Afternoon Review in IT Security — May 24, 2026
The cybersecurity landscape continues to face escalating threats from both legacy vulnerabilities and sophisticated supply chain attacks. Today's threat intelligence reveals active exploitation campaigns targeting IoT devices, coordinated malicious package distribution across multiple ecosystems, and widespread attacks on development infrastructure, underscoring the persistent risk to organizations across all technology stacks.
RondoDox Botnet Exploits Critical 2018 Vulnerability to Hijack ASUS Routers
VulnCheck researchers have identified an active campaign in which the RondoDox botnet is leveraging CVE-2018-5999, a critical vulnerability from 2018, to compromise over one million ASUS routers. The vulnerability permits attackers to bypass authentication mechanisms and gain unauthorized access to affected devices. Source: RondoDox Botnet Exploits Critical 2018 Vulnerability to Hijack ASUS Routers
This campaign demonstrates the continued risk posed by unpatched legacy vulnerabilities in widely deployed consumer networking equipment. Organizations and end users relying on ASUS routers should prioritize firmware updates and implement network segmentation to limit the potential impact of compromised devices.
Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects
Socket researchers have uncovered a coordinated supply chain attack affecting over 700 GitHub repositories through malicious postinstall hooks embedded in package.json files. Eight Composer packages hosted on Packagist were compromised with identical malicious scripts that download and execute a binary named gvfsd-network from attacker-controlled GitHub Releases, writing it to /tmp/.sshd with suppressed error output and background execution. Source: Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects
The attack is particularly concerning because the malicious code was placed in package.json rather than composer.json, targeting repositories that bundle JavaScript build tooling alongside PHP code. This cross-ecosystem placement allows the attack to evade defenders who focus exclusively on Composer metadata while overlooking JavaScript lifecycle scripts. The malicious script uses curl with disabled TLS certificate verification (curl -k), downloads an unauthenticated remote binary, and executes it immediately during installation with no integrity checking. Two affected packages—devdojo/wave with 6,400 GitHub stars and devdojo/genesis with 9,100 Packagist installs—represent the highest risk due to their use as Laravel starter kits, where the malicious package.json lands at the project root and executes during npm install. The attacker infrastructure centered on the GitHub account parikhpreyash4 suggests a broader campaign, with hundreds of additional references detected across Node.js repositories, though the full scope remains unconfirmed.
5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours
SafeDep has disclosed the Megalodon attack, which compromised 5,561 GitHub repositories in just six hours through malicious CI workflows designed to steal cloud credentials. The attack employed two malware variants, Optimize-Build and SysDiag, targeting development infrastructure at scale. Source: 5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours
This campaign highlights the speed and scale at which modern supply chain attacks can propagate through development platforms, with attackers leveraging CI/CD pipeline abuse to extract sensitive cloud credentials from compromised repositories.
Drupal: Critical SQL Injection Flaw Now Targeted in Attacks
Drupal has issued a warning that a highly critical SQL injection vulnerability announced earlier this week is now being actively exploited in the wild. The flaw, tracked as CVE-2026-9082, presents a significant risk to Drupal installations that have not yet applied available patches. Source: Drupal: Critical SQL Injection Flaw Now Targeted in Attacks
Organizations operating Drupal instances should treat this vulnerability with the highest priority and apply security updates immediately to prevent unauthorized database access and potential system compromise.
The convergence of these threats—from legacy IoT vulnerabilities to sophisticated supply chain attacks targeting both package repositories and CI/CD infrastructure—underscores the need for comprehensive security strategies spanning network segmentation, dependency auditing, and continuous monitoring of development pipelines.