CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
‹Sat · 16 May 2026›
All daily briefs →
Daily brief · UTC day

Saturday, 16 May 2026

9 verified findings from 1 run · the settled record for this UTC day, in the classic brief order.

CriticalVerify EEMS Mitigation M2 deployed on every on-premises Exchange Server 2016 / 2019 / SE; deploy EOMT manually on air-gapped ExchangeCVE-2026-42897 · exploited · 16 May 05:00Z
Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01CVE-2026-42897, Microsoft Exchange Server 2016 / 2019 / SE: stored XSS in OWA, actively exploited, no permanent patch. Microsoft Exchange Server CVE-2026-42897 (CVSS 8.1) actively exploited via crafted-email XSS in OWA; CISA KEV-added 2026-05-15; no permanent patch, only EEMS auto-mitigation; air-gapped servers need EOMT manual install; Exchange 2016/2019 permanent fix gated behind Period 2 ESU enrolment (Microsoft MSRC, 2026-05-14 · NCSC-CH Security Hub #12577, 2026-05-15). →
  2. 02CVE-2026-44112 / CVE-2026-44113 / CVE-2026-44115 / CVE-2026-44118, OpenClaw "Claw Chain": four chainable flaws in autonomous-agent platform enable sandbox. Cyera Research discloses OpenClaw "Claw Chain", four chainable vulnerabilities (CVE-2026-44112 CVSS 9.6 / CVE-2026-44115 8.8 / CVE-2026-44118 7.8 / CVE-2026-44113 7.7) in the autonomous-agent platform enabling sandbox escape → credential leak → privilege escalation → file disclosure; ~245 K publicly accessible instances; fixed by the 2026-04-23 OpenClaw release (GHSA-5h3g-6xhh-rg6p / wppj-c6mr-83jj / r6xh-pqhr-v4xh / x3h8-jrgh-p8jx) (Cyera Research, 2026-05-15). →
  3. 03node-ipc npm package backdoored via expired-domain maintainer takeover: three malicious versions steal developer and CI credentials on require(). node-ipc npm package (widely-used Node.js IPC library) hijacked via expired-domain account takeover; three malicious versions (9.1.6, 9.2.3, 12.0.1) exfiltrate cloud, CI/CD, SSH and Keychain credentials over DNS TXT (StepSecurity also reports an HTTPS channel that Socket did not find); rotate every secret on any workstation or CI runner that loaded one of the three versions (Socket Security, 2026-05-14 · StepSecurity, 2026-05-14). →

01Active threats, incidents & disclosures3 items

NOTABLE

BKA arrests Dream Market lead administrator "Speedstepper" in Germany, cryptocurrency-to-physical-gold OPSEC failure after seven years at large

Owe Martin Andresen, a 49-year-old German national alleged by US and German prosecutors to be "Speedstepper" (the lead administrator of the Dream Market darknet narcotics marketplace from 2013 until its 2019 voluntary shutdown) was arrested in Germany on 2026-05-07 and publicly identified on 2026-05-13–14 (The Record, 2026-05-14 · US DEA, 2026-05-13). The action was a coordinated multi-agency operation: the Bundeskriminalamt and the Zentrale Kriminalinspektion Oldenburg for the German side, with the US DEA Miami, IRS-CI Cyber Crimes Unit, FBI, USPIS, and HSI executing in parallel. A US federal grand jury in the Northern District of Georgia had returned a sealed indictment on 2026-01-13 charging Andresen with six counts of international concealment money laundering and six counts of concealment money laundering (240 years aggregate maximum); German charges carry up to five years. The OPSEC failures that closed the seven-year gap were operational, not technical: in late 2022 Andresen allegedly accessed Dream Market's dormant cryptocurrency wallets (an action only the holder of the original private keys could perform) and consolidated the contents into a single wallet, providing prosecutors with a definitive on-chain link; and in August 2023 he used an Atlanta-based cryptocurrency-to-physical-asset service to purchase gold bars that were shipped directly to his home address in Germany, providing the geographic and identity link. At arrest, German authorities seized approximately USD 1.7 million in gold bars, USD 23,000 in cash, and approximately USD 1.2 million in cryptocurrency. Three Dream Market co-administrators ("Oxymonster", "KITT3N", "GOWRON") had been convicted previously. The case is operationally interesting to public-sector intelligence liaisons because it illustrates that long-tail attribution of darknet operators is increasingly driven by post-cessation financial behaviour (wallet reactivation, regulated-service touchpoints, physical-asset conversion) rather than on-platform OPSEC; the seven-year delay between the marketplace's closure and the arrest is the operational signal.

threat16 May 05:00Zmulti-sourceOpen finding →
HIGHupdatedNATOB1

node-ipc npm package backdoored via expired-domain account takeover: three malicious versions steal developer and CI credentials, flagged about three minutes after publication

On 2026-05-14, three malicious versions of the node-ipc npm package (9.1.6, 9.2.3 and 12.0.1) were published at the same time by a co-maintainer account with no prior publish history on the package (StepSecurity, 2026-05-14). The account's email domain had expired on 2025-01-10 and was re-registered on 2026-05-07, a week before the attack (The Hacker News, 2026-05-14). Socket assesses that the new domain owner could then trigger a standard npm password reset and gain publish rights without touching the maintainer's own infrastructure (Socket Security, 2026-05-14). CSO counts almost 700K weekly downloads and 424 dependent projects, while StepSecurity reports over 10 million weekly downloads (CSO Online, 2026-05-14 · StepSecurity, 2026-05-14). The 9.x releases are fabricated from the 12.x package structure, so projects on ^9, ~9.1.x, ~9.2.x, ^12 or ~12.0 ranges received a malicious build on their next install or lockfile refresh (StepSecurity, 2026-05-14). When StepSecurity published, npm's latest tag pointed to 12.0.1, so an unpinned npm install node-ipc pulled the compromised tarball (StepSecurity, 2026-05-14).

