MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries
2026-05-26T19:24:12Z•da1276c4fca81f8e0ae6bc164860caefff1fdd68530f5f3ed1f79af53e0ff4ab
cert-incisa-kevcobalt-strikedll-side-loadingdrupalghost-cmsghostwritergithub-actionsknowledgedeliverlaravel-langlazaruslitespeed-cpanelmegalodonmuddywaternimbus-manticorenpmpackagistpatchingphishingproject-glasswingremotepeseo-poisoningsharepointsupply-chain-attacktrapdoor
What happened
The Hacker News roundup (26 May 2026) highlights multiple high-impact cyber incidents and active exploitation across enterprise and open-source ecosystems. Key items include an Iranian MuddyWater espionage campaign using DLL side‑loading across nine countries; multiple actively exploited or high-severity vulnerabilities (Microsoft SharePoint RCE CVE-2026-45659, Ghost CMS CVE-2026-26980, LiteSpeed cPanel plugin CVE-2026-48172, KnowledgeDeliver CVE-2026-5426, Drupal CVE-2026-9082, Cisco Secure Workload CVE-2026-20223); supply-chain campaigns (TrapDoor, Packagist infection, Laravel-Lang package &
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- da1276c4fca81f8e0ae6bc164860caefff1fdd68530f5f3ed1f79af53e0ff4ab
- Enrichment time
- 2026-05-26T19:24:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.