ALERT

ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know      ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks  •  How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts  •  The US military just turned off ad tracking on its phones. Maybe you should too  •  Hackers exploit Tencent app flaw to deploy GrayRabbit malware  •  CRPx0 ransomware: what you need to know

Home/The Wire/2026-05-26
▶The Wire — Daily Briefing

The Wire — Tuesday, May 26, 2026

Supply Chain Under Siege: When the Attack Surface Becomes the Attack Vector

19 stories analyzed

Supply Chain Under Siege: When the Attack Surface Becomes the Attack Vector

We are watching a strategic shift in how attackers target organizations, and the velocity is alarming. In the past 48 hours, we've tracked three separate coordinated campaigns—TrapDoor spreading across npm, PyPI, and Crates.io, Megalodon infecting 5,500 GitHub repositories, and Laravel-Lang packages poisoned for malware delivery—that share a common pattern: attackers are no longer trying to breach your perimeter. They're poisoning the supply chain that feeds into it. This is not noise. This is a fundamental restructuring of the threat landscape.

The appeal to attackers is clear. Why spend resources on defensive walls when you can slip malicious code into the foundations the walls are built on? TrapDoor alone affected 34 malicious packages across 384 versions. Megalodon injected GitHub Actions workflows designed to steal CI secrets, credentials, and tokens. These are not opportunistic compromises—they're surgical attacks on the infrastructure that matters: the things developers use every day to build, test, and deploy. Any organization using these ecosystems is potentially affected. That's millions of deployments.

What's enabling this acceleration? Part of it is detection: Anthropic's Mythos vulnerability detection model just identified 23,000 potential vulnerabilities across 1,000 open-source projects, many of them critical or high-severity. Vulnerability discovery has always been the bottleneck in exploitation. AI is removing that bottleneck. The time from "vulnerability exists" to "vulnerability is weaponized" is collapsing. And when you weaponize through the supply chain, your blast radius is enormous.

This vulnerability acceleration is playing out in real time across our coverage. CISA has ordered federal agencies to patch an actively exploited Drupal SQL injection vulnerability by Wednesday evening—treating it as a national security risk. A critical flaw in Ghost CMS (CVE-2026-26980) has already been exploited to compromise over 700 websites, including major institutions like Harvard, Oxford, and DuckDuckGo, with attackers injecting malicious JavaScript to fuel ClickFix attacks. KnowledgeDeliver LMS, a Learning Management System popular in Japan, had its high-severity vulnerability weaponized to deploy Godzilla and Cobalt Strike. The timeline from vulnerability disclosure to live exploitation is now measured in hours or days, not weeks.

The human cost is accumulating in parallel. Retail and healthcare organizations continue to pay the price. 7-Eleven disclosed a breach affecting 185,000 people after attackers from the ShinyHunters extortion gang compromised their systems in April. The data is just now being revealed—a reminder that breaches are not discrete incidents but ongoing exposures. In healthcare, Radiology Associates of Richmond reported a breach affecting 266,000 individuals with protected health information, and The Oncology Institute disclosed a breach involving a third-party vendor (likely TriZetto). Healthcare providers remain the highest-value targets for attackers because the data doesn't lose value—medical records are purchased on the dark market for years.

State-sponsored threats are operating with renewed boldness. The Iranian state-sponsored actor Nimbus Manticore has deployed MiniFast and MiniJunk V2 in fresh campaigns using phishing and SEO poisoning, maintaining a steady cadence of espionage operations. The North Korea-linked Lazarus Group continues to evolve its toolkit, recently deploying RemotePE, a cross-platform memory-only RAT targeting financial and cryptocurrency firms. And the Netherlands took enforcement action, seizing 800 servers and arresting two individuals for operating hosting infrastructure used by Russia to conduct cyberattacks and disinformation campaigns across the EU—a rare moment of government action against infrastructure enablers.

We're also tracking a troubling shift in attack sophistication targeting identity and authentication. The FBI is warning about Kali365, a phishing-as-a-service platform that hijacks Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication. This is particularly dangerous because it bypasses the modern security assumption that MFA is the line of defense. When phishing-as-a-service gains the ability to defeat MFA through OAuth abuse, every organization relying on that assumption is exposed.

One bright spot: organizations running Network Detection and Response (NDR) systems with agentic AI capabilities are finally getting relief from the alert firehose. The problem of alert fatigue—which has plagued defenders for years—is yielding to AI-driven correlation and response. If this matures, it represents a genuine inflection point in detection efficacy. We're watching this closely because the gap between attacker velocity and defender ability to respond has become untenable. Agentic AI might actually close it.

There are also operational reminders that defenders should not ignore. Microsoft confirmed a known issue affecting Windows Server 2016 where domain controller lookups fail after the May 2026 security update (KB5087537), which will frustrate patching efforts for organizations running legacy infrastructure. Patching is already hard. Patches that break authentication will be avoided—and avoided patches become exploitable vulnerabilities.

The convergence of these trends is what should concern every security leader: vulnerability discovery at scale, exploitation at speed, supply chains as primary targets, and state-sponsored actors operating freely across borders. The defenders who will survive the next 18 months are those who recognize that perimeter defense is theater. Supply chain integrity, dependency management, and artifact verification are now the real game. The organizations that assume their software dependencies are trustworthy will be the ones in the news next month explaining how attackers pivoted from a poisoned package to their production systems.

Key Takeaways

  • Supply chain attacks are now the primary vector. Three major coordinated campaigns in 48 hours targeting npm, PyPI, Crates.io, and GitHub Actions show attackers have shifted to poisoning the build and deployment infrastructure. Assume your dependencies are compromised until verified otherwise.
  • Vulnerability discovery is accelerating with AI. Anthropic's Mythos found 23,000 vulnerabilities in 1,000 open-source projects. As AI finds weaknesses faster, exploitation timelines are collapsing. Patch speed is now a measure of organizational survival.
  • MFA is no longer a sufficient defense against phishing. Kali365 and similar platforms are defeating OAuth-based MFA through device code authentication abuse. Authentication strategy requires rethinking beyond the MFA assumption.
  • Agentic AI for defense is starting to work. NDR systems with agentic AI are finally reducing alert fatigue. Organizations investing in AI-driven detection and response are gaining a meaningful advantage as attacker velocity continues to accelerate.

The Wire is HackWire's daily editorial briefing, published every morning.