Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

    May 30, 2026

    Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter

    May 30, 2026

    CVE-2026-10127 | THREATINT

    May 30, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»InfoSec News Nuggets 05/26/2026
    News

    InfoSec News Nuggets 05/26/2026

    adminBy adminMay 26, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning

    Researchers tied a fresh Nimbus Manticore campaign to phishing and SEO poisoning targeting aviation, software, telecom, and oil and gas organizations across the U.S., Europe, and the Middle East, using fake career lures, trojanized Zoom and SQL Developer installers, and new backdoors called MiniFast and MiniJunk V2, with evidence suggesting AI assisted some malware development. The campaign is notable for its move beyond direct phishing into search-driven software impersonation — a technique that can catch developers and technical users during routine work rather than requiring a targeted spear-phish. Organizations in the targeted sectors should scrutinize software downloads from search results, particularly installer packages for common developer and collaboration tools.

     

    Ghost CMS Flaw Abused to Push ClickFix Attacks on Hundreds of Sites

    Attackers are exploiting CVE-2026-26980, a patched Ghost CMS SQL injection flaw, to compromise more than 700 unpatched websites — including university sites — by exposing the Admin API key and using it to inject malicious JavaScript that redirects visitors into ClickFix-style malware execution flows. The attack chain is particularly effective because compromised sites appear legitimate, and visitors have no obvious reason to distrust content on a university or established organization’s domain. Site owners running Ghost should patch immediately, rotate any exposed Admin API keys, review recent content changes, and inspect published pages for injected scripts.

     

    NIST Publishes SP 1800-41 Draft to Focus on Ransomware Response and Operational Recovery in Manufacturing Networks

    NIST released a draft practice guide aimed at helping manufacturers respond to and recover from cyberattacks affecting ICS and OT environments, with guidance covering ransomware response, operational recovery, log review, event analysis, restoration planning, and continuity for industrial processes. The guide is notable for treating recovery as an operational requirement rather than a post-incident IT task, which better reflects the reality that production downtime carries direct financial and safety consequences in manufacturing environments. Critical infrastructure and manufacturing security teams should review the draft and use the comment period to shape guidance that reflects real-world constraints.

     

    ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains

    Researchers described Underminr, a CDN and shared-hosting abuse technique that makes malicious traffic appear to connect to trusted domains while actually reaching attacker-controlled infrastructure, exploiting the gap that arises when defenders don’t correlate DNS decisions, edge IPs, SNI, Host headers, and CDN tenant routing together. The technique can bypass DNS filtering and protective DNS controls that operate in isolation, which is a meaningful gap in environments where those tools are treated as a primary egress control. High-risk environments should complement DNS filtering with full egress inspection that accounts for CDN routing behavior, and detection engineers should review whether their C2 detection logic accounts for this class of traffic blending.

     

    Suspected KimWolf Botnet Admin Arrested Over DDoS-for-Hire Operation

    U.S. and Canadian authorities arrested a Canadian man accused of operating the KimWolf DDoS botnet, which infected more than one million IoT devices including digital photo frames and web cameras and rented them out through a cybercrime-as-a-service model to carry out attacks against victims worldwide, including Department of Defense network addresses. The case is a reminder that unmanaged and poorly secured consumer IoT devices remain a reliable recruitment pool for large-scale criminal services, even when they sit behind home or small-business networks with no visibility or logging. Organizations with IoT exposure — whether through employee devices, facility equipment, or supply chain connections — should treat unmanaged endpoints as potential botnet infrastructure rather than low-risk background noise.

    The post InfoSec News Nuggets 05/26/2026 appeared first on AboutDFIR – The Definitive Compendium Project.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleDebian Trixie SPIP Multiple Critical Remote Code Exec Issue DSA-6296-1
    Next Article ABB LVS MConfig | CISA
    admin
    • Website

    Related Posts

    News

    Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

    May 30, 2026
    News

    New CIFSwitch Linux flaw gives root on multiple distributions

    May 30, 2026
    News

    ‘Highly Plausible’ Aliens on Europa Are Earthlings’ Descendants, Study Says

    May 30, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Our Picks

    Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

    May 30, 2026

    Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter

    May 30, 2026

    CVE-2026-10127 | THREATINT

    May 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.