The payload is an 80 KB obfuscated function appended to the CommonJS bundle node-ipc.cjs. It runs on every require('node-ipc') and uses no npm lifecycle hook, so tools that only scan preinstall and postinstall scripts miss it (StepSecurity, 2026-05-14). ESM-only consumers do not load the malicious file unless another dependency or a direct require loads node-ipc.cjs (Socket Security, 2026-05-14). The payload forks a detached child Node process that collects cloud provider credentials, SSH keys, Kubernetes tokens, GitHub CLI configuration, Terraform state, CI workflow files, .env files, shell history and macOS Keychain databases, gzips them and exfiltrates them (Socket Security, 2026-05-14 · StepSecurity, 2026-05-14). Four stacked obfuscation layers (string-array shuffling, control-flow flattening, dead-code injection and a custom reversed-nibble base-16 encoding) resist static analysis (StepSecurity, 2026-05-14). Socket found no persistence and no second-stage download, and its scanner flagged the publish within roughly three minutes (Socket Security, 2026-05-14).

Contradiction: the analyses disagree on payload details. StepSecurity and The Hacker News describe 90+ file-path patterns, an HTTPS POST channel alongside DNS TXT exfiltration, and a SHA-256 targeting gate that leaves 12.0.1 inert except on one targeted project (StepSecurity, 2026-05-14 · The Hacker News, 2026-05-14). Socket counts 113 macOS and 127 Linux patterns, says the payload uses DNS TXT queries and not HTTP, HTTPS or TLS for exfiltration, and finds the same malicious file in all three versions, with a hash gate that only changes what the module exports (Socket Security, 2026-05-14). Treat all three versions as active stealers.

Correctionrun 2026-09-30T0639Z-auditbodyclassificationtechniquesheadlinesummarytitle

No source says the malicious versions were removed from the registry: when StepSecurity published, npm's latest tag pointed to the malicious 12.0.1 (StepSecurity, 2026-05-14). The payload fires on require() and uses no install hook, so disabling install scripts in CI does not stop it. Socket's advice is to review dependencies by their entrypoints and to rotate every secret on an affected host (Socket Security, 2026-05-14). Socket and StepSecurity disagree on the exfiltration channels, the pattern count and whether 12.0.1 is gated to one target (Socket Security, 2026-05-14 · StepSecurity, 2026-05-14), and all three versions should be treated as active. The entry previously named a domain registrar and Vue CLI and webpack tooling as dependents, which no cited source states.

incident16 May 05:00Zmulti-sourceOpen finding →
NOTABLEupdatedNATOB2

GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration (1M+ files from one victim); DLS shutdown signals possible rebrand

Google Threat Intelligence Group published on 2026-05-15 an analysis of UNC6671, a financially motivated extortion cluster that adopted the "BlackFile" brand by February 2026 and has targeted dozens of organizations across North America, Australia and the UK (Google Threat Intelligence Group, 2026-05-15). Callers hired by the actor phone employees' personal mobile numbers, pose as internal IT or helpdesk staff citing a passkey migration or MFA update, and send the victim to a lookalike single sign-on portal on Tucows-registered domains, lately as organization-named subdomains with "passkey" or "enrollment" themes (Google Threat Intelligence Group, 2026-05-15). The operator relays the credentials and the MFA code or push approval to the real SSO provider in real time, then immediately registers a new attacker-controlled MFA device for persistence (Google Threat Intelligence Group, 2026-05-15). GTIG stresses that these compromises come from social engineering, not a vendor vulnerability (Google Threat Intelligence Group, 2026-05-15).

After access, the actor moves into connected SaaS applications (SharePoint, OneDrive, Zendesk, Salesforce), searches for strings such as "confidential" and "SSN", and exfiltrates with Python requests and PowerShell scripts through Microsoft Graph and direct HTTP GET requests against document URLs, reusing session cookies (for example FedAuth) captured during the vishing phase (Google Threat Intelligence Group, 2026-05-15). In one case the script downloaded more than a million files from SharePoint and OneDrive (Google Threat Intelligence Group, 2026-05-15). The direct-fetch method is often logged as FileAccessed rather than FileDownloaded, so it slips past SOCs that treat FileAccessed as benign (Google Threat Intelligence Group, 2026-05-15). In early intrusions the FileDownloaded records carried a spoofed Microsoft Office ClientAppId, which GTIG says served to bypass basic conditional access filters, while the user-agent showed python-requests or WindowsPowerShell (Google Threat Intelligence Group, 2026-05-15). In later intrusions the FileAccessed records named python-requests as the client application in AppAccessContext (Google Threat Intelligence Group, 2026-05-15). The sessions came from commercial VPN exit nodes and hosting providers (Google Threat Intelligence Group, 2026-05-15).

