# Threat Intel Brief — May 28, 2026
TL;DR
- Critical vulnerabilities under active exploitation: CISA has issued emergency directives for federal agencies to patch actively exploited flaws in LiteSpeed cPanel plugin (CVE-2026-48172) and Drupal CMS within 72 hours, while Trend Micro Apex One/Vision One SEP vulnerabilities are being weaponized in the wild.
- Iranian state-sponsored campaigns intensify: MuddyWater (MOIS-linked) targeted nine countries using DLL side-loading, while Nimbus Manticore deployed custom malware against U.S., European, and Middle Eastern aviation and software sectors following February 2026 military tensions.
- Supply chain attacks persist: The GlassWorm botnet targeting developers was disrupted after a coordinated takedown by CrowdStrike, Google, and Shadowserver Foundation, while malicious npm packages continue to target AI development workflows.
- Banking trojans expand across continents: Grandoreiro and BTMOB RAT campaigns are actively targeting financial institutions in Spain, Portugal, Mexico, and Brazil through coordinated Windows and Android attacks.
- Novel cryptojacking tactics emerge: Threat actors are leveraging AI chatbot manipulation and SEO poisoning to distribute GPU mining malware, representing a significant evolution in social engineering techniques.
Critical Threats
LiteSpeed cPanel Plugin Actively Exploited (CVE-2026-48172)
What happened: CISA has added CVE-2026-48172, a critical vulnerability in the LiteSpeed cPanel/WHM plugin, to the Known Exploited Vulnerabilities catalog. Federal agencies have been given four days to patch, indicating active exploitation in the wild. The flaw affects web hosting infrastructure globally.
Impact: Successful exploitation could lead to unauthorized access to web hosting control panels, enabling attackers to compromise hosted websites, exfiltrate customer data, or establish persistent backdoors across shared hosting environments. The widespread deployment of cPanel/WHM in commercial hosting creates systemic risk for supply chain compromise.
Recommendations:
- Apply vendor patches for CVE-2026-48172 immediately on all cPanel servers running LiteSpeed plugin
- Audit web server access logs and cPanel authentication logs for suspicious activity
- If patching cannot be completed within 24 hours, temporarily disable the LiteSpeed plugin or restrict cPanel interface access
- Implement network-level access controls limiting cPanel management to trusted IP ranges
Drupal SQL Injection Under Active Exploitation
What happened: CISA has issued an emergency directive requiring U.S. government agencies to patch an actively exploited SQL injection vulnerability in Drupal CMS by Wednesday evening. The vulnerability is being weaponized against federal networks.
Impact: SQL injection flaws allow attackers to read, modify, or delete database contents, potentially leading to full site compromise, data exfiltration, and unauthorized administrative access. The active exploitation against government systems suggests coordinated targeting by sophisticated threat actors.
Recommendations:
- Identify all Drupal CMS instances immediately using asset inventory and network scanning
- Apply the latest Drupal security patches released by Drupal.org
- Review Drupal access logs and database query logs for suspicious SQL patterns
- If immediate patching is not possible, isolate affected instances or implement WAF rules blocking SQL injection attempts
- Verify database integrity and check for unauthorized administrative accounts
Trend Micro Endpoint Security Flaws Exploited
What happened: Multiple vulnerabilities in Trend Micro Apex One and Vision One Endpoint Security are being actively exploited in the wild. CERT.BE and other national cybersecurity agencies have issued urgent patching guidance.
Impact: Compromise of endpoint security platforms grants attackers privileged access to network visibility and control mechanisms, enabling lateral movement, data exfiltration, and persistent access while evading detection. Organizations relying on these products for endpoint protection face immediate risk of enterprise-wide compromise.
