Isometric network nodes illustrating multiple cybersecurity vulnerabilities and data leaks.

Daily Cybersecurity News - May 23, 2026

Underminr Vulnerability Hides C2 Behind Trusted Domains

A new DNS technique lets attackers tunnel command and control traffic through legitimate domains that security tools already trust.

Underminr abuses shared CDN routing so a connection can appear to go to a trusted domain while actually reaching another hosted domain.

Environments that rely on DNS allowlists without checking DNS, SNI, Host headers, and CDN routing together may be exposed. This includes enterprise proxies, endpoint agents, and cloud security stacks that skip subdomain checks.

Researchers say the method has already been abused in real-world attacks.

Source: SecurityWeek

Drupal Vulnerability Draws Hacker Attention

Drupal sites face quick exploitation attempts on a fresh SQL injection flaw right after disclosure.

CVE-2026-9082 sits in the core database abstraction API and lets unauthenticated attackers inject SQL on PostgreSQL-backed installs. CVSS 6.5, with working PoCs released the same day.

Affects Drupal 8.9 and up through recent 11.x branches when running on PostgreSQL. Non-PostgreSQL sites stay unaffected.

Security firms already logged attacks against thousands of sites within days of the advisory.

Source: SecurityWeek

LiteSpeed cPanel Plugin Gives Root Access

LiteSpeed plugin for cPanel lets unprivileged users run scripts as root.

CVE-2026-48172 scores CVSS 10.0 from incorrect privilege assignment. Attackers abuse it to execute arbitrary scripts with root rights. The flaw is actively exploited in the wild.

Affects LiteSpeed User-End cPanel Plugin versions 2.3 through 2.4.4. The issue was fixed in version 2.4.5.

LiteSpeed confirmed active exploitation and published indicators of compromise.

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

A CISA contractor posted AWS GovCloud keys and other agency secrets to a public GitHub account.

CISA is scrambling to contain the exposure while Congress demands briefings on how it happened and what was taken.

The repository was intentionally published, and GitHub’s built-in secret protection was reportedly disabled. No sophisticated intrusion was needed, just exposed access and poor handling of secrets.

Lawmakers from both chambers sent formal letters this week seeking full details on the scope.

Laravel Lang PHP Packages Compromised to Deliver Cross Platform Credential Stealer

Attackers slipped malicious code into several Laravel Lang PHP packages on Packagist.

The backdoor grabs credentials across Windows, Linux, and macOS. It targets browsers, password managers, and crypto wallets, then phones home with the loot.

This is a straight supply chain hit on a popular dependency ecosystem. No fancy zero-days, just compromised maintainer accounts pushing tainted updates.

The campaign affected multiple Laravel-Lang packages, with more than 700 associated versions identified across the compromised package set.