CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (28 May 2026)

Published: Loading…

At a Glance

  • Android banking trojan OverlayPhantom abuses Android accessibility services for device control, enabling screen streaming and overlay phishing against more than 180 financial applications.
  • OSV withdrew 157 malicious package reports across npm and PyPI after automated detection false positives propagated into OpenSSF vulnerability database pipelines.
  • CISA reported active exploitation of LiteSpeed cPanel plugin CVE-2026-48172 and highlighted Gitea CVE-2026-27771 exposing private container images to unauthenticated attackers.
  • Silent Ransom Group impersonates IT support personnel using callback phishing, legitimate remote access tools, and in-person intrusion to exfiltrate law firm data.
  • Malicious npm package codexui-android and its Android distribution variant exfiltrate OpenAI Codex authentication tokens via startup execution hooks and concealed network endpoints.
  • FortiClient EMS exploitation delivered EKZ Infostealer through malicious update mechanisms, while AI chatbot-driven cryptojacking campaigns deployed GPU miners via poisoned downloads.

Summary

OverlayPhantom Android banking trojan spreads via fake ID Austria and TikTok dropper applications, abusing accessibility services for persistent device control and credential theft. OverlayPhantom performs real-time screen streaming, multi-application overlays, and exfiltrates credentials to multi-port command-and-control infrastructure across more than 180 financial applications.

Malicious npm package codexui-android exfiltrates OpenAI Codex authentication tokens at startup, while Android distribution embeds Node.js runtime inside sandboxed application environments. JINX-0164 targets cryptocurrency developers through LinkedIn impersonation, deploying macOS malware that steals Keychain data, SSH keys, and CI/CD pipeline secrets.

Gitea CVE-2026-27771 allows unauthenticated attackers to access private container images, exposing source code, API keys, and infrastructure configuration across thousands of deployments. Stored XSS in pretalx CVE-2026-41241 enables session hijacking via organiser search execution, while LiteSpeed cPanel plugin CVE-2026-48172 faces active exploitation in internet-facing deployments.

Silent Ransom Group conducts IT impersonation campaigns against US law firms using callback phishing, remote access tools, and in-person device intrusion for data theft. AI chatbot-driven cryptojacking campaigns use poisoned search results and fake software downloads to deploy GPU miners through DLL sideloading and process injection techniques.

OSV withdrew 157 malicious package reports affecting npm and PyPI ecosystems after automated detection systems generated widespread false positives across OpenSSF vulnerability records. Glassworm botnet infrastructure was disrupted through coordinated takedown operations targeting command-and-control channels used in developer-focused supply chain malware campaigns since early 2025.

Highlights of the Day

CISA Adds LiteSpeed cPanel Flaw to Exploited Vulnerabilities List

CISA added CVE-2026-48172, a privilege escalation vulnerability affecting the LiteSpeed cPanel Plugin, to its Known Exploited Vulnerabilities catalog following evidence of active exploitation. The agency said the flaw represents a common attack vector used by malicious actors, while Binding Operational Directive 22-01 requires Federal Civilian Executive Branch agencies to remediate KEV-listed vulnerabilities by specified deadlines.

Cryptojacking Campaign Uses AI Chatbots and Fake Utility Downloads

Microsoft identified a cryptojacking campaign using SEO poisoning and AI chatbot responses to direct users to fake downloads impersonating CrystalDiskInfo, HWMonitor, FurMark and other Windows utilities favoured by GPU owners. The malware chain used DLL sideloading, abused ConnectWise ScreenConnect for persistent remote access, deployed a SimpleRunPE-based loader, and hollowed Microsoft-signed .NET binaries including InstallUtil.exe and MSBuild.exe to run GPU miners such as lolMiner and SRBMiner-MULTI.

Source: Microsoft

Gitea Flaw Exposes Private Container Images Without Authentication

Orca Security disclosed CVE-2026-27771, a critical access control vulnerability in Gitea’s built-in container registry that allows unauthenticated attackers to pull private OCI images without credentials or tokens. The flaw affects all Gitea versions before 1.26.2 and also impacts Forgejo, with researchers estimating that roughly 31,750 internet-facing instances across more than 30 countries are potentially exposed. Orca said attackers could retrieve application source code, API keys, database credentials and infrastructure configurations embedded within private images, while the vulnerability reportedly remained undetected for approximately four years.

