Weekly review

ThreatNoir Afternoon Brief — May 26

2026-05-26Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — May 26, 2026

The threat landscape continues to evolve rapidly as security teams face mounting pressure from both opportunistic cybercriminals and state-sponsored actors. Today's briefing covers critical vulnerabilities affecting widely-deployed systems, advanced persistent threat campaigns, and significant data breaches impacting consumer privacy.

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment

Threat actors have been actively exploiting a zero-day vulnerability in KnowledgeDeliver through hardcoded machineKey values stored in configuration files. This weakness enables ViewState deserialization attacks that lead to remote code execution on affected systems. Security researchers have identified the deployment of notorious post-exploitation tools including Cobalt Strike and Godzilla malware following successful exploitation. Source: SecurityWeek

The vulnerability, tracked as CVE-2026-5426, represents a critical risk to organizations running vulnerable versions of the KnowledgeDeliver platform. The combination of weak cryptographic configuration and remote code execution capabilities creates a direct pathway for attackers to establish persistent access and deploy additional malicious payloads within compromised environments.

CISA Orders Federal Agencies to Patch Actively Exploited Drupal Vulnerability

The Cybersecurity and Infrastructure Security Agency has issued an urgent directive requiring all U.S. government agencies to patch an actively exploited SQL injection vulnerability in the Drupal content management system by Wednesday evening. Source: BleepingComputer

Identified as CVE-2026-9082, this vulnerability poses an immediate threat to federal infrastructure and systems that depend on Drupal for content delivery. The active exploitation in the wild and the compressed remediation timeline underscore the severity of the threat and CISA's commitment to securing government digital assets against ongoing attacks.

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning

The Iranian state-sponsored threat actor Nimbus Manticore, also known as Screening Serpens and UNC1549, has launched a sophisticated campaign distributing malware variants MiniFast, MiniJunk V2, and MiniUpdate. The attackers are leveraging phishing emails and search engine optimization poisoning to target organizations in the aviation and software sectors across the United States, Europe, and the Middle East. Source: The Hacker News

This campaign follows the joint U.S.-Israeli military operations against Iran in late February 2026, suggesting a retaliatory cyber offensive. The use of multiple malware variants and multi-vector delivery mechanisms demonstrates the sophistication of the Iranian threat actor and the sustained targeting of critical infrastructure sectors. Researchers have identified the malicious domain getsqldeveloper[.]com as part of the attack infrastructure.

7-Eleven Data Breach Exposes Personal Information of 185,000 People

The ShinyHunters extortion gang has claimed responsibility for a data breach affecting 7-Eleven, resulting in the theft of personal information belonging to over 183,000 individuals. The breach occurred in April 2026 and was confirmed through the Have I Been Pwned data breach notification service. Source: BleepingComputer

The compromise of the convenience store chain's systems represents a significant privacy incident with potential consequences for affected consumers. The involvement of ShinyHunters, a known extortion-focused threat group, suggests the attackers may be leveraging the stolen data for financial gain through ransom demands or sale on underground markets.

Today's threat intelligence reflects the continuing convergence of financially-motivated cybercrime, state-sponsored operations, and zero-day exploitation affecting both commercial and government sectors. Organizations should prioritize patching of known vulnerabilities while implementing enhanced monitoring for indicators of compromise related to the identified malware families and infrastructure.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning
Malware3
  • MiniUpdate
    Alternate name for MiniFast backdoor
  • MiniJunk
    Trojan malware delivered via AppDomain hijacking in earlier campaign phases
  • MiniFast
    AI-assisted backdoor deployed by Nimbus Manticore for persistence and remote command execution
Domain1
  • getsqldeveloper[.]com
    Fake SQL Developer download page used in SEO poisoning campaign to deliver MiniFast