# Threat Intel Brief — May 29, 2026

TL;DR

  • Critical zero-day in Gogs Git service enables remote code execution on Internet-facing instances; no patch available—immediate isolation required.
  • Active exploitation of FortiClient EMS (CVE-2026-35616) delivers credential-stealing malware; patch and hunt for EKZ malware indicators now.
  • Multiple critical web framework flaws in Starlette/FastAPI, LiquidJS, and SharePoint demand immediate patching to prevent authentication bypass and RCE.
  • Supply chain attacks intensify: GlassWorm botnet disrupted after targeting developers; malicious npm package exfiltrated Claude AI user data.
  • Physical extortion emerges: Silent Ransom Group conducts in-person data theft at U.S. law firms, bypassing traditional cyber defenses.

---

Critical Threats

Gogs Git Service Zero-Day RCE (Unpatched)

What happened: An unpatched remote code execution vulnerability in Gogs self-hosted Git service allows any authenticated user to execute arbitrary code on affected systems. The flaw carries a CVSS score of 9.4 and remains without a CVE assignment or vendor patch. All Internet-facing Gogs instances are at immediate risk.

Impact: Organizations running Gogs for internal development face full system compromise, source code theft, credential harvesting, and lateral movement to connected infrastructure. The authentication requirement is a minimal barrier—any valid user account enables exploitation. The absence of a patch and public disclosure creates an asymmetric window for attackers.

Recommendations:

  • Immediate (0-24h): Isolate all Internet-facing Gogs instances from public access via firewall rules or network segmentation. Restrict access to VPN or internal networks only.
  • Enable comprehensive logging and monitor for suspicious authentication attempts, unusual API calls, or unexpected process execution.
  • Review all Gogs user accounts and remove unnecessary administrative privileges.
  • Subscribe to Gogs GitHub security advisories and prepare to apply patches immediately upon release.

---

FortiClient EMS Authentication Bypass Under Active Exploit

What happened: Threat actors are actively exploiting CVE-2026-35616, an authentication bypass vulnerability in Fortinet FortiClient Enterprise Management Server (EMS), to deploy EKZ credential stealer malware. The campaign disguises payloads as legitimate Fortinet endpoint management components, enabling mass distribution across managed endpoints.

Impact: Unauthorized access to FortiClient EMS infrastructure enables attackers to push malware to all managed endpoints without credentials. Organizations using FortiClient EMS face immediate risk of credential theft, lateral movement, and enterprise-wide compromise. The trust relationship between management servers and endpoints makes detection challenging.

Recommendations:

  • Immediate (0-24h): Identify all FortiClient EMS instances and isolate from Internet access if possible. Apply vendor patches for CVE-2026-35616 immediately.
  • Review FortiClient EMS authentication logs for unauthorized access attempts or anomalous login patterns from unknown sources.
  • Hunt for EKZ malware indicators across endpoints managed by FortiClient EMS, focusing on credential access and exfiltration behaviors (LSASS access, registry credential queries).
  • Implement network segmentation to limit FortiClient EMS exposure and enforce strict access controls until patching is complete.

---

Critical Web Framework Vulnerabilities Require Immediate Action

What happened: Multiple critical vulnerabilities have been disclosed in widely deployed web frameworks and enterprise platforms:

  • Starlette/FastAPI: Authentication bypass flaw affects millions of servers (CVE: see source).
  • LiquidJS: Remote code execution vulnerability in JavaScript templating engine (CVE: see source).
  • Microsoft SharePoint: Remote code execution vulnerability (CVE: see source).
  • Apache ActiveMQ NMS AMQP Client: Deserialization flaw enables RCE (CVE: see source).

Impact: These vulnerabilities collectively expose vast swaths of web infrastructure, API gateways, collaboration platforms, and messaging systems to authentication bypass, remote code execution, and full system compromise. The global deployment footprint creates asymmetric risk for both state-sponsored and criminal actors.

Recommendations:

  • Immediate (0-24h): Identify all affected frameworks and platforms through asset inventory and dependency scanning. Monitor vendor security advisories for patch releases.
  • For Starlette/FastAPI: Implement additional authentication controls such as WAF rules or API gateway validation as compensating controls until patches are available.
  • For SharePoint: Apply Microsoft security updates immediately; monitor IIS logs and Windows Event Logs (Event ID 4688, 4624) for suspicious activity.
  • For LiquidJS: Update to latest patched version via npm/yarn; implement input validation for user-controlled data passed to templates.
  • For ActiveMQ: Implement network segmentation to restrict access to message brokers; enable logging for unusual deserialization activity.

