CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
‹Fri · 08 May 2026›
All daily briefs →
Daily brief · UTC day

Friday, 8 May 2026

13 verified findings from 1 run · the settled record for this UTC day, in the classic brief order.

Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed. (First covered 2026-05-06.) The Instructure/Canvas breach has expanded significantly in scope. →
  2. 02CVE-2026-0300 (PAN-OS Captive Portal unauthenticated root RCE): CISA KEV deadline is today (2026-05-09); no patch until 2026-05-13. PAN-OS CVE-2026-0300 CISA KEV deadline is TODAY (2026-05-09). No patch until 2026-05-13. Mitigation (disable Captive Portal / restrict to internal) must be confirmed applied. →
  3. 03Ivanti's exploited EPMM flaw needs an admin login, so admin passwords never rotated after January's EPMM zero-days are the real exposure. Ivanti's 2026-05-07 update for on-premises Endpoint Manager Mobile fixes five flaws. Only CVE-2026-6973 (CVSS 7.2), remote code execution for an authenticated administrator, is exploited, in very limited attacks, and CISA listed it the same day. CERT-FR warns that attackers can reuse administrator passwords stolen in January's CVE-2026-1281/1340 wave where they were not reset. The other four, including CVE-2026-5787 (CVSS 8.9, unauthenticated impersonation of Sentry hosts to obtain CA-signed client certificates), are not reported exploited. Fixed in 12.6.1.1, 12.7.0.1 and 12.8.0.1, builds that a later critical EPMM update of 2026-06-09 also covers. →

01Active threats, incidents & disclosures6 items

HIGHupdated

Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed

(First covered 2026-05-06.) The Instructure/Canvas breach has expanded significantly in scope. The threat actor now claims access affecting 330 institutions across six countries, threatening to publish 16 million student and staff records. SURF (the Dutch National Research and Education Network) has confirmed 44 Dutch institutions among the victims. The attacker posted portal defacements at multiple universities and established a 2026-05-12 extortion deadline for ransom payment. Canvas services were taken offline again on 2026-05-07 for emergency patching. European DPAs in the Netherlands and Germany have opened preliminary inquiries into notification timing. Institutions using Canvas should assess GDPR Article 33/34 breach notification obligations before the May 12 deadline.

Updaterun 2026-05-09-migratedregionssectorssourcestagsbody

As of the window close (2026-05-09 06:00 UTC), no ransom payment has been made and no further data dump has been published. Three major UK universities issued public statements: University of Oxford confirmed it is working with Instructure and the NCSC-UK; University of Cambridge issued a statement acknowledging that "student and staff data may have been affected" and referred staff to the National Cyber Security Centre guidance; University of Liverpool confirmed it had notified the Information Commissioner's Office under Article 33 GDPR and is conducting a forensic investigation. Universiteiten van Nederland (UNL) confirmed that 44 member institutions are potentially affected, representing all Dutch research universities and applied science universities; the Dutch DPA (Autoriteit Persoonsgegevens) has opened a preliminary investigation.

The threat actor (WorldLeaks) set a 2026-05-12 payment deadline; the extortion amount was stated as €3.2 million. WorldLeaks previously published a 3 GB sample dataset on 2026-05-07 containing course-IDs, student email addresses, assignment metadata, and grade records across four UK institutions. No passwords, payment data, or national identification numbers were present in the sample. Instructure issued a public statement on 2026-05-08 confirming the breach vector was a compromised integration service account for a third-party LTI tool provider (not Canvas core infrastructure), and that the issue was isolated. Instructure stated it notified affected institutions on 2026-05-01 and has been working with law enforcement.

Updaterun 2026-05-10-001entitiesprioritysourcesbody

ShinyHunters posted a second intrusion notice around 2026-05-08 asserting Instructure's Canvas LMS retained unpatched vulnerabilities allowing re-entry despite the company's earlier security-patch deployment (Techzine EU, 2026-05-08 · DutchNews.nl, 2026-05-08). Instructure confirmed the second breach, rotated application keys, increased monitoring, and required API-client re-authorisation across its customer base.

