Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (15 May 2026)
Published: Loading…
At a Glance
- Windows zero-days YellowKey and GreenPlasma enable BitLocker bypass and SYSTEM-level privilege escalation across Windows 11 and Server environments via physical access conditions.
- Cisco Catalyst SD-WAN Controller CVE-2026-20182 authentication bypass exploited, granting attackers unauthenticated administrative access and enabling webshell deployment in enterprise networks.
- NGINX ngx_http_rewrite_module CVE-2026-42945 heap buffer overflow enables denial-of-service and potential remote code execution via crafted HTTP requests exploiting PCRE captures.
- Linux kernel Fragnesia CVE-2026-46300 exploits XFRM ESP-in-TCP page cache corruption, allowing local attackers to escalate privileges and obtain root access.
- npm supply chain attacks targeting TanStack and node-ipc abuse GitHub Actions cache poisoning, OIDC token theft, and malicious package republishing.
- Russian Kazuar botnet evolves into modular peer-to-peer architecture using encrypted C2 channels, targeting government and diplomatic systems across Europe and Central Asia.
Summary
Windows zero-days YellowKey and GreenPlasma enable BitLocker bypass and SYSTEM privilege escalation on Windows 11 and Server systems via physical access conditions. Linux kernel Fragnesia CVE-2026-46300 enables local privilege escalation via XFRM ESP-in-TCP page cache corruption, resulting in root-level access on affected systems.
Cisco Catalyst SD-WAN Controller CVE-2026-20182 is actively exploited, enabling unauthenticated administrative access and webshell deployment across enterprise network management infrastructure. NGINX CVE-2026-42945 affects ngx_http_rewrite_module, allowing heap buffer overflow exploitation that leads to denial-of-service conditions and potential remote code execution attacks.
Multiple npm supply chain compromises, including TanStack and node-ipc incidents, leverage GitHub Actions cache poisoning, OIDC token extraction, and malicious package republishing.
Kazuar botnet evolves into modular peer-to-peer architecture using encrypted command-and-control channels, targeting government and diplomatic systems in Europe and Central Asia. AMOS macOS infostealer spreads via ClickFix social engineering, harvesting credentials, Keychain data, and cryptocurrency wallets through staged payload execution on infected systems.
AI-assisted vulnerability research contributes to significant CVE disclosure increases across major software vendors and open source ecosystems, including GitHub-reported spikes. Supply chain abuse campaigns expand alongside malicious npm packages and coordinated contests encouraging package compromise across open source ecosystems activity.
Highlights of the Day
Linux Kernel Fragnesia Flaw Enables Root via ESP-in-TCP
Researchers disclosed Fragnesia, Linux kernel local privilege escalation in XFRM ESP-in-TCP enabling page cache corruption and root privilege gain via deterministic page-cache corruption primitive. Exploit abuses Linux XFRM ESP-in-TCP processing of spliced file-backed TCP buffers, causing AES-GCM keystream XOR writes into cached pages affecting /usr/bin/su leading to privilege escalation. Vulnerability affects Linux kernels prior to May 13 2026 patch and stems from logic flaw in ESP-in-TCP shared fragment handling in Dirty Frag family variant.
Windows Zero-Days Enable BitLocker Bypass and SYSTEM Escalation
Researchers disclosed Windows zero-days YellowKey and GreenPlasma enabling BitLocker bypass and SYSTEM-level privilege escalation across Windows 11, Server 2022 and 2025 systems. YellowKey exploits Windows Recovery Environment FsTx directory handling to bypass BitLocker via physical access during reboot on Windows 11 systems, with no CVE assigned. GreenPlasma enables privilege escalation to SYSTEM through arbitrary memory section object creation in SYSTEM-writable directory objects, with PoC code partially stripped by the researcher.
