Rosetta Daily · May 23, 2026
Auto-generated · 29 sources configured (WebSearch mode — feed allowlist unavailable) · 14 items selected
Window: past 24 hours (2026-05-22 → 2026-05-23)
In-the-Wild / New CISA KEV
-
🔴🔥⚠️ CISA adds Microsoft Defender EoP + DoS to KEV (continued from 5/20 batch) — actively exploited
- CVE-2026-41091— Microsoft Defender local privilege elevation to SYSTEM. Confirmed active exploitation in the wild; Microsoft acknowledged and CISA promoted to KEV in this week's batch of seven additions (which also includes a set of legacy IE / DirectX / Adobe Reader entries being added retrospectively after fresh exploitation evidence).
- CVE-2026-45498— Microsoft Defender denial-of-service paired with the EoP. Combination used by attackers to blind the endpointthen escalate.
Patch via Microsoft Update; Defender's platform update channel pushes out-of-band.
Help Net Security· CISA Alert — 7-CVE batch· CISA Alert — Langflow + Apex One (5/21)
-
🔴⚠️ Microsoft Exchange Server OWA zero-day CVE-2026-42897 still under active exploitation — no permanent patch (continued)
Spoofing / XSS in the Outlook Web Access component of Exchange SE / 2019 / 2016. A crafted email viewed in OWA runs arbitrary JavaScript in the user's authenticated browser session — session-token theft, mailbox impersonation, silent inbox-rule manipulation. Mitigations Microsoft published last week have been shown to leave gaps (researchers found OWA paths the recommended URL-rewrite rules don't normalize). Treat any internet-reachable on-prem Exchange OWA as compromised until further notice; disable OWA where possible.
SecurityWeek · TechTimes — mitigation gaps · The Hacker News · SecurityAffairs
Critical Vulnerabilities
-
🔴 CVE-2026-9082 — Drupal Core SQL Injection (PostgreSQL backends, "highly critical")
Drupal security team published an out-of-cycle advisory: specially crafted requests yield arbitrary SQL injection on sites using PostgreSQL. Although the assigned CVSS is 6.5, Drupal's own risk rubric tags it "highly critical" because the injection primitive chains to information disclosure → privilege escalation → RCE. Patches available in 10.x and 11.x branches; MySQL/MariaDB sites are not affected by this specific vector but should still update. PoCs are circulating in private channels.
The Hacker News daily recap — 5/22 · Hendry Adrian daily recap 5/21 -
🔴 CVE-2026-20182 — Cisco Catalyst SD-WAN Controller / Manager authentication bypass (CVSS 10.0)
Sixth Cisco SD-WAN zero-day this cycle. Maximum-severity unauthenticated bypass of the API authentication layer in vSmart / vManage; an attacker with network reach to the management plane gets administrative API control. Cisco PSIRT advisory live; this should be patched at the same urgency as your last firewall zero-day, not next maintenance window.
Cisco Security Advisory · Help Net Security — week in review · OpenVPN blog roundup -
⚠️ Cisco Secure Workload REST API privilege bypass
Insufficient validation and authentication in the Secure Workload (formerly Tetration) REST API let a remote attacker obtain Site Admin privileges. Hardening advisory issued; impact for environments using Secure Workload as the policy oracle is significant because Site Admin = full segmentation control.
The Hacker News recap -
⚠️ CVE-2026-46333 — Linux kernel local privilege escalation (CVSS 5.5)
Improper privilege-management flaw lets an unprivileged local user on default installations of . Lower CVSS but practical impact on multi-tenant or shared-developer hosts is high. Track distro backports.
Vendor Advisories
-
Chrome — 200+ vulnerabilities credited "reported by Google" in this month's releases
Google continues an aggressive internal-fuzzing cadence; this week's stable channel push includes a large batch of memory-safety fixes (most flagged as integer-overflow / use-after-free in V8 and Skia). Auto-update should already be rolling — verify enterprise-managed Chrome installs are not pinned to an old branch.
Daily recap aggregation -
Trend Micro Apex One on-prem ≥ 14.0.0.17079 — patch for CVE-2026-34926 (KEV-listed; see yesterday's brief).
Web Security Research
-
PortSwigger Research — "3 ways custom scan checks turn practitioner knowledge into scalable automation" (5/1, ongoing community engagement)
How senior pentester intuition (especially for custom auth schemes, JWT-handling quirks, and tenant-isolation bugs) is encoded into Burp custom scan checks. Practical patterns: regex-anchored signature matches, oracle-style differential checks, and authenticated-only follow-up requests. Useful read if you are operationalizing your bench's tribal knowledge.
