Summary & highlights
BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039). BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services Abuse. Nested Triple-Chain Google Domain Phishing — Microsoft SafeLinks -> meet.google.com/linkredirect -> google.com/url -> adservice.google.com.ph Evades SEGs and Lands M365 Credential Theft Plus OAuth 2.0 Device-Code Phishing (KnowBe4 ThreatLabs Nested Delivery Matrix).
Highlights
- TL-2026-0599 — BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039)
- TL-2026-0600 — BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services Abuse
- TL-2026-0601 — Nested Triple-Chain Google Domain Phishing — Microsoft SafeLinks -> meet.google.com/linkredirect -> google.com/url -> adservice.google.com.ph Evades SEGs and Lands M365 Credential Theft Plus OAuth 2.0 Device-Code Phishing (KnowBe4 ThreatLabs Nested Delivery Matrix)
- TL-2026-0602 — Gitea Container Registry Authorization Bypass (CVE-2026-27771) — Unauthenticated Pull of Private Container Images Across 31,000+ Self-Hosted Instances
- TL-2026-0603 — GlassWorm Developer Supply Chain Campaign Takedown — CrowdStrike + Google + Shadowserver Disrupt 4-Channel C2 (Solana / BitTorrent DHT / Google Calendar / VPS)
Theme of the day
Credential theft and active exploitation prevailed: Android banking trojans OverlayPhantom and BTMOB, nested Google-domain phishing, and Akira ransomware via SSLVPN. Critical CVEs hit Windows Kernel, GitHub Enterprise, Starlette/AI infra, plus a multi-CVE BIND 9 disclosure.
- credential-theft
- linux
- active-exploitation
- financially-motivated
- phishing
Threats published
14 threat lines in the 2026-05-27 debrief, most severe first. Each links to its full profile.
- OverlayPhantom Android Banking Trojan — Novel Overlay-Driven Credential Theft Targeting 180+ Banking and Crypto Apps (Cyble CRIL)CRITICAL
- Windows Kernel CVE-2026-40369 — NtQuerySystemInformation ProbeForWrite Bypass Enables Arbitrary Kernel Memory Increment → SYSTEM LPE from Browser Sandboxes (Ori Nimron)CRITICAL
- GitHub Enterprise Server 3.20.3 — Pre-Auth SSRF in Upload Endpoint (CVE-2026-9312) + Bundled "Dirty Frag" Kernel LPEs (CVE-2026-43284, CVE-2026-43500) + Mandatory GPG Signing Key RotationCRITICAL
- BadHost CVE-2026-48710 — Starlette HTTP Host Header Authentication Bypass Affecting FastAPI/AI Infrastructure (MCP, vLLM, LiteLLM)CRITICAL
- JINX-0164 — Crypto-Targeting macOS AUDIOFIX RAT via LinkedIn Social Engineering and Internal CI/CD Hijacking (Wiz CIRT)CRITICAL
- BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039)HIGH
- BTMOB Android RAT — SpySolr Evolution Sold as MaaS via Telegram with APK Builder and Accessibility Services AbuseHIGH
- Nested Triple-Chain Google Domain Phishing — Microsoft SafeLinks -> meet.google.com/linkredirect -> google.com/url -> adservice.google.com.ph Evades SEGs and Lands M365 Credential Theft Plus OAuth 2.0 Device-Code Phishing (KnowBe4 ThreatLabs Nested Delivery Matrix)HIGH
- Gitea Container Registry Authorization Bypass (CVE-2026-27771) — Unauthenticated Pull of Private Container Images Across 31,000+ Self-Hosted InstancesHIGH
- GlassWorm Developer Supply Chain Campaign Takedown — CrowdStrike + Google + Shadowserver Disrupt 4-Channel C2 (Solana / BitTorrent DHT / Google Calendar / VPS)HIGH
