Laravel Lang packages hijacked to deploy credential-stealing malware
2026-05-24T07:23:25Z•36796ce702506d1b64a5bc99b452e150a74d4829920f80409263cc48c8aaa893
apex-onebotnetchromiumcinemagoalcisco-secure-workloadcomposercredential-stealercrypto-drainerdrupalfirst-vpnfraud-preventionjfmbackdoorlaravellaw-enforcement-takedownmalwareprivilege-escalationremote-code-executionshowboatsql-injectionsupply-chaintelco-espionageubiquitiunifizero-day
What happened
Multiple high-impact security events reported: a supply‑chain compromise of Laravel Lang localization packages where attackers abused GitHub version tags to publish malicious Composer packages that deploy credential‑stealing malware; active exploitation of a Trend Micro Apex One zero‑day; a newly disclosed, actively targeted critical SQL‑injection flaw in Drupal; maximum‑severity UniFi OS vulnerabilities patched by Ubiquiti and a maximum‑severity privilege escalation in Cisco Secure Workload; an accidental leak of an unfixed Chromium flaw that could enable background JS RCE; newly observed tel
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 36796ce702506d1b64a5bc99b452e150a74d4829920f80409263cc48c8aaa893
- Enrichment time
- 2026-05-24T07:23:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.