
Daily Cybersecurity News - May 5, 2026
Microsoft Edge Dumps Passwords in Cleartext Memory
Microsoft Edge loads every saved password into process memory as plaintext right at startup. Malware running as you grabs them instantly.
Dump the "browser" sub-task memory via Task Manager. Run strings on the dump, search for patterns like "comhttps". Credentials spill out as "". Microsoft calls this intended behavior.
Hits any Windows user with Edge password manager on. Exposes Azure logins and site creds on shared desktops or if malware compromises your session.
No CVE assigned, no patch planned.
Weaver E-cology Bug Exploited Since March
Hackers hit Weaver E-cology office automation with a critical flaw, running discovery commands on victim networks since mid-March.
CVE-2026-22679 scores high severity and lets attackers execute commands remotely. Attackers already weaponized it for post-compromise recon.
Exposed setups run unpatched Weaver E-cology instances exposed online, common in enterprise office workflows.
Exploitation started mid-March, per attack logs.
Ollama Memory Leak Hits 300K Servers
Ollama has a nasty unauthenticated bug that lets attackers dump process memory from exposed servers.
CVE-2026-7482, dubbed Bleeding Llama, triggers a heap out-of-bounds read in the GGUF model loader via crafted files. Attackers hit three API calls to leak and exfiltrate data. CVSS 9.3, public PoC out.
Hits roughly 300,000 internet-facing Ollama deployments running without auth by default.
Patch lands in version 0.17.1.
DarkSword Zero-Day Chain Spreads Wide
DarkSword is a full-chain iOS exploit kit hitting iPhones with multiple zero-days. Google GTIG spotted it in the wild since November 2025.
It chains six flaws across Safari, kernel, and system for full device compromise on iOS 18.4 to 18.7. Attackers drop payloads like GHOSTBLADE in watering holes targeting Ukraine, Saudi Arabia, and others.
Novel part: multiple actors grabbed it fast, from Russian espionage group UNC6353 to Turkish vendor PARS Defense. Mirrors the Coruna kit's spread.
Active across commercial spyware and state ops since late 2025.
Daemon Tools Trojanized in Supply Chain Hit
Hackers trojanized official DAEMON Tools installers to drop backdoors on downloaders.
Since April 8, victims grabbed the poisoned setup files straight from the DAEMON Tools site. The backdoor deploys quietly, giving attackers remote control. Thousands of systems got hit worldwide.
This is classic supply chain tradecraft, straight off the shelf from years of similar attacks. Nothing novel here, just effective reuse on a popular app.
Attack active since April 8.
CloudZ RAT Hijacks Phone Link for OTP Theft
CloudZ RAT now abuses Microsoft Phone Link to snag SMS one-time passwords right from linked phones.
A new plugin called Pheno hooks into the Phone Link connection. Attackers steal OTPs and 2FA codes sent to victims' mobiles without touching the device.
This sidesteps mobile security entirely by riding a legit Microsoft feature. No prior reports of RATs targeting Phone Link like this.
Pheno marks the first plugin of its kind for CloudZ.
Persistent OAuth Tokens Backdoor Most Teams Miss
Every AI tool and productivity app employees connect to Google or Microsoft leaves a persistent OAuth token behind.
These tokens never expire, bypass MFA, and evade perimeter controls. Material Security's research finds 80% of leaders see them as a major risk, but 45% monitor nothing and 33% use spreadsheets. Hackers used stolen Drift tokens to hit Salesforce in over 700 organizations.
Awareness runs high, but action lags in most places. The survey comes from Material Security, a vendor selling OAuth monitoring tools.
Drift breach hit Cloudflare and PagerDuty among others.