Security News

Cybersecurity news aggregator

📰
INFO News

Security Morning Briefing - May 29, 2026

  • ## Þjónustu samantekt Þjónustuþróun er stjórnað af **breiddar, í virkri nýtingu veikleikum** á kerfisþjónustu, einnig á netþjónum, endapunktaöryggis og vefþjónum. Þarf er að gera uppfærslur á **Cisco SD-WAN**, **Fortinet FortiClientEMS** og **Citrix NetScaler**, sem eru undir virkri nýtingu með CISA ábyrgðarstöðum. Ný rúm á **Linux kérnunni réttindaaukning** og **AI-veittu nýtingu** sýnir aukningu í hæfileikum á hættaþátttakendur, en mikil innbrot með **aðfangakeðjuháttum (GitHub)** og **veiðarþjónustu (Tycoon2FA)** sýna aðgerðir áfram á vefþjónustu og auðkenningu. ## ⚠️ Þarf að gera áætlaða aðgerðir
  • *🏢 Cisco Catalyst SD-WAN Manager auðkenningarframhjáhlaup** Veikleiki (CVE-2026-20127) leyfir óauðkenndum hættaþátttakendum að fá kerfisstjóra aðgang. Þessi veikleiki er í virkri nýtingu og hefur verið bætt við CISA's Known Exploited Vulnerabilities skrá.
  • *CVE:** CVE-2026-20127 (CVSS: 10.0)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Fjölmargar útgáfur af Cisco Catalyst SD-WAN Manager
  • *Lagfært í:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [SC Media: 10.0 Cisco Catalyst SD-WAN Controller bug added to CISA’s KEV list](https://www.scworld.com/news/10-0-cisco-catalyst-sd-wan-controller-bug-added-to-cisas-kev-list)
  • *🏢 Fortinet FortiClientEMS SQL-innsetning og aðgangsstjórnunarveikleikar** Veikleikar (CVE-2026-21643, CVE-2026-35616) eru í nýtingu til að setja inn upplýsingarhátt. Óauðkenndir hættaþátttakendur geta keyrt óskilgreindan kóða og framhjálpað aðgangsstjórnun.
  • *CVE:** CVE-2026-21643 & CVE-2026-35616 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Útgáfur 7.4.0 til 7.4.6
  • *Lagfært í:** Uppfærslur og hitfæristar eru tiltækar
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [BleepingComputer: Hackers exploit FortiClient EMS flaw to push infostealer malware](https://www.bleepingcomputer.com/news/security/hackers-exploit-forticlient-ems-flaw-to-push-infostealer-malware/)
  • *Citrix NetScaler SAML minnisskrun veikleiki** Veikleiki (CVE-2026-3055) í NetScaler ADC/Gateway sem er stillt sem SAML IdP leyfir óauðkenndum hættaþátttakendum að leita út á vandlega minni. Þessi veikleiki er í virkri nýtingu.
  • *CVE:** CVE-2026-3055 (CVSS: 9.3)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Fjölmargar fyrri útgáfur
  • *Lagfært í:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [FortiGuard Outbreak Alerts: Citrix NetScaler Memory Overread Vulnerability](https://fortiguard.fortinet.com/outbreak-alert/citrix-netscaler-memory-overread)
  • *cPanel & WHM auðkenningarframhjáhlaup** Veikleiki (CVE-2026-41940) leyfir óauðkenndum hættaþátttakendum að fá kerfisstjóra aðgang á vefþjón, sem leiðir til gíslatökuhugbúnaðar og kerfisstjóra. Yfir 40.000 vefþjón eru áhrifðir.
  • *CVE:** CVE-2026-41940 (CVSS: 9.8)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** cPanel 11.40 til 130.0.19
  • *Lagfært í:** Uppfærslur eru í sérstökum útgáfum
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [FortiGuard Threat Signal: cPanel & WHM Authentication Bypass](https://fortiguard.fortinet.com/threat-signal-report/6447)
  • *Linux kérna 'Dirty Frag' réttindaaukning** Veikleiki í Linux kérnunni leyfir óþjálfuðum notendum að fá kerfisstjóra aðgang með því að nýta minnisskruna. Þetta áhrifir kérnueftir 4.11 til 6.7 og er í virkri nýtingu.
  • *CVE:** CVE-2026-43284 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Linux kérna útgáfur 4.11 til 6.7
  • *Lagfært í:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [SC Media: New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available](https://www.scworld.com/news/new-linux-privilege-escalation-flaw-fragnesia-disclosed-poc-available) ## 🔍 Þjónustu aðgerð
  • *GitHub aðfangakeðjuinnbrot með óþjálfuðum VS Code útkeyrslu:** Þjónustuþátttakandi TeamPCP innbrot í GitHub's innri kerfisþjóni með óþjálfuðum Visual Studio Code útkeyrslu, sem áhrifir 3.800 kerfisþjón. Aðgerðin varðar auðkenningarhátt og gagnaflyttingu. GitHub varða innbrotin með að skilja áhrifstæðuna og fjarlægja útkeyrsluna. Heimild: [The Hacker News: GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension](https://thehackernews.com/2026/05/github-internal-repositories-breached.html)
