CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (8 May 2026)

Published: Loading…

At a Glance

  • Ivanti Endpoint Manager Mobile CVE-2026-6973 allows authenticated administrators to execute remote code, with limited exploitation observed in on-prem deployments.
  • Palo Alto Networks disclosed CVE-2026-0300 in PAN-OS User-ID Authentication Portal enabling unauthenticated remote code execution with root privileges on exposed firewalls.
  • Google released Chrome 148 with 127 security fixes, including critical Blink integer overflow and multiple use-after-free vulnerabilities across core browser components.
  • vm2 Node.js library contains multiple critical sandbox escape flaws enabling arbitrary code execution through prototype pollution and allowlist bypass conditions.
  • TCLBANKER banking trojan spreads via WhatsApp and Outlook using MSI installers and browser monitoring to target financial services across Brazilian systems.

Summary

Multiple enterprise platforms were affected by high-impact vulnerabilities and active exploitation, including Palo Alto Networks PAN-OS, Ivanti Endpoint Manager Mobile, and exposed firewall management services. CVE-2026-0300 in PAN-OS enables unauthenticated remote code execution with root privileges, with exploitation observed on internet-facing deployments. Ivanti disclosed CVE-2026-6973 in EPMM enabling administrative remote code execution under limited exploitation conditions.

Browser and software supply-chain exposure continued through widespread vulnerability disclosures and patch cycles affecting widely deployed components. Google Chrome 148 addressed 127 security vulnerabilities, including integer overflow and use-after-free flaws in rendering and GPU subsystems. The vm2 Node.js library was found to contain multiple critical sandbox escape vulnerabilities enabling arbitrary code execution on host systems.

Malware distribution campaigns leveraged common communication and development platforms to deliver credential theft and remote access payloads. TCLBANKER spread via WhatsApp and Outlook using MSI installers and browser session monitoring to target Brazilian financial services and cryptocurrency platforms. Multi-stage infection chains also delivered Vidar stealer through AutoIt loaders using anti-analysis checks and command-and-control infrastructure.

AI-assisted development and automation tools were impacted by security weaknesses enabling supply-chain manipulation and data exposure. A Gemini CLI prompt injection flaw allowed attackers to manipulate GitHub issue triage workflows and exfiltrate repository secrets through workflow environment access. Additional research highlighted AI coding agent vulnerabilities enabling code execution and supply-chain compromise through prompt injection techniques.

Enterprise and infrastructure environments faced continued targeting through exploitation of software components and enterprise tooling vulnerabilities. Cisco patched multiple high-severity flaws across enterprise products, including denial-of-service and remote code execution conditions. Cross-platform exploitation efforts extended across cloud, container, and developer ecosystems through credential theft frameworks and malicious packages.

Phishing and infrastructure abuse campaigns expanded through large-scale use of trusted services and compromised platforms. Attackers leveraged Vercel hosting infrastructure for phishing distribution and abused AI-themed scam ecosystems spanning thousands of domains. Additional campaigns used malicious packages and fake AI service sites to deliver backdoors and information-stealing malware across Windows and Linux systems.

Highlights of the Day

vm2 Node.js Library Flaws Enable Sandbox Escape and RCE

A dozen critical vm2 Node.js library vulnerabilities, including CVE-2026-24118 and CVE-2026-44006, enable sandbox escape and arbitrary code execution on host systems. CVE list includes multiple CVSS 9.8–10.0 issues such as code injection, prototype pollution, and allowlist bypass affecting versions ≤3.11.1 and earlier. Maintainer patches span releases 3.10.5 to 3.11.2, following prior CVE-2026-22709 fixes and repeated sandbox bypass disclosures in vm2 across Node.js sandboxing environments.

TCLBANKER Banking Trojan Spreads via WhatsApp and Outlook

TCLBANKER, tracked in REF3076, is a Brazilian banking trojan linked to the MAVERICK/SORVEPOTEL family that spreads via MSI installers abusing Logitech Logi AI Prompt Builder DLL sideloading, using anti-analysis checks and geofencing while targeting 59 Brazilian banking, fintech and cryptocurrency domains through browser URL monitoring via UI Automation. Worm modules include WhatsApp Web session hijacking for spam distribution and an Outlook COM email bot, using Cloudflare Workers C2 and WPF overlays with WebSocket command control.

