CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (12 May 2026)

Published: Loading…

At a Glance

  • TrickMo Android banking malware routes command-and-control traffic through The Open Network using embedded TON proxy infrastructure and .adnl endpoints across European campaigns.
  • ShinyHunters exploited a Canvas vulnerability to steal 3.65 terabytes of education data affecting 275 million records across thousands of institutions worldwide.
  • Checkmarx Jenkins AST plugin compromise enabled malicious CI/CD artefacts linked to TeamPCP intrusion and Lapsus$ extortion activity targeting GitHub repositories.
  • TanStack npm ecosystem supply-chain attack injected obfuscated credential-stealing router_init.js into widely used React routing libraries affecting GitHub Actions and cloud environments.
  • Hackers used AI-generated exploit code to target a zero-day two-factor authentication bypass in open-source web administration software during mass exploitation planning.
  • CVE-2026-41940 cPanel authentication bypass actively exploited to deploy Filemanager backdoor, SSH keys, and webshells for persistent server-level control.

Summary

TrickMo Android banking malware campaigns targeting users in France, Italy, and Austria have shifted command-and-control infrastructure into The Open Network (TON) using embedded proxying and .adnl endpoints. The redesigned architecture integrates SSH tunnelling and SOCKS5 proxying on infected devices, enabling encrypted network pivoting and remote operator access. Additional reconnaissance capabilities include DNS lookup, ping, and traceroute execution directly from compromised Android devices.

ShinyHunters exploited a vulnerability in Canvas Free-for-Teacher systems to exfiltrate 3.65 terabytes of data spanning 275 million records across thousands of educational institutions. Stolen information included usernames, institutional emails, and internal messaging data across global education environments. The group transitioned from central extortion to school-by-school targeting after initial ransom deadlines expired.

A malicious version of the Checkmarx Jenkins AST plugin was published through the Jenkins Marketplace following a supply-chain intrusion linked to TeamPCP activity. The compromise affected CI/CD environments using vulnerable plugin versions and has been associated with broader extortion operations involving repository access theft. Affected artefacts included build and scanning components used in automated security pipelines.

The TanStack npm ecosystem experienced a large-scale supply-chain compromise involving more than 80 packages, including widely used React routing components. Attackers inserted obfuscated credential-stealing modules targeting GitHub Actions workflows, cloud environments, and secret management systems. The malware leveraged CI/CD execution paths to extract sensitive tokens and authentication material.

Cybercriminal activity involving AI-generated exploit code was observed targeting a zero-day two-factor authentication bypass vulnerability in open-source web administration software. The exploit was designed for mass exploitation campaigns and incorporated automation-driven attack workflows. Additional AI-assisted activity included malware development and phishing automation across multiple threat groups.

A critical cPanel authentication bypass (CVE-2026-41940) is being actively exploited to deploy persistent backdoors on compromised servers. Attackers are installing SSH keys, PHP webshells, and a Filemanager backdoor for long-term access. The exploitation chain enables full administrative control of affected hosting environments.

A multi-year phishing campaign has impacted over 500 organisations across aviation, energy, logistics, and public administration sectors. The activity spans credential theft operations and persistent access across diverse enterprise environments. Attack patterns indicate sustained targeting across critical infrastructure domains.

Highlights of the Day

Checkmarx Malicious Jenkins Plugin Extends Supply Chain Breach

Checkmarx disclosed that a malicious version of its Jenkins AST plugin was published to the Jenkins Marketplace between 9 and 10 May 2026, affecting the Checkmarx AST Scanner plugin used in CI/CD pipelines. The company identified compromised HPI, JAR and POM artifacts linked to the incident, and released clean plugin versions including 2.0.13-848.v76e89de8a_053 after advising users to remain on version 2.0.13-829.vc72453fa_1c16. Checkmarx said the compromise is connected to the March 2026 TeamPCP attack on Trivy, which enabled unauthorised access to its GitHub repositories, publication of malicious artifacts and later data leaks attributed to the Lapsus$ extortion group.

ShinyHunters Targets Schools After Canvas Data Theft

Halcyon reported that ShinyHunters exploited a vulnerability in Instructure’s Canvas Free-For-Teacher service on 25 April 2026, claiming theft of 3.65 TB of data containing roughly 275 million records from 8,809 educational institutions. Instructure said exposed data included names, institutional email addresses, student ID numbers and Canvas inbox messages, while the group later defaced login portals at around 330 schools after an initial ransom deadline passed. ShinyHunters, which operates a data theft and extortion model without ransomware encryption, set a final negotiation deadline of 12 May 2026 after shifting from extorting Instructure directly to targeting affected schools individually.

Source: Halcyon

Police Dismantle Relaunched Crimenetwork Dark Web Marketplace

German and Spanish authorities arrested a 35-year-old German national in Mallorca accused of rebuilding the Crimenetwork dark web marketplace days after its original administrator was arrested in December 2024. The relaunched platform, which traded stolen data, drugs and forged documents, accumulated more than 22,000 users, over 100 vendors and generated more than €3.6m in revenue through commissions and seller licensing fees. Germany’s BKA said investigators seized €194,000 in assets alongside user and transaction data, while the original Crimenetwork marketplace processed at least 1000 BTC and 20,000 XMR in transactions between 2018 and 2024.

