SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 98

2026-05-24T14:51:52Zd46f6a34cbfbbaadd4569ad8da9176e54acd8108e0548bbfdeed9f90e354c777
actions-coolactive-exploitationanthropic-glasswingantvbotnetcisa-kevcobalt-strikecredential-stealercve-2025-34291cve-2026-9082ddosdrupalghostwritergithub-action-compromisekimwolfnode-ipcnpmpatching-gapphishingshai-hulud-clonessupply-chain-attackteamPCPtrend-micro-apex-one','langflow','c2-infrastructure','middleeastuac-0057vulnerability-discovery

What happened

Security Affairs round-up highlighting multiple high-impact incidents: Drupal SQLi CVE-2026-9082 (CVSS 9.8) is being actively exploited within 48 hours of patch release and was added to CISA’s KEV catalog; CISA also added flaws including CVE-2025-34291 (Trend Micro Apex One / Langflow). Anthropic’s Project Glasswing found 10,000+ high/critical vulnerabilities, underscoring a major patching gap. Several supply-chain compromises and malware campaigns were reported — infected node-ipc npm package with a credential stealer, antv npm packages and a GitHub Action (actions-cool/issues-helper) tamper,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d46f6a34cbfbbaadd4569ad8da9176e54acd8108e0548bbfdeed9f90e354c777
Enrichment time
2026-05-24T14:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 98 · Baitaphish