Gemini CLI Supply Chain Hit by CVSS 10 Prompt Injection

Researchers reported CVSS 10 TrustIssues vulnerability in Google's Gemini CLI GitHub workflow, where AI issue-triage agents were prompt-injected via public issues to execute attacker instructions. Attackers could exfiltrate workflow secrets and GITHUB_TOKEN by reading environment and .git/config persisted by actions/checkout then pivot to actions:write to achieve full repository supply-chain compromise. Google issued GHSA-wpqr-6v78-jr5g, patching run-gemini-cli action 0.1.22 and Gemini CLI 0.39.1/0.40.0-preview.3, enforcing tool allowlisting in --yolo mode and recommending disabling credential persistence in checkout steps.

Cisco Patches High-Severity Enterprise Product Vulnerabilities

Cisco released patches addressing five high-severity vulnerabilities, including CVE-2026-20034 and CVE-2026-20035 in Unity Connection enabling SSRF and potential remote code execution as root. CVE-2026-20185 affects SG350 and SG350X switches in SNMP subsystem, where improper error handling allows authenticated attackers with valid credentials to trigger device reload denial-of-service. CVE-2026-20188 affects Crosswork and NSO enabling unauthenticated DoS via missing rate limiting, and CVE-2026-20167 in IoT Field Director allows crafted input to trigger reload denial-of-service.

VLM Study Shows Perturbations Enable Prompt Injection Evasion

Research on multimodal typographic prompt injection uses SSA-CWA optimisation on degraded text images with surrogate embedding models such as CLIP, SigLIP and JinaCLIP. Optimisation increases attack success rates across GPT-4o, Claude Sonnet 4.5, Mistral-Large-3 and Qwen3-VL-4B, shifting failures between readability recovery and safety refusal modes. Findings show perturbed images can evade OCR-based filters while remaining model-readable and also suppress refusal behaviour, enabling transfer across models without access to internals.

AutoIt Loader Delivers Vidar Stealer via Multi-Stage Chain

A multi-stage infection chain begins with MicrosoftToolkit.exe executing a command shell that stages disguised Swingers.dot.bat and AutoIt loader Replies.scr via extract32.exe. The AutoIt-compiled Replies.scr performs process enumeration, uses findstr and tasklist for defense evasion, and establishes outbound C2 communication linked to Vidar stealer infrastructure. Vidar stealer deployment enables credential, browser and cryptocurrency wallet theft while performing anti-analysis checks and post-execution cleanup to remove forensic artefacts.

Chrome 148 Releases with 127 Security Vulnerability Fixes

Google released Chrome 148 to the stable channel with 127 security fixes, including three critical-severity vulnerabilities affecting the Blink rendering engine and Chromoting and Mobile components. CVE-2026-7896 is an integer overflow in Blink enabling heap memory corruption via crafted HTML, while CVE-2026-7897 and CVE-2026-7898 are use-after-free flaws identified in Chrome components. The update also patches over 30 high-severity issues across V8, ANGLE, GPU, WebRTC, and other subsystems, with bug bounty rewards reaching $138,000 for external researchers.

Critical PAN-OS Flaw Enables Remote Code Execution

Palo Alto Networks disclosed CVE-2026-0300, a critical buffer overflow in PAN-OS User-ID Authentication Portal enabling unauthenticated remote code execution with root privileges via crafted packets. Active exploitation has been confirmed against internet-exposed PA-Series and VM-Series firewalls, prompting CISA KEV listing and mandated remediation for US federal agencies. Prisma Access, Cloud NGFW and Panorama are unaffected, while fixed PAN-OS releases address impacted versions across multiple branches of firewall software.

Ivanti EPMM Flaw Enables Admin-Level Remote Code Execution

Ivanti disclosed CVE-2026-6973 in Endpoint Manager Mobile enabling authenticated administrators to obtain remote code execution, with limited exploitation observed in on-prem deployments. Additional CVEs CVE-2026-5786, 5787, 5788 and 7821 affect EPMM, enabling privilege escalation, certificate impersonation, arbitrary method invocation and device enrollment information disclosure. Fixed releases 12.6.1.1, 12.7.0.1 and 12.8.0.1 address all issues, with Ivanti noting on-prem EPMM affected while cloud services remain unaffected.

Daily Coverage

Developments
Pan-Os RceIvanti Epmm ExploitChrome 148 PatchVm2 Sandbox Escape
Vulnerabilities
CVE-2026-6973Endpoint_Manager_Mobile 12.6.1.1 (High)CVE-2026-31431Linux 72548B093Ee38A6D4F2A19E6Ef1948Ae05C181F7 (High)CVE-2025-68670CVE-2026-43284Linux Cac2661C53F35Cbe651Bef9B07026A5A05Ab8Ce0CVE-2026-43500Linux D0D5C0Cd1E711C98703F3544C1E6Fc1372898De5CVE-2026-23918CVE-2026-20035CVE-2026-24118CVE-2026-20167CVE-2026-7898
Threat Groups
CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.