SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 97
2026-05-17T14:51:44Z•06eac2533d25fe2612135039cd0b483c7a35bc25199085ff627c075e0a646a67
CISA KEVCVE-2026-41940CVE-2026-42897FrostyNeighborFunnel BuilderGhostwriterJDownloaderKazuarMicrosoft ExchangeMr_Rot13OpenAIP2P botnetPwn2Own Berlin 2026Python RATTanStackTrickMoTurlaWooCommerceactive exploitationbanking malwaree-skimmersupply chain attackzero-dayzero-days
What happened
This Security Affairs roundup highlights multiple high-risk incidents: Microsoft confirmed active exploitation of Exchange Server zero-day CVE-2026-42897 (added to CISA KEV), and threat actor Mr_Rot13 is actively exploiting CVE-2026-41940 for backdoor deployment. Other notable events include a WordPress Funnel Builder flaw being abused to inject e-skimmers into WooCommerce checkouts, a supply-chain compromise via malicious TanStack packages that impacted OpenAI (exposing repository credentials), the JDownloader site being hacked to replace installers with a Python RAT, and a new TrickMo mobile
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 06eac2533d25fe2612135039cd0b483c7a35bc25199085ff627c075e0a646a67
- Enrichment time
- 2026-05-17T14:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.