CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (14 May 2026)

Published: Loading…

At a Glance

  • GemStuffer published more than 150 RubyGems packages exfiltrating scraped UK council portal data through uploaded .gem archives and API requests.
  • TeamPCP expanded supply-chain attacks across npm, PyPI and GitHub Actions, compromising OpenSearch, Mistral AI and Bitwarden CLI packages.
  • Intel and AMD patched 70 vulnerabilities including CVE-2026-20794 and CVE-2026-0481 affecting ESXi drivers, ROCm services and EPYC platforms.
  • Microsoft patched zero-click Outlook vulnerability CVE-2026-40361 enabling remote code execution through Preview Pane email rendering in Exchange environments.
  • Researchers disclosed Fragnesia Linux kernel vulnerability enabling local attackers to corrupt page cache contents and gain root privileges through ESP-in-TCP.

Summary

GemStuffer abused RubyGems as a data exfiltration mechanism by uploading more than 150 malicious packages containing scraped UK council portal information. RubyGems temporarily suspended new account registrations and throttled webhooks while responding to coordinated spam publishing activity involving newly created accounts.

TeamPCP expanded software supply-chain attacks across npm, PyPI, Docker Hub and GitHub Actions by compromising trusted development and release workflows. Trojanised packages affected OpenSearch, Mistral AI and Bitwarden CLI components while malicious workflows harvested GitHub tokens, cloud credentials and cryptocurrency secrets.

Microsoft released May Patch Tuesday updates addressing more than 130 vulnerabilities across Windows, Office, Azure, SharePoint and graphics components. The updates included CVE-2026-40361, a critical Outlook and Word use-after-free flaw enabling zero-click remote code execution through Preview Pane rendering.

Intel and AMD issued more than two dozen advisories covering 70 vulnerabilities affecting graphics drivers, firmware, processors and cloud software platforms. Critical flaws included Intel ESXi graphics driver vulnerability CVE-2026-20794 and AMD ROCm Device Metrics Exporter vulnerability CVE-2026-0481 exposing unauthenticated GPU-Agent access.

Researchers disclosed Fragnesia, a Linux kernel privilege escalation flaw affecting the XFRM ESP-in-TCP subsystem and enabling local attackers to obtain root access. Separate disclosures included critical Exim mail transfer agent remote code execution risk and Composer vulnerabilities exposing GitHub Actions authentication tokens in CI logs.

Nitrogen ransomware claimed responsibility for a cyberattack affecting Foxconn North American factories and alleged theft of eight terabytes of internal data. Internal leaks from The Gentlemen ransomware operation exposed affiliate coordination, network intrusion techniques and evaluation of Fortinet, Cisco and Microsoft 365 attack paths.

G7 cyber agencies and the European Commission published guidance defining minimum Software Bill of Materials elements for AI supply-chain transparency and cybersecurity. Vietnam separately announced plans for a domestic government cloud platform intended to reduce reliance on foreign providers and strengthen national data sovereignty.

Highlights of the Day

GemStuffer Abuses RubyGems for Data Exfiltration

Socket identified a campaign named GemStuffer that published more than 155 malicious RubyGems packages which scraped UK local government ModernGov portals and exfiltrated collected data through uploaded .gem archives. The payloads fetched council calendar and committee pages from Lambeth, Wandsworth and Southwark portals, embedded the responses into valid gem packages, then pushed them to RubyGems using hardcoded API tokens and direct API POST requests. Ruby Central said RubyGems temporarily disabled new account registrations and throttled webhooks while responding to a coordinated spam-publishing campaign involving newly created accounts and junk packages.

Source: Socket

TeamPCP Hijacks CI Pipelines in Expanding Supply Chain Campaign

Trend Micro linked TeamPCP to at least seven supply chain attacks between March and April 2026, including compromises affecting Checkmarx KICS, elementary-data and Bitwarden CLI through Docker Hub, PyPI, GitHub Actions and VS Code extensions. The KICS attack used poisoned Docker images, modified GitHub Actions workflows and malicious VS Code extensions to steal GitHub PATs, npm tokens, cloud credentials, SSH keys and AI tooling secrets, with stolen npm tokens later used to publish a trojanised @bitwarden/cli v2026.4.0 package. The elementary-data incident exploited unsanitised GitHub Actions comment handling to execute injected shell commands, trigger the project’s release pipeline and publish a malicious signed PyPI package containing a Python .pth credential stealer that harvested AWS, Kubernetes, database and cryptocurrency secrets while making live AWS Secrets Manager API calls.

