Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

    May 30, 2026

    Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter

    May 30, 2026

    CVE-2026-10127 | THREATINT

    May 30, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»InfoSec News Nuggets 05/15/2026
    News

    InfoSec News Nuggets 05/15/2026

    adminBy adminMay 15, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Microsoft Warns of Exchange Server Zero-Day Exploited in the Wild

    Microsoft warned that attackers are exploiting CVE-2026-42897, an on-prem Exchange Server flaw affecting Exchange Subscription Edition, 2016, and 2019. The issue is a spoofing and cross-site scripting vulnerability that can be triggered through a specially crafted email viewed in Outlook Web Access under certain conditions. Exchange Online isn’t affected, but organizations running on-prem Exchange should apply Microsoft’s temporary mitigations, confirm Exchange Emergency Mitigation Service coverage, and watch for follow-on guidance until a permanent patch is available.

     

    Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities

    Cisco Talos is tracking active exploitation of CVE-2026-20182, an authentication bypass flaw in Cisco Catalyst SD-WAN Controller and Manager that can let a remote unauthenticated attacker gain administrative privileges. Talos ties the activity to UAT-8616 and says the same actor has attempted to add SSH keys, modify NETCONF configurations, and escalate privileges. This matters because SD-WAN control infrastructure sits close to routing, segmentation, and branch connectivity, so compromise can create broad operational and lateral movement risk.

     

    Popular node-ipc npm Package Infected with Credential Stealer

    Socket found malicious versions of the widely used node-ipc npm package that contain obfuscated stealer and backdoor behavior. The affected versions are node-ipc 9.1.6, 9.2.3, and 12.0.1, and the malware attempts to fingerprint systems, read local files, package collected data, and exfiltrate it through attacker-controlled infrastructure. Development teams should block the affected versions, audit recent installs, and rotate exposed developer, cloud, CI/CD, and source control credentials if the package was used.

     

    Help-Desk Lures Drop KongTuke’s Evolved ModeloRAT

    ReliaQuest reported that the KongTuke initial access broker has moved into external Microsoft Teams chats to impersonate help desk staff and push users into running malicious PowerShell commands. The campaign delivers an evolved ModeloRAT payload with stronger persistence, multiple access paths, and a more resilient command-and-control setup. This is practical for defenders because Teams federation and external chat permissions are now part of the initial access surface, not just collaboration settings.

     

    Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin

    Attackers are exploiting CVE-2026-8181, a critical authentication bypass flaw in the Burst Statistics WordPress plugin that can allow admin impersonation through REST API requests. The plugin is active on roughly 200,000 WordPress sites, and Wordfence reported thousands of blocked attacks shortly after disclosure. Site owners should update to version 3.4.2 or disable the plugin, then review admin accounts, new user creation, redirects, and unexpected plugin or theme changes.

    The post InfoSec News Nuggets 05/15/2026 appeared first on AboutDFIR – The Definitive Compendium Project.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article2024-03-22: GoA SMS Phishing Scam & Spoofed Website
    Next Article ZDI-26-316: Siemens Simcenter Femap IPT File Parsing Memory Corruption Remote Code Execution Vulnerability
    admin
    • Website

    Related Posts

    News

    Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

    May 30, 2026
    News

    New CIFSwitch Linux flaw gives root on multiple distributions

    May 30, 2026
    News

    ‘Highly Plausible’ Aliens on Europa Are Earthlings’ Descendants, Study Says

    May 30, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Our Picks

    Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

    May 30, 2026

    Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter

    May 30, 2026

    CVE-2026-10127 | THREATINT

    May 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.