# Threat Intel Brief — May 24, 2026

TL;DR

  • Supply chain attacks compromised multiple Laravel and Packagist packages, distributing credential-stealing malware to developers worldwide.
  • Critical vulnerabilities in Cisco SD-WAN (CVE-2026-20127, exploited since 2023), Cisco Secure Workload (CVE-2026-20223, CVSS 10.0), and Langflow (CVE-2025-34291) are under active exploitation.
  • Zero-day flaws in Trend Micro Apex One and Drupal Core are being targeted in live attacks; immediate patching required.
  • Geopolitical activity: Belarus-aligned Ghostwriter targets Ukrainian government; law enforcement dismantles criminal VPN service used by ransomware groups.
  • Insider threat: CISA contractor intentionally leaked AWS GovCloud credentials on public GitHub repository.

---

Critical Threats

Cisco SD-WAN Authentication Bypass Exploited Since 2023

What happened: Cisco disclosed CVE-2026-20127, a critical vulnerability in Catalyst SD-WAN controllers and SD-WAN Manager that allows attackers to gain administrative access. The flaw has been actively exploited in the wild since 2023—three years before public disclosure.

Impact: Organizations running Cisco SD-WAN infrastructure face immediate risk of complete network compromise. Attackers with administrative access can reconfigure WAN routing, intercept traffic, deploy additional payloads, or disrupt connectivity across the entire SD-WAN fabric. The multi-year exploitation window suggests potential long-term compromise in affected environments.

Recommendations:

  • Apply Cisco security patches for CVE-2026-20127 immediately on all SD-WAN controllers and managers.
  • Review logs from 2023 onward for unauthorized administrative access, configuration changes, or anomalous authentication patterns.
  • Audit all administrative accounts and recent configuration changes for signs of compromise.
  • Implement network segmentation to isolate SD-WAN management plane from production networks.

---

Cisco Secure Workload CVSS 10.0 Flaw Enables Unauthenticated Data Access

What happened: Cisco patched CVE-2026-20223, a maximum-severity vulnerability in Secure Workload that allows unauthenticated remote attackers to access sensitive data through insufficient validation in REST API endpoints.

Impact: Unauthenticated attackers can remotely exfiltrate application dependency maps, security policies, flow data, and workload telemetry without credentials. This exposes internal infrastructure reconnaissance data and security posture information to adversaries.

Recommendations:

  • Identify all Cisco Secure Workload instances and apply vendor patches immediately.
  • Review REST API access logs for unusual unauthenticated requests or anomalous data access patterns.
  • Restrict network access to Secure Workload management interfaces using firewall rules until patched.
  • Monitor for follow-on exploitation attempts using updated threat intelligence.

---

Trend Micro Apex One Zero-Day Under Active Attack

What happened: Trend Micro disclosed a zero-day vulnerability in Apex One endpoint security software being actively exploited against Windows systems. CVE not yet publicly assigned.

Impact: Attackers are exploiting this flaw before patches are widely available, potentially bypassing endpoint security controls, gaining unauthorized access, or compromising systems protected by Apex One. Organizations in defense, government, and critical infrastructure sectors face elevated risk.

Recommendations:

  • Check Trend Micro security advisories immediately for emergency patches or hotfixes.
  • Review Apex One server and agent logs for suspicious activity or unauthorized access attempts.
  • Isolate Apex One management servers from untrusted networks.
  • Coordinate with Trend Micro support for incident response assistance if compromise is suspected.

---

Drupal Core SQL Injection Actively Exploited

What happened: Drupal warned that a critical SQL injection vulnerability in Drupal Core is being actively exploited in the wild. CVE not yet assigned.

Impact: SQL injection enables attackers to bypass authentication, extract database contents (credentials, PII, configuration data), modify or delete data, and potentially achieve remote code execution. Public-facing Drupal sites are high-priority targets.

Recommendations:

  • Apply Drupal security patches released this week to all instances immediately.
  • Review access logs and database query logs for suspicious SQL patterns or unauthorized access attempts from the past 72 hours.
  • If patching cannot be completed within hours, consider taking vulnerable sites offline or placing them behind WAF rules blocking SQL injection patterns.
  • After patching, rotate database credentials and review user accounts for unauthorized additions or privilege escalations.

---

CISA Contractor Leaks AWS GovCloud Credentials

What happened: A CISA contractor intentionally published AWS GovCloud keys and agency secrets on a public GitHub account, prompting Congressional scrutiny as CISA works to invalidate leaked credentials.

Impact: Exposure of government cloud infrastructure credentials creates opportunity for nation-state actors, cybercriminals, or other adversaries to exploit legitimate government cloud access for espionage, disruption, or data theft. The deliberate nature suggests insider threat rather than accidental exposure.

