12 verified findings from 1 run · the settled record for this UTC day, in the classic brief order.
Criticality
Kind
Topic
Region
TL;DR · the day in one read
01Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries. CISA added three supply-chain CVEs to KEV on 2026-05-27, the Nx Console / TanStack / DAEMON Tools cascade. The Nx Console v18.95.0 VS Code extension compromise (CVE-2026-48027) traces to the TanStack npm supply-chain compromise (CVE-2026-45321), whose payload exfiltrated a contributor's GitHub CLI OAuth token. GitHub's CISO named the extension as the vector for the theft of about 3,800 GitHub internal repositories, and Grafana Labs traced its own breach to the upstream TanStack compromise. Separately, CVE-2026-8398 covers a roughly four-week trojanisation of signed DAEMON Tools Lite builds 12.5.0.2421 to 12.5.0.2434 from the vendor's build environment. →
02CVE-2026-35087 / CVE-2026-35089 / CVE-2026-35090, Slican PBX telephony exchanges, triple pre-authentication admin bypass (CERT Polska). CERT-PL, three pre-authentication admin-bypass CVEs in Slican PBX (CVE-2026-35087 / -35089 / -35090, all CVSS 4.0 9.3 except -35089 at 8.7). Slican telephony equipment is widely deployed in Polish government, public administration and healthcare and is also sold across Central and Eastern Europe. CVE-2026-35090's hardcoded caller-ID admin bypass on the PSTN modem interface is particularly notable, if remote management is disabled, the call temporarily re-enables it (CERT Polska, 2026-05-27; ENISA EUVD entry, 2026-05-27). →
03CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1). Roundcube Webmail 1.6.16 / 1.7.1, pre-auth SQL injection in the virtuser_query plugin (CVE-2026-48842, CVSS 8.1) plus three further high-severity flaws. NCSC.ch published an advisory on 2026-05-27 flagging the cluster; Roundcube is the dominant self-hosted webmail across European public administrations and academic institutions (Roundcube Project, 2026-05-24; NCSC-CH, 2026-05-27; Heise, 2026-05-27). The companion bugs cover an LDAP autovalues code-injection (CVE-2026-48844), an SVG-based CSS-sanitisation bypass (CVE-2026-48848) and an SSRF / info-disclosure via crafted SVG animate (CVE-2026-48843). →
04Dutch National Police arrest 35-year-old over AFC Ajax fan-data breach, misconfigured API access-control and shared keys exposed 300,000+ accounts and 42,000. Dutch National Police arrested a 35-year-old from Buren over the AFC Ajax data breach. Per BleepingComputer and The Record (citing the Dutch police release), the underlying API access-control flaw and shared keys exposed ~300,000 fan accounts and ~42,000 season-ticket records; Ajax filed Article 33 to the Dutch DPA following the original March 2026 disclosure (BleepingComputer, 2026-05-27; The Record, 2026-05-27; Ajax victim statement, 2026-03-25). The recurring pattern (REST/mobile-app backend with shared-key API access-control) is directly transferable to public-sector citizen portals. →
05CrowdStrike, Google and Shadowserver simultaneously sever all four C2 channels of the GlassWorm developer-targeting botnet (not to be confused with the Nx. CrowdStrike, Google and Shadowserver simultaneously severed all four C2 channels of the GlassWorm developer-targeting botnet. The campaign (active since early 2025, attributed by CrowdStrike to likely Russia-based operators on the basis of CIS-locale exit checks) used Solana blockchain memo fields, BitTorrent DHT, Google Calendar event titles, and traditional VPS C2 in parallel for resilience; takedown required cutting all four at once. Infections persist on developer endpoints and post-compromise credential rotation is required (CrowdStrike, 2026-05-27; TechCrunch, 2026-05-27). →
06ILIAS LMS, nine fixes shipped 2026-05-27, two critical access-control gaps (CVSS 9.8 + 9.3), NCSC.ch flags SOAP interface as primary unauthenticated attack. ILIAS LMS, critical patch cluster: unauthenticated TileImageUploadHandler write (CVSS 9.8) plus SOAP access-bypass and multiple SQL-injection bugs. The open-source LMS dominant in Swiss federal training, Swiss/German universities, and DACH public-sector vocational portals shipped nine fixes on 2026-05-27 across the 9.20 / 10.8 / 11.1 branches; NCSC Switzerland published an advisory the same day flagging the SOAP interface as the primary unauthenticated attack surface (ILIAS Security Blog, 2026-05-27; NCSC-CH, 2026-05-27; BSI CERT-Bund WID-SEC-2026-1689, 2026-05-27). Per-bug CVSS not in NVD yet; vendor and BSI advisories are primary. →
Dutch National Police arrested a 35-year-old man from the municipality of Buren on 2026-05-26 on suspicion of computer trespass (computervredebreuk) against AFC Ajax Amsterdam, following an investigation triggered by Ajax's own disclosure in late March 2026 (BleepingComputer, 2026-05-27; The Record, 2026-05-27; NL Times, 2026-05-26; AFC Ajax victim statement, 2026-03-25). Investigators searched the suspect's residence and seized multiple digital storage devices. Ajax's own statement (issued at the time of the original March 2026 disclosure) attributes the breach to an unauthorised actor who accessed Ajax systems and exfiltrated data; BleepingComputer and The Record, citing the Dutch police release, report the underlying API flaw exposed more than 300,000 fan accounts and 42,000+ season-ticket holders (BleepingComputer, 2026-05-27; The Record, 2026-05-27). RTL reporting cited in BleepingComputer notes the attacker demonstrated the ability to reassign a VIP season ticket in seconds and modify stadium-ban records. Ajax filed an Article 33 GDPR notification to the Dutch Autoriteit Persoonsgegevens (AP) and a criminal complaint; the underlying gap has since been patched.
