Security Brief Daily

May 26, 2026 · #68


Listen Later

Episode 68

Security Brief Daily | 26 May 2026

In This Episode
  • CISA orders feds to patch actively exploited Drupal vulnerabilityBleeping Computer
    CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited. Drupal is typically used by large organizations managing massive...
  • Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server VersionsThe Hacker News
    Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met. The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of...
  • KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt StrikeThe Hacker News
    A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon. The...
  • 7-Eleven data breach exposes personal information of 185,000 peopleBleeping Computer
    The ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned. Founded in 1927, 7-Eleven now operates,...
  • FBI warns of Kali365 phishing service targeting Microsoft 365 accountsBleeping Computer
    The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). According to the FBI PSA , Kali365 first...
  • Netherlands Seizes 800 Servers, Arrests 2 for Aiding CyberattacksKrebs on Security
    Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the...
  • Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix AttacksThe Hacker News
    Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), an SQL...
  • Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO PoisoningThe Hacker News
    The Iranian state-sponsored threat actor known as Nimbus Manticore (aka Screening Serpens and UNC1549) has been attributed to a fresh campaign using lures impersonating organizations in the aviation and software sectors across the U.S., Europe, and the Middle East following...
  • Security Brief Daily is an AI-generated cybersecurity news podcast. Always verify critical information with primary sources.

    ...more
    View all episodesView all episodes
    Download on the App Store

    Security Brief DailyBy Security Brief Daily