China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts.

2026-05-22T08:51:42Za11f5a5f40e326a88b377c913f1d12bb8da6165f964576661b66fb28156015c6
API key reuseAPTCVE-2026-42897CVSS 10.0China-linkedCisco SD-WANDiscordGitHub breachGoogle API keysMicrosoft Graph APIOT/ICSRubyGemsSOCKS proxyShai-Hulud wormSoftEther VPNUnderminrWebwormcommand injectiondata breachdomain frontingransomware (Nitrogen) , Foxconnrobot OSsupply chaintunnelingzero-day

What happened

Aggregated DarkReading headlines (mid-May–May 22, 2026) cover a surge in high-impact cyber activity: a China-linked 'Webworm' APT leveraging Discord, Microsoft Graph APIs, and SOCKS/tunneling tools (SoftEther) to target EU governments; multiple critical and actively exploited vulnerabilities including Microsoft Exchange XSS (CVE-2026-42897), a CVSS 10.0 Cisco SD-WAN flaw, and an unauthenticated command-injection in an OT robot OS; high-profile breaches and supply-chain attacks (GitHub internal repo theft, weaponized RubyGems, Shai-Hulud worm code release); domain-fronting (Underminr) and macOS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
a11f5a5f40e326a88b377c913f1d12bb8da6165f964576661b66fb28156015c6
Enrichment time
2026-05-22T08:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.