SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 97

2026-05-18T02:51:44Z2b6a3158c1475764db3b05afe1a791bb68b510ae8fdb0e2d0b1875b88e0d35a2
cve-2026-41940cve-2026-42897e-skimmingfunnel-builderghostwriterjdownloaderkazuarknown-exploited-vulnerabilitymicrosoft-exchangemr_rot13openaipwn2ownpython-ratsupply-chaintanstacktrickmoturlawordpresszero-day

What happened

Multiple active and emerging threats reported: Microsoft Exchange Server zero-day CVE-2026-42897 (CVSS 8.1) is being actively exploited and was added to CISA’s KEV catalog; threat actor Mr_Rot13 is actively exploiting CVE-2026-41940 for backdoor deployment. Attackers are exploiting a critical WordPress Funnel Builder plugin vulnerability to inject e-skimmers into WooCommerce checkout pages. OpenAI suffered a TanStack supply-chain compromise that breached two employee devices and exposed repository credentials. Russia-linked APT Turla evolved its Kazuar backdoor into a stealthy P2P botnet for长期

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
2b6a3158c1475764db3b05afe1a791bb68b510ae8fdb0e2d0b1875b88e0d35a2
Enrichment time
2026-05-18T02:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.