THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
cPanel zero-day mass exploitation compromises 40,000+ servers

Attackers are actively exploiting a recently patched cPanel authentication bypass (CVE-2026-41940), leading to administrative takeover of hosting servers at scale. SecurityWeek reports more than 40,000 systems have been compromised so far, underscoring the urgency to patch, rotate credentials, and audit for web shell or backdoor persistence.

Source: SecurityWeek


Critical MOVEit Automation auth bypass and privilege escalation patched

Progress Software fixed a critical authentication bypass (CVE-2026-4670) and a privilege escalation (CVE-2026-5174) in MOVEit Automation that could enable unauthorized administrative access and data exposure. While exploitation hasn’t been reported, enterprises should urgently upgrade, review access logs, and validate workflow integrity given MOVEit’s history of high-impact attacks.

Source: Help Net Security


DigiCert support portal breach forces certificate revocations

A social engineering attack delivered malware via a customer chat, compromising an analyst’s machine and enabling access to DigiCert’s internal support systems. The Certificate Authority revoked impacted certificates and initiated incident response—customers should monitor revocation lists, re-issue code-signing materials, and review their trust chains.

Source: SecurityWeek


Canvas (Instructure) breach exposes student data and messages

Edtech provider Instructure disclosed a cyber incident affecting its Canvas LMS, with hackers stealing names, email addresses, student ID numbers, and user messages. With ShinyHunters threatening leaks, institutions should enable forced password resets, tighten SSO and MFA controls, and assess exposure of internal communications.

Source: SecurityWeek


‘Copy Fail’ Linux kernel bug added to CISA KEV as exploitation begins

CISA added the Linux “Copy Fail” vulnerability (CVE-2026-31431) to its Known Exploited Vulnerabilities catalog, and Microsoft has observed limited in-the-wild activity. Organizations should apply vendor patches immediately, prioritize internet-exposed and multi-tenant systems, and monitor for privilege escalation attempts linked to recent PoCs.

Source: SecurityWeek


DarkSword iOS exploit chain used by spyware vendors and state actors

Google’s Threat Intelligence Group identified “DarkSword,” a full iOS zero-day exploit chain deployed since late 2025 by commercial surveillance vendors and suspected state-backed actors. Campaigns targeted users in Saudi Arabia, Turkey, Malaysia, and Ukraine; iOS users should update promptly and consider Lockdown Mode where feasible.

Source: Schneier on Security


Microsoft: Large-scale credential theft hits 35,000 users in 26 countries

A multi-stage phishing operation used code-of-conduct themed lures and legitimate mail services to drive victims to attacker domains and steal authentication tokens, impacting more than 13,000 organizations. Defenders should enforce phishing-resistant MFA, block malicious OAuth consent, and monitor for token abuse and anomalous sign-ins.

Source: The Hacker News


You May Also Be Interested In...

Trellix Source Code Repository Breached

WhatsApp Discloses File Spoofing, Arbitrary URL Scheme Vulnerabilities

New ConsentFix v3 attack automates Microsoft Azure account hijacking

Cybersecurity — May 5, 2026 | Briefing24