On 2026-05-26T14:00Z, CrowdStrike Counter Adversary Operations, Google, and the Shadowserver Foundation executed a simultaneous takedown of all four C2 channels operated by GlassWorm, a developer-targeting supply-chain campaign active since at least early 2025 (CrowdStrike Counter Adversary Operations, 2026-05-27; TechCrunch, 2026-05-27; The Hacker News, 2026-05-27). GlassWorm's C2 architecture was designed for resilience: (1) Solana blockchain, C2 server addresses encoded in transaction memo fields as an immutable public dead-drop; (2) BitTorrent DHT, GlasswormRAT queries the peer-to-peer network for configuration data stored against hardcoded public keys; (3) Google Calendar, event titles used as Base64-encoded path dead-drops; (4) traditional VPS-hosted C2 for final payload. Taking down any subset would have left the remainder operational.
The attack surface spanned VS Code Marketplace, Open VSX (reaching Forgejo/Gitea-based forks), npm, PyPI, and direct GitHub repository poisoning via stolen developer credentials, 300+ GitHub repositories poisoned across the campaign. Infected hosts were converted into covert infrastructure: SOCKS proxies, hidden VNC (HVNC) servers, and Node.js-based remote execution nodes via WebRTC. CrowdStrike attributes the operators to likely Russia-based actors on the basis of the malware's CIS-locale / language / timezone exit check.
The ILIAS Security Group released a coordinated nine-issue security update on 2026-05-27 covering the open-source Learning Management System that dominates the CH/DE/AT public-sector e-learning estate: Swiss federal training portals, NATO DEEP ADL, and the majority of Swiss and German university LMS deployments (ILIAS Security Blog, 2026-05-27; NCSC-CH, 2026-05-27; BSI CERT-Bund WID-SEC-2026-1689, 2026-05-27). CVE identifiers were not assigned in the BSI CSAF document; the vendor uses internal MantisBT IDs.
Two issues are rated critical by the vendor. MantisBT 0047787 (CVSS 4.0: 9.8) is a missing access-control check in TileImageUploadHandler; an attacker with network access to the upload endpoint can write arbitrary files, bypassing authentication entirely, the textbook prerequisite for arbitrary file write to RCE on a PHP application. MantisBT 0047691 (CVSS 4.0: 9.3) is a post-auth SQL injection in the MyStaff module. Companion high-severity findings: MantisBT 0047581 (CVSS 8.7), broken access-control in the SOAP interface permitting unauthenticated SOAP calls; MantisBT 0047472 (CVSS 7.1), SQL injection reachable via the SOAP API; MantisBT 0047770 (CVSS 8.5) and 0047778 (CVSS 8.1), sort-field and SCORM2004-module SQLi paths; MantisBT 0047258, unauthorized SOAP function calls.
Why it matters to us: ILIAS is mission-critical for Swiss federal civil-servant training and Swiss/DACH academic certification, a compromise of the LMS exposes course content, learner PII, certification records, and any HR/IDP integration on the SOAP interface. NCSC.ch's recommended interim mitigation is to disable the SOAP interface on any deployment that does not require it for enterprise HR / SIS integration. Patched branches: 9.20, 10.8, 11.1. Detection concepts: monitor web-server access logs for POSTs to TileImageUploadHandler without a valid session cookie; flag any request to /ilias.php?baseClass=ilSOAPExplorer or the SOAP WSDL endpoint from non-internal source IPs. Hardening: AppArmor/SELinux profile constraining php-fpm writeable paths to content directories; reverse-proxy ACL blocking external access to /webservice/soap/ until patched.
The FBI issued CSA 260526 on 2026-05-26 warning that Silent Ransom Group (SRG; tracked variously across cited sources as Luna Moth, Chatty Spider and UNC3753, with the Storm-0252 designation specifically referenced by CyberScoop) (a Russia-linked extortion-only gang that does not deploy ransomware) has escalated its campaign against US law firms by physically sending operatives into victim offices impersonating IT support when remote access attempts fail (CyberScoop, 2026-05-27; The Record, 2026-05-27; Help Net Security, 2026-05-27). The kill chain begins with callback phishing, an email or call pretexting urgent IT support with a callback number; on the call, the actor attempts to establish a remote desktop session. If the target resists, an associate physically visits the office and attempts to insert a USB storage device into a workstation. CyberScoop, citing the FBI, reports the group has claimed more than 100 attacks.
