Daily Briefing

CyberGeoDigest

Geopolitical cyber intelligence in 5 minutes
Monday, May 25, 2026 · 6 stories
Share this digest:

Unknown Actor Exploits KnowledgeDeliver RCE to Backdoor Japanese LMS Platform (3 minute read)

Mandiant identified an unauthenticated RCE vulnerability via ViewState deserialization in KnowledgeDeliver, a widely used Japanese LMS, exploited in a late-2025 intrusion to inject malicious code.

Google Threat Intelligence · just now · Read full article →

Japan Eyes Taiwan Defense Partnership Through Frigate Diplomacy Initiative (1 minute read)

Japan is exploring expanded defense-industrial ties with Taiwan, potentially positioning itself as a second major democratic arms and technology partner alongside the United States. A formalized Japan-Taiwan defense relationship would redraw regional deterrence geometry and draw Beijing's direct response.

The Diplomat · 16h ago · Read full article →

Chinese-Language PhaaS Ecosystem Challenges Russia's Phishing Dominance (3 minute read)

Google Threat Intelligence identified a dozen mature Chinese-language phishing-as-a-service platforms in the criminal underground, many tied to broader regional cybercrime networks.

Google Threat Intelligence · just now · Read full article →

TrapDoor Attack Plants Credential Stealers Across npm, PyPI, and Crates.io (1 minute read)

A coordinated campaign dropped 34 malicious packages across 384 versions on npm, PyPI, and Crates.io starting May 22, 2026, stealing developer credentials at scale. Simultaneous targeting of three major ecosystems signals a sophisticated, multi-vector supply chain strategy designed to maximize developer exposure.

The Hacker News · 2h ago · Read full article →

Megalodon Supply Chain Attack Infects 5,500 GitHub Repositories via Fake Commits (1 minute read)

Attackers injected malicious GitHub Actions workflows through fake automated commits across 5,500-plus repositories, harvesting credentials, CI secrets, and API tokens.

SecurityWeek · just now · Read full article →

CVE-2026-26980: Ghost CMS SQL Injection Flaw Weaponized in ClickFix Campaign (1 minute read)

Attackers are mass-exploiting CVE-2026-26980, a critical SQL injection vulnerability in Ghost CMS, to inject JavaScript that launches ClickFix social-engineering attack flows.

BleepingComputer · 18h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now