SymJack Attack Hijacks AI Coding Agents Through Symlinked Repositories

Adversa AI disclosed SymJack, a symlink-based attack technique that achieved remote code execution against Claude Code, Gemini CLI, Cursor Agent CLI, GitHub Copilot CLI, Grok Build and OpenAI Codex CLI by overwriting agent configuration files through disguised shell copy operations. The attack used malicious repositories containing symlinked media files and hidden instruction files to trick agents into writing attacker-controlled MCP server configurations, which then executed arbitrary commands on the next restart with the user’s privileges. Adversa AI said the technique also affected CI runners configured to auto-trust workspaces and automatically approve tool calls, potentially exposing deploy keys, cloud credentials, signing material and registry tokens through a single malicious pull request.

Source: Adversa AI

pretalx XSS Flaw Enables Conference Platform Session Hijacking

A stored cross-site scripting vulnerability, CVE-2026-41241, was identified in pretalx, an open-source conference call-for-proposals platform used for managing speaker submissions and schedules across multiple events. The flaw allows injection of HTML or JavaScript through searchable fields such as submission titles and user identifiers, with payload execution occurring when organiser interface searches match malicious records and exposing CSRF tokens for authenticated actions. The issue was patched in pretalx 2026.1.0 after discovery by a security researcher who demonstrated session-level compromise capabilities within controlled testing environments.

JINX-0164 Targets Crypto Developers via macOS Malware and CI/CD Intrusions

Wiz identified JINX-0164, a financially motivated threat actor active since mid-2025, conducting social engineering campaigns against cryptocurrency developers using LinkedIn impersonation and fake recruitment lures to deliver macOS malware. The AUDIOFIX Python-based RAT deployed via malicious domains such as apple.driver-store[.]com stole macOS Keychain data, browser credentials, SSH keys, cloud API tokens, and cryptocurrency wallet extension data, while also exfiltrating secrets from GitHub Actions pipelines. The actor laterally moved into CI/CD and code distribution systems using stolen credentials, modified repositories through commit impersonation and branch manipulation, and in one case trojanised the npm package @velora-dex/sdk to distribute the MINIRAT Go backdoor.

Malicious npm Package Exfiltrates Files via GitHub Token Leak

OX Security identified npm package mouse5212-super-formatter as an infostealer that uploads files from /mnt/user-data using GitHub APIs and post-install execution. The package used a hardcoded or environment GitHub token to create repositories and recursively upload local files, with researchers observing around seven exfiltration events in the attacker-controlled repository. The package accumulated approximately 676 downloads before detection and also exposed its own GitHub token, enabling researchers to trace stolen data transfers.

FortiClient EMS Exploited to Deploy EKZ Infostealer via CVE-2026-35616

Arctic Wolf observed exploitation of CVE-2026-35616 affecting FortiClient Endpoint Management Server, allowing unauthenticated attackers to bypass API authentication and modify EMS configurations to distribute malicious updates. The campaign leveraged FortiClient EMS to push PowerShell commands via Remote Access Profile settings, which executed on managed endpoints through fortitray.exe and deployed a credential stealer named EKZ Infostealer. The malware extracted credentials from Chromium- and Firefox-based browsers, staging results locally before exfiltration over HTTP to attacker-controlled infrastructure.

Malicious Codex UI Package Exfiltrates AI Authentication Tokens

Aikido Security identified codexui-android as a compromised remote web UI for OpenAI Codex that exfiltrates authentication data from users’ local environments. The npm package executes a preloaded module at startup that reads ~/.codex/auth.json and sends access, refresh, and ID tokens to an attacker-controlled endpoint via HTTPS. The same tooling is distributed through an Android application that installs a Node.js runtime and executes the package inside a PRoot sandbox, enabling repeated token theft during normal use.

Silent Ransom Group Uses IT Impersonation for Data Theft

The FBI reported that the Silent Ransom Group (also known as Luna Moth, Chatty Spider, UNC3753) has conducted social engineering campaigns targeting US law firms through impersonation of IT support personnel. Since spring 2026, actors have used phone calls and phishing emails to trick victims into granting remote access, after which legitimate tools such as WinSCP, Rclone, and cloud storage services are used to exfiltrate data without deploying ransomware encryption. In some cases, attackers escalate physical access by visiting victim premises and using removable media to extract data, followed by extortion threats and publication on a dedicated leak site.

Source: FBI IC3

Daily Coverage

Developments
Android MalwareNpm Token TheftCpanel ExploitationGitea Exposure
Vulnerabilities
CVE-2026-35616Forticlientems 7.4.5 (Critical)CVE-2026-41241CVE-2026-48172CVE-2026-27771CVE-2026-48095CVE-2026-48800CVE-2026-48778CVE-2026-48770CVE-2026-8398CVE-2026-45208
Threat Groups
PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.