The German federal cabinet approved the Cybersicherheitsstärkungsgesetz (Law to Strengthen Cybersecurity) on 2026-05-27, granting three federal agencies, the Bundeskriminalamt (BKA), the Bundesamt für Sicherheit in der Informationstechnik (BSI) and the Bundespolizei, new authority to conduct what the government frames as active cyber defence rather than offensive hackback (Heise Security, 2026-05-27; onvista / dpa, 2026-05-27; t-online, 2026-05-27). Under the law the agencies may redirect attacker-controlled traffic, selectively intervene in IT systems used to attack Germany, delete or modify data on attacker servers, and shut down dangerous C2 nodes, explicitly including foreign infrastructure. Interior Minister Alexander Dobrindt (CSU) positioned the measure as active cyber defence targeting attacker command-and-control infrastructure rather than retaliatory hackback. The bill funds the order of 350 new positions across the three agencies and approximately €50 million per year in personnel and material (per onvista/dpa; t-online reports a smaller initial figure. The Bundesverband der Deutschen Industrie (BDI) and civil-society voices warned of collateral-damage risk on shared hosting and VPN servers and flagged constitutional concerns. The bill next proceeds to the Bundestag; it does not yet have force of law.
Why it matters to us: German LE gaining the legal authority to sinkhole, redirect, or disable attack infrastructure will change the threat-intel attribution picture across Europe. SOC managers should expect that unexplained C2 outages on Germany-adjacent hosting may be LE action rather than malware infrastructure rotation. Threat-intel teams tracking takedown patterns should add de.bka, de.bsi, de.bpol as expected actors in the takedown attribution stack alongside CrowdStrike Counter Adversary Operations, Microsoft DCU and Europol.
Gambit Security (Israeli threat-intelligence firm) published a technical report on 2026-05-26 attributing the March 2026 breach of Los Angeles County Metropolitan Transportation Authority (LACMTA / LA Metro) to an Iran-MOIS-linked cluster operating under the hacktivist persona Ababil of Minab (Gambit Security, 2026-05-26; TechCrunch, 2026-05-26; The Record, 2026-05-27). The persona surfaced in late March / early April 2026 claiming to be a standalone hacktivist crew; Gambit's forensic evidence ties the cluster's infrastructure and techniques to the MOIS-attributed Black Shadow group, a designation the Israel National Cyber Directorate (INCD) has previously applied. The campaign exfiltrated a large volume of emails, backups and other files from LACMTA, then deliberately targeted the recovery layer: virtual machines and storage volumes were deleted, backup infrastructure was destroyed, and multiple destructive techniques were applied in parallel to force concurrent remediation pathways and maximise downtime. LA Metro required weeks to recover. The campaign also touched named and unnamed organisations in Israel, Saudi Arabia and Turkey.
CERT Polska disclosed three vulnerabilities in Slican PBX firmware on 2026-05-27; Slican is a Polish manufacturer of PBX and IP-telephony equipment with broad deployment in Polish government, public administration and healthcare, and is also sold across Central and Eastern Europe (CERT Polska, 2026-05-27; ENISA EUVD-2026-32276, 2026-05-27). CVE-2026-35087 (CVSS 4.0: 9.3), the administrative protocol accepts a specific command that bypasses credential checks, granting admin shell access. CVE-2026-35089 (CVSS 4.0: 8.7); the secure key protecting the admin service is generated deterministically from system properties obtainable without authentication; an attacker can recompute the key and extract admin credentials. CVE-2026-35090 (CVSS 4.0: 9.3), the remote management modem interface accepts a hardcoded caller-ID that bypasses admin authentication on the PSTN side; if remote access is disabled, the call temporarily re-enables it. All three are exploitable remotely without authentication. Affected/fixed pairs: IPx series (≥ 6.61.0040), CCT-1668 / MAC-6400 (≥ 6.56.0430), CXS-0424 (≥ 6.30.0510), NCP (≥ 1.24.0250). EOL hardware (versions ≤ 4.xx, CCT-1668 CCT1CPU, MAC-6400, CXS-0424 discontinued 2011/2012) will not receive patches; vendor recommends hardware replacement.
The Roundcube Project shipped 1.6.16 (LTS) and 1.7.1 on 2026-05-24 patching a pre-authentication SQL-injection in the virtuser_query plugin: an unauthenticated network attacker can inject arbitrary SQL through the plugin's login-time virtual-user lookup when the plugin is enabled (Roundcube Project, 2026-05-24; NCSC Switzerland, 2026-05-27; Heise Security, 2026-05-27). Companion fixes in the same release: CVE-2026-48844 (HIGH, code injection in the LDAP autovalues option when configured; PHP-eval-class flaw), CVE-2026-48843 (HIGH; CSS-sanitisation bypass in HTML email via SVG animate attributeName="style" that can leak data through SSRF or disclose server-side information), and CVE-2026-48848 (HIGH, HTML-sanitisation bypass permitting CSS injection via a crafted SVG document). Branches 1.5.x and earlier are EOL and do not receive patches. Roundcube is the dominant self-hosted webmail across European public administrations, ISPs and academia, NCSC Switzerland flagged the cluster as requiring prompt action.