The BlackFile leak site went offline in late April 2026, came back on 2026-05-11 with a message that BlackFile "is shutting down… under this name", and was inaccessible at publication (Google Threat Intelligence Group, 2026-05-15). GTIG reads this as a possible transition phase rather than a permanent cessation, noting that extortion clusters commonly rebrand or disperse after shutdowns (Google Threat Intelligence Group, 2026-05-15). GTIG assesses UNC6671 as independent of ShinyHunters (UNC6240), although UNC6671 co-opted the ShinyHunters brand at least once (Google Threat Intelligence Group, 2026-05-15).

Triage: an Office client identity paired with a scripting-library user-agent is the mismatch GTIG found, and GTIG reads it as scripted access rather than a person using SharePoint (Google Threat Intelligence Group, 2026-05-15). A session source on a commercial VPN or hosting provider that is unusual for the user adds weight (Google Threat Intelligence Group, 2026-05-15).

Correctionrun 2026-09-30T0639Z-auditbodyclassificationtechniquestitleheadlinesummarypriorityentitiessectors

GTIG describes the leak-site shutdown as a possible transition phase rather than a permanent cessation, not as a probable rebrand (Google Threat Intelligence Group, 2026-05-15). The detection guidance is corrected to GTIG's own: the spoofed Microsoft Office ClientAppId appeared on FileDownloaded records, later FileAccessed records named python-requests as the client, and new MFA factor registrations are suspicious when immediately preceded by failed or abandoned MFA challenges (Google Threat Intelligence Group, 2026-05-15). The actor reused captured session cookies such as FedAuth, and GTIG does not describe theft of application access tokens (Google Threat Intelligence Group, 2026-05-15).

incident16 May 05:00Zsingle-sourceOpen finding →
CRITICALCVE-2026-42897exploited

CVE-2026-42897, Microsoft Exchange Server 2016 / 2019 / SE: stored XSS in OWA, actively exploited, no permanent patch

CVE-2026-42897 (CWE-79, CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N, base 8.1) is a stored / reflected cross-site scripting flaw in the Outlook Web Access component of on-premises Microsoft Exchange Server, disclosed by Microsoft on 2026-05-14 alongside the May 2026 Patch Tuesday cycle (Microsoft MSRC, 2026-05-14 · Microsoft Exchange Team, 2026-05-14 · NCSC-CH Security Hub #12577, 2026-05-15 · BSI WID-SEC-2026-1536, 2026-05-14 · NCSC-NL NCSC-2026-0159, 2026-05-15). An unauthenticated attacker delivers a specially crafted email; when the recipient opens it in OWA and a documented set of interaction conditions are met, arbitrary JavaScript executes in the OWA browser context, yielding session-token theft, content spoofing, and onward lateral phishing from the now-trusted sender. Microsoft has confirmed Exploitation Detected (the highest of its three exploitation-status tiers) and assesses the issue as Critical despite the 8.1 base score; CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2026-05-15 with a federal remediation deadline of 2026-05-29. Affected: Exchange Server 2016 (all CU levels), Exchange Server 2019 (all CU levels), Exchange Server Subscription Edition (RTM and current CUs). Exchange Online is not affected. There is no permanent patch in the May 2026 Patch Tuesday bundle. Microsoft is shipping only an interim URL-rewrite Mitigation M2 through the Exchange Emergency Mitigation Service (EEMS), which is enabled by default on Exchange 2016 SP1 and later and auto-applies without requiring a service restart; air-gapped or EEMS-disconnected servers, plus deployments where EEMS has been manually disabled, must apply Mitigation M2 by running the Exchange On-Premises Mitigation Tool (EOMT) script from aka.ms/UnifiedEOMT via the Exchange Management Shell. Permanent fixes are forthcoming for Exchange SE RTM (publicly available SU); for Exchange 2016 and Exchange 2019, the permanent update will be distributed only to organisations enrolled in the Period 2 Exchange Server Extended Security Update programme, which is a notable operational risk for any CH/EU public-sector organisation that has not enrolled. Detection: IIS access logs on the front-end Exchange role for /owa/ URLs containing <script> fragments or HTML-encoded equivalents in query strings; Exchange Application Event Log EID 4 (MSExchange Management) for EEMS mitigation-state changes; EDR alerts on browser processes spawning unexpected children from OWA sessions. EEMS verification: Get-ExchangeDiagnosticInfo -Server <name> -Process MSExchangeHMWorker -Component EemsMitigation -SettingName MitigationsApplied.

Current exploitation status: Actively Exploited

NCSC Switzerland Cyber Security Hub

Microsoft is supplying a temporary mitigation for this vulnerability through the Exchange Emergency Mitigation Service. We are working on developing and testing a more permanent fix.

Microsoft MSRC
vulnerability16 May 05:00Zmulti-sourceOpen finding →

CVE-2026-44112 / CVE-2026-44113 / CVE-2026-44115 / CVE-2026-44118, OpenClaw "Claw Chain": four chainable flaws in autonomous-agent platform enable sandbox escape → credential leak → privilege escalation → file disclosure

