Glowing lock icons breached by recent software and financial cyberattacks.

Daily Cybersecurity News - May 25, 2026

Ghost CMS Vuln Exploited on 700 Sites

Attackers exploited a Ghost CMS vulnerability to compromise over 700 websites.

The flaw was SQL injection, not RCE. Victims include Harvard, Oxford, and DuckDuckGo.

The attack hit multiple high-profile targets in one wave. It shows how a single unpatched CMS can spread fast.

Harvard and Oxford sites were among those breached in the campaign.

Source: SecurityWeek

Laravel Lang Packages Poisoned for Malware Delivery

Attackers poisoned several Laravel language packages on Packagist with malicious tags.

They pushed backdoored versions inside a 15-minute window that exfiltrated CI secrets from developer environments. Targets were projects pulling these common localization files during builds.

The move reuses supply-chain tactics seen in other open-source poisoning attempts but stands out for its tight timing and focus on continuous-integration pipelines rather than end-user machines.

The malicious tags appeared across May 22–23 before removal.

Source: SecurityWeek

Over 5500 GitHub Repos Hit in Megalodon Attack

Attackers poisoned over 5500 GitHub repositories with malicious workflow files that steal credentials and secrets.

They pushed fake automated commits that injected GitHub Actions workflows. The payloads targeted CI secrets, keys, and tokens across many public repos.

This is classic supply chain abuse via automated commits. Nothing novel in the vector itself, but the scale shows how easy it remains to hit developer tooling at volume.

The main commit wave ran for about six hours, affecting both personal and organizational accounts with no obvious common thread.

Source: SecurityWeek

Lazarus Deploys RemotePE Memory Only RAT Against Financial and Crypto Firms

Lazarus is hitting financial and cryptocurrency firms with a new cross-platform memory-only remote access tool called RemotePE.

It forms part of a multi-stage chain. The tool runs entirely in memory and avoids writing files to disk during execution.

The approach reuses the group's established multi-stage delivery pattern while shifting focus to in-memory execution for stealth.

Attacks target organizations across multiple regions with this specific tooling variant active in recent operations.