Roundcube webmail has a documented history of exploitation against government email systems specifically: the Winter Vivern (TA473) actor's CVE-2023-5631 cross-site-scripting zero-day targeted European government entities, and APT28 separately chained three earlier Roundcube flaws (CVE-2020-35730, CVE-2020-12641, CVE-2021-44026) to breach Ukrainian government email systems (BleepingComputer, 2026-09-24). Roundcube also ships pre-installed with the cPanel hosting-control panel (BleepingComputer, 2026-09-24), widening exposure beyond single-tenant installs to any organization whose mail runs on a cPanel-based hosting provider.
Open-source reporting indicates that CVE-2026-48842 is being exploited in the wild.
Successful exploitation can let threat actors with no privileges bypass authentication, inject and execute malicious database commands, and steal data from Roundcube's database in high-complexity attacks that don't require user interaction.
Canada's Cyber Centre updated its advisory on 2026-09-21 to record that "open-source reporting indicates that CVE-2026-48842 is being exploited in the wild" (Canadian Centre for Cyber Security, 2026-09-21), four months after the May patch. NCSC Switzerland updated its own Cyber Security Hub advisory to match on 2026-09-24, recording "Current exploitation status: Actively exploited" and citing the Canadian update as its source (NCSC Switzerland, 2026-09-24). Threat-monitoring nonprofit Shadowserver tracks more than 523,000 internet-exposed Roundcube instances, with no public breakdown of how many remain unpatched (BleepingComputer, 2026-09-24). Where immediate patching is not possible, disabling or removing the virtuser_query plugin removes the vulnerable code path entirely; the plugin is opt-in and mainly used by hosting/ISP-style deployments rather than single-tenant installs.
Symantec's Threat Hunter Team and Broadcom's Carbon Black published findings on 2026-05-12 documenting a Q1 2026 MuddyWater (a.k.a. Seedworm, Static Kitten, MERCURY, TEMP.Zagros, attributed to Iran's Ministry of Intelligence and Security) espionage campaign across at least nine organisations on four continents. The story re-surfaced this run via fresh aggregator coverage on 2026-05-26 (The Hacker News), included in window on that basis. Named victim categories include industrial and electronics manufacturing, education and public-sector bodies, financial services, and an international airport in the Middle East (Symantec / Broadcom Threat Intelligence, 2026-05-12; The Hacker News, 2026-05-26; Industrial Cyber, 2026-05-13).
The differentiating TTPs from prior MuddyWater coverage are twofold. First, DLL side-loading via two pairs of legitimately signed third-party binaries: Fortemedia audio-driver binary fmapp.exe side-loading a malicious fmapp.dll; SentinelOne's sentinelmemoryscanner.exe side-loading a rogue sentinelagentcore.dll, abuse of a signed security-product binary specifically chosen to bypass signature-based detection. Both malicious DLLs embed ChromElevator, an open-source post-exploitation tool that bypasses Chromium App-Bound Encryption to extract passwords, cookies and payment-card data without triggering AV. Second, orchestration moved to Node.js: node.exe appears as a parent-process ancestor of cmd.exe before any operator commands, i.e. a Node.js script (not a human operator) drives the kill chain. PowerShell scripts pulled from a staging server perform discovery (T1087, T1482), screenshot capture, SAM-hive theft via VSS (T1003.002), and SOCKS5 reverse-proxy tunnelling (T1090.003). A credential harvester calls CredUIPromptForWindowsCredentialsW to display a Windows security dialogue and trick targets into entering credentials. A Kerberos TGT extractor via GSS-API was also observed.
Why it matters to us: signed-binary side-loading abusing a security-product binary is the highest-value evasion class; signature-based controls are bypassed by design. Detection: Sysmon EID 7 image-loads from fmapp.exe or sentinelmemoryscanner.exe outside their expected installation directories; alert on node.exe as a parent of cmd.exe or powershell.exe -enc in non-developer environments; flag CredUIPromptForWindowsCredentialsW calls from non-standard parents. Hardening: AppLocker / WDAC enforcing signed-and-known-path DLL loads; restrict node.exe execution to development OUs.
