CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (11 May 2026)

Published: Loading…

At a Glance

  • Ollama heap out-of-bounds read CVE-2026-7482 allows unauthenticated remote attackers to leak process memory from over 300,000 servers globally via GGUF model loading.
  • Linux kernel Dirty Frag chain combining CVE-2026-43284 and CVE-2026-43500 enables local privilege escalation to root through IPsec ESP and RxRPC page-cache corruption paths.
  • German authorities shut down Crimenetwork reboot marketplace, arresting its operator in Mallorca after €3.6 million revenue and seizing €194,000 in assets.
  • Attackers abuse Google Ads and Claude.ai shared chats to distribute macOS malware using base64 scripts, loader.sh payloads, and MacSync infostealer variants.
  • HookedWing phishing campaign uses GitHub.io infrastructure and compromised servers to target aviation, government, and energy sectors, stealing over 2,500 credentials.

Summary

The Ollama framework is affected by CVE-2026-7482, a heap out-of-bounds read enabling remote unauthenticated memory leakage across large-scale deployments exceeding 300,000 servers. The flaw impacts GGUF model processing and allows extraction of process memory including credentials, prompts, and API keys through model loading and API endpoints. The issue is tracked as Bleeding Llama and carries a CVSS score of 9.1.

The Linux kernel Dirty Frag vulnerability chain combines CVE-2026-43284 and CVE-2026-43500 to enable local privilege escalation to root via IPsec ESP and RxRPC page-cache manipulation. The exploit affects multiple major distributions including Ubuntu, RHEL, Fedora, and AlmaLinux through kernel-level memory corruption mechanisms. Exploitation occurs after initial local access via compromised services or containers.

A shutdown operation against the Crimenetwork marketplace led to the arrest of its operator in Mallorca and seizure of €194,000 following infrastructure generating €3.6 million in illicit revenue. The rebooted platform supported over 22,000 users and 100 vendors before being dismantled by German and Spanish law enforcement. The original operator had previously received a prison sentence of seven years and ten months.

MacOS systems are targeted through malvertising campaigns abusing Google Ads and Claude.ai shared chats to deliver loader.sh-based malware via terminal commands. The infection chain deploys MacSync infostealer variants that extract browser credentials, cookies, and Keychain data following system profiling checks. The campaigns use polymorphic payload delivery and CIS-region filtering logic.

The HookedWing phishing campaign operates across GitHub.io and compromised infrastructure to distribute credential-harvesting pages targeting aviation, government, and energy sectors. The operation has collected more than 2,500 credentials across 500 organisations using email-based phishing lures and dynamic injection kits. Infrastructure reuse spans multiple hosting platforms and long-term compromised servers.

Highlights of the Day

Attackers abuse Google Ads and Claude.ai shared chats to deliver macOS malware via installation guides prompting Terminal commands, leading to base64 shell scripts retrieving a 'loader.sh' payload from external domains with polymorphic responses and checks for Russian or CIS keyboard locales and system profiling before macOS osascript execution. It steals browser credentials, cookies and Keychain data via MacSync infostealer variants, either skipping profiling or exfiltrating system data to attacker infrastructure.

Linux Kernel Dirty Frag Chain Enables Root Escalation

Linux kernel Dirty Frag (CVE-2026-43284, CVE-2026-43500) enables local users to escalate to root via IPsec ESP/RxRPC paths corrupting page-cache memory without altering disk files. Limited in-the-wild exploitation involves su-based privilege escalation affecting Ubuntu, RHEL, Fedora and AlmaLinux in cloud environments after initial access via compromised credentials or services. The issue impacts kernel modules for IPsec ESP and RxRPC with CVSS 7.8, enabling host compromise on non-containerised systems and system takeover in containerised deployments.

German Authorities Shut Down Crimenetwork Reboot

German authorities shut down the rebooted Crimenetwork marketplace and arrested its suspected administrator in Mallorca under a European arrest warrant involving BKA and Spanish police. The relaunch platform generated at least €3.6m in revenue, amassed about 22,000 users and over 100 vendors, and saw €194,000 in assets seized. The suspect faces charges under German Criminal Code provisions, while the original operator received seven years and ten months’ imprisonment plus €10 million forfeiture.

Ollama Flaw Leaks Memory via Malicious Model Files

Ollama before 0.17.1 contains CVE-2026-7482, a heap out-of-bounds read in the GGUF model loader tracked as Bleeding Llama, enabling unauthenticated remote attackers to leak process memory via /api/create, affecting over 300,000 servers with CVSS 9.1. Exploitation involves crafted GGUF files triggering heap reads through /api/create and subsequent data exfiltration via /api/push, exposing environment variables, API keys, system prompts and conversation data from the Ollama process memory.

HookedWing Phishing Campaign Targets Global Aviation and Government Sectors

Operation HookedWing is a multi-year phishing campaign active since 2022 using a custom phishing kit to target organisations across multiple sectors globally. Analysis by SOCRadar Threat Research team identifies GitHub.io landing pages and compromised servers hosting C2 infrastructure, with over 2,500 credentials and 500 organisations affected. Victims span aviation, government and energy sectors, with log analysis indicating targeted selection of high-value organisations across Africa, South Asia and Europe.

Daily Coverage

Developments
Ollama Memory LeakDirty Frag Linux LpeCrimenetwork TakedownMac Malware Campaign
Vulnerabilities
CVE-2026-43284Linux Cac2661C53F35Cbe651Bef9B07026A5A05Ab8Ce0CVE-2026-43500Linux D0D5C0Cd1E711C98703F3544C1E6Fc1372898De5CVE-2026-41940Cpanel 11.110.0 (Critical)CVE-2026-7482CVE-2026-42231N8N < 1.123.32 (High)
Threat Groups
CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.SilenceSilence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, Azerbaijan, Poland and Kazakhstan. They compromised various banking systems, including the Russian Central Bank's Automated Workstation Client, ATMs, and card processing.