Infosecurity Europe
2026-05-20T14:51:42Z•507150b0cc822f80215addae2bf9af15d2a24412e3d814a760d778afdd2623d1
CISA-leakCVE-2026-42897Cisco SD-WANactive-exploitationai-agentsai-bomaptdirty-fragexchange-owafoxconnhugging-facehuggingface-tokenizerinterpol-operation-ramzlinux-privilege-escalationmacOS-stealernpm-wormransomwareshai-huludsupply-chainvulnerabilitieswindows-zero-dayzero-day
What happened
Collection of Dark Reading headlines covering a broad surge in active vulnerabilities, exploit activity, and emergent threats. Notable items include a Microsoft Exchange OWA XSS zero-day (CVE-2026-42897) under active attack, a CVSS 10.0 Cisco SD‑WAN flaw being exploited in the wild, multiple recently disclosed Windows zero‑days, and a renewed wave of self‑propagating supply‑chain worms (Shai‑Hulud/Mini Shai‑Hulud) affecting npm and other ecosystems. Other high‑risk incidents: CISA’s inadvertent public exposure of secrets in a repo, macOS backdoor/stealer campaigns (SHub Reaper), Linux local‑es
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 507150b0cc822f80215addae2bf9af15d2a24412e3d814a760d778afdd2623d1
- Enrichment time
- 2026-05-20T14:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.