Cyera Research published on 2026-05-15 four chained vulnerabilities in OpenClaw (also marketed as Clawdbot), an autonomous AI-agent platform released in late 2025 with integrations including Microsoft Agent 365 (Cyera Research, 2026-05-15 · The Hacker News, 2026-05-15). All four CVEs are fixed by the OpenClaw release dated 2026-04-23, addressed under GitHub Security Advisories GHSA-5h3g-6xhh-rg6p, GHSA-wppj-c6mr-83jj, GHSA-r6xh-pqhr-v4xh, and GHSA-x3h8-jrgh-p8jx. The defender-relevant detail is that an attacker who can obtain code execution inside the OpenClaw managed sandbox (achievable via a malicious plugin, prompt injection into the agent context, or supply-chain compromise of an OpenClaw plugin) can chain the four primitives to a full sandbox-escape → credential-harvest → owner-level agent control → file-disclosure sequence whose steps each mimic normal agent behaviour and so evade controls calibrated to "human-attacker" indicators. CVE-2026-44112 (CVSS 9.6, Critical) is a TOCTOU race in the OpenShell sandbox backend that lets the sandbox process win the filesystem write race and redirect writes outside the intended mount root, enabling host-filesystem tampering and persistent backdoor placement. CVE-2026-44115 (CVSS 8.8, High) is an incomplete allowlist in OpenClaw's command parser, shell-expansion tokens embedded in environment-variable names bypass the validation gate, leaking API keys, tokens, and credentials at execution time. CVE-2026-44118 (CVSS 7.8, High) trusts a client-controlled senderIsOwner flag in MCP loopback messages without validating against the authenticated session, allowing privilege escalation to owner-level agent control. CVE-2026-44113 (CVSS 7.7, High) is the companion TOCTOU read escape enabling file disclosure outside the sandbox root. Exposure is broad: Cyera cites ~65 K (Shodan) and ~180 K (ZoomEye) publicly accessible OpenClaw instances as of May 2026, summing to an estimated ~245 K exposed servers. No in-the-wild exploitation reported at disclosure. Detection: alert on the agent process writing files outside designated sandbox mount directories; flag MCP loopback messages with senderIsOwner=true from sources not matching the authenticated session; alert on environment-variable expansion in command strings at agent execution time.

vulnerability16 May 05:00Zmulti-sourceOpen finding →

AMD-SB-7052 / CVE-2025-54518, AMD Zen 2 µop-cache corruption / SoC isolation failure: local privilege escalation (CVSS 7.3), microcode mitigation in May 2026 Windows update and Xen XSA-490

AMD disclosed AMD-SB-7052 (CVE-2025-54518, CVSS 7.3 on the CVSS 4.0 scale, CWE-1189 Improper Isolation of Shared Resources on System-on-Chip) affecting Zen 2-based processor models on 2026-05-12, with NCSC-NL flagging the advisory on 2026-05-15 (AMD Product Security, 2026-05-12 · NCSC-NL NCSC-2026-0158, 2026-05-15). The flaw allows a local attacker with code execution on the target system to corrupt the CPU operation (µop) cache and thereby cause instructions to execute at a higher privilege level than intended, enabling local privilege escalation and, in virtualisation contexts, potential degradation of hypervisor-level isolation. Mitigation is delivered as microcode integrated into the May 2026 Microsoft Windows cumulative update (the same window as the previously-covered CVE-2026-41089 / 41096 Patch Tuesday set); Fedora has issued separate kernel + microcode updates (advisory IDs per NCSC-NL CSAF references) and Xen has published XSA-490 for bare-metal hypervisor operators. Lenovo has published a product-security advisory covering affected ThinkPad / ThinkStation / Workstation models for BIOS / UEFI guidance. Attack class: T1068 Exploitation for Privilege Escalation, with elevated relevance in confidential-compute and multi-tenant virtualisation contexts (VDI estates, cloud-hosted VMs on Zen 2 hosts, shared university compute clusters). No in-the-wild exploitation confirmed. Detection / verification: confirm the May 2026 Windows CU includes the AMD microcode revision via the relevant KB and wmic cpu get name, dataWidth, processorId; for Linux hypervisors apply distro kernel + microcode updates and reboot; for Xen apply XSA-490; for Lenovo hardware check BIOS / UEFI update guidance per LEN-216977. The local-only attack vector limits external risk; the priority is multi-tenant and virtualisation contexts where guest-to-hypervisor or container-to-host isolation is part of the security boundary.

CVE Summary Table

CVE Product CVSS EPSS KEV Exploited Patch Source
CVE-2026-42897 Microsoft Exchange Server 2016 / 2019 / SE, OWA 8.1 (v3.1) n/a Yes (added 2026-05-15) Yes, Microsoft confirmed No permanent patch; EEMS Mitigation M2 (auto / EOMT manual) Microsoft MSRC
CVE-2026-44112 OpenClaw / Clawdbot, OpenShell sandbox (TOCTOU write escape) 9.6 (Critical) n/a No No OpenClaw 2026-04-23 release (GHSA-5h3g-6xhh-rg6p) Cyera Research
CVE-2026-44115 OpenClaw / Clawdbot, command-parser allowlist bypass 8.8 (High) n/a No No OpenClaw 2026-04-23 release (GHSA-wppj-c6mr-83jj) Cyera Research
CVE-2026-44118 OpenClaw / Clawdbot, MCP loopback senderIsOwner trust 7.8 (High) n/a No No OpenClaw 2026-04-23 release (GHSA-r6xh-pqhr-v4xh) Cyera Research
CVE-2026-44113 OpenClaw / Clawdbot, TOCTOU read escape (file disclosure) 7.7 (High) n/a No No OpenClaw 2026-04-23 release (GHSA-x3h8-jrgh-p8jx) Cyera Research
CVE-2025-54518 (AMD-SB-7052) AMD Zen 2 CPUs, µop cache / SoC isolation LPE 7.3 (CVSS 4.0) n/a No No May 2026 Windows CU; Fedora kernel + microcode updates; Xen XSA-490 AMD Product Security
vulnerability16 May 05:00Zmulti-sourceOpen finding →

