# Threat Intel Brief — May 27, 2026

TL;DR

  • Critical zero-days under active exploitation: Ghost CMS (CVE-2026-26980) compromised 700+ sites; KnowledgeDeliver LMS (CVE-2026-5426) exploited to deploy Godzilla web shell and Cobalt Strike; LiteSpeed cPanel/WHM plugin (CVE-2026-48172) actively targeted.
  • CISA emergency directive: U.S. federal agencies ordered to patch actively exploited Drupal SQL injection flaw by Wednesday evening; immediate action required across all sectors.
  • Iranian APT surge: MuddyWater and Nimbus Manticore conducting multi-country espionage campaigns targeting critical infrastructure, aviation, and software sectors following February 2026 military tensions.
  • Supply chain threats escalate: TrapDoor campaign distributes credential stealers across npm, PyPI, and Crates.io; Lazarus Group deploys memory-only RAT against financial institutions; Kali365 phishing-as-a-service bypasses MFA at scale.
  • Law enforcement disruption: Dutch authorities arrested hosting operators facilitating Russian cyber operations, seizing infrastructure previously used for EU-targeted attacks and disinformation campaigns.

---

Critical Threats

Ghost CMS SQL Injection Exploited in Mass Compromise

What happened: Threat actors are actively exploiting CVE-2026-26980, a critical SQL injection vulnerability (CVSS 9.4) in Ghost CMS Content API, to compromise over 700 websites. Attackers inject malicious JavaScript to conduct ClickFix social engineering attacks, tricking visitors into executing attacker-controlled commands. The vulnerability allows unauthenticated remote attackers to read arbitrary database contents.

Impact: Compromised sites serve as distribution infrastructure for secondary payloads, exposing visitors to malware and credential theft. Organizations running Ghost CMS face immediate risk of database exfiltration, including user credentials, API keys, and content. The scale of compromise indicates automated exploitation tooling is in circulation.

Recommendations:

  • Apply Ghost CMS security patches addressing CVE-2026-26980 immediately to all instances.
  • Scan Ghost installations for injected JavaScript in posts, pages, and theme files.
  • Review database integrity and web server logs for unauthorized Content API access since initial disclosure.
  • Implement WAF rules to block SQL injection attempts targeting Ghost Content API parameters.
  • Reset all Ghost admin credentials and API keys as a precautionary measure.

---

KnowledgeDeliver LMS Zero-Day Enables Persistent Access

What happened: CVE-2026-5426, a high-severity vulnerability in Digital Knowledge's KnowledgeDeliver learning management system, was exploited as a zero-day to deploy Godzilla web shell and Cobalt Strike Beacon. The flaw stems from hard-coded ASP.NET machine keys enabling authentication bypass and remote code execution. Patches are now available.

Impact: Organizations running KnowledgeDeliver LMS face risk of full system compromise. Hard-coded cryptographic keys allow attackers to forge authentication tokens, gain administrative access, and establish persistent backdoors. Educational institutions and corporate training environments are primary targets.

Recommendations:

  • Apply vendor patches for CVE-2026-5426 immediately to all KnowledgeDeliver instances.
  • Hunt for Godzilla web shell indicators in IIS logs and file systems (focus on .aspx files in web directories).
  • Review ASP.NET application event logs for anomalous admin-level access or token manipulation.
  • Conduct forensic analysis on internet-facing instances to determine if compromise occurred during zero-day window.
  • Isolate unpatched systems from network until remediation is complete.

---

CISA Emergency Directive: Drupal SQL Injection Under Active Exploitation

What happened: CISA issued an emergency directive requiring U.S. federal agencies to patch an actively exploited SQL injection vulnerability in Drupal CMS by Wednesday evening. The vulnerability is being exploited in the wild, prompting urgent action across government networks.

Impact: SQL injection enables attackers to extract, modify, or delete database contents, potentially leading to full site compromise, data theft, and unauthorized administrative access. Given active exploitation and CISA's compressed timeline, immediate risk exists for all unpatched Drupal installations across government and private sectors.

Recommendations:

  • Identify all Drupal CMS instances immediately using asset inventory and network scanning.
  • Apply latest Drupal security patches as soon as possible, prioritizing internet-facing instances.
  • Review Drupal access logs and database query logs for suspicious SQL patterns from past 7–14 days.
  • Implement WAF rules to block SQL injection attempts if patching cannot be completed within 24 hours.
  • Isolate or take offline any Drupal instances that cannot be patched immediately.

---

LiteSpeed cPanel/WHM Plugin Under Active Exploitation

What happened: CVE-2026-48172, a critical vulnerability in the LiteSpeed cPanel/WHM plugin, is being actively exploited in the wild. The flaw affects web hosting environments running cPanel/WHM with LiteSpeed integration. Specific technical details remain limited, but exploitation is confirmed.

Impact: Critical risk for hosting providers and organizations using cPanel/WHM with LiteSpeed. Active exploitation enables attackers to compromise web hosting infrastructure, potentially leading to mass exploitation across shared hosting environments, data breaches, and lateral movement.