SANS ISC handler Manuel Humberto Santander Pelaez published a forensic walkthrough on 2026-05-27 reconstructing an Akira ransomware intrusion using only two log sources (SSLVPN syslog and Windows EVTX exports) joined by source IP and normalised time (SANS Internet Storm Center, 2026-05-27). [SINGLE-SOURCE], high-reliability technical primary, but no independent corroboration of the specific kill chain. Initial access (T1078.001 / T1133): non-distributed brute force from a single hosting-provider IP against a single local SSLVPN account that had been deprovisioned in Active Directory but remained provisioned as a local firewall user with no MFA. Discovery: EID 4688 captures nltest.exe /dclist:, net.exe group "Domain Admins" /domain, net.exe group "Enterprise Admins" /domain, whoami.exe /all, and a renamed AdFind.exe variant, all parented explorer.exe → cmd.exe. Credential access (T1558.003 Kerberoasting): a cluster of EID 4769 RC4-encrypted TGS requests for multiple SPNs from a single workstation within a 90-second window. Lateral movement (T1021.001): EID 4624 Logon Type 10 chain from jump host to file server, domain controllers, backup server; EID 4672 special-logon privileges on DC. Defense evasion + impact: EID 1102 security-log clear; sc.exe / net stop of endpoint-protection services (System EID 7036); vssadmin delete shadows /all /quiet.
Why it matters to us: the diary is a forensic-primer for any SOC operating without full EDR coverage, the standard scenario in smaller public-sector entities and DACH commune networks. Concrete takeaways the SANS ISC author makes directly: reconcile local SSLVPN account directories against AD source-of-truth (deprovisioned-in-AD-but-retained-in-firewall is the recurring initial-access pathway in this class); alert on > 50 failed SSLVPN auths from a single source per hour; enable EID 4688 process auditing on every Windows host, set Security log size ≥ 1 GB; alert on RC4 TGS-REP (EID 4769 EncryptionType=0x17) for multiple SPNs from one workstation in a short window; EID 1102 security-log clear is incident-grade in every case; time-sync every host including the firewall to the same NTP source so perimeter-to-endpoint joins remain reliable.
Microsoft Defender Experts documented an active cryptojacking campaign dating from March 2026 that uses GPU-utility brand impersonation (CrystalDiskInfo, HWMonitor, Display Driver Uninstaller, FurMark, K-Lite Codec Pack, PDFgear) as initial delivery via SEO poisoning (Microsoft Security Blog, 2026-05-26; The Hacker News, 2026-05-27). The operationally novel evolution is from April 2026: users querying AI chatbots for software-download recommendations were directed to attacker-controlled domains in generated responses, search-poisoning extended into the LLM-generation layer. Delivery chain: (1) fake utility site hosts a ZIP on a gleeze.com subdomain (DDNS via Dynu); (2) ZIP contains the legitimate executable alongside an autorun.dll; (3) DLL side-loading installs vcredist_x64.dll via msiexec.exe, a ScreenConnect packaged installer named to mimic Visual C++ Redistributable; (4) ScreenConnect establishes persistent remote access; (5) the session delivers SimpleRunPE.exe; (6) SimpleRunPE persists via Registry Run keys and scheduled tasks, configures Microsoft Defender exclusions, and uses process hollowing to inject miner code (gminer, lolMiner, SRBMiner-MULTI) into a Microsoft-signed binary. 150+ malicious domains identified since March 2026.
The TanStack → Nx Console pivot: CVE-2026-45321 and CVE-2026-48027.
The chain begins on 2026-05-11 with GHSA-g7cv-rxg3-hmpx (CVE-2026-45321): 84 malicious versions across 42 @tanstack/* npm packages were published with a credential-stealing payload (Nx postmortem, 2026-05-21). On a Nx contributor's machine the payload read locally stored credentials and exfiltrated them, including the contributor's GitHub CLI OAuth token. The Nx postmortem names @tanstack/zod-adapter@1.166.15 as the malicious dependency resolved on that machine (Nx postmortem, 2026-05-21). Seven days later, the attacker published Nx Console v18.95.0 as a legitimate Nx core contributor (Nx postmortem, 2026-05-21), tracked as CVE-2026-48027 (CISA KEV catalog, 2026-05-27). The malicious version was live on the Visual Studio Marketplace from 12:30 to 12:48 UTC on 2026-05-18 and on Open VSX from 12:33 to 13:09 UTC (GHSA-c9j4-9m59-847w, 2026-05-18). Nx Console is a VS Code extension with 2.2 million installs (Help Net Security, 2026-05-21). The payload ran on extension activation in VS Code or a fork such as Cursor and harvested Vault tokens, npm tokens, AWS metadata-service, Secrets Manager, SSM and Web Identity credentials, GitHub tokens, the contents of an active 1Password op CLI session, SSH private keys, .env files and GCP and Docker credentials (Nx postmortem, 2026-05-21). The advisory describes it as an obfuscated payload that the extension fetched, and says the harvested data was exfiltrated over HTTPS, the GitHub API and DNS (GHSA-c9j4-9m59-847w, 2026-05-18).
The advisory says the leaked credentials "allowed the attacker to run workflows on our GitHub repository as a contributor" (GHSA-c9j4-9m59-847w, 2026-05-18). The postmortem names the gap that let this become a release: until the incident any core contributor could publish a new Nx Console version without a second human's approval, with no required-reviewer rule and no environment gate (Nx postmortem, 2026-05-21). A stolen developer credential therefore turned into a downstream publish without secondary review.