03Research, reports & policy2 items

NOTABLE

SentinelOne: "Living Off the Pipeline", CI/CD subversion taxonomy with three real intrusion cases (TeamCity, GitLab service-account pivot, Contagious Interview)

SentinelOne published on 2026-05-15 a practitioner-focused taxonomy of CI/CD pipeline subversion techniques, illustrated with three real intrusion case studies that are immediately useful for SOC and DevSecOps teams running JetBrains TeamCity, GitLab, or GitHub Actions (SentinelOne, 2026-05-15). Case 1: an unpatched TeamCity server (CVE-2023-42793) exploited to deploy backdoors via privileged build tasks, remaining undetected for 12+ months. Case 2: a GitLab service-account token compromise enabling creation of malicious Ansible playbooks that were then automatically executed by pipelines, a clean demonstration of how service-account over-privilege translates directly into production code execution. Case 3: the Contagious Interview campaign using fraudulent job offers directing developer victims to fake skill-assessment sites that deploy malware silently to developer workstations. Additional vectors covered include attacker-registered self-hosted runners, workflow triggers from repository discussion comments, dependency poisoning with reconnaissance preinstall scripts, and maintainer-account compromise appending malicious code; the article cross-links a separate SentinelOne analysis of the "Sha1-Hulud" NPM compromise as a related supply-chain case. MITRE ATT&CK: T1195.002, T1547 (rogue runner registration as persistence), T1555 (pipeline secret extraction), T1204 (user execution via fake job-offer social engineering), T1072 (software-deployment-tool abuse via Ansible). Defender monitoring priorities surfaced in the report: GitHub / GitLab audit logs for runner.registered events with unfamiliar names or unexpected source IP ranges; new or modified pipelines authored by service accounts; suspicious child-process spawn from build agents (cmd.exe, powershell.exe, curl, wget outside baseline); credential-access and reverse-tunnel traffic originating from build infrastructure; and secret-injection patterns in workflow-config modifications. Single-source, SentinelOne only.

research16 May 05:00Zsingle-sourceOpen finding →
NOTABLE

Unit 42: Gremlin Stealer evolved with .NET-resource XOR obfuscation, real-time crypto-clipper, and WebSocket browser-process session-hijack module

Palo Alto Networks Unit 42 published on 2026-05-15 an analysis of evolved variants of the Gremlin information stealer, adding three new capability tiers operationally relevant to defenders running endpoint detections tuned for older Gremlin samples (Palo Alto Networks Unit 42, 2026-05-15). Obfuscation has shifted to embedding encrypted payloads in .NET resource sections (XOR-keyed) combined with single- or double-character identifier renaming and a runtime string-decoder function (_003CModule_003E.c()), defeating static signature analysis of string literals that previous-generation Gremlin samples used. A new crypto-clipper component continuously monitors the system clipboard and replaces Bitcoin and Ethereum wallet addresses with attacker-controlled equivalents in real time, T1115. The most operationally interesting addition is a WebSocket-based session-hijack module that reads active browser process memory (Chrome-based browsers) to extract session tokens directly from running processes, bypassing the cookie-encryption mitigations modern browsers apply at disk, T1185 Browser Session Hijacking. Credential scope includes browser cookies, session tokens, saved passwords, payment-card details, FTP and VPN credentials, Discord tokens (dedicated regex scanner), clipboard content, and cryptocurrency wallet files. Exfiltration is HTTPS POST to a private web panel; a Telegram Bot API channel is the secondary channel. Detection: Sysmon EID 10 (process access) targeting chrome.exe or msedge.exe (and other Chrome-based browser processes) from unexpected parent processes; clipboard-monitoring hook registration from non-standard processes (generic Windows clipboard-listener API surface). Hardening: browser isolation for high-value sessions; clipboard-API access audited in EDR telemetry. Single-source, Unit 42 only; flagged for verification.

research16 May 05:00Zsingle-sourceOpen finding →

04Deep dive1 item

NOTABLECVE-2026-42897exploited

Microsoft Exchange CVE-2026-42897: Active Exploitation Without a Patch

Background. On-premises Microsoft Exchange has been a sustained, high-value target for advanced and opportunistic actors for the entire 2021–2026 window. ProxyLogon (CVE-2021-26855 + chain) in March 2021 was exploited at scale by Hafnium and dozens of follow-on clusters before mitigations stuck; ProxyShell (CVE-2021-34473 + chain) repeated the pattern in August 2021 (Microsoft Threat Intelligence, 2021-03-02 · CISA Alert AA21-321A, 2021-11-17). The Exchange Emergency Mitigation Service (EEMS), introduced in Exchange Server 2016 CU22 and 2019 CU11, was Microsoft's explicit response to that pattern: a small auto-update mechanism that ships URL-rewrite rules to live Exchange front-ends in the gap between an in-the-wild zero-day and a permanent CU (Microsoft, 2021-09-28). CVE-2026-42897 is the first 2026 case where EEMS (not a Patch Tuesday CU) is the line of defence against active exploitation; the deep dive that follows is therefore as much about EEMS verification and bypass conditions as about the XSS itself.

