Skip to main content
Back to articles
Security Solutions Team

CISO Daily Digest: Cybersecurity Roundup (20260527)

Taiwan's EVERY8D OTP platform was breached, North Korean Lazarus Group deployed RemotePE malware targeting financial institutions, and a Ghost CMS SQL injection compromised 700+ sites with ClickFix attacks, while Microsoft patched the UnDefend and RedSun zero-days and the Megalodon malware campaign infected thousands of GitHub repos.

CISO cybersecurity threat intelligence

EVERY8D Breach, Lazarus Campaign, Ghost CMS ClickFix, and Widespread Vulnerability Disclosures

  • Taiwan’s largest OTP messaging platform EVERY8D was hacked, with F-ISAC issuing an orange-level security alert
  • North Korean Lazarus Group targeted financial and cryptocurrency institutions using the RemotePE malware
  • Ghost CMS SQL injection vulnerability exploited to hack 700+ websites spreading ClickFix attacks; JPCERT issued weekly vulnerability reports covering Drupal, Cisco, Splunk, BIND, Chrome, and more

πŸ”— εƒθ€ƒθ³‡ζ–™οΌš 碜合報導(EVERY8D Breach、Lazarus RemotePE、Ghost CMS ClickFixοΌ‰

ζœ¬ι€±ζ΄»θΊε¨θ„…

πŸ“Œ Microsoft Patches Two Zero-Days: UnDefend and RedSun

Microsoft fixed two zero-day vulnerabilities β€” codenamed UnDefend and RedSun β€” affecting multiple Windows components, with active exploitation reported in the wild.

πŸ”— Reference: xakep.ru

πŸ“Œ Laravel Lang Packages Compromised to Distribute Malware

Compromised Laravel Lang packages on Packagist were found distributing malware to PHP developers, highlighting ongoing supply chain risks in the PHP ecosystem.

πŸ”— Reference: xakep.ru

πŸ“Œ Megalodon Malware Infects Thousands of GitHub Repos

The β€˜Megalodon’ malware campaign infected thousands of GitHub repositories in a large-scale software supply chain attack, stealing credentials and injecting malicious code.

πŸ”— Reference: Dark Reading

πŸ“Œ llama.cpp GGUF Parser Critical Integer Overflow Enables Arbitrary Reads in AI Stacks

Critical integer overflow vulnerabilities were discovered in the llama.cpp GGUF parser, enabling arbitrary memory reads across every local AI deployment using the popular framework.

πŸ”— Reference: Tech Times

πŸ“Œ AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites

Researchers found that AI chatbot recommendations are being manipulated to redirect users to cryptojacking malware sites, exploiting user trust in AI-generated responses.

πŸ”— Reference: The Hacker News

πŸ“Œ Hackers Abuse Google Ads with Claude.ai Share Pages to Distribute macOS Malware

Threat actors abused Google Ads combined with shared Claude.ai conversation pages to distribute malware targeting macOS users.

πŸ”— Reference: iThome

πŸ“Œ Apple Integrates Two Quantum-Safe Algorithms into Core Cryptography Libraries

Apple added two post-quantum cryptographic algorithms to its OS-level cryptography libraries and introduced formal verification tools.

πŸ”— Reference: iThome

πŸ“Œ 7-Zip Fixes Critical NTFS Image Bug Allowing Arbitrary Code Execution

7-Zip released a new version patching a critical vulnerability in malicious NTFS image file handling that could lead to arbitrary code execution.

πŸ”— Reference: iThome

πŸ“Œ ExifTool Fixes macOS Command Injection Vulnerability via Malicious Image Metadata

A command injection vulnerability in ExifTool for macOS allows attackers to execute arbitrary commands through crafted image metadata β€” update immediately.

πŸ”— Reference: iThome

πŸ“Œ Taiwan MODA Tests 4 Chinese Apps: AutoNavi Found More Dangerous Than Google Maps

Taiwan’s Ministry of Digital Affairs tested four Chinese apps for security, finding AutoNavi (Gaode) maps posed greater privacy risks than Google Maps.

πŸ”— Reference: iThome