SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 98
2026-05-25T02:51:46Z•085605c995a4f1c50040462b7b8cf07f07b6d6ea8b1388ca8dd7294d269dc5f5
APTCISACVE-2025-34291CVE-2026-9082Known-Exploited-Vulnerabilitiesactive-exploitarrestbotnetc2-infrastructurecobalt-strikedrupalghostwritergithub-action-compromisehunt.iokimwolfnode-ipcnpm-compromisepatching-gapphishingpure-extortionransomwaresql-injectionsupply-chaintelecom-hostingvulnerability-discovery
What happened
Security Affairs roundup: Drupal disclosed a highly critical SQL injection (CVE-2026-9082, CVSS 9.8) that is already being actively exploited and was added to CISA’s Known Exploited Vulnerabilities catalog. CISA also added other high‑severity flaws (including CVE-2025-34291) affecting products such as Trend Micro Apex One and Langflow. Other notable items: Anthropic’s Project Glasswing found 10,000+ high/critical vulnerabilities highlighting a major patching gap; multiple supply‑chain compromises (infected node-ipc npm package, compromised @antv npm packages, a hijacked GitHub Action); Ghostwr
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 085605c995a4f1c50040462b7b8cf07f07b6d6ea8b1388ca8dd7294d269dc5f5
- Enrichment time
- 2026-05-25T02:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.