Vulnerability mechanics. CVE-2026-42897 is classified by Microsoft as a spoofing vulnerability (impact category) underpinned by CWE-79, improper neutralisation of input during web-page generation, in the Outlook Web Access (OWA) component (Microsoft MSRC, 2026-05-14). The CVSS:3.1 vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N describes a network-deliverable XSS that requires the victim to open the malicious message in OWA: no authentication is required of the attacker, only of the recipient. Microsoft assesses severity Critical despite the 8.1 base score, the "Critical" label reflects the impact reach (session-token theft, content tampering in the OWA session, downstream phishing from a now-trusted internal mailbox), not the base metric. Microsoft has not published the precise attacker-controlled fragment that delivers the JavaScript payload (consistent with Exploitation Detected status, the team is withholding payload format pending the permanent SU) but the MSRC FAQ confirms the chain shape: crafted email → OWA render → script execution → spoofing actions taken under the victim's authenticated OWA context. Affected versions are Exchange Server 2016 (all CU levels), Exchange Server 2019 (all CU levels), and Exchange Server Subscription Edition (RTM and current CUs); Exchange Online is unaffected.

Exploitation status and attribution. Microsoft confirmed Exploitation Detected on 2026-05-14 with the published advisory (Microsoft MSRC, 2026-05-14). The NCSC Switzerland Cyber Security Hub independently restated the active-exploitation finding in advisory #12577 on 2026-05-15 (NCSC-CH Security Hub #12577, 2026-05-15). CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2026-05-15 with a federal civilian-branch remediation deadline of 2026-05-29; per PD-13 in this brief series, that deadline has no jurisdictional weight in Switzerland or the EU and is recorded here only as confirmation of the exploitation signal; defenders should drive the remediation timeline off the Microsoft-confirmed active exploitation, not the BOD 22-01 date. No named threat-actor attribution has been published; Microsoft notes the scale and identity of the exploitation activity are not yet detailed publicly (The Hacker News, 2026-05-15).

Attack chain. From the limited disclosure, the operationally credible kill chain is:

  1. T1566.001 Phishing: Spearphishing Attachment: attacker delivers a specifically crafted email to a target whose mailbox is hosted on a vulnerable on-premises Exchange Server.
  2. T1059.007 Command and Scripting Interpreter: JavaScript: when the target opens the message in OWA, browser-side JavaScript executes in the OWA origin's context.
  3. T1185 Browser Session Hijacking: payload reads OWA session cookies / auth tokens and exfiltrates to attacker-controlled infrastructure.
  4. T1078 Valid Accounts: attacker re-uses the exfiltrated session material to issue authenticated OWA requests as the victim, with full mailbox read/send privileges.
  5. T1534 Internal Spearphishing: onward phishing from the now-trusted internal sender to high-value recipients (executives, finance, identity admins), spreading the access.

EEMS; what it does, when it doesn't apply. The Exchange Emergency Mitigation Service is a small Windows service installed by the Exchange setup process on Exchange 2016 CU22 / Exchange 2019 CU11 and later; it polls a Microsoft-hosted Office Config Service endpoint hourly for new mitigation rules and applies URL-rewrite rules to the IIS configuration when one matches the server's installed Exchange version. For CVE-2026-42897, Microsoft has published Mitigation M2, which rewrites the specific request format the in-the-wild exploit uses to deliver the XSS payload; the mitigation does not require an Exchange restart and applies automatically on any internet-connected, EEMS-enabled Exchange server (Microsoft Exchange Team, 2026-05-14). EEMS does not apply automatically in the following operationally common configurations: (a) Exchange Server 2013, on which EEMS is not available; (b) Exchange servers with no outbound HTTPS connectivity to officeclient.microsoft.com (air-gapped networks, segmented DMZs, environments with strict egress controls); (c) Exchange servers where EEMS has been manually disabled (Set-OrganizationConfig -MitigationsEnabled $false, Set-Server -MitigationsEnabled $false, or via Group Policy); (d) Exchange servers that have been hardened with custom IIS rewrite rules that conflict with the EEMS rule placement. For all four cases, operators must run the Exchange On-Premises Mitigation Tool (EOMT) (downloadable from aka.ms/UnifiedEOMT) via the Exchange Management Shell as Administrator, which applies the same URL-rewrite Mitigation M2 manually.

EEMS verification; what to actually run on every Exchange server. The canonical check is:

  • Get-ExchangeDiagnosticInfo -Server <server> -Process MSExchangeHMWorker -Component EemsMitigation -SettingName MitigationsApplied and confirm the Mitigation M2 identifier published in the MSRC advisory appears in the output.
  • Get-OrganizationConfig | Select-Object MitigationsEnabled and Get-Server <server> | Select-Object MitigationsEnabled should both return True.
  • IIS Manager → Default Web Site → URL Rewrite should show the EEMS-injected rewrite rule corresponding to CVE-2026-42897.

If any check fails, run EOMT immediately; do not wait for the next EEMS poll cycle.

Permanent-patch availability, the Period 2 ESU constraint. Microsoft has signalled that the permanent fix will ship as a CU for Exchange Server Subscription Edition (publicly available SU) and as a security update for Exchange 2016 CU23 and Exchange 2019 CU14 / CU15, but the Exchange 2016 / 2019 updates will only be distributed to organisations enrolled in the Period 2 Exchange Server Extended Security Update programme (Microsoft Exchange Team, 2026-05-14). Any Swiss or European public-sector organisation running Exchange 2016 / 2019 in production today should verify ESU enrolment status with its Microsoft licensing partner before relying on the permanent update path; organisations that are not enrolled face a structural constraint where EEMS Mitigation M2 is the permanent operational mitigation, not the bridge.

