Glowing lock icons broken, representing major cybersecurity bypasses and root exploits.

Daily Cybersecurity News - May 15, 2026

Cisco SD-WAN Auth Bypass Still Active

Cisco Catalyst SD-WAN controllers face ongoing attacks from multiple clusters exploiting auth bypass flaws.

CVE-2026-20182 scores CVSS 10.0 via broken peering auth in vdaemon over DTLS port 12346. Attackers send crafted requests to impersonate peers, log in via NETCONF as vmanage-admin, and rewrite configs across the fabric. Zero-day for UAT-8616 since 2023, now actively exploited by 10 more groups post-PoC.

Hits Controller and Manager in on-prem, cloud, all versions before fixes like 20.9.9.1 or 20.12.7.1. CISA KEV mandates federal patches by May 17.

Attackers inject SSH keys and check control connections for challenge-ack:0.

Source: Tenable Blog

Linux Kernel Fragnesia Hands Out Root

Linux kernel scored another local root bug called Fragnesia. Unprivileged users overwrite page cache on setuid binaries like su for root.

CVE-2026-46300 sits in XFRM ESP-in-TCP. Kernel fails to propagate SKBFL_SHARED_FRAG flag during socket buffer coalescing, enabling 192-byte XOR writes via AES-GCM. CVSS 7.8, public PoC available on GitHub.

Hits kernels before May 13 patch across Ubuntu, RHEL, AlmaLinux 8/9/10, Debian, SUSE. Dirty Frag patches do not fix it; needs separate update.

Patch hit netdev list May 13; rmmod esp4 esp6 rxrpc blacklists as interim mitigation.

Source: Tenable Blog

Bypassing AI Age Checks With Fake Mustache

Kids fool AI video age verification on adult sites and social platforms with a simple drawn-on mustache.

UK Internet Matters report details children sketching facial hair using eyebrow pencils during selfie scans. Systems mistake them for older users. No CVE, but actively exploited by enterprising minors.

Hits platforms enforcing UK Online Safety Act rules, like Instagram and Facebook age gates. Survey covers 1,000 UK kids aged 9-16.

12-year-old's pencil mustache verified him as 15 years old.

Exchange Zero-Day Turns OWA Emails into Script Bombs

Attackers send crafted emails that turn Outlook Web Access into an XSS launchpad when users interact. Microsoft calls it a zero-day they're racing to patch.

CVE-2026-42897 is a spoofing bug via improper input neutralization, scored CVSS 8.1. Unauth attackers trigger arbitrary JavaScript in the victim's browser context after specific OWA interactions. It's actively exploited.

Hits on-premises Exchange Server 2016, 2019, and Subscription Edition, even fully patched versions. OWA users in enterprise setups take the hit.

Mitigate now with Exchange Emergency Mitigation Service or EOMT.ps1 script targeting the CVE.

OpenAI Breached in TanStack Mini Shai-Hulud Attack

TeamPCP hit OpenAI through the TanStack supply chain compromise in the Mini Shai-Hulud campaign.

TeamPCP abused TanStack's GitHub Actions to push 84 malicious npm package versions on May 11. Malware infected two OpenAI employee devices, stealing credentials from internal repos. OpenAI rotated code-signing certs across macOS, Windows, iOS, and Android apps.

Worm-like malware self-propagated to hundreds of packages. TanStack's popularity made this blast radius massive.

macOS users must update apps by June 12 due to revoked certificates.

TeamPCP Open-Sources Shai-Hulud Worm

TeamPCP just dropped the source code for their Shai-Hulud supply chain worm. They're pushing others to weaponize it against open source projects.

The modular framework steals developer credentials and API keys from npm and PyPI packages. It exfiltrates data to GitHub repos and C2 servers using random passphrases per build to dodge signatures.

Open sourcing hands copycats a blueprint for npm poisoning via OIDC token theft. What's wild is forks adding features like FreeBSD support hours after takedown.

Code hit GitHub on May 12, 2026, via compromised accounts with spoofed 2099 dates.

Source: SecurityWeek

China Hackers Drop TencShell on Indian Factory

China-linked hackers targeted a global manufacturer's Indian branch with fresh malware.

They delivered TencShell via a Donut shellcode dropper disguised as a web font file, injecting it into memory. The Go-based implant, forked from open-source Rshell, handles command execution, file ops, screen control, UAC bypass, and pivoting over Tencent-mimicking C2 paths.

Crew customized public red-team tools instead of building custom code, blending C2 into legit web traffic. Reuse of Rshell with infrastructure tweaks points to China alignment, though attribution stays fuzzy.

Cato CTRL blocked the April 2026 attempt through a suspicious third-party login.