Offensive supply chain, unprecedented APT operations, new vulnerabilities exploited ITW
Threat: multiple supply chain attacks detected
On May 13, 2026, OpenAI published an official statement confirming that it had been affected by the supply chain attack known as Mini Shai-Hulud. The company determined that two devices within its corporate environment had been compromised. The malicious activity detected was limited to unauthorized access and credential exfiltration from a subset of internal source code repositories. Credentials potentially involved included those related to signing certificates used for iOS, macOS, and Windows products. OpenAI specified that no malicious software had been signed using its certificates and that customer passwords and API keys had not been compromised. A few days later, on May 17, 2026, a new supply chain attack campaign emerged on npm, carried out through the upload of four malicious packages to the platform by a single attacker, one of which represented a direct and unobfuscated clone of the Shai-Hulud malware. Furthermore, on May 19, 2026, security researchers tracked a new wave of supply chain attacks still linked to the Mini Shai-Hulud campaign, which affected hundreds of packages, with a particular concentration in the @antv ecosystem dedicated to data visualization, charting, mapping, and React components, in addition to other widely used packages such as echarts-for-react, timeago.js, and size-sensor. Grafana Labs confirmed a targeted attack by an unauthorized actor who gained access to its GitHub repositories and downloaded source code. The incident originated from a supply chain attack targeting TanStack npm packages as part of the Mini Shai-Hulud campaign. The investigation ruled out any compromise of production systems, customer operations, or the Grafana Cloud platform. No evidence also emerged of access to customer data or personal information. Although Grafana Labs did not publicly attribute the breach to a specific adversary, on May 15, 2026, the ransomware group Coinbase Cartel claimed responsibility for the attack on its leak site. Finally, GitHub launched an investigation into unauthorized access to its internal repositories after the group TeamPCP claimed on an underground forum to have gained access to approximately 4,000 private repositories containing the platform’s source code and information related to internal organizations. The activity reportedly involved only GitHub’s internal repositories, with no evidence of impact on public repositories or customer-hosted repositories. The company announced its intention to provide a more comprehensive report once internal analyses are completed.
APT: Ukrainian, Belarusian, Russian, and Asian operations tracked
Starting in March 2026, security researchers tracked a new spear phishing campaign orchestrated by the Belarusian group Ghostwriter, primarily targeting governmental and military organizations in Ukraine and aimed at distributing the JavaScript variant of PicassoLoader. In addition, between September 2025 and May 2026, researchers identified an ongoing operation attributed to Gamaredon Group against Ukrainian state institutions, aimed at distributing GammaDrop and GammaLoad. The offensive consists of dozens of spear phishing waves using emails with spoofed senders or messages sent from compromised governmental e-mail accounts. Furthermore, a campaign orchestrated by the Russian Turla Group emerged, aimed at deploying the Kazuar backdoor against governmental and diplomatic organizations in Europe, Central Asia, and Ukraine, with a particular focus on ministries of foreign affairs, embassies, government offices, and defense-related entities. Infection typically occurs through dropper variants that deploy .NET or native loaders, often with in-memory execution of the final payload, whose primary objective appears to be intelligence collection in support of Russian foreign policy and military objectives. From late September 2025 and at least until April 2026, security researchers observed an operation attributed with moderate confidence to the Chinese state-sponsored group Mustang Panda, which targeted entities in the Asia-Pacific and Japan (APJ) region using an updated version (3.2.5.1) of the FDMTP backdoor; one documented case involved a financial sector organization where access was maintained for eleven consecutive days. The Beijing-linked APT used infrastructure impersonation techniques for content delivery, mimicking well-known services associated with Yahoo and Apple. Lastly, a campaign named Operation Dragon Whistle was observed, orchestrated by a group called UNG0002 (alias Unknown Group 0002), assessed with high confidence to originate from Southeast Asia, targeting the Chinese education sector and aimed at the reflective loading of Cobalt Strike on target systems.
Vulnerabilities: Microsoft and Cisco flaws exploited ITW
Microsoft assigned the identifier CVE-2026-45585 (CVSS 6.8) to the recently disclosed 0-day known as YellowKey and released an advisory stating that it is aware of instances of exploitation of CVE-2026-42897 (CVSS 7.5), a Cross-Site Scripting (XSS) vulnerability affecting Exchange Outlook Web Access (OWA), through which an attacker could send a specially crafted e-mail to a user and execute arbitrary JavaScript in the browser context. The flaw was added by CISA to its KEV catalog after evidence of active exploitation was identified. Also, on May 20 and 21, 2026, CISA added the following vulnerabilities to its KEV catalog: CVE-2008-4250 affecting Microsoft Windows, CVE-2009-1537 affecting Microsoft DirectX, CVE-2009-3459 affecting Adobe Acrobat and Reader, CVE-2010-0249 and CVE-2010-0806 affecting Microsoft Internet Explorer, CVE-2026-41091 and CVE-2026-45498 affecting Microsoft Defender, CVE-2025-34291 affecting Langflow, and CVE-2026-34926 affecting Trend Micro Apex One (On-Premise). CVE-2025-34291 had already been reported as exploited ITW in a campaign by the Iranian state-sponsored group MuddyWater targeting the Middle East. Agencies within the US Federal Civilian Executive Branch (FCEB) were tasked with remediating CVE-2008-4250, CVE-2009-1537, CVE-2009-3459, CVE-2010-0249, CVE-2010-0806, CVE-2026-41091, and CVE-2026-45498 by June 3, 2026; while CVE-2025-34291 and CVE-2026-34926 must be addressed by June 4, 2026. As for Cisco, it released security advisories warning about an ITW-exploited flaw tracked as CVE-2026-20182 (CVSS 10.0). This Authentication Bypass vulnerability could allow a remote unauthenticated adversary to bypass authentication and obtain administrative privileges on an affected system. Cisco Talos stated that exploitation activity has so far been limited in scope and is attributed with high confidence to the cluster UAT-8616. Specifically, in post-compromise operations observed following exploitation of the vulnerability, UAT-8616 attempted to add authorized SSH keys, modify NETCONF configurations, and escalate privileges to root, leveraging infrastructure overlapping with monitored ORB networks.
Weekly Threats Report is Telsy’s weekly update featuring the main developments on cyber attacks and threat actors worldwide, produced by our Threat Intelligence & Response team.
The team is composed of analysts and security researchers with technical and investigative skills and internationally recognized experience.
Through continuous monitoring of cyber threats and geopolitical events, it produces and provides organizations with useful information to anticipate attacks and understand their scope, with the support of a trusted partner in the event of a cyber incident.
Learn more about our Cyber Threat Intelligence solution.