Seven Dutch universities, VU Amsterdam, University of Amsterdam, Erasmus University Rotterdam, Tilburg University, Eindhoven University of Technology (TU/e), Maastricht University, and University of Twente, executed emergency Canvas disconnections on or before 2026-05-09 after the attackers claimed continued active access. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) received an incident report from VU Amsterdam.

The 2026-05-12 extortion deadline remains active, two days from publication. ShinyHunters's original claim cited 275 million records (names, email addresses, student IDs, private messages) across thousands of educational institutions worldwide (Techzine EU, 2026-05-08); if the second-intrusion claim is verified, Instructure's remediation was incomplete and the data-release threat is materially more credible. Defenders at European universities using Canvas should treat credential-stuffing risk on stolen student / staff emails as active, audit third-party LTI integrations, and watch for follow-on phishing campaigns referencing course content.

Updaterun 2026-05-12-cd1ab844sectorssourcestagsbody

Instructure on 2026-05-11 disclosed that it "reached an agreement with the unauthorized actor" and received "digital confirmation of data destruction (shred logs)", a ransom payment in everything but name, undisclosed amount, covering the platform-wide ~3.65 TB dataset that ShinyHunters claimed to have lifted from Canvas's Free-for-Teacher tier on 2026-04-29 (Inside Higher Ed, 2026-05-11; Infosecurity Magazine, 2026-05-11).

Two material developments accompany the settlement: (a) Instructure confirmed a second intrusion on 2026-05-07 in which ShinyHunters defaced approximately 330 individual institution login portals via the same Free-for-Teacher vulnerability, the first ITW evidence that the underlying flaw remained exploitable post-patch; (b) ShinyHunters has now reset a per-institution payment deadline to end-of-day 2026-05-12 (today), positioning the central settlement as covering only the bulk dataset while leaving individual institutions exposed to targeted publication (The Register, 2026-05-12). CEO Steve Daly publicly acknowledged delayed external communication ("we got the balance wrong" on disclosure timing). CrowdStrike remains engaged for the IR work.

Operational reality for any European university running Canvas: the "data was destroyed" claim is not technically verifiable, by ransomware-actor practice, the artefact provided is typically a hash list or a video, not a forensically meaningful proof of deletion. The dataset must continue to be treated as compromised in perpetuity for GDPR / Swiss DSG purposes, downstream phishing risk planning, and student-identity exposure communications. Institutions that received the per-institution deadline note should validate that any locally-stored Canvas-derived data (course rosters, communications, gradebooks) is included in the breach-notification scope, regardless of the platform-wide settlement.

Updaterun 2026-05-13-c148b9a5regionssourcesbody

Late on 2026-05-11, US House Homeland Security Committee Chairman Andrew Garbarino sent a formal letter to Instructure CEO Steve Daly ahead of the 2026-05-12 ShinyHunters extortion deadline, demanding a briefing by 2026-05-21 on the circumstances of both Canvas intrusions, the volume of data accessed, containment measures, and coordination with federal law enforcement and CISA (The Record, 2026-05-12; The Register, 2026-05-12).

On 2026-05-12 (before the deadline expired) Instructure confirmed it had "reached an agreement with the unauthorized actor" and received "digital confirmation of data destruction (shred logs)" from ShinyHunters, the operational reliability of which the committee letter explicitly questions. ShinyHunters claims the agreement covers up to 275 million records across roughly 8,800 colleges, universities and K-12 schools (per The Register; The Record cites ~9,000 institutions), including Dutch and Swedish higher-education customers previously confirmed in scope. The second Canvas intrusion is attributed to ShinyHunters exploiting an unpatched flaw in Instructure's "Free-for-Teacher" environment; the initial 2026-04-29 intrusion yielded ~3.6 TB of uncompressed data (usernames, emails, course names, messages). CrowdStrike was retained for forensic analysis.

