{"id":923,"date":"2026-05-14T17:25:54","date_gmt":"2026-05-14T17:25:54","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=923"},"modified":"2026-05-14T17:25:54","modified_gmt":"2026-05-14T17:25:54","slug":"pan-os-rce-mythos-curl-bug-ai-tokenizer-attacks-and-10-stories","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=923","title":{"rendered":"PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">May 14, 2026<\/span><\/span><span class=\"p-tags\">Hacking News \/ Cybersecurity News<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjImYNT-qC7frGzEXeok3KDX_JNMKote6V1FVXIpkAoSEER2z1YyT8dpFq5RtRhBQ0cweEPbBIuioDWFf5rw_Mf-0V6rXR2ZrMh2ISDa7X7NlV9zIGsoLSAnyd_86eVkrR4wU24yxbuCYaAmyGFwlF77YCjvgU3n43P-yFT-pzjsmQ35Oaut1klg62bs_-i\/s1700-e365\/threatsday-2.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>Everything is still on fire.<\/p>\n<p>This week feels dumb in the worst way \u2014 bad links, weak checks, fake help desks, shady forum posts, and people turning supply chain attacks into some cursed little game for clout and cash. Half of it feels new. Half of it feels like crap we should have fixed years ago.<\/p>\n<p>The mess keeps getting louder: users get tricked, boxes get popped, tools meant for normal work get used for bad stuff, and nobody seems shocked anymore. Great. Love that for us.<\/p>\n<p>Anyway. Let\u2019s get into it.<\/p>\n<div class=\"td-wrap\">\n<section aria-labelledby=\"threatsday-title\" class=\"td-section\">\n<ol class=\"td-timeline\" role=\"list\">\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Exploited PAN-OS RCE<\/span><\/p>\n<p class=\"td-desc\">\n      Palo Alto Networks has released the first round of fixes to address CVE-2026-0300, a critical buffer overflow vulnerability in the User-ID Authentication Portal service of PAN-OS software that could allow an unauthenticated attacker to execute arbitrary code with root privileges by sending specially crafted packets. The company said it has observed the flaw being exploited in limited attacks since at least last month, with unknown threat actors leveraging it to drop payloads like EarthWorm and ReverseSocks5.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<p><a name=\"more\"\/><\/p>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Private AI chats<\/span><\/p>\n<p class=\"td-desc\">\n      Meta has <a href=\"https:\/\/about.fb.com\/news\/2026\/05\/incognito-chat-whatsapp-meta-ai\/\">announced<\/a> Incognito Chat with Meta AI in its namesake app and WhatsApp. Incognito Chat is \u00aba completely private way to interact with AI, similar to how end-to-end encryption means no one can read your conversations, even Meta or WhatsApp,\u00bb CEO Mark Zuckerberg said. \u00abIncognito Chat handles all AI inference in a Trusted Execution Environment that ensures your messages are not accessible to us. The conversations on your phone also disappear when you exit the session.\u00bb The feature is powered by Private Processing, which already underlies its message summarization and composition tools.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Zero-auth data leak<\/span><\/p>\n<p class=\"td-desc\">\n      A defense technology company with Department of Defense contracts exposed user records and military training materials through API endpoints that lacked meaningful authorization checks. The issue affected Schemata, an AI-powered virtual training platform used in military and defense settings. According to <a href=\"https:\/\/www.strix.ai\/blog\/how-strix-found-zero-auth-vulnerability-dod-backed-startup\">Strix<\/a>, an ordinary low-privilege account was able to access data across multiple tenants, including user listings, organization records, course information, training metadata, and direct links to documents hosted on Schemata\u2019s Amazon Web Services instances. In a statement posted on the company\u2019s website, Schemata <a href=\"https:\/\/schemata.com\/blog\/security-disclosure-notice-and-response\">said<\/a> it did not have \u00abevidence that any third party exploited the vulnerability to access customer data.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Router update reprieve<\/span><\/p>\n<p class=\"td-desc\">\n      The U.S. Federal Communications Commission (FCC) has extended the deadline for owners of banned internet routers to provide security updates to U.S.-based users by two years. In March 2026, the FCC banned the import and sale of all \u00abconsumer-grade\u00bb internet routers produced in a foreign country, citing unacceptable national security risks. In a new public notice published last week, the Commission&#8217;s Office of Engineering and Technology (OET) said it is extending this deadline until \u00abat least\u00bb January 1, 2029. That said, the extension only applies to software and firmware updates so as to ensure the continued safety of already deployed routers in the U.S. and mitigate potential harm. \u00abThese include all software and firmware updates to ensure the continued functionality of the devices, such as those that patch vulnerabilities and facilitate compatibility with different operating systems,\u00bb per the <a href=\"https:\/\/www.fcc.gov\/document\/oet-announces-extension-and-expansion-waivers\">FCC<\/a>.