Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (19 May 2026)
Published: Loading…
At a Glance
- Attackers exploited CVE-2026-42945 in NGINX rewrite module heap overflow enabling denial-of-service and possible remote code execution in exposed servers.
- Compromised Nx Console VS Code extension delivered credential-stealing payload via orphan GitHub commit affecting millions of developer installations.
- MiniPlasma Windows zero-day in cldflt.sys enables SYSTEM privilege escalation on fully patched Windows systems via Cloud Files driver flaw.
- Malicious npm packages deployed Shai-Hulud clone infostealers stealing cloud credentials, wallets and environment variables from developer machines and systems.
- Linux kernel CVE-2026-46333 exposes root-only files including SSH keys and shadow data via ptrace race condition vulnerability across LTS versions.
- INTERPOL Operation Ramz across thirteen MENA countries led to 201 arrests linked to phishing, malware distribution and fraud networks.
Summary
Active exploitation of CVE-2026-42945 affected NGINX Open Source and NGINX Plus through heap overflow in rewrite module causing denial-of-service and potential remote code execution in exposed deployments. Linux kernel CVE-2026-46333 enabled local privilege escalation exposing root-only files such as SSH keys and /etc/shadow across LTS versions via ptrace race condition flaw.
Compromised Nx Console VS Code extension was published to the VS Code Marketplace using stolen publisher credentials and executed a credential-stealing payload fetched from a dangling orphan commit in the nrwl/nx repository upon workspace activation, affecting developer environments and CI/CD pipelines. Malicious npm packages distributed Shai-Hulud clone malware stealing cloud credentials, wallets and environment variables from developer systems and build pipelines.
Phishing campaigns impersonating Zoom delivered ConnectWise ScreenConnect remote access tool via malicious installers and scripted payloads enabling credential harvesting and persistent remote access on compromised hosts. SHub Reaper macOS infostealer spoofed Apple, Google and Microsoft installers using AppleScript and LaunchAgent persistence to exfiltrate credentials and wallets.
MiniPlasma Windows zero-day in cldflt.sys enabled SYSTEM privilege escalation on fully patched Windows systems via cloud files driver flaw affecting Windows 11 deployments. Grafana Labs disclosed GitHub environment compromise via stolen access token allowing attackers to download source code and issue ransom demands.
INTERPOL Operation Ramz involved thirteen Middle East and North Africa countries conducting coordinated cybercrime raids targeting phishing, malware distribution and fraud networks. Authorities recorded 201 arrests, 382 suspects identified, 3,867 victims and 53 servers seized during operations spanning phishing-as-a-service and financial fraud infrastructure.
Highlights of the Day
Malicious npm packages deploy Shai-Hulud clone and infostealers
Four malicious npm packages uploaded by a single threat actor included chalk-tempalte, @deadcode09284814/axios-util, axois-utils and color-style-utils, delivering infostealer malware and a Shai-Hulud clone based on leaked source code. The packages were distributed as a typo-squatting campaign targeting Axios-related dependencies, with payloads exfiltrating IP addresses, cloud configurations, environment variables and crypto wallet data. One variant implemented persistence mechanisms and a DDoS botnet component, while combined weekly downloads across the malicious packages reached 2,678.
SHub Reaper macOS stealer targets Apple, Google and Microsoft
SHub Reaper macOS stealer uses fake WeChat and Miro installers, delivering AppleScript via Script Editor, spoofing Apple Google and Microsoft infrastructure across stages. It includes AMOS-style filegrabber routines targeting documents and wallets, stages data in /tmp archives, and establishes LaunchAgent persistence under a GoogleUpdate masquerade for remote execution. It conducts fingerprinting and telemetry collection, checks CIS locale, and exfiltrates browser data, wallets, and system details through Telegram C2 channels.
