logo

Microsoft Exchange zero-day in active use; npm worm clones spread after source leak

ID: 2f65fa41-dd6b-5858-95d3-00b788258c04

STIX ID: report--2f65fa41-dd6b-5858-95d3-00b788258c04

Feed Name: defend.network – Daily Threat Briefings

Threat Score
92/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

...
...

Critical, multi-faceted threat briefing: a Microsoft Exchange zero-day (CVE-2026-42897) is being actively exploited with no patch available; Shai-Hulud worm source was leaked and cloned packages have appeared targeting npm developers; coordinated supply-chain credential-theft campaigns impacted npm, PyPI, and Docker Hub; Grafana’s source code was stolen using a compromised GitHub token; and INTERPOL’s Operation Ramz led to 201 arrests—urgent remediation and credential/secret rotation are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.