Hunt and detection concepts. The mitigation prevents future exploitation; it does not retroactively detect or remediate prior exploitation. Defenders should look back to 2026-05-09 (a generous overlap window prior to public disclosure):

  • IIS access logs (front-end Exchange role): /owa/ URLs with <script>, javascript:, or HTML-encoded equivalents in query strings; OWA URLs with anomalous referrer headers from external mail-rendering paths.
  • Exchange transport logs: emails with HTML bodies that embed encoded JavaScript fragments delivered to mailboxes whose owners are OWA users (cross-correlate with Get-CASMailbox -OWAEnabled $true).
  • EDR telemetry on Exchange front-end servers: w3wp.exe (IIS worker process, Exchange app pool) spawning unexpected children (cmd.exe, powershell.exe, cscript.exe, browser launchers) is the post-exploitation tell of XSS-to-execution chains observed in prior Exchange compromises.
  • Exchange Application Event Log EID 4 (MSExchange Management): for EEMS mitigation-state changes; flag any disable / re-enable cycle that does not correspond to a documented change.
  • OWA session anomalies: Get-MailboxAuditLog for unusual mailbox-folder reads or message-send activity from sessions whose source IP differs from the user's established pattern.

Hardening and mitigation. The non-negotiable immediate action is verifying EEMS Mitigation M2 is applied on every Exchange Server 2016, 2019, and SE in the estate and applying EOMT where it is not. Beyond that, defenders should: (a) confirm Period 2 ESU enrolment for any Exchange 2016 / 2019 production deployment that is not on a migration path to SE or Online; (b) restrict OWA access at the perimeter to users behind Conditional Access compliant-device policy where possible, reducing the population of XSS-deliverable mailboxes; (c) plan migration to Exchange Server SE or Exchange Online; repeated EEMS-only mitigations across the 2021–2026 Exchange CVE history are the operational signal that on-premises Exchange has become structurally expensive to defend on the 2016 / 2019 codebases.

Background.

ctipilot v2 brief (migrated)
vulnerability16 May 05:00Zmulti-sourceOpen finding →