---

CISA Orders Federal Agencies to Patch LiteSpeed cPanel Plugin in 4 Days

What happened: CISA has added a critical vulnerability in the LiteSpeed cPanel user-end plugin to the Known Exploited Vulnerabilities (KEV) catalog, requiring U.S. federal agencies to patch within four days. The flaw is actively exploited in the wild (CVE: see source).

Impact: Critical severity flaw in widely-used web hosting control panel plugin enables attackers to compromise web servers. Federal agencies face a 4-day remediation deadline per CISA BOD 22-01. Private sector organizations using affected LiteSpeed cPanel plugin face immediate risk of server compromise, data theft, and potential ransomware deployment.

Recommendations:

  • Immediate (0-24h): Identify all cPanel installations using the LiteSpeed user-end plugin. Apply vendor patches as soon as available from LiteSpeed or cPanel repositories.
  • Monitor web server logs for suspicious authentication attempts, privilege escalation, or unauthorized file modifications.
  • If patching cannot be completed within 4 days, disable the LiteSpeed cPanel plugin and revert to alternative web server configurations.
  • Review cPanel access logs for indicators of compromise dating back at least 30 days to identify potential prior exploitation.

---

Threat Actor Activity

GreyVibe: AI-Augmented Phishing Targets Ukraine

A likely Russian-aligned threat cluster designated GreyVibe is targeting Ukrainian entities with AI-generated phishing lures powered by ChatGPT and Gemini. The campaign combines generative AI for social engineering with custom malware deployment, representing an evolution in threat actor tradecraft. The use of commercial AI platforms suggests an effort to scale operations and evade detection through varied, contextually relevant messaging. Organizations in Ukraine and allied nations should enhance email filtering to detect AI-generated content anomalies and conduct user awareness training focused on sophisticated social engineering.

JINX-0164: Cryptocurrency Firms Under Siege

A previously undocumented threat actor, JINX-0164, is targeting cryptocurrency organizations with fake recruiter lures and custom macOS malware designed to facilitate digital asset theft. The campaign targets CI/CD infrastructure, potentially enabling widespread compromise or access to production environments containing cryptocurrency wallets and transaction systems. Cryptocurrency firms should implement strict code review and integrity verification for CI/CD pipelines, deploy EDR solutions on macOS systems, and conduct security awareness training focused on recruiter impersonation tactics.

Silent Ransom Group: Physical Data Theft at U.S. Law Firms

The Silent Ransom Group (SRG) has shifted from traditional ransomware operations to conducting in-person data theft attacks targeting U.S.-based law firms. This tactical evolution bypasses cyber defenses entirely, exploiting potential gaps in physical security. Law firms should implement comprehensive physical security controls including badge access systems, visitor logging, security cameras in server rooms, and enforce strict clean desk policies with automatic screen locking. Deploy full-disk encryption on all workstations and servers to protect data at rest from physical theft scenarios.

Storm-2697: The Gentlemen Ransomware Spreads Aggressively

Storm-2697 affiliates are deploying The Gentlemen, a Go-based ransomware featuring per-file ephemeral key encryption and aggressive self-propagation capabilities for lateral movement across networks. The malware's cross-platform compatibility and anti-analysis properties complicate detection and response. Organizations should monitor for unusual Go-compiled binaries, implement network segmentation to limit lateral movement, and maintain offline, immutable backups with tested restoration procedures.

---

Geopolitical Context

Russia-Ukraine Cyber Operations Continue

GreyVibe's targeting of Ukrainian entities with AI-generated lures represents a continuation of Russia's sustained cyber operations against Ukrainian government, military, and critical infrastructure since the 2022 invasion. The integration of generative AI into phishing workflows may lower operational costs and increase campaign velocity, potentially signaling a shift in threat actor resourcing. European allies, particularly frontline NATO members, may face spillover risks or parallel targeting as Russian-aligned actors refine AI-augmented tradecraft.

