
Coverage: Last 24 hours
Today’s Highlights
Operational technology, identity infrastructure, and software supply chains all saw credible attack activity and defensive pivots. Zero-days, fileless Linux implants, and blind spots in vulnerability management highlight a need for proactive review of both legacy tooling and high-assurance controls. A surge of active exploits is putting critical firewalls, developer workflows, and widely used applications in the crosshairs, while regulators like the FTC are shifting expectations around third-party data risk and vendor controls.
Table of Contents
- New stealthy Quasar Linux malware targets software developers
- FTC to ban data broker Kochava from selling Americans’ location data
- The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss
- Vimeo data breach exposes personal information of 119,000 people
- Palo Alto Networks warns of firewall RCE zero-day exploited in attacks
- Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs
- Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution
- Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
Top Stories
New stealthy Quasar Linux malware targets software developers
Source: BleepingComputer | Risk: High | Impacted: Developer workstations, CI/CD pipelines consuming npm or PyPI, Organizations using Docker and Kubernetes in build environments
Summary: A newly discovered Linux implant named Quasar Linux (QLNX) targets software developers by establishing fileless persistence using rootkit and PAM backdoor components, harvesting credentials, and enabling a full-featured remote access trojan. It compromises development environments across npm, PyPI, GitHub, AWS, Docker, and Kubernetes to facilitate stealthy supply‑chain attacks.
Why it matters: Development environments are now key attack surfaces, as intrusions here can facilitate stealthy supply-chain attacks and lateral compromise of high-privilege systems and sensitive code bases.
Practitioner Perspective
Software development shops and CI/CD operators are now prime targets. Attackers leveraging Quasar Linux (QLNX) are specifically aiming to exploit complex developer toolchains and cloud integration points, evading agent-based threat detection with rootkits and fileless persistence. Supply-chain compromise risk is especially high if developer credentials or cloud tokens are reused elsewhere. Your protection hinges on both tight access controls and comprehensive endpoint visibility on every developer system. Treat every developer endpoint as both a sensitive asset and a potential breach vector when planning detection or containment.
Recommended Actions
- Hunt for Quasar Linux/PAM backdoor activity in Linux authentication and process logs on developer systems
- Audit container, npm, and PyPI dependencies for tampering or unexplained updates in development projects
FTC to ban data broker Kochava from selling Americans’ location data
Source: BleepingComputer | Risk: Medium | Impacted: Organizations purchasing US location data from Kochava or similar brokers, Legal and compliance teams managing vendor risk, Marketing and product teams using location analytics
Summary: The FTC has reached a proposed settlement to prohibit data broker Kochava and its subsidiary Collective Data Solutions from selling precise location data without consumers’ explicit consent. The settlement mandates consent verification, programs for sensitive location data, disclosure and deletion mechanisms, incident reporting, and other safeguards to prevent misuse of location information.
Why it matters: Organizations dependent on location data brokers now face a stricter regulatory landscape and heightened third-party risk, particularly for compliance, privacy incident, and breach notification obligations.
Practitioner Perspective
The FTC’s mandate introduces new baseline expectations for explicit consent and data lifecycle controls for all location data shared via brokers like Kochava. Any enterprise sourcing location intelligence, adtech, or analytics data must validate their vendors’ compliance stance immediately. Regulators are signaling zero tolerance for inadequate consent verification, meaning your own data flows may become a downstream risk factor. Thoroughly reassess contracts and supplier review processes, especially if your analytics or marketing relies on third-party location feeds. Compliance teams must work with security engineers to document and enforce consent, deletion, and sensitive data boundaries.
Recommended Actions
- Review contracts with Kochava and other location data vendors for new data export, consent, and deletion clauses
- Perform audit of existing data sets sourced from Kochava for compliance with FTC requirements
The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss
Source: BleepingComputer | Risk: High | Impacted: Enterprises with legacy or abandoned code dependencies, CI/CD pipeline security teams, Compliance managers relying on SCA or vulnerability scanning tools
Summary: The article explains how vulnerability scanners, SBOM tools, and CVE feeds often fail to flag vulnerabilities in end-of-life (EOL) software versions because these versions fall outside the officially tracked affected ranges. Sonatype and HeroDevs research found that this creates significant false negatives, with hundreds of thousands of vulnerable EOL components going undetected. The article urges organizations not to treat scanner silence as safety and recommends using EOL-specific scanning tools.
Why it matters: Producing or maintaining software that relies on out-of-support components means real vulnerabilities may never be surfaced in internal or third-party risk scans, leaving entire portfolios falsely marked as ‘compliant.’
Practitioner Perspective
SBOMs and commercial SCA tools routinely miss vulnerabilities in EOL packages because these are excluded from tracked CVE ranges when official support ends. Security teams that assume scanner silence equals safety are exposed, especially in regulated sectors. Your critical path: identify every unsupported binary or dependency across your codebase and infrastructure, regardless of what the CVE feed says. Invest in EOL-aware scanning and force the conversation with asset owners or developers about migration. Do not accept ‘legacy’ as a permanent exception if you want to cut exposure windows.
