SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 98

2026-05-25T02:51:46Z085605c995a4f1c50040462b7b8cf07f07b6d6ea8b1388ca8dd7294d269dc5f5
APTCISACVE-2025-34291CVE-2026-9082Known-Exploited-Vulnerabilitiesactive-exploitarrestbotnetc2-infrastructurecobalt-strikedrupalghostwritergithub-action-compromisehunt.iokimwolfnode-ipcnpm-compromisepatching-gapphishingpure-extortionransomwaresql-injectionsupply-chaintelecom-hostingvulnerability-discovery

What happened

Security Affairs roundup: Drupal disclosed a highly critical SQL injection (CVE-2026-9082, CVSS 9.8) that is already being actively exploited and was added to CISA’s Known Exploited Vulnerabilities catalog. CISA also added other high‑severity flaws (including CVE-2025-34291) affecting products such as Trend Micro Apex One and Langflow. Other notable items: Anthropic’s Project Glasswing found 10,000+ high/critical vulnerabilities highlighting a major patching gap; multiple supply‑chain compromises (infected node-ipc npm package, compromised @antv npm packages, a hijacked GitHub Action); Ghostwr

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
085605c995a4f1c50040462b7b8cf07f07b6d6ea8b1388ca8dd7294d269dc5f5
Enrichment time
2026-05-25T02:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 98 · Baitaphish