PortSwigger Research -
Pwn2Own Berlin 2026 fallout — xchglabs "retaliatory disclosure" drop of 86 vulns
After Pwn2Own Berlin sold out for the first time in its 19-year history and locked out walk-up researchers, the xchglabs team publicly released technical details on 86 vulnerabilities spanning NVIDIA drivers, Docker, Linux KVM, and PyTorch. Mix of memory-corruption and logic bugs; vendors had no advance notice. Expect 2–3 weeks of exploit-availability turbulence.
FreeBuf coverage (中文)
AI Security
-
⚠️🛡 Forcepoint X-Labs — "10 Indirect Prompt Injection Payloads Caught in the Wild" (5/21)
First public field-evidence report on production Indirect Prompt Injection (IPI) payloads found embedded in real, indexable web pages targeting AI agents. The ten cataloged payloads include: hidden Markdown comments that issue tool-call instructions, CSSdisplay:none"agent-only" sections, base64-encoded directives in alt-text, JSON-LD schema poisoning, and invisible Unicode tag-character payloads that bypass naive sanitization. IPI is no longer theoretical — it is being deployed at scale against browsing and shopping agents.
Digital Journal — coverage of the Forcepoint report · Repello AI — jailbreak techniques companion read -
⚠️🛡 Homotopy-style prompt obfuscation hits 76% jailbreak success across evaluated frontier models
New 2026 benchmark paper introduces an attack that systematically deforms prompts through chained linguistic transformations (rewording → translation pivot → noise injection → semantic re-anchoring), achieving a 76% jailbreak success rate on a panel of evaluated production LLMs. Companion line of research — autonomous "jailbreak agents" (Nature Communications, March 2026) — already reported 97.14% success in some configurations. Direction of travel: alignment-only defenses keep losing ground; runtime guard-rails + provenance + capability-scoping are the survivable layer.
arXiv survey · MDPI review — attack vectors + defenses · arXiv: LLM analysis against PI/jailbreak -
🛡 HiddenLayer typosquat on Hugging Face — supply-chain poisoning targeting AI devs (continued coverage)
Earlier in May (5/7) HiddenLayer flagged a typosquat of OpenAI's Privacy Filter project uploaded to Hugging Face as a malicious repository targeting AI development pipelines. Reinforces M-Trends 2026's thesis that the AI tooling supply chain is now a first-class adversary surface. Inventory your / lines that point into HF / GH org-typosquat zones.
Threat Intelligence
-
Mandiant / GTIG — M-Trends 2026 expansion: 22-second adversary hand-off + GRIDTIDE follow-on
Follow-on coverage of the M-Trends 2026 release: median time from initial access to hands-on-keyboard lateral movement is now 22 seconds for the most-mature criminal groups. China-nexus GRIDTIDE (UNC2814) disruption count revised: 53 confirmed victims across 42 countries at the moment of takedown. Edge-device targeting (VPNs / routers without EDR telemetry) by UNC6201 and UNC5807 continues to dominate the espionage caseload.
M-Trends 2026 — Google Cloud Blog · ComplexDiscovery — 22-second hand-off · SecurityBrief AU · Disrupting GRIDTIDE -
Mandiant — PROMPTFLUX / PROMPTSTEAL: malware families that call LLMs at runtime
GTIG tracks two malware families that query Gemini API at runtime: PROMPTFLUX uses the model to rewrite its own source code hourly (polymorphism via LLM); PROMPTSTEAL uses model output to dynamically construct exfiltration payloads. Both demonstrate the offensive operationalization of LLMs beyond simple lure-generation. Detection guidance: outbound calls to model-provider APIs from non-AI-workload hosts is now a useful EDR signal.
Adversaries Leverage AI — Google Cloud Blog
Chinese-Language Community Picks
- FreeBuf — Pwn2Own Berlin retaliatory disclosure / BitUnlocker / Android adbd zero-click / cPanel triple patch / HiddenLayer HF poisoning
FreeBuf tracked five overseas incidents this week: the xchglabs team publicly released 86 Pwn2Own candidate vulnerabilities; BitUnlockerexploits the timing gap between patch rollout and certificate revocation to downgrade-decrypt an already-patched Windows 11 BitLocker volume within five minutes; Google's May Android Security Bulletin disclosed a zero-click flaw in the adbd daemon, CVE-2026-0073— a proximate attacker gains a shell with no interaction; cPanel simultaneously fixed three high-severity issues, CVE-2026-29201/2/3(privilege escalation, code execution, DoS); and HiddenLayer disclosed the 5/7 typosquat poisoning of an OpenAI Privacy Filter package on Hugging Face.
FreeBuf· FreeBuf weekly repost
Ransomware Today
Active leak-site posting continues at the Q1 elevated tempo (ReliaQuest: +22% YoY in DLS posts). New victims observed on 2026-05-21 / early 5-22:
- Qilin: CJ Architects (US, architecture), CZ Collections (NY, fashion/apparel)
- PEAR: Exchange Group (Canada, financial services), Fana Jewelry (NY, luxury), ProFarm Group (CA, agri-tech)
- TheGentlemen: Grupo Pasquel (construction / hardware retail)
- LockBit(5.0 variant resurgence): Shottermill Junior School(UK state-funded primary education — watchlist hit:
sector:education)
Active groups this week (top by DLS volume): Qilin, TheGentlemen, Akira, with secondary activity from Inc Ransom, Clop, Play, Nightspire, DragonForce, Sinobi.