U.S. Federal Cybersecurity Posture Hardens

CISA's aggressive 4-day patching mandate for the LiteSpeed cPanel plugin reflects the U.S. government's continued effort to harden federal civilian networks against opportunistic exploitation. The directive is consistent with the Binding Operational Directive framework established to enforce baseline cybersecurity hygiene across executive branch agencies, a policy response to repeated intrusions exploiting unpatched software in government environments. Private sector organizations should view federal mandates as leading indicators of critical risk.

Latin American Banking Trojans Expand to Europe

Coordinated campaigns deploying Grandoreiro malware against companies in Spain, Portugal, and Mexico, alongside BTMOB RAT targeting mobile users in Brazil, demonstrate the expansion of Latin American banking trojans into European markets. The dual-platform approach—targeting both Windows desktop and Android mobile devices—signals adaptation to changing consumer banking behaviors. Financial institutions in affected regions should enhance cross-border information sharing and coordinate defensive measures given the transnational nature of these threat actors.

---

Recommended Actions

Immediate (0-24 hours)

1. Isolate all Internet-facing Gogs instances from public access via firewall rules or network segmentation until patches are available.
2. Patch FortiClient EMS for CVE-2026-35616 and hunt for EKZ malware indicators across managed endpoints.
3. Identify and patch LiteSpeed cPanel plugin instances; disable plugin if patching cannot be completed within 4 days.
4. Audit developer workstations for GlassWorm indicators of compromise; review package manager logs and browser extension installations since early 2025.
5. Search all Node.js projects for malicious npm package "mouse5212-super-formatter" and remove if present; rotate API keys and credentials that may have been stored in Claude AI user data directories.

Within 24-72 hours

1. Apply patches for Starlette/FastAPI, LiquidJS, SharePoint, and ActiveMQ vulnerabilities; implement compensating controls (WAF rules, network segmentation) if immediate patching is not possible.
2. Review Gitea instances and upgrade to version 1.26.2 or later to address CVE-2026-27771; audit container registry access logs for unauthorized pull requests.
3. Deploy mobile threat defense (MTD) solutions on corporate and BYOD Android devices to detect BTMOB RAT behavior and C2 communication patterns.
4. Implement comprehensive physical security controls at law firms and other high-value data holders, including badge access systems, visitor logging, and security cameras in server rooms.

This week

1. Patch bzip2 (CVE-2026-42250) and Kidsview (CVE-2026-8990) vulnerabilities; monitor vendor advisories for affected version details and patch availability.
2. Conduct user awareness training focused on AI-generated phishing content, recruiter impersonation, and Android phishing tactics.
3. Review and harden authentication policies for container registries, endpoint management servers, and web frameworks across the organization.
4. Implement application whitelisting on high-value GPU systems to prevent execution of cryptojacking malware distributed via SEO poisoning and AI chatbot manipulation.

---

Watch List

  • Gogs zero-day: Monitor Gogs GitHub repository for patch release and CVE assignment; prepare for immediate deployment.
  • Dell Container Storage Modules: CERT.BE issued critical warning regarding information disclosure vulnerability (CVE: see source); monitor Dell Security Advisory portal for patches.
  • FIFA World Cup fraud: FBI warns of fraudulent websites impersonating FIFA to steal credentials and sell counterfeit tickets for 2026 tournament; educate users to verify official channels.
  • Carnival Corporation breach: ShinyHunters claims breach affecting nearly 6 million people; organizations in travel/tourism sector should review data protection controls.

---

Sources

  • BleepingComputer: GreyVibe hackers, FortiClient EMS exploitation, Gogs zero-day, Romanian sentencing, Carnival breach, GPU mining malware, Glassworm disruption, Silent Ransom Group, CISA cPanel directive
  • The Hacker News: Gogs RCE, FortiClient EMS exploitation, JINX-0164, Grandoreiro/BTMOB campaigns, npm package theft, GlassWorm takedown, Gitea vulnerability, AI chatbot cryptojacking
  • Microsoft Security: The Gentlemen ransomware analysis
  • CERT.BE (Belgium): Starlette/FastAPI, LiquidJS, Dell Container Storage Modules, Apache ActiveMQ, Microsoft SharePoint vulnerabilities
  • CERT.PL (Poland): Kidsview (CVE-2026-8990), bzip2 (CVE-2026-42250) vulnerabilities