- forge-jsxy npm Supply Chain RAT — 22 Versions in 22 Days with Crypto Wallet Theft, WebRTC P2P Exfil & Cross-Platform Persistent Backdoor (OSV MAL-2026-3609, SafeDep)HIGH
- Grandoreiro Banking Trojan Resurgence (May 2026) — Dual-Vector DLL Side-Loading & VBS Geofenced Campaign with SGC WebSockets/WebRTC C2 Tunneled Through Google Cloud Pub/Sub, Azure MQTT and AWS MQTT Targeting 20+ Portuguese Banks, Spain, Mexico and LATAMHIGH
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow Copy Deletion (SANS ISC Forensic Reconstruction, May 2026)HIGH
- EKZ Infostealer Campaign — FortiClient EMS CVE-2026-35616 Abused via on_connect Script Injection (Arctic Wolf, May 2026)HIGH
Techniques observed
216 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1003.001
- T1005
- T1012
- T1018
- T1020
- T1021.001
- T1027
- T1027.010
- T1027.013
- T1029
- T1033
- T1036
- T1036.003
- T1036.005
- T1039
- T1041
- T1046
- T1048
- T1053.004
- T1053.005
- T1053.006
- T1055
- T1056
- T1056.001
- T1056.002
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.005
- T1059.007
- T1068
- T1069.002
- T1070
- T1070.001
- T1071
- T1071.001
- T1078
- T1078.002
- T1078.003
- T1080
- T1082
- T1083
- T1087.002
- T1090
- T1090.002
- T1090.004
- T1098
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110.001
- T1110.002
- T1110.004
- T1113
- T1114
- T1115
- T1119
- T1133
- T1134
- T1134.001
- T1134.002
- T1134.004
- T1136.002
- T1140
- T1176
- T1185
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1203
- T1204
- T1204.002
- T1211
- T1213
- T1213.003
- T1217
- T1218
- T1219
- T1406
- T1409
- T1414
- T1417
- T1417.002
- T1418
- T1422
- T1426
- T1429
- T1430
- T1437
- T1453
- T1456
- T1474
- T1476
- T1481
- T1482
- T1484.001
- T1486
- T1489
- T1490
- T1496
- T1497
- T1497.001
- T1498
- T1498.002
- T1499
- T1499.003
- T1499.004
- T1505
- T1509
- T1512
- T1513
- T1516
- T1517
- T1518
- T1518.001
- T1521
- T1526
- T1528
- T1531
- T1532
- T1533
- T1539
- T1541
- T1543
- T1543.001
- T1543.002
- T1546
- T1547.001
- T1547.009
- T1548
- T1550
- T1550.001
- T1550.003
- T1552
- T1552.001
- T1552.005
- T1552.007
- T1553
- T1555
- T1555.003
- T1558.003
- T1559
- T1560
- T1562
- T1562.001
- T1562.002
- T1564
- T1564.001
- T1565
- T1566
- T1566.002
- T1567
- T1567.002
- T1569.002
- T1571
- T1572
- T1573
- T1573.002
- T1574.002
- T1575
- T1580
- T1582
- T1583
- T1583.001
- T1583.002
- T1583.003
- T1583.004
- T1583.006
- T1584
- T1585
- T1585.003
- T1586
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1589
- T1590
- T1590.002
- T1592
- T1593
- T1595
- T1595.002
- T1596
- T1596.005
- T1602
- T1608
- T1608.001
- T1613
- T1614
- T1614.001
- T1621
- T1622
- T1624
- T1624.001
- T1626
- T1628
- T1628.001
- T1632
- T1636
- T1640
- T1641
- T1644
- T1646
- T1655
- T1655.001
- T1656
- T1657
- T1660
Threat actors
6 named threat actors across the reports.
- BTMOB MaaS operator (Unattributed)
- GlassWorm Operators (Russian-speaking crimeware crew)
- jacksonkaandorp2 (npm supply-chain operator)
- Grandoreiro operators
- Akira (ransomware-as-a-service operation)
- JINX-0164
Nation-state attribution
- Russia
- Brazil
Threat categories
- VULNERABILITY
- MALWARE
- PHISHING
- SUPPLY_CHAIN
- RANSOMWARE
- APT
Severity breakdown
- critical5
- high9
- medium0
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 111
- behavioral 104
- file 64
- infrastructure 29
- package 29
- technique 22
- malware 19
- tool 16
- entity 4