Critical vm2 sandbox bug lets attackers execute code on hosts
2026-05-06T19:23:33Z•1a20cef5cb682d0a337986c9ea3156afdf59a42a95b27f9e28930b393d919be3
AcronisChaos ransomwareCiscoDAEMON ToolsInstructure breach claim','student-TETRA-rail-attack','Kochava-Linux malwareMuddyWaterNode.jsPAN-OSPalo AltoQuasar LinuxVimeobackdoorbackupsdata-breachdenial-of-servicefirewallransomwarereboot-requiredremote-code-executionsandbox-escapesupply-chaintrojanized-installervm2zero-day
What happened
Multiple high-impact incidents and zero-days reported: a critical vm2 Node.js sandbox vulnerability allows sandbox escape and arbitrary host code execution; Palo Alto Networks warns of an actively exploited PAN-OS User-ID Authentication Portal RCE zero-day; DAEMON Tools installers were trojanized in a supply-chain attack delivering a backdoor; and Cisco patched a DoS that requires manual reboot to recover. Other notable stories include a new Quasar Linux implant targeting developers, MuddyWater using Chaos ransomware as a decoy, large data theft claims at Instructure and a Vimeo breach, FTC's措
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 1a20cef5cb682d0a337986c9ea3156afdf59a42a95b27f9e28930b393d919be3
- Enrichment time
- 2026-05-06T19:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.