05Action items4 items

Verification & coverage notes1 run

2026-05-16-5bc123a0 · Claude Opus 4.7 · window 36 h · 10 entries published

  • Items dropped (duplicate of prior coverage):
    • Exim CVE-2026-45185 ("Dead.Letter" pre-auth heap UAF via BDAT/GnuTLS), already covered as a § 2 Trending Vulnerability in briefs/2026-05-13.md (primary source XBOW research blog 2026-05-12). S1's re-surfacing in this run includes the discoverer attribution (Federico Kirschbaum / XBOW) and patch detail (4.99.3 fixes by resetting input-processing stack on TLS close_notify during BDAT), none of which constitute material new development under PD-8. No § 4 UPDATE warranted.
  • Items dropped / deferred (out-of-window recency, PD-7):
    • Microsoft IR case study "Undermining the trust boundary, 106-day stealth intrusion via trusted HPE Operations Manager (HPOM)" (Microsoft IR, 2026-05-12): primary source published 2026-05-12, more than 36 h before this run's start; no fresher in-window development. Substantive technical research with strong defender takeaways (HPOM VBScript push as living-off-trusted-tools persistence, Updater.dll network-provider DLL credential interception, 106-day undetected dwell), deferred to the weekly summary for cross-day consolidation. out-of-window: primary source 2026-05-12, window_hours=36.
    • Cushman & Wakefield vishing breach (ShinyHunters Salesforce CRM data + Qilin separate listing): initial disclosure 2026-05-05, victim statement 2026-05-05, HIBP indexing 2026-05-12. All evidence dates fall outside the 36-hour window. Pattern (vishing → SaaS-CRM credential capture → bulk record exfil) is consistent with previously-covered ShinyHunters operations and adds no fresh TTP. out-of-window: primary sources 2026-05-05 to 2026-05-12, window_hours=36.
  • F5 BIG-IP / BIG-IQ May 2026 Quarterly Security Notification (K000160932): NCSC-NL flagged the bundle as HIGH on 2026-05-15 (NCSC-NL NCSC-2026-0162, 2026-05-15). Per-CVE enumeration requires authenticated myF5 portal access and could not be obtained from the public CSAF excerpt in this run. Operators of F5 BIG-IP / BIG-IQ in Swiss financial-sector, telco, and large public-sector perimeters should pull the K-article matrix directly; we will surface the per-CVE detail in the next brief that pivots through an authenticated review or a corroborating researcher write-up.
  • Sub-agent telemetry: S1 returned (Claude Sonnet 4.6, 236 s, 7 webfetch + 6 websearch + 18 bridge). S2 returned (Claude Sonnet 4.6, 245 s, 14 webfetch + 8 websearch + 12 bridge). S3 returned (Claude Sonnet 4.6, 616 s, 12 webfetch + 0 websearch + 8 bridge). S4 returned (Claude Sonnet 4.6, 524 s, 12 webfetch + 12 websearch + 11 bridge).
  • Item-overlap consolidation: CVE-2026-42897 Exchange OWA XSS was independently surfaced by S1, S2, S3, and S4, consolidated into one § 2 item, one § 5 deep dive, and the § 0 Immediate Action callout, with sources pooled across all four sub-agent returns. Kazuar / Secret Blizzard was surfaced by S2 and S3, consolidated into one § 1 item. node-ipc npm was surfaced by S3 and S4, consolidated into one § 1 item.
  • Single-source items: Gremlin Stealer evolved (Palo Alto Networks Unit 42, 2026-05-15), sole reputable primary, no independent corroboration found in window. SentinelOne "Living Off the Pipeline" CI/CD subversion taxonomy (SentinelOne, 2026-05-15), sole primary; the analytical content draws on prior public CVE-2023-42793 / Contagious Interview reporting, but the synthesis is single-sourced.
  • Coverage gaps / fetch failures:
    • databreaches-net: WebFetch returned 403 (5th consecutive run failing); WebSearch fallback used for breach-story discovery, no unique stories lost in this run. Rotation-priority signal preserved for the next run.
    • inside-it-ch: Cloudflare Managed Challenge blocked WebFetch (4th consecutive run); WebSearch fallback found no CH-specific items beyond what NCSC-CH posts surfaced. Rotation-priority signal preserved.
    • bleepingcomputer: rotation-priority source, multiple article URLs returned 403; URLs successfully fetched by S2 (e.g. the Microsoft Exchange zero-day article) used after cross-confirmation; broader feed listing not enumerated.
    • helpnetsecurity: rotation-priority source, known 429 rate-limit; one article cited (CVE-2026-42897 coverage) fetched successfully and corroborated.
    • cert-eu: no new advisories in the 36-hour window (latest 2026-006 dated 2026-05-06).
    • anssi-fr (CERT-FR): most recent avis bulletins outside the 36-hour window (latest 2026-05-12 / 13).
    • sophos-xops: feed returned HTTP 503; no items retrieved this run.
    • sekoia: no new posts in window (latest 2026-04-23).
    • cert-pl: SPA listing not navigated this run.
    • cnil-fr: site under scheduled maintenance 2026-05-13 to 2026-05-18 per maintenance notice.
    • sec-disclosures-edgar: SEC EDGAR Item 1.05 bridge returned 0 cyber-disclosure filings for the 2026-05-12 to 2026-05-16 window, quiet period for material cyber disclosures.
  • Coverage gaps: databreaches-net (403 5×); inside-it-ch (Cloudflare 4×); cert-eu (no in-window advisories); anssi-fr (no in-window AVI); sophos-xops (feed 503); sekoia (no in-window posts); cert-pl (SPA listing not navigated); cnil-fr (scheduled maintenance); sec-disclosures-edgar (no in-window 8-K Item 1.05 filings).
  • Verification status: CLEAN at iteration 4 (4 iterations, model-rotated). Iter 1 (Opus): 4 truth findings (Period 2 ESU citation, BlackFile ClientAppId location, Gremlin SetClipboardViewer API, node-ipc 822K download count), all fixed. Iter 2 (Sonnet): 2 truth + 1 editorial + 2 advisory (AMD-SB-7052 CVE/CVSS missing → CVE-2025-54518 CVSS 7.3 added, node-ipc DNS TXT count unsupported → dropped, Gremlin detection SetClipboardViewer still unsupported → softened, Fedora/Lenovo advisory IDs unverified → IDs dropped, helpdesk-priviledged typo), all fixed. Iter 3 (Opus, cold): 4 truth + 1 advisory (Gremlin Brave browser, OpenClaw "2026.4.22" version label, Kazuar "European" narrowing, SentinelOne Sha1-Hulud pattern claim, Aqua Blizzard paraphrase strength), all fixed. Iter 4 (Sonnet, with deltas): CLEAN, all iter-3 remediations verified correct against re-fetched primary sources. verification_residual_count: 0.

Unmatched action items (migrated)

  • Inventory every node-ipc install across developer workstations and CI/CD runners (transitive deps included); rotate every credential accessible from any environment that installed 9.1.6 / 9.2.3 / 12.0.1. Run npm ls node-ipc against every project; flag any install whose timestamp falls between 2026-05-14 publish-time and registry removal. Treat any match as a full developer-secret compromise: cloud SDK profiles, SSH keys, Kubernetes contexts, GitHub / npm / Git tokens, Terraform state, .env files, and macOS Keychain databases were all in scope. Going forward, enforce npm ci --ignore-scripts and lockfile-based installs in CI, monitor outbound DNS to the bt.node.js suffix, and add domain-expiry monitoring for maintainer email domains of critical dependencies. See § 1 (node-ipc entry).
  • Add the BlackFile vishing → AiTM → rogue-MFA → SharePoint-API exfiltration detections to M365 / Okta monitoring. Concretely: alert on Okta system.multifactor.factor.setup events without a preceding user-initiated session; alert on M365 audit FileAccessed events with AppAccessContext.ClientAppId == d3590ed6-52b3-4102-aeff-aad2292ab01c AND user-agent containing python-requests or PowerShell; require Conditional Access compliant-device for Graph API access by administrative accounts; move helpdesk-privileged accounts to FIDO2 phishing-resistant MFA so the live-vishing capture-and-replay chain fails at the second factor. See § 1 (BlackFile entry).
  • Hunt for Kazuar P2P artefacts on systems hosting European government, diplomatic, or defence workloads. Concretely: Sysmon EID 17 / 18 for Mailslot creation from non-standard processes; registry audit on HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages for unsigned DLL additions; flag programmatic Exchange Web Services authentication originating from non-Exchange processes against the organisation's own mail servers. Where Aqua Blizzard / Gamaredon presence has been previously detected, treat Kazuar implant presence as a concurrent hypothesis. See § 1 (Secret Blizzard entry).

Migrated from briefs/2026-05-16.md (v2).