Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (7 May 2026)
Published: Loading…
At a Glance
- Palo Alto Networks disclosed CVE-2026-0300, a PAN-OS authentication portal buffer overflow enabling unauthenticated remote code execution in firewall deployments.
- Lazarus Group operators hid second-stage malware within Git hooks in fake developer assessments, delivering InvisibleFerret and BeaverTail payloads via repositories.
- Cofense reported attackers abusing Vercel GenAI tools to rapidly generate realistic phishing pages impersonating major brands and exfiltrating credentials.
- Attackers compromised Daemon Tools installers in a global supply-chain attack, inserting a backdoor that targeted government and scientific systems.
- CloudZ remote access malware exploited Microsoft Phone Link integration to intercept SMS one-time passwords and steal user credentials and tokens.
Summary
Palo Alto Networks disclosed exploitation of CVE-2026-0300 affecting PAN-OS firewalls, enabling unauthenticated remote code execution on exposed systems. Cisco patched a denial-of-service vulnerability in Crosswork Network Controller and Network Services Orchestrator, requiring manual reboot to restore affected systems after exploitation.
Lazarus Group and OceanLotus-linked operations deployed malware through Git hooks and PyPI packages, targeting developers with credential theft and cross-platform loaders. Iranian threat actor MuddyWater conducted Microsoft Teams-based social engineering campaigns using false ransomware narratives to establish persistence and harvest credentials. CloudZ malware abused Microsoft Phone Link integration to intercept SMS one-time passwords, enabling credential theft across targeted Windows environments and associated authentication flows in enterprise communications.
Attackers abused Vercel GenAI platform to generate realistic phishing pages impersonating major brands and automating credential exfiltration through Telegram integrations. Malicious NuGet packages impersonating Chinese .NET UI libraries delivered infostealers targeting browsers, cryptocurrency wallets, and CI/CD developer environments at scale. Daemon Tools installers were compromised in a supply-chain attack distributing backdoors through official software channels affecting government and scientific entities.
A large-scale fraud ecosystem used deepfake financial personas and social media advertising to steal over $187 million through fake cryptocurrency platforms. IoT botnet xlabs_v1 exploited Android Debug Bridge vulnerabilities to compromise internet-exposed devices and conduct distributed denial-of-service attacks at scale across global networks. Chrome silently downloaded a 4GB Gemini Nano AI model onto user systems, enabling on-device features including summarisation and scam detection capabilities.
Highlights of the Day
Palo Alto Zero-Day Enables Root Access on PAN-OS Firewalls
Palo Alto Networks disclosed CVE-2026-0300, a critical buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal that allows unauthenticated remote code execution with root privileges through specially crafted packets. The flaw affects PA-Series and VM-Series firewalls running multiple PAN-OS 10.2, 11.1, 11.2 and 12.1 versions when the Captive Portal is exposed to untrusted networks or the public internet, and limited in-the-wild exploitation has been observed. Palo Alto Networks said Prisma Access, Cloud NGFW and Panorama are unaffected, with initial security fixes scheduled for release on 13 May and additional patches planned for 28 May.
Attackers Abuse Vercel AI Tools to Build Phishing Sites
Cofense researchers reported that threat actors are abusing Vercel’s GenAI-powered v0.dev platform to generate realistic phishing pages that spoof brands including Microsoft, Adidas, Spotify and Nike using simple text prompts and cloud-hosted deployment features. The campaigns use Vercel integrations with Telegram bots to exfiltrate stolen credentials in real time, while attackers also leverage automated hosting, rapid redeployment and customised anti-analysis functions within the generated phishing infrastructure. Cofense said observed Vercel abuse has increased significantly since 2022, with minimally skilled actors using free or low-cost account tiers to create credential phishing campaigns that previously required advanced web development capabilities.
Lazarus Hides Malware in Git Hooks for Fake Coding Tests
Researchers at OpenSourceMalware observed Lazarus Group operators using malicious Git pre-commit and post-checkout hooks in fake developer assessment repositories linked to the Contagious Interview campaign targeting cryptocurrency and Web3 job seekers. The loader script fingerprints the victim operating system, retrieves platform-specific payloads from precommit.vercel.app using curl or wget, and silently executes Bash or Windows command shell malware before Git commits are completed. The repositories used freshly created GitHub accounts, minimal commit histories and DeFi-themed projects, while the malware infrastructure replaced earlier delivery methods including VS Code tasks.json files, package.json postinstall scripts and disguised font files.
