Attackers began weaponizing a highly critical SQL injection in Drupal (CVE-2026-9082) within 48 hours of the May 20 patch release. The flaw allows unauthenticated compromise of Drupal sites that use PostgreSQL, enabling data exfiltration or full site takeover. Organizations should urgently apply the latest Drupal Core updates and validate whether their deployments rely on PostgreSQL.
Source: Security Affairs
CISA Adds Drupal Core CVE-2026-9082 to KEV, Citing Active Exploitation
U.S. CISA added Drupal’s critical SQL injection (CVE-2026-9082) to its Known Exploited Vulnerabilities catalog, confirming in-the-wild attacks. Federal agencies are now obligated to remediate by the KEV deadline, and the listing signals broader risk for any internet-facing Drupal instance. Prioritize patching and consider temporary access restrictions if immediate maintenance windows are not feasible.
Source: TheHackerNews
LiteSpeed cPanel Plugin (CVE-2026-48172) Exploited to Execute Code as root
A maximum-severity flaw in the LiteSpeed User-End cPanel Plugin is being actively exploited, allowing any cPanel user to run arbitrary scripts with root privileges. The incorrect privilege assignment (CVSS 10.0) creates a potent path to full server compromise from even low-privileged or hijacked accounts. Patch immediately, audit cPanel users for suspicious activity, and check for persistence mechanisms.
Source: TheHackerNews
‘Underminr’ Lets Attackers Masquerade Malicious Traffic Behind Trusted Domains
A newly disclosed “Underminr” vulnerability affects roughly 88 million domains and can be abused to bypass DNS filtering while camouflaging command-and-control communications. The technique undermines trust signals used by security tools and can facilitate stealthy lateral movement and data exfiltration. Defenders should reevaluate DNS and egress controls and strengthen domain validation beyond basic allowlists.
Source: SecurityWeek
Anthropic’s Project Glasswing Finds 10,000+ High/Critical Flaws in a Month
Anthropic reports its AI-driven Project Glasswing surfaced more than 10,000 high- or critical-severity vulnerabilities across widely used, systemically important software in just one month. The scale spotlights a persistent patching gap: discovery is accelerating faster than remediation. Security teams should prepare for higher vulnerability volumes by prioritizing patch automation, risk-based remediation, and SLAs aligned to exploit trends.
Source: Security Affairs
Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
Researchers uncovered a software supply chain attack on multiple Laravel-Lang PHP packages (including laravel-lang/lang and http-statuses), weaponized to deliver a comprehensive credential-stealing framework. The campaign abused newly published tags to infiltrate developer environments and downstream apps. Review dependency trees, pin and verify known-good versions, rotate exposed secrets, and monitor developer endpoints for anomalous activity.
Source: TheHackerNews
npm Rolls Out 2FA-Gated ‘Staged Publishing’ and Install Controls
GitHub introduced staged publishing on npm, requiring a human maintainer to pass a 2FA challenge before a release becomes publicly installable. New install controls further restrict exposure to risky packages. These changes harden the ecosystem against account takeovers and malicious publishes; maintainers and orgs should enable 2FA and adapt CI/CD workflows accordingly.
Source: TheHackerNews
You May Also Be Interested In...