Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (22 May 2026)
Published: Loading…
At a Glance
- Drupal released updates for CVE-2026-9082 affecting Drupal Core database abstraction API, enabling SQL injection leading to remote code execution on PostgreSQL-backed deployments.
- GitHub confirmed internal repository breach originated from compromised employee device via malicious Nx Console Visual Studio Code extension linked to broader supply chain compromise.
- Microsoft Defender vulnerabilities CVE-2026-41091 and CVE-2026-45498 are being actively exploited, prompting inclusion in the CISA Known Exploited Vulnerabilities catalog.
- EclecticIQ identified SEO poisoning campaigns impersonating Gemini CLI and Claude Code, distributing Windows infostealers that execute in memory via PowerShell.
- Cyble reported INJ3CTOR3 targeting FreePBX systems with JOMANGY webshell and ZenharR to enable VoIP toll fraud across thousands of infected IP addresses.
- Canadian authorities arrested Jacob Butler, alleged operator of the Kimwolf IoT botnet used in distributed denial-of-service attacks reaching nearly 30 terabits per second.
Summary
The Drupal Core vulnerability CVE-2026-9082 enables SQL injection through the database abstraction API affecting PostgreSQL-backed deployments. Exploitation can result in remote code execution, privilege escalation, and information disclosure across affected Drupal versions. Active exploit attempts have been observed targeting exposed web applications running vulnerable configurations.
The GitHub internal repository breach has been linked to a compromised employee device involving a malicious Nx Console Visual Studio Code extension. Attackers leveraged the compromise to access private repositories after chaining access through development environments and supply chain tooling. The same extension compromise has been associated with additional downstream breaches across developer infrastructure.
Microsoft Defender vulnerabilities CVE-2026-41091 and CVE-2026-45498 are actively exploited in the wild and have been added to the CISA KEV catalogue. The flaws enable local privilege escalation to SYSTEM and denial-of-service conditions within Defender’s malware protection engine. Microsoft has issued patched engine and platform updates to mitigate exploitation.
SEO poisoning campaigns impersonating Gemini CLI and Claude Code are distributing Windows infostealers using PowerShell-based in-memory execution. The malware harvests credentials, OAuth tokens, and system data before exfiltration to command-and-control infrastructure. The activity targets developer tooling environments and cloud-connected authentication assets.
The INJ3CTOR3 threat group is exploiting FreePBX systems using JOMANGY PHP webshells and ZenharR payloads to enable VoIP toll fraud operations. The campaign maintains persistence through cron-based execution, watchdog processes, and backup mechanisms across thousands of compromised IP addresses. Attackers abuse SIP trunk configurations to route unauthorised telecommunications traffic.
Canadian authorities arrested Jacob Butler, identified as operator of the Kimwolf IoT botnet, which conducted distributed denial-of-service attacks peaking at nearly 30 terabits per second. The botnet infected millions of internet-connected devices and was linked to multiple global DDoS-for-hire operations. Butler faces criminal charges in Canada and the United States following coordinated infrastructure seizures.
Highlights of the Day
Microsoft Defender flaws actively exploited, added to CISA KEV
Microsoft Defender vulnerabilities CVE-2026-41091 and CVE-2026-45498 are being actively exploited, with CISA adding both flaws to its Known Exploited Vulnerabilities catalog after confirming in-the-wild activity reported by Microsoft. CVE-2026-41091 enables local privilege escalation via improper link resolution in the Microsoft Malware Protection Engine, allowing SYSTEM-level access, while CVE-2026-45498 triggers denial of service in the Microsoft Defender Antimalware Platform; Microsoft has issued patched engine v1.1.26040.8 and platform v4.18.26040.7.
Cisco Secure Workload API flaw grants admin access
Cisco disclosed CVE-2026-20223 in Secure Workload Cluster Software allowing unauthenticated remote access via internal REST APIs due to insufficient authentication and validation controls. Cisco Secure Workload SaaS and on-prem deployments are affected, where crafted API requests can yield Site Admin privileges and cross-tenant access to sensitive resources. Cisco released updates fixing versions 3.10.8.3 and 4.0.3.17, with SaaS already patched, no workarounds available, and no evidence of active exploitation reported.