Recommended Actions
- Deploy EOL-specific vulnerability scanning tools like Sonatype or HeroDevs on codebases and images
- Inventory legacy dependencies and unsupported components outside the scope of active SCA scanners
Vimeo data breach exposes personal information of 119,000 people
Source: BleepingComputer | Risk: Medium | Impacted: Vimeo business customers, Organizations with analytics integration via Anodot, Data privacy and legal incident response teams
Summary: In April, the ShinyHunters extortion group hacked Vimeo via a breach at Anodot, stealing technical data, video titles, metadata and, in some cases, customer email addresses, exposing personal information of about 119,200 people, though no credentials, payment details or video content were compromised.
Why it matters: Service provider breaches like Anodot’s can lead to secondary compromise of enterprise customer data, highlighting risk exposure from SaaS platforms used for analytics or monitoring within critical workflows.
Practitioner Perspective
Organizations depending on Vimeo or third-party analytics providers such as Anodot should expect that technical and user-level metadata may surface in the underground following these breaches. While credentials and payment data were reportedly not lost, mapping exposure is still key for legal, privacy, and incident response readiness. Review the breadth of permissions Saas integrations hold into your data stores, especially if sensitive metadata or identifiers flow to external analytic services. Reinforce federated authentication and least-privilege contracts between your environment and all connected SaaS vendors.
Recommended Actions
- Review OAuth scopes granted to Anodot or similar analytics SaaS vendors and revoke unused permissions
- Audit logs for all API activity or data exports performed via analytics integrations since breach window
Emerging Signals
No emerging signal items for this cycle.
Exploits & CVEs
Palo Alto Networks warns of firewall RCE zero-day exploited in attacks
Source: BleepingComputer | Risk: Critical | Impacted: Internet-facing Palo Alto PA-Series firewalls, Internet-facing Palo Alto VM-Series firewalls, Environments using PAN-OS Captive Portal
Summary: Palo Alto Networks has issued an urgent advisory warning that a critical, unpatched buffer‑overflow vulnerability (CVE‑2026‑0300) in its PAN‑OS User‑ID Authentication (Captive) Portal is under active exploitation. The flaw allows unauthenticated attackers to execute code as root on internet‑exposed PA‑Series and VM‑Series firewalls. Until patched, customers are urged to restrict or disable portal access from untrusted networks. Shadowserver reports over 5,800 vulnerable firewalls online. The vendor is working on a fix.
Why it matters: Attackers can achieve full remote code execution as root on exposed critical perimeter devices, creating the potential for network foothold, lateral movement, and attacker-controlled persistence before detection.
Practitioner Perspective
Any organization with internet-exposed Palo Alto firewalls running User-ID Captive Portal is at immediate risk. This flaw enables pre-auth code execution, so attackers do not need valid credentials. Given Shadowserver’s data and active exploitation, your asset inventory and segmentation controls are your only protection until the patch is available. Even if you believe the portal is disabled, validate configuration via CLI and management plane. The most pressing issue: eliminate outside exposure now and pre-stage rollback or recovery steps for compromised devices.
Recommended Actions
- Disable or strictly restrict access to PAN-OS User-ID Authentication Portal from untrusted networks
- Audit firewalls for exposure of the Captive Portal using both vendor and external scanning tools
Windows Phone Link Exploited by CloudZ RAT to Steal Credentials and OTPs
Source: The Hacker News | Risk: High | Impacted: Windows 10 and 11 workstations with Phone Link enabled, Azure AD and M365 tenants using SMS OTP for authentication, User populations with mixed mobile and desktop usage
Summary: Cisco Talos researchers revealed that since at least January 2026, the CloudZ remote access trojan (RAT), equipped with a novel plugin called Pheno, has been exploiting Microsoft’s Phone Link app on Windows 10 and 11 to harvest browser credentials and intercept SMS-based one‑time passwords (OTPs) synced to the PC, without compromising the mobile device.
Why it matters: Exploiting cross-device sync features in Microsoft Phone Link exposes a blind spot where malware can exfiltrate both credentials and time-sensitive OTPs directly from desktop environments even if the mobile device remains uncompromised.
Practitioner Perspective
Enterprises deploying Microsoft’s Phone Link on Windows 10/11 are at risk of having browser credentials and SMS OTPs stolen from compromised endpoints via the CloudZ RAT and its Pheno plugin. This tactic bypasses mobile anti-malware and leverages the trusted desktop environment, turning one compromised user into a chain of multi-factor failures. Existing EDR and SIEM rules likely need to be updated to detect and correlate Phone Link data access with credential and OTP exfiltration attempts. You should critically reassess the trust model around cross-device sync products within your estate.
