SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 98
2026-05-24T14:51:52Z•d46f6a34cbfbbaadd4569ad8da9176e54acd8108e0548bbfdeed9f90e354c777
actions-coolactive-exploitationanthropic-glasswingantvbotnetcisa-kevcobalt-strikecredential-stealercve-2025-34291cve-2026-9082ddosdrupalghostwritergithub-action-compromisekimwolfnode-ipcnpmpatching-gapphishingshai-hulud-clonessupply-chain-attackteamPCPtrend-micro-apex-one','langflow','c2-infrastructure','middleeastuac-0057vulnerability-discovery
What happened
Security Affairs round-up highlighting multiple high-impact incidents: Drupal SQLi CVE-2026-9082 (CVSS 9.8) is being actively exploited within 48 hours of patch release and was added to CISA’s KEV catalog; CISA also added flaws including CVE-2025-34291 (Trend Micro Apex One / Langflow). Anthropic’s Project Glasswing found 10,000+ high/critical vulnerabilities, underscoring a major patching gap. Several supply-chain compromises and malware campaigns were reported — infected node-ipc npm package with a credential stealer, antv npm packages and a GitHub Action (actions-cool/issues-helper) tamper,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- d46f6a34cbfbbaadd4569ad8da9176e54acd8108e0548bbfdeed9f90e354c777
- Enrichment time
- 2026-05-24T14:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.