Infosecurity Europe

2026-05-20T14:51:42Z507150b0cc822f80215addae2bf9af15d2a24412e3d814a760d778afdd2623d1
CISA-leakCVE-2026-42897Cisco SD-WANactive-exploitationai-agentsai-bomaptdirty-fragexchange-owafoxconnhugging-facehuggingface-tokenizerinterpol-operation-ramzlinux-privilege-escalationmacOS-stealernpm-wormransomwareshai-huludsupply-chainvulnerabilitieswindows-zero-dayzero-day

What happened

Collection of Dark Reading headlines covering a broad surge in active vulnerabilities, exploit activity, and emergent threats. Notable items include a Microsoft Exchange OWA XSS zero-day (CVE-2026-42897) under active attack, a CVSS 10.0 Cisco SD‑WAN flaw being exploited in the wild, multiple recently disclosed Windows zero‑days, and a renewed wave of self‑propagating supply‑chain worms (Shai‑Hulud/Mini Shai‑Hulud) affecting npm and other ecosystems. Other high‑risk incidents: CISA’s inadvertent public exposure of secrets in a repo, macOS backdoor/stealer campaigns (SHub Reaper), Linux local‑es

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
507150b0cc822f80215addae2bf9af15d2a24412e3d814a760d778afdd2623d1
Enrichment time
2026-05-20T14:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Infosecurity Europe · Baitaphish