FCC Extends Security Update Waiver for Covered Devices

The US Federal Communications Commission extended until at least 1 January 2029 waivers allowing software and firmware security updates for previously authorised covered routers, uncrewed aircraft systems and UAS critical components produced in foreign countries. The waiver applies to Class I and Class II permissive changes under FCC rules, including vulnerability patches and operating system compatibility updates, despite the devices being added to the FCC Covered List in 2025 and 2026. The FCC said the measure covers devices authorised before their Covered List designation and follows concerns that existing restrictions could block security-related updates intended to mitigate harm to US consumers.

Google Threat Intelligence Group said cyber criminals used an AI-generated Python exploit to target a zero-day two-factor authentication bypass flaw in a popular open-source web administration platform during a planned mass exploitation campaign. The report also described AI-assisted malware including PROMPTSPY, an Android backdoor that uses the Gemini API to autonomously navigate device interfaces, replay biometric authentication gestures and execute commands through accessibility services. Google linked additional AI-enabled activity to PRC, DPRK and Russia-aligned threat actors using large language models for exploit research, malware obfuscation, phishing reconnaissance, deepfake operations and supply chain attacks targeting repositories including Trivy, LiteLLM and Checkmarx.

Hackers Exploit cPanel Flaw to Deploy Persistent Backdoors

Qianxin XLab reported that the threat group “Mr_Rot13” is actively exploiting CVE-2026-41940, a critical unauthenticated authentication bypass vulnerability in cPanel & WHM with a CVSS score of 9.8. The attackers deployed a Go-based infector that changes root passwords, implants SSH keys, installs PHP webshells, injects credential-stealing JavaScript into cPanel login pages and deploys a cross-platform backdoor named Filemanager for remote administration. XLab linked the activity to infrastructure dating back to 2020, including the domain wrned.com and a previously undetected PHP backdoor uploaded to VirusTotal in 2022 that used ROT13 and RC4 obfuscation techniques.

TanStack Packages Hijacked in Expanding Supply-Chain Campaign

Socket researchers identified malicious code in 84 compromised npm packages under the TanStack namespace, including @tanstack/react-router, where attackers added an obfuscated router_init.js credential stealer targeting GitHub Actions, AWS, Kubernetes and HashiCorp Vault environments. The malware used GitHub Actions cache poisoning and a pull_request_target workflow attack to obtain OIDC publishing access, then deployed persistence mechanisms through Claude Code and VS Code configuration files while exfiltrating secrets through the Session decentralised messaging network. Socket linked the incident to the ongoing Mini Shai-Hulud campaign, which also compromised OpenSearch, Guardrails AI, Mistral AI and additional npm and PyPI packages using malicious install hooks and remote payload execution.

Source: Socket

Attackers Exploit AD CS Misconfigurations for Privilege Escalation

Palo Alto Networks Unit 42 detailed how attackers are abusing Active Directory Certificate Services misconfigurations, including ESC1 template flaws and shadow credentials, to impersonate privileged accounts and maintain persistent access. The report describes widespread use of tools including Certify, Certipy and pyWhisker to exploit permissive certificate templates, manipulate the msDS-KeyCredentialLink attribute and obtain Kerberos tickets through PKINIT authentication. Unit 42 linked the techniques to ransomware and state-backed operations, citing exploitation of CVE-2022-26923 and recent investigations involving Fighting Ursa and Fog ransomware activity targeting enterprise Active Directory environments.

TrickMo Android Malware Shifts C2 Traffic to TON

ThreatFabric identified a redesigned TrickMo Android banking malware variant targeting banking, fintech, wallet and authenticator applications in France, Italy and Austria through campaigns masquerading as TikTok and streaming apps. The malware routes command-and-control traffic through The Open Network using embedded TON proxy infrastructure and .adnl endpoints, while retaining capabilities including credential theft, screen streaming, SMS interception and full device remote control through abused accessibility services. The updated variant also adds SSH tunnelling, SOCKS5 proxying, DNS lookups and network reconnaissance commands, allowing compromised Android devices to operate as encrypted traffic pivots and network exit nodes.

Daily Coverage

Developments
Trickmo Ton MigrationCanvas Data TheftJenkins Plugin BreachTanstack Compromise
Vulnerabilities
CVE-2026-45185Exim 4.97 (Critical)CVE-2026-32161CVE-2026-33109CVE-2022-26923CVE-2026-41940Cpanel 11.110.0 (Critical)CVE-2026-8260Dcs-935L 1.10.01 (High)CVE-2026-30893Wazuh >= 4.4.0, < 4.14.4 (Critical)CVE-2025-12659Simcenter Femap (High)CVE-2026-28941Ios And Ipados (High)CVE-2026-28940Ios And Ipados (High)
Threat Groups
SeedwormMuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.