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">APT phishing campaign<\/span><\/p>\n<p class=\"td-desc\">\n      A new state-sponsored threat cluster dubbed Operation GriefLure has been <a href=\"https:\/\/www.seqrite.com\/blog\/operation-grieflure-dissecting-an-apt-campaign-targeting-vietnams-military-telecom-philippine-healthcare\/\">observed<\/a> targeting Vietnam&#8217;s telecom and the Philippines&#8217; healthcare sectors with a RAR archive distributed via spear-phishing emails to deploy a remote access trojan on compromised hosts, while leveraging credible decoy documents to give them a veneer of legitimacy and trust. The malware is capable of process enumeration, screenshot capture, file and directory listing, credential harvesting, and file execution capabilities.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">JPEG PowerShell lure<\/span><\/p>\n<p class=\"td-desc\">\n      A multi-stage intrusion campaign has been observed leveraging a weaponized PowerShell payload disguised as a legitimate JPEG image file to deliver a trojanized instance of ConnectWise ScreenConnect to stealthy remote access. \u00abThe intrusion likely originated through social engineering techniques such as phishing emails, malicious attachments, deceptive file-sharing interactions, or fake update lures involving a malicious file named sysupdate.jpeg,\u00bb CYFIRMA <a href=\"https:\/\/www.cyfirma.com\/research\/operation-silentcanvas-jpeg-based-multistage-powershell-intrusion\/\">said<\/a>. \u00abThe payload was specifically crafted to exploit user trust and bypass conventional file-extension validation mechanisms while blending malicious activity with legitimate enterprise software.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Aid-themed infostealer<\/span><\/p>\n<p class=\"td-desc\">\n      A targeted cyber espionage campaign is leveraging social engineering and trusted infrastructure to establish persistent access to victim systems. The activity, which employs lure themes centred around humanitarian aid, is assessed to target Russian-speaking individuals or entities. \u00abThe attack is delivered via phishing emails containing a malicious LNK file disguised within a RAR archive, using a Russian humanitarian aid request form to exploit contextual trust,\u00bb Cyble <a href=\"https:\/\/cyble.com\/blog\/operation-humanitarianbait-infostealer-campaign\/\">said<\/a>. \u00abExecution triggers a stealthy, multi-stage infection chain in which a decoy document is presented to the user while a heavily obfuscated, fileless (PE-less) Python-based implant is silently deployed.\u00bb The payload is retrieved from GitHub Releases, allowing the operator to blend in with legitimate enterprise activity. The implant operates as a \u00abfull-spectrum surveillance platform,\u00bb facilitating credential harvesting, keystroke logging, clipboard and screenshot capture, sensitive data exfiltration, and covert remote access.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Ransomware-like file lock<\/span><\/p>\n<p class=\"td-desc\">\n      A new proof-of-concept (PoC) tool dubbed GhostLock, created by Kim Dvash of Israel Aerospace Industries, has revealed that it&#8217;s possible for a domain user with read access to a file share to deny access to files without the need for deploying any ransomware or requiring elevated privileges. \u00abBy calling CreateFileW with dwShareMode = 0x00000000 across a target share, a low-privileged user holds files in an exclusively locked state indefinitely,\u00bb Dvash <a href=\"https:\/\/ghostlock.io\/\">said<\/a>. \u00abOther clients receive STATUS_SHARING_VIOLATION (0xC0000043) on every access attempt. ERP systems fail. Workflow queues stall. The impact is indistinguishable from encrypted ransomware. The attack produces none of the signals that encrypted ransomware produces.\u00bb The disruptive technique is not a vulnerability, but rather documented behavior required for data integrity. <a href=\"https:\/\/github.com\/kimd155\/ghostlock\">GhostLock<\/a> affects \u00abany organization running SMB-backed shared file infrastructure where users have standard domain credentials and network access to file shares.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">AI scan false positives<\/span><\/p>\n<p class=\"td-desc\">\n      cURL developer Daniel Stenberg said that Anthropic Mythos model&#8217;s scan of the utility five \u00abconfirmed security vulnerabilities,\u00bb out of which one was a low-severity bug, while the rest were false positives. \u00abThe single confirmed vulnerability is going to end up a severity low CVE planned to get published in sync with our pending next curl release 8.21.0 in late June,\u00bb Stenberg <a href=\"https:\/\/daniel.haxx.se\/blog\/2026\/05\/11\/mythos-finds-a-curl-vulnerability\/\">said<\/a>. \u00abThe flaw is not going to make anyone grasp for breath. All details of that vulnerability will ofcourse not get public before then, so you need to hold out for details on that.