Recommendations:

  • Update LiteSpeed cPanel/WHM plugin to latest patched version immediately via WHM interface.
  • Audit all cPanel/WHM servers for indicators of compromise in LiteSpeed plugin logs.
  • Temporarily disable LiteSpeed plugin if patching cannot be completed within 4 hours.
  • Monitor for unauthorized administrative access and suspicious file modifications.
  • Implement network segmentation to isolate cPanel/WHM management interfaces.

---

Multiple Critical Vulnerabilities in Enterprise Security Products

What happened: CERT.BE issued urgent warnings for actively exploited vulnerabilities in Trend Micro Apex One and Vision One Endpoint Security, critical flaws in Ubiquiti UniFi OS, and a critical vulnerability in Cisco Secure Workload. Specific CVE identifiers for these flaws are not yet publicly assigned.

Impact: Organizations using affected products face immediate compromise risk. Trend Micro vulnerabilities under active exploitation may enable unauthorized access to endpoint protection infrastructure, potentially disabling security controls. Ubiquiti and Cisco flaws affect network management and application security platforms with privileged access to organizational networks.

Recommendations:

  • Apply vendor-supplied patches for Trend Micro Apex One and Vision One SEP without delay.
  • Update Ubiquiti UniFi OS to latest version via web interface or mobile app.
  • Check Cisco Security Advisory portal for Secure Workload patches and apply immediately.
  • Review product logs for unusual authentication attempts or configuration changes.
  • Conduct threat hunts on systems running vulnerable products, focusing on past 30 days.

---

Threat Actor Activity

Iranian APT Groups Escalate Multi-Country Campaigns

MuddyWater (MOIS-linked): Conducted Q1 2026 espionage campaign using DLL side-loading techniques, targeting at least nine organizations across nine countries. Affected sectors include industrial manufacturing, electronics, education, public administration, financial services, and professional services. The campaign demonstrates continued evolution in tradecraft, moving from traditional macro-laden documents to DLL side-loading for improved evasion.

Nimbus Manticore (aka Screening Serpens, UNC1549): Deployed MiniFast and MiniJunk V2 malware via phishing and SEO poisoning, targeting aviation and software sectors across the U.S., Europe, and the Middle East. Activity surged following military tensions in February 2026, indicating reactive targeting driven by geopolitical events.

Defensive priorities:

  • Monitor for DLL side-loading by detecting unsigned or anomalous DLLs loaded by legitimate signed binaries.
  • Block macros in Office documents from the internet; enable Attack Surface Reduction rules.
  • Deploy web proxy filtering to detect SEO poisoning attempts and block newly registered domains.
  • Hunt for MiniFast, MiniJunk V2, and associated loader indicators in aviation/software environments.

---

ShinyHunters Targets U.S. Telecommunications and Retail

The financially motivated extortion group breached Charter Communications and 7-Eleven in separate incidents, stealing data from over 183,000 individuals in the 7-Eleven breach alone. ShinyHunters operates as a data broker and extortionist, threatening public disclosure unless ransom demands are met. The group's targeting of major U.S. telecommunications and retail infrastructure underscores persistent threats to consumer-facing sectors managing large volumes of PII.

Defensive priorities:

  • Implement comprehensive monitoring for internet-facing databases and APIs.
  • Deploy data loss prevention solutions with egress filtering to detect bulk data exfiltration.
  • Establish threat intelligence monitoring for ShinyHunters activity on underground forums.
  • Implement database activity monitoring with alerting on bulk exports and privileged account usage.

---

Lazarus Group Deploys Memory-Only RAT Against Financial Sector

North Korean state-sponsored Lazarus Group deployed RemotePE, a cross-platform memory-only remote access trojan, against financial and cryptocurrency organizations. The malware is delivered via multi-stage infection chains involving DPAPILoader and RemotePELoader. The campaign aligns with DPRK's strategic imperative to generate revenue through illicit cyber operations amid international sanctions.

Defensive priorities:

  • Implement memory scanning and behavioral detection for fileless malware execution.
  • Monitor for multi-stage loader activity and unusual DLL loading sequences.
  • Deploy YARA rules specific to RemotePE, DPAPILoader, and RemotePELoader indicators.
  • Harden cryptocurrency transaction systems with network segmentation and strict egress filtering.

---

Kali365 Phishing-as-a-Service Bypasses MFA

The FBI warned of Kali365, a phishing-as-a-service platform targeting Microsoft 365 accounts by exploiting OAuth device code authentication to steal session tokens and bypass multi-factor authentication. The service commoditizes sophisticated authentication bypass techniques, enabling less technical actors to conduct account takeover operations at scale.

Defensive priorities:

  • Implement conditional access policies restricting OAuth device code authentication flows.
  • Monitor for anomalous OAuth application consent requests and device code authentication attempts.
  • Deploy token binding and continuous access evaluation in Microsoft 365.
  • Enable phishing-resistant authentication methods such as FIDO2 security keys.