Windows MiniPlasma zero-day enables SYSTEM privilege escalation
Chaotic Eclipse released a MiniPlasma proof-of-concept for SYSTEM privilege escalation in Windows cldflt.sys, linked to a 2020 Google Project Zero report. The flaw in cldflt.sys HsmOsBlockPlaceholderAccess is believed unpatched since CVE-2020-17103, with PoC reportedly achieving SYSTEM on Windows 11 May 2026 updates. Will Dormann reported reliable SYSTEM execution on Windows 11, with Insider Canary builds appearing unaffected due to variations in the race condition behaviour.
Attackers exploit critical NGINX heap overflow vulnerability
SecurityWeek reports the first in-the-wild exploitation of CVE-2026-42945, a CVSS 9.2 heap buffer overflow in the ngx_http_rewrite_module affecting NGINX Plus and Open Source, patched by F5 after 16 years of presence, with PoC code published shortly after disclosure. The flaw results from a two-pass buffer sizing mechanism where internal state changes leave unpropagated flags, allowing attacker-supplied HTTP requests to overwrite heap memory, causing worker process crashes and denial-of-service or enabling remote code execution when ASLR is disabled under specific rewrite configurations. VulnCheck telemetry identifies around 5.7 million internet-exposed NGINX servers, with exploitation expected against a smaller subset, and public PoC material noted as capable of facilitating ASLR bypass for RCE.
Zoom Phishing Campaign Delivers ScreenConnect Remote Access Tool
Cofense reports a phishing campaign impersonating Zoom meetings to deliver ConnectWise ScreenConnect remote access software via spoofed invitations and landing pages. A Visual Basic Script file disguised as a Zoom installer downloads ScreenConnect MSI from 212.11.64.45 and executes it via Windows Script Host. Once installed, ScreenConnect enables persistent remote access, credential harvesting and reconnaissance activity, communicating with 212.11.64.45 and spoofed Zoom meeting infrastructure.
7-Eleven confirms breach after ShinyHunters ransom demand
7-Eleven confirmed a data breach following ShinyHunters ransom claims after intrusion detected on April 8 affecting franchisee systems and personal data in a Maine notification. ShinyHunters claimed 600,000 Salesforce records were stolen, listing 7-Eleven on April 17 and demanding ransom by April 21, $250,000 sought after access via phishing or integration abuse.
Linux kernel flaw exposes SSH keys and shadow data
KnightLi reports CVE-2026-46333, a Linux kernel ptrace access-control flaw affecting multiple distributions that allows low-privileged local users to read root-owned data including SSH host private keys and /etc/shadow. The issue originates in __ptrace_may_access() logic during process exit, where task->mm becomes null while file descriptors remain accessible, enabling pidfd_getfd to retrieve sensitive files within a race window. A public proof-of-concept named ssh-keysign-pwn demonstrates extraction of SSH host keys and password hashes across supported kernel versions prior to the upstream fix.
Nx Console VS Code Extension Compromised via Orphan Commit
A compromised nrwl.angular-console VS Code extension v18.95.0 was published to the VS Code Marketplace using stolen publisher credentials on 18 May 2026, affecting 2.2 million installations. Upon workspace activation, it executed an obfuscated payload fetched from a dangling orphan commit in the nrwl/nx repository. The payload harvested credentials from GitHub, npm, AWS, and Vault, and exfiltrated them via HTTPS and DNS. It remained active for approximately 11 minutes before removal, during which stolen tokens enabled downstream abuse including Sigstore-signed npm provenance generation.
INTERPOL Operation Leads to 201 Arrests Across MENA Region
INTERPOL Operation Ramz across 13 Middle East and North Africa countries led to 201 arrests and identification of 382 suspects linked to phishing malware distribution and fraud networks. Authorities identified 3,867 victims, seized 53 servers and disseminated nearly 8,000 intelligence items to support investigations across participating agencies. National actions included dismantling phishing-as-a-service infrastructure in Algeria, seizure of banking data and devices in Morocco, and takedown of compromised servers and fraud operations in Oman and Jordan.
Daily Coverage