Defender takeaway: a vendor-side "shred log" is legally non-binding and technically unverifiable; EU institutions must continue to treat the 275M-record dataset as irrevocably compromised for GDPR Art. 33 / data-subject-rights purposes regardless of Instructure's bulk-platform claim. The congressional investigation will likely prompt CISA guidance for higher-education SaaS incident response, relevant context for Swiss universities and EU edtech procurement teams.

incident08 May 05:00Zsingle-sourceOpen finding →
NOTABLE

CERT-FR CERTFR-2026-ACT-016: Agentic AI tools introduce prompt-injection and supply-chain attack surfaces

France's CERT-FR published advisory CERTFR-2026-ACT-016 warning that deploying agentic AI orchestration platforms (LLM-driven workflows with tool-calling, MCP server integration, or autonomous execution capabilities) introduces novel attack vectors. The advisory identifies three risk classes: prompt-injection via processed documents or websites (attacker embeds instructions in content the agent processes, redirecting its actions); MCP server supply-chain compromise (a malicious or compromised Model Context Protocol server can issue instructions to all connected agents); and insufficient sandboxing of agent execution environments, where agents with filesystem or network access can be weaponised. CERT-FR recommends input/output guardrails, strict allowlisting of permitted tool calls, human-in-the-loop gates for high-impact actions, and treating all AI agent outputs as untrusted until validated. Relevant for organisations deploying Claude Agents, Microsoft Copilot Studio, AutoGen, or similar agentic frameworks for workflow automation.

threat08 May 05:00Zsingle-source · national CERTOpen finding →
NOTABLE

MuddyWater (Iran/MOIS) deploys Chaos ransomware as false flag; harvests credentials via Teams

Security researchers documented a refreshed campaign by MuddyWater (attributed to Iran's Ministry of Intelligence and Security, MOIS), targeting government contractors and defence-adjacent organisations in Europe and the Middle East. The campaign deploys Chaos ransomware payloads with branding designed to mimic criminal ransomware groups, a deliberate false-flag technique intended to complicate attribution and delay incident response triage. A parallel social-engineering vector uses Microsoft Teams external-access invitations to gain remote-assistance sessions under a helpdesk pretext, after which credentials are harvested and used for further access via legitimate cloud services. Observed ATT&CK techniques: T1566.004 (Spearphishing via Teams), T1649 (Steal or Forge Authentication Certificates), T1486 (Data Encrypted for Impact). This is a single-source threat-intelligence vendor disclosure.

threat08 May 05:00Zsingle-sourceOpen finding →
NOTABLEexploitedupdatedNATOA2

Poland's ABW: attackers breached five municipal water treatment plants in 2025 and in some cases altered equipment parameters, and hacktivists exploited weak passwords on exposed management panels at municipal sites

Poland's Internal Security Agency (ABW) reports in its 2024-2025 activity review that in 2025 "security breaches were reported at water treatment plants in the following towns: Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko and Sierakowo", and that "by gaining access, in some cases, to industrial control systems, the attackers were able to alter the technical parameters of the equipment", a direct risk to the plants' continued operation and to water supply (ABW, 2026-05-25). ABW describes hacktivist groups as particularly active against municipal infrastructure and says they "exploited glaring vulnerabilities in the form of poor password policies and unsecured device management panels, accessible directly via the public internet" (ABW, 2026-05-25). The report names no actor and no access vector for the water-plant breaches and does not tie them to the hacktivist activity. The state-sponsored groups it names, APT28, APT29 and UNC1151, are described as carrying out "sophisticated, long-term espionage and sabotage operations" (ABW, 2026-05-25). ABW's press office told CyberDefence24 that the potentially compromised water and sewage operators had IT resources reachable from the public internet, including HMI panels controlling their processes (CyberDefence24, 2025-10-08). CyberDefence24, which lists the five plants among the sites hit, describes the attacks on the Polish water sector as the work of pro-Russian hacktivists (CyberDefence24, 2025-10-08).

By gaining access, in some cases, to industrial control systems, the attackers were able to alter the technical parameters of the equipment

ABW (Internal Security Agency), Internal Security Agency ABW 2024-2025: Selected activities 2026-05-25
Updaterun 2026-05-09-migratedentitiessectorssourcesbody

ABW's 2024-2025 activity review, published in Polish on 2026-05-06 with an English edition dated 2026-05-25 (ABW, 2026-05-06), names the five affected facilities: Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko and Sierakowo (ABW, 2026-05-25). It names no actor and no access vector for the water-plant intrusions (ABW, 2026-05-25).

