Isometric network nodes showing widespread zero-day, phishing, and malware attacks.

Daily Cybersecurity News - May 27, 2026

CISA Gives Feds Days to Patch cPanel Flaw

CISA just ordered federal agencies to patch a critical flaw in the LiteSpeed cPanel plugin within four days because attackers are already using it.

CVE-2026-48172 lets unprivileged attackers run scripts as root. CVSS 10.0 and actively exploited.

Affects LiteSpeed User-End cPanel Plugin versions 2.3 through 2.4.4. Federal agencies and any public-facing cPanel installs running the plugin must act.

CISA urged all defenders to prioritize patching.

KnowledgeDeliver Flaw Exploited as Zero Day

Hackers used a zero-day flaw in KnowledgeDeliver to drop web shells on a learning management server.

The zero-day let attackers install the Godzilla web shell without credentials.

The flaw is tracked as CVE-2026-5426.

The server ran the KnowledgeDeliver LMS. Attackers targeted it specifically for remote access.

Godzilla shell appeared in the first observed compromise.

Kali365 Phishing Kit Bypasses MFA And Steals Microsoft Logins

Attackers are pushing a new phishing kit called Kali365 that grabs Microsoft Outlook, Teams, and OneDrive accounts even when MFA is enabled.

The kit abuses Microsoft device-code login to capture OAuth access and refresh tokens after the victim approves the request.

This is phishing-as-a-service (PhaaS) built around Microsoft OAuth token theft.

The FBI issued a specific alert on this kit in May 2026 after it appeared in multiple confirmed compromises.

Source: Malwarebytes

Feeding Frenzy Megalodon Malware Infects Thousands of GitHub Repos

A supply-chain campaign hit thousands of GitHub repositories in hours, stealing credentials and secrets from developer accounts.

Attackers pushed malicious commits across more than 5,500 repos using automated commits against repositories with weak branch protection.

The speed and scale stand out compared to slower, targeted watering-hole attacks seen in prior credential theft operations.

The operation ran for just six hours before detection, leaving over 5,500 repositories compromised in that window.

Source: Dark Reading