Cybersecurity News | Daily Recap [27 May 2026]

Cybersecurity News | Daily Recap [27 May 2026]

Daily Recap, CISA ordered U.S. agencies to patch an actively exploited LiteSpeed cPanel plugin zero-day within 4 days, while Microsoft released a fix for a SharePoint RCE flaw and KnowledgeDeliver was exploited as a zero-day to deploy web shells. The FBI warned that Silent Ransom is using in-person tactics like operatives inserting USB drives to steal data, and Glassworm’s botnet was disrupted after a takedown of its C2 infrastructure. #LiteSpeed #cPanel #SharePoint #KnowledgeDeliver #SilentRansom #FBI #ShinyHunters #Charter #MuddyWater #DLLsideloading #LA_Metro #Iran #GRU #Russian #Glassworm #C2 #USBdrives

Zero-Days & Patching

  • CISA ordered U.S. agencies to patch an actively exploited LiteSpeed cPanel plugin zero-day within 4 days, while Microsoft also shipped a fix for a SharePoint RCE flaw across server versions. – cPanel Fix, LiteSpeed Fix, SharePoint RCE
  • KnowledgeDeliver was exploited as a zero-day to deploy web shells, underscoring continued post-compromise abuse of enterprise software. – KnowledgeDeliver

Ransomware & Extortion

  • The FBI warned that the Silent Ransom gang is using in-person data theft tactics, including operatives who insert USB drives to steal information. – Silent Ransom, USB Tactics
  • Charter confirmed a data breach after extortion pressure from ShinyHunters, adding to the group’s string of high-profile coercion campaigns. – Charter Breach

State-Backed Threats

  • MuddyWater used DLL side-loading in an espionage campaign targeting 9 countries, while the LA Metro cyberattack was tied to Iranian state-sponsored hackers. – MuddyWater, LA Metro
  • Dutch authorities arrested suspects accused of providing infrastructure for Russian cyber operations, and the Kremlin named a cyber executive with alleged GRU ties to a Security Council role. – Dutch Arrests, Kremlin Pick

Law Enforcement & Theft

  • Romanian hacker Marcel was sentenced in the U.S. for selling access to a state network, highlighting the criminal market for stolen footholds. – Romanian Hacker
  • Lithuania is investigating the theft of 600,000 state registry records by a foreign actor, pointing to large-scale public-sector data exposure. – Lithuania Records
  • Dutch police arrested a suspect linked to the Ajax football club hack, continuing enforcement actions around recent intrusions. – Ajax Hack

Botnets & Malware

  • The Glassworm botnet was disrupted after a takedown of its resilient C2 infrastructure, weakening its ability to recover. – Glassworm Botnet

Vulnerability Research & Defense

  • Apple open-sourced quantum-resistant encryption code, while RevEng.AI raised $15 million to find flaws and backdoors in software binaries. – Apple Quantum, RevEng.AI
  • Anthropic said its Mythos system found more than 10,000 software flaws in its first month, signaling rapid growth in AI-assisted vulnerability discovery. – Mythos Flaws
  • SecurityWeek will host an AI Risk Summit on August 11-12 at the Ritz-Carlton, Half Moon Bay, as organizations assess emerging AI threats. – AI Summit
  • White House unveiled new federal cybersecurity logging guidance, aiming to improve visibility and incident response across agencies. – Logging Rules
  • Windows 11 update KB5089573 was released with performance improvements, continuing Microsoft’s routine platform maintenance. – Win11 Update

Cybersecurity News | Daily Recap – hendryadrian.com