Isometric network nodes illustrating diverse cyber attack vectors.

Daily Cybersecurity News - May 6, 2026

Palo Alto Firewall Buffer Overflow Grants Root RCE

Palo Alto firewalls have a buffer overflow attackers exploit for unauthenticated root RCE. They hit exposed User-ID portals with crafted packets.

CVE-2026-0300 sits in the User-ID Authentication Portal service. CVSS 9.3, limited active exploitation confirmed by Palo Alto.

PA-Series and VM-Series firewalls running PAN-OS 10.2 through 12.1 count as exposed if portals face the internet on ports 6081 or 6082.

Patches start rolling out May 13 with 12.1.4-h5 and others.

Source: Wiz Blog

Linux Copy Fail Roots Every Major Distro

Linux kernels just got a dead-simple local root exploit that works on every major distro since 2017.

CVE-2026-31431 sits in the kernel's algif_aead crypto code. Unprivileged users chain AF_ALG sockets with splice() for a 4-byte page cache overwrite on setuid binaries like su. CVSS 7.8, public PoC out, actively exploited per CISA KEV.

Hits kernels 4.14 through 6.19.11 across Ubuntu 24.04, RHEL, SUSE, Amazon Linux, Debian. Breaks containers, CI runners, multi-tenant servers.

732-byte Python script roots them all unmodified.

Source: Unit 42

Rowhammer Attacks on NVIDIA GPUs Grab Root

Rowhammer just hit NVIDIA GPUs. Attackers hammer GDDR memory to flip bits and seize full control of the host machine.

Two teams showed this on Ampere cards: GDDRHammer corrupts page tables for CPU memory access, GeForge hits RTX 3060 with 1,171 bit flips. No CVE yet, public PoCs demonstrated root shells, no wild exploits.

Hits RTX 3060 and RTX 6000 Ada cards untouched. Cloud VMs and workstations with IOMMU off take the hit.

GeForge induced 1,171 bit flips on RTX 3060.

Hackers abuse Windows Phone Link to hijack SMS on connected PCs and bypass 2FA.

They drop CloudZ RAT with a new Pheno plugin that taps the Phone Link bridge between Windows PCs and Android phones. This grabs one-time codes from texts in real time. No initial access details yet.

The angle is abusing a legit Microsoft feature for stealthy credential theft. RAT stays hidden while Phone Link does the heavy lifting.

Detection stays tough with no custom malware hitting phone disks.

Source: Dark Reading

OceanLotus Poisons PyPI with ZiChatBot

OceanLotus is hiding droppers in PyPI packages to push ZiChatBot malware at developers.

They upload malicious Python wheels that work on Windows and Linux. The packages drop ZiChatBot, a fresh implant from this Vietnam-aligned APT.

PyPI abuse is lazy for them; they've stuck to Office docs and watering-hole attacks for years. ZiChatBot shows they're dipping into dev tooling supply chains.

Targets both Windows and Linux systems.

Source: Securelist

MuddyWater Fakes Chaos Ransomware With Teams Phishing

MuddyWater Iranian hackers fake a Chaos ransomware hit to mask their espionage ops.

They start with Microsoft Teams social engineering to snag initial access. Then they stage Chaos ransomware files for cover while dropping their real backdoor for persistence and data theft.

The decoy ploy is fresh for them. It throws off responders chasing ransomware instead of the real intrusion.

Same Teams trick they've reused since at least 2023.

DAEMON Tools Trojanized in Supply Chain Hit

Hackers compromised DAEMON Tools installers on the official site. Since April 8, thousands of downloads delivered a backdoor straight to victims.

They trojanized the legit setup files to drop the backdoor payload. No word yet on attribution or targets beyond general users grabbing the software.

Supply chain strikes on official download pages like this are rare for consumer tools. Most campaigns reuse cracked pirate sites instead.

Active since April 8 with thousands of infections.