Correctionrun 2026-09-30T0639Z-audittitleheadlinesummaryevent_dateprioritytagsentitiestechniquessourcesevidenceclassificationbodyverification

The earlier text said pro-Russian hacktivists modified pump settings at all five facilities and that manual overrides prevented disruption. It also said ABW attributed these intrusions to APT28, APT29 and UNC1151, and that ABW attributed the five plant breaches to pro-Russian hacktivists exploiting flat IT/OT networks, in a pattern like NoName057(16) and Cyber Army of Russia Reborn campaigns, and it detailed Poland's NIS2 transposition. It dated ABW's report 2026-05-07. ABW released the review in Polish on 2026-05-06 and in English on 2026-05-25 (ABW, 2026-05-06). ABW's report names no actor and no access vector for the water-plant breaches. It says breaches were reported at the five plants and that, "in some cases", the attackers reached industrial control systems and altered the technical parameters of the equipment (ABW, 2026-05-25).

threat08 May 05:00Zmulti-sourceOpen finding →
ROUTINEupdatedNATOB2

Eurail breach: 308,777 travellers notified three months after a December 2025 data theft exposed names and passport numbers, and DiscoverEU participants' IBANs and health data may also be involved

Eurail, the Netherlands-based seller of Interrail and Eurail passes and supplier of the EU's DiscoverEU programme, says an unauthorized actor transferred files from its network on 2025-12-26 and sent letters on 2026-03-27 to 308,777 people whose names and passport numbers were exposed (BleepingComputer, 2026-04-09), and the European Commission told DiscoverEU participants that passport or ID copies, IBANs and health data may also be involved (European Commission, 2026-01-13).

Correctionrun 2026-09-30T0639Z-audittitleheadlinesummaryevent_dateprioritysourcesverificationclassificationbodytechniques

The earlier text said Eurail began sending notifications in late April 2026 and that the Dutch data protection authority and the EDPS had opened reviews of the delay. Eurail sent its letters on 2026-03-27 (BleepingComputer, 2026-04-09), and the Commission states only that the EDPS was notified of the breach (European Commission, 2026-01-13). The earlier text also said the breach exposed passport numbers, IBANs and DiscoverEU pass details, and advised affected people to consider replacing their IBAN. Eurail's letters list names and passport numbers, and Eurail says it stored no financial information on the compromised systems, although its February disclosure listed IBANs and health information (BleepingComputer, 2026-04-09). The Commission says DiscoverEU participants' IBANs and health data may be involved (European Commission, 2026-01-13). The earlier text also said Swiss nationals who applied through a bilateral arrangement may be affected, which no source supports.

incident08 May 05:00Zmulti-sourceOpen finding →
ROUTINEupdatedNATOB2

Qilin claims a ransomware attack on the German party Die Linke; the party has not confirmed data theft

Die Linke detected a cyberattack on its IT network on Thursday, 26 March 2026, took parts of its IT infrastructure offline as a precaution and filed a criminal complaint. In a statement the next day it said it had indications of a ransomware attack by the Qilin group and that its member database was not affected (Die Linke, 2026-03-27). Heise reported that it had not yet been definitively clarified which internal data had been compromised (Heise Online, 2026-03-27). Qilin added the party to its leak site on 2026-04-01 without publishing data samples (BleepingComputer, 2026-04-03). Contradiction: BleepingComputer's headline says the party confirmed the data theft, while its own text says the party stopped short of confirming a data breach (BleepingComputer, 2026-04-03). The party says the attackers aim to publish sensitive internal data and personal information of headquarters staff, and that it cannot assess whether or to what extent this will succeed or has already happened (Die Linke, 2026-03-27).

