CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (15 May 2026)

Published: Loading…

At a Glance

  • Windows zero-days YellowKey and GreenPlasma enable BitLocker bypass and SYSTEM-level privilege escalation across Windows 11 and Server environments via physical access conditions.
  • Cisco Catalyst SD-WAN Controller CVE-2026-20182 authentication bypass exploited, granting attackers unauthenticated administrative access and enabling webshell deployment in enterprise networks.
  • NGINX ngx_http_rewrite_module CVE-2026-42945 heap buffer overflow enables denial-of-service and potential remote code execution via crafted HTTP requests exploiting PCRE captures.
  • Linux kernel Fragnesia CVE-2026-46300 exploits XFRM ESP-in-TCP page cache corruption, allowing local attackers to escalate privileges and obtain root access.
  • npm supply chain attacks targeting TanStack and node-ipc abuse GitHub Actions cache poisoning, OIDC token theft, and malicious package republishing.
  • Russian Kazuar botnet evolves into modular peer-to-peer architecture using encrypted C2 channels, targeting government and diplomatic systems across Europe and Central Asia.

Summary

Windows zero-days YellowKey and GreenPlasma enable BitLocker bypass and SYSTEM privilege escalation on Windows 11 and Server systems via physical access conditions. Linux kernel Fragnesia CVE-2026-46300 enables local privilege escalation via XFRM ESP-in-TCP page cache corruption, resulting in root-level access on affected systems.

Cisco Catalyst SD-WAN Controller CVE-2026-20182 is actively exploited, enabling unauthenticated administrative access and webshell deployment across enterprise network management infrastructure. NGINX CVE-2026-42945 affects ngx_http_rewrite_module, allowing heap buffer overflow exploitation that leads to denial-of-service conditions and potential remote code execution attacks.

Multiple npm supply chain compromises, including TanStack and node-ipc incidents, leverage GitHub Actions cache poisoning, OIDC token extraction, and malicious package republishing.

Kazuar botnet evolves into modular peer-to-peer architecture using encrypted command-and-control channels, targeting government and diplomatic systems in Europe and Central Asia. AMOS macOS infostealer spreads via ClickFix social engineering, harvesting credentials, Keychain data, and cryptocurrency wallets through staged payload execution on infected systems.

AI-assisted vulnerability research contributes to significant CVE disclosure increases across major software vendors and open source ecosystems, including GitHub-reported spikes. Supply chain abuse campaigns expand alongside malicious npm packages and coordinated contests encouraging package compromise across open source ecosystems activity.

Highlights of the Day

Linux Kernel Fragnesia Flaw Enables Root via ESP-in-TCP

Researchers disclosed Fragnesia, Linux kernel local privilege escalation in XFRM ESP-in-TCP enabling page cache corruption and root privilege gain via deterministic page-cache corruption primitive. Exploit abuses Linux XFRM ESP-in-TCP processing of spliced file-backed TCP buffers, causing AES-GCM keystream XOR writes into cached pages affecting /usr/bin/su leading to privilege escalation. Vulnerability affects Linux kernels prior to May 13 2026 patch and stems from logic flaw in ESP-in-TCP shared fragment handling in Dirty Frag family variant.

Windows Zero-Days Enable BitLocker Bypass and SYSTEM Escalation

Researchers disclosed Windows zero-days YellowKey and GreenPlasma enabling BitLocker bypass and SYSTEM-level privilege escalation across Windows 11, Server 2022 and 2025 systems. YellowKey exploits Windows Recovery Environment FsTx directory handling to bypass BitLocker via physical access during reboot on Windows 11 systems, with no CVE assigned. GreenPlasma enables privilege escalation to SYSTEM through arbitrary memory section object creation in SYSTEM-writable directory objects, with PoC code partially stripped by the researcher.

Cisco SD-WAN Flaws Under Active Exploitation

Cisco Talos reports active exploitation of CVE-2026-20182 in Cisco Catalyst SD-WAN Controller and Manager, enabling authentication bypass and unauthenticated administrative access, attributed to UAT-8616. Multiple clusters exploit CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122 in Cisco SD-WAN Manager, deploying webshells including XenShell, Godzilla and Behinder via publicly released proof-of-concepts. Post-compromise clusters include webshell C2 infrastructure, AdaptixC2 and Sliver implants, XMRig mining, Nim-based backdoors and credential theft targeting SD-WAN environments.

NGINX Rewrite Module Flaw Enables DoS and Potential RCE

CVE-2026-42945 affects NGINX ngx_http_rewrite_module, where crafted HTTP requests exploiting unnamed PCRE captures can trigger heap buffer overflow and unauthenticated denial-of-service. The flaw impacts NGINX Open Source versions 1.0.0 to 1.30.0 and NGINX Plus R32 to R36, including Ingress Controller and related components. Technical analysis attributes the issue to PCRE capture handling in rewrite directives, with public proof-of-concept code increasing risk of exploitation and potential RCE.