  • *Tycoon2FA veiðarþjónustu halda áfram eftir aðgerð:** Þó að heimsdæmum hafi verið gert, hefur Tycoon2FA, sem framhjálpar MFA með aðgerðum á milli hættaþátttakenda, snúið aftur að virkni. Heimild: [CrowdStrike: Tycoon2FA persists post-takedown](https://www.crowdstrike.com/?p=289702)
  • *AI-veittu núll-daga veikleiki framhjálpar 2FA:** Google fann fyrstu tilfelli af AI-veittu núll-daga veikleika, Python skrift sem áhrifir vinsæla opinni vefþjónustu til að framhjálpa 2FA. Þetta var fundið áður en massa nýtingu. Heimild: [Infosecurity Magazine: Hackers Observed Using AI to Develop Zero-Day for the First Time](https://www.infosecurity-magazine.com/news/hackers-using-ai-zero-day-first/)
  • *Cryptojacking aðgerð notar AI chatbot og SEO skemmd:** Aðgerð notar AI chatbot rekomendatión og SEO skemmd til að skipta notendum á óþjálfuða vef sem áhrifir kerfisþjón, sem leiðir til fjarkeyrslu með ScreenConnect og .NET fyrir GPU cryptojacking. Heimild: [The Hacker News: AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites](https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html) ## 📋 Uppfærslur og uppfærslur
  • *🏢 Microsoft SharePoint:** Fjölmargir kritískir RCE og farsæðisveikleikar (CVE-2026-20963, CVE-2026-32201) eru í virkri nýtingu. Uppfærslur voru útgefnar í ágúst 2026 fyrir SharePoint Server 2016, 2019 og önnur útgáfur. Heimild: [Microsoft Security Response Center: CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659)
  • *Microsoft Defender:** Tveir í virkri nýtingu veikleikar (CVE-2026-41091, CVE-2026-45498) sem leyfa réttindaaukning og þjónustuneitun eru lagaðir í Microsoft Defender Antimalware Platform útgáfu 4.18.2604+. Heimild: [Microsoft Security Response Center: CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498)
  • *Trend Micro Apex One:** Fjölmargir kritískir RCE og réttindaaukning veikleikar (CVE-2026-34926, CVSS 9.4) eru í nýtingu og eru lagaðir fyrir Windows og macOS útgáfur. Heimild: [Help Net Security: Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926)](https://www.helpnetsecurity.com/?p=371992)
  • *Drupal:** Kritísk SQL-innsetning veikleiki (CVE-2026-9082) sem leyfir RCE er í virkri nýtingu. Uppfærslur eru tiltækar fyrir Drupal 10.x og 11.x fyrir sérstök uppfærslur. CISA hefur beðið um uppfærslur fyrir stjórnarskála. Heimild: [BleepingComputer: CISA orders feds to patch actively exploited Drupal vulnerability](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-drupal-vulnerability/) ## Þessar dagar árangur 1. **Nýtingaruppfærslur:** Þarf að gera uppfærslur á **Cisco SD-WAN Manager**, **Fortinet FortiClientEMS** og **Citrix NetScaler** útgáfum, sem eru undir virkri nýtingu með kritískum auðkenningarframhjáhlaup og kóðanýtingu. 2. **Linux kérna skoðun:** Skoða og velja uppfærslur fyrir Linux kerfisþjón sem keyra kérnur 4.11 til 6.7 gegn 'Dirty Frag' réttindaaukning, með fyrirsögn á netþjónum og fleiri notendum kerfum. 3. **Vefþjón skoðun:** Skoða og uppfæra **cPanel/WHM**, **Drupal** og **Ghost CMS** útgáfur, sem eru í nýtingu fyrir kerfisstjóra og gíslatökuhugbúnað. 4. **Aðfangakeðju aðgengi:** Skoða útgáfu aðgangsþjónustu og skoða óþjálfuðar VS Code útkeyrslur eftir GitHub innbrotin, og styrkja upplýsingar um SEO skemmd og AI chatbot áhugamál. ## 🔗 Heimildir - [SC Media: 10.0 Cisco Catalyst SD-WAN Controller bug added to CISA’s KEV list](https://www.scworld.com/news/10-0-cisco-catalyst-sd-wan-controller-bug-added-to-cisas-kev-list) - [BleepingComputer: Hackers exploit FortiClient EMS flaw to push infostealer malware](https://www.bleepingcomputer.com/news/security/hackers-exploit-forticlient-ems-flaw-to-push-infostealer-malware/) - [FortiGuard Outbreak Alerts: Citrix NetScaler Memory Overread Vulnerability](https://fortiguard.fortinet.com/outbreak-alert/citrix-netscaler-memory-overread) - [The Hacker News: GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension](https://thehackernews.com/2026/05/github-internal-repositories-breached.html) - [Infosecurity Magazine: Hackers Observed Using AI to Develop Zero-Day for the First Time](https://www.infosecurity-magazine.com/news/hackers-using-ai-zero-day-first/)
Read Full Article →

