Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (13 May 2026)
Published: Loading…
At a Glance
- TeamPCP-linked Mini Shai-Hulud supply chain worm compromised npm and PyPI packages via GitHub Actions workflows, exfiltrating CI/CD secrets and propagating through stolen registry credentials across ecosystems.
- Foxconn confirmed a cyberattack impacting North American factories after Nitrogen ransomware claimed theft of 8 TB of data spanning over 11 million files including internal engineering documentation.
- Exim patched CVE-2026-45185, a GnuTLS-based BDAT use-after-free vulnerability in SMTP message handling that could allow remote code execution via malformed TLS session teardown sequences.
- Fortinet addressed CVE-2026-44277 and CVE-2026-26083 in FortiAuthenticator and FortiSandbox, enabling unauthenticated command execution through improper access control and missing authorisation flaws.
- Microsoft’s May 2026 Patch Tuesday fixed up to 137 vulnerabilities across Windows and enterprise products, including multiple remote code execution flaws but no actively exploited zero-days.
- Attackers used malicious npm and PyPI packages impersonating trusted libraries including TanStack, Mistral AI, UiPath and OpenSearch in a coordinated software supply chain compromise campaign.
Summary
Supply chain compromise activity spread across npm and PyPI ecosystems, with malicious packages impersonating widely used developer libraries including TanStack, Mistral AI, and OpenSearch. The campaign leveraged GitHub Actions workflows to inject payloads and harvest CI/CD secrets across affected repositories. Compromised packages were modified to enable credential theft and self-propagation through registry access tokens.
Enterprise infrastructure incidents included a Foxconn cyberattack affecting North American manufacturing operations following claims of large-scale data theft by a ransomware group. The dataset allegedly included internal engineering documentation and technical drawings associated with multiple major technology clients. Operational disruption was reported across multiple factories while production recovery processes were initiated.
Multiple vendor vulnerabilities were disclosed affecting widely deployed infrastructure software. Exim patched a GnuTLS-based BDAT use-after-free flaw enabling potential remote code execution during TLS session teardown in SMTP processing. Fortinet addressed unauthenticated command execution vulnerabilities in FortiAuthenticator IAM and FortiSandbox web interfaces affecting enterprise identity and security inspection systems.
Microsoft released its monthly security updates addressing a broad set of vulnerabilities across Windows and enterprise platforms. The update covered remote code execution, elevation of privilege, and spoofing issues across components including Office, Azure services, and Windows networking stacks. No zero-day vulnerabilities were confirmed as part of the release.
Highlights of the Day
Microsoft fixes 120 vulnerabilities in May 2026 Patch Tuesday
Microsoft May 2026 Patch Tuesday resolves 120 vulnerabilities across Windows and applications, including 17 critical issues, 14 remote code execution flaws, and no zero-days disclosed. Multiple Microsoft Office vulnerabilities affecting Word and Excel enable remote code execution through malicious documents opened by users or rendered in the preview pane. Additional fixes include vulnerabilities in .NET, Azure services, SharePoint, Windows components, and Windows DNS, covering elevation of privilege, spoofing, and denial of service flaws.
Supply chain worm compromises npm and PyPI packages via GitHub Actions
TeamPCP launched a coordinated supply chain attack on 11 May 2026 targeting npm and PyPI ecosystems, compromising multiple high-profile namespaces via GitHub Actions workflows. The TanStack breach used a malicious pull_request_target workflow to poison GitHub Actions cache, later abusing OIDC tokens to publish malicious package versions. The payload acts as a credential-stealing worm targeting CI/CD secrets, cloud credentials and Kubernetes tokens, exfiltrating data and self-propagating through stolen registry access.
Foxconn confirms cyberattack after ransomware data theft claims
Foxconn confirms cyberattack affecting North American operations after Nitrogen ransomware listing, claiming theft of 8 TB and over 11 million files including confidential instructions, project docs and technical drawings linked to major clients. Foxconn spokesperson said response mechanism was activated, operational measures implemented, affected factories are resuming normal production in North America. Nitrogen ransomware group active since 2023 is linked to Conti-derived codebase, with ESXi decryptor flaws that may prevent file recovery after ransom payment.
Exim BDAT Use-After-Free Flaw Enables Remote Code Execution
Exim released fixes for CVE-2026-45185 (Dead.Letter), a use-after-free in BDAT message body parsing within GnuTLS-backed SMTP sessions enabling potential remote code execution. Affected Exim 4.97 to 4.99.2 builds using USE_GNUTLS=yes are vulnerable when BDAT receives TLS close_notify followed by cleartext data, fixed in 4.99.3 reported by XBOW.
Fortinet fixes critical RCE flaws in FortiSandbox and FortiAuthenticator
CVE-2026-44277 improper access control in FortiAuthenticator IAM allows unauthenticated code execution via crafted requests, patched in 6.5.7, 6.6.9, 8.0.3; FortiAuthenticator Cloud not impacted. CVE-2026-26083 missing authorization in FortiSandbox, FortiSandbox Cloud and PaaS web UI enables unauthenticated HTTP-based command execution; Fortinet did not confirm in-the-wild exploitation. CISA has previously catalogued 24 Fortinet vulnerabilities as actively exploited including EMS flaws and authentication bypass CVE-2026-35616.
Daily Coverage