Recommendations:
- Apply all available patches for Trend Micro Apex One and Vision One SEP immediately
- Hunt for indicators of compromise including suspicious process execution, privilege escalation, or lateral movement from systems running affected products
- Monitor Trend Micro management consoles for unauthorized configuration changes or administrative activity
- Review network segmentation to limit potential lateral movement if compromise is suspected
KnowledgeDeliver LMS Zero-Day Exploited (CVE-2026-5426)
What happened: A zero-day vulnerability in Digital Knowledge KnowledgeDeliver LMS (CVE-2026-5426) was exploited to deploy Godzilla web shell and Cobalt Strike Beacon. The flaw stems from hard-coded ASP.NET machine keys enabling authentication bypass and remote code execution. A patch is now available.
Impact: Organizations running KnowledgeDeliver LMS face immediate risk of full system compromise. Hard-coded cryptographic keys allow attackers to forge authentication tokens, execute arbitrary code, and establish persistent access. The deployment of Cobalt Strike indicates targeted post-exploitation activity typical of APT or ransomware operations.
Recommendations:
- Apply vendor patch for CVE-2026-5426 immediately on all KnowledgeDeliver LMS instances
- Hunt for Godzilla web shell artifacts and Cobalt Strike Beacon indicators in web directories and process memory
- Review IIS logs and ASP.NET application logs for anomalous POST requests to authentication or file upload handlers
- Rotate all application credentials and API keys, as hard-coded machine keys may have exposed session tokens
- Isolate unpatched LMS instances from network until remediation is complete
Threat Actor Activity
Iranian State-Sponsored Operations Intensify
MuddyWater (MOIS-linked) conducted a multi-country espionage campaign in Q1 2026 using DLL side-loading techniques, targeting at least nine organizations across nine countries. The campaign affected industrial manufacturing, electronics manufacturing, education, public sector, financial services, and professional services sectors. This activity aligns with Iran's strategic intelligence collection priorities and demonstrates operational continuity despite prior public disclosures and sanctions.
Nimbus Manticore (also tracked as Screening Serpens and UNC1549) launched a campaign deploying MiniFast and MiniJunk V2 malware via phishing and SEO poisoning, targeting aviation and software sectors across the U.S., Europe, and the Middle East. The timing following February 2026 military tensions suggests reactive tasking driven by escalated geopolitical conflict.
Defensive priorities:
- Monitor for DLL side-loading by detecting unexpected DLL loads from non-standard paths
- Implement enhanced email security controls and user awareness training focused on phishing lures related to current geopolitical events
- Deploy behavioral analytics to detect custom malware post-compromise activity
- Establish threat hunting procedures targeting Iranian TTPs, including SEO poisoning infrastructure and known phishing themes
ShinyHunters Extortion Campaign Targets Major U.S. Entities
The financially motivated ShinyHunters group confirmed breaches of Charter Communications (major U.S. telecommunications provider) and 7-Eleven (exposing personal information of over 183,000 individuals). The group operates with a business model centered on data theft, extortion, and sale of stolen databases on underground forums.
Defensive priorities:
- Implement robust monitoring for unusual database access patterns and large-scale data exfiltration attempts
- Enforce multi-factor authentication on all internet-facing applications and cloud infrastructure
- Deploy data loss prevention solutions to detect and block unauthorized transfer of sensitive customer databases
- Establish incident response procedures specifically for extortion scenarios
Silent Ransom Group Shifts to Physical Data Theft
The FBI has warned that the Silent Ransom Group (SRG) is conducting in-person data theft attacks targeting U.S.-based law firms. This represents a significant tactical evolution from traditional ransomware operations to physical theft and extortion, bypassing traditional network security controls.
Defensive priorities:
- Implement comprehensive physical security controls including visitor management systems, badge access logs, and mandatory escort policies
- Conduct regular physical security audits and penetration testing including social engineering scenarios
- Establish data handling procedures that minimize physical document storage and implement secure document destruction protocols
- Deploy monitoring for unusual physical access patterns and after-hours building entry
Geopolitical Context
India Mandates Aggressive Vulnerability Patching Timeline
CERT-In has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged, citing concerns about threat actors using AI tools and large language models to automate vulnerability exploitation. This positions India among the most aggressive national cybersecurity regulators globally and reflects heightened threat perception amid Indo-Pacific strategic competition.
