Cyber Threat Brief
SHOW NOTES - 2026-05-25 STORIES COVERED * Today: * Ghost CMS SQL Injection (CVE-2026-26980) [https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/] [Critical Alerts] * KnowledgeDeliver LMS ViewState Deserialization (CVE-2026-5426) [https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability/] [Critical Alerts] * TrapDoor Supply Chain Attack (npm, PyPI, Crates.io) [https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html] [Business & Infrastructure Threats] * Megalodon GitHub Actions Attack (5,500+ Repositories) [https://www.securityweek.com/over-5500-github-repositories-infected-in-megalodon-supply-chain-attack/] [Business & Infrastructure Threats] * DocketWise Data Breach (143,000 Affected) [https://www.securityweek.com/docketwise-data-breach-impacts-143000/] [Business & Infrastructure Threats] * Chinese-Language Phishing-as-a-Service Ecosystem [https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services/] [General Security News] * Anthropic Mythos Finds 23,000 Vulnerabilities [https://news.risky.biz/risky-bulletin-mythos-found-thousands-of-critical-bugs/] [General Security News] * Linus Torvalds Cracks Down on AI-Generated Pull Requests [https://www.theregister.com/oses/2026/05/25/linus-torvalds-to-start-being-more-hardnosed-about-pointless-pull-requests-some-of-which-come-from-ais/5245549] [General Security News] * Wireshark 4.6.6 [https://isc.sans.edu/diary/rss/33010] [Vulnerability Disclosures] * CVE-2026-43029 (mptcp soft lockup) [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43029] [Vulnerability Disclosures] * CVE-2026-43414 (qla2xxx fcport double free) [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43414] [Vulnerability Disclosures] CVES REFERENCED CVE-2026-26980, CVE-2026-43029, CVE-2026-43414, CVE-2026-5426 Read the full brief [https://carolinacleartech.com/brief/2026-05-25/]
90 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Cyber Threat Brief!