Russian Kazuar Botnet Evolves into Modular P2P System

Kazuar malware attributed to Russian state actor Secret Blizzard has evolved into a modular peer-to-peer botnet targeting government and diplomatic organisations in Europe and Central Asia. Kazuar uses Kernel, Bridge and Worker modules with leader election and inter-process communication via named pipes, mailslots and Windows messaging to reduce observable network activity. It employs HTTP, EWS and WebSocket transport for command-and-control, encrypted messaging and tasking, alongside anti-analysis checks, distributed data collection and staged exfiltration workflows.

npm Supply Chain Worm Uses Tor-Based C2

CloudSEK TRIAD identified npm supply chain attack via typosquatted package crypto-javascri stealing npm and GitHub credentials and republishing trojanized packages via compromised maintainer accounts. The final payload contains a modified Arti Tor client implementing credential theft, cryptomining, privilege escalation capabilities, systemd persistence and Tor-based command-and-control communication. Execution occurs via npm preinstall hooks development environment triggers enabling silent propagation across packages maintained by compromised developers within supply chain workflows CI environments.

AMOS macOS Infostealer Deployed via ClickFix Terminal Trick

Sophos MDR reports AMOS (Atomic macOS) infostealer variant delivered via ClickFix-style social engineering tricking users into executing Terminal commands, initiating a bootstrap script that downloads secondary payloads, captures macOS credentials, and retrieves a second-stage payload executed with elevated privileges. The malware validates passwords locally, harvests macOS Keychain, browser profiles, and cryptocurrency wallet data, performs VM checks, establishes LaunchDaemon persistence, registers with command-and-control infrastructure, and exfiltrates archived data to attacker-controlled servers.

AI-assisted research drives surge in CVE disclosures

VulnCheck reports sharp year-to-date CVE disclosure increases across Chrome, VMware, Apache, Mozilla, HPE and F5, alongside a 476 percent rise on GitHub. GitHub attributes the rise to distributed reporting across many projects, while Mozilla, Microsoft and Apache cite AI-assisted vulnerability discovery initiatives. Anthropic Project Glasswing and Claude Mythos Preview are referenced alongside partner organisations including AWS, Apple, Google, Microsoft and Palo Alto Networks.

Source: VulnCheck

CI Workflow Misconfiguration Enables npm Supply Chain Compromise

On 11 May 2026, 84 malicious versions across 42 @tanstack packages were published to npm with valid SLSA provenance signed by the legitimate tanstack/router repository, following exploitation of GitHub Actions pull_request_target misconfiguration, cache poisoning, and OIDC token extraction. Attackers never stole maintainer credentials or bypassed branch protection, instead leveraging fork pull_request_target execution, Actions cache restore in release workflows, and in-memory OIDC JWT theft from runner processes to directly publish packages via npm registry APIs.

Source: Endor Labs

Daily Coverage

Developments
Cisco Sd-Wan ExploitNginx Rce FlawFragnesia RootNpm Supply Chain Attack
Vulnerabilities
CVE-2026-20182Cisco Catalyst Sd-Wan Manager 20.1.12 (Critical)CVE-2026-42897Microsoft Exchange Server 2016 Cumulative Update 23 - (High)CVE-2017-9841CVE-2026-42945Nginx Plus R36 (High)CVE-2026-46300CVE-2026-20133Cisco Catalyst Sd-Wan Manager 20.1.12 (Medium)CVE-2026-20128CVE-2026-20122CVE-2026-44565Open-Webui < 0.6.10 (High)CVE-2026-41615Microsoft Authenticator For Android 6.0.0 (Critical)
Threat Groups
Secret BlizzardTurla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging inhouse tools and malware, such as Uroburos.Velvet Chollima[Also known as: Kimsuky, Springtail, Black Banshee, APT43] Kimsuky is a North Koreabased cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subjectmatter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Its operations have overlapped with other DPRK actors, likely due to ad hoc collaboration or limited resource sharing. Because of overlapping operations, some researchers group a wide range of North Korean statesponsored cyber activity under the broader Lazarus Group umbrella rather than tracking separate subgroup or cluster distinctions. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models to assist with vulnerability research, scripting, social engineering and reconnaissance.Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.Salt TyphoonSalt Typhoon is a People's Republic of China (PRC) statebacked actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U. S. telecommunication and internet service providers (ISP).TWILL TYPHOON[Also known as: Mustang Panda] Mustang Panda is a Chinabased cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to deliver malicious payloads. Mustang Panda has targeted government, diplomatic, and nongovernmental organizations, including think tanks, religious institutions, and research entities, across the United States, Europe, and Asia, with notable activity in Russia, Mongolia, Myanmar, Pakistan, and Vietnam.