⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
2026-05-25T19:24:10Z•d786f5890829d39e500a35648df4651874c0fc95fa3887b009072cafaf83cfce
cisa-kevcrates-iocredential-theftgit-integritygithub-breachincident-responselaravel-langlazaruslinux-kernelmegalodonmemory-only-malwarenpmnx-consolepackagistprivilege-escalationpypiratremote-code-executionremotepeshowboatsql-injectionsupply-chainsupply-chain-attacktrapdoorvulnerability-disclosure
What happened
Weekly security recap: multiple active exploits, high-severity disclosures, and widespread supply‑chain campaigns. Notable incidents include exploitation of Ghost CMS (CVE-2026-26980, SQL injection) to inject malicious JS for ClickFix attacks; LiteSpeed cPanel plugin (CVE-2026-48172) being exploited for root script execution; Drupal Core (CVE-2026-9082) added to CISA KEV for active SQLi exploitation; Cisco Secure Workload REST API (CVE-2026-20223, CVSS 10.0) patched for unauthenticated data access; a 9‑year Linux kernel flaw (CVE-2026-46333) enabling local root; Microsoft Defender privilege-es
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- d786f5890829d39e500a35648df4651874c0fc95fa3887b009072cafaf83cfce
- Enrichment time
- 2026-05-25T19:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.