Rosetta Daily · May 25, 2026
Auto-generated · 29 sources configured (WebSearch mode — feed allowlist still in effect) · 17 items selected
Window: past 24-48 hours (2026-05-23 → 2026-05-25)
In-the-Wild / Actively Exploited
-
🔴🔥⚠️ CVE-2026-48172 — LiteSpeed cPanel Plugin privilege escalation to root (CVSS 10.0, actively exploited)
LiteSpeed has confirmed that a maximum-severity flaw in its User-End cPanel Plugin is already being exploited in the wild. The root cause is thelsws.redisAbleJSON-API endpoint, which is exposed to every logged-in cPanel user by default — any cPanel user (or a compromised account) can run arbitrary scripts as root, giving full server takeover on shared hosting. Affected: plugin versions 2.3–2.4.4. Patch immediately to plugin v2.4.7+ (WHM 5.3.1.0). Because cPanel is ubiquitous in budget/SMB hosting, expect mass scanning and opportunistic backdooring of shared servers within days.
The Hacker News · Cyber Security News · Cyberpress -
🔴🔥⚠️ CVE-2025-34291 — Langflow account takeover + RCE added to CISA KEV (5/21, CVSS 9.4)
CISA added the Langflow origin-validation/CORS chain to KEV on 5/21. The bug is a chain of three weaknesses — overly permissive CORS with credentials, missing CSRF protection on the refresh-token endpoint (SameSite=None), and a code-execution endpoint exposed by design — letting an attacker who lures a logged-in Langflow operator to a malicious page steal refresh tokens and execute Python in the workflow runner. Active exploitation in the wild since 2026-01-23, PoC code circulating. Langflow is one of the most popular AI agent frameworks, so this is the practical face of "agent platform = unauthenticated RCE pivot." Federal agencies must remediate per KEV deadline.
The Hacker News · Crowdsec — vuln tracking · Obsidian Security analysis -
🔥⚠️ CVE-2026-34926 — Trend Micro Apex One on-prem directory traversal added to CISA KEV (5/21, CVSS 6.7)
Apex One on-prem (2019 builds <17079) ships a relative-path-traversal bug that lets a pre-authenticated local admin overwrite a key database table on the server, then push that injected code to every connected endpoint agent via the normal agent deployment channel. Effectively an EDR-as-distribution-channel attack. CISA confirms at least one in-the-wild attempt; three public PoCs on GitHub. Federal remediation deadline: 2026-06-04. Patch to ≥14.0.0.17079. For Apex One operators this also means review whose admin creds are reachable from the management network — the bug needs admin, but admin on Apex One typically lives in the same trust zone as Active Directory accounts attackers already harvest.
Cyber Security News · SecurityWeek · CVE feed
Critical Vulnerabilities & Advisories
-
Drupal Core CVE-2026-9082 (still expanding) — Imperva now reporting 25,000+ exploit attempts
Tracking update on yesterday's KEV addition: Imperva, Cloudflare and Akamai are now jointly reporting >25k attack attempts against ~9k distinct PostgreSQL-backed Drupal sites across 70+ countries within 72 hours of disclosure. Patch coverage is uneven; managed-hosting providers report only ~55% of customer sites are on a fixed Drupal release. If you run Drupal+PG, treat as urgent.
Tenable · Imperva -
Oracle moves to monthly Critical Security Patch Updates (first one: 5/28)
Oracle is changing patch cadence after 22 years of pure quarterly CPUs. Starting 2026-05-28, monthly CSPUs land on the third Tuesday of most months between the existing quarterly windows. Oracle's stated reason: AI-assisted vulnerability discovery (they explicitly cite using Claude Mythos Preview and OpenAI frontier models via Trusted Access for Cyber) has compressed the disclosure-to-exploit window enough that quarterly cadence is no longer safe. Operationally: plan for ~12 patch windows/year instead of 4, with smaller per-window scopes.
Oracle security blog · Help Net Security · daily.dev summary
Vendor Advisories
- Microsoft Exchange CVE-2026-42897 — automatic mitigation now widely deployed; KEV deadline 5/29
No code-level patch yet for the OWA XSS/spoofing zero-day. Microsoft's Emergency Mitigation Service has pushed automatic mitigation M2.1.x to all enrolled on-prem Exchange tenants this week. Verify M2.1.x is applied — TechCommunity has the verification commands. Federal KEV deadline is 2026-05-29 (Friday).