---

Geopolitical Context

Dutch Law Enforcement Disrupts Russian Cyber Infrastructure

Dutch authorities arrested two co-owners of Internet hosting companies for operating infrastructure used by Russia to conduct cyberattacks, influence operations, and disinformation campaigns within the EU. The companies had assumed control of Stark Industries Solutions' technical infrastructure, an ISP previously sanctioned by the EU for facilitating Russian intelligence cyber operations. The action represents a significant enforcement effort targeting the commercial enablement layer of state-aligned cyber operations.

Implications: The arrests demonstrate EU commitment to enforcing cyber-related sanctions and may encourage similar prosecutorial efforts in other member states. The case establishes precedent for holding infrastructure providers accountable for knowingly enabling state-sponsored operations, potentially increasing operational costs for Russia-linked cyber activity within European jurisdiction.

---

India Mandates 12-Hour Patching for Critical Vulnerabilities

CERT-In issued guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged, citing concerns about threat actors using AI tools and large language models to automate vulnerability exploitation. The policy represents one of the most aggressive patching mandates globally and reflects India's urgency in protecting critical infrastructure amid AI-augmented offensive capabilities.

Implications: Multinational corporations operating in India will need to align global patch management processes with the 12-hour requirement. The policy may set a precedent for other nations concerned about AI-enabled threats and could accelerate India's push for indigenous cybersecurity solutions.

---

TrapDoor Supply Chain Attack Targets Developer Ecosystems

A coordinated campaign distributed credential-stealing malware across npm, PyPI, and Crates.io package repositories, affecting over 34 malicious packages spanning 384+ versions. The campaign began in May 2026 and represents a significant cross-ecosystem threat targeting multiple programming language communities. Compromised credentials may enable lateral movement, source code theft, and supply chain compromise of downstream customers.

Implications: The campaign underscores persistent vulnerabilities in open-source package ecosystems and the need for enhanced package repository controls. Organizations must implement dependency auditing, package pinning, and private mirrors with allowlist-based approval processes.

---

Recommended Actions

Immediate (0–24 hours)

1. Patch critical vulnerabilities: Apply updates for CVE-2026-26980 (Ghost CMS), CVE-2026-5426 (KnowledgeDeliver), CVE-2026-48172 (LiteSpeed), Drupal SQL injection, Trend Micro products, Ubiquiti UniFi OS, and Cisco Secure Workload.
2. Hunt for active compromise: Scan for Godzilla web shell, Cobalt Strike Beacon, and injected JavaScript in Ghost CMS installations.
3. Isolate unpatched systems: Remove vulnerable instances from network until patches can be applied.
4. Review authentication logs: Check for unauthorized access attempts, OAuth anomalies, and token manipulation across enterprise platforms.

Short-term (24–72 hours)

1. Audit dependency manifests: Review package.json, requirements.txt, and Cargo.toml for suspicious packages added after May 2026.
2. Rotate credentials: Reset API keys, service account credentials, and admin passwords for systems potentially exposed during vulnerability windows.
3. Deploy detection rules: Implement YARA signatures and behavioral analytics for Iranian APT tooling (MiniFast, MiniJunk V2) and Lazarus malware (RemotePE, DPAPILoader).
4. Enhance MFA controls: Implement conditional access policies and phishing-resistant authentication for Microsoft 365 environments.

This week

1. Conduct threat hunts: Search for DLL side-loading, memory-only malware execution, and OAuth device code abuse across enterprise environments.
2. Review supply chain security: Implement package repository controls, dependency pinning, and private mirrors for development environments.
3. Strengthen network segmentation: Isolate hosting management interfaces, database servers, and development environments from untrusted networks.
4. Update incident response plans: Incorporate lessons from recent zero-day exploitation and supply chain attacks into playbooks.

---

Watch List

  • Microsoft SharePoint CVE-2026-45659: Remote code execution via unsafe deserialization (CVSS 8.8). Patches available; monitor for exploitation activity.
  • OutSystems Lifetime CVE-2026-40127: Authorization bypass through user-controlled key. Affects enterprise low-code platforms; vendor guidance pending.
  • Windows Server 2016 KB5087537: Known issue causing domain controller lookup failures. Pause deployment and uninstall from affected systems.
  • Cryptojacking campaign: SEO poisoning and ScreenConnect abuse for GPU mining. Monitor for unauthorized remote access and sustained GPU utilization.
  • Iranian APT infrastructure: Continued monitoring for MuddyWater and Nimbus Manticore indicators across critical infrastructure sectors.

---

Sources

  • BleepingComputer: KnowledgeDeliver, Charter Communications, CISA Drupal directive, 7-Eleven breach, Kali365 warning
  • The Hacker News: MuddyWater campaign, SharePoint RCE, Iranian phishing, KnowledgeDeliver exploitation, Ghost CMS compromise, Lazarus RemotePE, TrapDoor supply chain attack
  • Microsoft Security: Cryptojacking campaign analysis
  • CERT.BE: LiteSpeed, Ubiquiti, Trend Micro, Cisco advisories
  • Krebs on Security: Netherlands infrastructure seizure
  • CERT.PL: OutSystems Lifetime vulnerability
  • CERT-In: India 12-hour patching mandate