Supply Chain Security Remains Critical Priority
The disruption of the GlassWorm botnet by CrowdStrike, Google, and Shadowserver Foundation highlights ongoing threats to software development infrastructure. The campaign targeted developers through malicious packages and extensions since early 2025, utilizing Solana blockchain and BitTorrent DHT for resilient C2 infrastructure. Separately, a malicious npm package "mouse5212-super-formatter" was discovered targeting Claude AI user data directories, demonstrating continued evolution of supply chain attack techniques.
Banking Sector Under Sustained Attack
Coordinated campaigns deploying Grandoreiro malware (targeting Spain, Portugal, Mexico) and BTMOB RAT (targeting Brazil) demonstrate persistent threats to financial services across Latin America and Europe. The dual-platform approach targeting both Windows enterprise environments and Android mobile banking reflects sophisticated operational planning designed to compromise multiple points in the financial transaction chain.
Recommended Actions
Immediate (0-24 hours)
- Patch CVE-2026-48172 (LiteSpeed cPanel/WHM plugin) on all affected systems
- Patch actively exploited Drupal SQL injection vulnerability on all instances
- Apply Trend Micro patches for Apex One and Vision One SEP
- Patch CVE-2026-5426 (KnowledgeDeliver LMS) and hunt for Godzilla/Cobalt Strike indicators
- Audit developer workstations for GlassWorm compromise indicators and malicious npm packages
- Search for "mouse5212-super-formatter" npm package across all development systems and CI/CD pipelines
Within 24-72 hours
- Upgrade Gitea to version 1.26.2 or later to address CVE-2026-27771 (unauthenticated container image access)
- Patch CVE-2026-45659 (Microsoft SharePoint RCE) across all SharePoint Server instances
- Deploy enhanced monitoring for banking trojan indicators (Grandoreiro, BTMOB RAT) in affected regions
- Review ScreenConnect deployments for unauthorized sessions and implement MFA
- Audit Ubiquiti UniFi OS devices and apply available firmware updates
- Patch Apache ActiveMQ NMS AMQP Client deserialization vulnerability
- Review Cisco Secure Workload deployments and apply available patches
This week
- Implement GPU utilization monitoring to detect cryptojacking campaigns leveraging SEO poisoning and AI chatbot manipulation
- Conduct physical security assessments for law firms and professional services organizations
- Review DLL side-loading detection capabilities to identify MuddyWater-style intrusions
- Assess compliance with India's 12-hour patching mandate if operating in that jurisdiction
- Enhance email security controls to detect Iranian phishing campaigns (Nimbus Manticore)
- Review Windows Server 2016 domain controllers for KB5087537-related issues and uninstall if domain lookup failures occur
Watch List
- Proof-of-concept exploits for CVE-2026-48172, CVE-2026-5426, and Drupal SQL injection may accelerate exploitation
- Attribution disclosures for Trend Micro, Drupal, or LiteSpeed exploitation campaigns could inform defensive priorities
- Additional Iranian cyber operations likely if geopolitical tensions persist or escalate
- Expansion of AI chatbot manipulation techniques to distribute malware beyond cryptojacking
- Copycat physical data theft operations following Silent Ransom Group's tactical innovation
- Secondary exploitation of Charter Communications and 7-Eleven breach data by additional threat actors
Sources
- BleepingComputer
- The Hacker News
- CERT.BE (Belgium)
- Microsoft Security Blog
- CISA Known Exploited Vulnerabilities Catalog
- FBI Public Service Announcements
- CERT-In (India)
- JPCERT/CC (Japan)
- WatchGuard Threat Intelligence
- ESET Research
- OX Security
- CrowdStrike Intelligence
- Google Threat Analysis Group
- Shadowserver Foundation
---
*This report synthesizes open-source threat intelligence for professional IT security audiences. Organizations should validate findings against their specific environments and threat models. For urgent security incidents, contact your national CERT or relevant law enforcement agencies.*
