Floating servers showing critical Azure, WooCommerce, and Grafana vulnerabilities.

Daily Cybersecurity News - May 17, 2026

Microsoft Rejects Critical Azure Vulnerability Report

A researcher reported a critical privilege-escalation flaw in Azure Backup for AKS. Users with only the low-privileged “Backup Contributor” role on a backup vault could gain full cluster-admin access and steal cluster secrets without needing Kubernetes credentials.

Microsoft rejected the submission and called the behavior expected. The researcher documented steps showing the escalation and later observed tightened access controls (silent fix). Affects Azure Kubernetes Service users who enable Backup for their clusters.

No CVE was issued.

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

WordPress Funnel Builder plugin lets attackers slip malicious JavaScript straight into WooCommerce checkout pages.

They target an unauthenticated stored cross-site scripting flaw that lets them persist scripts loading on every customer payment screen. Actively exploited in the wild now.

Affects all versions before the fix on sites running WooCommerce with this plugin installed.

Sansec spotted injection attempts starting last week on multiple shops.

Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt

Grafana lost access to its GitHub org when attackers stole a token.

They downloaded the full codebase and demanded payment. No customer data or personal information left the environment.

Token theft through supply chain or insider access is common now. This one stayed contained because the org had no production secrets.

Extortion attempt started right after the download finished.

Russian hackers turn Kazuar backdoor into modular P2P botnet

Secret Blizzard turned their old Kazuar backdoor into a full P2P botnet for long-term spying.

They added modular plugins that let each infected machine act as a node, routing traffic between peers instead of relying on central servers. Targets include government and diplomatic networks in Europe and North America.

The move reuses familiar Kazuar code but adds true P2P communication for better resilience against takedowns. This feels like a step up from their usual command-and-control setups.

Active since early 2025, the botnet already controls machines in at least five countries.

The Boring Stuff is Dangerous Now

AI agents now hunt obscure bugs that humans overlook.

Developers ship huge volumes of AI-written code that carries hidden flaws. Defenders must rewrite detection rules because old signatures miss these new patterns.

The article reads like vendor marketing dressed as news. No numbers, no sample, no year-over-year comparison. Just a restatement of known AI risks.

It quotes researchers from security firms including CrowdStrike and SentinelOne.

Source: Dark Reading