\u00bb Stenberg, however, acknowledged that artificial intelligence powered code analyzers are significantly better at finding security flaws and mistakes in source code than any traditional code analyzers.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Fraud intel pact<\/span><\/p>\n<p class=\"td-desc\">\n      The Indian Cyber Crime Coordination Centre (I4C), along with the Ministry of Home Affairs, and Reserve Bank Innovation Hub (RBIH), have <a href=\"https:\/\/www.pib.gov.in\/PressReleasePage.aspx?PRID=2260277&amp;reg=3&amp;lang=2\">signed<\/a> a Memorandum of Understanding (MoU) to \u00abfacilitate cooperation in the areas of fraud-risk intelligence sharing, analytical support, and operational coordination for strengthening proactive fraud detection and prevention mechanisms.\u00bb The goal is to combat cyber-enabled financial fraud and curtail mule accounts across the banking and digital payments ecosystem.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">OnlyFans ransomware lure<\/span><\/p>\n<p class=\"td-desc\">\n      Attackers are enticing users seeking \u00abfree OnlyFans accounts\u00bb to download a seemingly harmless ZIP file that contains the crpx0 ransomware. The activity targets both Windows and macOS systems. \u00abInside that ZIP file is a small trick, a malicious shortcut disguised as something legitimate. When the user clicks it, it quietly executes hidden commands,\u00bb Aryaka <a href=\"https:\/\/www.aryaka.com\/blog\/crpx0-ransomware-multi-stage-attack\/\">said<\/a>. \u00abA VBScript loader prepares the system and silently installs the components needed to run Python-based code. This is where the attack becomes more flexible. Rather than relying on a single static payload, the attackers now have a programmable environment. Once the Python script is running, it connects to a remote server.\u00bb The Python-based malware allows the attackers to send commands, update the malware, or deploy new payloads. This enables system profiling, clipboard hijacking to conduct cryptocurrency theft, seed phrase harvesting, andransomware deployment.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">ClickFix proxy access<\/span><\/p>\n<p class=\"td-desc\">\n      A new ClickFix campaign carried out via a compromised website has been observed using scheduled tasks for persistence and <a href=\"https:\/\/github.com\/MisterDaneel\/pysoxy\/\">PySoxy<\/a>, an open-source Python SOCKS5 proxy, to establish encrypted proxy access. \u00abIn the observed chain, one user-executed command led to persistence, domain reconnaissance, an initial PowerShell-based command-and-control (C2) channel, and a second C2 path through PySoxy, giving the attacker encrypted proxy access without relying on well-known malware or remote monitoring and management (RMM) tools,\u00bb ReliaQuest <a href=\"https:\/\/reliaquest.com\/blog\/threat-spotlight-clickfix-evolves-with-pysoxy-proxying\/\">said<\/a>. \u00abThis development shows ClickFix moving beyond one-time user execution into modular post-exploitation, where older open-source tools can create redundant access paths that are harder to classify and contain.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Tokenizer output hijack<\/span><\/p>\n<p class=\"td-desc\">\n      HiddenLayer has demonstrated a technique called tokenizer tampering that details how modifying the \u00abtokenizer.json\u00bb file in Hugging Face AI models can give an attacker direct control over model output, enabling an attacker to exfiltrate sensitive data via, say, stealthy tool call injections. The attack works across Safetensors, ONNX, and GGUF formats. \u00abTokenizer.json ships with the model in a HuggingFace repository, as shown above, and is loaded automatically when the model is initialized for inference, making it a direct attack surface,\u00bb HiddenLayer <a href=\"https:\/\/www.hiddenlayer.com\/research\/tokenizer-tampering\">said<\/a>. \u00abThis can affect conversational responses, tool-call arguments, and any other generated text, without weight modifications, adversarial input, or knowledge of the model\u2019s architecture.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Teams helpdesk lure<\/span><\/p>\n<p class=\"td-desc\">\n      Threat actors are sending Microsoft Teams messages from a fake IT Support account to trigger an attack chain that enables remote access, malware deployment, privilege escalation, credential theft, lateral movement, and exfiltration. \u00abBy abusing Teams external access, the threat actor delivered a Dropbox-hosted Python payload [called ModeloRAT] that established command-and-control, deployed multiple backdoors, and began mapping the internal environment,\u00bb Rapid7 <a href=\"https:\/\/www.rapid7.com\/blog\/post\/tr-it-support-dissecting-modelorat-campaign-microsoft-teams-compromise\/\">said<\/a>. \u00abThe attacker then escalated privileges to SYSTEM using CVE-2023-36036 before deploying a fake Windows lock screen designed to harvest the user&#8217;s domain password.