Drupal core SQL flaw enables PostgreSQL remote code execution
Drupal has released updates for CVE-2026-9082 in Drupal Core, a SQL injection flaw in the database abstraction API affecting PostgreSQL deployments accessible to anonymous users. Exploitation can lead to information disclosure, privilege escalation and remote code execution, with Drupal reporting active exploit attempts across version 10 and 11 branches.
SEO poisoning campaign impersonates AI tools to deploy infostealer
EclecticIQ identified a March 2026 SEO poisoning campaign targeting Gemini CLI and Claude Code users through fake domains impersonating AI installation pages. Threat actors deliver a Windows infostealer via SEO-poisoned results, using PowerShell fileless execution in memory to harvest credentials, OAuth tokens, and system data. The malware provides remote code execution and exfiltrates data to command-and-control infrastructure, enabling compromise of developer tooling, CI/CD secrets, and enterprise session cookies.
FreePBX JOMANGY webshell campaign drives toll fraud activity
Cyble reports INJ3CTOR3 is exploiting FreePBX systems with JOMANGY PHP webshell and ZenharR to enable VoIP toll fraud tied to CVE-2025-64328 and CVE-2025-57819. Six persistence layers combine cron polling, shell injection, immutable backups, watchdog processes and webshell propagation, protecting infections across 3,080 IP addresses used for mass exploitation. The campaign establishes multiple backdoor accounts and abuses SIP trunks through Asterisk commands, while an active Netherlands-based C2 continues serving payloads and credentials.
Showboat Linux malware targets Middle East telecom
Lumen Technologies Black Lotus Labs reported Showboat, a Linux malware deployed against a Middle East telecommunications provider since at least mid-2022, with links to China-affiliated clusters including Calypso. The modular framework provides remote shell execution, file transfer and SOCKS5 proxying, communicating with C2 infrastructure and exfiltrating system data encoded within PNG fields. Researchers also observed Pastebin-based code concealment and attribution to Chengdu-linked nodes, alongside related Windows malware JFMBackdoor delivered via DLL side-loading in parallel operations.
SonicWall Scanning Spike Precedes CVE-2026-0400 Pattern
GreyNoise records a May 9–18, 2026 surge in SonicWall SonicOS API scanning, peaking at 597,000 sessions on May 12, 46× baseline. Earlier spikes on January 18, January 30, and February 14 preceded disclosure of CVE-2026-0400, using same scanner tag telemetry and traffic characteristics observed in Q1. Current activity shows consistent tooling with Chrome 119 Linux user-agent, concentrated traffic from Netherlands and Ukraine networks across ports 80 and 8080.
npm Invalidates Tokens After Mini Shai-Hulud Campaign
npm invalidated all granular access tokens with write access bypassing 2FA following the Mini Shai-Hulud supply chain campaign affecting npm registry users and maintainers. Sustained activity included hijacked maintainer atool publishing 639 malicious versions across 323 npm packages in the @antv ecosystem after earlier TanStack compromise. npm introduced staged publishing in public preview, adding MFA-approved release staging alongside OIDC-based trusted publishing, after attackers abused CI/CD workflows and tokenless publication paths.
Alleged Kimwolf Botmaster Arrested Over Massive IoT Botnet
Canadian authorities arrested Ottawa man Jacob Butler, known as Dort, over alleged Kimwolf IoT botnet used for DDoS attacks reaching nearly 30 terabits per second. On March 19, international law enforcement seized Kimwolf infrastructure and related botnets, disrupting services and takedown operations targeting multiple distributed denial of service networks. Butler faces computer intrusion and mischief charges in Canada and aiding and abetting charges in the United States while awaiting extradition proceedings.
Daily Coverage