CVE-2026-8398: DAEMON Tools Lite signed-build trojanisation.
CVE-2026-8398 covers a separate but parallel compromise of Disc Soft Limited's build environment. DAEMON Tools Lite versions 12.5.0.2421 through 12.5.0.2434, circulating since 2026-04-08, contained trojanised DTHelper.exe, DiscSoftBusServiceLite.exe, and DTShellHlp.exe binaries signed with a valid AVB Disc Soft digital signature, which contact a command-and-control server at every system start (Kaspersky, 2026-05-05). Disc Soft says it found "unauthorized interference within our infrastructure" and that certain installation packages "were impacted within our build environment and were released in a compromised state". It released the clean version 12.6 on 2026-05-05 (Disc Soft Limited, 2026-05-06). Kaspersky detected several thousand attempts to install additional payloads through infected installations during the roughly four-week distribution window (Kaspersky, 2026-05-05). Safe version: 12.6 or later. CISA added the CVE to KEV on 2026-05-27 (CISA KEV catalog, 2026-05-27).
Downstream impact: what GitHub and Grafana Labs publicly confirmed.
GitHub CISO Alexis Wales named the malicious Nx Console v18.95.0 extension, installed by a GitHub employee, as the vector for GitHub's breach in which about 3,800 private repositories were exfiltrated (Help Net Security, 2026-05-21). Grafana Labs' CISO Joe McManus traced Grafana's separate GitHub breach to "a TanStack npm supply chain attack via the Mini Shai-Hulud campaign", not to Nx Console, so both breaches trace back to the TanStack compromise by different routes (Help Net Security, 2026-05-21). The malicious version was live for less than an hour (about 18 minutes on the Visual Studio Marketplace and 36 on Open VSX) (GHSA-c9j4-9m59-847w, 2026-05-18); the postmortem's summary gives about 11 minutes for the Marketplace, counted from the maintainers' first alert (Nx postmortem, 2026-05-21), and one install by a GitHub employee was enough for the attackers to reach GitHub's private repositories (Help Net Security, 2026-05-21).
Detection and hardening: what to push to operators today.
Hardening: enforce an organisational policy controls list for VS Code / Cursor / Windsurf extensions (the malicious upload passed the Visual Studio Marketplace's automated signing, manifest and malware checks (Nx postmortem, 2026-05-21)); pin npm dependencies with lockfile + --ignore-scripts for CI/CD builds; require human approval for any package that adds or modifies postinstall / preinstall / install scripts; rotate every CI/CD secret, npm token, GitHub PAT, and AWS access key accessible from any host that ran an affected Nx Console version between 2026-05-18 12:30 and 13:09 UTC. Treat any host that installed Nx Console 18.95.0, or had Nx Console installed with auto-update enabled in VS Code or a fork such as Cursor during that window, as potentially compromised (Nx postmortem, 2026-05-21).
TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.
CISA's Known Exploited Vulnerabilities catalog marks both CVE-2026-48027 (Nx Console) and CVE-2026-45321 (TanStack) as used in known ransomware campaigns (CISA KEV catalog, 2026-05-27). The attackers who stole Grafana Labs' codebase through the TanStack compromise demanded payment not to release or sell it, and Grafana did not pay (Help Net Security, 2026-05-21). Credentials exposed through either compromise are best handled on the assumption that an extortion group holds them.
The Nx postmortem does not describe token scopes, a tag push or hosted-runner publish secrets. It says any core contributor could publish without a second approval (Nx postmortem, 2026-05-21). The harvested credentials are Vault, npm, AWS service, GitHub, 1Password op session, SSH, .env, GCP and Docker secrets (Nx postmortem, 2026-05-21). GitHub named Nx Console only for its own breach, while Grafana Labs traced its breach to the TanStack npm attack (Help Net Security, 2026-05-21). The DAEMON Tools trojanised builds circulated for about four weeks, from 2026-04-08 until the clean 12.6 release on 2026-05-05 (Kaspersky, 2026-05-05; Disc Soft Limited, 2026-05-06).
Roundcube (upgrade to 1.6.16 LTS or 1.7.1 now; CVE-2026-48842 is confirmed under active exploitation. Where immediate patching is not possible, disable or remove the virtuser_query plugin entirely) it is opt-in and mainly used by hosting/ISP-style deployments. Reference: Canadian Centre for Cyber Security, 2026-09-21.
2026-05-28-3e33200a· Claude Opus 4.7 · window 40 h · 12 entries published
Items dropped; vulnerabilities that did not clear § 2 inclusion gates.
