Daily Recap, Exploited vulnerabilities and zero-days dominated the news: LiteSpeed cPanel Plugin CVE-2026-48172 is abused for root access, Drupal core SQL injection issues are being actively exploited and added to CISA KEV, and Trend Micro warned that an Apex One zero-day is in use in the wild. Phishing activity also accelerated with the FBI flagging the Kali365 phishing-as-a-service kit targeting Microsoft 365 tokens, while Ghostwriter used Prometheus to target Ukraine government entities and authorities pursued infrastructure actions including a global VPN service dismantling linked to 25 ransomware groups. #CVE-2026-48172 #LiteSpeed #cPanel #root #Drupal #CISAKEV #DrupalSQLi #ApexOne #Kali365 #Microsoft365 #FBI #Ghostwriter #Prometheus #Ukraine #VPN #Netherlands #Webworm #Discord #MicrosoftGraph
Exploited Bugs
- LiteSpeed cPanel Plugin CVE-2026-48172 is being abused to run scripts as root, and Drupal Core SQL injection flaws are now actively exploited and added to the CISA KEV list. β LiteSpeed Root, Drupal SQLi, Drupal Crosshairs, Apex One Zero-Day
- Trend Micro warned that an Apex One zero-day is being exploited in the wild, adding to a day of fast-moving vulnerability abuse. β Apex One Zero-Day
Phishing Campaigns
- The FBI warned about the fast-growing Kali365 phishing-as-a-service kit, which followed recent Microsoft 365 attacks and is designed to steal access tokens and credentials. β Kali365 PhaaS, Kali365 Tokens
- Ghostwriter targeted Ukraine government entities with Prometheus phishing malware in a campaign tied to espionage activity. β Ghostwriter Phish
Infrastructure Takedowns
- A joint global operation dismantled the first VPN service linked to use by 25 ransomware groups, disrupting a major criminal infrastructure hub. β VPN Takedown
- Authorities in the Netherlands seized 800 servers from a hosting firm accused of enabling cyberattacks, cutting off attacker infrastructure at scale. β Server Seizure
State & APT Activity
- Chinaβs Webworm campaign used Discord and Microsoft Graph services to infiltrate EU government networks, highlighting stealthy abuse of trusted cloud tools. β Webworm Hack
Fraud & Scams
- Former US executives pleaded guilty to helping tech support scammers, underscoring how insider assistance can fuel large-scale fraud operations. β Execs Guilty
Other Security News
- Meta settled a lawsuit with school districts over claims its addictive design harmed studentsβ mental health, closing another high-profile digital harms case. β Meta Settlement
- SecurityWeek also flagged industrial router exploitation, a new CISA KEV nomination form, and gas station hacking in its roundup of notable security developments. β Other News