Recommendations:

  • Implement automated secret scanning tools to detect exposed credentials in repositories before publication.
  • Enforce short-lived credentials and role-based access with session tokens rather than long-term access keys for GovCloud.
  • Deploy Data Loss Prevention controls and egress monitoring to detect exfiltration attempts to code repositories.
  • Establish continuous monitoring for cloud account abuse by logging AWS CloudTrail events and alerting on anomalous API calls.
  • Strengthen insider threat programs with behavioral analytics and enhanced vetting of contractors with privileged access.

---

Threat Actor Activity

Belarus-Aligned Ghostwriter Targets Ukrainian Government

Ghostwriter (UAC-0057, UNC1151) is conducting a phishing campaign against Ukrainian government entities using lures impersonating the Prometheus online learning platform. The campaign employs credential harvesting techniques consistent with the group's established espionage operations supporting Belarusian strategic interests in the Russia-Ukraine conflict.

Defensive measures: Implement multi-factor authentication for all government personnel, deploy email security controls to detect typosquatting domains, and monitor for connections to known Ghostwriter C2 infrastructure.

---

Iranian APT Screening Serpens Targets Defense and Technology Sectors

Unit 42 reports that Screening Serpens, an Iranian APT group, is conducting espionage campaigns targeting technology and defense sectors using AppDomainManager hijacking techniques and custom RAT variants. The targeting aligns with Iranian intelligence priorities for military modernization and technology acquisition.

Defensive measures: Monitor for unusual AppDomainManager.dll loads, implement application whitelisting, and detect unusual outbound network connections from workstations to Iranian infrastructure.

---

ROADtools Framework Misused in Cloud Intrusions

Nation-state actors are misusing the legitimate open-source ROADtools framework for Azure AD reconnaissance and privilege escalation in cloud environments. The dual-use tool enables adversaries to blend malicious activity with legitimate security assessments.

Defensive measures: Monitor for unusual ROADtools execution patterns, establish baselines for Azure AD Graph API queries, and correlate ROADtools indicators with other post-compromise behaviors.

---

Geopolitical Context

Law Enforcement Disrupts Criminal Infrastructure

Authorities in Europe and North America dismantled First VPN Service, a criminal VPN used by approximately 25 ransomware groups to obscure attack origins. The operation, led by France and the Netherlands, represents continued transatlantic cooperation targeting ransomware supply chains.

Separately, U.S. and Canadian authorities arrested a Canadian national for operating the KimWolf DDoS botnet, which infected nearly two million devices worldwide.

Netherlands Seizes Hosting Infrastructure

Dutch financial crime investigators arrested two individuals and seized 800 servers from a web hosting company facilitating cyberattacks, interference operations, and disinformation campaigns. The action underscores the Netherlands' proactive stance on transnational cybercrime enforcement.

---

Recommended Actions

Immediate (0-24 hours)

  • Patch Cisco SD-WAN (CVE-2026-20127) and Cisco Secure Workload (CVE-2026-20223) immediately.
  • Apply Trend Micro Apex One emergency patches as soon as available.
  • Update Drupal Core to patched versions on all instances.
  • Audit Laravel and Packagist dependencies for compromised packages; rotate credentials accessible from developer workstations.
  • Review CISA contractor access and rotate AWS GovCloud credentials if exposure is suspected.

Within 24-72 hours

  • Patch Ivanti EPMM critical RCE vulnerabilities (CVE: see source).
  • Update React Server Components and integrating frameworks (Next.js, Remix) to latest versions.
  • Apply Microsoft WSUS out-of-band update for critical RCE flaw (CVE: see source).
  • Patch Ubiquiti UniFi OS maximum-severity vulnerabilities (CVE: see source).
  • Update FortiOS per Fortinet's October 14, 2025 advisory (CVE: see source).

This week

  • Patch Unbound DNS resolver for denial-of-service vulnerabilities (CVE: see source).
  • Review Cisco Secure Email Gateway advisory and implement remediation measures (no patch available; CVE: see source).
  • Conduct compromise assessments on systems where Laravel-Lang or Packagist packages were installed.
  • Audit GitHub repositories for malicious commits related to Megalodon campaign.
  • Review F5 BIG-IP and Confluence logs for signs of multi-stage intrusion attempts.

---

Watch List

  • Anthropic Project Glasswing: Monitor vendor advisories for patches related to 10,000+ high/critical vulnerabilities discovered in systemically important software.
  • Langflow CVE-2025-34291: CISA KEV-listed, actively exploited origin validation error (CVSS 9.4).
  • Italian CINEMAGOAL disruption: Credential theft infrastructure targeting Netflix, Disney+, Spotify may reconstitute under new branding.
  • Megalodon GitHub campaign: Monitor for additional malicious commits targeting CI/CD workflows.

---

Sources

  • BleepingComputer
  • The Hacker News
  • CERT-EU Advisories
  • Krebs on Security
  • Unit 42 (Palo Alto Networks)
  • Microsoft Security Blog
  • CERT.BE (Belgium)