\u00bb The attackers then moved laterally to a second host, used legitimate tooling such as DumpIt to gather system memory, and likely exfiltrated the data via an anonymous file-sharing service. ReliaQuest has <a href=\"https:\/\/reliaquest.com\/blog\/threat-spotlight-help-desk-lures-drop-kongtukes-evolved-modelorat\/\">attributed<\/a> the activity to a financially motivated initial access broker (IAB) tracked as KongTuke.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">Supply chain contest<\/span><\/p>\n<p class=\"td-desc\">\n      The notorious threat actor known as TeamPCP, which was recently linked to the compromise of <a href=\"https:\/\/tanstack.com\/blog\/incident-followup\">TanStack&#8217;s npm packages<\/a>, has teamed up with Breached forum to announce a supply chain attack competition with a $1,000 prize in Monero. As part of the announcement, the Shai-Hulud worm has been open-sourced and hosted on the forum&#8217;s content delivery network. While it was also <a href=\"https:\/\/www.ox.security\/blog\/shai-hulud-open-source-malware-github\/\">made available on GitHub<\/a>, it has since been removed. According to <a href=\"https:\/\/x.com\/DarkWebInformer\/status\/2054590267252940870\">screenshots shared<\/a> by Dark Web Informer on X, the competition rules require participants to use the worm in their attacks and submit proof that they have obtained access to a target&#8217;s environment. \u00abThe biggest supply chain based on the amount of weekly\/monthly downloads will win,\u00bb the threat actor said. \u00abIf you compromise many small packages, it will be added up.\u00bb The development marks a newfound escalation of TeamPCP&#8217;s tradecraft. \u00abThe contest essentially functions as a public recruitment stunt, turning supply chain compromise into a leaderboard for lower-tier actors willing to trade risk for recognition,\u00bb Socket <a href=\"https:\/\/socket.dev\/blog\/teampcp-supply-chain-attack-contest\">said<\/a>. \u00abTeamPCP has already been positioning supply chain compromise as a way to harvest credentials, expose enterprise environments, and hand access to groups that know how to monetize it. Now it is giving forum users an open source worm, a scoring system, and a reason to rack up compromises.\u00bb\n    <\/p>\n<\/p><\/div>\n<\/li>\n<li class=\"td-item\">\n  <span aria-hidden=\"true\" class=\"td-dot\"\/><\/p>\n<div class=\"td-stack\">\n    <span class=\"td-punch\">NATS-powered C2<\/span><\/p>\n<p class=\"td-desc\">\n      An unknown threat actor has been spotted using a <a href=\"https:\/\/github.com\/nats-io\/nats-server\">NATS<\/a> server as a command-and-control (C2) channel rather than relying on traditional HTTP-based panels or chat platforms. The novel technique has been codenamed NATS-as-C2 by cloud security company Sysdig. The activity relates to the exploitation ofCVE-2026-33017, an unauthenticated remote code execution (RCE) vulnerability in Langflow. \u00abOver roughly 30 minutes of hands-on activity, the operator at 159.89.205.184 (DigitalOcean) downloaded a Python worker and a Go binary,\u00bb the company <a href=\"https:\/\/www.sysdig.com\/blog\/nats-as-c2-inside-a-new-technique-attackers-are-using-to-harvest-cloud-credentials-and-ai-api-keys\">said<\/a>. While threat actors have adopted legitimate platforms and services as covert communication channels, this is the first time NATS, a high-performance communications system, has been leveraged for this purpose.\n    <\/p>\n<\/p><\/div>\n<\/li>\n<\/ol>\n<\/section>\n<\/div>\n<p>That\u2019s it. Attackers keep winning with simple crap: fake prompts, trusted tools, weak checks, and old systems nobody wants to fix.<\/p>\n<p>Do the boring work. Patch. Change keys. Check users. Test backups. Block the obvious junk. We\u2019ll be back when the fire moves.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802May 14, 2026Hacking News \/ Cybersecurity News Everything is still on fire. This week feels dumb in the worst way \u2014 bad links, weak checks, fake help desks, shady&hellip;<\/p>\n","protected":false},"author":1,"featured_media":924,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[24,610,1677,1116,1537,316,187,1678],"class_list":["post-923","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attacks","tag-bug","tag-curl","tag-mythos","tag-panos","tag-rce","tag-stories","tag-tokenizer"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/923","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=923"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/923\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/924"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=923"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=923"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=923"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}