## Executive Summary The threat landscape is dominated by **widespread, active exploitation of critical vulnerabilities** across core enterprise infrastructure, including network appliances, endpoint security, and web platforms. Urgent patching is required for **Cisco SD-WAN**, **Fortinet FortiClientEMS**, and **Citrix NetScaler**, all of which are under active attack with CISA-mandated deadlines. A new wave of **Linux kernel privilege escalation** and **AI-assisted exploitation** marks a significant escalation in attacker capabilities, while major breaches via **supply chain attacks (GitHub)** and **phishing-as-a-service (Tycoon2FA)** underscore persistent risks to software development and identity security.

## ⚠️ Immediate Action Required * **🏢 Cisco Catalyst SD-WAN Manager Authentication Bypass** A critical vulnerability (CVE-2026-20127) allows unauthenticated attackers to gain administrative access. This flaw is actively exploited and has been added to CISA's Known Exploited Vulnerabilities catalog. * **CVE:** CVE-2026-20127 (CVSS: 10.0) * **Status:** Active exploitation detected * **Vulnerable:** Multiple versions of Cisco Catalyst SD-WAN Manager * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [SC Media: 10.0 Cisco Catalyst SD-WAN Controller bug added to CISA’s KEV list](https://www.scworld.com/news/10-0-cisco-catalyst-sd-wan-controller-bug-added-to-cisas-kev-list)

* **🏢 Fortinet FortiClientEMS SQL Injection & Access Control Flaws** Critical vulnerabilities (CVE-2026-21643, CVE-2026-35616) are being exploited to deploy infostealer malware. Unauthenticated attackers can execute arbitrary code and bypass security controls. * **CVE:** CVE-2026-21643 & CVE-2026-35616 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Versions 7.4.0 through 7.4.6 * **Fixed:** Patches and hotfixes are available * **Workaround:** None mentioned in source * **Reference:** [BleepingComputer: Hackers exploit FortiClient EMS flaw to push infostealer malware](https://www.bleepingcomputer.com/news/security/hackers-exploit-forticlient-ems-flaw-to-push-infostealer-malware/)

* **Citrix NetScaler SAML Memory Overread Vulnerability** A critical out-of-bounds read flaw (CVE-2026-3055) in NetScaler ADC/Gateway configured as a SAML IdP allows unauthenticated attackers to leak sensitive memory data. It is being actively exploited. * **CVE:** CVE-2026-3055 (CVSS: 9.3) * **Status:** Active exploitation detected * **Vulnerable:** Multiple prior releases * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [FortiGuard Outbreak Alerts: Citrix NetScaler Memory Overread Vulnerability](https://fortiguard.fortinet.com/outbreak-alert/citrix-netscaler-memory-overread)

* **cPanel & WHM Authentication Bypass** A critical flaw (CVE-2026-41940) allows unauthenticated attackers to gain administrative control of web hosting servers, leading to ransomware deployment and server takeover. Over 40,000 servers have been compromised. * **CVE:** CVE-2026-41940 (CVSS: 9.8) * **Status:** Active exploitation detected * **Vulnerable:** cPanel 11.40 through 130.0.19 * **Fixed:** Patches are available in specific builds * **Workaround:** None mentioned in source * **Reference:** [FortiGuard Threat Signal: cPanel & WHM Authentication Bypass](https://fortiguard.fortinet.com/threat-signal-report/6447)

* **Linux Kernel 'Dirty Frag' Local Privilege Escalation** A critical flaw in the Linux kernel allows unprivileged users to gain root access by exploiting page-cache write flaws. It affects kernel versions 4.11 to 6.7 and is actively exploited. * **CVE:** CVE-2026-43284 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Linux kernel versions 4.11 to 6.7 * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [SC Media: New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available](https://www.scworld.com/news/new-linux-privilege-escalation-flaw-fragnesia-disclosed-poc-available)

