CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (25 May 2026)

Published: Loading…

At a Glance

  • Attackers deployed TrapDoor crypto stealer across npm, PyPI, and Crates.io using 34 malicious packages and 384 versions targeting developer credentials.
  • Italian authorities dismantled CINEMAGOAL piracy network using virtual machines to capture streaming authentication codes from Netflix, Disney+, and Spotify subscriptions.
  • LiteSpeed disclosed CVE-2026-48172 in cPanel plugin v2.3–v2.4.4, enabling root-level script execution via lsws.redisAble privilege escalation flaw.
  • Anthropic Project Glasswing identified over ten thousand high or critical vulnerabilities across 1,000 open-source projects using Claude Mythos Preview.
  • Laravel-Lang supply chain attack rewrote Git tags to deploy Composer autoload malware exfiltrating CI secrets and cloud credentials via flipboxstudio.info.

Summary

The TrapDoor supply chain campaign distributed malicious packages across npm, PyPI, and Crates.io ecosystems using coordinated publication waves. The malware targeted crypto and developer environments, harvesting SSH keys, cloud credentials, and wallet data through installation and build-time execution paths. Persistence mechanisms included Git hooks, system services, and environment modification techniques embedded in package payloads.

Italian authorities disrupted the CINEMAGOAL piracy ecosystem that used virtual machines to extract valid streaming authentication codes from legitimate Netflix, Disney+, Sky, and Spotify subscriptions. The operation involved coordinated seizures across France and Germany, alongside identification of reseller networks distributing subscription access. Investigators attributed millions of euros in illegal revenue and issued penalties to early identified subscribers.

The LiteSpeed cPanel plugin vulnerability CVE-2026-48172 enabled privilege escalation allowing arbitrary script execution as root through the lsws.redisAble function. Affected versions included user-end plugin releases from v2.3 through v2.4.4 prior to remediation in v2.4.5 and later bundled updates. Exploitation activity was reported prior to the release of hardened WHM plugin versions.

The Project Glasswing initiative identified over ten thousand high or critical vulnerabilities across widely used open-source software through large-scale automated scanning. Scans covered more than 1,000 projects and included confirmed issues such as a wolfSSL certificate forging flaw tracked as CVE-2026-5194. The effort highlighted large-scale triage backlogs affecting vulnerability verification and patch deployment.

The Laravel-Lang supply chain attack rewrote Git tags across Composer packages to introduce autoload-triggered malware that exfiltrated CI secrets and cloud credentials. The payload contacted attacker infrastructure at flipboxstudio.info and executed automatically through Composer dependency loading mechanisms. Affected repositories included laravel-lang/lang, laravel-lang/http-statuses, laravel-lang/actions, and laravel-lang/attributes.

Highlights of the Day

Laravel-Lang Package Tags Rewritten to Deploy Credential-Stealing Malware

Researchers reported a supply chain attack against four Laravel-Lang Composer packages after attackers force-pushed every existing Git tag to malicious commits that added a PHP payload through Composer autoload.files. The injected code contacted flipboxstudio.info, dropped hidden PHP and ELF binaries into /tmp, exfiltrated CI runner environment data including GitHub tokens and cloud credentials, then deleted artefacts within seconds to evade forensic analysis. StepSecurity confirmed exploitation of laravel-lang/http-statuses v3.4.5 in a GitHub Actions runner, while Aikido reported 233 compromised package versions across laravel-lang/lang, laravel-lang/attributes and laravel-lang/http-statuses.

LiteSpeed cPanel Plugin Flaw Enables Root Code Execution

LiteSpeed disclosed CVE-2026-48172 in its cPanel user-end plugin, a privilege escalation flaw affecting versions v2.3 through v2.4.4 enabling root-level script execution. Exploitation involves the lsws.redisAble function, allowing any cPanel user or compromised account to execute arbitrary scripts with root privileges on affected systems. Fixes were released in v2.4.5 and later bundled cPanel plugin v2.4.7 with WHM plugin v5.3.1.0 following additional security review findings reported timeline.

Project Glasswing Finds Ten Thousand Software Vulnerabilities

Anthropic reported Project Glasswing using Claude Mythos Preview identified over ten thousand high or critical severity vulnerabilities across key software. Open-source scanning of more than 1,000 projects found 6,202 high or critical vulnerabilities, including wolfSSL CVE-2026-5194 certificate forging exploit reported. The report highlights triage bottlenecks as maintainers struggle to verify and patch findings, with partners and enterprises accelerating disclosure workflows.

Source: Anthropic

Italy Disrupts CINEMAGOAL Streaming Credential Theft Network

Italian authorities dismantled CINEMAGOAL piracy ecosystem that used an app to capture streaming authentication and decryption codes from subscriptions via virtual machines. The operation involved 100 searches and server seizures in France and Germany, with the system targeting Netflix, Disney+, Sky, DAZN and Spotify services. Authorities estimated €300 million in losses, identified over 70 resellers, and issued penalties of €154 to €5,000 to 1,000 subscribers.

TrapDoor Supply Chain Attack Steals Crypto Developer Credentials

Researchers identified TrapDoor supply chain campaign spanning 34 malicious packages and 384 versions across npm, PyPI, and Crates.io ecosystems targeting crypto developers. It uses ecosystem-specific execution paths including npm postinstall hooks, PyPI import-time execution, and Rust build.rs scripts to deploy trap-core.js payload credential stealing malware. The malware steals SSH keys, cloud credentials, and crypto wallets while establishing persistence via Git hooks, system services, and environment modifications.

Daily Coverage

Developments
Trapdoor CampaignCinemagoal TakedownLitespeed CVE-2026-48172Glasswing Findings
Vulnerabilities
CVE-2026-26980CVE-2026-5426Knowledgedeliver (High)CVE-2026-48172CVE-2026-5194CVE-2026-9256