MSRC· Microsoft TechCommunity· The Hacker News (exploit path)
Web Security Research
-
PortSwigger — "3 ways custom scan checks turn practitioner knowledge into scalable automation"
PortSwigger argues that senior pentesters' implicit checklists are the single biggest source of missed bugs in standardized scanners. The post walks through three patterns for converting that intuition into reusable Burp custom scan checks: (1) "weird response → secondary probe" patterns, (2) chained authentication-state checks, (3) per-tech-stack triggers. Worth reading for anyone running an AppSec program — most of the leverage is in turning your 1–2 best testers' notes into checks the whole team gets for free.
PortSwigger blog · research home -
Trail of Bits — zizmor now validated against 41,253 real-world GitHub Actions workflows
Alexis Challande shipped an upgrade to zizmor, the GitHub Actions static analyzer, focused on YAML anchors (the source of a large class of false negatives in CI security tooling). Tested on 41k+ public workflows from high-value OSS projects, which is also a useful corpus for anyone studying CI/CD attack surface in the wake of the TanStack / Nx Console supply-chain attack last week. Companion posts this week: gosentry (a fuzzing-oriented fork of the Go toolchain) and a walkthrough of Linux ping / Windows-driver C/C++ challenges.
Trail of Bits blog · TanStack postmortem (context)
AI Security
-
⚠️ Anthropic Project Glasswing — Claude Mythos has now surfaced 10,000+ high/critical vulnerabilities in ~30 days
Anthropic disclosed yesterday that Project Glasswing, its restricted vulnerability-discovery program built around the unreleased Claude Mythos Preview model, has flagged 10,000+ high- or critical-severity candidates across "systemically important" software since the program went live in April. Of those, 1,726 validated true positives, 1,094 confirmed high/critical, 97 patched. Notable finds include a 27-year-old OpenBSD bug and a 16-year-old FFmpeg bug that survived every prior round of human review. Distribution is restricted to ~50 strategic partners; public release of Mythos is paused for safety. The practical implication for defenders: the patch backlog is now structurally larger than maintainers can absorb. Some OSS maintainers have asked Anthropic to slow disclosures.
Anthropic — Project Glasswing · The Next Web · Cyber Security News · Engadget -
⚠️ Google: malicious prompt-injection payloads on the web up 32% since November
Google's web-monitoring team reports a 32% rise in prompt-injection payloads embedded in public web content between November 2025 and February 2026 — i.e. attackers are seeding the open web with payloads tuned for browsing/agentic AI clients. Sophistication remains relatively low (most are still "ignore previous instructions" descendants), but volume and targeting are increasing. Pair this with the HiddenLayer 2026 AI Threat Landscape Report finding that 1 in 8 AI breaches now involve agentic systems for context.
SecurityWeek · HiddenLayer 2026 AI Threat report
Threat Intelligence
-
DFIR Report — full deconstruction of "The Gentlemen" RaaS intrusion (5/22 publication)
The DFIR Report (with Check Point Research) released a detailed intrusion analysis of an affiliate of The Gentlemen RaaS — currently growing fast (≈320 publicly-claimed victims, mostly 2026). Notable TTPs: SystemBC SOCKS5 proxy malware with RC4-encrypted C2; final ransomware delivery via Group Policy / GPO so the binary executes on every domain-joined system during the next policy refresh. The DFIR Report's writeup includes full IOCs, ATT&CK mapping, and detection opportunities.
The DFIR Report — The Gentlemen analysis · DFIR Report homepage -
Trend Micro — China-aligned APT "SHADOW-EARTH-053" exploiting on-prem Exchange + IIS across Asia + Poland (NATO)
New cluster active since December 2024, going after government and defense ministries in Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lanka, Taiwan, and Poland, plus journalists and diaspora activists. TTPs: N-day exploits on internet-exposed Microsoft Exchange + IIS → Godzilla web shells → ShadowPad via DLL sideloading of signed binaries. The pairing of government targets with diaspora targets is consistent with PRC transnational-repression doctrine. If you operate on-prem Exchange in any of the listed countries, hunt for Godzilla/ShadowPad indicators now.
