CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (13 May 2026)

Published: Loading…

At a Glance

  • TeamPCP-linked Mini Shai-Hulud supply chain worm compromised npm and PyPI packages via GitHub Actions workflows, exfiltrating CI/CD secrets and propagating through stolen registry credentials across ecosystems.
  • Foxconn confirmed a cyberattack impacting North American factories after Nitrogen ransomware claimed theft of 8 TB of data spanning over 11 million files including internal engineering documentation.
  • Exim patched CVE-2026-45185, a GnuTLS-based BDAT use-after-free vulnerability in SMTP message handling that could allow remote code execution via malformed TLS session teardown sequences.
  • Fortinet addressed CVE-2026-44277 and CVE-2026-26083 in FortiAuthenticator and FortiSandbox, enabling unauthenticated command execution through improper access control and missing authorisation flaws.
  • Microsoft’s May 2026 Patch Tuesday fixed up to 137 vulnerabilities across Windows and enterprise products, including multiple remote code execution flaws but no actively exploited zero-days.
  • Attackers used malicious npm and PyPI packages impersonating trusted libraries including TanStack, Mistral AI, UiPath and OpenSearch in a coordinated software supply chain compromise campaign.

Summary

Supply chain compromise activity spread across npm and PyPI ecosystems, with malicious packages impersonating widely used developer libraries including TanStack, Mistral AI, and OpenSearch. The campaign leveraged GitHub Actions workflows to inject payloads and harvest CI/CD secrets across affected repositories. Compromised packages were modified to enable credential theft and self-propagation through registry access tokens.

Enterprise infrastructure incidents included a Foxconn cyberattack affecting North American manufacturing operations following claims of large-scale data theft by a ransomware group. The dataset allegedly included internal engineering documentation and technical drawings associated with multiple major technology clients. Operational disruption was reported across multiple factories while production recovery processes were initiated.

Multiple vendor vulnerabilities were disclosed affecting widely deployed infrastructure software. Exim patched a GnuTLS-based BDAT use-after-free flaw enabling potential remote code execution during TLS session teardown in SMTP processing. Fortinet addressed unauthenticated command execution vulnerabilities in FortiAuthenticator IAM and FortiSandbox web interfaces affecting enterprise identity and security inspection systems.

Microsoft released its monthly security updates addressing a broad set of vulnerabilities across Windows and enterprise platforms. The update covered remote code execution, elevation of privilege, and spoofing issues across components including Office, Azure services, and Windows networking stacks. No zero-day vulnerabilities were confirmed as part of the release.

Highlights of the Day

Microsoft fixes 120 vulnerabilities in May 2026 Patch Tuesday

Microsoft May 2026 Patch Tuesday resolves 120 vulnerabilities across Windows and applications, including 17 critical issues, 14 remote code execution flaws, and no zero-days disclosed. Multiple Microsoft Office vulnerabilities affecting Word and Excel enable remote code execution through malicious documents opened by users or rendered in the preview pane. Additional fixes include vulnerabilities in .NET, Azure services, SharePoint, Windows components, and Windows DNS, covering elevation of privilege, spoofing, and denial of service flaws.

Supply chain worm compromises npm and PyPI packages via GitHub Actions

TeamPCP launched a coordinated supply chain attack on 11 May 2026 targeting npm and PyPI ecosystems, compromising multiple high-profile namespaces via GitHub Actions workflows. The TanStack breach used a malicious pull_request_target workflow to poison GitHub Actions cache, later abusing OIDC tokens to publish malicious package versions. The payload acts as a credential-stealing worm targeting CI/CD secrets, cloud credentials and Kubernetes tokens, exfiltrating data and self-propagating through stolen registry access.

Source: Wiz

Foxconn confirms cyberattack after ransomware data theft claims

Foxconn confirms cyberattack affecting North American operations after Nitrogen ransomware listing, claiming theft of 8 TB and over 11 million files including confidential instructions, project docs and technical drawings linked to major clients. Foxconn spokesperson said response mechanism was activated, operational measures implemented, affected factories are resuming normal production in North America. Nitrogen ransomware group active since 2023 is linked to Conti-derived codebase, with ESXi decryptor flaws that may prevent file recovery after ransom payment.

Exim BDAT Use-After-Free Flaw Enables Remote Code Execution

Exim released fixes for CVE-2026-45185 (Dead.Letter), a use-after-free in BDAT message body parsing within GnuTLS-backed SMTP sessions enabling potential remote code execution. Affected Exim 4.97 to 4.99.2 builds using USE_GNUTLS=yes are vulnerable when BDAT receives TLS close_notify followed by cleartext data, fixed in 4.99.3 reported by XBOW.

Fortinet fixes critical RCE flaws in FortiSandbox and FortiAuthenticator

CVE-2026-44277 improper access control in FortiAuthenticator IAM allows unauthenticated code execution via crafted requests, patched in 6.5.7, 6.6.9, 8.0.3; FortiAuthenticator Cloud not impacted. CVE-2026-26083 missing authorization in FortiSandbox, FortiSandbox Cloud and PaaS web UI enables unauthenticated HTTP-based command execution; Fortinet did not confirm in-the-wild exploitation. CISA has previously catalogued 24 Fortinet vulnerabilities as actively exploited including EMS flaws and authentication bypass CVE-2026-35616.

Daily Coverage

Developments
Npm/Pypi WormFoxconn BreachExim RceFortinet Rces
Vulnerabilities
CVE-2026-40361CVE-2024-55591CVE-2025-32433CVE-2025-33073Windows_10_1507 10.0.10240.21034 (High)CVE-2026-45185Exim 4.97 (Critical)CVE-2026-44277CVE-2026-26083Fortisandbox Cloud 5.0.0 (Critical)CVE-2026-35616Forticlientems 7.4.5 (Critical)
Threat Groups
CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.Static Kitten[Also known as: MuddyWater, Seedworm] MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.