Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (1 June 2026)
Published: Loading…
At a Glance
- DriveSurge compromises thousands of websites using zTDS traffic distribution systems to redirect users into ClickFix and FakeUpdates malware campaigns.
- CIFSwitch Linux kernel flaw enables forged cifs.spnego key requests that trigger root-level execution via cifs.upcall across multiple distributions.
- Flowise CVE-2026-40933 allows one-click remote code execution through malicious chatflow imports that trigger stdio MCP command execution during canvas rendering.
- Malicious Packagist development branch roberts/leads delivers DPRK-linked JavaScript loader using blockchain RPC infrastructure and Node.js execution chains.
- WP Maps Pro plugin vulnerability enables unauthenticated attackers to create rogue administrator accounts on vulnerable WordPress installations.
Summary
DriveSurge compromises thousands of legitimate websites using the zTDS traffic distribution system, redirecting users into ClickFix and FakeUpdates malware delivery chains across large-scale bot infrastructure. The operation also includes clipboard-hijacking and macOS infection chains that connect to command-and-control infrastructure at 147.45.42.205:8133.
The Linux kernel CIFSwitch vulnerability enables forged cifs.spnego key requests, which are processed by cifs.upcall and escalate privileges to root across multiple Linux distributions. The flaw affects Ubuntu, Debian, Rocky Linux, CentOS Stream, Kali Linux and SUSE systems through namespace switching and NSS-based execution paths.
Flowise CVE-2026-40933 enables one-click remote code execution through malicious chatflow imports that trigger stdio MCP command execution during canvas rendering. The vulnerability exposes self-hosted deployments to credential and API key compromise while Flowise Cloud remains unaffected due to disabled stdio MCP support.
A malicious Packagist development branch of roberts/leads delivers a DPRK-linked JavaScript loader that uses TRON, Aptos and BNB Smart Chain RPC infrastructure to retrieve encrypted payloads. The loader executes via eval() and spawns hidden Node.js processes, with links to BeaverTail, DEV#POPPER RAT and OmniStealer malware families.
A WordPress WP Maps Pro vulnerability enables unauthenticated attackers to create administrator accounts on affected sites. The issue impacts vulnerable plugin installations and allows full administrative control without authentication.
Highlights of the Day
DriveSurge Hijacks Thousands of Sites for Malware Delivery
Silent Push identified a threat actor it named DriveSurge, which uses the zTDS traffic distribution system to compromise thousands of legitimate websites and redirect visitors to ClickFix and FakeUpdates malware campaigns. The operation is assessed as a pay-per-install initial access broker and serves fake browser updates impersonating Chrome, Firefox, Edge, Safari and other browsers, with observed downloads including malicious ZIP archives and executables. Researchers also analysed an obfuscated macOS infection chain that hijacks clipboard contents, delivers payloads from attacker-controlled servers and ultimately connects to command-and-control infrastructure at 147.45.42.205:8133.
CIFSwitch Flaw Grants Root Access on Linux Systems
Researcher Asim Manizada disclosed CIFSwitch, a local privilege escalation vulnerability with a pending CVE that affects Linux systems using vulnerable CIFS kernel code and certain cifs-utils versions. The flaw allows unprivileged users to create forged cifs.spnego key requests that launch the root-privileged cifs.upcall helper, which trusts attacker-controlled fields including pid and upcall_target. Exploitation abuses namespace switching and NSS module loading to execute attacker-controlled code as root, with confirmed impact on multiple Ubuntu, Debian, Rocky Linux, CentOS Stream, Kali Linux and SUSE configurations.
Flowise Chatflow Import Triggers One-Click Server Compromise
Obsidian Security disclosed CVE-2026-40933, a one-click remote code execution vulnerability in self-hosted Flowise deployments where Custom MCP tools can launch user-supplied stdio MCP commands as server-side child processes. A crafted chatflow JSON can embed a malicious MCP configuration, and importing the workflow automatically triggers command execution when Flowise enumerates available MCP actions during canvas rendering. Researchers found current validation controls can be bypassed, enabling access to server environments, stored credentials, API keys and connected cloud or SaaS services, while Flowise Cloud is unaffected because stdio MCP is disabled.
Malicious Packagist Branch Delivers DPRK-Linked Malware Loader
Socket discovered malicious JavaScript hidden in the Packagist development release dev-drewroberts/feature/test-case of the legitimate PHP package roberts/leads, with the payload appended to a Tailwind configuration file in an exposed development branch. The loader contacts TRON, Aptos and BNB Smart Chain infrastructure to retrieve encrypted payloads, decrypts them with embedded XOR keys, executes them via eval(), and can launch detached Node.js child processes. Researchers linked the infrastructure and techniques to Famous Chollima activity, noting similarities to Contagious Interview campaigns and previous delivery of BeaverTail, DEV#POPPER RAT and OmniStealer malware.
Daily Coverage