Full table + watchlist hits: intel/ransomware/daily/2026-05-23.html
Ransomware.live · RansomLook · Check Point — Q1 2026 state of ransomware
AI Frontier
OpenAI
- GPT-5.5 Instant (5/5, ongoing rollout)— new default ChatGPT model: lower hallucination in law / medicine / finance, retained low latency. Releasebot — OpenAI· TechCrunch
- Voice Intelligence API (5/7)— realtime voice models that reason / translate / transcribe in-line. Releasebot — OpenAI
- Codex business workflows (5/14–5/15)— appshots, GA goal mode, browser-annotation tools, remote locked computer use, shared plugins, admin analytics for adoption tracking. Material for the agentic-coding side. Releasebot — OpenAI
- ChatGPT personal finance (5/15)— Plaid-backed bank connections in preview for Pro subscribers (US); 12,000+ institutions. TechCrunch
- OpenAI joins C2PA as Conforming Generator Product (5/19)— content-provenance signatures now travel with OpenAI-generated media. Direct defensive signal vs. AI-deepfake disinformation pipelines.Releasebot — OpenAI
Anthropic
- Claude for Small Business (5/13)— packaged connectors + run-ready workflows for QuickBooks / PayPal / HubSpot / Canva / Docusign / Google Workspace / M365. Anthropic news· SiliconANGLE
- KPMG global alliance— Claude embedded inside KPMG's "Digital Gateway" with tax / legal tooling; rollout to 276,000+ employees globally. Anthropic announcement· KPMG press
- PwC expanded partnership— Claude Code + Cowork to PwC US, scaling toward hundreds of thousands of professionals. Anthropic announcement
- Code with Claude 2026 (5/6, SF)— Managed Agents, proactive workflows, dreaming, multi-agent orchestration, outcomes, webhooks; self-hosted sandboxesin public beta. InfoQ
- Project Glasswing partner consortiumcontinues to absorb Mythos Preview findings (see yesterday's AI-Security entry for the 500-zero-day disclosure).
Google DeepMind / AI
- Gemini 3.5 Flash + Ultra price cut to $200/mo + new $100/mo Developer tier (Google I/O 2026, 5/19–20)— Heygotrade I/O recap· CNBC· eWeek
- Gemini Spark agent— general-purpose Gemini-app agent that reasons across connected apps; beta to trusted testers + Ultra. CNBC
- Omni world model— physical-environment simulator added to Google's AI portfolio. CNBC
- Gemini Intelligence on premium Android + Chrome+ GooglebookGemini-first laptop preview (Android Show: I/O Edition, 5/12).
- 900M Gemini MAU (2× YoY); 2.5B AI Overviews MAU.
- DeepMind hires 20+ Contextual AI researchers ($80–90M licensing deal)— continued talent stockpiling for the agent-research stack.
- Project Zero — "A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens" (5/13)— chained two vulns in the new
/dev/vpudriver (Chips&Media Wave677DV on Tensor G5) for zero-interaction root. Project Zero post· CybersecurityNews
🛡 = security-relevant. Anthropic + Google security spinoff files live in
intel/ai-frontier/security/.
Failed Sources
The cowork-egress allowlist blocks direct RSS / HTML fetches for the configured feeds (only *.anthropic.com and a handful of package registries are reachable from the workspace's web-fetch). Today's brief was assembled from WebSearch summaries with linked primary sources instead of direct feed pulls. Sources affected:
cisa.gov(CISA KEV feed) — blocked at egressmsrc.microsoft.com(Microsoft MSRC blog) — blockedportswigger.net(PortSwigger Research) — blockedgoogleprojectzero.blogspot.com— blockedfeeds.feedburner.com(The Hacker News) — blockedbleepingcomputer.com— blockedkrebsonsecurity.com— blockedcloud.google.com(Mandiant blog) — blockedthedfirreport.com— blockedfreebuf.com— blockedopenai.com— blockeddeepmind.google/blog.google— blockedanthropic.com— reachable but page payload exceeded fetch limit (rendered HTML, no JS)
Recommended fix: add cisa.gov, *.cisa.gov, msrc.microsoft.com, portswigger.net, googleprojectzero.blogspot.com, projectzero.google, feeds.feedburner.com, *.bleepingcomputer.com, krebsonsecurity.com, cloud.google.com, blog.google, deepmind.google, openai.com, www.freebuf.com, www.ransomlook.io to the workspace egress allowlist (Settings → Capabilities).
Sources used: see intel/sources.yaml