CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (18 May 2026)

Published: Loading…

At a Glance

  • Grafana GitHub token compromise enabled unauthorised access to repositories and codebase downloads, followed by extortion attempts from suspected data theft actors.
  • NGINX CVE-2026-42945 heap buffer overflow in ngx_http_rewrite_module is being actively exploited in NGINX Plus and Open Source deployments worldwide.
  • MiniPlasma Windows zero-day abuses cldflt.sys Cloud Filter driver to escalate privileges to SYSTEM on fully patched Windows 11 systems.
  • Tycoon2FA phishing kit adds device-code authentication abuse and Trustifi tracking URL manipulation to hijack Microsoft 365 accounts.
  • WordPress Funnel Builder plugin vulnerability is actively exploited to inject JavaScript skimmers into WooCommerce checkout pages, stealing payment data.
  • Secret Blizzard evolves Kazuar backdoor into modular peer-to-peer botnet for persistent espionage operations.

Summary

Multiple authentication and access-control incidents affected enterprise environments, including Grafana GitHub token exposure enabling codebase downloads and subsequent extortion attempts by data theft actors. Microsoft 365 accounts were targeted through Tycoon2FA phishing kits leveraging device-code authentication abuse and tracking URL manipulation for session hijacking.

Active exploitation activity increased across widely deployed infrastructure software, with NGINX CVE-2026-42945 heap buffer overflow attacks observed in NGINX Plus and Open Source versions 0.6.27 through 1.30.0. A separate WordPress Funnel Builder plugin vulnerability enabled JavaScript injection into WooCommerce checkout pages, capturing payment data through browser-based skimming techniques.

Windows platform security was impacted by a MiniPlasma zero-day exploit abusing the cldflt.sys Cloud Filter driver to achieve SYSTEM-level privileges on fully patched Windows 11 systems. Testing confirmed successful privilege escalation on standard builds while newer Insider Preview Canary releases blocked exploitation attempts.

Malware and espionage tooling evolved across multiple threat ecosystems, including Russian threat group Secret Blizzard’s Kazuar backdoor, which was restructured into a modular peer-to-peer botnet supporting long-term persistence and command distribution. Fast16 framework targeting of LS-DYNA and AUTODYN nuclear simulation software was confirmed, with manipulation of uranium compression modelling parameters.

Highlights of the Day

Obfuscated Joomla Backdoor Injects SEO Spam Through Remote C2

Sucuri analysed a Joomla compromise where obfuscated PHP code injected into index.php contacted attacker-controlled C2 domains, including cdn[.]erpsaz[.]com and cdn[.]saholerp[.]com, to retrieve instructions dynamically. The malware assembled strings from two-character fragments to evade signature-based scanners, collected server environment data through the $_SERVER variable, and supported redirect, payload injection and fake XML sitemap delivery modes. Researchers found the loader redirected visitors, injected spam product links and served keyword-stuffed HTML pages to search engine crawlers without storing the malicious content locally on the Joomla site.

Source: Sucuri

Fast16 Sabotaged Nuclear Weapons Simulations Before Stuxnet

Symantec analysed the fast16 sabotage framework, active since around 2005, which patched LS-DYNA and AUTODYN simulation software in memory to manipulate high-explosive and nuclear detonation modelling results. The malware reduced Cauchy stress tensor and pressure outputs when simulated uranium density exceeded 30g/cm3, using tailored hooks across up to ten software builds and targeting specific Equation of State models linked to explosive compression. Fast16 spread through Windows network shares using impersonation and remote service creation, installed a boot-start filesystem driver and abused Image File Execution Options persistence while remaining confined to local network ranges.

MiniPlasma Zero-Day Grants SYSTEM Access on Windows

Researcher Chaotic Eclipse released a proof-of-concept exploit named MiniPlasma that gains SYSTEM privileges on fully patched Windows 11 systems by abusing the cldflt.sys Cloud Filter driver. The exploit targets the HsmOsBlockPlaceholderAccess routine linked to CVE-2020-17103, a privilege escalation flaw originally reported by Google Project Zero in 2020 and previously marked as patched by Microsoft. BleepingComputer and Tharros confirmed the exploit worked on current Windows 11 releases, while testing showed it failed on the latest Windows 11 Insider Preview Canary build.

Grafana GitHub Breach Triggers Extortion Attempt

Grafana disclosed that attackers used a compromised token to access its GitHub environment and download company codebases, although the firm said no customer data or systems were affected. The company invalidated the exposed credentials, launched a forensic investigation and said the threat actor attempted to extort payment to prevent publication of the stolen data. Reports from Hackmanac and Ransomware.live linked the incident to CoinbaseCartel, a data extortion group associated with the ShinyHunters, Scattered Spider and LAPSUS$ ecosystems.

Daily Coverage

Developments
Grafana Token BreachNginx ExploitMiniplasma Zero-DayTycoon2Fa Phishing
Vulnerabilities
CVE-2026-42945Nginx Plus R36 (High)CVE-2026-8043CVE-2026-46333Linux Bfedb589252C01Fa505Ac9F6F2A3D5D68D707Ef4 (High)CVE-2020-17103
Threat Groups
Secret BlizzardTurla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. Turla is known for conducting watering hole and spearphishing campaigns, and leveraging inhouse tools and malware, such as Uroburos.EquationEquation is a sophisticated threat group that employs multiple remote access tools. The group is known to use zeroday exploits and has developed the capability to overwrite the firmware of hard disk drives.LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.