CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (16 May 2026)

Published: Loading…

At a Glance

  • CISA added Cisco SD-WAN CVE-2026-20182 to KEV after confirmed exploitation enabling administrative privilege access by attackers.
  • Microsoft disclosed Exchange Server CVE-2026-42897 spoofing vulnerability exploited via crafted emails triggering OWA cross-site scripting for arbitrary execution.
  • Chrome 148 update patches critical use-after-free and other vulnerabilities across multiple browser components affecting rendering and security systems on multiple platforms.
  • China-linked threat actors deployed TencShell malware against a global manufacturer using open-source tooling, reflective loading, and steganographic delivery methods.
  • UNC6671 BlackFile operation uses adversary-in-the-middle attacks targeting Microsoft 365 and Okta to exfiltrate SaaS data and extort organisations.
  • Linux kernel ptrace vulnerability enables local privilege escalation allowing theft of SSH keys and /etc/shadow via race condition exploit.

Summary

Cisco SD-WAN, Exchange Server, and Chrome 148 faced active exploitation and critical vulnerability remediation across enterprise and browser environments. Cisco SD-WAN CVE-2026-20182 was added to KEV following confirmed exploitation enabling authentication bypass and administrative access. Exchange Server CVE-2026-42897 enabled Outlook Web Access cross-site scripting through crafted emails under active exploitation conditions.

Supply-chain compromises affected node-ipc, TanStack, and JDownloader, impacting npm ecosystems, developer devices, and installer distribution channels. OpenAI reported credential theft from employee devices during TanStack supply-chain compromise affecting internal repositories while confirming no production systems were impacted. JDownloader installer compromise replaced downloads with malware while developers confirmed targeted website breach affecting Windows and Linux installer distribution channels.

Malware and cyberespionage activity included TencShell deployments and Turla Kazuar botnet transformation across targeted environments. China-linked threat actors deployed TencShell malware against a global manufacturer using steganographic delivery, reflective loading, and open-source offensive tooling frameworks. Turla operators transformed Kazuar backdoor into modular peer-to-peer botnet enabling persistent access and stealthy command execution across compromised systems in targeted campaigns.

Cloud-focused extortion operations by UNC6671 BlackFile, Microsoft 365, and Okta enabled large-scale SaaS data theft via adversary-in-the-middle techniques. UNC6671 BlackFile operation used adversary-in-the-middle attacks targeting Microsoft 365 and Okta to exfiltrate SaaS data and establish persistent access across enterprise environments. Post-compromise activity included Python and PowerShell automation leveraging Microsoft Graph APIs and session cookies to stream SharePoint and OneDrive data at scale.

Vulnerability exploitation and data theft incidents expanded across OpenAI, WordPress, and THORChain alongside broader application security issues. OpenAI reported credential theft from employee devices during TanStack supply-chain compromise affecting internal repositories while confirming no production systems were impacted. THORChain crypto platform incident resulted in approximately $10.7 million theft following compromise of one vault within decentralized infrastructure systems across network operations.

Highlights of the Day

CISA Flags Exploited Cisco SD-WAN Authentication Bypass

CISA added CVE-2026-20182, an authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller systems, to its Known Exploited Vulnerabilities catalog following evidence of active exploitation. The agency linked the flaw to Emergency Directive 26-03 and supplemental hardening guidance covering Cisco SD-WAN systems, while Binding Operational Directive 22-01 requires Federal Civilian Executive Branch agencies to remediate catalogued vulnerabilities by mandated deadlines.

Microsoft Exchange Flaw Exploited Through Crafted OWA Emails

Microsoft disclosed CVE-2026-42897, a critical spoofing vulnerability in on-premises Exchange Server caused by a cross-site scripting flaw that is being actively exploited in the wild. The vulnerability allows attackers to send crafted emails that execute arbitrary JavaScript in Outlook Web Access browser sessions under certain interaction conditions, affecting Exchange Server 2016, Exchange Server 2019 and Exchange Server Subscription Edition. Microsoft said Exchange Online is unaffected and issued temporary mitigations through the Exchange Emergency Mitigation Service while a permanent security update is being developed.

China-Linked TencShell Malware Targeted Global Manufacturer

Cato Networks uncovered an attempted intrusion against a global manufacturing company using TencShell, a previously undocumented Go-based implant derived from the open-source Rshell command-and-control framework. The attack chain used a first-stage dropper, Donut shellcode delivered through a masqueraded .woff web-font resource, reflective in-memory loading and Tencent-themed API paths for command-and-control traffic designed to resemble legitimate web activity. Cato Networks said the malware supported remote command execution, SOCKS5 proxying, browser artefact access, remote screen control and registry-based persistence through the Windows Run key, while the intrusion was blocked before durable access was established.

PawsRunner Steganography Loader Delivers PureLogs Infostealer

The campaign begins with a phishing email delivering a TXZ archive, where JavaScript abuses environment variables to trigger PawsRunner steganography loader deploying PureLogs .NET infostealer. PawsRunner decrypts and decompresses payloads using AES and Gzip, retrieving a .NET assembly hidden inside PNG images via steganography markers for in-memory execution. PureLogs infostealer establishes HTTPS C2 communication via /ping and /plugin endpoints, harvesting browser credentials, extensions, crypto wallets, Discord data and system information for exfiltration.

BlackFile Vishing Campaign Abuses AiTM to Breach SaaS Platforms

Google Threat Intelligence Group tracked UNC6671, also known as the BlackFile operation, conducting voice phishing campaigns that use adversary-in-the-middle techniques to compromise Microsoft 365 and Okta single sign-on environments. The group captures credentials and multi-factor authentication tokens in real time, then registers attacker-controlled MFA devices to maintain persistent access across SaaS services including SharePoint, OneDrive, Salesforce and Zendesk. Post-compromise activity includes automated exfiltration via Python and PowerShell scripts using Microsoft Graph and session cookies, enabling high-volume data theft recorded as FileAccessed events and supporting extortion operations under the BlackFile brand.

Linux Kernel Flaw Enables SSH Key and Shadow File Theft

A Linux kernel vulnerability in ptrace access-control logic, affecting kernels prior to commit 31e62c2e, allows a local unprivileged attacker to duplicate file descriptors from privileged processes during a race condition in process exit handling. Exploitation leverages pidfd_getfd() against tasks losing their memory descriptor, enabling access to sensitive files such as SSH host private keys and /etc/shadow via setuid-root helpers. A public proof-of-concept demonstrates extraction of ssh-keysign-held keys and shadow file contents across multiple distributions including Debian, Ubuntu, Arch, and CentOS 9.

Daily Coverage

Developments
Cisco Sd-Wan ExploitExchange Zero-DayChrome 148 PatchTencshell Intrusion
Vulnerabilities
CVE-2026-42897Microsoft Exchange Server 2016 Cumulative Update 23 - (High)CVE-2026-20182Cisco Catalyst Sd-Wan Manager 20.1.12 (Critical)
Threat Groups
TurlaTurla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging inhouse tools and malware, such as Uroburos.