The Hacker News · The Diplomat — strategic context -
Mandiant M-Trends 2026 — "PROMPTFLUX/PROMPTSTEAL" malware querying LLMs mid-execution; backup-targeting becomes mainstream
M-Trends 2026 (5/22) confirms attackers now embed LLM API queries inside running malware to evade signature/behavioral detection (PROMPTFLUX, PROMPTSTEAL families). Separately, ransomware operators are deliberately destroying recovery infrastructure first (REDBIKE/AGENDA = Akira/Qilin). The report is grounded in 500,000+ hours of incident-response data from 2025, so trends are well-evidenced. Recommended reading for IR teams.
Google Cloud blog — M-Trends 2026 ·
Chinese-Language Community Picks
- Ongoing coverage this week from FreeBuf / Anquanke / Yijing Lab and others: CVE-2026-9082 Drupal SQLi, CVE-2026-29202 cPanel & WHM Perl code injection, CVE-2026-0073 Android ADB authentication-bypass zero-click RCE, the Grav CMS unauthenticated exploit chain, a 21-year-old PHP
unserialize()UAF that bypassesdisable_functionsfor RCE, and Nginx CVE-2026-42945(CVSS 9.2) — the "18 years unpatched" RCE that set the Chinese-language sphere alight; domestic estimates put roughly 2.54 millionChinese websites in scope. - BitUnlocker tool: a downgrade attack on BitLocker — exploiting the window between patch and certificate revocation to physically crack an already-patched Windows 11 encrypted volume in five minutes; picked up by multiple Chinese-language outlets.
- HiddenLayer's report on the Hugging Face counterfeit OpenAI "Privacy Filter" supply-chain poisoning (disclosed 5/7)continues to reverberate among domestic developers.
FreeBuf· Yijing Lab daily
Ransomware Today
- ~40 new DLS posts in last 24hacross 91 active leak sites. Top actors: Qilin (5), Akira (5), Genesis (7 — new high), CoinbaseCartel (4), Lamashtu (4). Continued dominance by Qilin (1,733 tracked victims YTD)and Akira (1,299). The Gentlemen affiliates continue posting despite the 5/5 internal leak — confirms the 90/10 affiliate split is keeping retention.
- Full per-victim breakdown + watchlist hits → intel/ransomware/daily/2026-05-25.html
AI Frontier
OpenAI
- GPT-5.5 Instant— new default ChatGPT model, replaces GPT-5.3 Instant. Reduced hallucination on legal/medical/finance with maintained low latency. GPT-5.5 Instant
- ChatGPT Personal Finance (preview)— Pro users (US) can connect bank/brokerage via Plaid (12,000+ institutions: Schwab, Fidelity, Chase, Robinhood, Amex, Capital One). TechCrunch
- Realtime voice models in the API— reasoning + translation + transcription in one pipeline.
- OpenAI becomes a C2PA Conforming Generator Product— content provenance for ChatGPT outputs.
- GPT-5.5-Cyberbehind restricted access (similar to Anthropic Glasswing model). The Register
Anthropic
- Project Glasswing update (5/23)— 10,000+ vulnerabilities flagged in 30 days via Claude Mythos Preview. See AI Security above.Glasswing
- Claude Opus 4.7— GA, materially better on hard SWE tasks; safety profile comparable to 4.6. Opus 4.7
- Claude Security (public beta)— scanning, triage, fix-generation for security teams. Cyber Verification Tools available to eligible teams.
- Claude for Small Business— first-party integrations with QuickBooks, PayPal, HubSpot, Canva, Docusign, Google Workspace, M365.
- Managed Agents now get MCP tunnels + self-hosted sandboxes(5/19) — eases enterprise deployment of agentic Claude. 9to5Mac
Google DeepMind / AI
- Gemini 3.5 family (3.5 Flash first)— frontier intelligence "with action," targeted at long-horizon agents + coding. (5/19) Gemini 3.5
- Co-Scientist— multi-agent research partner published in Nature(5/19). Co-Scientist
- Project Genie + Street View— generative world simulation grounded in real imagery.
- Singapore national AI partnership(5/20) — health, education, workforce.
Failed Sources
- RansomLook API + RSS— blocked by sandbox egress allowlist (HTTP 403 from proxy). Ransomware section uses WebSearch aggregation of secondary sources; full per-victim accuracy not guaranteed.
Sources used: see intel/sources.yaml