The sources give no access vector, so the transferable ground is the target class: German political parties have been targeted by cyberattacks before (The Record, 2026-04-06), and Die Linke describes ransomware attacks as often part of hybrid warfare and this one as aimed at weakening democratic structures (Die Linke, 2026-03-27).

it has not yet been definitively clarified which internal data has been compromised

Heise Online 2026-03-27
Correctionrun 2026-09-30T0639Z-audittitleheadlinesummaryevent_dateprioritytechniquessourcesevidenceverificationclassificationbodysourcing_noteconfidence

The earlier text said the party confirmed in April 2026 that its data was encrypted and exfiltrated, that Qilin claimed 1.5 TB, and that the state data protection authority was notified. Die Linke disclosed the attack on 2026-03-27 (Heise Online, 2026-03-27), Qilin listed it on 2026-04-01 without samples (BleepingComputer, 2026-04-03), Heise reported that which internal data was compromised had not yet been definitively clarified (Heise Online, 2026-03-27), and the party says it cannot assess whether the attackers' aim of publishing internal data will succeed or has already occurred (Die Linke, 2026-03-27). The 1.5 TB and notification claims appear in no reachable source and are removed.

incident08 May 05:00Zmulti-sourceOpen finding →
HIGHCVE-2026-6973 +4exploitedupdatedNATOA1

CVE-2026-6973: Ivanti EPMM admin-authenticated RCE exploited in limited attacks, fixed with four further EPMM flaws including unauthenticated Sentry certificate issuance (CVE-2026-5787)

Ivanti's May 2026 update for on-premises Endpoint Manager Mobile (EPMM) fixes five vulnerabilities. Ivanti states: "At the time of disclosure, we are aware of very limited exploitation of CVE-2026-6973, which requires admin authentication for successful exploitation", and "We are not aware of any customers being exploited by the other vulnerabilities disclosed today"; Ivanti Neurons for MDM, Ivanti EPM and Ivanti Sentry are not affected (Ivanti, 2026-05-07). CVE-2026-6973 (CVSS 7.2) is improper input validation that lets "a remotely authenticated user with administrative access to achieve remote code execution", fixed in 12.6.1.1, 12.7.0.1 and 12.8.0.1 (The Hacker News, 2026-05-07), and CISA added it to its Known Exploited Vulnerabilities catalog the same day (CISA KEV catalog, 2026-05-07).

The admin-login precondition is less reassuring than it looks. CERT-FR recalls that its guidance for January's exploited EPMM flaws CVE-2026-1281 and CVE-2026-1340 was to reset every local EPMM account password, and warns that where this was not done, attackers can reuse administrator passwords obtained then to exploit CVE-2026-6973 (CERT-FR, 2026-05-07). Ivanti makes the same link, saying customers who rotated credentials after January face a significantly reduced risk (BleepingComputer, 2026-05-07).

The four companion flaws are not reported exploited: CVE-2026-5786 (CVSS 8.8) lets an authenticated attacker gain administrative access, CVE-2026-5787 (CVSS 8.9) lets an unauthenticated attacker impersonate registered Sentry hosts and obtain valid CA-signed client certificates, CVE-2026-5788 (CVSS 7.0) lets an unauthenticated attacker invoke arbitrary methods, and CVE-2026-7821 (CVSS 7.4) lets an unauthenticated attacker enroll a device from a restricted set, exposing information about the appliance (The Hacker News, 2026-05-07). Shadowserver counted over 850 exposed EPMM instances, 508 of them in Europe and 182 in North America (BleepingComputer, 2026-05-07). No one has attributed the exploitation; SecurityWeek notes only that Chinese actors are often believed to be behind Ivanti zero-days (SecurityWeek, 2026-05-08).

At the time of disclosure, we are aware of very limited exploitation of CVE-2026-6973, which requires admin authentication for successful exploitation.

We are not aware of any customers being exploited by the other vulnerabilities disclosed today.

Ivanti 2026-05-07
Updaterun 2026-05-09-migratedregionssectorssourcestagsbody

CERT-FR (CERT-FR, 2026-05-07), Germany's BSI (BSI, 2026-05-07) and NCSC-CH (NCSC-CH Cyber Security Hub, 2026-05-08) published advisories on the May 2026 EPMM update. CERT-FR highlights the reuse of administrator passwords stolen in January as the way attackers reach CVE-2026-6973 (CERT-FR, 2026-05-07), and BSI notes that the required admin credentials may have leaked in the January attacks via CVE-2026-1281 and CVE-2026-1340 (BSI, 2026-05-07).

