered active exploitation, with CISA adding it to the KEV catalogue following observed attempts to gain root-level access on affected systems. A separate flaw in Weaver E-cology (CVE-2026-22679) has been exploited since March to execute reconnaissance commands within enterprise environments.
Phishing activity continues to leverage trusted infrastructure, with attackers abusing Amazon SES and Google AppSheet to deliver emails that pass authentication checks and evade filtering controls. A multi-stage AiTM phishing campaign targeted over 35,000 users using code-of-conduct lures, CAPTCHA-gated delivery, and token interception during proxied authentication flows. The VENOMOUS#HELPER campaign used RMM tools including SimpleHelp and ScreenConnect to establish persistent access across more than 80 organisations.
Significant breaches include a compromise of DigiCert systems via a malicious file delivered through a support chat channel, resulting in certificate revocations and internal access. Instructure disclosed a breach exposing student data and communications following service disruption and hacker extortion threats. A separate incident involving France Titres exposed up to 18 million records, with stolen data offered for sale and a suspect detained.
Law enforcement actions targeted cybercrime operations, with authorities dismantling nine cryptocurrency scam centres and arresting 276 individuals involved in investment fraud schemes affecting victims internationally. Two individuals received prison sentences for facilitating ALPHV/BlackCat ransomware attacks against multiple US organisations. A ransomware group also claimed a breach of a Hungarian media company, reporting unauthorised access to significant volumes of data.
Additional developments include a breach of a source code repository affecting Trellix, though no impact on software distribution processes was reported. Critical vulnerabilities in MOVEit Automation (CVE-2026-4670, CVE-2026-5174) enable authentication bypass and privilege escalation, exposing enterprise file transfer systems to potential compromise. Data privacy concerns persist as workplace applications collect extensive user data, while voter records and social media correlation enable identification of sensitive individuals.
Highlights of the Day
Backdoored PyTorch Lightning Release Steals Credentials via Hidden Payload
A malicious PyTorch Lightning version 2.6.3 uploaded to PyPI contained a hidden execution chain that triggered on import, spawning a background process to download a Bun runtime and execute an obfuscated JavaScript payload. The malware, detected as ShaiWorm, harvested .env files, API keys, browser data from Chrome, Firefox and Brave, and credentials from AWS, Azure and GCP services while supporting arbitrary command execution. Microsoft reported limited impact affecting a small number of devices, and the compromised package was reverted to version 2.6.1 while the breach of the build pipeline is investigated.
Attackers Exploit Amazon SES to Send Trusted Phishing Emails
Attackers are abusing Amazon Simple Email Service by using compromised AWS IAM access keys to send phishing emails that pass SPF, DKIM, and DMARC checks and appear legitimate to security systems. Campaigns observed in early 2026 include fake DocuSign notifications directing victims to credential-harvesting forms hosted on amazonaws.com using redirects and custom HTML templates. The same infrastructure has also been used in business email compromise schemes, where attackers impersonate employees and send fabricated invoice threads with payment details to finance departments.
Critical MOVEit Automation Flaws Enable Auth Bypass and Privilege Escalation
Progress Software disclosed a critical authentication bypass vulnerability tracked as CVE-2026-4670 affecting MOVEit Automation versions before 2025.1.5, 2025.0.9, and 2024.1.8, allowing remote unauthenticated exploitation without user interaction. A second flaw, CVE-2026-5174, caused by improper input validation, enables privilege escalation via backend command port interfaces, potentially leading to administrative control and data exposure. Over 1,400 internet-exposed MOVEit Automation instances were identified, including systems linked to US government agencies, though active exploitation has not been confirmed.
Copilot Flaws Enabled Data Theft via Prompt Injection Chains
A researcher disclosed CVE-2026-24299 affecting Microsoft Copilot, chaining prompt injection, HTML preview rendering, and permissive Content Security Policies to exfiltrate sensitive data through external resource requests. Attackers used CSS background images and @font-face loading to trigger outbound requests containing extracted emails, documents, or chat data, with some exploits achieving zero-click execution by forcing automatic preview rendering. Additional techniques abused Copilot memory features to persist malicious instructions and enable ongoing data exfiltration across sessions, while delayed tool invocation improved exploit reliability before fixes were deployed between December 2025 and March 2026.
Code-of-Conduct Phishing Campaign Steals Tokens via AiTM Attack
Microsoft observed a multi-stage phishing campaign between 14 and 16 April 2026 targeting over 35,000 users across 13,000 organisations, using code-of-conduct themed emails with PDF attachments and attacker-controlled domains. Victims were routed through CAPTCHA-gated landing pages and intermediate sites before reaching an adversary-in-the-middle authentication flow that proxied Microsoft sign-ins and captured session tokens. The campaign used legitimate email services, cloud-hosted infrastructure, and tailored HTML lures, primarily impacting US organisations across healthcare, finance, professional services, and technology sectors.
pnpm 11 Adds Default Protections Against Supply Chain Attacks
pnpm 11 introduces default supply chain protections including a 24-hour minimum release age, preventing newly published package versions from being installed immediately to limit exposure to compromised releases. The update also blocks exotic subdependencies from non-registry sources and adds an allowBuilds model to control execution of dependency build scripts, a common attack vector in package compromises. These changes follow recent multi-ecosystem attacks using install-time hooks and obfuscated payloads to steal credentials from developer environments and CI/CD systems.
Quasar Linux RAT Targets Developers with Rootkit and Credential Theft
Trend Micro uncovered Quasar Linux (QLNX), a previously undocumented Linux remote access trojan that executes filelessly, deploys LD_PRELOAD rootkits, and installs PAM backdoors to intercept plaintext credentials. The malware harvests sensitive data from developer and cloud environments, including .npmrc, .pypirc, AWS credentials, Kubernetes configs, Git tokens, browser data, and SSH keys, enabling compromise of package registries and CI/CD pipelines. QLNX maintains persistence via systemd services, crontab, and preload injection, communicates over TLS or HTTP(S) with a custom protocol, and supports peer-to-peer mesh networking alongside 58 command handlers for system control and data exfiltration.
Daily Coverage