CVE-2026-9256 / CVE-2026-42945, NGINX double rewrite-module heap buffer overflow. S1 surfaced these as actively-exploited per NCSC-NL CSAF (NGINX meldt bekend te zijn met (pogingen tot) misbruik), but the freshest sources are dated 2026-05-22 (NGINX vendor advisory and oss-security mailing list) and 2026-05-18 (NCSC-NL), both outside the 40-h recency window with no in-window corroborator surfaced. Dropped to § 7 rather than included as a stale exploitation note. Patch is still relevant (1.31.1+ or 1.30.2+) defenders running unpatched NGINX should not wait for a future brief to act.
CVE-2026-45659, Microsoft SharePoint Server CWE-502 deserialization RCE (CVSS 8.8). S1 + S2 both surfaced; NCSC.ch flagged on 2026-05-26 in CSH 12594 (Microsoft MSRC; NCSC-CH post 12594; Help Net Security, 2026-05-26). Did not clear § 2 inclusion gates: post-auth (Site Member, PR:L), no CISA KEV, no ENISA EUVD exploited=true, no in-the-wild exploitation confirmed, CVSS 8.8 below the 9.0 EUVD-critical floor, and no public PoC reported. Defenders running on-prem SharePoint should still apply the May 2026 CU (SE 16.0.19725.20280 / SP2019 16.0.10417.20128 / SP2016 16.0.5552.1002), the prior history of rapid weaponisation of SharePoint deserialization gadget chains supports priority patching even without current exploitation evidence.
CVE-2026-27771, Gitea container-registry access-control failure (~30,000+ deployments). S1 + S3 both surfaced (NoScope, 2026-05-25; The Hacker News, 2026-05-27). Patched in Gitea v1.26.2 (released 2026-05-20). Did not clear § 2 gates, unauthenticated image-pull (data-exposure), not RCE; no KEV / EUVD-critical / confirmed in-the-wild exploitation. Forgejo (the fork used by Codeberg and many EU academic instances) confirmed affected. The four-year window of exposure means retrospective log review for unauthenticated /v2/<namespace>/<repo>/{manifests,blobs} GETs is warranted on any self-hosted Gitea / Forgejo instance running below 1.26.2; rotate any secrets embedded in container images that were stored as private.
Grandoreiro + BTMOB Android RAT (WatchGuard / ESET, 2026-05-26). Surfaced by S3. Banking-only sector (Portugal / Spain / Brazil / Europe consumer-banking customers); did not clear the daily-relevance bar for a Swiss/EU public-sector SOC audience. Mentioned here so the next run does not re-surface it as new.
Catalin Dragomir / Oregon OEM sentencing (TheRecord, 2026-05-27). Surfaced by S4. 2021 access-broker sentencing is procedurally significant but the underlying breach is years old and the operational signal (emergency-management network as access-broker target class) is generic; below the daily inclusion bar. Logged here for next-run dedup.
[SINGLE-SOURCE] items. § 3 SANS Internet Storm Center Akira kill-chain reconstruction, single primary publisher, but a high-reliability technical forensic primer; included per PD-5 carve-out (HIGH-reliability primary research source). No defender action flows from the item that needs a second confirmation.
Reduced confidence, only aggregator sources. § 1 FBI FLASH CSA 260526 (Silent Ransom Group physical-USB tactic), the FBI IC3 primary PDF (https://www.ic3.gov/CSA/2026/260526.pdf) returned HTTP 403 to the routine UA and to the bridge fetcher; the three cited sources (CyberScoop, The Record, Help Net Security) are all news aggregators paraphrasing the same FBI advisory. The advisory itself is the substantive primary; operators should fetch the IC3 PDF directly from a desktop browser session to confirm the verbatim text before acting.
MuddyWater / Symantec primary-source date resolution. S1 reported the Symantec primary as 2026-05-22; S3 reported it as 2026-05-26. Phase 5.7 iteration 1 independently extracted the actual Symantec publication date as 2026-05-12 (and Industrial Cyber as 2026-05-13). § 3 has been re-dated to those values; The Hacker News (2026-05-26) is the in-window publication that pulled the story back to surface and is the reason the item appears in this brief at all. Under PD-7's "freshest source in window" reading the item remains in scope; readers should note the underlying Symantec research is two weeks old.
Contradictions across linked sources. Germany Cybersicherheitsstärkungsgesetz staffing figure, onvista (dpa) reports "more than 350 new positions" across BKA / BSI / Bundespolizei plus ~€50 million per year; t-online reports a notably smaller initial figure (37 additional employees). The brief carries the dpa-sourced ~350 framing because the onvista/dpa wire is more likely to reflect the cabinet's published bill text; the t-online figure may refer to one specific agency or a phased intake. Operators tracking the bill's progression should follow the Bundestag-stage publication for the authoritative position count.
Stalled or non-returning sub-agents. None, all four cti-research sub-agents returned within the 30-min hard cap (S1: 527 s; S2: 496 s; S3: 542 s; S4: 560 s).