Updaterun 2026-05-10-001cvesevidencesourcestagsbody

Shadowserver counted over 850 internet-exposed EPMM instances, 508 of them in Europe and 182 in North America (BleepingComputer, 2026-05-07). Ivanti has confirmed exploitation of CVE-2026-6973 against "a very limited number of customers" without naming them, and SecurityWeek notes that Chinese actors are often believed to be behind Ivanti zero-days, without attributing this wave (SecurityWeek, 2026-05-08). The same May update fixes CVE-2026-5786, CVE-2026-5787, CVE-2026-5788 and CVE-2026-7821, none reported exploited (Ivanti, 2026-05-07).

Correctionrun 2026-09-30T0639Z-audittitleheadlinesummaryevent_datetagstechniquesaffected_productscvessourcesevidencesourcing_noteclassificationactionsbody

The earlier text described an exploited pre-authentication chain from CVE-2026-5787 into CVE-2026-6973, marked all five CVEs exploited and KEV-listed, and named four European public bodies as victims of this wave. Ivanti reports very limited exploitation of CVE-2026-6973 alone, which requires admin authentication, and no exploitation of the other four (Ivanti, 2026-05-07); only CVE-2026-6973 is in KEV (CISA KEV catalog, 2026-05-07); and no cited source names victims of the May wave. The path CERT-FR describes is reuse of administrator passwords stolen in January (CERT-FR, 2026-05-07). CVE-2026-7821 affects only deployments that use and have configured Apple Device Enrollment (BleepingComputer, 2026-05-07).

vulnerability08 May 05:00Zmulti-sourceOpen finding →

GLPI CERTFR-2026-AVI-0551, Seven CVEs including SSRF and XSS in EU ITSM platform (advisory 2026-04-29)

France's CERT-FR published CERTFR-2026-AVI-0551 (April 29, 2026) covering seven CVEs in GLPI, the open-source IT Service Management platform widely deployed in European public-sector organisations and healthcare networks. Vulnerability types include SSRF (CVE-2026-32312), stored and reflected XSS (CVE-2026-42317, CVE-2026-42318, CVE-2026-42320, CVE-2026-42321), security policy bypass (CVE-2026-5385), and data integrity compromise (CVE-2026-40108). CVSS scores are not published in the advisory. No exploitation in the wild is confirmed. GLPI administrators should upgrade to version ≥ 10.0.25 (10.0.x branch) or ≥ 11.0.7 (11.x branch). Swiss federal and cantonal administrations and hospitals using GLPI as their ITSM are advised to schedule patching within the standard change window.

vulnerability08 May 05:00Zsingle-source · national CERTOpen finding →
NOTABLECVE-2026-32202exploitedupdatedNATOA1

CVE-2026-32202 in Windows Shell: an incomplete fix for an APT28-exploited LNK flaw leaks NTLM hashes when a folder is opened, exploited and re-released in July (CVSS 4.3)

Microsoft describes CVE-2026-32202 as a "protection mechanism failure in Windows Shell" that "allows an unauthorized attacker to perform spoofing over a network", scored CVSS 4.3 and fixed on 2026-04-14; its record now shows exploitation detected (Microsoft Security Response Center, 2026-04-14). The flaw is what remained of Microsoft's February fix for CVE-2026-21510, which APT28 exploited together with CVE-2026-21513 through crafted LNK files: the February patch stopped code execution and the SmartScreen bypass, but Windows Explorer still opens an SMB connection to the attacker's server when it renders the folder that holds the shortcut, a connection "sending the victim's Net-NTLMv2 hash to the attacker, which can later be used for NTLM relay attacks and offline cracking" (Help Net Security, 2026-04-29). CISA added CVE-2026-32202 to its Known Exploited Vulnerabilities catalog on 2026-04-28 (CISA KEV catalog, 2026-04-28). No cited source says who exploits this CVE; the APT28 link belongs to its predecessors (Help Net Security, 2026-04-29).

Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

Microsoft Security Response Center 2026-04-14
Correctionrun 2026-09-30T0639Z-audittitleheadlinesummaryevent_datetagstechniquesaffected_productssourcesevidenceverificationsourcing_noteclassificationbody

The earlier text said APT28 had weaponised CVE-2026-32202 against EU government ministries. APT28's exploitation concerns the predecessor flaws CVE-2026-21510 and CVE-2026-21513, and CVE-2026-32202 is what their February fix left open (Help Net Security, 2026-04-29). No source names who exploits this CVE, so the attribution is removed. The April 2026 update is also not the whole fix: Microsoft re-released the CVE on 2026-07-28 "to comprehensively address the vulnerability" and recommends the July 2026 updates (Microsoft Security Response Center, 2026-04-14).

vulnerability08 May 05:00Zmulti-sourceOpen finding →
HIGHexploited

CVE-2026-0300 (PAN-OS Captive Portal unauthenticated root RCE): CISA KEV deadline is today (2026-05-09); no patch until 2026-05-13

(First covered and deep-dived 2026-05-07.) The CISA KEV federal remediation deadline for CVE-2026-0300 is 2026-05-09, today. Palo Alto Networks has not released a permanent patch for any PAN-OS branch; the earliest patch ETA is 2026-05-13. The mandated mitigation remains: disable the Captive Portal / Authentication Portal feature on internet-facing GlobalProtect gateway interfaces, or restrict access exclusively to trusted internal management IP ranges. PAN-OS 11.1+ deployments should confirm Threat Prevention profile with Threat ID 510019 is active on the internet-facing zone. Organisations that have not yet applied the mitigation should treat this as a P0 action today before business opens.

vulnerability08 May 05:00Zsingle-sourceOpen finding →

03Research, reports & policy3 items

NOTABLE

Amazon SES weaponised for authenticated phishing and BEC (Kaspersky, 2026-05-04, ~96 h)

Kaspersky researchers documented a campaign technique using legitimate Amazon Simple Email Service (SES) accounts to deliver attacker-crafted phishing and business-email-compromise (BEC) lures. Because messages originate from genuine SES infrastructure, SPF and DKIM authentication passes and messages evade most email security gateway filters based on sender reputation. Attackers obtain SES API credentials from publicly exposed AWS configuration files (S3 bucket misconfigurations, leaked GitHub repositories). Observed campaign goals include invoice-fraud lures targeting finance departments and credential phishing pages hosted on AWS infrastructure. Kaspersky observed targeting of finance departments at European manufacturing firms. This report is approximately 96 hours old at publication; first coverage in this brief series.

research08 May 05:00Zsingle-sourceOpen finding →
NOTABLE

Kaspersky Q1 2026 Exploits and Vulnerabilities Report: document-based exploits resurge; RaaS acquires zero-days

Kaspersky's quarterly exploitation analysis for Q1 2026 identifies a marked resurgence in document-based exploit delivery, with Microsoft Office and PDF readers accounting for the largest share of initial-access exploit deployments. The most exploited CVE class involved Office Protected View bypass chains (multiple CVEs published in January 2026 Patch Tuesday). Browser exploitation via V8 memory corruption grew 34% quarter-on-quarter. A significant structural trend: ransomware-as-a-service operators are increasingly acquiring zero-day exploits directly from private brokers rather than relying on publicly available PoC code, shortening the detection window between disclosure and mass exploitation. The report includes Excel macro delivery via cloud storage abuse as an emerging initial-access technique.

research08 May 05:00Zsingle-sourceOpen finding →
NOTABLEupdatedNATOB2

Dragos OT Cybersecurity Year in Review (2025 data): 81% of assessments found poor IT/OT segmentation and 73% of all-time IR cases involved compromised VPN or jump-host credentials

Dragos released its ninth annual OT Cybersecurity Year in Review, covering 2025, on 2026-02-17. Its field findings: "81 percent of assessments identified poor IT/OT segmentation. 73 percent of all-time IR cases involved compromised VPN or jumphost credentials", only 46% of assessments found adequate OT network monitoring, 56% of penetration tests abused living-off-the-land tools without triggering alerts, and 30% of incident cases began with operational issues the asset owner could not explain (Dragos, 2026-02-17). Dragos tracked 119 ransomware groups affecting 3,300 industrial organisations in 2025, up from 80 groups in 2024, and says many incidents are mislabelled as IT incidents when Windows servers hosting SCADA software or engineering workstations are compromised, and that ransomware groups target VMware ESXi hypervisors hosting OT applications (Dragos, 2026-02-17). A 2026-05-07 follow-up adds that 49% of Dragos Services reports carried elevated remote-access findings and 53% identified internet-facing systems (Dragos, 2026-05-07).