Fraud Network Stole $187 Million Through Fake Crypto Platforms
Group-IB uncovered an investment fraud ecosystem using deepfake financial experts, geo-targeted social media advertisements and WhatsApp coordination groups to manipulate legitimate stocks and direct victims into cryptocurrency scams across Australia and the United States. Investigators identified more than 200 connected fraudulent investment domains linked through shared infrastructure and contact details, with blockchain analysis estimating combined revenues exceeding $187 million from fake cryptocurrency platforms accepting BTC, ETH and USDT deposits. The operation also used Australian and US phone numbers, fabricated trading profits and coordinated buying instructions to inflate NASDAQ-listed small-cap stocks before orchestrated sell-offs caused major price collapses for victims.
VoidStealer Bypasses Chrome Encryption to Steal Session Data
Kaspersky researchers analysed a new build of the VoidStealer infostealer that bypasses Chrome’s Application-Bound Encryption by attaching to the browser as a debugger and extracting plaintext encryption keys directly from memory. The malware targets the moment Chromium-based browsers decrypt stored session cookies and credentials, setting breakpoints in the decryption process to capture master keys used by Chrome, Edge, Brave, Opera and Vivaldi. Google introduced Application-Bound Encryption in Chrome 127 during 2024 to prevent DPAPI-based cookie theft, but multiple infostealers including Lumma, Meduza and Whitesnake have since developed successful bypass techniques.
Attackers Use Bun Runtime to Deliver NWHStealer Malware
Malwarebytes researchers observed attackers using the Bun JavaScript runtime to distribute the Rust-based NWHStealer infostealer through ZIP archives posing as game trainers, software activators and media tools hosted on platforms including GitHub, SourceForge and Itch.io. The Bun-based loader executes obfuscated JavaScript that performs extensive anti-virtualisation checks through PowerShell and WMI commands, gathers system information and downloads encrypted payloads from command-and-control domains including silent-harvester.cc. Once deployed, NWHStealer steals browser credentials, cryptocurrency wallet data and application information, injects code into browser processes, establishes persistence through scheduled tasks and retrieves updated infrastructure details from Telegram.
Suspected OceanLotus PyPI Campaign Delivered ZiChatBot Malware
Kaspersky researchers identified malicious PyPI packages named uuid32-utils, colorinal and termncolor that deployed a previously unknown malware family called ZiChatBot on Windows and Linux systems through concealed DLL and shared library droppers. The campaign used dependency chains and self-deleting Python scripts to install malware that established persistence through Windows registry autorun keys or Linux crontab jobs, then communicated through Zulip REST APIs instead of dedicated command-and-control servers. Kaspersky linked the operation to the OceanLotus APT group with medium confidence after identifying similarities between the new droppers and previously analysed OceanLotus malware, while the malicious packages and associated Zulip organisation were removed following disclosure.
Researcher Claims Chrome Silently Downloads Gemini Nano Model
Privacy researcher Alexander Hanff reported that recent Chrome versions automatically download a roughly 4 GB Gemini Nano model file named weights.bin into the OptGuideOnDeviceModel directory on supported Windows and macOS systems. The report states Chrome enables on-device AI features through optimisation guide components, re-downloads the model after deletion, and stores feature flags and model metadata linked to Gemini Nano deployments. Hanff also documented filesystem events, updater logs and Chrome profile data showing the model installation occurred without direct user interaction during automated browser sessions.
Malicious NuGet Packages Steal Browser Credentials and Crypto Wallets
Socket researchers identified five malicious NuGet packages masquerading as Chinese .NET UI and infrastructure libraries, with roughly 65,000 downloads exposing developer workstations and CI/CD systems to credential theft. The packages used .NET Reactor obfuscation and JIT hooking to deploy an infostealer targeting saved credentials from 12 browsers, cryptocurrency wallet data from desktop and browser extensions, SSH keys, Outlook profiles, and files stored in Documents, Desktop, and Downloads. The malware exfiltrated stolen data to the domain dns-providersa2[.]com, staged archives under a fake Microsoft OneDrive path, and used 219 hidden package versions to evade hash-based detection and prolong distribution through the NuGet ecosystem.
Philips Hue Zigbee Flaw Enables Remote Code Execution
Synacktiv researchers exploited CVE-2026-3555 in the Philips Hue Bridge during Pwn2Own, achieving remote code execution over Zigbee by abusing a heap overflow in the Download Blob state machine. The vulnerability allowed attackers to send crafted ZCL frames with oversized fragments, corrupt musl allocator metadata, and gain an arbitrary write primitive through manipulated free chunk structures. The exploit used a malicious Zigbee device to trigger the flaw, overwrite a global function pointer, and execute shellcode that launched a reverse shell on the Linux-based bridge.
Daily Coverage