Fragnesia Linux Kernel Flaw Enables Root Privilege Escalation

Researchers disclosed Fragnesia, a new Linux local privilege escalation vulnerability affecting the kernel’s XFRM ESP-in-TCP subsystem that allows unprivileged attackers to corrupt read-only page cache contents and obtain root access. The flaw stems from improper handling of shared page fragments during skb coalescing, enabling attackers to manipulate AES-GCM decryption in queued TCP data and overwrite cached binaries such as /usr/bin/su without modifying files on disk. Researchers demonstrated exploitation using user and network namespaces with CAP_NET_ADMIN inside isolated namespaces, while Ubuntu AppArmor restrictions on unprivileged user namespaces may partially mitigate attacks.

Source: Wiz

The Gentlemen Ransomware Leak Exposes Internal Operations

Check Point Research analysed leaked internal chats and backend data from The Gentlemen ransomware-as-a-service operation, exposing nine operator accounts, affiliate coordination, ransom negotiations and infrastructure linked to roughly 332 published victims during 2026. The leak revealed the group’s use of Fortinet and Cisco edge devices, NTLM relay attacks, OWA and Microsoft 365 credential logs, and active evaluation of CVE-2024-55591, CVE-2025-32433 and CVE-2025-33073 for network intrusions. Researchers also identified eight affiliate TOX IDs tied to 29 ransomware campaigns, while leaked conversations showed the administrator zeta88 directly deploying ransomware, managing payouts and discussing AI-assisted development of the group’s tooling and control panels.

Intel and AMD Patch 70 Security Flaws Across Product Lines

Intel and AMD released more than two dozen advisories during May 2026 Patch Tuesday, addressing 70 vulnerabilities affecting graphics drivers, firmware, processors, cloud drivers and management software. Intel patched critical buffer overflow flaw CVE-2026-20794 in the Data Center Graphics Driver for VMware ESXi, while AMD fixed critical vulnerability CVE-2026-0481 in the ROCm Device Metrics Exporter that exposed an unauthenticated GPU-Agent gRPC service on port 50061. Additional high-severity vulnerabilities affected Intel EMA, Vision software and QuickAssist Technology drivers, alongside AMD Secure Processor, EPYC platforms, Zen 2 cache operations, RAID drivers and ESXi cloud drivers, with potential impacts including privilege escalation, arbitrary code execution and unauthorised memory access.

Microsoft Fixes Critical Zero-Click Outlook RCE Flaw

Microsoft patched CVE-2026-40361, a critical use-after-free vulnerability in Microsoft Word and Outlook that enables remote code execution when a victim previews or reads a specially crafted email. Researcher Haifei Li said the flaw affects a shared DLL heavily used by Word and Outlook, allowing zero-click attacks in Exchange Server environments without requiring users to open links or attachments. Microsoft rated exploitation as “more likely” and confirmed the Preview Pane is an attack vector, with affected products including Microsoft 365 Apps, Office 2019, Office LTSC and Word 2016.

G7 Agencies Publish AI SBOM Guidance Framework

Cyber agencies from G7 nations and the EU published guidance defining minimum elements for Software Bills of Materials for AI, aiming to improve transparency and cybersecurity across AI supply chains. The framework outlines seven clusters covering metadata, models, datasets, infrastructure, security properties and software dependencies, with guidance applying to both public and private sector AI systems. The document states that AI SBOMs alone are insufficient for supply chain protection and should integrate with vulnerability management tools, security advisories and broader cybersecurity monitoring mechanisms.

Foxconn Confirms Cyberattack on North American Factories

Foxconn confirmed that several North American factories were impacted by a cyberattack attributed to the Nitrogen ransomware group, which listed the company on its leak site in March 2026. The attackers claim to have stolen around 8TB of data comprising more than 11 million files, including confidential documents and schematics linked to major technology customers such as Apple, Intel, Google, Dell and Nvidia. Foxconn stated that its cybersecurity team activated incident response procedures and that affected facilities are now resuming normal production while investigations continue.

Daily Coverage

Developments
Outlook Zero-Click RceTeampcp CampaignGemstuffer ExfiltrationFragnesia Privilege Escalation
Vulnerabilities
CVE-2026-46300CVE-2026-20182Cisco Catalyst Sd-Wan Manager 20.1.12 (Critical)CVE-2026-42945Nginx Plus R36 (High)CVE-2026-44338CVE-2026-20133Cisco Catalyst Sd-Wan Manager 20.1.12 (Medium)CVE-2026-20128CVE-2026-20122CVE-2026-45398CVE-2026-40361CVE-2025-33073Windows_10_1507 10.0.10240.21034 (High)
Threat Groups
CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.MuddyWater[Also known as: Seedworm, Static Kitten] MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.