Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (23 May 2026)
Published: Loading…
At a Glance
- An automated Megalodon campaign injected malicious GitHub Actions workflows across thousands of repositories, exfiltrating CI secrets and cloud credentials.
- A CVSS 10.0 Cisco Secure Workload REST API vulnerability, CVE-2026-20223, enables unauthenticated remote attackers to access sensitive organisational data.
- CISA added Langflow CVE-2025-34291 and Trend Micro Apex One CVE-2026-34926 to KEV after evidence of active exploitation campaigns.
- Hackers accessed Grafana GitHub repositories after compromised TanStack token was not rotated during a supply chain attack, enabling codebase and data theft.
- FBI warns Kali365 phishing-as-a-service uses OAuth token capture to bypass MFA and access Microsoft 365 environments via Telegram platform.
Summary
Supply chain compromise activity affects developer ecosystems and cloud infrastructure services. Grafana repositories were accessed following TanStack token compromise, enabling theft of codebase and internal data. Megalodon campaigns injected malicious GitHub Actions workflows across thousands of repositories.
Critical vulnerability activity spans enterprise platforms, browser infrastructure, and widely deployed web applications. Cisco Secure Workload is affected by a CVSS 10.0 REST API flaw enabling unauthenticated data access. CISA also expanded its KEV catalog with actively exploited Langflow and Apex One vulnerabilities.
Browser and application security updates include Chrome 148 patches addressing WebRTC and UI spoofing flaws. These issues enable remote code execution and post-compromise manipulation on Windows systems. Drupal has also reported active exploitation of a newly disclosed SQL injection vulnerability.
Additional supply chain activity includes postinstall hook abuse across more than 700 repositories and Packagist packages. Malicious scripts executed downloaded binaries through CI/CD pipelines. These operations expanded credential theft and execution across development environments.
Phishing and identity-based attacks increasingly target cloud authentication systems and enterprise SaaS platforms. Kali365 uses OAuth token theft to bypass multi-factor authentication in Microsoft 365 environments distributed via Telegram channels. ROADtools abuse enables Entra ID token theft and Microsoft Graph API enumeration in cloud intrusions.
Botnet disruption and infrastructure takedowns continue across global law enforcement operations. The Kimwolf DDoS botnet operator was arrested after infecting over one million IoT devices. First VPN infrastructure was dismantled, with Dutch authorities seizing servers linked to cyberattack enabling services.
Nation-state and advanced intrusion activity includes credential theft, tunnelling, and malware evolution across multiple campaigns. Cloud Atlas deployed PowerShell backdoors and SSH tunnelling against organisations in Russia and Belarus. Void Dokkaebi and Nimbus Manticore operations introduced Cython compiled malware and SEO poisoned AI-assisted intrusion chains.
Highlights of the Day
CISA Adds Two Actively Exploited Vulnerabilities to KEV Catalog
CISA has added CVE-2025-34291 affecting Langflow and CVE-2026-34926 impacting Trend Micro Apex One on-premises to its Known Exploited Vulnerabilities Catalog after evidence of active exploitation. Langflow vulnerability stems from an origin validation error, while Trend Micro Apex One on-premises is affected by a directory traversal flaw enabling unauthorised access patterns. Under Binding Operational Directive 22-01, US federal civilian agencies must remediate KEV-listed vulnerabilities, while CISA urges wider organisations to prioritise mitigation.
Canadian Charged Over KimWolf IoT DDoS Botnet Operation
US authorities have charged a Canadian man, Jacob Butler, with operating the KimWolf IoT DDoS-for-hire botnet after his arrest in Canada. Court documents state KimWolf infected over one million IoT devices worldwide and was used to launch DDoS attacks reaching nearly 30 terabits per second. International law enforcement also seized command-and-control infrastructure and targeted 45 DDoS-for-hire platforms, disrupting services linked to multiple botnets including KimWolf.
Cloud Atlas Deploys New PowerShell Backdoors and Tunnelling Tools
Used phishing ZIP archives with LNK files executing PowerShell scripts and malicious documents exploiting CVE-2018-0802, sustaining SSH tunnelling into 2026 across Russian and Belarusian organisations. Deployed VBCloud and PowerShower for credential theft and lateral movement, alongside reverse SSH tunnels, RevSocks, and Tor-based access with command-and-control infrastructure seizures disrupting operations. PowerCloud and browser-checker scripts collected administrator data and process activity, exfiltrating to Google Sheets, with campaigns targeting government and diplomatic entities in Russia and Belarus.