Recommended Actions
- Monitor for unauthorized access or data scraping activity from Phone Link app processes on endpoints
- Add threat intel coverage for CloudZ RAT and Pheno plugin to EDR and SIEM platforms
Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution
Source: The Hacker News | Risk: Critical | Impacted: Organizations operating public-facing Palo Alto PAN-OS appliances, Teams relying on User-ID Authentication Portal, Enterprises without strong firewall change controls
Summary: A critical buffer‑overflow vulnerability in Palo Alto Networks PAN‑OS (CVE‑2026‑0300) allows unauthenticated remote code execution via the User‑ID Authentication Portal and is already being exploited in the wild. Palo Alto plans to release patches beginning May 13, 2026, and recommends restricting or disabling the portal until then.
Why it matters: Perimeter firewalls at thousands of organizations are at risk of total compromise, providing attackers an initial foothold from which to pivot deeper into trusted network segments.
Practitioner Perspective
This PAN-OS flaw is already under active exploitation, giving unauthenticated attackers root access to devices on untrusted networks. Your board and C-suite depend on these appliances for ‘last line’ defense, so the exposure window before patch release is both a technical and governance crisis. Immediate action must be coordinated between network, IR, and GRC leadership to lock down at-risk portals and stage incident response tools for potential device rebuild. Assume successful exploits may have already occurred at any public IP not affirmatively locked down.
Recommended Actions
- Disable User-ID Authentication Portal or restrict inbound traffic to trusted sources until PAN-OS patches are deployed
- Immediately scan for public-exposed Captive Portal endpoints and validate against asset inventory
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
Source: The Hacker News | Risk: High | Impacted: Web servers running Apache HTTP Server 2.4.66 with HTTP/2 enabled, Organizations hosting critical internet-facing applications, DevOps teams managing custom Apache modules
Summary: The Apache Software Foundation has patched a critical vulnerability, CVE‑2026‑23918, in Apache HTTP Server 2.4.66’s HTTP/2 handling, a double‑free flaw that allows denial‑of‑service and, under certain conditions, remote code execution. The issue is fixed in version 2.4.67.
Why it matters: Unpatched Apache HTTP Server instances can be crashed or potentially exploited for remote code execution, expanding the attack surface and increasing downtime risk for externally facing web services.
Practitioner Perspective
All operators of Apache HTTP Server 2.4.66 with HTTP/2 enabled should treat this as an urgent patch event, even if direct exploitability is unclear. Attackers will rapidly incorporate this double-free flaw (CVE-2026-23918) into typical web scanning and denial-of-service toolkits. Any production workload exposed to HTTP/2 traffic is a candidate for both service interruption and potential shell access. If running older Apache branches, especially in complex DMZ or reverse proxy chains, validate versioning and prioritize upgrade. Coordination with app owners is critical to avoid unexpected breakage during the patch window.
Recommended Actions
- Upgrade vulnerable Apache HTTP Server instances to version 2.4.67 to address CVE-2026-23918
- Scan for HTTP/2 exposure on both public and internal web infrastructure
Defensive Actions
- Disable or strictly restrict access to PAN-OS User-ID Authentication Portal from untrusted networks
- Audit firewalls for exposure of the Captive Portal using both vendor and external scanning tools
- Monitor for signs of exploitation targeting CVE-2026-0300 in pan_logs and syslogs
- Pre-stage response procedures (including out-of-band console access and clean image reinstall) for affected firewall appliances
- Track Palo Alto advisory updates for patch availability and apply fixes as soon as released
- Hunt for Quasar Linux/PAM backdoor activity in Linux authentication and process logs on developer systems
- Audit container, npm, and PyPI dependencies for tampering or unexplained updates in development projects
- Deploy EDR tools capable of detecting fileless persistence and rootkit behavior on all Linux endpoints in dev environments
- Revoke and rotate credentials and cloud tokens (AWS, GitHub, etc.) from any exposed developer machines
- Monitor for anomalous access patterns to AWS, Docker, and Kubernetes APIs from development IP ranges
- Deploy EOL-specific vulnerability scanning tools like Sonatype or HeroDevs on codebases and images
- Inventory legacy dependencies and unsupported components outside the scope of active SCA scanners
What We’re Watching
- Continuing supply-chain attacks leveraging trojanized desktop installers and mass export features in educational SaaS, signaling a widening of attack surfaces outside traditional perimeter controls.
- Expanding regulatory scrutiny for data brokers and analytics vendors, raising the stakes for organizations whose workflows depend on external data collection or integration platforms.
- Ongoing exploitation of zero-days in both network appliances and web infrastructure, emphasizing the need for rapid investigation and tight segmentation of internet-facing assets.
- Adoption of public verification logs for Android applications by Google as a shift toward more transparent and verifiable supply chain assurance for mobile environments.
Categories: Cybersecurity Blog, Cybersecurity News
Leave a Reply