Verification loop. Phase 5.7 ran four iterations (Opus → Sonnet → Opus → Sonnet, per the v2.47 model-rotation contract). Iteration 4 returned NEEDS_FIXES with one F3 (citation-does-not-support-claim) finding, the AFC Ajax TL;DR bullet retained the iter-3-flagged "granted himself access" framing after the § 1 body had been re-paraphrased. That TL;DR-vs-body inconsistency was remediated post-iter-4 (TL;DR rewritten to match the § 1 body's neutral phrasing). Per v2.50 early-exit (truth + editorial ≤ 2 AND no F1/F4), the brief publishes with verification_residual_count = 1 (the iter-4 F3 finding, since fixed in place, same disposition as a cap-breach reached at iter 4 rather than at iter 5). Two F11 advisories (Slican "hardcoded" / "widely deployed in Polish public sector" framing exceeds CERT-PL's direct language; ILIAS vendor blog list-page render date 2026-05-26 vs NCSC-CH 12599 publish stamp 2026-05-27) were deferred as defensible and non-load-bearing.
Coverage gaps:databreaches-net (HTTP 403, sixth consecutive run, covered via BleepingComputer / TheRecord / SecurityWeek; not a real gap this run); inside-it-ch (HTTP 403, fifth consecutive run, no exclusive in-window CH-tech story surfaced via alternates); sophos-xops (HTTP 503, fifth consecutive run, no Sophos research story surfaced elsewhere in window); anssi-fr (avis-recent newest item 2026-05-20, outside window; actu-recent stale at October 2025); ncsc-uk (RSS items 2022–2025 only, no in-window content); cisa-news (no fresh in-window emergency directive); apple-security, oracle-cpu, chrome-releases (no in-window vendor publication); dfirreport, sekoia (RSS empty for window).
New candidate source surfaced, gambit-security. Israeli threat-intelligence firm with primary MOIS / Iran-linked research; the Ababil-of-Minab attribution report (2026-05-26) on the LACMTA breach is the discovery event. Surfaced by S4. Added to sources/sources.json as status: "candidate" per the one-candidate-per-run rule; promote after 3 successful contributing fetches.
NoScope, the discoverer of CVE-2026-27771 (Gitea private container exposure), also surfaced as a candidate source by S3 but is deferred per the one-candidate-per-run rule. Carried as a coverage-gap note for next-run consideration.
Hardcoded sinkhole IP avoided. CrowdStrike's post-takedown GlassWorm sinkhole at 164.92.88[.]210 is the operationally useful artefact for retrospective detection, but the brief avoids IPs per PD-3 (no IOCs). Operators acting on the GlassWorm § 1 item should obtain the sinkhole address directly from the CrowdStrike post and apply it in their network telemetry.
Unmatched action items (migrated)
Inventory and patch ILIAS deployments to 9.20 / 10.8 / 11.1 today. Two critical access-control bugs (TileImageUploadHandler unauth file-write CVSS 9.8; MyStaff post-auth SQLi CVSS 9.3) plus seven further high-severity issues, see § 1. Interim mitigation per NCSC.ch: disable the SOAP interface (/webservice/soap/) on any deployment that does not require it for enterprise HR / SIS integration. Reference: ILIAS Security Blog, NCSC-CH 12599.
Inventory VS Code / Cursor / Windsurf extensions across the developer estate against an approved-extensions allowlist; pin Nx Console to ≥ 18.100.0 and rotate every CI/CD secret accessible from a host that ran Nx Console v18.95.0 between 2026-05-18 12:30 and 13:09 UTC. See § 5 for the full chain, TanStack → Nx Console → GitHub / Grafana. CISA KEV adds 2026-05-27 confirm active in-the-wild exploitation. Reference: Nx postmortem.
DAEMON Tools Lite (replace versions 12.5.0.2421–12.5.0.2434 with ≥ 12.6.0 on every host they were installed on. Trojanised builds signed by the legitimate vendor certificate during the 2026-04-08 → 2026-05-05 window) see § 5. Reference: Disc Soft Limited security notice.
Hunt for GlassWorm-class developer infections in the network, focus on the dev estate. Even after the C2 takedown the endpoints remain infected; rotate every credential and CI/CD secret accessible from a developer host that installed extensions from VS Code Marketplace or Open VSX between early 2025 and 2026-05-26. Detection concepts in § 1. Reference: CrowdStrike.
Reconcile local SSLVPN account directories against AD source-of-truth; enforce MFA on every SSLVPN account regardless of directory. SANS ISC's Akira walkthrough (see § 3) confirms deprovisioned-in-AD-but-retained-in-firewall accounts as the primary initial-access pathway for this class. Alert on >50 failed SSLVPN authentications from a single source per hour; set Windows Security log size ≥ 1 GB on every host so EID 4688 discovery-phase evidence does not roll off before incident response arrives.
Defenders running large hypervisor estates, separate the recovery plane from the production identity boundary. The MOIS / Ababil-of-Minab LACMTA pattern (see § 1) explicitly targets backup and VM-lifecycle APIs for destruction in parallel with exfiltration. Treat backup-orchestration admin access as a separate identity boundary with MFA on backup-job execution and a tested air-gapped restore path that does not depend on the same identity provider as production.