Cisco SD-WAN Flaws Under Active Exploitation
Cisco Talos reports active exploitation of CVE-2026-20182 in Cisco Catalyst SD-WAN Controller and Manager, enabling authentication bypass and unauthenticated administrative access, attributed to UAT-8616. Multiple clusters exploit CVE-2026-20133, CVE-2026-20128 and CVE-2026-20122 in Cisco SD-WAN Manager, deploying webshells including XenShell, Godzilla and Behinder via publicly released proof-of-concepts. Post-compromise clusters include webshell C2 infrastructure, AdaptixC2 and Sliver implants, XMRig mining, Nim-based backdoors and credential theft targeting SD-WAN environments.
NGINX Rewrite Module Flaw Enables DoS and Potential RCE
CVE-2026-42945 affects NGINX ngx_http_rewrite_module, where crafted HTTP requests exploiting unnamed PCRE captures can trigger heap buffer overflow and unauthenticated denial-of-service. The flaw impacts NGINX Open Source versions 1.0.0 to 1.30.0 and NGINX Plus R32 to R36, including Ingress Controller and related components. Technical analysis attributes the issue to PCRE capture handling in rewrite directives, with public proof-of-concept code increasing risk of exploitation and potential RCE.
Russian Kazuar Botnet Evolves into Modular P2P System
Kazuar malware attributed to Russian state actor Secret Blizzard has evolved into a modular peer-to-peer botnet targeting government and diplomatic organisations in Europe and Central Asia. Kazuar uses Kernel, Bridge and Worker modules with leader election and inter-process communication via named pipes, mailslots and Windows messaging to reduce observable network activity. It employs HTTP, EWS and WebSocket transport for command-and-control, encrypted messaging and tasking, alongside anti-analysis checks, distributed data collection and staged exfiltration workflows.
npm Supply Chain Worm Uses Tor-Based C2
CloudSEK TRIAD identified npm supply chain attack via typosquatted package crypto-javascri stealing npm and GitHub credentials and republishing trojanized packages via compromised maintainer accounts. The final payload contains a modified Arti Tor client implementing credential theft, cryptomining, privilege escalation capabilities, systemd persistence and Tor-based command-and-control communication. Execution occurs via npm preinstall hooks development environment triggers enabling silent propagation across packages maintained by compromised developers within supply chain workflows CI environments.
AMOS macOS Infostealer Deployed via ClickFix Terminal Trick
Sophos MDR reports AMOS (Atomic macOS) infostealer variant delivered via ClickFix-style social engineering tricking users into executing Terminal commands, initiating a bootstrap script that downloads secondary payloads, captures macOS credentials, and retrieves a second-stage payload executed with elevated privileges. The malware validates passwords locally, harvests macOS Keychain, browser profiles, and cryptocurrency wallet data, performs VM checks, establishes LaunchDaemon persistence, registers with command-and-control infrastructure, and exfiltrates archived data to attacker-controlled servers.
AI-assisted research drives surge in CVE disclosures
VulnCheck reports sharp year-to-date CVE disclosure increases across Chrome, VMware, Apache, Mozilla, HPE and F5, alongside a 476 percent rise on GitHub. GitHub attributes the rise to distributed reporting across many projects, while Mozilla, Microsoft and Apache cite AI-assisted vulnerability discovery initiatives. Anthropic Project Glasswing and Claude Mythos Preview are referenced alongside partner organisations including AWS, Apple, Google, Microsoft and Palo Alto Networks.
CI Workflow Misconfiguration Enables npm Supply Chain Compromise
On 11 May 2026, 84 malicious versions across 42 @tanstack packages were published to npm with valid SLSA provenance signed by the legitimate tanstack/router repository, following exploitation of GitHub Actions pull_request_target misconfiguration, cache poisoning, and OIDC token extraction. Attackers never stole maintainer credentials or bypassed branch protection, instead leveraging fork pull_request_target execution, Actions cache restore in release workflows, and in-memory OIDC JWT theft from runner processes to directly publish packages via npm registry APIs.
Daily Coverage