Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (27 May 2026)
Published: Loading…
At a Glance
- Glassworm botnet was disrupted in a coordinated takedown after targeting developers through trojanised VSCode extensions, poisoned npm and Python packages, and compromised GitHub repositories.
- ShinyHunters accessed Canvas LMS operated by Instructure, exposing accounts and data tied to approximately 275 million users and leveraging a dependency-related compromise affecting global education platforms.
- CVE-2026-45695 in Kopia Backup enables unauthenticated remote code execution through SSH ProxyCommand injection via vulnerable API endpoint configuration handling.
- Mirasvit Cache Warmer for Magento contains CVE-2026-45247 allowing unauthenticated PHP object injection through crafted CacheWarmer cookies leading to remote code execution.
- Tycoon 2FA AiTM phishing campaigns bypass multi-factor authentication across Entra ID and Google Workspace using reverse-proxy token interception and device-code abuse.
Summary
Supply-chain compromise activity was dominated by the Glassworm botnet, which targeted software developers through trojanised VSCode extensions, poisoned npm packages, and compromised GitHub repositories. It used distributed command-and-control infrastructure spanning blockchain, peer-to-peer networks, and VPS-hosted servers to deliver payloads across infected systems.
Enterprise exploitation activity included critical vulnerabilities in Kopia Backup and the Mirasvit Cache Warmer extension for Magento. CVE-2026-45695 enabled unauthenticated remote code execution through SSH ProxyCommand injection in Kopia API processing. CVE-2026-45247 enabled PHP object injection via deserialised cookie handling, resulting in remote code execution on affected Magento deployments.
Large-scale data exposure incidents affected education and retail sectors, including a Canvas LMS compromise involving accounts and data tied to approximately 275 million users following a dependency-related compromise and a 7-Eleven breach exposing data affecting approximately 185,300 individuals. ShinyHunters accessed LMS infrastructure and extracted sensitive datasets following a dependency-related compromise. Stolen records included personal identifiers, contact details, and account information across affected environments.
Identity-based intrusion campaigns used Tycoon 2FA AiTM phishing techniques to bypass multi-factor authentication in Microsoft Entra ID and Google Workspace. Attackers implemented reverse-proxy interception, OAuth device-code flows, and session token capture to maintain persistent access to compromised accounts.
Highlights of the Day
ShinyHunters Breach Exposes Data of 185,000 7-Eleven Customers
7-Eleven disclosed that attackers accessed systems storing franchisee documents on 8 April 2026, while the ShinyHunters extortion group later claimed responsibility for the breach. Have I Been Pwned said the leaked data exposed information belonging to 185,300 people, including names, dates of birth, email addresses, phone numbers and physical addresses. ShinyHunters claimed the attackers breached a Salesforce environment, stole more than 600,000 records and published a 9.4GB archive of corporate and personal data after ransom demands were rejected.
Lithuania Investigates Foreign Role in National Data Register Leak
Lithuanian authorities are investigating a breach involving more than 600,000 entries from national real estate and legal entity registers accessed using credentials belonging to authorised institutions. Prosecutors said additional cybersecurity restrictions were introduced after the leak, including blocking suspected user accounts and forcing credential updates, while officials suspect involvement by a foreign state actor. The breach prompted the resignation of State Enterprise Centre of Registers head Adrijus Jusas, and opposition politician Laurynas Kasčiūnas claimed without evidence that Russian intelligence may have conducted the operation.
Critical PHP Object Injection Hits Mirasvit Magento Cache
Warmer Sansec discovered an unauthenticated PHP object injection vulnerability, CVE-2026-45247, in Mirasvit Cache Warmer for Magento and Adobe Commerce, where a crafted CacheWarmer cookie is deserialized via PHP unserialize, enabling remote code execution through gadget chains. All Mirasvit Cache Warmer versions before 1.11.12 are vulnerable, with the extension bundled in multiple packages and Sansec estimating around 6,000 affected stores based on scans, likely undercounted due to CDN masking.
ShinyHunters Supply Chain Attack Hits Canvas LMS Platform
ShinyHunters accessed Canvas LMS operated by Instructure, exposing accounts and data tied to approximately 275 million users across education institutions globally. The platform was shut down during incident response, and Instructure disabled Free-For-Teacher accounts after attackers exploited an unspecified vulnerability in the system. Instructure announced on May 12 an agreement to pay ShinyHunters to prevent public disclosure of stolen data, while services were gradually restored.
Phishing Campaign Deploys PureLogs via JavaScript Loader
FortiGuard Labs identified phishing campaign distributing PureLogs variant targeting Windows via fake purchase-order emails containing RAR archive with obfuscated JavaScript dropping PowerShell script. Decodes Base64 and XOR encrypted payloads, performs process hollowing into MsBuild.exe using MAFF.ProcessHollowing, deploying .NET downloader module communicating with C2 over /ping and /plugin endpoints. Exfiltrates browser credentials, Discord tokens, cryptocurrency wallet data and application credentials, encrypting collected data with AES and transmitting via HTTP POST to remote server.
Kopia Backup Flaw Enables Unauthenticated Remote Code Execution
Kopia Backup was found to contain CVE-2026-45695, a critical vulnerability allowing unauthenticated remote code execution via SSH ProxyCommand injection in the /api/v1/repo/exists HTTP endpoint. The flaw arises from insufficient validation of SFTP storage configuration fields, which are passed into SSH command lines and can be abused to inject arbitrary commands before network connections are established. The issue affects Kopia HTTP server versions 0.22.3 and earlier when run in passwordless mode with external SSH enabled, particularly in configurations exposing the service to non-loopback interfaces. Exploitation enables arbitrary command execution under the Kopia process context and access to backup data managed by affected deployments.
Tycoon 2FA AiTM Phishing Bypasses MFA Across Entra ID
Elastic analysed Tycoon 2FA AiTM phishing-as-a-service targeting Microsoft Entra ID and Google Workspace, using reverse-proxy credential theft and session token interception to bypass multi-factor authentication. Campaign variants include WebSocket-based relays and OAuth device-code abuse, with infrastructure using cloud VPS ASNs and real-time token forwarding to capture session cookies refresh tokens. Detection engineering identified Graph API reconnaissance bursts, device registration persistence via primaryRefreshToken, and cross-ASN sign-ins enabling automated compromise across enterprise identity systems.
CrowdStrike Disrupts Glassworm Developer Supply Chain Botnet
CrowdStrike executed a coordinated takedown of the Glassworm botnet on 26 May 2026, targeting developers through supply chain compromises across open-source ecosystems. Operators distributed trojanised VSCode extensions, poisoned npm and Python packages, and compromised GitHub repositories while using Solana blockchain, BitTorrent DHT and Google Calendar for C2. In collaboration with Google and Shadowserver Foundation, CrowdStrike simultaneously disrupted four command-and-control channels, severing Glassworm operators’ access and halting further payload delivery capabilities.
Daily Coverage