Daily Briefing

CyberGeoDigest

Geopolitical cyber intelligence in 5 minutes
Tuesday, May 26, 2026 · 15 stories
Share this digest:

Lazarus Deploys Memory-Only RemotePE RAT Against Crypto and Finance Firms (1 minute read)

North Korea's Lazarus Group is deploying a fileless RAT called RemotePE via a two-stage loader chain—DPAPILoader and RemotePELoader—against financial and cryptocurrency targets.

The Hacker News · 22h ago · Read full article →

🇰🇵 Lazarus · North Korea

Laravel-Lang Supply Chain Attack Backdoors CI Pipelines to Steal Secrets (1 minute read)

Attackers poisoned Laravel-Lang packages within a 15-minute publication window, introducing backdoors designed to exfiltrate CI/CD pipeline secrets. The compressed attack timeline suggests automation and targets developer credentials with broad downstream access across dependent projects.

SecurityWeek · 21h ago · Read full article →

Netherlands Arrests 2, Seizes 800 Servers Hosting Russian Cyber Operations (2 minute read)

Dutch authorities arrested co-owners of two hosting firms that operated infrastructure for Russian cyberattacks, influence ops, and disinformation inside the EU, linked to sanctioned provider Stark Industries Solutions.

Krebs on Security · 18h ago · Read full article →

U.S. Manufacturing Decline Leaves Economic Statecraft Without Backbone (3 minute read)

China's 2010 rare-earth embargo against Japan exposed how industrial capacity underpins geopolitical leverage, a vulnerability the U.S. now mirrors. Washington cannot credibly wield economic statecraft while dependent on adversary supply chains for critical goods.

War on the Rocks · 1h ago · Read full article →

Pentagon Climate Program Cuts Degrade Base Resilience and Combat Readiness (3 minute read)

The Trump administration cut $1.2 billion from NOAA, USGS, and DoD climate programs—equal to the cost of repairing flood damage at Offutt AFB in 2019 alone.

War on the Rocks · just now · Read full article →

U.S. Military's Missing Ethics Doctrine Corrodes Battlefield Decision-Making (3 minute read)

A Marine officer's firsthand account from al-Qa'im, Iraq illustrates how the absence of a codified military ethics doctrine produces inconsistent life-and-death decisions at the tactical level.

War on the Rocks · 1h ago · Read full article →

ShinyHunters Steals 185,000 Records from 7-Eleven in April Breach (1 minute read)

Extortion group ShinyHunters exfiltrated personal data on 183,000-plus individuals after breaching 7-Eleven's systems in April, confirmed via Have I Been Pwned. ShinyHunters continues targeting high-volume consumer brands to monetize bulk PII, sustaining a criminal data-broker pipeline that feeds downstream fraud.

BleepingComputer · 1h ago · Read full article →

Oncology Institute Discloses Patient Data Breach via Third-Party Vendor (1 minute read)

The Oncology Institute disclosed a data breach originating from an unnamed third-party vendor, with TriZetto identified as a possible candidate. Healthcare supply-chain breaches continue to expose sensitive oncology patient records through vendor access points outside direct institutional control.

SecurityWeek · 20h ago · Read full article →

Radiology Associates of Richmond Breach Exposes 266,000 Patients' Health Data (1 minute read)

Threat actors exfiltrated files containing names and protected health information from Radiology Associates of Richmond, affecting 266,000 individuals. The breach adds to a sustained pattern of ransomware and data-theft operations targeting mid-size regional healthcare providers with limited security resources.

SecurityWeek · 21h ago · Read full article →

DocketWise Breach Leaks SSNs and Financial Data on 143,000 Individuals (1 minute read)

Hackers accessed names, addresses, Social Security numbers, financial records, and medical data from DocketWise third-party partner repositories, impacting 143,000 people. Third-party repository exposure remains a critical gap, giving attackers high-value PII without breaching the primary target's core infrastructure.

SecurityWeek · 22h ago · Read full article →

CVE-2026-5426 Zero-Day in Japanese LMS Drops Godzilla Shell, Cobalt Strike (1 minute read)

Attackers exploited CVE-2026-5426 (CVSS 7.5) in Digital Knowledge's KnowledgeDeliver LMS—widely used in Japan—as a zero-day to plant the Godzilla web shell and stage Cobalt Strike Beacon. Hard-coded ASP.NET machine keys as the root cause signals a systemic secure-development failure in enterprise education software.

The Hacker News · 2h ago · Read full article →

Linux Flaws, Microsoft Defender Zero-Days, Router Botnets Hit in Single Week (2 minute read)

A week of overlapping incidents—supply chain-poisoned dev tools, revived legacy CVEs, router botnets, and Defender zero-days—compressed multiple attack surfaces into one reporting cycle. The convergence illustrates how defenders triaging one crisis routinely miss simultaneous exploitation of forgotten infrastructure.

The Hacker News · 18h ago · Read full article →

Ghost CMS Vulnerability Compromises 700 Sites Including Harvard and Oxford (1 minute read)

Attackers exploited a Ghost CMS flaw to backdoor over 700 websites, including Harvard, Oxford, and DuckDuckGo. Compromise of high-trust institutional domains creates ready infrastructure for credential phishing and disinformation distribution at scale.

SecurityWeek · 18h ago · Read full article →

AI Accelerates Exploit Development, Forcing Defensive Triage Into Arms Race (1 minute read)

Attackers are using AI to compress vulnerability discovery and weaponization timelines, narrowing the patch window defenders depend on. The asymmetry favors offense—finding one exploitable flaw beats defending every surface simultaneously.

Wired Security · 21h ago · Read full article →

CVE-2026-26980 SQL Injection Hijacks 700+ Ghost CMS Sites for ClickFix (1 minute read)

Unidentified threat actors are exploiting CVE-2026-26980 (CVSS 9.4), an unauthenticated SQL injection flaw in Ghost CMS Content API, to inject malicious JavaScript across 700+ compromised sites. Scale of infection signals an automated campaign weaponizing a freshly disclosed critical flaw before defenders can patch.

The Hacker News · 20h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now