CISA Opens KEV Vulnerability Nomination Form for Public Submissions
CISA launched new KEV nomination form enabling researchers, vendors, partners to report exploited vulnerabilities for possible inclusion in KEV catalog via web form. Submissions can also be made via existing vulnerability@cisa.dhs.gov email, and reports are handled through a Qualtrics web system for analysis and triage. Requirements for KEV listing include assigned CVE identifier, confirmed exploitation evidence, and clear remediation guidance as part of CISA validation criteria.
ROADtools, an open-source Python framework, has been observed in cloud intrusions targeting Microsoft Entra ID through token acquisition, device registration, and API-based enumeration techniques. Tool modules roadrecon and roadtx enable Entra ID discovery and token exchange, allowing attackers to manipulate OAuth flows, register devices, and bypass multi-factor authentication. Nation-state actors have used ROADtools in targeted phishing and cloud operations for persistence and discovery, leveraging Microsoft Graph API access for tenant-wide enumeration.
Chrome Patches Critical WebRTC and UI Spoofing Vulnerabilities
Chrome update 148.0.7778.178/179 patches CVE-2026-9111 WebRTC use-after-free enabling remote code execution via crafted HTML on Linux and CVE-2026-9110 UI spoofing after renderer compromise on Windows. ChromeOS LTS-144 144.0.7559.252 fixes CVE-2026-5289 Navigation use-after-free, CVE-2026-6309 Viz use-after-free, CVE-2026-4449 Blink use-after-free, plus CSS Media WebCodecs and Extensions vulnerabilities.
Nimbus Manticore uses SEO poisoning and AI-assisted malware development
Nimbus Manticore, an IRGC-linked threat actor, deployed updated intrusion chains during Operation Epic Fury against aviation and software targets across the US, Europe and Middle East, using phishing lures, SEO poisoning and a trojanised Zoom installer alongside AppDomain Hijacking techniques and a newly identified MiniFast backdoor with suspected AI-assisted development. The malware communicated with command and control servers via JSON and Base64 encoded exchanges, supporting file operations, process execution and persistence through scheduled task abuse.
Qualcomm BootROM flaw enables device compromise via EDL
CVE-2026-25262 in Qualcomm BootROM affects the Sahara Emergency Download Mode used during USB-based recovery, introducing a write-what-where condition that enables arbitrary memory writes across multiple chipsets including MDM9x07, MSM8909 and SDX50. The flaw impacts the primary boot layer before operating system startup, where crafted data chunks during device repair or service access can be used to execute unauthorised code and compromise the device state. Exploitation at BootROM level enables full control over affected smartphones, IoT devices and automotive modules, including access to stored data and hardware interfaces such as sensors.
Mass GitHub Actions campaign backdoors thousands of repositories
An automated campaign codenamed Megalodon pushed malicious GitHub Actions workflow commits into 5,561 repositories, totalling 5,718 commits within a six-hour window. The injected workflows contained base64-encoded bash payloads that exfiltrated CI secrets, cloud credentials and SSH keys to C2 216.126.225.129:8443 endpoint. Targeted variants replaced workflows in some repositories and spread via compromised npm package @tiledesk/tiledesk-server versions 2.18.6–2.18.12 enabling persistent secret theft.
Postinstall malware spreads across 700 GitHub repositories via GitHub Actions
Socket identified eight Packagist packages with a malicious postinstall script downloading a GitHub Releases binary to /tmp/.sshd and executing it in background. The campaign extended across more than 700 GitHub repositories, where package.json lifecycle hooks executed a curl-based command that disabled TLS verification and ran a binary. Malicious commits to upstream repositories inserted the same payload across multiple projects, leading Packagist branch-tracking versions to distribute identical /tmp/.sshd executables via updated releases.
Void Dokkaebi Compiles InvisibleFerret into Cython Malware Binaries
Void Dokkaebi has updated InvisibleFerret using Cython compilation, shifting from Python scripts to .pyd and .so binaries for Windows and macOS. BeaverTail has expanded into multi variant malware adding backdoor and credential theft capabilities, downloading InvisibleFerret modules for browser data, wallets, and system information. The campaign targets software developers and cryptocurrency users with access to CI/CD pipelines and keys, using binary obfuscation to evade script based detection.
Daily Coverage