## 🔍 Threat Activity * **GitHub Supply Chain Breach via Malicious VS Code Extension:** Threat actor TeamPCP breached GitHub's internal repositories using a malicious Visual Studio Code extension, compromising 3,800 repos. The attack involved credential theft and data exfiltration. GitHub contained the breach by isolating the affected endpoint and removing the extension. Reference: [The Hacker News: GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension](https://thehackernews.com/2026/05/github-internal-repositories-breached.html) * **Tycoon2FA Phishing-as-a-Service Persists Post-Takedown:** Despite a global law enforcement takedown, the Tycoon2FA platform, which bypasses MFA using adversary-in-the-middle techniques targeting Microsoft 365 and Gmail, has quickly resumed operations. Reference: [CrowdStrike: Tycoon2FA persists post-takedown](https://www.crowdstrike.com/?p=289702) * **AI-Generated Zero-Day Bypasses 2FA:** Google identified the first known instance of an AI-developed zero-day exploit, a Python script targeting a popular open-source web administration tool to bypass two-factor authentication. It was discovered before mass exploitation. Reference: [Infosecurity Magazine: Hackers Observed Using AI to Develop Zero-Day for the First Time](https://www.infosecurity-magazine.com/news/hackers-using-ai-zero-day-first/) * **Cryptojacking Campaign Uses AI Chatbots & SEO Poisoning:** A campaign uses AI chatbot recommendations and SEO poisoning to redirect users to malicious sites impersonating system utilities, leading to remote access via ScreenConnect and .NET for GPU cryptojacking. Reference: [The Hacker News: AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites](https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html)

## 📋 Patches & Updates * **🏢 Microsoft SharePoint:** Multiple critical RCE and spoofing vulnerabilities (CVE-2026-20963, CVE-2026-32201) are under active exploitation. Patches were released in April 2026 for SharePoint Server 2016, 2019, and other versions. Reference: [Microsoft Security Response Center: CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659) * **Microsoft Defender:** Two actively exploited vulnerabilities (CVE-2026-41091, CVE-2026-45498) allowing privilege escalation and DoS have been patched in Microsoft Defender Antimalware Platform version 4.18.2604+. Reference: [Microsoft Security Response Center: CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45498) * **Trend Micro Apex One:** Multiple critical RCE and privilege escalation flaws (CVE-2026-34926, CVSS 9.4) exploited in the wild have been patched for Windows and macOS versions. Reference: [Help Net Security: Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926)](https://www.helpnetsecurity.com/?p=371992) * **Drupal:** A critical SQL injection vulnerability (CVE-2026-9082) leading to RCE is actively exploited. Patches are available for Drupal 10.x and 11.x prior to specific updates. CISA has mandated patching for federal agencies. Reference: [BleepingComputer: CISA orders feds to patch actively exploited Drupal vulnerability](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-drupal-vulnerability/)

## Today's Priorities 1. **Emergency Patching:** Immediately patch **Cisco SD-WAN Manager**, **Fortinet FortiClientEMS**, and **Citrix NetScaler** appliances, as these are under active attack with critical authentication bypass and code execution flaws. 2. **Linux Kernel Assessment:** Review and prioritize patching for Linux systems running kernel versions 4.11 to 6.7 against the 'Dirty Frag' LPE vulnerability, prioritizing internet-facing and multi-tenant systems. 3. **Web Platform Review:** Audit and patch **cPanel/WHM**, **Drupal**, and **Ghost CMS** installations, as these are being exploited at scale for server takeover and malware delivery. 4. **Supply Chain Vigilance:** Review developer access controls and monitor for unauthorized VS Code extensions following the GitHub breach, and reinforce awareness of SEO-poisoning and AI chatbot-based social engineering tactics.

## 🔗 References

  • [SC Media: 10.0 Cisco Catalyst SD-WAN Controller bug added to CISA’s KEV list](https://www.scworld.com/news/10-0-cisco-catalyst-sd-wan-controller-bug-added-to-cisas-kev-list)
  • [BleepingComputer: Hackers exploit FortiClient EMS flaw to push infostealer malware](https://www.bleepingcomputer.com/news/security/hackers-exploit-forticlient-ems-flaw-to-push-infostealer-malware/)
  • [FortiGuard Outbreak Alerts: Citrix NetScaler Memory Overread Vulnerability](https://fortiguard.fortinet.com/outbreak-alert/citrix-netscaler-memory-overread)
  • [The Hacker News: GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension](https://thehackernews.com/2026/05/github-internal-repositories-breached.html)
  • [Infosecurity Magazine: Hackers Observed Using AI to Develop Zero-Day for the First Time](https://www.infosecurity-magazine.com/news/hackers-using-ai-zero-day-first/)

Share this article