logo

ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

ID: 9978f03d-7bad-53d0-98fa-6398f1e54ae6

STIX ID: report--9978f03d-7bad-53d0-98fa-6398f1e54ae6

Feed Name: The Hacker News

Threat Score
82/100

Date Published: 2026-05-28

Date Updated: 2026-05-29

Author: [email protected] (The Hacker News)

...
...

A May 2026 cybersecurity roundup detailing a range of active threats: discovery of 1,350 C2 servers across Middle East providers and dominant malware families (IoT botnets and offensive frameworks); a high-severity AKS privilege escalation (CVSS 9.9) and a supply-chain compromise of DAEMON Tools (CVE-2026-8398, CVSS 9.3) that trojanized signed binaries; multiple malware campaigns (DinDoor Deno RAT, PureLogs, signed RVTools RAT), large-scale phishing/PhaaS operations (Kali365, device-code phishing, Vaultjacking), targeted activity by Silent Ransom Group against law firms, extension-based data exfiltration networks (WaSteal), and disruptive TTPs like GhostTree that defeat endpoint scanning — collectively emphasizing active exploitation, broad scale, and persistent risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.