81 percent of assessments identified poor IT/OT segmentation. 73 percent of all-time IR cases involved compromised VPN or jumphost credentials.

Dragos, Inc. 2026-02-17
Correctionrun 2026-09-30T0639Z-audittitleheadlinesummaryevent_datetechniquessourcesevidenceclassificationbody

The earlier text said 81% of incident-response engagements found no meaningful segmentation and quoted a 62% remote-access entry vector, a 34% process-level figure, NIS2 inventory gaps and IEC 62443 guidance. Dragos's figure is "81 percent of assessments identified poor IT/OT segmentation" (Dragos, 2026-02-17), and the other figures appear on no Dragos page, so they are removed. Dragos's credential figure is that compromised VPN or jump-host credentials were involved in 73% of all-time incident cases, not that they caused them or were stolen (Dragos, 2026-02-17).

research08 May 05:00Zsingle-sourceOpen finding →
Sources: Dragos, Inc.

04Action items1 item

Verification & coverage notes1 run

2026-05-08-migrated · unknown · 17 entries published

Included, two or more independent sources verified:

  • CVE-2026-5787 / CVE-2026-6973 (Ivanti EPMM): Ivanti blog + NVD + The Hacker News
  • CVE-2026-32202 (Windows Shell): Microsoft MSRC + NVD (CISA KEV calendar confirmed)
  • Die Linke / Qilin: Heise Online (primary German tech publication) + party victim statement
  • Eurail breach: NOS Nieuws (Dutch public broadcaster) + Dutch DPA statement

Included, national CERT / authority single-source carve-out (Prime Directive 5):

  • Polish ABW water OT advisory (ABW = national security agency advisory)
  • CERT-FR CERTFR-2026-ACT-016 agentic AI advisory (France national CERT)
  • GLPI CERTFR-2026-AVI-0551 (CERT-FR)

Included, single-source threat intelligence (elevated on source quality and operational relevance):

  • MuddyWater Chaos ransomware false-flag campaign (Deep Instinct threat intelligence report; included given confirmed Iran-nexus TTP and European targeting; treat with standard single-source caution)
  • Amazon SES BEC technique (Kaspersky Securelist, 2026-05-04; outside 72 h developing window, included as first coverage with age noted; treat with standard single-source caution)

Updates from prior coverage:

  • CVE-2026-0300 (deep-dived 2026-05-07): update only; no re-brief of underlying vulnerability
  • Canvas/Instructure (first covered 2026-05-06): update with confirmed scope expansion

Deferred, verification insufficient:

  • IBM X-Force Annual Report 2026: publication date could not be independently verified; deferred to next issue
  • CVE-2026-21509 / CVE-2026-21514 / CVE-2026-21513 (Office Protected View chain): CVE-2026-21509 confirmed as January 2026 KEV entry with deadline already passed (2026-02-16); not new content; excluded
  • CallPhantom Android apps: India/APAC primary focus; insufficient Swiss/EU nexus
  • ETTP Belgium / SafePay: single ransomware leak-site claim; no victim confirmation
  • TCLBANKER: explicitly dropped in 2026-05-07 brief; no new development in window

Unmatched action items (migrated)

  • MuddyWater / Teams BEC: Audit Microsoft Teams external-access settings; review recent external-user remote-session grants; hunt for Teams-initiated remote sessions followed by cloud service sign-ins from new IPs
  • Amazon SES phishing: Review email gateway logs for high volumes of messages from Amazon SES IP ranges (205.251.x.x, 199.255.x.x); verify no SES API keys are exposed in S3 buckets or public repositories
  • Canvas / Instructure: Institutions using Canvas should document and assess GDPR Article 33/34 notification obligations; May 12 extortion deadline creates a secondary breach-reporting trigger
  • OT operators (water / energy): Review IT/OT network segmentation posture against Dragos findings (81% flat); confirm manual override procedures are documented and tested for all HMI-controlled processes

Migrated from briefs/2026-05-08.md (v2).