Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: May 29, 2026 - May 29, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Friday, May 29, 2026 -29% vs prior run
[!!] ALERT THRESHOLD BREACHED

AI & Supply Chain

[HIGH]

CVE-2026-8398 — Daemon Tools Lite

Embedded malicious code vulnerability in Daemon Tools Lite with high impact on confidentiality, integrity, and availability. CISA added to KEV catalog May 27, 2026 with action due date May 30, 2026.

REMEDIATION

Uninstall affected Daemon Tools versions immediately. Scan systems for indicators of compromise. Rotate credentials accessible from machines running vulnerable versions. Deploy endpoint detection to identify malicious activity.

Source: CISA  •  Published: 2026-05-27

Threat Actors & Dark Web

[CRITICAL]

CVE-2026-26980 — Ghost CMS

Critical SQL injection vulnerability in Ghost CMS allowing unauthenticated attackers to read database including Admin API Keys. Large-scale exploitation campaign injecting malicious JavaScript for ClickFix attacks. Over 700 domains compromised including Harvard, Oxford, Auburn universities and DuckDuckGo. XLab first detected May 7, 2026.

REMEDIATION

Urgently upgrade Ghost CMS to patched version. Rotate all credentials: Admin API Key, Content API Key, administrator passwords, sessions. Clean implanted content at database level. Review web application firewall logs.

Source: NVD  •  Published: 2026-05-07

[CRITICAL]

INSTRUCTURE-CANVAS-BREACH-2026 — Instructure Canvas LMS

ShinyHunters ransomware group breached Canvas LMS stealing approximately 275 million records of students, teachers, and staff. Attackers demanded ransom by May 6, 2026. Affected 8,809 school districts, universities, and online education platforms per shared victim list.

REMEDIATION

Schools and universities must notify affected students and staff immediately. Reset all Canvas credentials. Enable MFA on all education platform accounts. Monitor for phishing campaigns using personalized breach data.

Source: BleepingComputer  •  Published: 2026-05-06

[CRITICAL]

NYC-HEALTH-BIOMETRIC-BREACH-2026 — NYC Health + Hospitals

NYC public healthcare system breach affecting 1.8+ million individuals with theft of personal data, medical records, and biometric scans including fingerprints. One of largest recorded healthcare breaches of 2026 with highly sensitive biometric data compromise.

REMEDIATION

Affected individuals should enroll in provided identity theft protection services. Monitor medical records for fraudulent activity. Healthcare organizations must review biometric data storage practices and implement enhanced encryption.

Source: BleepingComputer  •  Published: 2026-05-29

[HIGH]

APT28-DNS-HIJACK-2026 — MikroTik and TP-Link routers

Russia-linked APT28 (Forest Blizzard/Storm-2754) DNS hijacking campaign compromising insecure SOHO routers since May 2025. Modified DNS settings to capture authentication credentials. Microsoft identified 200+ organizations and 5,000+ consumer devices impacted. FBI Operation Masquerade neutralized U.S. infrastructure across 23+ states.

REMEDIATION

Factory reset SOHO routers and update to latest firmware. Verify DNS settings point to legitimate ISP or trusted resolvers. Implement network segmentation isolating SOHO devices from critical assets. Monitor DNS query anomalies.

Source: GTIG  •  Published: 2026-05-29

Priority Action Matrix

01DO NOWCVE-2026-26980 (Ghost CMS): Urgently upgrade Ghost CMS to patched version. Rotate all credentials: Admin API Key, Content API Key, administrator passwords, sessions. Clean implanted content at database level. Review web applicat...
02DO NOWINSTRUCTURE-CANVAS-BREACH-2026 (Instructure Canvas LMS): Schools and universities must notify affected students and staff immediately. Reset all Canvas credentials. Enable MFA on all education platform accounts. Monitor for phishing campaigns using personal...
03DO NOWNYC-HEALTH-BIOMETRIC-BREACH-2026 (NYC Health + Hospitals): Affected individuals should enroll in provided identity theft protection services. Monitor medical records for fraudulent activity. Healthcare organizations must review biometric data storage practice...
04TODAYCVE-2026-8398 (Daemon Tools Lite): Uninstall affected Daemon Tools versions immediately. Scan systems for indicators of compromise. Rotate credentials accessible from machines running vulnerable versions. Deploy endpoint detection to i...
05TODAYAPT28-DNS-HIJACK-2026 (MikroTik and TP-Link routers): Factory reset SOHO routers and update to latest firmware. Verify DNS settings point to legitimate ISP or trusted resolvers. Implement network segmentation isolating SOHO devices from critical assets. ...

Biggest Risk This Period

BIGGEST RISK

CVE-2026-26980: Critical SQL injection vulnerability in Ghost CMS allowing unauthenticated attackers to read database including Admin API Keys. Large-scale exploitation campaign injecting malicious JavaScript for ClickFix attacks. Over 700 domains compromised including Harvard, Oxford, Auburn universities and DuckDuckGo. XLab first detected May 7, 2026.